This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Solved] Help with hidden spyware/malware

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Greetings,

I have a reoccuring problem with a popup/tab and believe it to be spy/malware related. I have searched using Spybot SD, MBAM, AVAST free, and Hijackthis and can't find. I've tried scanning from a safeboot, and scanning on startup and can't find it. I'll post a Hijackthis.log.

This is a VISTA PC, the symptoms is a random popup/tab to a web001.com site with a 404 not found error. Thanks!

jlkoppen

–

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:38:39 PM, on 5/31/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18904)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\Home\AppData\Local\Temp\SoftwareProtection.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\system32\rundll32.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: wit for ie - {75ED56AF-4DC9-4243-A30C-4EF4DD0CA28F} - C:\Program Files\ChameleonTom\wit4ie.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: TBSB05974 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Search Toolbar\tbcore3.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll
O3 - Toolbar: Search Toolbar - {0C8413C1-FAD1-446C-8584-BE50576F863E} - C:\Program Files\Search Toolbar\tbcore3.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ABC] C:\Users\Home\AppData\Local\Temp\SoftwareProtection.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident/4.0; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; yie8)" -"http://www.nickjr.com/playtime/cats/games/all_games/blue_doyousee.jhtml"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3375747449-1210083304-1964767510-1001\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User '?')
O4 - HKUS\S-1-5-21-3375747449-1210083304-1964767510-1002\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup (User 'llkool')
O4 - HKUS\S-1-5-21-3375747449-1210083304-1964767510-1002.bk\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User '?')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - http://support.dell.com/systemprofiler/SysProExe.CAB
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {DB7BF79A-FC51-4B5A-92BC-A65731174380} (InstantAction Game Launcher) - http://www.instantaction.com/download/iaplayer.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://frontier.webex.com/client/T26L/support/ieatgpc1.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FD6E879D-9F2B-4120-9841-3A45B077D977}: NameServer = 8.8.8.8,8.8.4.4
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll (file missing)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: WebEx Service Host for Support Center (atashost) - WebEx Communications, Inc. - C:\Windows\system32\atashost.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 10892 bytes
Hello and welcome to the forums! My name is SweetTech, it's a pleasure to meet you. :)

I am very sorry for the delay in responding, but as you can see we are at the moment being flooded with logs which, when paired with the never-ending shortage of helpers, resulted in the delayed responding to your thread.

If you have already received help elsewhere please inform me so that this topic can be closed.

If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:
  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • In Windows Vista and Windows 7, all tools need to be started by right clicking and selecting Run as Administrator!
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within three days
    failure to reply will result in the topic being closed!
  • Please do not PM me directly for help. If you have any questions, post them in this topic. The only time you can and should PM me is when I have not been replying to you for several days (usually around 4 days) and you need an explanation. If that's the case, just send me a message on here. ;)
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
____________________________________________________


OTL Custom Scan
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /180

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.


NEXT:



Scanning with GMER

Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

    [external image: Posted Image]
  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system…click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save… button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and be sure to re-enable your anti-virus, Firewall and any other security programs you had disabled.
– If you encounter any problems, try running GMER in safe mode.
– If GMER crashes or keeps resulting in a BSODs, uncheck Devices on the right side before scanning
.



NEXT:



Please make sure you include the following items in your next post:

1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. The logs that were produced after running the OTL scans. (OTL.txt & Extras.txt)
3. The log that was produced after running GMER
4. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.
Hello SweetTech and thanks for taking the time to help. Your answers…

1. Any comments or questions you may have that you'd like for me to answer in my next post to you.

Nothing ATT, but once the culprit is found, advice on how to further shore up defenses.

2. The logs that were produced after running the OTL scans. (OTL.txt & Extras.txt)

Here is the first OTL.txt

OTL logfile created on: 6/1/2010 7:52:17 PM - Run 1
OTL by OldTimer - Version 3.2.5.3 Folder = C:\Users\Home\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 54.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 69.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 64.46 Gb Total Space | 7.09 Gb Free Space | 11.00% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 7.00 Gb Free Space | 70.05% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOME-PC
Current User Name: Home
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Home\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Home\AppData\Local\Temp\SoftwareProtection.exe (Microsoft Inc.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Windows\System32\atashost.exe (WebEx Communications, Inc.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\AERTSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)


========== Modules (SafeList) ==========

MOD - C:\Users\Home\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (GoogleDesktopManager-110309-193829) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (atashost) – C:\Windows\System32\atashost.exe (WebEx Communications, Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AERTFilters) – C:\Windows\System32\AERTSrv.exe (Andrea Electronics Corporation)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()


========== Driver Services (SafeList) ==========

DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (pavboot) – C:\Windows\system32\drivers\pavboot.sys (Panda Security, S.L.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (X4HSX32) – C:\Program Files\GameTap\bin\Release\X4HSX32.sys (Exent Technologies Ltd.)
DRV - (xnacc) – C:\Windows\System32\drivers\xnacc.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (xusb21) – C:\Windows\System32\drivers\xusb21.sys (Microsoft Corporation)
DRV - (nvstor32) – C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (dsunidrv) – C:\Windows\System32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (ENETHUSB) – C:\Windows\System32\drivers\enethusb.sys (Siemens Subscriber Networks, Inc.)
DRV - (MaVctrl) – C:\Windows\System32\drivers\MaVc2K.sys (Mobile Action Technology Inc.)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (maz500u) – C:\Windows\System32\drivers\maz500u.sys (Mobile Action Technology Inc.)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (winusb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWBS2) – C:\Windows\System32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (sscdmdm) – C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\Windows\System32\drivers\sscdbus.sys (MCCI)
DRV - (maz500m) – C:\Windows\System32\drivers\maz500m.sys (Mobile Action Technology Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.google.com/ig/dell?hl=en&cl;…amp;ibd=4071026
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.startup.homepage: "http://bing.zugo.com/?cfg=2-77-0-X35c"
FF - prefs.js..extensions.enabledItems: [removed]:0.4.1.1
FF - prefs.js..extensions.enabledItems: {f0178163-d454-7451-6914-3ddfbc0cdfe6}:[removed]
FF - prefs.js..extensions.enabledItems: {896642E4-C556-4ED3-85D1-9AC431603E7D}:1.0.4
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.5.8.6
FF - prefs.js..keyword.URL: "http://bing.zugotoolbar.com/s/?iesrc=IE-Address&site;=Bing&q;="


FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/11 12:54:00 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/11 12:54:00 | 000,000,000 | —D | M]

[2009/11/04 17:40:27 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Mozilla\Extensions
[2010/05/23 21:03:57 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions
[2009/12/10 23:35:41 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/05/11 17:16:39 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2010/04/26 20:21:56 | 000,000,000 | —D | M] (Search Toolbar) – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{896642E4-C556-4ED3-85D1-9AC431603E7D}
[2010/02/04 13:04:15 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\[removed]
[2010/04/26 20:21:57 | 000,000,737 | —- | M] () – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\searchplugins\bing-ff.xml
[2010/04/26 20:22:13 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/26 20:22:13 | 000,000,000 | —D | M] (LoudMo Contextual Ad Assistant) – C:\Program Files\Mozilla Firefox\extensions\{f0178163-d454-7451-6914-3ddfbc0cdfe6}

O1 HOSTS File: ([2010/05/05 20:24:28 | 000,393,216 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-domains-registrations.com
O1 - Hosts: 127.0.0.1 www.1-domains-registrations.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 13579 more lines…
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (WitBHO Class) - {75ED56AF-4DC9-4243-A30C-4EF4DD0CA28F} - C:\Program Files\ChameleonTom\wit4ie.dll File not found
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (TBSB05974 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Search Toolbar\tbcore3.dll ()
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Search Toolbar) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - C:\Program Files\Search Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Search Toolbar) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - C:\Program Files\Search Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Zynga Toolbar) - {7B13EC3E-999A-4B70-B9CB-2617B8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [ECenter] C:\DELL\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ABC] C:\Users\Home\AppData\Local\Temp\SoftwareProtection.exe (Microsoft Inc.)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -Mozilla\4.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident\4.0; File not found
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} http://support.dell.com/systemprofiler/SysProExe.CAB (WMI Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {DB7BF79A-FC51-4B5A-92BC-A65731174380} http://www.instantaction.com/download/iaplayer.cab (InstantAction Game Launcher)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://frontier.webex.com/client/T26L/support/ieatgpc1.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll File not found
O24 - Desktop WallPaper: C:\Users\Home\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Home\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{3163d020-eb73-11de-8a29-001aa05eef43}\Shell\AutoRun\command - "" = F:\rcaeasyrip_setup.exe – File not found
O33 - MountPoints2\{3163d020-eb73-11de-8a29-001aa05eef43}\Shell\install\command - "" = F:\rcaeasyrip_setup.exe – File not found
O33 - MountPoints2\{3163d020-eb73-11de-8a29-001aa05eef43}\Shell\usermanualEnglish\command - "" = F:\rcaeasyrip_setup.exe – File not found
O33 - MountPoints2\{3163d020-eb73-11de-8a29-001aa05eef43}\Shell\usermanualFrench\command - "" = F:\rcaeasyrip_setup.exe – File not found
O33 - MountPoints2\{3163d020-eb73-11de-8a29-001aa05eef43}\Shell\usermanualSpanish\command - "" = F:\rcaeasyrip_setup.exe – File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2008/10/01 03:13:09 | 000,000,000 | —D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.SP54 - C:\Windows\System32\Sp5x_32.dll (Sunplus)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/06/01 19:50:36 | 000,571,904 | —- | C] (OldTimer Tools) – C:\Users\Home\Desktop\OTL.exe
[2010/05/31 12:34:34 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/05/31 10:41:12 | 000,998,736 | —- | C] (Kaspersky Lab) – C:\Users\Home\Desktop\TDSSKiller.exe
[2010/05/31 09:53:07 | 000,028,552 | —- | C] (Panda Security, S.L.) – C:\Windows\System32\drivers\pavboot.sys
[2010/05/31 09:53:03 | 000,000,000 | —D | C] – C:\Program Files\Panda Security
[2010/05/29 08:45:29 | 000,000,000 | —D | C] – C:\ProgramData\Alwil Software
[2010/05/25 17:00:49 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/05/15 23:52:11 | 000,000,000 | —D | C] – C:\Users\Home\AppData\Local\assembly
[2010/05/15 23:50:58 | 000,000,000 | —D | C] – C:\Users\Home\AppData\Local\IsolatedStorage
[2010/05/15 23:48:24 | 000,000,000 | —D | C] – C:\Program Files\Virtual Earth 3D
[2010/05/04 21:57:13 | 000,000,000 | —D | C] – C:\Users\Home\AppData\Roaming\Malwarebytes
[2010/05/04 21:57:04 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/05/04 21:57:03 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/05/04 21:57:02 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/05/04 21:57:01 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/06/01 19:56:08 | 006,553,600 | -HS- | M] () – C:\Users\Home\ntuser.dat
[2010/06/01 19:50:45 | 000,293,376 | —- | M] () – C:\Users\Home\Desktop\jn9ule5l.exe
[2010/06/01 19:50:39 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\Home\Desktop\OTL.exe
[2010/06/01 18:25:41 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/01 18:25:41 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/01 16:33:40 | 000,000,236 | —- | M] () – C:\Users\Home\Desktop\DAN-gh..url
[2010/05/31 20:31:02 | 003,701,914 | —- | M] () – C:\Users\Home\Desktop\ComboFix.exe
[2010/05/31 20:28:37 | 000,998,736 | —- | M] (Kaspersky Lab) – C:\Users\Home\Desktop\TDSSKiller.exe
[2010/05/31 12:34:55 | 000,002,521 | —- | M] () – C:\Users\Home\Desktop\HiJackThis.lnk
[2010/05/31 12:33:17 | 001,402,880 | —- | M] () – C:\Users\Home\Desktop\HiJackThis.msi
[2010/05/31 12:31:58 | 000,690,960 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/05/31 12:31:58 | 000,595,446 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/05/31 12:31:58 | 000,101,144 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/05/31 12:25:45 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/05/31 12:25:34 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/05/31 12:25:30 | 2078,793,728 | -HS- | M] () – C:\hiberfil.sys
[2010/05/31 12:24:48 | 000,524,288 | -HS- | M] () – C:\Users\Home\ntuser.dat{6ee29a04-1b3e-11de-b98e-001aa05eef43}.TMContainer00000000000000000001.regtrans-ms
[2010/05/31 12:24:48 | 000,065,536 | -HS- | M] () – C:\Users\Home\ntuser.dat{6ee29a04-1b3e-11de-b98e-001aa05eef43}.TM.blf
[2010/05/31 11:21:19 | 000,001,087 | —- | M] () – C:\Users\Home\Desktop\Spybot - Search & Destroy.lnk
[2010/05/29 08:47:00 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2010/05/29 08:47:00 | 000,001,842 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/05/29 08:43:47 | 051,731,232 | —- | M] () – C:\Users\Home\Desktop\setup_av_free.exe
[2010/05/27 03:00:00 | 000,000,308 | —- | M] () – C:\Windows\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2010/05/26 03:00:00 | 000,000,316 | —- | M] () – C:\Windows\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2010/05/23 21:09:40 | 000,006,866 | —- | M] () – C:\Users\Home\Desktop\Outer lines.rtf
[2010/05/22 19:40:47 | 000,033,094 | —- | M] () – C:\Users\Home\Desktop\DF-Spider_Sound.ogg
[2010/05/16 00:31:52 | 000,018,432 | —- | M] () – C:\Users\Home\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/15 23:50:34 | 000,001,891 | —- | M] () – C:\Users\Public\Desktop\Bing Maps 3D.lnk
[2010/05/15 19:37:11 | 003,852,800 | —- | M] () – C:\Users\Home\Desktop\The Rodwell Line.wps
[2010/05/15 19:37:11 | 000,001,104 | —- | M] () – C:\Users\Home\AppData\Roaming\wklnhst.dat
[2010/05/12 11:21:16 | 000,221,568 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2010/05/06 15:59:57 | 000,038,848 | —- | M] (ALWIL Software) – C:\Windows\System32\avastSS.scr
[2010/05/06 15:59:36 | 000,165,032 | —- | M] (ALWIL Software) – C:\Windows\System32\aswBoot.exe
[2010/05/06 15:39:23 | 000,046,672 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswTdi.sys
[2010/05/06 15:39:00 | 000,164,048 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswSP.sys
[2010/05/06 15:34:27 | 000,023,376 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswRdr.sys
[2010/05/06 15:34:10 | 000,051,792 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2010/05/06 15:33:47 | 000,019,024 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2010/05/05 20:24:28 | 000,393,216 | R— | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/05/05 20:21:16 | 000,393,216 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100505-202428.backup
[2010/05/05 20:18:35 | 000,393,216 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100505-202116.backup
[2010/05/04 21:57:06 | 000,000,820 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/01 19:50:35 | 000,293,376 | —- | C] () – C:\Users\Home\Desktop\jn9ule5l.exe
[2010/05/31 20:30:55 | 003,701,914 | —- | C] () – C:\Users\Home\Desktop\ComboFix.exe
[2010/05/31 12:34:34 | 000,002,521 | —- | C] () – C:\Users\Home\Desktop\HiJackThis.lnk
[2010/05/31 12:33:06 | 001,402,880 | —- | C] () – C:\Users\Home\Desktop\HiJackThis.msi
[2010/05/31 12:25:30 | 2078,793,728 | -HS- | C] () – C:\hiberfil.sys
[2010/05/29 08:47:00 | 000,001,842 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/05/29 08:43:42 | 051,731,232 | —- | C] () – C:\Users\Home\Desktop\setup_av_free.exe
[2010/05/23 21:09:40 | 000,006,866 | —- | C] () – C:\Users\Home\Desktop\Outer lines.rtf
[2010/05/22 19:40:46 | 000,033,094 | —- | C] () – C:\Users\Home\Desktop\DF-Spider_Sound.ogg
[2010/05/15 23:50:34 | 000,001,891 | —- | C] () – C:\Users\Public\Desktop\Bing Maps 3D.lnk
[2010/05/05 20:07:07 | 000,000,316 | —- | C] () – C:\Windows\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2010/05/05 20:05:15 | 000,000,308 | —- | C] () – C:\Windows\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2010/05/04 21:57:06 | 000,000,820 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/02 17:17:34 | 000,179,091 | —- | C] () – C:\Windows\System32\xlive.dll.cat
[2009/09/11 01:57:46 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/03/19 09:05:30 | 000,000,110 | —- | C] () – C:\Windows\TLCAPPS.INI
[2009/03/08 15:37:48 | 000,000,343 | —- | C] () – C:\Windows\WININIT.INI
[2009/03/08 15:37:28 | 000,000,068 | —- | C] () – C:\Windows\SLS.INI
[2008/09/19 16:57:34 | 003,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2008/09/19 16:55:10 | 000,000,416 | —- | C] () – C:\Windows\System32\dtu100.dll.manifest
[2008/09/19 16:55:10 | 000,000,416 | —- | C] () – C:\Windows\System32\dpl100.dll.manifest
[2008/09/19 16:54:18 | 000,012,288 | —- | C] () – C:\Windows\System32\DivXWMPExtType.dll
[2008/05/27 00:15:08 | 000,001,325 | —- | C] () – C:\Windows\Remove.ini
[2008/05/26 21:32:40 | 000,000,000 | —- | C] () – C:\Windows\I531_109.INI
[2007/03/19 05:04:58 | 000,003,584 | —- | C] () – C:\Windows\System32\namResES.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResIT.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResFR.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResENG.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResDE.dll
[2007/03/19 05:04:56 | 000,003,584 | —- | C] () – C:\Windows\System32\namResPTB.dll
[2007/03/19 05:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHC.dll
[2007/03/19 05:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResKO.dll
[2007/03/19 05:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResJA.dll
[2007/03/19 05:04:54 | 000,022,016 | —- | C] () – C:\Windows\System32\nam_page.dll
[2007/03/19 05:04:54 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHT.dll
[2006/11/02 05:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini

========== LOP Check ==========

[2010/04/13 08:56:00 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/02/09 23:11:49 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\LimeWire
[2008/06/07 11:56:21 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\MobileAction
[2009/10/04 23:15:29 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Softplicity
[2007/12/26 23:18:54 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Template
[2007/12/22 19:05:54 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Wal-Mart
[2010/05/31 11:24:42 | 000,032,590 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 16:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/11/10 16:59:07 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 16:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2007/10/25 19:32:57 | 000,004,095 | RH– | M] () – C:\dell.sdr
[2010/05/31 12:25:30 | 2078,793,728 | -HS- | M] () – C:\hiberfil.sys
[2008/05/26 13:44:41 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/05/26 13:44:41 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/05/31 12:25:28 | 2392,596,480 | -HS- | M] () – C:\pagefile.sys
[2007/11/22 20:39:20 | 000,008,947 | —- | M] () – C:\SSInst.log
[2010/05/31 20:33:35 | 000,054,618 | —- | M] () – C:\TDSSKiller.2.3.2.0_31.05.2010_20.33.14_log.txt
[2008/06/27 15:08:30 | 000,000,000 | —- | M] () – C:\wizard.txt
[2007/12/28 22:28:01 | 000,000,158 | —- | M] () – C:\YServer.txt

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/03/08 06:31:42 | 000,348,160 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\dxtmsft.dll
[2009/03/08 06:31:37 | 000,216,064 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\dxtrans.dll
[2009/04/11 01:27:47 | 000,241,128 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\rsaenh.dll
[2009/04/11 01:28:23 | 000,228,352 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\SLC.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2006/11/02 05:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 05:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 05:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %systemroot%\system32\drivers\*.sys /180 >
[2010/05/06 15:33:47 | 000,019,024 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2010/05/06 15:34:10 | 000,051,792 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2010/05/06 15:34:27 | 000,023,376 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswRdr.sys
[2010/05/06 15:39:00 | 000,164,048 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswSP.sys
[2010/05/06 15:39:23 | 000,046,672 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswTdi.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/02/23 06:10:13 | 000,106,496 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb.sys
[2010/02/23 06:10:19 | 000,212,992 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb10.sys
[2010/02/23 06:10:13 | 000,079,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb20.sys
[2009/12/11 06:43:30 | 000,302,080 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srv.sys
[2009/12/11 06:43:11 | 000,098,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srvnet.sys
[2010/02/18 09:07:16 | 000,904,576 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tcpip.sys
[2009/12/08 12:26:18 | 000,030,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tcpipreg.sys
[2010/02/18 06:28:13 | 000,025,088 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tunnel.sys

========== Alternate Data Streams ==========

@Alternate Data Stream - 777 bytes -> C:\Users\Home\Desktop\RE_ Rushton Family .eml:OECustomProperty
@Alternate Data Stream - 741 bytes -> C:\Users\Home\Desktop\More pictures.eml:OECustomProperty
< End of report >

I will split these logs up in separate posts, as they are a little long…

3OTL logfile created on: 6/1/2010 7:52:17 PM - Run 1
OTL by OldTimer - Version 3.2.5.3 Folder = C:\Users\Home\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 54.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 69.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 64.46 Gb Total Space | 7.09 Gb Free Space | 11.00% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 7.00 Gb Free Space | 70.05% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOME-PC
Current User Name: Home
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Home\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Home\AppData\Local\Temp\SoftwareProtection.exe (Microsoft Inc.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Windows\System32\atashost.exe (WebEx Communications, Inc.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\AERTSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)


========== Modules (SafeList) ==========

MOD - C:\Users\Home\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (GoogleDesktopManager-110309-193829) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (atashost) – C:\Windows\System32\atashost.exe (WebEx Communications, Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AERTFilters) – C:\Windows\System32\AERTSrv.exe (Andrea Electronics Corporation)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()


========== Driver Services (SafeList) ==========

DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (pavboot) – C:\Windows\system32\drivers\pavboot.sys (Panda Security, S.L.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (X4HSX32) – C:\Program Files\GameTap\bin\Release\X4HSX32.sys (Exent Technologies Ltd.)
DRV - (xnacc) – C:\Windows\System32\drivers\xnacc.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (xusb21) – C:\Windows\System32\drivers\xusb21.sys (Microsoft Corporation)
DRV - (nvstor32) – C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (dsunidrv) – C:\Windows\System32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (ENETHUSB) – C:\Windows\System32\drivers\enethusb.sys (Siemens Subscriber Networks, Inc.)
DRV - (MaVctrl) – C:\Windows\System32\drivers\MaVc2K.sys (Mobile Action Technology Inc.)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (maz500u) – C:\Windows\System32\drivers\maz500u.sys (Mobile Action Technology Inc.)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (winusb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWBS2) – C:\Windows\System32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (sscdmdm) – C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\Windows\System32\drivers\sscdbus.sys (MCCI)
DRV - (maz500m) – C:\Windows\System32\drivers\maz500m.sys (Mobile Action Technology Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.google.com/ig/dell?hl=en&cl;…amp;ibd=4071026
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.startup.homepage: "http://bing.zugo.com/?cfg=2-77-0-X35c"
FF - prefs.js..extensions.enabledItems: [removed]:0.4.1.1
FF - prefs.js..extensions.enabledItems: {f0178163-d454-7451-6914-3ddfbc0cdfe6}:[removed]
FF - prefs.js..extensions.enabledItems: {896642E4-C556-4ED3-85D1-9AC431603E7D}:1.0.4
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.5.8.6
FF - prefs.js..keyword.URL: "http://bing.zugotoolbar.com/s/?iesrc=IE-Address&site;=Bing&q;="


FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/11 12:54:00 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/11 12:54:00 | 000,000,000 | —D | M]

[2009/11/04 17:40:27 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Mozilla\Extensions
[2010/05/23 21:03:57 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions
[2009/12/10 23:35:41 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/05/11 17:16:39 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2010/04/26 20:21:56 | 000,000,000 | —D | M] (Search Toolbar) – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{896642E4-C556-4ED3-85D1-9AC431603E7D}
[2010/02/04 13:04:15 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\[removed]
[2010/04/26 20:21:57 | 000,000,737 | —- | M] () – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\searchplugins\bing-ff.xml
[2010/04/26 20:22:13 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/26 20:22:13 | 000,000,000 | —D | M] (LoudMo Contextual Ad Assistant) – C:\Program Files\Mozilla Firefox\extensions\{f0178163-d454-7451-6914-3ddfbc0cdfe6}

O1 HOSTS File: ([2010/05/05 20:24:28 | 000,393,216 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-domains-registrations.com
O1 - Hosts: 127.0.0.1 www.1-domains-registrations.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 13579 more lines…
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (WitBHO Class) - {75ED56AF-4DC9-4243-A30C-4EF4DD0CA28F} - C:\Program Files\ChameleonTom\wit4ie.dll File not found
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (TBSB05974 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Search Toolbar\tbcore3.dll ()
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Search Toolbar) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - C:\Program Files\Search Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Search Toolbar) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - C:\Program Files\Search Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Zynga Toolbar) - {7B13EC3E-999A-4B70-B9CB-2617B8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [ECenter] C:\DELL\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ABC] C:\Users\Home\AppData\Local\Temp\SoftwareProtection.exe (Microsoft Inc.)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -Mozilla\4.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident\4.0; File not found
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} http://support.dell.com/systemprofiler/SysProExe.CAB (WMI Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {DB7BF79A-FC51-4B5A-92BC-A65731174380} http://www.instantaction.com/download/iaplayer.cab (InstantAction Game Launcher)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://frontier.webex.com/client/T26L/support/ieatgpc1.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll File not found
O24 - Desktop WallPaper: C:\Users\Home\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Home\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{3163d020-eb73-11de-8a29-001aa05eef43}\Shell\AutoRun\command - "" = F:\rcaeasyrip_setup.exe – File not found
O33 - MountPoints2\{3163d020-eb73-11de-8a29-001aa05eef43}\Shell\install\command - "" = F:\rcaeasyrip_setup.exe – File not found
O33 - MountPoints2\{3163d020-eb73-11de-8a29-001aa05eef43}\Shell\usermanualEnglish\command - "" = F:\rcaeasyrip_setup.exe – File not found
O33 - MountPoints2\{3163d020-eb73-11de-8a29-001aa05eef43}\Shell\usermanualFrench\command - "" = F:\rcaeasyrip_setup.exe – File not found
O33 - MountPoints2\{3163d020-eb73-11de-8a29-001aa05eef43}\Shell\usermanualSpanish\command - "" = F:\rcaeasyrip_setup.exe – File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2008/10/01 03:13:09 | 000,000,000 | —D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.SP54 - C:\Windows\System32\Sp5x_32.dll (Sunplus)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/06/01 19:50:36 | 000,571,904 | —- | C] (OldTimer Tools) – C:\Users\Home\Desktop\OTL.exe
[2010/05/31 12:34:34 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/05/31 10:41:12 | 000,998,736 | —- | C] (Kaspersky Lab) – C:\Users\Home\Desktop\TDSSKiller.exe
[2010/05/31 09:53:07 | 000,028,552 | —- | C] (Panda Security, S.L.) – C:\Windows\System32\drivers\pavboot.sys
[2010/05/31 09:53:03 | 000,000,000 | —D | C] – C:\Program Files\Panda Security
[2010/05/29 08:45:29 | 000,000,000 | —D | C] – C:\ProgramData\Alwil Software
[2010/05/25 17:00:49 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/05/15 23:52:11 | 000,000,000 | —D | C] – C:\Users\Home\AppData\Local\assembly
[2010/05/15 23:50:58 | 000,000,000 | —D | C] – C:\Users\Home\AppData\Local\IsolatedStorage
[2010/05/15 23:48:24 | 000,000,000 | —D | C] – C:\Program Files\Virtual Earth 3D
[2010/05/04 21:57:13 | 000,000,000 | —D | C] – C:\Users\Home\AppData\Roaming\Malwarebytes
[2010/05/04 21:57:04 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/05/04 21:57:03 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/05/04 21:57:02 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/05/04 21:57:01 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/06/01 19:56:08 | 006,553,600 | -HS- | M] () – C:\Users\Home\ntuser.dat
[2010/06/01 19:50:45 | 000,293,376 | —- | M] () – C:\Users\Home\Desktop\jn9ule5l.exe
[2010/06/01 19:50:39 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\Home\Desktop\OTL.exe
[2010/06/01 18:25:41 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/01 18:25:41 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/01 16:33:40 | 000,000,236 | —- | M] () – C:\Users\Home\Desktop\DAN-gh..url
[2010/05/31 20:31:02 | 003,701,914 | —- | M] () – C:\Users\Home\Desktop\ComboFix.exe
[2010/05/31 20:28:37 | 000,998,736 | —- | M] (Kaspersky Lab) – C:\Users\Home\Desktop\TDSSKiller.exe
[2010/05/31 12:34:55 | 000,002,521 | —- | M] () – C:\Users\Home\Desktop\HiJackThis.lnk
[2010/05/31 12:33:17 | 001,402,880 | —- | M] () – C:\Users\Home\Desktop\HiJackThis.msi
[2010/05/31 12:31:58 | 000,690,960 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/05/31 12:31:58 | 000,595,446 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/05/31 12:31:58 | 000,101,144 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/05/31 12:25:45 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/05/31 12:25:34 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/05/31 12:25:30 | 2078,793,728 | -HS- | M] () – C:\hiberfil.sys
[2010/05/31 12:24:48 | 000,524,288 | -HS- | M] () – C:\Users\Home\ntuser.dat{6ee29a04-1b3e-11de-b98e-001aa05eef43}.TMContainer00000000000000000001.regtrans-ms
[2010/05/31 12:24:48 | 000,065,536 | -HS- | M] () – C:\Users\Home\ntuser.dat{6ee29a04-1b3e-11de-b98e-001aa05eef43}.TM.blf
[2010/05/31 11:21:19 | 000,001,087 | —- | M] () – C:\Users\Home\Desktop\Spybot - Search & Destroy.lnk
[2010/05/29 08:47:00 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2010/05/29 08:47:00 | 000,001,842 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/05/29 08:43:47 | 051,731,232 | —- | M] () – C:\Users\Home\Desktop\setup_av_free.exe
[2010/05/27 03:00:00 | 000,000,308 | —- | M] () – C:\Windows\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2010/05/26 03:00:00 | 000,000,316 | —- | M] () – C:\Windows\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2010/05/23 21:09:40 | 000,006,866 | —- | M] () – C:\Users\Home\Desktop\Outer lines.rtf
[2010/05/22 19:40:47 | 000,033,094 | —- | M] () – C:\Users\Home\Desktop\DF-Spider_Sound.ogg
[2010/05/16 00:31:52 | 000,018,432 | —- | M] () – C:\Users\Home\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/15 23:50:34 | 000,001,891 | —- | M] () – C:\Users\Public\Desktop\Bing Maps 3D.lnk
[2010/05/15 19:37:11 | 003,852,800 | —- | M] () – C:\Users\Home\Desktop\The Rodwell Line.wps
[2010/05/15 19:37:11 | 000,001,104 | —- | M] () – C:\Users\Home\AppData\Roaming\wklnhst.dat
[2010/05/12 11:21:16 | 000,221,568 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2010/05/06 15:59:57 | 000,038,848 | —- | M] (ALWIL Software) – C:\Windows\System32\avastSS.scr
[2010/05/06 15:59:36 | 000,165,032 | —- | M] (ALWIL Software) – C:\Windows\System32\aswBoot.exe
[2010/05/06 15:39:23 | 000,046,672 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswTdi.sys
[2010/05/06 15:39:00 | 000,164,048 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswSP.sys
[2010/05/06 15:34:27 | 000,023,376 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswRdr.sys
[2010/05/06 15:34:10 | 000,051,792 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2010/05/06 15:33:47 | 000,019,024 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2010/05/05 20:24:28 | 000,393,216 | R— | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/05/05 20:21:16 | 000,393,216 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100505-202428.backup
[2010/05/05 20:18:35 | 000,393,216 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100505-202116.backup
[2010/05/04 21:57:06 | 000,000,820 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/01 19:50:35 | 000,293,376 | —- | C] () – C:\Users\Home\Desktop\jn9ule5l.exe
[2010/05/31 20:30:55 | 003,701,914 | —- | C] () – C:\Users\Home\Desktop\ComboFix.exe
[2010/05/31 12:34:34 | 000,002,521 | —- | C] () – C:\Users\Home\Desktop\HiJackThis.lnk
[2010/05/31 12:33:06 | 001,402,880 | —- | C] () – C:\Users\Home\Desktop\HiJackThis.msi
[2010/05/31 12:25:30 | 2078,793,728 | -HS- | C] () – C:\hiberfil.sys
[2010/05/29 08:47:00 | 000,001,842 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/05/29 08:43:42 | 051,731,232 | —- | C] () – C:\Users\Home\Desktop\setup_av_free.exe
[2010/05/23 21:09:40 | 000,006,866 | —- | C] () – C:\Users\Home\Desktop\Outer lines.rtf
[2010/05/22 19:40:46 | 000,033,094 | —- | C] () – C:\Users\Home\Desktop\DF-Spider_Sound.ogg
[2010/05/15 23:50:34 | 000,001,891 | —- | C] () – C:\Users\Public\Desktop\Bing Maps 3D.lnk
[2010/05/05 20:07:07 | 000,000,316 | —- | C] () – C:\Windows\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2010/05/05 20:05:15 | 000,000,308 | —- | C] () – C:\Windows\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2010/05/04 21:57:06 | 000,000,820 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/02 17:17:34 | 000,179,091 | —- | C] () – C:\Windows\System32\xlive.dll.cat
[2009/09/11 01:57:46 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/03/19 09:05:30 | 000,000,110 | —- | C] () – C:\Windows\TLCAPPS.INI
[2009/03/08 15:37:48 | 000,000,343 | —- | C] () – C:\Windows\WININIT.INI
[2009/03/08 15:37:28 | 000,000,068 | —- | C] () – C:\Windows\SLS.INI
[2008/09/19 16:57:34 | 003,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2008/09/19 16:55:10 | 000,000,416 | —- | C] () – C:\Windows\System32\dtu100.dll.manifest
[2008/09/19 16:55:10 | 000,000,416 | —- | C] () – C:\Windows\System32\dpl100.dll.manifest
[2008/09/19 16:54:18 | 000,012,288 | —- | C] () – C:\Windows\System32\DivXWMPExtType.dll
[2008/05/27 00:15:08 | 000,001,325 | —- | C] () – C:\Windows\Remove.ini
[2008/05/26 21:32:40 | 000,000,000 | —- | C] () – C:\Windows\I531_109.INI
[2007/03/19 05:04:58 | 000,003,584 | —- | C] () – C:\Windows\System32\namResES.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResIT.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResFR.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResENG.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResDE.dll
[2007/03/19 05:04:56 | 000,003,584 | —- | C] () – C:\Windows\System32\namResPTB.dll
[2007/03/19 05:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHC.dll
[2007/03/19 05:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResKO.dll
[2007/03/19 05:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResJA.dll
[2007/03/19 05:04:54 | 000,022,016 | —- | C] () – C:\Windows\System32\nam_page.dll
[2007/03/19 05:04:54 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHT.dll
[2006/11/02 05:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini

========== LOP Check ==========

[2010/04/13 08:56:00 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/02/09 23:11:49 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\LimeWire
[2008/06/07 11:56:21 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\MobileAction
[2009/10/04 23:15:29 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Softplicity
[2007/12/26 23:18:54 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Template
[2007/12/22 19:05:54 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Wal-Mart
[2010/05/31 11:24:42 | 000,032,590 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 16:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/11/10 16:59:07 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 16:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2007/10/25 19:32:57 | 000,004,095 | RH– | M] () – C:\dell.sdr
[2010/05/31 12:25:30 | 2078,793,728 | -HS- | M] () – C:\hiberfil.sys
[2008/05/26 13:44:41 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/05/26 13:44:41 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/05/31 12:25:28 | 2392,596,480 | -HS- | M] () – C:\pagefile.sys
[2007/11/22 20:39:20 | 000,008,947 | —- | M] () – C:\SSInst.log
[2010/05/31 20:33:35 | 000,054,618 | —- | M] () – C:\TDSSKiller.2.3.2.0_31.05.2010_20.33.14_log.txt
[2008/06/27 15:08:30 | 000,000,000 | —- | M] () – C:\wizard.txt
[2007/12/28 22:28:01 | 000,000,158 | —- | M] () – C:\YServer.txt

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/03/08 06:31:42 | 000,348,160 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\dxtmsft.dll
[2009/03/08 06:31:37 | 000,216,064 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\dxtrans.dll
[2009/04/11 01:27:47 | 000,241,128 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\rsaenh.dll
[2009/04/11 01:28:23 | 000,228,352 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\SLC.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2006/11/02 05:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 05:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 05:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %systemroot%\system32\drivers\*.sys /180 >
[2010/05/06 15:33:47 | 000,019,024 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2010/05/06 15:34:10 | 000,051,792 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2010/05/06 15:34:27 | 000,023,376 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswRdr.sys
[2010/05/06 15:39:00 | 000,164,048 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswSP.sys
[2010/05/06 15:39:23 | 000,046,672 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswTdi.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/02/23 06:10:13 | 000,106,496 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb.sys
[2010/02/23 06:10:19 | 000,212,992 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb10.sys
[2010/02/23 06:10:13 | 000,079,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb20.sys
[2009/12/11 06:43:30 | 000,302,080 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srv.sys
[2009/12/11 06:43:11 | 000,098,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srvnet.sys
[2010/02/18 09:07:16 | 000,904,576 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tcpip.sys
[2009/12/08 12:26:18 | 000,030,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tcpipreg.sys
[2010/02/18 06:28:13 | 000,025,088 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tunnel.sys

========== Alternate Data Streams ==========

@Alternate Data Stream - 777 bytes -> C:\Users\Home\Desktop\RE_ Rushton Family .eml:OECustomProperty
@Alternate Data Stream - 741 bytes -> C:\Users\Home\Desktop\More pictures.eml:OECustomProperty
< End of report >
From OLT Extras.txt

OTL Extras logfile created on: 6/1/2010 7:52:17 PM - Run 1
OTL by OldTimer - Version 3.2.5.3 Folder = C:\Users\Home\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 54.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 69.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 64.46 Gb Total Space | 7.09 Gb Free Space | 11.00% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 7.00 Gb Free Space | 70.05% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOME-PC
Current User Name: Home
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{09AC6E7D-6FF1-4A6A-B6E8-3DED341A4821}" = lport=138 | protocol=17 | dir=in | app=system |
"{0A994719-92A3-4FB8-8B99-2435BF7ABAEF}" = lport=10243 | protocol=6 | dir=in | app=system |
"{109DB8E9-16ED-44E7-BE4D-8D004772558B}" = rport=10243 | protocol=6 | dir=out | app=system |
"{24654832-8224-4D52-907E-363DF478E195}" = lport=139 | protocol=6 | dir=in | app=system |
"{26F426AB-3704-4912-B17B-FC9367140B3F}" = lport=445 | protocol=6 | dir=in | app=system |
"{3AB5C31B-A0BD-4AD9-856C-1F455A034FD8}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{442F5FEE-57A9-42DB-8DF9-5FB26821A8D1}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{49E0F363-7FA4-46C6-A8E5-64962D714079}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4BB4EC5B-7B51-491F-BE1B-AE3F6DBBDD9C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{68FE896A-0483-45A6-BD67-572EFDDECA51}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{8492B514-A9CC-481B-BEB7-585EB9EEB58A}" = rport=445 | protocol=6 | dir=out | app=system |
"{86E4EE5A-AD95-4F37-AF31-81E3C88C67C1}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{91CA7932-93DD-4E4E-B51F-55A2A60CF5EF}" = rport=138 | protocol=17 | dir=out | app=system |
"{9AA48EAE-5539-4D92-97D8-94B65C6F8D1B}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{BAC382B8-8A34-41BC-A04A-7B3074764C61}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{BFFBC125-87FE-49C5-9E35-7FC0B802DD97}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C61D17E2-117E-4583-B4ED-8C2198D362DD}" = rport=137 | protocol=17 | dir=out | app=system |
"{CC9930E8-69F7-4F91-9621-DED7A81085A9}" = lport=137 | protocol=17 | dir=in | app=system |
"{EA6FB814-6362-4CB4-9224-999D89AA89AC}" = rport=139 | protocol=6 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{06868387-B24E-4755-B431-4C4853D02428}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{0B77C0F7-FB9A-4F6F-A456-836B22E54CA2}" = protocol=6 | dir=in | app=c:\program files\microsoft games\halo 2\halo2.exe |
"{1DAA4086-0076-40D4-8BF9-F609FA003281}" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-enus-downloader.exe |
"{23BD0DBF-E132-4603-963E-3BE47893296A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{32198A39-7BD8-46C6-95EA-FEF986299D95}" = protocol=6 | dir=out | app=system |
"{3E3A802C-9FE2-4253-93E4-5A5DBA876059}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4C2B1688-05A5-4D35-8AF0-7DB7FBA1657E}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{68C3EA12-B700-453E-9C27-F88915B4386D}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{6D1D07C6-C6EE-4373-B650-7C2778A83DE7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6DD3AB63-E3B5-49B2-A362-B68D3843532B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7F9700CB-A64C-4F09-9DF0-E36476EFE31F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{9CFCC075-1218-44F7-83B3-55D8B831CA0D}" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-enus-downloader.exe |
"{9DE5A8A3-C08E-4789-BC62-4FD47F0D5020}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{A1A6CA86-F319-48A7-8752-F6C0613C24A1}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{A2AA5365-1CA6-46BE-89EB-C563D790BC8B}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{AC52B78B-940D-4396-B435-01366485DB90}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{AFEFC84E-A9CE-497F-9F91-1FDA669A8E27}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{BA8BCB27-782D-4C72-893B-459AE081DB81}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{BBC0C107-8AB0-434D-8FB2-146C7352F1D6}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{D55137B9-20C9-4F54-830B-FF3B2577434E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D6AE4F5D-110F-42E4-90A5-0F7ACB4FEE93}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DDAECD8B-8377-4215-9BF3-E63817D94090}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F3B9B278-44EA-4709-B1EB-E82BCA860A32}" = protocol=17 | dir=in | app=c:\program files\microsoft games\halo 2\halo2.exe |
"{F5C9307F-C4AE-4EFF-B2EC-466B94005FC1}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"TCP Query User{0CBECA03-8437-4A6C-9B6E-13CD6CA004D6}C:\program files\starcraft\starcraft.exe" = protocol=6 | dir=in | app=c:\program files\starcraft\starcraft.exe |
"TCP Query User{0CFEC3AA-2588-46C2-B29E-2F389500183F}C:\users\public\games\world of warcraft\wow-3.2.0.10192-to-3.3.0.10958-enus-downloader.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\wow-3.2.0.10192-to-3.3.0.10958-enus-downloader.exe |
"TCP Query User{14F63FCE-21EB-4505-9ECF-85CE2B56BA39}C:\users\public\games\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe |
"TCP Query User{1E121FED-8DE8-4AF9-846F-EA9EB87B842D}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{4E86F751-0C8C-47B1-AEFA-1BB53DF88BB2}C:\users\public\games\world of warcraft\wow-3.3.0.11159-to-3.3.2.11403-enus-downloader.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\wow-3.3.0.11159-to-3.3.2.11403-enus-downloader.exe |
"TCP Query User{4F60B587-0FF8-41FB-96F5-378A80BC3199}C:\users\llkool.home-pc\appdata\roaming\myspace\im\bin\myspaceim.exe" = protocol=6 | dir=in | app=c:\users\llkool.home-pc\appdata\roaming\myspace\im\bin\myspaceim.exe |
"TCP Query User{6339CE65-40B1-4083-8ED1-31E57107BC3D}C:\users\home\appdata\local\microsoft\windows\temporary internet files\content.ie5\mfh2nc8f\terran_demo_esrb_xvid.avi-downloader[1].exe" = protocol=6 | dir=in | app=c:\users\home\appdata\local\microsoft\windows\temporary internet files\content.ie5\mfh2nc8f\terran_demo_esrb_xvid.avi-downloader[1].exe |
"TCP Query User{68D576CB-11E5-4509-BD0E-EF6E8708A81C}C:\program files\starcraft\starcraft.exe" = protocol=6 | dir=in | app=c:\program files\starcraft\starcraft.exe |
"TCP Query User{82C4C157-1C89-4779-AFB8-7585EBE55FA6}C:\users\home\desktop\720_starcraft2gameplayvideo_englishus.avi-downloader.exe" = protocol=6 | dir=in | app=c:\users\home\desktop\720_starcraft2gameplayvideo_englishus.avi-downloader.exe |
"TCP Query User{A831A591-63CE-4ABB-BC3D-4B1F0A4463AA}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{ABD4D5F3-6DFA-4F6B-BF6F-2AE849E3675D}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{BDC6C371-396F-432F-B241-857575368557}C:\users\llkool.home-pc\appdata\roaming\myspace\im\bin\myspaceim.exe" = protocol=6 | dir=in | app=c:\users\llkool.home-pc\appdata\roaming\myspace\im\bin\myspaceim.exe |
"TCP Query User{DC66D22E-D452-41A8-90E3-B1499C5AECCC}C:\users\home\desktop\720_starcraft2gameplayvideo_englishus.avi-downloader.exe" = protocol=6 | dir=in | app=c:\users\home\desktop\720_starcraft2gameplayvideo_englishus.avi-downloader.exe |
"TCP Query User{DD0ACDB7-1DA5-4F03-8526-7E2C1A2B80E7}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"TCP Query User{F3C4CE38-C90F-4E09-8DCF-54D31569A2A8}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{0198DCD6-28E9-477F-9F9B-106E6BD3F8A7}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{2E136D26-8748-467F-B773-78AD16B704CE}C:\users\llkool.home-pc\appdata\roaming\myspace\im\bin\myspaceim.exe" = protocol=17 | dir=in | app=c:\users\llkool.home-pc\appdata\roaming\myspace\im\bin\myspaceim.exe |
"UDP Query User{38328EFC-7A36-45C0-ABB9-D0A4D9BDA76A}C:\users\home\desktop\720_starcraft2gameplayvideo_englishus.avi-downloader.exe" = protocol=17 | dir=in | app=c:\users\home\desktop\720_starcraft2gameplayvideo_englishus.avi-downloader.exe |
"UDP Query User{4FB7EBF3-743E-4C03-A5B4-DD740143BE9A}C:\program files\starcraft\starcraft.exe" = protocol=17 | dir=in | app=c:\program files\starcraft\starcraft.exe |
"UDP Query User{769C6DDA-88B2-4A94-A8EC-7CFD79DE49F4}C:\users\public\games\world of warcraft\wow-3.3.0.11159-to-3.3.2.11403-enus-downloader.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\wow-3.3.0.11159-to-3.3.2.11403-enus-downloader.exe |
"UDP Query User{82B71A22-3AB1-4FFB-952D-326497F49DAE}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{84E708C4-14FE-45D8-977D-D796757ECB85}C:\users\home\appdata\local\microsoft\windows\temporary internet files\content.ie5\mfh2nc8f\terran_demo_esrb_xvid.avi-downloader[1].exe" = protocol=17 | dir=in | app=c:\users\home\appdata\local\microsoft\windows\temporary internet files\content.ie5\mfh2nc8f\terran_demo_esrb_xvid.avi-downloader[1].exe |
"UDP Query User{8A9812E9-9E82-4E13-AE35-A6E26BC9FC78}C:\users\llkool.home-pc\appdata\roaming\myspace\im\bin\myspaceim.exe" = protocol=17 | dir=in | app=c:\users\llkool.home-pc\appdata\roaming\myspace\im\bin\myspaceim.exe |
"UDP Query User{A42E0B5F-C42E-4945-A613-28601D85A18D}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{AF34E44B-BAEF-41BC-ABE8-6C4FC594338A}C:\program files\starcraft\starcraft.exe" = protocol=17 | dir=in | app=c:\program files\starcraft\starcraft.exe |
"UDP Query User{B144686C-34D9-42C2-9FEE-AD5CD1920FF1}C:\users\public\games\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe |
"UDP Query User{D0E40156-125A-4FB0-A314-5008F3DDB585}C:\users\public\games\world of warcraft\wow-3.2.0.10192-to-3.3.0.10958-enus-downloader.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\wow-3.2.0.10192-to-3.3.0.10958-enus-downloader.exe |
"UDP Query User{D23C84F3-FC73-448D-8851-E8D869C575EC}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{E1B5602A-376C-4296-9B37-7BB34796EAC2}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"UDP Query User{ECEF3FD5-8CEB-4C87-9C54-6AFE6A59CC24}C:\users\home\desktop\720_starcraft2gameplayvideo_englishus.avi-downloader.exe" = protocol=17 | dir=in | app=c:\users\home\desktop\720_starcraft2gameplayvideo_englishus.avi-downloader.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{13BA7B44-B712-4DEE-A7B8-1DD564F37AE5}" = Dell System Customization Wizard
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{281ECE39-F043-492B-8337-F2E546B5604A}" = PowerDVD
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2D87E961-577B-492B-AD54-1368680FB9A7}" = Bing Maps 3D
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}" = User's Guides
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{67E158AF-8856-4337-B483-EA21930786AF}" = GameTap
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{89CEAE14-DD0F-448E-9554-15781EC9DB24}" = Product Documentation Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8FB1B528-E260-451E-9B55-E9152F94B80B}" = Microsoft Games for Windows - LIVE Redistributable
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{C1771DDC-BEA1-4375-B2A2-B46F43ACB476}" = Wal-Mart Digital Photo Manager
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D00353E1-9A80-11D8-A6E6-0000E24CCC1B}" = Digital Camera
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{EFAD4066-CAF3-4B27-9669-12EED352C376}" = NVIDIANetworkDiagnostic
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F63A3748-B93D-4360-9AD4-B064481A5C7B}" = Modem Diagnostic Tool
"{F97E3841-CA9D-4964-9D64-26066241D26F}" = Microsoft Games for Windows - LIVE
"ActiveScan 2.0" = Panda ActiveScan 2.0
"Activision_StarTrekArmadaUninstallKey" = Star Trek: Armada
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3
"avast5" = avast! Free Antivirus
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1" = Conexant D850 PCI V.92 Modem
"Comix Zone_is1" = Comix Zone
"EfntSSDSL" = Siemens Subscriber Networks SpeedStream DSL
"Game Maker 7.0" = Game Maker 7.0
"Google Desktop" = Google Desktop
"GoToAssist" = GoToAssist 8.0.0.514
"HyperCam 2" = HyperCam 2
"InstallShield_{EFAD4066-CAF3-4B27-9669-12EED352C376}" = NVIDIANetworkDiagnostic
"LimeWire" = LimeWire 4.18.8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.9)" = Mozilla Firefox (3.5.9)
"Multi-Page TIFF Editor v.1.6_is1" = Multi-Page TIFF Editor v.1.6
"NVIDIA Drivers" = NVIDIA Drivers
"rrpw32.exe" = Reader Rabbit's Preschool
"Starcraft" = Starcraft
"World of Warcraft" = World of Warcraft
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
"Zynga Toolbar" = Zynga Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ActiveTouchMeetingClient" = WebEx
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 3/4/2009 10:22:04 PM | Computer Name = Home-PC | Source = avast! | ID = 33554522
Description =

Error - 3/4/2009 10:22:06 PM | Computer Name = Home-PC | Source = avast! | ID = 33554522
Description =

Error - 3/4/2009 10:22:06 PM | Computer Name = Home-PC | Source = avast! | ID = 33554522
Description =

Error - 3/4/2009 10:22:08 PM | Computer Name = Home-PC | Source = avast! | ID = 33554522
Description =

Error - 3/4/2009 10:22:10 PM | Computer Name = Home-PC | Source = avast! | ID = 33554522
Description =

Error - 3/4/2009 10:22:11 PM | Computer Name = Home-PC | Source = avast! | ID = 33554522
Description =

Error - 3/4/2009 10:22:13 PM | Computer Name = Home-PC | Source = avast! | ID = 33554522
Description =

Error - 3/4/2009 10:22:13 PM | Computer Name = Home-PC | Source = avast! | ID = 33554522
Description =

Error - 8/8/2009 11:52:39 PM | Computer Name = Home-PC | Source = avast! | ID = 33554522
Description =

Error - 8/8/2009 11:52:48 PM | Computer Name = Home-PC | Source = avast! | ID = 33554522
Description =

[ Application Events ]
Error - 5/28/2010 2:56:45 AM | Computer Name = Home-PC | Source = VSS | ID = 8193
Description =

Error - 5/28/2010 4:00:13 AM | Computer Name = Home-PC | Source = VSS | ID = 8193
Description =

Error - 5/28/2010 4:01:13 AM | Computer Name = Home-PC | Source = System Restore | ID = 8193
Description =

Error - 5/28/2010 4:32:53 PM | Computer Name = Home-PC | Source = VSS | ID = 8193
Description =

Error - 5/29/2010 9:45:35 AM | Computer Name = Home-PC | Source = VSS | ID = 8193
Description =

Error - 5/30/2010 1:36:50 AM | Computer Name = Home-PC | Source = VSS | ID = 8193
Description =

Error - 5/31/2010 12:43:21 PM | Computer Name = Home-PC | Source = EventSystem | ID = 4609
Description =

Error - 5/31/2010 1:33:57 PM | Computer Name = Home-PC | Source = VSS | ID = 8193
Description =

Error - 5/31/2010 3:19:00 PM | Computer Name = Home-PC | Source = VSS | ID = 8193
Description =

Error - 6/1/2010 8:53:04 PM | Computer Name = Home-PC | Source = VSS | ID = 8193
Description =

[ System Events ]
Error - 5/31/2010 12:43:21 PM | Computer Name = Home-PC | Source = DCOM | ID = 10005
Description =

Error - 5/31/2010 12:43:24 PM | Computer Name = Home-PC | Source = DCOM | ID = 10005
Description =

Error - 5/31/2010 12:43:24 PM | Computer Name = Home-PC | Source = DCOM | ID = 10005
Description =

Error - 5/31/2010 12:43:25 PM | Computer Name = Home-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 5/31/2010 12:43:25 PM | Computer Name = Home-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 5/31/2010 12:43:58 PM | Computer Name = Home-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 5/31/2010 12:44:00 PM | Computer Name = Home-PC | Source = DCOM | ID = 10005
Description =

Error - 5/31/2010 12:44:00 PM | Computer Name = Home-PC | Source = DCOM | ID = 10005
Description =

Error - 5/31/2010 12:44:01 PM | Computer Name = Home-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 5/31/2010 1:26:01 PM | Computer Name = Home-PC | Source = Service Control Manager | ID = 7000
Description =


< End of report >
3. The log that was produced after running GMER

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-06-01 20:45:41
Windows 6.0.6002 Service Pack 2
Running: jn9ule5l.exe; Driver: C:\Users\Home\AppData\Local\Temp\pxldipow.sys


—- System - GMER 1.0.15 —-

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0x8CA75AC6]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0x8CA758EA]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0x8CA75A24]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject

—- Kernel code sections - GMER 1.0.15 —-

PAGE ntkrnlpa.exe!ZwLoadDriver 81FACDF0 7 Bytes JMP 8CA75A28 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 8201828F 5 Bytes JMP 8CA71536 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObInsertObject 82071038 5 Bytes JMP 8CA72EC2 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!NtCreateSection 820728C3 7 Bytes JMP 8CA758EE \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 820D2892 7 Bytes JMP 8CA75ACA \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Internet Explorer\iexplore.exe[4776] USER32.dll!CreateDialogParamW 758872A2 5 Bytes JMP 100D36CB C:\Program Files\Zynga\tbZyng.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[4776] USER32.dll!CreateWindowExW 75891305 5 Bytes JMP 6DD6DAC4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4776] USER32.dll!DialogBoxParamW 758B10B0 5 Bytes JMP 100D389B C:\Program Files\Zynga\tbZyng.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[4776] USER32.dll!DialogBoxIndirectParamW 758B2EF5 5 Bytes JMP 6DE6473F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4776] USER32.dll!DialogBoxParamA 758C8152 5 Bytes JMP 6DE646DC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4776] USER32.dll!DialogBoxIndirectParamA 758C847D 5 Bytes JMP 6DE647A2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4776] USER32.dll!MessageBoxIndirectA 758DD4D9 5 Bytes JMP 6DE64671 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4776] USER32.dll!MessageBoxIndirectW 758DD5D3 5 Bytes JMP 6DE64606 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4776] USER32.dll!MessageBoxExA 758DD639 5 Bytes JMP 6DE645A4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4776] USER32.dll!MessageBoxExW 758DD65D 5 Bytes JMP 6DE64542 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5964] USER32.dll!CreateDialogParamW 758872A2 5 Bytes JMP 100D36CB C:\Program Files\Zynga\tbZyng.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[5964] USER32.dll!SetWindowsHookExW 758887AD 5 Bytes JMP 6DD69A75 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5964] USER32.dll!CallNextHookEx 75888E3B 5 Bytes JMP 6DD5D101 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5964] USER32.dll!UnhookWindowsHookEx 758898DB 5 Bytes JMP 6DCD466E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5964] USER32.dll!CreateWindowExW 75891305 5 Bytes JMP 6DD6DAC4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5964] USER32.dll!DialogBoxParamW 758B10B0 5 Bytes JMP 100D389B C:\Program Files\Zynga\tbZyng.dll (Conduit Toolbar/Conduit Ltd.)
.text C:\Program Files\Internet Explorer\iexplore.exe[5964] USER32.dll!DialogBoxIndirectParamW 758B2EF5 5 Bytes JMP 6DE6473F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5964] USER32.dll!DialogBoxParamA 758C8152 5 Bytes JMP 6DE646DC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5964] USER32.dll!DialogBoxIndirectParamA 758C847D 5 Bytes JMP 6DE647A2 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5964] USER32.dll!MessageBoxIndirectA 758DD4D9 5 Bytes JMP 6DE64671 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5964] USER32.dll!MessageBoxIndirectW 758DD5D3 5 Bytes JMP 6DE64606 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5964] USER32.dll!MessageBoxExA 758DD639 5 Bytes JMP 6DE645A4 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5964] USER32.dll!MessageBoxExW 758DD65D 5 Bytes JMP 6DE64542 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5964] ole32.dll!OleLoadFromStream 75971E12 5 Bytes JMP 6DE64AA7 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5964] ole32.dll!CoCreateInstance 759A9EA6 5 Bytes JMP 6DD6DB20 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\Windows\system32\services.exe[588] @ C:\Windows\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 001B0002
IAT C:\Windows\system32\services.exe[588] @ C:\Windows\system32\services.exe [KERNEL32.dll!CreateProcessW] 001B0000

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)

AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-

4. An update on how your computer is currently running

No change, still random popup tabs to webs001.com

Thanks again, let me know what the next step is.

jlkoppen
Running ComboFix
Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Ok, combofix log files… ComboFix 10-05-31.02 - Home 06/01/2010 21:45:24.1.1 - x86 Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.1982.930 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: avast! antivirus 4.8.1229 [VPS 081227-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} SP: avast! antivirus 4.8.1229 [VPS 081227-0] *enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\program files\Search Toolbar c:\program files\Search Toolbar\basis.xml c:\program files\Search Toolbar\bg.bmp c:\program files\Search Toolbar\bing_logo.png c:\program files\Search Toolbar\celebrity.png c:\program files\Search Toolbar\drop_images.png c:\program files\Search Toolbar\drop_maps.png c:\program files\Search Toolbar\drop_news.png c:\program files\Search Toolbar\drop_videos.png c:\program files\Search Toolbar\drop_web.png c:\program files\Search Toolbar\facebook.png c:\program files\Search Toolbar\favicon.png c:\program files\Search Toolbar\games.png c:\program files\Search Toolbar\hotmail.png c:\program files\Search Toolbar\icon.ico c:\program files\Search Toolbar\images.png c:\program files\Search Toolbar\include.xml c:\program files\Search Toolbar\info.txt c:\program files\Search Toolbar\lifestyle.png c:\program files\Search Toolbar\maps.png c:\program files\Search Toolbar\messenger.png c:\program files\Search Toolbar\msn.png c:\program files\Search Toolbar\news.png c:\program files\Search Toolbar\SearchToolbar.dll c:\program files\Search Toolbar\SearchToolbarUninstall.exe c:\program files\Search Toolbar\tbcore3.dll c:\program files\Search Toolbar\tbhelper.dll c:\program files\Search Toolbar\twitter.png c:\program files\Search Toolbar\uninstall.exe c:\program files\Search Toolbar\update.exe c:\program files\Search Toolbar\version.txt c:\program files\Search Toolbar\video.png c:\program files\Search Toolbar\videos.png c:\program files\Search Toolbar\weather.png c:\program files\Search Toolbar\web.png c:\programdata\Microsoft\Network\Downloader\qmgr0.dat c:\programdata\Microsoft\Network\Downloader\qmgr1.dat c:\users\Home\AppData\Local\Microsoft\Windows\Temporary Internet Files\-H-m–_GljVxi4 c:\users\Home\AppData\Local\Microsoft\Windows\Temporary Internet Files\F_0sY04-h c:\users\Home\GoToAssistDownloadHelper.exe c:\windows\Downloaded Program Files\popcaploader.inf c:\windows\system32\%appdata% —– BITS: Possible infected sites —– hxxp://i275.photobucket.com . ((((((((((((((((((((((((( Files Created from 2010-05-02 to 2010-06-02 ))))))))))))))))))))))))))))))) . 2010-06-02 02:54 . 2010-06-02 02:54 ——– d—–w- c:\users\TEMP\AppData\Local\temp 2010-06-02 02:54 . 2010-06-02 02:54 ——– d—–w- c:\users\llkool.Home-PC\AppData\Local\temp 2010-06-02 02:54 . 2010-06-02 02:54 ——– d—–w- c:\users\Default\AppData\Local\temp 2010-06-02 02:54 . 2010-06-02 02:54 ——– d—–w- c:\users\llkool\AppData\Local\temp 2010-05-31 17:34 . 2010-05-31 17:34 ——– d—–w- c:\program files\Trend Micro 2010-05-31 14:53 . 2009-06-30 14:37 28552 —-a-w- c:\windows\system32\drivers\pavboot.sys 2010-05-31 14:53 . 2010-05-31 14:53 ——– d—–w- c:\program files\Panda Security 2010-05-29 13:45 . 2010-05-29 13:45 ——– d—–w- c:\programdata\Alwil Software 2010-05-25 22:00 . 2010-04-23 14:13 2048 —-a-w- c:\windows\system32\tzres.dll 2010-05-16 04:52 . 2010-05-16 04:52 ——– d—–w- c:\users\Home\AppData\Local\assembly 2010-05-16 04:50 . 2010-05-16 04:50 ——– d—–w- c:\users\Home\AppData\Local\IsolatedStorage 2010-05-16 04:48 . 2010-05-16 04:50 ——– d—–w- c:\program files\Virtual Earth 3D 2010-05-12 10:30 . 2010-01-29 15:40 738816 —-a-w- c:\windows\system32\inetcomm.dll 2010-05-06 00:55 . 2010-05-06 00:55 ——– d—–w- c:\users\llkool.Home-PC\AppData\Roaming\Malwarebytes 2010-05-05 02:57 . 2010-05-05 02:57 ——– d—–w- c:\users\Home\AppData\Roaming\Malwarebytes 2010-05-05 02:57 . 2010-04-29 20:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-05-05 02:57 . 2010-05-05 02:57 ——– d—–w- c:\programdata\Malwarebytes 2010-05-05 02:57 . 2010-04-29 20:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-05-05 02:57 . 2010-05-05 02:57 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-05-31 17:34 . 2010-05-31 17:34 388096 —-a-r- c:\users\Home\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2010-05-29 13:49 . 2007-11-23 02:22 ——– d—–w- c:\program files\Alwil Software 2010-05-16 00:37 . 2007-11-26 02:18 1104 —-a-w- c:\users\Home\AppData\Roaming\wklnhst.dat 2010-05-13 08:18 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail 2010-05-12 16:21 . 2009-10-02 21:11 221568 ——w- c:\windows\system32\MpSigStub.exe 2010-05-06 20:59 . 2007-11-23 02:23 38848 —-a-w- c:\windows\system32\avastSS.scr 2010-05-06 20:59 . 2007-11-23 02:23 165032 —-a-w- c:\windows\system32\aswBoot.exe 2010-05-06 20:39 . 2007-11-23 02:23 46672 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2010-05-06 20:39 . 2008-05-11 20:23 164048 —-a-w- c:\windows\system32\drivers\aswSP.sys 2010-05-06 20:34 . 2007-11-23 02:23 23376 —-a-w- c:\windows\system32\drivers\aswRdr.sys 2010-05-06 20:34 . 2007-11-23 02:23 51792 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2010-05-06 20:33 . 2008-05-11 20:23 19024 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2010-05-06 01:01 . 2009-09-18 04:04 ——– d—–w- c:\users\llkool.Home-PC\AppData\Roaming\LimeWire 2010-05-05 11:30 . 2010-03-27 00:26 ——– d—–w- c:\program files\Steam 2010-04-29 18:37 . 2007-12-07 02:00 ——– d—–w- c:\programdata\Spybot - Search & Destroy 2010-04-29 12:41 . 2007-12-07 02:00 ——– d—–w- c:\program files\Spybot - Search & Destroy 2010-04-27 19:45 . 2010-04-27 19:45 72856 —-a-w- c:\windows\system32\xliveinstallhost.exe 2010-04-27 19:45 . 2010-04-27 19:45 187544 —-a-w- c:\windows\system32\xliveinstall.dll 2010-04-27 01:21 . 2010-04-27 01:21 84480 —-a-w- c:\users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{896642E4-C556-4ED3-85D1-9AC431603E7D}\components\Engine.dll 2010-04-27 01:21 . 2010-04-27 01:21 56832 —-a-w- c:\users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{896642E4-C556-4ED3-85D1-9AC431603E7D}\chrome\content\id_searchtoolbar\update.exe 2010-04-27 01:21 . 2010-04-27 01:21 42496 —-a-w- c:\users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{896642E4-C556-4ED3-85D1-9AC431603E7D}\chrome\content\id_searchtoolbar\uninstall.exe 2010-04-27 01:21 . 2010-04-27 01:21 301568 —-a-w- c:\users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{896642E4-C556-4ED3-85D1-9AC431603E7D}\chrome\content\id_searchtoolbar\tbhelper.dll 2010-04-27 01:21 . 2010-04-27 01:21 2767360 —-a-w- c:\users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{896642E4-C556-4ED3-85D1-9AC431603E7D}\chrome\content\id_searchtoolbar\tbcore3.dll 2010-04-27 01:21 . 2010-04-27 01:21 152664 —-a-w- c:\users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{896642E4-C556-4ED3-85D1-9AC431603E7D}\components\setup_widget_serv.exe 2010-04-27 01:21 . 2010-04-27 01:21 41984 —-a-w- c:\users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{896642E4-C556-4ED3-85D1-9AC431603E7D}\chrome\content\id_searchtoolbar\SearchToolbar.dll 2010-04-13 13:56 . 2010-04-13 13:56 ——– d—–w- c:\users\Home\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 2010-04-06 22:51 . 2008-09-08 00:44 4118 —-a-w- c:\users\llkool.Home-PC\AppData\Roaming\wklnhst.dat 2010-04-02 22:17 . 2010-04-02 22:17 15426200 —-a-w- c:\windows\system32\xlive.dll 2010-04-02 22:17 . 2010-04-02 22:17 13642904 —-a-w- c:\windows\system32\xlivefnt.dll 2010-03-29 14:59 . 2010-05-11 22:16 52224 —-a-w- c:\users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll 2010-03-29 14:59 . 2010-05-11 22:16 101376 —-a-w- c:\users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll 2010-03-25 23:01 . 2007-11-22 05:12 66368 —-a-w- c:\users\Home\AppData\Local\GDIPFONTCACHEV1.DAT 2010-03-24 18:17 . 2010-03-24 08:04 952768 —-a-w- c:\programdata\Adobe\Reader\9.3\ARM\25197\AdobeARM.exe 2010-03-24 18:17 . 2010-03-24 08:04 952768 —-a-w- c:\programdata\Adobe\Reader\9.3\ARM\20147\AdobeARM.exe 2010-03-24 18:17 . 2010-03-24 08:04 952768 —-a-w- c:\programdata\Adobe\Reader\9.3\ARM\15486\AdobeARM.exe 2010-03-24 18:17 . 2010-03-24 08:04 70584 —-a-w- c:\programdata\Adobe\Reader\9.3\ARM\25197\AdobeExtractFiles.dll 2010-03-24 18:17 . 2010-03-24 08:04 70584 —-a-w- c:\programdata\Adobe\Reader\9.3\ARM\20147\AdobeExtractFiles.dll 2010-03-24 18:17 . 2010-03-24 08:04 70584 —-a-w- c:\programdata\Adobe\Reader\9.3\ARM\15486\AdobeExtractFiles.dll 2010-03-24 18:17 . 2010-03-24 08:04 326056 —-a-w- c:\programdata\Adobe\Reader\9.3\ARM\25197\ReaderUpdater.exe 2010-03-24 18:17 . 2010-03-24 08:04 326056 —-a-w- c:\programdata\Adobe\Reader\9.3\ARM\25197\AcrobatUpdater.exe 2010-03-24 18:17 . 2010-03-24 08:04 326056 —-a-w- c:\programdata\Adobe\Reader\9.3\ARM\20147\ReaderUpdater.exe 2010-03-24 18:17 . 2010-03-24 08:04 326056 —-a-w- c:\programdata\Adobe\Reader\9.3\ARM\20147\AcrobatUpdater.exe 2010-03-24 18:17 . 2010-03-24 08:04 326056 —-a-w- c:\programdata\Adobe\Reader\9.3\ARM\15486\ReaderUpdater.exe 2010-03-24 18:17 . 2010-03-24 08:04 326056 —-a-w- c:\programdata\Adobe\Reader\9.3\ARM\15486\AcrobatUpdater.exe 2010-03-19 22:50 . 2008-05-05 21:14 680 —-a-w- c:\users\llkool.Home-PC\AppData\Local\d3d9caps.dat 2010-03-05 14:01 . 2010-04-14 23:36 420352 —-a-w- c:\windows\system32\vbscript.dll 2009-11-27 23:48 . 2009-11-27 23:48 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll 2007-10-26 00:32 . 2007-10-26 00:23 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{7b13ec3e-999a-4b70-b9cb-2617b8323822}"= "c:\program files\Zynga\tbZyng.dll" [2010-02-22 2353176] [HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7b13ec3e-999a-4b70-b9cb-2617b8323822}] 2010-02-22 17:05 2353176 —-a-w- c:\program files\Zynga\tbZyng.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{7b13ec3e-999a-4b70-b9cb-2617b8323822}"= "c:\program files\Zynga\tbZyng.dll" [2010-02-22 2353176] [HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{7B13EC3E-999A-4B70-B9CB-2617B8323822}"= "c:\program files\Zynga\tbZyng.dll" [2010-02-22 2353176] [HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe" [2009-07-31 468408] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184] "ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-25 17920] "RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 4907008] "PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 118784] "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-11-27 30192] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952] "avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ \0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Digital Line Detect.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk backup=c:\windows\pss\Digital Line Detect.lnk.CommonStartup backupExtension=.CommonStartup [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "VistaSp2"=hex(B):17,56,13,c0,bd,5f,ca,01 R3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2009-11-27 30192] R3 maz500m;maz500m;c:\windows\system32\Drivers\maz500m.sys [2005-06-16 25044] R3 maz500u;maz500u;c:\windows\system32\Drivers\maz500u.sys [2007-01-04 51285] S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-06-30 28552] S1 aswSP;aswSP; [x] S2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-05 77824] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-05-06 51792] S2 atashost;WebEx Service Host for Support Center;c:\windows\system32\atashost.exe [2009-01-13 20376] S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}] 2009-03-08 11:32 128512 —-a-w- c:\windows\System32\advpack.dll . Contents of the 'Scheduled Tasks' folder 2010-05-27 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job - c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2010-04-29 20:31] 2010-05-26 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job - c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2010-04-29 20:31] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com/ mStart Page = hxxp://www.yahoo.com/ mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html TCP: {FD6E879D-9F2B-4120-9841-3A45B077D977} = 8.8.8.8,8.8.4.4 FF - ProfilePath - c:\users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\ FF - prefs.js: browser.search.selectedEngine - Bing FF - prefs.js: browser.startup.homepage - hxxp://bing.zugo.com/?cfg=2-77-0-X35c FF - prefs.js: keyword.URL - hxxp://bing.zugotoolbar.com/s/?iesrc=IE-Address&site;=Bing&q;= FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll FF - component: c:\users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll FF - component: c:\users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll FF - component: c:\users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{896642E4-C556-4ED3-85D1-9AC431603E7D}\components\Engine.dll FF - plugin: c:\program files\GameTap\bin\Release\npgametaptool.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll FF - plugin: c:\users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\[removed]\plugins\npiaplayer.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ —- FIREFOX POLICIES —- c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); . - - - - ORPHANS REMOVED - - - - Toolbar-{0C8413C1-FAD1-446C-8584-BE50576F863E} - c:\program files\Search Toolbar\tbcore3.dll WebBrowser-{0C8413C1-FAD1-446C-8584-BE50576F863E} - c:\program files\Search Toolbar\tbcore3.dll Notify-GoToAssist - c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ———————— Other Running Processes ———————— . c:\windows\system32\nvvsvc.exe c:\windows\system32\rundll32.exe c:\program files\Alwil Software\Avast5\AvastSvc.exe c:\program files\Dell Support Center\bin\sprtsvc.exe c:\windows\system32\DRIVERS\xaudio.exe c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe c:\windows\RtHDVCpl.exe c:\program files\Alwil Software\Avast5\AvastUI.exe c:\windows\system32\wbem\unsecapp.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\windows\servicing\TrustedInstaller.exe . ************************************************************************** . Completion time: 2010-06-01 22:09:22 - machine was rebooted ComboFix-quarantined-files.txt 2010-06-02 03:09 Pre-Run: 8,104,300,544 bytes free Post-Run: 11,348,721,664 bytes free - - End Of File - - 28FFF3EFDB2A66FB5E7DB27D3B39E9B8
Hello,


Malwarebytes' Anti-Malware

I see that you have Malwarebytes' Anti-Malware installed on your computer could you please do a scan using these settings:

  • Open Malwarebytes' Anti-Malware
  • Select the Update tab
  • Click Check for Updates
  • After the update have been completed, Select the Scanner tab.
  • Select Perform quick scan, then click on Scan
  • Leave the default options as it is and click on Start Scan
  • When done, you will be prompted. Click OK, then click on Show Results
  • Checked (ticked) all items and click on Remove Selected
  • After it has removed the items, Notepad will open. Please post this log in your next reply. You can also find the log in the Logs tab. The bottom most log is the latest
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT:



ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]


NEXT:



OTL Custom Scan

We need to run an OTL Custom Scan
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following bolded text into the [external image: Posted Image] textbox.


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /180

  • Push [external image: Posted Image]
  • A report will open. Copy and Paste that report in your next reply.



NEXT:


Please make sure you include the following items in your next post:

1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
2. The log that was produced after running the updated MalwareBytes' Anti-Malware scan.
3. The log that was produced after running the ESET Online Virus Scanner.
4. The log that was produced after running the OTL scan.
5. An update on how your computer is currently running.

It would be helpful if you could answer each question in the order asked, as well as numbering your answers.

Cheers,
SweetTech.
Hello SweetTech, just an FYI the online scanner is taking a lot of time to run so it's likely I will not have results to post until morning. Interesting to note the online scanner has found various threats the other scans have not, so I'm hopeful we're getting closer to the problem. jlkoppen
MBAM scan results Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4165 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18904 6/2/2010 8:19:40 PM mbam-log-2010-06-02 (20-19-40).txt Scan type: Quick scan Objects scanned: 144775 Time elapsed: 13 minute(s), 39 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ESET online scan results C:\Users\Home\Documents\LimeWire\Incomplete\T-5190865-love def leppard [new single].au a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Users\llkool.Home-PC\Downloads\ChameleonTom(2).exe Win32/Adware.Primawega.AC.Gen application C:\Users\llkool.Home-PC\Downloads\ChameleonTom.exe Win32/Adware.Primawega.AC.Gen application
OLT scan results

OTL logfile created on: 6/3/2010 12:24:20 AM - Run 2
OTL by OldTimer - Version 3.2.5.3 Folder = C:\Users\Home\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 34.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 57.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 64.46 Gb Total Space | 10.04 Gb Free Space | 15.58% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 7.00 Gb Free Space | 70.05% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOME-PC
Current User Name: Home
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Home\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil10d.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe ()
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Windows\System32\atashost.exe (WebEx Communications, Inc.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\AERTSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)


========== Modules (SafeList) ==========

MOD - C:\Users\Home\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (GoogleDesktopManager-110309-193829) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (atashost) – C:\Windows\System32\atashost.exe (WebEx Communications, Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AERTFilters) – C:\Windows\System32\AERTSrv.exe (Andrea Electronics Corporation)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()


========== Driver Services (SafeList) ==========

DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (pavboot) – C:\Windows\system32\drivers\pavboot.sys (Panda Security, S.L.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (X4HSX32) – C:\Program Files\GameTap\bin\Release\X4HSX32.sys (Exent Technologies Ltd.)
DRV - (xnacc) – C:\Windows\System32\drivers\xnacc.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (xusb21) – C:\Windows\System32\drivers\xusb21.sys (Microsoft Corporation)
DRV - (nvstor32) – C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (dsunidrv) – C:\Windows\System32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (ENETHUSB) – C:\Windows\System32\drivers\enethusb.sys (Siemens Subscriber Networks, Inc.)
DRV - (MaVctrl) – C:\Windows\System32\drivers\MaVc2K.sys (Mobile Action Technology Inc.)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (maz500u) – C:\Windows\System32\drivers\maz500u.sys (Mobile Action Technology Inc.)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (winusb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWBS2) – C:\Windows\System32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (sscdmdm) – C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\Windows\System32\drivers\sscdbus.sys (MCCI)
DRV - (maz500m) – C:\Windows\System32\drivers\maz500m.sys (Mobile Action Technology Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.google.com/ig/dell?hl=en&cl;…amp;ibd=4071026
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.startup.homepage: "http://bing.zugo.com/?cfg=2-77-0-X35c"
FF - prefs.js..extensions.enabledItems: [removed]:0.4.1.1
FF - prefs.js..extensions.enabledItems: {f0178163-d454-7451-6914-3ddfbc0cdfe6}:[removed]
FF - prefs.js..extensions.enabledItems: {896642E4-C556-4ED3-85D1-9AC431603E7D}:1.0.4
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.5.8.6
FF - prefs.js..keyword.URL: "http://bing.zugotoolbar.com/s/?iesrc=IE-Address&site;=Bing&q;="


FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/11 12:54:00 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/11 12:54:00 | 000,000,000 | —D | M]

[2009/11/04 17:40:27 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Mozilla\Extensions
[2010/05/23 21:03:57 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions
[2009/12/10 23:35:41 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/05/11 17:16:39 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2010/04/26 20:21:56 | 000,000,000 | —D | M] (Search Toolbar) – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{896642E4-C556-4ED3-85D1-9AC431603E7D}
[2010/02/04 13:04:15 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\[removed]
[2010/04/26 20:21:57 | 000,000,737 | —- | M] () – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\searchplugins\bing-ff.xml
[2010/04/26 20:22:13 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/26 20:22:13 | 000,000,000 | —D | M] (LoudMo Contextual Ad Assistant) – C:\Program Files\Mozilla Firefox\extensions\{f0178163-d454-7451-6914-3ddfbc0cdfe6}

O1 HOSTS File: ([2010/06/01 21:58:06 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (WitBHO Class) - {75ED56AF-4DC9-4243-A30C-4EF4DD0CA28F} - C:\Program Files\ChameleonTom\wit4ie.dll File not found
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (TBSB05974 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Search Toolbar\tbcore3.dll File not found
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Zynga Toolbar) - {7B13EC3E-999A-4B70-B9CB-2617B8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [ECenter] C:\DELL\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -Mozilla\4.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident\4.0; File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} http://support.dell.com/systemprofiler/SysProExe.CAB (WMI Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {DB7BF79A-FC51-4B5A-92BC-A65731174380} http://www.instantaction.com/download/iaplayer.cab (InstantAction Game Launcher)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://frontier.webex.com/client/T26L/support/ieatgpc1.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Home\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Home\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{6df2fdd0-a455-11dc-a688-001aa05eef43}\Shell\AutoRun\command - "" = F:\setupSNK.exe – File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2008/10/01 03:13:09 | 000,000,000 | —D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/06/02 20:28:59 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/06/01 21:42:19 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2010/06/01 21:42:19 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2010/06/01 21:42:19 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2010/06/01 21:42:15 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/06/01 21:40:14 | 000,000,000 | —D | C] – C:\Qoobox
[2010/06/01 21:39:58 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2010/06/01 19:50:36 | 000,571,904 | —- | C] (OldTimer Tools) – C:\Users\Home\Desktop\OTL.exe
[2010/05/31 12:34:34 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/05/31 10:41:12 | 000,998,736 | —- | C] (Kaspersky Lab) – C:\Users\Home\Desktop\TDSSKiller.exe
[2010/05/31 09:53:07 | 000,028,552 | —- | C] (Panda Security, S.L.) – C:\Windows\System32\drivers\pavboot.sys
[2010/05/31 09:53:03 | 000,000,000 | —D | C] – C:\Program Files\Panda Security
[2010/05/29 08:45:29 | 000,000,000 | —D | C] – C:\ProgramData\Alwil Software
[2010/05/25 17:00:49 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/05/15 23:52:11 | 000,000,000 | —D | C] – C:\Users\Home\AppData\Local\assembly
[2010/05/15 23:50:58 | 000,000,000 | —D | C] – C:\Users\Home\AppData\Local\IsolatedStorage
[2010/05/15 23:48:24 | 000,000,000 | —D | C] – C:\Program Files\Virtual Earth 3D
[2010/05/04 21:57:13 | 000,000,000 | —D | C] – C:\Users\Home\AppData\Roaming\Malwarebytes
[2010/05/04 21:57:04 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/05/04 21:57:03 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/05/04 21:57:02 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/05/04 21:57:01 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/06/03 00:29:19 | 006,553,600 | -HS- | M] () – C:\Users\Home\ntuser.dat
[2010/06/02 22:53:11 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/02 22:53:11 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/02 20:04:37 | 000,524,288 | -HS- | M] () – C:\Users\Home\ntuser.dat{6ee29a04-1b3e-11de-b98e-001aa05eef43}.TMContainer00000000000000000001.regtrans-ms
[2010/06/02 20:04:37 | 000,065,536 | -HS- | M] () – C:\Users\Home\ntuser.dat{6ee29a04-1b3e-11de-b98e-001aa05eef43}.TM.blf
[2010/06/02 03:00:28 | 000,000,316 | —- | M] () – C:\Windows\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2010/06/01 22:53:15 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/06/01 22:53:04 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/06/01 22:53:01 | 2078,793,728 | -HS- | M] () – C:\hiberfil.sys
[2010/06/01 22:51:55 | 001,632,483 | -H– | M] () – C:\Users\Home\AppData\Local\IconCache.db
[2010/06/01 22:13:02 | 000,690,960 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/06/01 22:13:02 | 000,595,446 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/06/01 22:13:02 | 000,101,144 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/06/01 21:58:29 | 000,000,286 | —- | M] () – C:\Windows\system.ini
[2010/06/01 21:58:06 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/06/01 19:50:45 | 000,293,376 | —- | M] () – C:\Users\Home\Desktop\jn9ule5l.exe
[2010/06/01 19:50:39 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\Home\Desktop\OTL.exe
[2010/06/01 16:33:40 | 000,000,236 | —- | M] () – C:\Users\Home\Desktop\DAN-gh..url
[2010/05/31 20:31:02 | 003,701,914 | R— | M] () – C:\Users\Home\Desktop\ComboFix.exe
[2010/05/31 20:28:37 | 000,998,736 | —- | M] (Kaspersky Lab) – C:\Users\Home\Desktop\TDSSKiller.exe
[2010/05/31 12:34:55 | 000,002,521 | —- | M] () – C:\Users\Home\Desktop\HiJackThis.lnk
[2010/05/31 12:33:17 | 001,402,880 | —- | M] () – C:\Users\Home\Desktop\HiJackThis.msi
[2010/05/31 11:21:19 | 000,001,087 | —- | M] () – C:\Users\Home\Desktop\Spybot - Search & Destroy.lnk
[2010/05/29 08:47:00 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2010/05/29 08:47:00 | 000,001,842 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/05/29 08:43:47 | 051,731,232 | —- | M] () – C:\Users\Home\Desktop\setup_av_free.exe
[2010/05/27 03:00:00 | 000,000,308 | —- | M] () – C:\Windows\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2010/05/23 21:09:40 | 000,006,866 | —- | M] () – C:\Users\Home\Desktop\Outer lines.rtf
[2010/05/22 19:40:47 | 000,033,094 | —- | M] () – C:\Users\Home\Desktop\DF-Spider_Sound.ogg
[2010/05/16 00:31:52 | 000,018,432 | —- | M] () – C:\Users\Home\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/15 23:50:34 | 000,001,891 | —- | M] () – C:\Users\Public\Desktop\Bing Maps 3D.lnk
[2010/05/15 19:37:11 | 003,852,800 | —- | M] () – C:\Users\Home\Desktop\The Rodwell Line.wps
[2010/05/15 19:37:11 | 000,001,104 | —- | M] () – C:\Users\Home\AppData\Roaming\wklnhst.dat
[2010/05/12 11:21:16 | 000,221,568 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2010/05/06 15:59:57 | 000,038,848 | —- | M] (ALWIL Software) – C:\Windows\System32\avastSS.scr
[2010/05/06 15:59:36 | 000,165,032 | —- | M] (ALWIL Software) – C:\Windows\System32\aswBoot.exe
[2010/05/06 15:39:23 | 000,046,672 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswTdi.sys
[2010/05/06 15:39:00 | 000,164,048 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswSP.sys
[2010/05/06 15:34:27 | 000,023,376 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswRdr.sys
[2010/05/06 15:34:10 | 000,051,792 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2010/05/06 15:33:47 | 000,019,024 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2010/05/05 20:21:16 | 000,393,216 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100505-202428.backup
[2010/05/05 20:18:35 | 000,393,216 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100505-202116.backup
[2010/05/04 21:57:06 | 000,000,820 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/01 21:42:19 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2010/06/01 21:42:19 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2010/06/01 21:42:19 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2010/06/01 21:42:19 | 000,077,312 | —- | C] () – C:\Windows\MBR.exe
[2010/06/01 21:42:19 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2010/06/01 19:50:35 | 000,293,376 | —- | C] () – C:\Users\Home\Desktop\jn9ule5l.exe
[2010/05/31 20:30:55 | 003,701,914 | R— | C] () – C:\Users\Home\Desktop\ComboFix.exe
[2010/05/31 12:34:34 | 000,002,521 | —- | C] () – C:\Users\Home\Desktop\HiJackThis.lnk
[2010/05/31 12:33:06 | 001,402,880 | —- | C] () – C:\Users\Home\Desktop\HiJackThis.msi
[2010/05/31 12:25:30 | 2078,793,728 | -HS- | C] () – C:\hiberfil.sys
[2010/05/29 08:47:00 | 000,001,842 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/05/29 08:43:42 | 051,731,232 | —- | C] () – C:\Users\Home\Desktop\setup_av_free.exe
[2010/05/23 21:09:40 | 000,006,866 | —- | C] () – C:\Users\Home\Desktop\Outer lines.rtf
[2010/05/22 19:40:46 | 000,033,094 | —- | C] () – C:\Users\Home\Desktop\DF-Spider_Sound.ogg
[2010/05/15 23:50:34 | 000,001,891 | —- | C] () – C:\Users\Public\Desktop\Bing Maps 3D.lnk
[2010/05/05 20:07:07 | 000,000,316 | —- | C] () – C:\Windows\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2010/05/05 20:05:15 | 000,000,308 | —- | C] () – C:\Windows\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2010/05/04 21:57:06 | 000,000,820 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/02 17:17:34 | 000,179,091 | —- | C] () – C:\Windows\System32\xlive.dll.cat
[2009/09/11 01:57:46 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/03/19 09:05:30 | 000,000,110 | —- | C] () – C:\Windows\TLCAPPS.INI
[2009/03/08 15:37:48 | 000,000,343 | —- | C] () – C:\Windows\WININIT.INI
[2009/03/08 15:37:28 | 000,000,068 | —- | C] () – C:\Windows\SLS.INI
[2008/09/19 16:57:34 | 003,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2008/09/19 16:55:10 | 000,000,416 | —- | C] () – C:\Windows\System32\dtu100.dll.manifest
[2008/09/19 16:55:10 | 000,000,416 | —- | C] () – C:\Windows\System32\dpl100.dll.manifest
[2008/09/19 16:54:18 | 000,012,288 | —- | C] () – C:\Windows\System32\DivXWMPExtType.dll
[2008/05/27 00:15:08 | 000,001,325 | —- | C] () – C:\Windows\Remove.ini
[2008/05/26 21:32:40 | 000,000,000 | —- | C] () – C:\Windows\I531_109.INI
[2007/03/19 05:04:58 | 000,003,584 | —- | C] () – C:\Windows\System32\namResES.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResIT.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResFR.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResENG.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResDE.dll
[2007/03/19 05:04:56 | 000,003,584 | —- | C] () – C:\Windows\System32\namResPTB.dll
[2007/03/19 05:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHC.dll
[2007/03/19 05:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResKO.dll
[2007/03/19 05:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResJA.dll
[2007/03/19 05:04:54 | 000,022,016 | —- | C] () – C:\Windows\System32\nam_page.dll
[2007/03/19 05:04:54 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHT.dll
[2006/11/02 05:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 16:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/11/10 16:59:07 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2010/06/01 22:09:23 | 000,020,591 | —- | M] () – C:\ComboFix.txt
[2006/09/18 16:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2007/10/25 19:32:57 | 000,004,095 | RH– | M] () – C:\dell.sdr
[2010/06/01 22:53:01 | 2078,793,728 | -HS- | M] () – C:\hiberfil.sys
[2008/05/26 13:44:41 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/05/26 13:44:41 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/06/01 22:52:59 | 2392,596,480 | -HS- | M] () – C:\pagefile.sys
[2007/11/22 20:39:20 | 000,008,947 | —- | M] () – C:\SSInst.log
[2010/05/31 20:33:35 | 000,054,618 | —- | M] () – C:\TDSSKiller.2.3.2.0_31.05.2010_20.33.14_log.txt
[2008/06/27 15:08:30 | 000,000,000 | —- | M] () – C:\wizard.txt
[2007/12/28 22:28:01 | 000,000,158 | —- | M] () – C:\YServer.txt

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/03/08 06:31:42 | 000,348,160 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\dxtmsft.dll
[2009/03/08 06:31:37 | 000,216,064 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\dxtrans.dll
[2010/02/23 01:33:44 | 000,184,320 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\iepeers.dll
[2009/04/11 01:27:47 | 000,241,128 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\rsaenh.dll
[2009/04/11 01:28:23 | 000,228,352 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\System32\SLC.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2006/11/02 05:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 05:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 05:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %systemroot%\system32\drivers\*.sys /180 >
[2010/05/06 15:33:47 | 000,019,024 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2010/05/06 15:34:10 | 000,051,792 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2010/05/06 15:34:27 | 000,023,376 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswRdr.sys
[2010/05/06 15:39:00 | 000,164,048 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswSP.sys
[2010/05/06 15:39:23 | 000,046,672 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswTdi.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/02/23 06:10:13 | 000,106,496 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb.sys
[2010/02/23 06:10:19 | 000,212,992 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb10.sys
[2010/02/23 06:10:13 | 000,079,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb20.sys
[2009/12/11 06:43:30 | 000,302,080 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srv.sys
[2009/12/11 06:43:11 | 000,098,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srvnet.sys
[2010/02/18 09:07:16 | 000,904,576 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tcpip.sys
[2009/12/08 12:26:18 | 000,030,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tcpipreg.sys
[2010/02/18 06:28:13 | 000,025,088 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tunnel.sys

========== Alternate Data Streams ==========

@Alternate Data Stream - 777 bytes -> C:\Users\Home\Desktop\RE_ Rushton Family .eml:OECustomProperty
@Alternate Data Stream - 741 bytes -> C:\Users\Home\Desktop\More pictures.eml:OECustomProperty
< End of report >


jlkoppen
Hello,

Java Outdated
Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Look for "JDK 6 Update 20 (JDK or JRE)".
  • Click the "Download JRE" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Under Required Files, check the box for Windows Offline Installation, click the link below it and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u20-windows-i586.exe to install the newest version.
  • If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
  • When the Java Setup - Welcome window opens, click the Install > button.
  • If offered to install a Toolbar, just uncheck the box before continuing unless you want it.
– Starting with Java 6u10, the uninstaller incorporated in each new release uses Enhanced Auto update to automatically remove the previous version when updating to a later update release. It will not remove older versions, so they will need to be removed manually.
– Java is updated frequently. If you want to be automatically notified of future updates, just turn on the Java Automatic Update feature and you will not have to remember to update when Java releases a new version.


Note:
The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications.
To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter.
Click Ok and reboot your computer.


NEXT



Clean Java Cache & Temporary Files
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window

    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT



OTL Fix

We need to run an OTL Fix
  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    :OTL
    [2010/04/26 20:22:13 | 000,000,000 | —D | M] (LoudMo Contextual Ad Assistant) – C:\Program Files\Mozilla Firefox\extensions\{f0178163-d454-7451-6914-3ddfbc0cdfe6}
    O2 - BHO: (WitBHO Class) - {75ED56AF-4DC9-4243-A30C-4EF4DD0CA28F} - C:\Program Files\ChameleonTom\wit4ie.dll File not found
    O2 - BHO: (TBSB05974 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Search Toolbar\tbcore3.dll File not found
    O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -Mozilla\4.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident\4.0; File not found
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
    O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
    O33 - MountPoints2\{6df2fdd0-a455-11dc-a688-001aa05eef43}\Shell\AutoRun\command - "" = F:\setupSNK.exe – File not found
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
    [2010/06/01 19:50:45 | 000,293,376 | —- | M] () – C:\Users\Home\Desktop\jn9ule5l.exe
    
    :Files
    C:\Users\Home\Documents\LimeWire\Incomplete\T-5190865-love def leppard [new single].au
    C:\Users\llkool.Home-PC\Downloads\ChameleonTom(2).exe
    C:\Users\llkool.Home-PC\Downloads\ChameleonTom.exe
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [start explorer]
    [Reboot]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.


NEXT:



Update FireFox
While in Firefox go to the Help menu.
Locate Check for Updates.
Allow Firefox to install the latest update. Which is 3.6.3



NEXT:



Security Check
Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Hello SweetTech,

I updated the Java JRE and cleaned out the cache per your instructions. I also updated Mozilla Firefox, although I rarely use that. Here are the results of the OLT scan…

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
C:\Program Files\Mozilla Firefox\extensions\{f0178163-d454-7451-6914-3ddfbc0cdfe6}\components folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{f0178163-d454-7451-6914-3ddfbc0cdfe6}\chrome folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\{f0178163-d454-7451-6914-3ddfbc0cdfe6} folder moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75ED56AF-4DC9-4243-A30C-4EF4DD0CA28F}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{75ED56AF-4DC9-4243-A30C-4EF4DD0CA28F}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Shockwave Updater deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\localhost\ deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\GD\\http deleted successfully.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
C:\Windows\Downloaded Program Files\gp.inf not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6df2fdd0-a455-11dc-a688-001aa05eef43}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6df2fdd0-a455-11dc-a688-001aa05eef43}\ not found.
File F:\setupSNK.exe not found.
C:\Windows\msdownld.tmp\AS66C80C.tmp folder deleted successfully.
C:\Windows\msdownld.tmp folder deleted successfully.
C:\Users\Home\Desktop\jn9ule5l.exe moved successfully.
========== FILES ==========
C:\Users\Home\Documents\LimeWire\Incomplete\T-5190865-love def leppard [new single].au moved successfully.
C:\Users\llkool.Home-PC\Downloads\ChameleonTom(2).exe moved successfully.
C:\Users\llkool.Home-PC\Downloads\ChameleonTom.exe moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Home
->Temp folder emptied: 418196 bytes
->Temporary Internet Files folder emptied: 90025706 bytes
->Java cache emptied: 4515262 bytes
->FireFox cache emptied: 39342117 bytes
->Flash cache emptied: 577978 bytes

User: llkool
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 1470351 bytes
->Flash cache emptied: 3806 bytes

User: llkool.Home-PC
->Temp folder emptied: 191991 bytes
->Temporary Internet Files folder emptied: 97720872 bytes
->Java cache emptied: 100727334 bytes
->FireFox cache emptied: 84899113 bytes
->Flash cache emptied: 752186 bytes

User: Public
->Temp folder emptied: 0 bytes

User: TEMP
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3001 bytes
RecycleBin emptied: 1603859211 bytes

Total Files Cleaned = 1,931.00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Home
->Flash cache emptied: 0 bytes

User: llkool
->Flash cache emptied: 0 bytes

User: llkool.Home-PC
->Flash cache emptied: 0 bytes

User: Public

User: TEMP

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.5.3 log created on 06032010_195759

Files\Folders moved on Reboot…
C:\Users\Home\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NUQCMCKS\banner[1].htm moved successfully.
C:\Users\Home\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NUQCMCKS\iframe[1].htm moved successfully.
C:\Users\Home\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NUQCMCKS\xd_receiver[1].htm moved successfully.
C:\Users\Home\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BHIS7LB6\login_status[1].htm moved successfully.
C:\Users\Home\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3PYB9QFQ\Help_hidden_spyware_malware_t112362[1].html moved successfully.
C:\Users\Home\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
File move failed. C:\Windows\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.
File move failed. C:\Windows\temp\WebEx\Log\63\atashost.log scheduled to be moved on reboot.

Registry entries deleted on Reboot…

Here is the Security Check scan result…

Results of screen317's Security Check version 0.99.4
Windows Vista Service Pack 2 (UAC is enabled)
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
avast! Free Antivirus
ESET Online Scanner v3
Antivirus up to date!
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
Java™ 6 Update 20
Adobe Flash Player 10.0.32.18
Adobe Reader 9.3
Mozilla Firefox (3.5.9) Firefox Out of Date!
````````````````````````````````
Process Check:
objlist.exe by Laurent

Windows Defender MSASCui.exe
Windows Defender MSASCui.exe
Alwil Software Avast5 AvastSvc.exe
Alwil Software Avast5 AvastUI.exe
````````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

``````````End of Log````````````


FWIW, I have not seen the popup appear recently, we may have killed that.

jlkoppen
Hello,

If you have no further issues with your computer, then please proceed with the following housekeeping procedures outlined below.



NEXT:



Time for some housekeeping
The following will implement some cleanup procedures as well as reset System Restore points:

Click Start > Run and copy/paste the following bolded text into the Run box and click OK: ComboFix /Uninstall



NEXT:



OTL Clean-Up
Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.



NEXT:



All Clean Speech

===> Make sure you've re-enabled any Security Programs that we may have disabled during the malware removal process. <===

Below I have included a number of recommendations for how to protect your computer against malware infections.
  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at: http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.
  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.
  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.
  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE
  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from Here
    • If you choose to use Firefox, I highly recommend this add-on to keep your PC even more secure.
      • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.

Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

Cheers,
SweetTech.
SweetTech, Thanks for you help, I been through several reboot and checks and see no further sign of malware. No popups, redirects, etc. I have most of the recommendations already implemented. I will consider hiding IE and using Firefox only, as I have not run into too many compatibility problems. I will try WOT, it looks interesting. Is there any advantage to the other spy/malware progs over Spybot SD & Teatimer? I've used this and AVAST for years, so it's what I am most familar with, but if there is another superior product, I'd be willing to change it. Thanks again! jlkoppen

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI