This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Web Browser Constantly Re-directs - I have included my Hijackthis log

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have been experiencing much trouble with my web browser redirecting. Sometimes while on one page it will automatically redirect to a random advertisement page. Other times it will redirect if I click on one website link, it takes me to a random page. I use Mozilla Firefox as my browser. (This issue does occur however in BOTH Internet Explorer and Mozilla Firefox) My OS is Windows XP. A while back I downloaded the add-on "NoScript [removed]". (Just in case you needed that bit of info.) It doesn't really help the redirecting issue I am having. It does block some things but that wasn't really my main issue. I mainly wanted to fix the browser redirecting problem. I have just recently downloaded and run Hijackthis and I have the log file below:


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:22:59 PM, on 5/18/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\regsvr32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\All Users\Application Data\0FGAVxDX.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: profitizeme browser enhancer - {140C76D7-8D8B-E7D7-E5A2-6FB4377D954F} - C:\WINDOWS\system32\dnhiozxybgjuwe.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (file missing)
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [gcpbwnlsegpcoto] C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\dnhiozxybgjuwe.dll"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10c.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10c.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://download.windowsupdate.com
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1259681558109
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

–
End of file - 8769 bytes


I have read that Hijackthis is a wonderful little tool and I decided to try it, hoping it will help to fix my browsing issues!! Please let me know if any further info is needed or any more explanation on my part. I'm new to this and not all that tech savvy. Thank You for any help!
Hello Desiree and :welcome:

My name is JonTom.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.

  • Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
  • This may cause a delay in response time, but I will do my best to keep it as short as possible.
  • I will reply back shortly with instructions.
Hello Desiree

Thank you for the log.

I'm new to this and not all that tech savvy.

Don't worry. If you are unsure about what to do at any point just come back and ask, its what I am here for :)

Please work your way through the steps below. If you encounter any difficulties, come back and let me know.

  • Please RUN HijackThis


    • Click the "Do a System Scan Only" button to produce a log.
    • Place a check mark beside each one of the following items (if they are present):


    O2 - BHO: profitizeme browser enhancer - {140C76D7-8D8B-E7D7-E5A2-6FB4377D954F} - C:\WINDOWS\system32\dnhiozxybgjuwe.dll
    O4 - HKLM\..\Run: [gcpbwnlsegpcoto] C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\dnhiozxybgjuwe.dll"



    • Now with all the items selected, and all windows closed except for HJT, delete the selected items by clicking the FIX checked button. Close the HijackThis window.


  • Download and run OTL by Oldtimer


    • Please download OTL by Oldtimer by clicking here and save the file (called OTL.exe) to your desktop.
    • Close all open windows on your computer then Double click on the OTL.exe icon to run the program.
    • Check the boxes beside "LOP Check" and "Purity Check".
    • Under Custom Scan paste this in:

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
    CREATERESTOREPOINT


    • Click the "Run Scan" button. Do not change any settings unless specifically told to do so. The scan will not take long.

    • When the scan completes, it will open two notepad windows: OTL.Txt and Extras.Txt.
    • Note: These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
    • Please Copy and Paste the contents of both files in your next reply. You may need two posts to fit them both in.

  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

      [external image: Posted Image]
      Click the image to enlarge it
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.


    **Caution**
    Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries



    Please provide the OTL logs and the GMER log in your next reply.

    Note: You may need to make more than one post to fit all of the required information in.
Posted below are the logs from OTL, which worked fine. However, each time I ran GMER it would get stuck (it APPEARED to me that it got "stuck") at the section: C:\WINDOWS\system32\drivers\atapi.sys. Not sure what it's doing, or rather, NOT doing. ha! Let me know what I need to do on that end as well. Thanks!! The two logs from OTL are as follows…


OTL logfile created on: 5/21/2010 7:17:34 PM - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Documents and
Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type =
NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date
Format: M/d/yyyy

1.00 Gb Total Physical Memory | 0.00 Gb Available Physical Memory |
37.00% Memory free
2.00 Gb Paging File | 0.00 Gb Available in Paging File | 21.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% =
C:\Program Files
Drive C: | 465.75 Gb Total Space | 438.13 Gb Free Space | 94.07% Space
Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: WILSON
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/05/21 19:04:56 | 000,571,904 | —- | M] (OldTimer Tools)
– C:\Documents and Settings\Owner\Desktop\OTL.exe
PRC - [2010/04/21 09:02:18 | 000,620,896 | —- | M] (AVG Technologies
CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/04/01 09:26:12 | 001,101,152 | —- | M] (AVG Technologies
CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/03/15 09:45:11 | 000,508,184 | —- | M] (AVG Technologies
CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/03/15 09:45:04 | 000,308,064 | —- | M] (AVG Technologies
CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2010/03/15 09:43:30 | 000,710,424 | —- | M] (AVG Technologies
CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking
Ltd.) – C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2007/06/13 05:23:07 | 001,033,216 | —- | M] (Microsoft
Corporation) – C:\WINDOWS\explorer.exe


========== Modules (SafeList) ==========

MOD - [2010/05/21 19:04:56 | 000,571,904 | —- | M] (OldTimer Tools)
– C:\Documents and Settings\Owner\Desktop\OTL.exe
MOD - [2004/08/04 02:57:00 | 001,050,624 | —- | M] (Microsoft
Corporation) –
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
MOD - [2004/08/04 01:01:17 | 000,102,400 | —- | M] (Microsoft
Corporation) – C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - [2010/03/15 09:45:04 | 000,308,064 | —- | M] (AVG Technologies
CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG9\avgwdsvc.exe
– (avg9wd)
SRV - [2009/12/02 09:39:54 | 000,654,848 | —- | M] (Macrovision
Europe Ltd.) [On_Demand | Stopped] – C:\Program Files\Common
Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe –
(FLEXnet Licensing Service)


========== Driver Services (SafeList) ==========

DRV - [2010/04/21 09:02:19 | 000,242,896 | —- | M] (AVG Technologies
CZ, s.r.o.) [Kernel | System | Running] –
C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX)
DRV - [2010/03/15 09:45:10 | 000,029,512 | —- | M] (AVG Technologies
CZ, s.r.o.) [File_System | System | Running] –
C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86)
DRV - [2010/03/15 09:43:30 | 000,216,200 | —- | M] (AVG Technologies
CZ, s.r.o.) [Kernel | System | Running] –
C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86)
DRV - [2004/03/05 23:15:34 | 000,647,929 | —- | M] (Intel
Corporation) [Kernel | On_Demand | Running] –
C:\WINDOWS\system32\drivers\IntelC52.sys – (IntelC52)
DRV - [2004/03/05 23:14:42 | 001,233,525 | —- | M] (Intel
Corporation) [Kernel | On_Demand | Running] –
C:\WINDOWS\system32\drivers\IntelC51.sys – (IntelC51)
DRV - [2004/03/05 23:13:52 | 000,060,949 | —- | M] (Intel
Corporation) [Kernel | On_Demand | Running] –
C:\WINDOWS\system32\drivers\IntelC53.sys – (IntelC53)
DRV - [2004/03/05 23:13:38 | 000,037,048 | —- | M] (Intel
Corporation) [Kernel | On_Demand | Running] –
C:\WINDOWS\system32\drivers\mohfilt.sys – (mohfilt)
DRV - [2003/06/30 19:11:52 | 000,043,136 | R— | M] (Broadcom
Corporation) [Kernel | On_Demand | Running] –
C:\WINDOWS\system32\drivers\bcm4sbxp.sys – (bcm4sbxp)
DRV - [2001/08/22 09:42:58 | 000,013,632 | —- | M] (Dell Computer
Corporation) [Kernel | System | Running] –
C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS – (OMCI)
DRV - [2001/08/17 14:57:38 | 000,016,128 | —- | M] (Microsoft
Corporation) [Kernel | On_Demand | Running] –
C:\WINDOWS\system32\drivers\MODEMCSA.sys – (MODEMCSA)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} -
C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings:
"ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings:
"ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.selectedEngine: "Yahoo! Search"
FF - prefs.js..extensions.enabledItems:
{3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.812
FF - prefs.js..extensions.enabledItems: avg@igeared:4.002.023.004
FF - prefs.js..extensions.enabledItems:
{73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.9.42
FF - prefs.js..keyword.URL:
"http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p="

FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}:
C:\Program Files\AVG\AVG9\Firefox [2010/04/21 09:03:57 | 000,000,000 |
—D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\avg@igeared: C:\Program
Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/03/28 08:00:33 |
000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox
3.5.9\extensions\\Components: C:\Program Files\Mozilla
Firefox\components [2010/04/07 21:15:25 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Plugins:
C:\Program Files\Mozilla Firefox\plugins [2010/03/31 14:31:18 |
000,000,000 | —D | M]

[2009/12/01 00:18:33 | 000,000,000 | —D | M] – C:\Documents and
Settings\Owner\Application Data\Mozilla\Extensions
[2010/05/20 10:33:52 | 000,000,000 | —D | M] – C:\Documents and
Settings\Owner\Application
Data\Mozilla\Firefox\Profiles\209kmn1w.default\extensions
[2010/01/28 12:25:43 | 000,000,000 | —D | M] (NoScript) –
C:\Documents and Settings\Owner\Application
Data\Mozilla\Firefox\Profiles\209kmn1w.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/05/20 10:47:29 | 000,000,000 | —D | M] – C:\Program
Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2003/07/16 15:29:34 | 000,000,734 | —- | M]) -
C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -
C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) -
{53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot -
Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (AVG Security Toolbar BHO) -
{A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program
Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) -
{DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program
Files\Java\jre6\bin\jp2ssv.dll File not found
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) -
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program
Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) -
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program
Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program
Files\Adobe\Reader 9.0\Reader\Reader_sl.exe File not found
O4 - HKLM..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
(Ahead Software Gmbh)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search
& Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer:
NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration
- {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot -
Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program
Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] https in Trusted sites)
O15 - HKCU\..Trusted Domains: windowsupdate.com ([download] http in
Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
http://www.apple.com/qtactivex/qtplugin.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu…b?1259681558109
(MUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
(Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key
error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\linkscanner
{F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program
Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe
(Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\sdra64.exe) -
C:\WINDOWS\system32\sdra64.exe ()
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll -
C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll -
C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local
Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local
Settings\Application Data\Microsoft\Wallpaper1.bmp
O29 - HKLM SecurityProviders - (mbykipnf.dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/11/30 23:22:00 | 000,000,000 | —- | M] ()
- C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/11/30 23:21:41 |
000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17465059307421696)

========== Files/Folders - Created Within 30 Days
==========


[2010/05/21 19:04:50 | 000,571,904 | —- | C] (OldTimer Tools) –
C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/05/18 13:21:12 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/05/18 09:12:11 | 000,000,000 | —D | C] – C:\Documents and
Settings\All Users\Application Data\Google
[2010/05/18 08:33:36 | 000,000,000 | RH-D | C] – C:\Documents and
Settings\Owner\Recent
[2010/05/18 01:12:32 | 000,000,000 | —D | C] – C:\Program
Files\Spybot - Search & Destroy
[2010/05/18 01:12:32 | 000,000,000 | —D | C] – C:\Documents and
Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/05/18 00:58:31 | 000,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2010/05/18 00:51:59 | 000,000,000 | -HSD | C] – C:\Documents and
Settings\Owner\IECompatCache
[2010/05/18 00:40:41 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2010/05/18 00:19:57 | 000,000,000 | —D | C] – C:\Documents and
Settings\NetworkService\Local Settings\Application Data\Google
[2010/05/18 00:01:35 | 000,000,000 | —D | C] – C:\Documents and
Settings\Owner\Local Settings\Application Data\Temp
[2010/05/18 00:01:35 | 000,000,000 | —D | C] – C:\Documents and
Settings\LocalService\Local Settings\Application Data\Google
[2010/05/18 00:01:14 | 000,000,000 | —D | C] – C:\Documents and
Settings\Owner\Local Settings\Application Data\Google
[2010/05/18 00:01:11 | 000,000,000 | —D | C] – C:\Program Files\Google
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/05/21 19:12:05 | 000,002,497 | —- | M] () – C:\Documents and
Settings\Owner\Desktop\Microsoft Office Word 2003.lnk
[2010/05/21 19:08:14 | 000,000,162 | -H– | M] () – C:\Documents and
Settings\Owner\Desktop\~$rum help.doc
[2010/05/21 19:05:48 | 000,000,000 | —- | M] () – C:\Documents and
Settings\Owner\Local Settings\Application Data\prvlcl.dat
[2010/05/21 19:05:34 | 004,194,304 | -H– | M] () – C:\Documents and
Settings\Owner\NTUSER.DAT
[2010/05/21 19:04:56 | 000,571,904 | —- | M] (OldTimer Tools) –
C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/05/21 19:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At92.job
[2010/05/21 19:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At68.job
[2010/05/21 19:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At44.job
[2010/05/21 19:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At164.job
[2010/05/21 19:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At140.job
[2010/05/21 19:00:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At116.job
[2010/05/21 18:55:06 | 000,002,447 | —- | M] () – C:\Documents and
Settings\Owner\Desktop\HiJackThis.lnk
[2010/05/21 18:54:44 | 000,114,176 | —- | M] () – C:\Documents and
Settings\Owner\Desktop\forum help.doc
[2010/05/21 18:44:02 | 060,246,260 | —- | M] () –
C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/05/21 18:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At19.job
[2010/05/21 18:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At91.job
[2010/05/21 18:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At67.job
[2010/05/21 18:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At43.job
[2010/05/21 18:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At163.job
[2010/05/21 18:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At139.job
[2010/05/21 18:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At115.job
[2010/05/21 17:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At18.job
[2010/05/21 17:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At90.job
[2010/05/21 17:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At66.job
[2010/05/21 17:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At42.job
[2010/05/21 17:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At162.job
[2010/05/21 17:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At138.job
[2010/05/21 17:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At114.job
[2010/05/21 16:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At17.job
[2010/05/21 16:00:07 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At89.job
[2010/05/21 16:00:06 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At65.job
[2010/05/21 16:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At41.job
[2010/05/21 16:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At161.job
[2010/05/21 16:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At137.job
[2010/05/21 16:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At113.job
[2010/05/21 15:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At16.job
[2010/05/21 15:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At88.job
[2010/05/21 15:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At64.job
[2010/05/21 15:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At40.job
[2010/05/21 15:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At160.job
[2010/05/21 15:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At136.job
[2010/05/21 15:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At112.job
[2010/05/21 14:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At15.job
[2010/05/21 14:00:17 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At87.job
[2010/05/21 14:00:16 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At63.job
[2010/05/21 14:00:15 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At39.job
[2010/05/21 14:00:14 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At159.job
[2010/05/21 14:00:13 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At135.job
[2010/05/21 14:00:11 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At111.job
[2010/05/21 13:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At14.job
[2010/05/21 13:06:13 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At86.job
[2010/05/21 13:06:12 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At62.job
[2010/05/21 13:06:11 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At38.job
[2010/05/21 13:06:11 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At158.job
[2010/05/21 13:06:10 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At134.job
[2010/05/21 13:06:10 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At110.job
[2010/05/21 12:45:11 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/05/21 12:45:02 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/05/21 12:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At13.job
[2010/05/21 12:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At85.job
[2010/05/21 12:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At61.job
[2010/05/21 12:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At37.job
[2010/05/21 12:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At157.job
[2010/05/21 12:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At133.job
[2010/05/21 12:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At109.job
[2010/05/21 11:41:01 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At12.job
[2010/05/21 11:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At84.job
[2010/05/21 11:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At60.job
[2010/05/21 11:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At36.job
[2010/05/21 11:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At156.job
[2010/05/21 11:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At132.job
[2010/05/21 11:00:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At108.job
[2010/05/21 10:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At11.job
[2010/05/21 10:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At83.job
[2010/05/21 10:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At59.job
[2010/05/21 10:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At35.job
[2010/05/21 10:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At155.job
[2010/05/21 10:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At131.job
[2010/05/21 10:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At107.job
[2010/05/21 09:40:01 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At10.job
[2010/05/21 09:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At82.job
[2010/05/21 09:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At58.job
[2010/05/21 09:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At34.job
[2010/05/21 09:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At154.job
[2010/05/21 09:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At130.job
[2010/05/21 09:00:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At106.job
[2010/05/21 08:45:18 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At9.job
[2010/05/21 02:08:39 | 000,000,178 | -HS- | M] () – C:\Documents and
Settings\Owner\ntuser.ini
[2010/05/21 02:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At99.job
[2010/05/21 02:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At75.job
[2010/05/21 02:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At51.job
[2010/05/21 02:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At27.job
[2010/05/21 02:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At147.job
[2010/05/21 02:00:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At123.job
[2010/05/21 01:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At2.job
[2010/05/21 01:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At98.job
[2010/05/21 01:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At74.job
[2010/05/21 01:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At50.job
[2010/05/21 01:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At26.job
[2010/05/21 01:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At146.job
[2010/05/21 01:00:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At122.job
[2010/05/21 00:46:56 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At25.job
[2010/05/21 00:43:07 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2010/05/21 00:43:06 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At73.job
[2010/05/21 00:43:04 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At49.job
[2010/05/21 00:33:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At97.job
[2010/05/21 00:30:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At121.job
[2010/05/21 00:18:40 | 000,095,360 | —- | M] (Microsoft Corporation)
– C:\WINDOWS\System32\dllcache\atapi.sys
[2010/05/21 00:17:27 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At145.job
[2010/05/20 23:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At24.job
[2010/05/20 23:00:15 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At96.job
[2010/05/20 23:00:13 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At72.job
[2010/05/20 23:00:12 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At48.job
[2010/05/20 23:00:10 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At168.job
[2010/05/20 23:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At144.job
[2010/05/20 23:00:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At120.job
[2010/05/20 22:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At23.job
[2010/05/20 22:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At95.job
[2010/05/20 22:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At71.job
[2010/05/20 22:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At47.job
[2010/05/20 22:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At167.job
[2010/05/20 22:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At143.job
[2010/05/20 22:00:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At119.job
[2010/05/20 21:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At22.job
[2010/05/20 21:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At94.job
[2010/05/20 21:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At70.job
[2010/05/20 21:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At46.job
[2010/05/20 21:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At166.job
[2010/05/20 21:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At142.job
[2010/05/20 21:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At118.job
[2010/05/20 20:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At21.job
[2010/05/20 20:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At93.job
[2010/05/20 20:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At69.job
[2010/05/20 20:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At45.job
[2010/05/20 20:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At165.job
[2010/05/20 20:00:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At141.job
[2010/05/20 20:00:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At117.job
[2010/05/20 19:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At20.job
[2010/05/20 09:29:00 | 000,000,472 | —- | M] () –
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/05/20 08:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At81.job
[2010/05/20 08:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At57.job
[2010/05/20 08:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At33.job
[2010/05/20 08:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At153.job
[2010/05/20 08:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At129.job
[2010/05/20 08:00:00 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At105.job
[2010/05/20 07:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At8.job
[2010/05/19 07:19:11 | 000,007,168 | —- | M] () – C:\Documents and
Settings\Owner\Local Settings\Application
Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/18 13:26:59 | 000,039,424 | —- | M] () – C:\Documents and
Settings\Owner\My Documents\forum post.doc
[2010/05/18 07:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At80.job
[2010/05/18 07:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At56.job
[2010/05/18 07:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At32.job
[2010/05/18 07:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At152.job
[2010/05/18 07:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At128.job
[2010/05/18 07:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At104.job
[2010/05/18 06:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At7.job
[2010/05/18 06:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At79.job
[2010/05/18 06:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At55.job
[2010/05/18 06:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At31.job
[2010/05/18 06:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At151.job
[2010/05/18 06:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At127.job
[2010/05/18 06:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At103.job
[2010/05/18 05:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At6.job
[2010/05/18 05:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At78.job
[2010/05/18 05:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At54.job
[2010/05/18 05:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At30.job
[2010/05/18 05:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At150.job
[2010/05/18 05:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At126.job
[2010/05/18 05:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At102.job
[2010/05/18 04:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At5.job
[2010/05/18 04:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At77.job
[2010/05/18 04:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At53.job
[2010/05/18 04:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At29.job
[2010/05/18 04:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At149.job
[2010/05/18 04:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At125.job
[2010/05/18 04:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At101.job
[2010/05/18 03:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At4.job
[2010/05/18 03:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At76.job
[2010/05/18 03:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At52.job
[2010/05/18 03:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At28.job
[2010/05/18 03:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At148.job
[2010/05/18 03:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At124.job
[2010/05/18 03:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\tasks\At100.job
[2010/05/18 02:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At3.job
[2010/05/18 01:12:47 | 000,000,933 | —- | M] () – C:\Documents and
Settings\Owner\Desktop\Spybot - Search & Destroy.lnk
[2010/05/18 00:50:37 | 000,000,803 | —- | M] () – C:\Documents and
Settings\Owner\Desktop\Internet Explorer.lnk
[2010/05/17 13:13:29 | 000,355,086 | —- | M] () –
C:\WINDOWS\System32\PerfStringBackup.INI
[2010/05/17 13:13:29 | 000,311,604 | —- | M] () –
C:\WINDOWS\System32\perfh009.dat
[2010/05/17 13:13:29 | 000,039,992 | —- | M] () –
C:\WINDOWS\System32\perfc009.dat
[2010/05/17 12:37:05 | 000,000,112 | —- | M] () – C:\Documents and
Settings\All Users\Application Data\xm8848Hu.dat
[2010/05/17 12:37:03 | 000,069,122 | —- | M] () – C:\Documents and
Settings\All Users\Application Data\0FGAVxDX.exe
[2010/05/16 17:09:26 | 000,031,822 | —- | M] () – C:\debug
[2010/05/15 10:16:13 | 000,023,040 | —- | M] () – C:\Documents and
Settings\Owner\My Documents\Jehovah Want Submit Action Need Spirit
Come Upon You Depend.doc
[2010/05/14 14:25:08 | 000,050,994 | —- | M] () –
C:\WINDOWS\System32\tpithphlaqely.exe
[2010/05/12 20:01:14 | 000,000,664 | —- | M] () –
C:\WINDOWS\System32\d3d9caps.dat
[2010/05/11 13:08:57 | 000,021,504 | —- | M] () – C:\Documents and
Settings\Owner\My Documents\nilda armstrong wedding cancellation of
event.doc
[2010/05/03 08:17:37 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/05/02 08:58:54 | 000,022,016 | —- | M] () – C:\Documents and
Settings\Owner\My Documents\WATCHTOWER STUDY questions.doc
[2010/05/01 00:34:52 | 000,022,528 | —- | M] () – C:\Documents and
Settings\Owner\My Documents\fcp TO DO list.doc
[2010/04/27 08:58:12 | 000,046,080 | —- | M] () – C:\Documents and
Settings\Owner\My Documents\TMS 4 26 10 review.doc
[2010/04/27 06:36:54 | 000,392,704 | —- | M] () –
C:\WINDOWS\System32\dnhiozxybgjuwe.dll
[2010/04/23 12:54:53 | 000,064,000 | —- | M] () – C:\Documents and
Settings\Owner\My Documents\PROOF ALBUM NUMBER CATALOG.doc
[2010/04/23 11:52:09 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/05/21 19:08:14 | 000,000,162 | -H– | C] () – C:\Documents and
Settings\Owner\Desktop\~$rum help.doc
[2010/05/21 18:54:25 | 000,114,176 | —- | C] () – C:\Documents and
Settings\Owner\Desktop\forum help.doc
[2010/05/18 13:21:12 | 000,002,447 | —- | C] () – C:\Documents and
Settings\Owner\Desktop\HiJackThis.lnk
[2010/05/18 10:08:59 | 000,039,424 | —- | C] () – C:\Documents and
Settings\Owner\My Documents\forum post.doc
[2010/05/18 01:12:47 | 000,000,933 | —- | C] () – C:\Documents and
Settings\Owner\Desktop\Spybot - Search & Destroy.lnk
[2010/05/18 00:50:37 | 000,000,803 | —- | C] () – C:\Documents and
Settings\Owner\Desktop\Internet Explorer.lnk
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At168.job
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At167.job
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At166.job
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At165.job
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At164.job
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At163.job
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At162.job
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At161.job
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At160.job
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At159.job
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At158.job
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At157.job
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At156.job
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At155.job
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At154.job
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At153.job
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At152.job
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At151.job
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At150.job
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At149.job
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At148.job
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At147.job
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At146.job
[2010/05/17 12:37:06 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At145.job
[2010/05/17 09:34:51 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At144.job
[2010/05/17 09:34:51 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At143.job
[2010/05/17 09:34:51 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At142.job
[2010/05/17 09:34:51 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At141.job
[2010/05/17 09:34:51 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At140.job
[2010/05/17 09:34:51 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At139.job
[2010/05/17 09:34:51 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At138.job
[2010/05/17 09:34:51 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At137.job
[2010/05/17 09:34:51 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At136.job
[2010/05/17 09:34:51 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At135.job
[2010/05/17 09:34:51 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At134.job
[2010/05/17 09:34:51 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At133.job
[2010/05/17 09:34:51 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At132.job
[2010/05/17 09:34:51 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At131.job
[2010/05/17 09:34:51 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At130.job
[2010/05/17 09:34:51 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At129.job
[2010/05/17 09:34:51 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At128.job
[2010/05/17 09:34:51 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At127.job
[2010/05/17 09:34:51 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At126.job
[2010/05/17 09:34:51 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At125.job
[2010/05/17 09:34:51 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At124.job
[2010/05/17 09:34:51 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At123.job
[2010/05/17 09:34:50 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At122.job
[2010/05/17 09:34:50 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At121.job
[2010/05/17 07:31:57 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At120.job
[2010/05/17 07:31:57 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At119.job
[2010/05/17 07:31:57 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At118.job
[2010/05/17 07:31:57 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At117.job
[2010/05/17 07:31:57 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At116.job
[2010/05/17 07:31:57 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At115.job
[2010/05/17 07:31:57 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At114.job
[2010/05/17 07:31:57 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At113.job
[2010/05/17 07:31:57 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At112.job
[2010/05/17 07:31:56 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At99.job
[2010/05/17 07:31:56 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At98.job
[2010/05/17 07:31:56 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At97.job
[2010/05/17 07:31:56 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At111.job
[2010/05/17 07:31:56 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At110.job
[2010/05/17 07:31:56 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At109.job
[2010/05/17 07:31:56 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At108.job
[2010/05/17 07:31:56 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At107.job
[2010/05/17 07:31:56 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At106.job
[2010/05/17 07:31:56 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At105.job
[2010/05/17 07:31:56 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At104.job
[2010/05/17 07:31:56 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At103.job
[2010/05/17 07:31:56 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At102.job
[2010/05/17 07:31:56 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At101.job
[2010/05/17 07:31:56 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At100.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At96.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At95.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At94.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At93.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At92.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At91.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At90.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At89.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At88.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At87.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At86.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At85.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At84.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At83.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At82.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At81.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At80.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At79.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At78.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At77.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At76.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At75.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At74.job
[2010/05/16 19:44:16 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At73.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At72.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At71.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At70.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At69.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At68.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At67.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At66.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At65.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At64.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At63.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At62.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At61.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At60.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At59.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At58.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At57.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At56.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At55.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At54.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At53.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At52.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At51.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At50.job
[2010/05/16 17:42:43 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At49.job
[2010/05/16 17:09:26 | 000,031,822 | —- | C] () – C:\debug
[2010/05/16 17:07:49 | 000,000,112 | —- | C] () – C:\Documents and
Settings\All Users\Application Data\xm8848Hu.dat
[2010/05/16 17:07:47 | 000,069,122 | —- | C] () – C:\Documents and
Settings\All Users\Application Data\0FGAVxDX.exe
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At48.job
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At47.job
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At46.job
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At45.job
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At44.job
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At43.job
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At42.job
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At41.job
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At40.job
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At39.job
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At38.job
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At37.job
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At36.job
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At35.job
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At34.job
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At33.job
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At32.job
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At31.job
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At30.job
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At29.job
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At28.job
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At27.job
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At26.job
[2010/05/16 17:07:47 | 000,000,416 | —- | C] () – C:\WINDOWS\tasks\At25.job
[2010/05/16 17:04:20 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At9.job
[2010/05/16 17:04:20 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At8.job
[2010/05/16 17:04:20 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At7.job
[2010/05/16 17:04:20 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At6.job
[2010/05/16 17:04:20 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At5.job
[2010/05/16 17:04:20 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At4.job
[2010/05/16 17:04:20 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At3.job
[2010/05/16 17:04:20 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At24.job
[2010/05/16 17:04:20 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At23.job
[2010/05/16 17:04:20 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At22.job
[2010/05/16 17:04:20 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At21.job
[2010/05/16 17:04:20 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At20.job
[2010/05/16 17:04:20 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At19.job
[2010/05/16 17:04:20 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At18.job
[2010/05/16 17:04:20 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At17.job
[2010/05/16 17:04:20 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At16.job
[2010/05/16 17:04:20 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At15.job
[2010/05/16 17:04:20 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At14.job
[2010/05/16 17:04:20 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At13.job
[2010/05/16 17:04:20 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At12.job
[2010/05/16 17:04:20 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At11.job
[2010/05/16 17:04:20 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At10.job
[2010/05/16 17:04:19 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At2.job
[2010/05/16 17:04:19 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At1.job
[2010/05/15 10:07:42 | 000,023,040 | —- | C] () – C:\Documents and
Settings\Owner\My Documents\Jehovah Want Submit Action Need Spirit
Come Upon You Depend.doc
[2010/05/14 14:25:08 | 000,050,994 | —- | C] () –
C:\WINDOWS\System32\tpithphlaqely.exe
[2010/05/11 13:08:56 | 000,021,504 | —- | C] () – C:\Documents and
Settings\Owner\My Documents\nilda armstrong wedding cancellation of
event.doc
[2010/05/02 08:58:54 | 000,022,016 | —- | C] () – C:\Documents and
Settings\Owner\My Documents\WATCHTOWER STUDY questions.doc
[2010/05/01 00:24:38 | 000,022,528 | —- | C] () – C:\Documents and
Settings\Owner\My Documents\fcp TO DO list.doc
[2010/04/27 09:07:44 | 000,046,080 | —- | C] () – C:\Documents and
Settings\Owner\My Documents\TMS 4 26 10 review.doc
[2010/04/27 06:36:54 | 000,392,704 | —- | C] () –
C:\WINDOWS\System32\dnhiozxybgjuwe.dll
[2010/04/23 12:54:52 | 000,064,000 | —- | C] () – C:\Documents and
Settings\Owner\My Documents\PROOF ALBUM NUMBER CATALOG.doc
[2010/04/23 11:52:09 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/01/14 10:48:48 | 000,000,151 | —- | C] () –
C:\WINDOWS\PhotoSnapViewer.INI
[2009/12/14 10:33:35 | 000,026,000 | —- | C] () –
C:\WINDOWS\System32\PteVideo.dll
[2009/12/02 10:07:54 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () –
C:\WINDOWS\System32\OUTLPERF.INI
[2000/06/28 04:00:00 | 000,124,416 | —- | C] () –
C:\WINDOWS\System32\dXCtrls.dll

========== LOP Check ==========

[2010/02/06 02:05:15 | 000,000,000 | —D | M] – C:\Documents and
Settings\All Users\Application Data\AVG Security Toolbar
[2010/05/17 20:16:37 | 000,000,000 | —D | M] – C:\Documents and
Settings\All Users\Application Data\avg9
[2009/12/14 10:33:36 | 000,000,000 | —D | M] – C:\Documents and
Settings\All Users\Application Data\PicturesToExe
[2009/12/01 15:04:53 | 000,000,000 | —D | M] – C:\Documents and
Settings\Owner\Application Data\Watchtower
[2009/12/01 14:53:23 | 000,000,000 | —D | M] – C:\Documents and
Settings\Owner\Application Data\{2E4547EE-58B4-47D5-ABF1-2CAE76550252}
[2010/05/20 09:29:00 | 000,000,472 | —- | M] () –
C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010/05/21 00:43:07 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2010/05/21 09:40:01 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At10.job
[2010/05/18 03:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At100.job
[2010/05/18 04:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At101.job
[2010/05/18 05:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At102.job
[2010/05/18 06:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At103.job
[2010/05/18 07:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At104.job
[2010/05/20 08:00:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At105.job
[2010/05/21 09:00:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At106.job
[2010/05/21 10:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At107.job
[2010/05/21 11:00:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At108.job
[2010/05/21 12:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At109.job
[2010/05/21 10:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At11.job
[2010/05/21 13:06:10 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At110.job
[2010/05/21 14:00:11 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At111.job
[2010/05/21 15:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At112.job
[2010/05/21 16:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At113.job
[2010/05/21 17:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At114.job
[2010/05/21 18:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At115.job
[2010/05/21 19:00:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At116.job
[2010/05/20 20:00:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At117.job
[2010/05/20 21:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At118.job
[2010/05/20 22:00:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At119.job
[2010/05/21 11:41:01 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At12.job
[2010/05/20 23:00:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At120.job
[2010/05/21 00:30:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At121.job
[2010/05/21 01:00:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At122.job
[2010/05/21 02:00:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At123.job
[2010/05/18 03:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At124.job
[2010/05/18 04:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At125.job
[2010/05/18 05:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At126.job
[2010/05/18 06:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At127.job
[2010/05/18 07:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At128.job
[2010/05/20 08:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At129.job
[2010/05/21 12:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At13.job
[2010/05/21 09:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At130.job
[2010/05/21 10:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At131.job
[2010/05/21 11:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At132.job
[2010/05/21 12:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At133.job
[2010/05/21 13:06:10 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At134.job
[2010/05/21 14:00:13 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At135.job
[2010/05/21 15:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At136.job
[2010/05/21 16:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At137.job
[2010/05/21 17:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At138.job
[2010/05/21 18:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At139.job
[2010/05/21 13:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At14.job
[2010/05/21 19:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At140.job
[2010/05/20 20:00:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At141.job
[2010/05/20 21:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At142.job
[2010/05/20 22:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At143.job
[2010/05/20 23:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At144.job
[2010/05/21 00:17:27 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At145.job
[2010/05/21 01:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At146.job
[2010/05/21 02:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At147.job
[2010/05/18 03:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At148.job
[2010/05/18 04:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At149.job
[2010/05/21 14:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At15.job
[2010/05/18 05:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At150.job
[2010/05/18 06:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At151.job
[2010/05/18 07:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At152.job
[2010/05/20 08:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At153.job
[2010/05/21 09:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At154.job
[2010/05/21 10:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At155.job
[2010/05/21 11:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At156.job
[2010/05/21 12:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At157.job
[2010/05/21 13:06:11 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At158.job
[2010/05/21 14:00:14 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At159.job
[2010/05/21 15:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At16.job
[2010/05/21 15:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At160.job
[2010/05/21 16:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At161.job
[2010/05/21 17:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At162.job
[2010/05/21 18:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At163.job
[2010/05/21 19:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At164.job
[2010/05/20 20:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At165.job
[2010/05/20 21:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At166.job
[2010/05/20 22:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At167.job
[2010/05/20 23:00:10 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At168.job
[2010/05/21 16:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At17.job
[2010/05/21 17:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At18.job
[2010/05/21 18:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At19.job
[2010/05/21 01:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At2.job
[2010/05/20 19:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At20.job
[2010/05/20 20:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At21.job
[2010/05/20 21:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At22.job
[2010/05/20 22:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At23.job
[2010/05/20 23:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At24.job
[2010/05/21 00:46:56 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At25.job
[2010/05/21 01:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At26.job
[2010/05/21 02:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At27.job
[2010/05/18 03:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At28.job
[2010/05/18 04:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At29.job
[2010/05/18 02:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At3.job
[2010/05/18 05:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At30.job
[2010/05/18 06:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At31.job
[2010/05/18 07:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At32.job
[2010/05/20 08:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At33.job
[2010/05/21 09:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At34.job
[2010/05/21 10:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At35.job
[2010/05/21 11:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At36.job
[2010/05/21 12:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At37.job
[2010/05/21 13:06:11 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At38.job
[2010/05/21 14:00:15 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At39.job
[2010/05/18 03:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At4.job
[2010/05/21 15:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At40.job
[2010/05/21 16:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At41.job
[2010/05/21 17:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At42.job
[2010/05/21 18:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At43.job
[2010/05/21 19:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At44.job
[2010/05/20 20:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At45.job
[2010/05/20 21:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At46.job
[2010/05/20 22:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At47.job
[2010/05/20 23:00:12 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At48.job
[2010/05/21 00:43:04 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At49.job
[2010/05/18 04:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At5.job
[2010/05/21 01:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At50.job
[2010/05/21 02:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At51.job
[2010/05/18 03:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At52.job
[2010/05/18 04:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At53.job
[2010/05/18 05:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At54.job
[2010/05/18 06:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At55.job
[2010/05/18 07:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At56.job
[2010/05/20 08:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At57.job
[2010/05/21 09:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At58.job
[2010/05/21 10:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At59.job
[2010/05/18 05:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At6.job
[2010/05/21 11:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At60.job
[2010/05/21 12:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At61.job
[2010/05/21 13:06:12 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At62.job
[2010/05/21 14:00:16 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At63.job
[2010/05/21 15:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At64.job
[2010/05/21 16:00:06 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At65.job
[2010/05/21 17:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At66.job
[2010/05/21 18:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At67.job
[2010/05/21 19:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At68.job
[2010/05/20 20:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At69.job
[2010/05/18 06:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At7.job
[2010/05/20 21:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At70.job
[2010/05/20 22:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At71.job
[2010/05/20 23:00:13 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At72.job
[2010/05/21 00:43:06 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At73.job
[2010/05/21 01:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At74.job
[2010/05/21 02:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At75.job
[2010/05/18 03:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At76.job
[2010/05/18 04:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At77.job
[2010/05/18 05:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At78.job
[2010/05/18 06:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At79.job
[2010/05/20 07:40:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At8.job
[2010/05/18 07:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At80.job
[2010/05/20 08:00:01 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At81.job
[2010/05/21 09:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At82.job
[2010/05/21 10:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At83.job
[2010/05/21 11:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At84.job
[2010/05/21 12:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At85.job
[2010/05/21 13:06:13 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At86.job
[2010/05/21 14:00:17 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At87.job
[2010/05/21 15:00:03 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At88.job
[2010/05/21 16:00:07 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At89.job
[2010/05/21 08:45:18 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\At9.job
[2010/05/21 17:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At90.job
[2010/05/21 18:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At91.job
[2010/05/21 19:00:04 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At92.job
[2010/05/20 20:00:02 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At93.job
[2010/05/20 21:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At94.job
[2010/05/20 22:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At95.job
[2010/05/20 23:00:15 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At96.job
[2010/05/21 00:33:00 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At97.job
[2010/05/21 01:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At98.job
[2010/05/21 02:00:05 | 000,000,416 | —- | M] () – C:\WINDOWS\Tasks\At99.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2009/12/01 11:41:00 | 022,245,337 | —- | M] () .cab file –
C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/12/01 11:41:00 | 022,245,337 | —- | M] () .cab file –
C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation)
MD5=08FD04AA961BDC77FB983F328334E3D7 –
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\agp440.sys
[2004/08/04 01:07:41 | 000,042,368 | —- | M] (Microsoft Corporation)
MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB –
C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2004/08/04 01:07:41 | 000,042,368 | —- | M] (Microsoft Corporation)
MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB –
C:\WINDOWS\system32\drivers\agp440.sys
[2001/08/17 14:58:00 | 000,025,472 | —- | M] (Microsoft Corporation)
MD5=65880045C51AA36184841CEE915A61DF –
C:\WINDOWS\SoftwareDistribution\Download\eb5ff0ae9fdaa24285c4924997a7aa90\backup\agp440.sys

< MD5 for: ATAPI.SYS >
[2003/07/16 15:46:14 | 010,158,890 | —- | M] () .cab file –
C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2009/12/01 11:41:00 | 022,245,337 | —- | M] () .cab file –
C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/12/01 11:41:00 | 022,245,337 | —- | M] () .cab file –
C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2002/08/29 02:27:50 | 000,086,912 | —- | M] (Microsoft Corporation)
MD5=95B858761A00E1D4F81F79A0DA019ACA –
C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2002/08/29 02:27:50 | 000,086,912 | —- | M] (Microsoft Corporation)
MD5=95B858761A00E1D4F81F79A0DA019ACA –
C:\WINDOWS\SoftwareDistribution\Download\eb5ff0ae9fdaa24285c4924997a7aa90\backup\atapi.sys
[2003/07/16 15:24:25 | 000,086,912 | —- | M] (Microsoft Corporation)
MD5=95B858761A00E1D4F81F79A0DA019ACA –
C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation)
MD5=9F3A2F5AA6875C72BF062C712CFA2674 –
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys
[2004/08/04 00:59:42 | 000,095,360 | —- | M] (Microsoft Corporation)
MD5=CDFE4411A69C224BD1D11B2DA92DAC51 –
C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2010/05/21 00:18:40 | 000,095,360 | —- | M] (Microsoft Corporation)
MD5=CDFE4411A69C224BD1D11B2DA92DAC51 –
C:\WINDOWS\system32\dllcache\atapi.sys
[2010/05/21 00:18:40 | 000,095,360 | —- | M] (Microsoft Corporation)
MD5=CDFE4411A69C224BD1D11B2DA92DAC51 –
C:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation)
MD5=6D4FEB43EE538FC5428CC7F0565AA656 –
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\eventlog.dll
[2004/08/04 02:56:42 | 000,055,808 | —- | M] (Microsoft Corporation)
MD5=82B24CB70E5944E6E34662205A2A5B78 –
C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2004/08/04 02:56:42 | 000,055,808 | —- | M] (Microsoft Corporation)
MD5=82B24CB70E5944E6E34662205A2A5B78 –
C:\WINDOWS\system32\eventlog.dll
[2003/07/16 15:28:04 | 000,049,152 | —- | M] (Microsoft Corporation)
MD5=BF3C8CF53C77B48206B39910B6D6CBCC –
C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2003/07/16 15:28:04 | 000,049,152 | —- | M] (Microsoft Corporation)
MD5=BF3C8CF53C77B48206B39910B6D6CBCC –
C:\WINDOWS\SoftwareDistribution\Download\eb5ff0ae9fdaa24285c4924997a7aa90\backup\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation)
MD5=1B7F071C51B77C272875C3A23E1E4550 –
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\netlogon.dll
[2003/07/16 15:38:12 | 000,399,360 | —- | M] (Microsoft Corporation)
MD5=3ADD563ED7A1C66E6F5E0F7A661AA96D –
C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2003/07/16 15:38:12 | 000,399,360 | —- | M] (Microsoft Corporation)
MD5=3ADD563ED7A1C66E6F5E0F7A661AA96D –
C:\WINDOWS\SoftwareDistribution\Download\eb5ff0ae9fdaa24285c4924997a7aa90\backup\netlogon.dll
[2009/02/06 13:46:09 | 000,408,064 | —- | M] (Microsoft Corporation)
MD5=6C476D33D82F1054849790181E8F7772 –
C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 13:46:09 | 000,408,064 | —- | M] (Microsoft Corporation)
MD5=6C476D33D82F1054849790181E8F7772 –
C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004/08/04 02:56:44 | 000,407,040 | —- | M] (Microsoft Corporation)
MD5=96353FCECBA774BB8DA74A1C6507015A –
C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2004/08/04 02:56:44 | 000,407,040 | —- | M] (Microsoft Corporation)
MD5=96353FCECBA774BB8DA74A1C6507015A –
C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 02:56:44 | 000,180,224 | —- | M] (Microsoft Corporation)
MD5=0F78E27F563F2AAF74B91A49E2ABF19A –
C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2004/08/04 02:56:44 | 000,180,224 | —- | M] (Microsoft Corporation)
MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\scecli.dll
[2003/07/16 15:43:57 | 000,174,592 | —- | M] (Microsoft Corporation)
MD5=97418A5C642A5C748A28BD7CF6860B57 –
C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2003/07/16 15:43:57 | 000,174,592 | —- | M] (Microsoft Corporation)
MD5=97418A5C642A5C748A28BD7CF6860B57 –
C:\WINDOWS\SoftwareDistribution\Download\eb5ff0ae9fdaa24285c4924997a7aa90\backup\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation)
MD5=A86BB5E61BF3E39B62AB4C7E7085A084 –
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2009/11/30 16:49:10 | 000,094,208 | —- | M] () –
C:\WINDOWS\system32\config\default.sav
[2009/11/30 16:49:10 | 000,602,112 | —- | M] () –
C:\WINDOWS\system32\config\software.sav
[2009/11/30 16:49:10 | 000,393,216 | —- | M] () –
C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\drivers\*.sys /90 >
[2010/05/21 00:18:40 | 000,095,360 | —- | M] (Microsoft Corporation)
– C:\WINDOWS\system32\drivers\atapi.sys
[2010/03/15 09:43:30 | 000,216,200 | —- | M] (AVG Technologies CZ,
s.r.o.) – C:\WINDOWS\system32\drivers\avgldx86.sys
[2010/03/15 09:45:10 | 000,029,512 | —- | M] (AVG Technologies CZ,
s.r.o.) – C:\WINDOWS\system32\drivers\avgmfx86.sys
[2010/04/21 09:02:19 | 000,242,896 | —- | M] (AVG Technologies CZ,
s.r.o.) – C:\WINDOWS\system32\drivers\avgtdix.sys
< End of report >





********************************************************************************
**************************************************





OTL Extras logfile created on: 5/21/2010 7:17:34 PM - Run 1
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Documents and
Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type =
NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date
Format: M/d/yyyy

1.00 Gb Total Physical Memory | 0.00 Gb Available Physical Memory |
37.00% Memory free
2.00 Gb Paging File | 0.00 Gb Available in Paging File | 21.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% =
C:\Program Files
Drive C: | 465.75 Gb Total Space | 438.13 Gb Free Space | 94.07% Space
Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: WILSON
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla
Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft
Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
(Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe
%SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L
(Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program
Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies
CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program
Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies
CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}" = Adobe ExtendScript Toolkit 2
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4ABB4D92-0682-4887-A0BC-CE5F920DDD23}" = Watchtower Library 2009 - English
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{52504CE6-E909-4113-B232-4AFEC6543A61}" = Broadcom 440x 10/100
Integrated Controller
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}" = Adobe Setup
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}" = Adobe Color Common Settings
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{762FDEB0-9A34-4D90-AA52-4424D0135DE1}" = PROOF AND REPRINT
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005
ATL Update kb973923 - x86 8.0.50727.4053
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005
Redistributable
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard
Edition 2003
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008
Redistributable - x86 9.0.30729.17
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A254D625} PicturesToExe 6.0_is1" = PicturesToExe 6.0
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{ABB2901A-3D0A-4F21-8324-2F13C3EFE163}" = LightScribe [removed]
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}" = Adobe Setup
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BE8A9C2C-8E41-445B-A746-BEB0B1F992F8}" = DJ_AIO_03_F4200_Software_Min
"{C3B6AEB1-390C-4792-8677-CD87F8B2C959}" = HP Deskjet F4200 All-In-One
Driver 11.0 03
"{C89B5E3A-690F-4CEE-909A-BF869E198B0A}" = Scan
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D1BB4446-AE9C-4256-9A7F-4D46604D2462}" = Adobe Setup
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{DE5BFF9C-84D1-4B09-9C20-54633044CB85}" = Watchtower Library 2008 - English
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E96B0085-6659-486b-A221-5042A042728D}" = Toolbox
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime
- (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" =
Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F7B0E599-C114-4493-BC4D-D8FC7CBBABBB}" = 32 Bit HP CIO Components Installer
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_2ac78060bc5856b0c1cf873bb919b58" = Adobe Photoshop CS3
"Adobe_3e054d2218e7aa282c2369d939e58ff" = Adobe ExtendScript Toolkit 2
"Adobe_6c8e2cb4fd241c55406016127a6ab2e" = Adobe Color Common Settings
"AVG9Uninstall" = AVG Free 9.0
"CCleaner" = CCleaner
"ie8" = Windows Internet Explorer 8
"InstallShield_{52504CE6-E909-4113-B232-4AFEC6543A61}" = Broadcom 440x
10/100 Integrated Controller
"Intel® 537EP V9x DF PCI Modem" = Intel® 537EP V9x DF PCI Modem
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.5.9)" = Mozilla Firefox (3.5.9)
"MVApplication1" = SureThing CD Labeler 4 SE
"NeroMultiInstaller!UninstallKey" = Nero Suite
"tpithphlaqely" = Performance Maximizer Profitizeme
"Windows XP Service Pack" = Windows XP Service Pack 2

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Collages.net Upload Manager" = Collages.net Upload Manager

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/21/2010 12:16:30 AM | Computer Name = WILSON | Source =
Application Hang | ID = 1002
Description = Hanging application WINWORD.EXE, version 11.0.8313.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/21/2010 12:21:58 AM | Computer Name = WILSON | Source =
Application Hang | ID = 1002
Description = Hanging application WINWORD.EXE, version 11.0.8313.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/21/2010 10:42:03 AM | Computer Name = WILSON | Source =
Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.1.3726,
hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 5/21/2010 12:18:29 PM | Computer Name = WILSON | Source =
Application Hang | ID = 1002
Description = Hanging application WINWORD.EXE, version 11.0.8313.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/21/2010 1:07:52 PM | Computer Name = WILSON | Source =
Application Hang | ID = 1002
Description = Hanging application WINWORD.EXE, version 11.0.8313.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/21/2010 1:07:55 PM | Computer Name = WILSON | Source =
Application Hang | ID = 1002
Description = Hanging application WINWORD.EXE, version 11.0.8313.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/21/2010 1:32:20 PM | Computer Name = WILSON | Source =
Application Hang | ID = 1002
Description = Hanging application WINWORD.EXE, version 11.0.8313.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/21/2010 1:34:48 PM | Computer Name = WILSON | Source =
Application Hang | ID = 1002
Description = Hanging application WINWORD.EXE, version 11.0.8313.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/21/2010 8:12:01 PM | Computer Name = WILSON | Source =
Application Hang | ID = 1002
Description = Hanging application WINWORD.EXE, version 11.0.8313.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/21/2010 8:13:19 PM | Computer Name = WILSON | Source =
Application Hang | ID = 1002
Description = Hanging application WINWORD.EXE, version 11.0.8313.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 5/21/2010 7:00:04 PM | Computer Name = WILSON | Source =
Schedule | ID = 7901
Description = The At67.job command failed to start due to the
following error: %%2147942405

Error - 5/21/2010 7:00:05 PM | Computer Name = WILSON | Source =
Schedule | ID = 7901
Description = The At91.job command failed to start due to the
following error: %%2147942405

Error - 5/21/2010 7:40:00 PM | Computer Name = WILSON | Source =
Schedule | ID = 7901
Description = The At19.job command failed to start due to the
following error: %%2147942402

Error - 5/21/2010 7:48:49 PM | Computer Name = WILSON | Source =
MRxSmb | ID = 8003
Description = The master browser has received a server announcement
from the computer
DESI-PC that believes that it is the master browser for the domain
on transport
NetBT_Tcpip_{F381BFB9-1D6D-48E7-8. The master browser is stopping or
an election
is being forced.

Error - 5/21/2010 8:00:00 PM | Computer Name = WILSON | Source =
Schedule | ID = 7901
Description = The At116.job command failed to start due to the following error:
%%2147942405

Error - 5/21/2010 8:00:01 PM | Computer Name = WILSON | Source =
Schedule | ID = 7901
Description = The At140.job command failed to start due to the following error:
%%2147942405

Error - 5/21/2010 8:00:02 PM | Computer Name = WILSON | Source =
Schedule | ID = 7901
Description = The At164.job command failed to start due to the following error:
%%2147942405

Error - 5/21/2010 8:00:03 PM | Computer Name = WILSON | Source =
Schedule | ID = 7901
Description = The At44.job command failed to start due to the
following error: %%2147942405

Error - 5/21/2010 8:00:04 PM | Computer Name = WILSON | Source =
Schedule | ID = 7901
Description = The At68.job command failed to start due to the
following error: %%2147942405

Error - 5/21/2010 8:00:04 PM | Computer Name = WILSON | Source =
Schedule | ID = 7901
Description = The At92.job command failed to start due to the
following error: %%2147942405


< End of report >
Hello Desiree

Thank you for the logs.

each time I ran GMER it would get stuck

The malware on your system is preventing the tool from running normally.

Lets try this:

  • GMER


  • If you are having trouble getting GMER to complete a scan, please run it again, but this time uncheck everything EXCEPT "Sections" and "C:\".
  • If GMER does not produce a log please try running it from Safe Mode.

  • How to use the F8 method to Start Your Computer in Safe Mode

  • Restart your computer.
  • As soon as BIOS is loaded begin tapping the F8 key until the "Advanced Options" menu appears.
  • Use the arrow keys to select the Safe mode menu item.
  • Press Enter.

If GMER produces a log, please post it in your next reply. If not, come back and let me know.

If you are having trouble getting GMER to complete a scan, please run it again, but this time uncheck everything EXCEPT "Sections" and "C:\".


I tried this… didn't work. Still stalled out at C:\WINDOWS\system32\drivers\atapi.sys


If GMER does not produce a log please try running it from Safe Mode.



I tried this as well… same outcome as above. Stalls out at same spot too.
Hello Desiree

Stalls out at same spot


Thank you for letting me know. Please work your way through the folowing steps. If you encounter any difficulties come back and let me know.

  • Download Combofix and RE-NAME it BEFORE saving


  • Download Combofix from either of the links below. You must rename it to desiree.exe before saving it.
  • Save it to your desktop. Change the "save as file type" to "all files".
  • Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop.


  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


Link 1
Link 2



  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.


  • NOTE: If ComboFix asks to install the Recovery Console, please ALLOW it to do so.


  • Double click on the renamed ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.
Here is the ComboFix log:


ComboFix 10-05-28.02 - Owner 05/28/2010 23:14:10.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1278.858 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\desiree.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\0FGAVxDX.exe
c:\windows\system32\dnhiozxybgjuwe.dll
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\lowsec\user.ds.lll
c:\windows\system32\sdra64.exe
c:\windows\system32\tpithphlaqely.exe
c:\windows\Tasks\At1.job
c:\windows\Tasks\At104.job
c:\windows\Tasks\At108.job
c:\windows\Tasks\At110.job
c:\windows\Tasks\At111.job

Infected copy of c:\windows\system32\drivers\atapi.sys was found and disinfected
Restored copy from - Kitty had a snack :P
.
((((((((((((((((((((((((( Files Created from 2010-04-28 to 2010-05-29 )))))))))))))))))))))))))))))))
.

2010-05-18 18:21 . 2010-05-18 18:21 388096 —-a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-05-18 18:21 . 2010-05-18 18:21 ——– d—–w- c:\program files\Trend Micro
1601-01-01 00:00 . 1601-01-01 00:00 ——– d—–w- c:\windows\LastGood.Tmp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-29 03:35 . 2010-05-18 06:12 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-05-29 00:05 . 2010-01-28 15:56 0 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\prvlcl.dat
2010-05-28 02:02 . 2009-12-01 05:09 95360 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-05-18 14:12 . 2010-05-18 05:01 ——– d—–w- c:\program files\Google
2010-05-18 06:16 . 2010-05-18 06:12 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-05-18 05:58 . 2010-02-01 15:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-05-18 01:16 . 2010-01-28 15:19 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-05-17 17:37 . 2010-05-16 22:07 112 —-a-w- c:\documents and settings\All Users\Application Data\xm8848Hu.dat
2010-05-13 01:01 . 2010-01-24 21:43 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-05-12 13:13 . 2010-04-20 17:38 0 —-a-w- c:\windows\system32\tmp.tmp
2010-04-21 14:02 . 2010-01-28 15:20 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-03-24 18:17 . 2010-03-24 08:04 952768 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.2\ARM\17553\AdobeARM.exe
2010-03-24 18:17 . 2010-03-24 08:04 70584 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.2\ARM\17553\AdobeExtractFiles.dll
2010-03-24 18:17 . 2010-03-24 08:04 326056 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.2\ARM\17553\ReaderUpdater.exe
2010-03-24 18:17 . 2010-03-24 08:04 326056 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.2\ARM\17553\AcrobatUpdater.exe
2010-03-15 14:45 . 2010-03-15 14:45 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-03-15 14:45 . 2010-01-28 15:19 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-03-15 14:43 . 2010-01-28 15:19 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-01 05:42 . 2009-12-01 05:42 800544 —-a-w- c:\program files\JavaSetup6u17-rv.exe
2009-12-01 05:17 . 2009-12-01 05:17 8084968 —-a-w- c:\program files\Firefox Setup 3.5.5.exe
.
c:\program files\Adobe\Reader 9.0\Reader\Reader_sl .exe
c:\program files\Ahead\ODD Toolkit\DVDTray .exe
c:\program files\AVG\AVG9\avgtray .exe
c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM .exe

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 15:25 2117704 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2005-10-19 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2005-10-19 126976]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [N/A]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10c.exe" [2009-07-18 257440]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-15 14:45 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, mbykipnf.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [1/28/2010 10:19 AM 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [1/28/2010 10:20 AM 242896]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [3/15/2010 9:45 AM 308064]
S2 uqpffvgkyudxfe;uqpffvgkyudxfe;\??\c:\windows\system32\drivers\stsprapag.sys –> c:\windows\system32\drivers\stsprapag.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: microsoft.com\*.update
Trusted Zone: windowsupdate.com\download
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\209kmn1w.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type;=yahoo_avg_hs2-tb-web_us&p;=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
- - - - ORPHANS REMOVED - - - -

AddRemove-tpithphlaqely - c:\windows\system32\tpithphlaqely.exe
AddRemove-Collages.net Upload Manager - c:\windows\system32\javaws.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-28 23:30
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b2,0e,73,84,f8,55,01,40,bd,79,5c,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b2,0e,73,84,f8,55,01,40,bd,79,5c,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(2664)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-05-28 23:35:38 - machine was rebooted
ComboFix-quarantined-files.txt 2010-05-29 04:35

Pre-Run: 471,328,923,648 bytes free
Post-Run: 478,662,336,512 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

- - End Of File - - 8272716EC4E07903FA55A12706C0367F
Hello Desiree

We are making progress. Before we continue, I would like to take a closer look at a couple of files on your system. Please do the following:

  • Please make all files and folders VISIBLE:


    • Click "Start" Go to My Computer-> Tools-> Folder Options-> View tab:
    • Choose to "Show hidden files and folders."
    • Uncheck the "Hide protected operating system files" and the "Hide extensions for know file types" boxes.
    • Close the window with "OK".

  • Please scan the following files


    • Please visit Virus Total by clicking here.
    • Click the Browse button and search for the following file (if present): c:\documents and settings\All Users\Application Data\xm8848Hu.dat
    • Click Open.
    • Then click Send File.
    • Please be patient while the file is scanned.
    • If Virus Total tells you that the file has already been scanned, click "reanalyse now".

    • Once the scan results appear, copy and paste them into Notepad and repeat the procedure for the following file(s):

    c:\windows\system32\tmp.tmp

    • Please provide the results from the scans in your next reply.
Here are the results from the Virus Total scans on the two files you needed:

xm8848Hu.dat

File xm8848Hu.dat received on 2010.06.01 04:50:46 (UTC)
Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED
Result: 0/40 (0%)

Antivirus Version Last Update Result
a-squared 5.0.0.26 2010.06.01 -
AhnLab-V3 2010.06.01.00 2010.05.31 -
AntiVir 8.2.1.242 2010.05.31 -
Antiy-AVL 2.0.3.7 2010.05.31 -
Authentium 5.2.0.5 2010.06.01 -
Avast 4.8.1351.0 2010.06.01 -
Avast5 5.0.332.0 2010.06.01 -
AVG 9.0.0.787 2010.05.31 -
BitDefender 7.2 2010.06.01 -
CAT-QuickHeal 10.00 2010.05.31 -
ClamAV 0.96.0.3-git 2010.06.01 -
Comodo 4971 2010.06.01 -
DrWeb 5.0.2.03300 2010.06.01 -
eSafe 7.0.17.0 2010.05.30 -
eTrust-Vet 35.2.7522 2010.05.31 -
F-Prot 4.6.0.103 2010.05.31 -
F-Secure 9.0.15370.0 2010.06.01 -
Fortinet 4.1.133.0 2010.05.30 -
GData 21 2010.06.01 -
Ikarus T3.1.1.84.0 2010.06.01 -
Jiangmin 13.0.900 2010.05.31 -
Kaspersky 7.0.0.125 2010.06.01 -
McAfee 5.400.0.1158 2010.06.01 -
McAfee-GW-Edition 2010.1 2010.05.31 -
Microsoft 1.5802 2010.05.31 -
NOD32 5160 2010.06.01 -
Norman 6.04.12 2010.05.31 -
nProtect 2010-05-31.01 2010.05.31 -
Panda 10.0.2.7 2010.05.31 -
PCTools 7.0.3.5 2010.06.01 -
Rising 22.50.01.01 2010.06.01 -
Sophos 4.53.0 2010.06.01 -
Sunbelt 6383 2010.06.01 -
Symantec 20101.1.0.89 2010.06.01 -
TheHacker 6.5.2.0.290 2010.05.31 -
TrendMicro 9.120.0.1004 2010.06.01 -
TrendMicro-HouseCall 9.120.0.1004 2010.06.01 -
VBA32 3.12.12.5 2010.05.31 -
ViRobot 2010.6.1.2332 2010.06.01 -
VirusBuster 5.0.27.0 2010.05.31 -
Additional information
File size: 112 bytes
MD5…: 39429cb13af78d5cd808f026eed7c2ed
SHA1..: 36a39c7e40bdddfe56f41a00133b146c033d73f9
SHA256: 70f98b7d53bcfd11edaf8287bf8975efe73bf6d7303452282a05f2cac704260e
ssdeep: 3:h+zJpaci4JqD8E4nFgPSM367W4Df+G4dYjJuVn:hMJpxRJqgVq3679Df+G4wgV
PEiD..: -
PEInfo: -
RDS…: NSRL Reference Data Set
-
pdfid.: -
trid..: HP Printer Control Language capture/bitmap (100.0%)
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned






When I entered the file "c:\windows\system32\tmp.tmp"
(I tried it twice) both times I received the following results…


0 bytes size received / Se ha recibido un archivo vacio
One more thing, I don't know if I need to handle this on this thread or not, but also, my programs are running very very slowly now too. It was a little slow right when my internet problems began, but now, since I had added all the malware programs (this was before I joined whatthetech), and just in general over the past few weeks, programs have a 60-90 second (most of the time, it's way longer) delay in doing simple tasks, like in Word and such. Not sure if the techniques in this thread you are helping me with will eventually correct this problem too, or if I need to have another thread for that. Any advice would be great! Just let me know. Thanks!!!
Hello Desiree

Thank you for the scan logs.

my programs are running very very slowly now too

This is most likely due to the malware that is still present on your system. You have a number of infections on your machine. Once we have dealt with them all, your system performance should improve.

We need to run ComboFix again, but this time, we will be running it in a slightly different way. If you encounter any problems, just come back here and let me know.


  • Please work through the following steps


    • Open Notepad (Click on "Start", then on "Run" and type "notepad" (without quotations) in the Open field, then click on "OK").
    • NOTE: Do not Use Wordpad or any other text editor except Notepad or the script will fail.
    • Copy and Paste the text in the codebox below (including the link) into the open Notepad window:

      http://forums.whatthetech.com/Web_Browser_Constantly_Re_directs_I_have_included_my_Hijackthis_log_t112155.html
      
      collect::
      c:\windows\LastGood.Tmp
      c:\windows\system32\drivers\stsprapag.sys
      
      File::
      c:\windows\system32\tmp.tmp
      
      Driver::
      uqpffvgkyudxfe
      
      RenV::
      c:\program files\Adobe\Reader 9.0\Reader\Reader_sl .exe
      c:\program files\Ahead\ODD Toolkit\DVDTray .exe
      c:\program files\AVG\AVG9\avgtray .exe
      c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM .exe
      
      Registry::
      [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
      "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
    • Save this as "CFScript.txt" (including the quotation marks), change the "Save as type" to "All Files" and save it to your desktop.
    • Close any open browsers.
    • Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Refering to the picture below, drag CFScript.txt into ComboFix.exe

      [external image: Posted Image]
    • When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
    • Once the log is produced, re-engage your resident anti virus.
    • Note: When ComboFix finishes running, the ComboFix log will open along with a message box - do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
    • Ensure you are connected to the internet and click OK on the message box.

  • Please download GooredFix by JPShortstuff


    • Please download GooredFix from one of the locations below and save it to your Desktop.

    Download Mirror #1
    Download Mirror #2

    • Ensure all Firefox windows are closed.
    • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
    • When prompted to run the scan, click Yes.
    • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).

  • TDSS Killer


    • Download TDSSKiller and save it to your Desktop.
    • Extract the file and run it.
    • Once completed it will create a log in your C:\ drive called TDSSKiller_* (* denotes version & date)
    • Please post the contents of the TDSSKiller log.

    In your next reply, please provide the ComboFix log, the GooredFix log and the TDSSKiller log.
Hey JonTom, I am still with ya. I haven't had a chance to get those logs yet, but I plan to do so either tonight or Sunday evening. Hope this is okay. I will respond back here with the logs asap when I do. Thanks!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI