This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Web Browser Constantly Re-directs - I have included my Hijackthis log

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This thread has been re-opened at the request of the User.


Hello Desiree

If you are having trouble with Kaspersky, lets try this:


  • Please run the following scan


  • Scan your system with Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use.
  • Click the "Start" button.
  • Now click the "Install" button.
  • Click "Start". The scanner engine will initialise and update.
  • Do Not place a check mark in the box beside "Remove found threats".
  • Click the "Scan" button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
I have run the ESET online scanner. Here is the log: ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=dd58fd8ea160e94da9e6ad62027099ff # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-06-23 07:50:57 # local_time=2010-06-23 02:50:57 (-0600, Central Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=512 16777215 100 0 2192216 2192216 0 0 # compatibility_mode=1024 16777191 100 0 11710706 11710706 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=66481 # found=1 # cleaned=0 # scan_time=1973 C:\Program Files\Trend Micro\HiJackThis\backups\backup-20100521-190149-267.dll a variant of Win32/Adware.GooochiBiz.AG application 00000000000000000000000000000000 I
Hello Desiree

Thank you for the ESET scan log.

Please do the following:


  • Please open OTL


  • Copy and paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    
    :Files
    C:\Program Files\Trend Micro\HiJackThis\backups\backup-20100521-190149-267.dll
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [start explorer]
    [Reboot]

  • Once you have pasted the information into the Custom Scans/Fixes box, click the "Run Fix" button at the top.
  • Allow the program to run unhindered.
  • Your machine will re-start itself. This is normal.
  • A log will be created after your machine reboots. Please post the contents of the log in your next reply.

Please provide the OTL log in your next reply, along with a new OTL scan of your machine.
Here is the log after I did “Run Fix”…



All processes killed
========== OTL ==========
No active process named explorer.exe was found!
========== FILES ==========
C:\Program Files\Trend Micro\HiJackThis\backups\backup-20100521-190149-267.dll moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 14 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 319 bytes
->Flash cache emptied: 0 bytes

User: Owner
->Temp folder emptied: 47537150 bytes
->Temporary Internet Files folder emptied: 9771049 bytes
->Java cache emptied: 1953901 bytes
->FireFox cache emptied: 90099835 bytes
->Google Chrome cache emptied: 819568 bytes
->Flash cache emptied: 10129 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1126364 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 70 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 450974 bytes

Total Files Cleaned = 145.00 mb


[EMPTYFLASH]

User: Administrator

User: All Users

User: Default User

User: LocalService
->Flash cache emptied: 0 bytes

User: NetworkService
->Flash cache emptied: 0 bytes

User: Owner
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.5.0 log created on 06252010_115910

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…



- - - - - - - - - - -



Here is the log after the new OTL scan…



OTL logfile created on: 6/25/2010 12:02:53 PM - Run 2
OTL by OldTimer - Version 3.2.5.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 64.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 437.90 Gb Free Space | 94.02% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: WILSON
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/06/02 08:04:16 | 000,620,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/06/02 08:04:16 | 000,515,424 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/06/02 08:03:03 | 000,722,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/06/02 08:03:02 | 001,101,152 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/05/21 19:04:56 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
PRC - [2010/03/15 09:45:04 | 000,308,064 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2007/06/13 05:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe


========== Modules (SafeList) ==========

MOD - [2010/05/21 19:04:56 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
MOD - [2004/08/04 02:57:00 | 001,050,624 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
MOD - [2004/08/04 01:01:17 | 000,102,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - [2010/03/15 09:45:04 | 000,308,064 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2009/12/02 09:39:54 | 000,654,848 | —- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)


========== Driver Services (SafeList) ==========

DRV - [2010/06/02 08:04:16 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX)
DRV - [2010/06/02 08:04:16 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86)
DRV - [2010/03/15 09:43:30 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86)
DRV - [2004/03/05 23:15:34 | 000,647,929 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\IntelC52.sys – (IntelC52)
DRV - [2004/03/05 23:14:42 | 001,233,525 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\IntelC51.sys – (IntelC51)
DRV - [2004/03/05 23:13:52 | 000,060,949 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\IntelC53.sys – (IntelC53)
DRV - [2004/03/05 23:13:38 | 000,037,048 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\mohfilt.sys – (mohfilt)
DRV - [2003/06/30 19:11:52 | 000,043,136 | R— | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\bcm4sbxp.sys – (bcm4sbxp)
DRV - [2001/08/22 09:42:58 | 000,013,632 | —- | M] (Dell Computer Corporation) [Kernel | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS – (OMCI)
DRV - [2001/08/17 14:57:38 | 000,016,128 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\MODEMCSA.sys – (MODEMCSA)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.selectedEngine: "Yahoo! Search"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.825
FF - prefs.js..extensions.enabledItems: avg@igeared:4.504.019.002
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..keyword.URL: "http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p="

FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/06/03 06:33:27 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/05/22 13:17:15 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/06/23 18:54:44 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/23 18:44:58 | 000,000,000 | —D | M]

[2009/12/01 00:18:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2010/06/07 11:33:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\209kmn1w.default\extensions
[2010/06/24 20:48:10 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/06/07 11:25:32 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/06/07 11:25:17 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/06/04 23:10:37 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([*.update] https in Trusted sites)
O15 - HKCU\..Trusted Domains: windowsupdate.com ([download] http in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1259681558109 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/11/30 23:22:00 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/06/11 00:38:19 | 000,000,000 | RHSD | M] - C:\autorun.inf – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/06/25 11:59:10 | 000,000,000 | —D | C] – C:\_OTL
[2010/06/23 14:14:52 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/06/13 23:48:16 | 000,000,000 | —D | C] – C:\ac5b03302de015e82584284e8d
[2010/06/12 20:04:39 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Owner\UserData
[2010/06/11 00:38:19 | 000,000,000 | RHSD | C] – C:\autorun.inf
[2010/06/09 19:52:17 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2010/06/09 13:48:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Yahoo!
[2010/06/09 13:40:17 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusb.dll
[2010/06/09 13:40:15 | 000,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusd.dll
[2010/06/09 13:38:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\REO
[2010/06/07 11:26:07 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/06/07 11:25:30 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/06/07 11:25:30 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/06/07 11:25:30 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/06/07 11:25:30 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/06/07 11:25:30 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/06/07 11:25:13 | 000,000,000 | —D | C] – C:\Program Files\Java
[2010/06/07 10:22:56 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/06/07 10:22:55 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/06/07 10:22:55 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/06/04 23:34:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\misc programs
[2010/06/04 23:34:17 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/06/04 23:14:56 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/05/28 23:32:53 | 003,555,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\moviemk.exe
[2010/05/28 23:08:47 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/05/28 23:02:58 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT

========== Files - Modified Within 30 Days ==========

[2010/06/25 12:02:43 | 000,025,088 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Here is the log after I did.doc
[2010/06/25 12:01:42 | 000,002,497 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Microsoft Office Word 2003.lnk
[2010/06/25 12:00:44 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/25 12:00:39 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/06/25 11:59:55 | 004,718,592 | -H– | M] () – C:\Documents and Settings\Owner\NTUSER.DAT
[2010/06/25 11:59:55 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Owner\ntuser.ini
[2010/06/25 09:44:52 | 061,399,985 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/06/24 16:05:29 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\prvlcl.dat
[2010/06/23 14:14:33 | 002,672,312 | —- | M] () – C:\Documents and Settings\Owner\Desktop\esetsmartinstaller_enu.exe
[2010/06/22 07:52:09 | 000,008,192 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/22 07:26:15 | 000,058,700 | —- | M] () – C:\Documents and Settings\Owner\Desktop\FCP Newborn Session 2010.tif
[2010/06/22 07:26:01 | 000,040,828 | —- | M] () – C:\Documents and Settings\Owner\Desktop\FCP Maternity Session 2010.tif
[2010/06/20 08:53:09 | 000,023,552 | —- | M] () – C:\Documents and Settings\Owner\My Documents\wt.doc
[2010/06/15 13:41:44 | 000,024,064 | —- | M] () – C:\Documents and Settings\Owner\My Documents\REO CONTACT INFO.doc
[2010/06/14 23:50:17 | 000,021,504 | —- | M] () – C:\Documents and Settings\Owner\My Documents\REO detail cleaning of home.doc
[2010/06/14 08:39:58 | 000,023,040 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Progressive REO Checklist.doc
[2010/06/14 07:29:25 | 001,411,512 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/13 23:57:02 | 000,000,599 | —- | M] () – C:\WINDOWS\win.ini
[2010/06/13 23:54:36 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/06/11 00:37:20 | 000,132,597 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Flash_Disinfector.exe
[2010/06/10 11:50:21 | 000,020,992 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Hey Kendra and Family.doc
[2010/06/09 16:27:35 | 000,020,992 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Supplies Needed.doc
[2010/06/07 11:25:16 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/06/07 11:25:16 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/06/07 11:25:16 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/06/07 11:25:16 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/06/07 11:25:16 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/06/07 10:22:59 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\MBAM.lnk
[2010/06/06 16:39:51 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/06/04 23:10:51 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/06/04 23:10:37 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/06/04 00:26:36 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/06/02 11:24:08 | 000,019,968 | —- | M] () – C:\Documents and Settings\Owner\My Documents\BILL OF SALE.doc
[2010/06/02 08:04:16 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/06/02 08:04:16 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/05/31 22:33:12 | 000,019,808 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/05/31 14:38:18 | 000,023,552 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Newborn Photography Prices.doc
[2010/05/30 07:39:37 | 000,027,648 | —- | M] () – C:\Documents and Settings\Owner\My Documents\WATCHTOWER STUDY questions may 30.doc
[2010/05/28 23:08:54 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/05/27 21:02:36 | 000,095,360 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\atapi.sys
[2010/05/27 11:23:48 | 000,024,064 | —- | M] () – C:\Documents and Settings\Owner\Desktop\fan invite.doc
[2010/05/27 11:23:48 | 000,000,162 | -H– | M] () – C:\Documents and Settings\Owner\Desktop\~$n invite.doc

========== Files Created - No Company Name ==========

[2010/06/25 12:02:43 | 000,025,088 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Here is the log after I did.doc
[2010/06/23 14:14:27 | 002,672,312 | —- | C] () – C:\Documents and Settings\Owner\Desktop\esetsmartinstaller_enu.exe
[2010/06/22 07:26:14 | 000,058,700 | —- | C] () – C:\Documents and Settings\Owner\Desktop\FCP Newborn Session 2010.tif
[2010/06/20 08:52:56 | 000,023,552 | —- | C] () – C:\Documents and Settings\Owner\My Documents\wt.doc
[2010/06/15 13:41:44 | 000,024,064 | —- | C] () – C:\Documents and Settings\Owner\My Documents\REO CONTACT INFO.doc
[2010/06/14 23:45:56 | 000,021,504 | —- | C] () – C:\Documents and Settings\Owner\My Documents\REO detail cleaning of home.doc
[2010/06/14 08:21:30 | 000,023,040 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Progressive REO Checklist.doc
[2010/06/11 00:37:20 | 000,132,597 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Flash_Disinfector.exe
[2010/06/10 11:50:21 | 000,020,992 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Hey Kendra and Family.doc
[2010/06/07 10:22:59 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\MBAM.lnk
[2010/06/04 14:47:48 | 000,020,992 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Supplies Needed.doc
[2010/06/02 11:22:58 | 000,019,968 | —- | C] () – C:\Documents and Settings\Owner\My Documents\BILL OF SALE.doc
[2010/05/31 14:38:18 | 000,023,552 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Newborn Photography Prices.doc
[2010/05/30 20:03:09 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2010/05/30 07:24:20 | 000,027,648 | —- | C] () – C:\Documents and Settings\Owner\My Documents\WATCHTOWER STUDY questions may 30.doc
[2010/05/28 23:08:53 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/05/28 23:08:49 | 000,260,272 | —- | C] () – C:\cmldr
[2010/05/27 12:07:36 | 000,368,561 | —- | C] () – C:\Documents and Settings\Owner\Desktop\FCP Senior Info 2011.pdf
[2010/05/27 11:23:48 | 000,000,162 | -H– | C] () – C:\Documents and Settings\Owner\Desktop\~$n invite.doc
[2010/05/27 11:23:47 | 000,024,064 | —- | C] () – C:\Documents and Settings\Owner\Desktop\fan invite.doc
[2010/04/23 11:52:09 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/01/14 10:48:48 | 000,000,151 | —- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2009/12/14 10:33:35 | 000,026,000 | —- | C] () – C:\WINDOWS\System32\PteVideo.dll
[2009/12/02 10:07:54 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2000/06/28 04:00:00 | 000,124,416 | —- | C] () – C:\WINDOWS\System32\dXCtrls.dll
< End of report >
Hello Desiree

Your logs appear to be clean!

Please work your way through the following cleanup and update procedures:


  • Please perform the following cleanup procedure


    • Double click on the OTL.exe icon on your desktop to run the program. (Note: If you are running Vista, right-click on the file and choose Run As Administrator).
    • Once OTL has opened, click on the "CleanUp!" button.
    • Follow any prompts that you receive.

  • Removal of Tools


    • You no longer need GooredFix or TDSSKiller. Please delete them from your machine.

  • Please create a new System Restore point


    • Click on "Start" > "All Programs" > "Accessories" > "System tools" > "System Restore".
    • In the dialogue box that appears select "Create a Restore Point".
    • Click "Next".
    • Enter a name
    • e.g. Clean.
    • Click "Create".

  • Please purge the old System Restore points from your system


    • Malware can sometimes hide in the old System Restore points saved on your computer.
    • Follow the steps below to flush the old Restore Points from your system.
    • Click on "Start" > "All Programs" > "Accessories" > "System tools" > "Disk Cleanup".
    • In the drop down box that appears, select your main drive e.g. "C".
    • Click on "OK".
    • Your system will perform a quick calculation and then display a dialogue box containing various tabs.
    • Select the "More Options" tab.
    • At the bottom of this tab, there will be a system restore box with a "Cleanup" button.
    • click on the "Cleanup" button, accept the warning and select "OK".

  • Your Adobe is out of date


    • You can obtain the latest version of Adobe Reader from here, and the latest version of Flash Player from here.
    • For more information and links to Adobe updates and downloads click here.

  • Please install XP Service Pack 3


    • XP Service Pack 3 contains many more security features that are not present in Service Pack 2.
    • Instructions for downloading XP Service Pack 3 can be found here.


    Once you have completed the above steps you should be good to go! If you have any further questions, please feel free to ask.

  • Finally, please take the time to read through the information provided below:

    Enhance your System Security

    • For an excellent list of free anti virus software, free online virus scanners, free spyware detection/removal and free firewalls, click here.

    • IMPORTANT! Please make sure you only have ONE firewall and ONE real-time antivirus installed on your system. When using "on demand" scanners, first update the detection signature files, then disconnect from the internet and disable your resident security program before running the scan.
    • Once complete, remember to re-engage your resident security before going online.

    Web Browsers and Browser Security

    Firefox
    • Firefox is generally considered to have greater browsing security in comparison to other popular programs. You can download Firefox 3.0 from here.

    No-Script
    • If you use Firefox as your default browser, No-Script can provide additional security by preventing malicious scripts from being executed on your system.
    • You can download No-Script by clicking here.

    Internet Explorer
    • The newest version of Internet Explorer is available from here.

    SpywareBlaster
    • If you use Internet Explorer as your default browser, SpywareBlaster would be a valuable addition to your online security.
    • SpywareBlaster prevents malicious ActiveX objects from being downloaded onto your system.
    • You can download SpywareBlaster by clicking here.

    Web of Trust
    • When using search engines, Web of Trust provides you with an easy way of telling the good sites from the bad and is compatible with both Firefox and Internet Explorer.
    • Coloured symbols are displayed next to search results, giving you more confidence in the links you choose to click on: Green (To go), Yellow (Caution) and Red (Stop).
    • You can download Web of Trust by clicking here.

    Keep your Software Updated
    • Outdated software can sometimes have vulnerabilities that are exploitable by malware.
    • Check if there are available updates for your installed software with Secunia's Online Software Inspector by clicking here.

    Passwords
    • Learn how to create strong passwords by clicking here and test the strength of the passwords you already use by clicking here.

    General Reading

    Learn How To Combat Malware
    • Would you like to learn how to fight back against malware and help others? Enroll at the What The Tech (Formerly Tom Coyotes) Malware Classroom by clicking here.
Thanks JonTom!! I will be taking care of getting those updates and downloads on my computer to get it up to date and keep it protected. Also, I will post as well my other computer's MBAM log soon. Earlier, you said that if that computer had any problems, we'll deal with them once this computer is clean. I'll report that log back here once I run that program over on the other machine. Thanks again!!
Due to inactivity, this topic has been closed. If you are the topic starter and need this topic reopened, please PM a staff member (include the address of this thread in your request). Everyone else please start a new topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI