This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Browser hijacker and continue to be infected w WIndows Securi

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Thanks so much for your help. As mentioned above, My broswer keeps getting hijacked on my google search pages, and if I dont run Superantispyware AND Malwarebytes a couple of times each day, I get the Windows Security virus (AV) and related viruses, porn on my desktop, etc. It sucks. I am running Windows XP. Here is my Hijack This log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:44:06 PM, on 5/12/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Common Files\Apple\Mobile Device

Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\Acrobat.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\Adobelm_Cleanup.0001
C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\Adobelm_Cleanup.0001
C:\WINDOWS\system32\notepad.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

http://biblegateway.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =

http://www.gateway.com/g/startpage.html?Ch…TP&M=GT5058
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet

Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =

*.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {6F45AEA2-9C81-4832-8390-7134102B8DE5} - C:\Program

Files\WeatherStudio Desktop\bin\WeatherStudio Desktop.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program

Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} -

C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -

C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} -

c:\windows\system32\BAE.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program

Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program

Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program

Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes'

Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (rootkit-scan)] "C:\Program

Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program

Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Owner\Local

Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program

Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common

Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB

F5D7050\Wireless Utility\Belkinwcui.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program

Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program

Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program

Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program

Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program

Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program

Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe

Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program

Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel -

res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google

Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -

C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683}

- C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.camperconnection.net
O16 - DPF: {0C92900E-4D5A-4F04-ACC9-729E1767BBAE} (Image Uploader Control) -

http://www.ritzpix.com/net/Uploader/LPUploader45.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -

http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -

http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} (SupportSoft External Control) -

https://actsvr.comcastonline.com/techtools/…%20Controls.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) -

http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -

http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} -

http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) -

https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} (GameHouse Games Player) -

http://aolsvc.aol.com/onlinegames/free-tri…houseplayer.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) -

http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) -

http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) -

http://knoxville.yourhub.com/YourHub/ImageUploader3.cab
O16 - DPF: {C1BAC744-8F0B-11D0-89E7-00C0A8295197} (Cameractl Class) -

http://www.berkeley.edu/webcams/camera.cab
O16 - DPF: {C7DEDA04-2FFF-4B81-AE66-0A0E0EF4AD2F} (Image Uploader Control) -

http://www.ritzpix.com/net/Uploader/LPUploader57.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) -

https://technologyondemand.webex.com/client…bex/ieatgpc.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -

http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} -

http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} -

C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon -

{8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe

Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common

Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program

Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program

Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation -

C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. -

C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes'

Anti-Malware\mbamservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -

C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common

Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program

Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 11490 bytes
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 5 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post
•Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
•This may cause a delay in response time, but I will do my best to keep it as short as possible.
•I will reply back shortly with instructions.
Hello mknorrell,please do the following.

Please open notepad click format and make sure word wrap is not ticked.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries



In your next reply please post the following.
  • Both OTL logs
  • GMER log
MAIN OTL LOG…THANK YOU!!!!

OTL logfile created on: 5/14/2010 12:57:58 PM - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 74.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 228.79 Gb Total Space | 12.45 Gb Free Space | 5.44% Space Free | Partition Type: NTFS
Drive D: | 4.09 Gb Total Space | 2.38 Gb Free Space | 58.28% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KATIE
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe (Belkin Corporation)
PRC - C:\Program Files\Digital Media Reader\readericon45G.exe (Alcor Micro, Corp.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (PrismXL) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
SRV - (Pml Driver) – C:\WINDOWS\system32\hphipm09.exe (HP)
SRV - (Adobe Version Cue CS2) – C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe (Adobe Systems Incorporated)


========== Driver Services (SafeList) ==========

DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (gqejw) – C:\WINDOWS\system32\drivers\syfwco.sys ()
DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (BANTExt) – C:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (NdisWDM) – C:\WINDOWS\system32\drivers\NdisWDM.sys (Broadcom Corporation)
DRV - (Dot4Storage HPH09) Storage Class Driver for IEEE-1284.4 (HPH09) – C:\WINDOWS\system32\drivers\hphs2k09.sys (Hewlett-Packard)
DRV - (Dot4Usb HPH09) – C:\WINDOWS\system32\drivers\hphius09.sys (HP)
DRV - (Dot4Print HPH09) – C:\WINDOWS\system32\drivers\hphipr09.sys (HP)
DRV - (Dot4 HPH09) – C:\WINDOWS\system32\drivers\hphid409.sys (HP)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\alcxwdm.sys (Realtek Semiconductor Corp.)
DRV - (BLKWGU(Belkin)) Belkin Wireless G USB Network Adapter(Belkin) – C:\WINDOWS\system32\drivers\BLKWGU.sys (Belkin Corporation)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (Cdralw2k) – C:\WINDOWS\system32\drivers\cdralw2k.sys (Roxio)
DRV - (Cdr4_xp) – C:\WINDOWS\system32\drivers\cdr4_xp.sys (Roxio)
DRV - (ZDPSp50) – C:\WINDOWS\system32\drivers\ZDPSp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (mxnic) – C:\WINDOWS\system32\drivers\mxnic.sys (Macronix International Co., Ltd. )
DRV - (ASPI32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://biblegateway.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = :0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071101000055
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8

FF - HKLM\software\mozilla\eMusic Download Manager\Extensions\\Components: C:\Program Files\eMusic Download Manager\xulrunner\components [2009/06/08 19:56:40 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\eMusic Download Manager\Extensions\\Plugins: C:\Program Files\eMusic Download Manager\xulrunner\plugins [2009/06/08 19:56:42 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/24 16:29:33 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/24 16:29:33 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Netscape Browser 8.1.0.0\Extensions\\Components: C:\Program Files\\Netscape\\Netscape Browser\Components [2008/12/07 13:42:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Netscape Browser 8.1.0.0\Extensions\\Plugins: C:\Program Files\\Netscape\\Netscape Browser\Plugins [2009/11/06 18:36:09 | 000,000,000 | —D | M]

[2010/02/04 16:40:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2009/01/28 16:51:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\[removed]
[2010/05/12 15:40:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\a3sry7s4.default\extensions
[2010/05/03 13:27:13 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\a3sry7s4.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/11/27 16:14:57 | 000,000,000 | —D | M] (Web Developer) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\a3sry7s4.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2008/10/02 21:17:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\a3sry7s4.default\extensions\[removed]
[2010/05/12 15:40:46 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2006/05/24 13:36:57 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2008/01/02 01:10:23 | 000,159,744 | —- | M] (CNN) – C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll
[2007/04/16 13:07:12 | 000,180,293 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll

O1 HOSTS File: ([2004/08/10 15:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: () - {6F45AEA2-9C81-4832-8390-7134102B8DE5} - C:\Program Files\WeatherStudio Desktop\bin\WeatherStudio Desktop.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\WINDOWS\system32\bae.dll (Gateway Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (rootkit-scan)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe (Alcor Micro, Corp.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe (Belkin Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: camperconnection.net ([]* in Trusted sites)
O16 - DPF: {0C92900E-4D5A-4F04-ACC9-729E1767BBAE} http://www.ritzpix.com/net/Uploader/LPUploader45.cab (Image Uploader Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/pub/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab (YInstStarter Class)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photos.walmart.com/WalmartActivia.cab (Snapfish Activia)
O16 - DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} https://actsvr.comcastonline.com/techtools/…%20Controls.cab (SupportSoft External Control)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab (DLM Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://go.divx.com/plugin/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} http://aolsvc.aol.com/onlinegames/free-tri…houseplayer.cab (GameHouse Games Player)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} http://web1.shutterfly.com/downloads/Uploader.cab (Shutterfly Picture Upload Plugin)
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} http://knoxville.yourhub.com/YourHub/ImageUploader3.cab (Aurigma Image Uploader 3.5 Control)
O16 - DPF: {C1BAC744-8F0B-11D0-89E7-00C0A8295197} http://www.berkeley.edu/webcams/camera.cab (Cameractl Class)
O16 - DPF: {C7DEDA04-2FFF-4B81-AE66-0A0E0EF4AD2F} http://www.ritzpix.com/net/Uploader/LPUploader57.cab (Image Uploader Control)
O16 - DPF: {CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://technologyondemand.webex.com/client…bex/ieatgpc.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.16.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/01/09 21:13:09 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2004/09/13 12:15:24 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O33 - MountPoints2\{4d15b38a-9bc3-11dd-a561-0015581f7a49}\Shell\AutoRun\command - "" = K:\Autorun.exe – File not found
O33 - MountPoints2\{4d15b38a-9bc3-11dd-a561-0015581f7a49}\Shell\Shell00\Command - "" = K:\Autorun.exe – File not found
O33 - MountPoints2\{4d15b38a-9bc3-11dd-a561-0015581f7a49}\Shell\Shell01\Command - "" = K:\Autorun.exe – File not found
O33 - MountPoints2\{4d15b38a-9bc3-11dd-a561-0015581f7a49}\Shell\Shell02\Command - "" = K:\Autorun.exe – File not found
O33 - MountPoints2\{7855b9a1-9814-11da-9eba-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{7855b9a1-9814-11da-9eba-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{871e1fdf-fdc0-11dc-a53a-0015581f7a49}\Shell\AutoRun\command - "" = K:\wd_windows_tools\WDSetup.exe – File not found
O33 - MountPoints2\{a3862743-c727-11dd-a574-0015581f7a49}\Shell\AutoRun\command - "" = K:\wd_windows_tools\WDSetup.exe – File not found
O33 - MountPoints2\{b3053969-9822-11da-b84e-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{b3053969-9822-11da-b84e-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{c89802f5-d71c-11da-a480-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{c89802f5-d71c-11da-a480-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{e16a983d-c7a4-11dd-a578-0015581f7a49}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{e16a983d-c7a4-11dd-a578-0015581f7a49}\Shell\AutoRun\command - "" = L:\autorun.exe – File not found
O33 - MountPoints2\{e16a983d-c7a4-11dd-a578-0015581f7a49}\Shell\phone\command - "" = L:\autorun.exe – File not found
O33 - MountPoints2\{f23e23e2-0bc2-11db-a499-0015581f7a49}\Shell\AutoRun\command - "" = K:\setupSNK.exe – File not found
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\K\Shell - "" = AutoRun
O33 - MountPoints2\K\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2005/01/09 21:12:02 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Error starting restore point: System Restore is disabled.
Error closing restore point: System Restore is disabled.

========== Files/Folders - Created Within 30 Days ==========

[2010/05/14 12:43:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\desktopjunk
[2010/05/14 12:18:01 | 000,570,880 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/05/12 14:32:03 | 000,640,000 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTS.exe
[2010/05/11 20:12:53 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/04/29 11:06:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\eskbackup
[2010/04/28 16:37:52 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\U3
[2010/04/22 12:08:29 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Google
[2010/04/22 12:05:08 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\aayqfpbnl
[2010/04/22 12:05:06 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\umqrfnmkr
[2010/04/20 17:14:37 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/04/20 16:45:55 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\AdobeUM
[2010/04/20 16:04:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2010/04/20 16:04:11 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2010/04/20 16:04:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
[2010/04/20 16:03:37 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2010/04/18 12:46:01 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Malwarebytes
[2010/04/17 17:45:45 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/17 17:45:42 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/17 16:09:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2010/04/17 16:09:45 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/04/17 16:09:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/04/17 14:33:58 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/04/17 14:33:55 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/04/17 13:01:36 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/05/14 12:59:01 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/14 12:42:01 | 000,000,650 | —- | M] () – C:\WINDOWS\win.ini
[2010/05/14 12:42:01 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/05/14 12:42:01 | 000,000,209 | RHS- | M] () – C:\boot.ini
[2010/05/14 12:41:53 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/05/14 12:41:52 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/14 12:40:48 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/05/14 12:40:47 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/05/14 12:40:46 | 2011,746,304 | -HS- | M] () – C:\hiberfil.sys
[2010/05/14 12:21:01 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3193571741-738124885-782117674-1006UA.job
[2010/05/14 12:18:02 | 000,570,880 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/05/13 16:37:00 | 000,448,869 | —- | M] () – C:\Documents and Settings\Owner\Desktop\amanda.jpg
[2010/05/13 16:35:59 | 000,029,363 | —- | M] () – C:\Documents and Settings\Owner\Desktop\4565864025_e3cabd78e3_o.jpg
[2010/05/13 15:21:01 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3193571741-738124885-782117674-1006Core.job
[2010/05/12 14:52:12 | 016,252,928 | —- | M] () – C:\Documents and Settings\Owner\ntuser.dat
[2010/05/12 14:32:04 | 000,640,000 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTS.exe
[2010/05/12 13:43:50 | 000,002,447 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HiJackThis.lnk
[2010/05/11 22:12:21 | 000,004,224 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rdpcdd.sys
[2010/05/11 18:17:18 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Owner\ntuser.ini
[2010/05/11 17:55:40 | 000,054,016 | —- | M] () – C:\WINDOWS\System32\drivers\syfwco.sys
[2010/05/11 16:48:42 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/05/11 16:19:13 | 000,012,552 | —- | M] () – C:\Documents and Settings\Owner\My Documents\sjcmeeting_51110.pdf
[2010/05/11 16:18:15 | 000,040,960 | —- | M] () – C:\Documents and Settings\Owner\My Documents\sjc_562010.doc
[2010/05/11 15:43:00 | 000,051,058 | —- | M] () – C:\Documents and Settings\Owner\My Documents\UT Flyer.pdf
[2010/05/11 15:26:00 | 000,165,121 | —- | M] () – C:\Documents and Settings\Owner\My Documents\UT Flyer.xls
[2010/05/11 13:31:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/05/08 16:13:06 | 000,037,888 | —- | M] () – C:\Documents and Settings\Owner\My Documents\journal4302010.doc
[2010/05/06 15:21:52 | 000,000,162 | -H– | M] () – C:\Documents and Settings\Owner\My Documents\~$Bee.doc
[2010/05/06 15:21:39 | 000,136,192 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Bee.doc
[2010/04/30 14:34:45 | 000,028,160 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Lisa Murray_critical incident.doc
[2010/04/30 14:32:43 | 000,029,184 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Lisa Murray learning autobio.doc
[2010/04/30 14:32:00 | 000,376,320 | —- | M] () – C:\Documents and Settings\Owner\My Documents\reading record.xls
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/29 05:21:25 | 000,002,284 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Google Chrome.lnk
[2010/04/28 13:30:02 | 000,031,232 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Journal.doc
[2010/04/26 20:57:03 | 002,544,759 | —- | M] () – C:\Documents and Settings\Owner\My Documents\record-march-2010.pdf
[2010/04/26 14:27:39 | 000,034,304 | —- | M] () – C:\Documents and Settings\Owner\My Documents\There is no safety in man.doc
[2010/04/22 12:03:59 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/04/20 18:27:33 | 000,014,858 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\2fOFu
[2010/04/20 18:27:32 | 000,014,858 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\2fOFu
[2010/04/20 16:58:15 | 000,015,350 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\p63586CeJQo2
[2010/04/20 16:58:15 | 000,015,350 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\p63586CeJQo2
[2010/04/20 16:04:16 | 000,000,780 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Professional.lnk
[2010/04/20 16:03:12 | 007,899,168 | —- | M] () – C:\Documents and Settings\Owner\Desktop\SUPERAntiSpywarePro.exe
[2010/04/17 20:40:30 | 000,024,064 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Proposal for SJC.doc
[2010/04/17 17:45:48 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/17 17:06:01 | 000,017,274 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\JH40y5L
[2010/04/17 17:06:01 | 000,017,274 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\664514575
[2010/04/17 17:05:57 | 000,016,074 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\JH40y5L
[2010/04/17 16:58:16 | 000,019,022 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\664514575
[2010/04/17 16:58:16 | 000,019,022 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\2604077421
[2010/04/17 16:58:10 | 000,019,160 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\2604077421
[2010/04/17 15:50:18 | 000,000,319 | —- | M] () – C:\Documents and Settings\Owner\Desktop\trojan_fakerean_exe_fix.reg
[2010/04/17 15:23:08 | 000,012,772 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\7UGM6
[2010/04/17 15:23:08 | 000,012,772 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\7UGM6
[2010/04/17 15:22:27 | 000,001,130 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\uk267W7
[2010/04/17 15:22:26 | 000,001,130 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\uk267W7
[2010/04/17 14:49:29 | 000,012,590 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\1917792730
[2010/04/17 14:49:28 | 000,012,590 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\1917792730
[2010/04/17 14:47:16 | 000,012,606 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\2254186452
[2010/04/17 14:47:16 | 000,012,606 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\2254186452
[2010/04/17 14:18:27 | 000,028,160 | —- | M] () – C:\Documents and Settings\Owner\My Documents\KATIE NORRELL_references.doc
[2010/04/17 14:10:55 | 000,000,100 | –S- | M] () – C:\WINDOWS\System32\1324528605.dat
[2010/04/16 13:38:03 | 000,052,808 | —- | M] () – C:\Documents and Settings\Owner\My Documents\resume_norrell_41610.pdf
[2010/04/16 13:36:50 | 000,057,856 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Katie Norrell_cover3.doc
[2010/04/15 18:06:12 | 000,007,408 | —- | M] () – C:\Documents and Settings\Owner\My Documents\norrell_references.pdf
[2010/04/15 17:55:55 | 000,046,505 | —- | M] () – C:\Documents and Settings\Owner\My Documents\norrell_resume_utathletics.pdf
[2010/04/15 17:55:22 | 000,058,368 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Katie Norrell_cover2.doc
[2010/04/15 17:14:33 | 000,052,696 | —- | M] () – C:\Documents and Settings\Owner\My Documents\norrell_resume_41510.pdf
[2010/04/15 17:13:24 | 000,007,857 | —- | M] () – C:\Documents and Settings\Owner\My Documents\KATIE NORRELL_references.pdf
[2010/04/15 11:24:01 | 000,048,128 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Katie Norrell_cover.doc
[2010/04/15 10:53:46 | 000,050,176 | —- | M] () – C:\Documents and Settings\Owner\My Documents\resume_4142010.doc
[2010/04/15 00:04:42 | 000,043,986 | —- | M] () – C:\Documents and Settings\Owner\My Documents\resume_4142010.pdf
[2010/04/14 14:58:15 | 000,036,264 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Resume_KNorrell_talentsphere.pdf
[2010/04/14 14:57:11 | 000,079,945 | —- | M] () – C:\Documents and Settings\Owner\My Documents\resume_knorrell.pdf
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/05/14 12:29:47 | 000,293,376 | —- | C] () – C:\Documents and Settings\Owner\Desktop\gmer.exe
[2010/05/13 16:36:59 | 000,448,869 | —- | C] () – C:\Documents and Settings\Owner\Desktop\amanda.jpg
[2010/05/13 16:35:59 | 000,029,363 | —- | C] () – C:\Documents and Settings\Owner\Desktop\4565864025_e3cabd78e3_o.jpg
[2010/05/11 20:12:54 | 000,002,447 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HiJackThis.lnk
[2010/05/11 18:13:30 | 2011,746,304 | -HS- | C] () – C:\hiberfil.sys
[2010/05/11 17:55:40 | 000,054,016 | —- | C] () – C:\WINDOWS\System32\drivers\syfwco.sys
[2010/05/11 16:19:13 | 000,012,552 | —- | C] () – C:\Documents and Settings\Owner\My Documents\sjcmeeting_51110.pdf
[2010/05/11 15:43:00 | 000,051,058 | —- | C] () – C:\Documents and Settings\Owner\My Documents\UT Flyer.pdf
[2010/05/11 15:28:12 | 000,165,121 | —- | C] () – C:\Documents and Settings\Owner\My Documents\UT Flyer.xls
[2010/05/06 15:21:52 | 000,000,162 | -H– | C] () – C:\Documents and Settings\Owner\My Documents\~$Bee.doc
[2010/05/06 15:21:38 | 000,136,192 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Bee.doc
[2010/05/06 13:38:35 | 000,040,960 | —- | C] () – C:\Documents and Settings\Owner\My Documents\sjc_562010.doc
[2010/04/30 14:34:45 | 000,028,160 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Lisa Murray_critical incident.doc
[2010/04/30 14:32:43 | 000,029,184 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Lisa Murray learning autobio.doc
[2010/04/30 14:32:00 | 000,376,320 | —- | C] () – C:\Documents and Settings\Owner\My Documents\reading record.xls
[2010/04/30 11:57:52 | 000,037,888 | —- | C] () – C:\Documents and Settings\Owner\My Documents\journal4302010.doc
[2010/04/28 12:19:29 | 000,031,232 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Journal.doc
[2010/04/26 20:57:02 | 002,544,759 | —- | C] () – C:\Documents and Settings\Owner\My Documents\record-march-2010.pdf
[2010/04/25 22:02:46 | 000,034,304 | —- | C] () – C:\Documents and Settings\Owner\My Documents\There is no safety in man.doc
[2010/04/20 18:08:50 | 000,014,858 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\2fOFu
[2010/04/20 18:08:50 | 000,014,858 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\2fOFu
[2010/04/20 17:34:25 | 000,002,600 | —- | C] () – C:\Documents and Settings\Owner\Desktop\xp_exe_fix.reg
[2010/04/20 16:04:16 | 000,000,780 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Professional.lnk
[2010/04/20 16:02:58 | 007,899,168 | —- | C] () – C:\Documents and Settings\Owner\Desktop\SUPERAntiSpywarePro.exe
[2010/04/20 15:18:01 | 000,002,284 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Google Chrome.lnk
[2010/04/20 15:16:43 | 000,000,978 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3193571741-738124885-782117674-1006UA.job
[2010/04/20 15:16:42 | 000,000,926 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3193571741-738124885-782117674-1006Core.job
[2010/04/20 14:44:05 | 000,000,335 | —- | C] () – C:\Documents and Settings\Owner\Desktop\FixExe.reg
[2010/04/20 14:11:24 | 000,000,319 | —- | C] () – C:\Documents and Settings\Owner\Desktop\trojan_fakerean_exe_fix.reg
[2010/04/20 14:04:57 | 000,015,350 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\p63586CeJQo2
[2010/04/20 14:02:17 | 000,015,350 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\p63586CeJQo2
[2010/04/20 14:02:17 | 000,010,376 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\p63586CeJQo2
[2010/04/17 20:40:30 | 000,024,064 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Proposal for SJC.doc
[2010/04/17 17:45:48 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/17 16:55:58 | 000,019,160 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\2604077421
[2010/04/17 16:55:58 | 000,019,022 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\664514575
[2010/04/17 16:55:58 | 000,019,022 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\2604077421
[2010/04/17 16:55:54 | 000,017,274 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\JH40y5L
[2010/04/17 16:55:54 | 000,017,274 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\664514575
[2010/04/17 16:55:53 | 000,016,074 | -HS- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\JH40y5L
[2010/04/17 16:53:17 | 000,016,074 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\JH40y5L
[2010/04/17 16:53:17 | 000,007,748 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\JH40y5L
[2010/04/17 15:22:21 | 000,001,130 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\uk267W7
[2010/04/17 15:22:21 | 000,001,130 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\uk267W7
[2010/04/17 14:44:58 | 000,012,590 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\1917792730
[2010/04/17 14:43:53 | 000,012,606 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\2254186452
[2010/04/17 14:43:53 | 000,012,590 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\1917792730
[2010/04/17 14:43:34 | 000,012,772 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\7UGM6
[2010/04/17 14:43:34 | 000,012,606 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\2254186452
[2010/04/17 14:34:04 | 000,012,772 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\7UGM6
[2010/04/17 14:34:04 | 000,012,598 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\7UGM6
[2010/04/17 14:33:55 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/04/16 13:37:39 | 000,052,808 | —- | C] () – C:\Documents and Settings\Owner\My Documents\resume_norrell_41610.pdf
[2010/04/16 13:36:30 | 000,057,856 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Katie Norrell_cover3.doc
[2010/04/15 18:06:12 | 000,007,408 | —- | C] () – C:\Documents and Settings\Owner\My Documents\norrell_references.pdf
[2010/04/15 17:55:55 | 000,046,505 | —- | C] () – C:\Documents and Settings\Owner\My Documents\norrell_resume_utathletics.pdf
[2010/04/15 17:28:52 | 000,058,368 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Katie Norrell_cover2.doc
[2010/04/15 17:13:24 | 000,007,857 | —- | C] () – C:\Documents and Settings\Owner\My Documents\KATIE NORRELL_references.pdf
[2010/04/15 16:48:56 | 000,028,160 | —- | C] () – C:\Documents and Settings\Owner\My Documents\KATIE NORRELL_references.doc
[2010/04/15 11:24:18 | 000,052,696 | —- | C] () – C:\Documents and Settings\Owner\My Documents\norrell_resume_41510.pdf
[2010/04/15 10:50:19 | 000,048,128 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Katie Norrell_cover.doc
[2010/04/15 00:04:42 | 000,043,986 | —- | C] () – C:\Documents and Settings\Owner\My Documents\resume_4142010.pdf
[2010/04/14 15:00:11 | 000,050,176 | —- | C] () – C:\Documents and Settings\Owner\My Documents\resume_4142010.doc
[2010/04/14 14:58:15 | 000,036,264 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Resume_KNorrell_talentsphere.pdf
[2010/04/14 14:57:10 | 000,079,945 | —- | C] () – C:\Documents and Settings\Owner\My Documents\resume_knorrell.pdf
[2008/12/10 23:20:03 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2008/12/10 21:59:17 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2008/12/10 21:59:16 | 000,757,760 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2008/12/07 14:43:38 | 000,000,164 | —- | C] () – C:\WINDOWS\avrack.ini
[2008/12/07 14:43:24 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2008/12/07 13:58:11 | 000,003,840 | —- | C] () – C:\WINDOWS\System32\drivers\BANTExt.sys
[2008/06/10 15:03:04 | 000,166,912 | —- | C] () – C:\WINDOWS\System32\Lame_enc.dll
[2008/04/24 21:05:21 | 000,036,291 | —- | C] () – C:\WINDOWS\CSTBox.INI
[2006/12/24 21:26:49 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/08/15 21:14:28 | 000,000,126 | R— | C] () – C:\WINDOWS\hpw9600k.ini
[2006/08/15 21:06:55 | 000,014,973 | —- | C] () – C:\WINDOWS\hpdj9600.ini
[2006/05/23 13:00:57 | 000,000,034 | —- | C] () – C:\WINDOWS\hpfsched.ini
[2006/02/07 16:11:31 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/02/07 15:51:54 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/02/07 15:51:54 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/02/07 15:51:53 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/02/07 15:51:51 | 001,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/02/07 15:51:51 | 000,573,440 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/02/07 15:51:51 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/02/07 15:51:49 | 000,046,080 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2005/08/06 01:01:54 | 000,239,104 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/07/12 14:44:42 | 000,015,872 | —- | C] () – C:\WINDOWS\System32\InsDrvZD64.DLL
[2005/06/11 11:47:00 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\fpprintmon.dll
[2005/01/12 13:38:00 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/01/09 19:49:16 | 000,001,220 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2005/01/09 19:49:16 | 000,000,491 | —- | C] () – C:\WINDOWS\System32\emver.ini
[2004/12/20 11:08:28 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2004/12/20 11:03:26 | 000,679,936 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2004/03/23 16:38:00 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\InsDrvZD.dll
[2003/01/07 19:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2008/07/04 10:43:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Comcast
[2009/02/02 22:56:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2008/02/16 00:54:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameHouse
[2006/12/24 21:13:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2008/12/01 20:22:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Smilebox
[2008/12/01 20:19:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2008/06/10 15:25:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/06/12 21:53:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/02/05 23:24:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WeatherStudio Desktop
[2008/02/04 14:36:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WeatherStudio348
[2008/12/07 13:45:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2006/05/12 23:01:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Alien Skin
[2009/04/01 18:32:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Artisteer
[2008/10/31 20:36:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Canon
[2009/05/31 16:30:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\com.adobe.ExMan
[2009/06/08 19:56:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\eMusic
[2010/05/14 12:20:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FileZilla
[2009/01/28 16:51:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Flickr
[2006/06/02 21:31:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FrostWire
[2009/12/31 15:07:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GetRightToGo
[2008/08/10 17:40:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2008/10/16 23:28:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\LimeWire
[2008/12/13 12:51:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mjusbsp
[2006/04/28 21:23:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MSNInstaller
[2006/05/24 13:49:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Netscape
[2006/05/08 12:37:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Opera
[2006/12/24 21:12:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\RhinoSoft.com
[2006/02/07 16:32:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2006/10/05 20:20:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Smilebox
[2006/12/15 22:13:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Snapfish
[2006/05/07 00:19:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Template
[2007/02/10 12:47:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Viewpoint
[2008/05/25 00:19:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Vso
[2008/02/05 23:24:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WeatherStudio Desktop
[2009/05/19 14:24:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\webex
[2009/12/31 15:09:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Xilisoft Corporation

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/10 15:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2004/08/10 15:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\agp440.sys
[2004/08/04 10:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\system32\drivers\AGP440.SYS

< MD5 for: ATAPI.SYS >
[2004/08/10 15:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2004/08/10 15:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\atapi.sys
[2004/08/04 09:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\eventlog.dll
[2004/08/10 15:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\netlogon.dll
[2004/08/10 15:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/10 15:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2005/07/26 00:39:44 | 001,267,200 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\comsvcs.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2005/01/09 12:58:49 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/01/09 12:58:49 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/01/09 12:58:49 | 000,868,352 | —- | M] () – C:\WINDOWS\system32\config\system.sav

========== Alternate Data Streams ==========

@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C1F4198F
< End of report >
Hi - I posted earlier…was asked to post an OTL log, but my malware infested computer grinded to a hault and I couldnt post the rest of my logs…had to hire someone to come and remove the offending trojan. Im not sure if he got everything…computer still running a little slow….could you please check me out? Many, many thanks. Cant afford to keep hiring folks. Thanks very much.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:25:31 PM, on 5/15/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\hphmon03.exe
C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANToManager.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://biblegateway.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gateway.com/g/startpage.html?Ch…TP&M=GT5058
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {6F45AEA2-9C81-4832-8390-7134102B8DE5} - C:\Program Files\WeatherStudio Desktop\bin\WeatherStudio Desktop.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (rootkit-scan)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [PSUNMain] "C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe" /Traybar
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O4 - Global Startup: Dynex Wireless Networking Utility.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.camperconnection.net
O16 - DPF: {0C92900E-4D5A-4F04-ACC9-729E1767BBAE} (Image Uploader Control) - http://www.ritzpix.com/net/Uploader/LPUploader45.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {42D06124-98A2-47EC-8098-3778B58CE7D5} (SupportSoft External Control) - https://actsvr.comcastonline.com/techtools/…%20Controls.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} (GameHouse Games Player) - http://aolsvc.aol.com/onlinegames/free-tri…houseplayer.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://knoxville.yourhub.com/YourHub/ImageUploader3.cab
O16 - DPF: {C1BAC744-8F0B-11D0-89E7-00C0A8295197} (Cameractl Class) - http://www.berkeley.edu/webcams/camera.cab
O16 - DPF: {C7DEDA04-2FFF-4B81-AE66-0A0E0EF4AD2F} (Image Uploader Control) - http://www.ritzpix.com/net/Uploader/LPUploader57.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://technologyondemand.webex.com/client…bex/ieatgpc.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} - http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NanoServiceMain - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 11341 bytes
mknorrell Please follow Mowmans instructions and post the required logs. Do not start any new topics, reply to this one only

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI