This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus keeps showing up on Avast

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello. I am using Avast free version antivirus and I get alert messages saying that I've been infected. I run Comodo a couple of times and it stops for a little while but not long. Also, when I do a search and I click on a link I often get redirected to generic sites. Any help would be appreciated. Thank you.

Here is a copy of the HJT logfile:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:40:07 PM, on 6/10/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\ahead\InCD\InCD.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\PROGRA~1\Alwil Software\Avast4\ashDisp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
G:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\WINDOWS\system32\java.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [IPInSightMonitor 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Alwil Software\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "G:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "G:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Chat -
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) -
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} -
O16 - DPF: {2CFB52FD-7CF2-479C-BF65-B27F8A834F31} (SecureSession Class) -
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) -
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} -
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) -
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} -
O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} (UploadListView Class) - http://picasaweb.google.com/s/v/59.04/uploader2.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) -
O16 - DPF: {515DA9EC-7B03-3F80-D87E-3DB976424323} -
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
O16 - DPF: {7440672B-1B25-7D3F-E4E5-495D702279D7} -
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} -
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} -
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} -
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) -
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} (Office Update Installation Engine) -
O16 - DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} (Java Plug-in 1.6.0_10) -
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} -
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} -
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} -
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} -
O16 - DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: 28fd0830899 - C:\WINDOWS\system32\comuid32.dllcht1532.dll21lsrykyexn6gcx32.dlllyyhn62q32.dll9gct9jw7032.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate1c9ecbd4ae4c310) (gupdate1c9ecbd4ae4c310) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\KEVINL~1\LOCALS~1\Temp\hpdj.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\ahead\InCD\InCDsrv.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Linksys Updater (LinksysUpdater) - Unknown owner - C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPcservice.exe

–
End of file - 11834 bytes
Hello and welcome to What The Tech.

I am currently assessing your situation and will be back with a fix for your problem as soon as possible.

Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this, click Options, then click Track this topic. Please select Immediate Email Notification for the topic subscription, then click Proceed.

Please be patient with me during this time.
Hello cklenertz :),

Welcome to What The Tech. I am Jack&Jill, and I will be helping you out.

Before we go further, there are a few things that I would like to make clear so that we are share the same understanding.
  • Please observe and follow these Terms of Use and the rules in Are you Infected? Getting Started: How To Get Help.
  • Any advice is for your computer only and is taken at your own risk. Fixes sometimes will cause unexpected results, but I will do my best to assist you.
  • Please read the instructions carefully and follow them closely, in the order they are presented to you.
  • If you have any doubts or problems during the fix, please stop and ask.
  • All the tools that I will ask you to download and use are safe. Please allow if prompted by any of your security softwares.
  • Do not use or run any malware cleaning tools without supervision as they may cause more harm if improperly used.
  • Refrain from installing any new programs except those that I request during the fix to prevent interference to my diagnosis of the problem.
  • Lack of malware symptoms does not mean your computer is clean. Stick to this topic until I give the All Clear.
  • If you do not reply within 3 days, this topic will be closed.
If you are agreeable to the above, then everything should go smoothly :) . We may begin.

——————–

Please download OTL© by OldTimer and save it to your desktop. Click here.
  • Double click on OTL.exe to run it.
  • Make sure all the Use SafeList options is checked (ticked). There are six of them.
  • Check Scan All Users.
  • At the lower right corner, check LOP Check and Purity Check.
  • Click on Run Scan at the top left hand corner. This might take a while.
  • When done, two Notepad files will open. Please post the contents of these 2 Notepad files in your next reply. One log per reply please.
    Note: These files are saved as OTL.txt and Extras.txt on the desktop.
——————–

Please close all programs and do not run any others before and during the GMER scan. Do not use the computer for anything else until after the scan is completed.

Please download GMER and save it to your desktop. Click here.
  • Please disable your real time protection of any Antivirus, Antispyware or Antimalware programs temporarily when running GMER. They may cause the computer to freeze.
  • If you need help to disable your protection programs see here.
  • Double click the .exe file. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan, click on No.
  • In the right panel, you will see several boxes that have been checked (ticked).
    • Uncheck IAT/EAT
    • Uncheck All other Drives/Partitions except C:\ (leave C:\ checked)
    • Uncheck Show All (don't miss this one)
  • Then click the Scan button and wait for it to finish.
  • Once done, click on the Save… button and save it as "Gmer.txt" at a convenient location. Post the contents of that report.
  • Enable back your security softwares as soon as you completed the GMER steps.
    Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries.
——————–

Go to C:\Program Files\Alwil Software\Avast4\DATA\report and open up Resident protection.txt. Find the range of dates when you experienced the alerts and copy and paste the information here. The log might be quite long, but I do not need all of the contents. Just those dates with the alerts would do.

——————–

Please post back:
1. the OTL logs (OTL.txt and Extras.txt)
2. GMER result
3. Avast log
Jack&Jill;,
Thanks for your time.

OTL.txt Report:

OTL logfile created on: 6/11/2010 5:36:50 PM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\Kevin Lenertz\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 54.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.28 Gb Total Space | 11.60 Gb Free Space | 30.31% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 39.06 Gb Total Space | 36.82 Gb Free Space | 94.26% Space Free | Partition Type: NTFS
Drive G: | 126.96 Gb Total Space | 75.96 Gb Free Space | 59.83% Space Free | Partition Type: NTFS
Drive H: | 67.74 Gb Total Space | 55.21 Gb Free Space | 81.51% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded

Computer Name: LENERTZ
Current User Name: Kevin Lenertz
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/06/11 17:35:51 | 000,572,416 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Kevin Lenertz\My Documents\Downloads\OTL.exe
PRC - [2010/04/16 08:33:40 | 000,144,672 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/04/02 17:52:46 | 000,910,296 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/12/17 18:14:06 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\system32\java.exe
PRC - [2009/11/24 16:51:40 | 000,081,000 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009/11/24 16:51:35 | 000,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009/11/24 16:51:21 | 000,254,040 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/11/24 16:48:48 | 000,352,920 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2009/11/24 16:43:56 | 000,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2008/12/12 18:06:40 | 000,642,856 | —- | M] (Cisco Systems, Inc.) – C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
PRC - [2008/11/13 12:43:49 | 000,204,800 | —- | M] () – C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2006/11/03 19:20:12 | 000,866,584 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2006/11/03 19:19:58 | 000,013,592 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MsMpEng.exe
PRC - [2005/04/12 11:15:30 | 001,383,936 | —- | M] (Nero AG) – C:\Program Files\ahead\InCD\InCD.exe
PRC - [2005/04/12 11:15:04 | 000,869,376 | —- | M] (Nero AG) – C:\Program Files\ahead\InCD\InCDsrv.exe
PRC - [2004/12/22 02:09:44 | 000,077,824 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\SOUNDMAN.EXE
PRC - [2003/06/26 19:50:24 | 000,126,976 | —- | M] (Hewlett-Packard Company) – C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
PRC - [2003/06/11 01:52:26 | 000,122,880 | —- | M] (Visual Networks) – C:\Program Files\Visual Networks\Visual IP InSight\SBC\ipmon32.exe


========== Modules (SafeList) ==========

MOD - [2010/06/11 17:35:51 | 000,572,416 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Kevin Lenertz\My Documents\Downloads\OTL.exe
MOD - [2008/04/13 17:10:20 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msscript.ocx
MOD - [2003/06/11 01:52:24 | 000,098,304 | —- | M] (Visual Networks) – C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPHk2KS2.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – – (SQLBrowser)
SRV - File not found [Disabled | Stopped] – – (MSSQLServerADHelper)
SRV - File not found [Disabled | Stopped] – – (MSSQL$MSSMLBIZ) SQL Server (MSSMLBIZ)
SRV - [2010/04/16 08:33:40 | 000,144,672 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2009/11/24 16:51:35 | 000,138,680 | —- | M] (ALWIL Software) [Auto | Running] – C:\Program Files\Alwil Software\Avast4\ashServ.exe – (avast! Antivirus)
SRV - [2009/11/24 16:51:21 | 000,254,040 | —- | M] (ALWIL Software) [On_Demand | Running] – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe – (avast! Mail Scanner)
SRV - [2009/11/24 16:48:48 | 000,352,920 | —- | M] (ALWIL Software) [On_Demand | Running] – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe – (avast! Web Scanner)
SRV - [2009/11/24 16:43:56 | 000,018,752 | —- | M] (ALWIL Software) [Auto | Running] – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe – (aswUpdSv)
SRV - [2009/11/06 10:18:50 | 000,051,168 | —- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] – C:\Program Files\NOS\bin\getPlus_Helper.dll – (getPlusHelper) getPlus®
SRV - [2009/09/23 14:38:18 | 000,935,208 | —- | M] (Nero AG) [On_Demand | Stopped] – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe – (Nero BackItUp Scheduler 4.0)
SRV - [2009/02/25 18:06:42 | 000,013,088 | —- | M] (Intuit Inc.) [On_Demand | Stopped] – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe – (IntuitUpdateService)
SRV - [2008/12/12 18:06:40 | 000,642,856 | —- | M] (Cisco Systems, Inc.) [Auto | Running] – C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe – (nmservice)
SRV - [2008/11/13 12:43:49 | 000,204,800 | —- | M] () [Auto | Running] – C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe – (LinksysUpdater)
SRV - [2006/11/03 19:19:58 | 000,013,592 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MsMpEng.exe – (WinDefend)
SRV - [2005/11/14 01:06:04 | 000,069,632 | —- | M] (Macrovision Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe – (IDriverT)
SRV - [2005/04/12 11:15:04 | 000,869,376 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files\ahead\InCD\InCDsrv.exe – (InCDsrv)
SRV - [2003/08/11 01:07:30 | 000,278,528 | —- | M] (HP) [On_Demand | Stopped] – C:\WINDOWS\system32\hpdj – (hpdj)
SRV - [2003/05/19 16:07:38 | 000,086,016 | —- | M] (Yahoo! Inc.) [On_Demand | Stopped] – C:\WINDOWS\system32\YPcservice.exe – (YPCService)


========== Driver Services (SafeList) ==========

DRV - [2009/11/24 16:49:07 | 000,048,560 | —- | M] (ALWIL Software) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\aswTdi.sys – (aswTdi)
DRV - [2009/11/24 16:48:57 | 000,023,120 | —- | M] (ALWIL Software) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\aswRdr.sys – (aswRdr)
DRV - [2009/11/24 16:47:54 | 000,027,408 | —- | M] (ALWIL Software) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\aavmker4.sys – (Aavmker4)
DRV - [2009/09/15 04:56:14 | 000,094,160 | —- | M] (ALWIL Software) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\aswmon2.sys – (aswMon2)
DRV - [2009/09/15 04:55:30 | 000,114,768 | —- | M] (ALWIL Software) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\aswSP.sys – (aswSP)
DRV - [2009/09/15 04:55:19 | 000,020,560 | —- | M] (ALWIL Software) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\aswFsBlk.sys – (aswFsBlk)
DRV - [2009/05/07 00:04:50 | 000,157,712 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\tmcomm.sys – (tmcomm)
DRV - [2009/04/23 17:24:26 | 000,016,640 | —- | M] (Wondershare) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\WsAudio_DeviceS(1).sys – (WsAudio_DeviceS(1)) WsAudio_DeviceS(1)
DRV - [2009/04/22 14:28:08 | 000,008,704 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\epmntdrv.sys – (epmntdrv)
DRV - [2009/04/22 14:28:06 | 000,003,072 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\EuGdiDrv.sys – (EuGdiDrv)
DRV - [2008/12/12 18:05:20 | 000,025,264 | —- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\purendis.sys – (purendis)
DRV - [2008/12/12 18:05:18 | 000,023,984 | —- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\pnarp.sys – (pnarp)
DRV - [2008/05/16 15:01:00 | 006,557,408 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2008/04/13 11:45:29 | 000,010,624 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\gameenum.sys – (gameenum)
DRV - [2007/04/16 22:46:00 | 000,033,792 | —- | M] (Advanced Micro Devices) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AmdPPM.sys – (AmdPPM)
DRV - [2006/01/12 12:56:56 | 000,102,528 | —- | M] (Silicon Image, Inc) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\SI3112r.sys – (SI3112r)
DRV - [2005/09/19 09:41:00 | 000,241,280 | —- | M] (Marvell) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\yk51x86.sys – (yukonwxp)
DRV - [2005/04/12 11:07:50 | 000,099,456 | —- | M] (Nero AG) [File_System | Disabled | Running] – C:\WINDOWS\system32\drivers\InCDfs.sys – (InCDfs)
DRV - [2005/04/12 11:07:30 | 000,029,056 | —- | M] (Nero AG) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\InCDpass.sys – (InCDPass)
DRV - [2005/04/12 11:07:26 | 000,028,160 | —- | M] (Nero AG) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\InCDrm.sys – (incdrm)
DRV - [2005/04/07 17:18:34 | 000,003,840 | —- | M] () [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\BANTExt.sys – (BANTExt)
DRV - [2004/12/22 02:07:12 | 002,304,320 | R— | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/11/01 12:21:32 | 000,010,368 | —- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys – (SiFilter)
DRV - [2004/05/25 15:58:04 | 000,396,032 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nvapu.sys – (nvnforce) Service for NVIDIA® nForce™
DRV - [2004/05/25 15:58:02 | 000,048,640 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nvax.sys – (nvax) Service for NVIDIA® nForce™
DRV - [2004/02/24 12:08:52 | 000,400,384 | —- | M] (Sensaura) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ALCXSENS.SYS – (ALCXSENS)
DRV - [2003/07/17 18:58:20 | 000,036,992 | R— | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\SISAGPX.sys – (SISAGP)
DRV - [2003/06/06 15:53:16 | 000,070,656 | R— | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\NVENET.sys – (NVENET)
DRV - [2003/04/07 18:56:36 | 000,820,133 | R— | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\sis7012.sys – (SiS7012) Service for AC'97 Sample Driver (WDM)
DRV - [2003/03/25 02:50:46 | 000,004,096 | R— | M] (Silicon Integrated Systems Corp.) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\siside.sys – (SiSide)
DRV - [2003/03/19 00:51:00 | 000,018,688 | R— | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\nv_agp.sys – (nv_agp)
DRV - [2002/10/17 00:14:46 | 000,049,024 | R— | M] (Windows ® 2000 DDK provider) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\sisidex.sys – (sisidex)
DRV - [2002/08/28 22:59:12 | 000,036,224 | —- | M] (ADMtek Incorporated.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\an983.sys – (AN983)
DRV - [2002/08/20 02:19:08 | 000,009,472 | R— | M] (Silicon Integrated Systems Corp.) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\sisperf.sys – (sisperf)
DRV - [2002/08/01 19:30:12 | 000,035,427 | —- | M] (SiS Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sisnic.sys – (SISNIC)
DRV - [2002/07/31 13:52:22 | 000,016,896 | —- | M] (First International Digital, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ir100.sys – (ir100)
DRV - [2001/10/24 17:16:10 | 000,036,224 | R— | M] (LinkSys Group Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\lne100v5.sys – (LNE100) Linksys LNE100TX(v5)
DRV - [2001/08/23 05:00:00 | 000,036,736 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ultra.sys – (ultra)
DRV - [2001/08/17 07:00:04 | 000,002,944 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\msmpu401.sys – (ms_mpu401)
DRV - [2001/02/28 11:42:44 | 000,034,712 | —- | M] (Marimba, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\MrtRate.sys – (mrtRate)
DRV - [1997/04/22 11:16:00 | 000,006,272 | —- | M] () [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\ASLM75.SYS – (aslm75)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/…/search/ie.html


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = F1 0D 46 01 8F F4 0A 45 AE 37 22 BC 92 12 6F 2E [binary data]
IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = F1 0D 46 01 8F F4 0A 45 AE 37 22 BC 92 12 6F 2E [binary data]
IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = F1 0D 46 01 8F F4 0A 45 AE 37 22 BC 92 12 6F 2E [binary data]
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = F1 0D 46 01 8F F4 0A 45 AE 37 22 BC 92 12 6F 2E [binary data]
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-2025429265-2139871995-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = F1 0D 46 01 8F F4 0A 45 AE 37 22 BC 92 12 6F 2E [binary data]
IE - HKU\S-1-5-21-2025429265-2139871995-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-21-2025429265-2139871995-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKU\S-1-5-21-2025429265-2139871995-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?ei=UTF-8&fr;=ytff-&p;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.wwdb.com/"
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7.3
FF - prefs.js..extensions.enabledItems: {1018e4d6-728f-4b20-ad56-37578a4de76b}:4.0.4
FF - prefs.js..extensions.enabledItems: {31c7d459-9cc3-44f2-9dca-fc11795309b4}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:0.5.2010040201
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.1
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: {52a69273-25f5-4cb9-a0a3-4f97c4b0fb60}:1.0
FF - prefs.js..keyword.URL: "http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type;=yahoo_avg_hs2-tb-web_us&p;="

FF - user.js..browser.search.openintab: false

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/05/01 09:57:18 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/01 09:57:18 | 000,000,000 | —D | M]

[2009/08/16 10:33:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Extensions
[2009/08/16 10:33:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Extensions\[removed]
[2010/06/10 17:53:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\extensions
[2010/04/14 06:40:52 | 000,000,000 | —D | M] (Flagfox) – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2010/05/01 09:32:50 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/03 18:44:50 | 000,000,000 | —D | M] (IObitCom Toolbar) – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\extensions\{31c7d459-9cc3-44f2-9dca-fc11795309b4}
[2009/10/19 19:40:11 | 000,000,000 | —D | M] (PDF Download) – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2010/05/01 14:28:28 | 000,000,000 | —D | M] (XUL Cache) – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\extensions\{52a69273-25f5-4cb9-a0a3-4f97c4b0fb60}
[2008/09/05 06:16:53 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\extensions\{5359A5B3-9AFD-49ee-8C39-0A8F97A2A2D6}
[2010/05/01 10:46:49 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/04/14 06:40:47 | 000,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/04/14 06:40:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\extensions\[removed]
[2008/06/21 20:30:31 | 000,001,712 | —- | M] () – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\searchplugins\ask.xml
[2010/06/07 01:06:16 | 000,002,125 | —- | M] () – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\searchplugins\flickr-tags.xml
[2009/10/11 09:29:59 | 000,001,850 | —- | M] () – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\searchplugins\gocook-recipe-search.xml
[2008/10/30 23:50:02 | 000,005,383 | —- | M] () – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\searchplugins\goldstar.xml
[2010/06/07 01:06:17 | 000,002,390 | —- | M] () – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\searchplugins\heaprcom—web.xml
[2010/03/26 00:07:02 | 000,001,504 | —- | M] () – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\searchplugins\imdb.xml
[2009/10/11 09:29:41 | 000,001,863 | —- | M] () – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\searchplugins\searchalot.xml
[2009/10/11 09:30:03 | 000,001,859 | —- | M] () – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\searchplugins\searchgeek.xml
[2009/10/18 13:04:13 | 000,002,359 | —- | M] () – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\searchplugins\searchmurawskich.xml
[2009/10/11 09:29:54 | 000,002,256 | —- | M] () – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\searchplugins\snappy-words.xml
[2008/06/06 11:16:05 | 000,001,961 | —- | M] () – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\searchplugins\technorati-new.xml
[2009/10/11 09:30:13 | 000,001,855 | —- | M] () – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\searchplugins\wikibuddy-wiki-search.xml
[2009/10/11 09:31:54 | 000,001,223 | —- | M] () – C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Profiles\0zynv3mo.default\searchplugins\yahoo-finance.xml
[2010/06/10 17:53:07 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2006/09/05 19:46:56 | 000,114,688 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
[2007/09/05 13:56:00 | 000,352,256 | —- | M] ( ) – C:\Program Files\Mozilla Firefox\plugins\npsabffx.dll
[2007/03/09 11:35:00 | 000,365,056 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npupd62.dll
[2010/01/13 15:46:00 | 000,063,488 | —- | M] (Nullsoft, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npwachk.dll

O1 HOSTS File: ([2010/06/03 01:48:12 | 000,608,415 | —- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 fr.a2dfp.net
O1 - Hosts: 127.0.0.1 m.fr.a2dfp.net
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 adserver.abv.bg
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 achmedia.com
O1 - Hosts: 127.0.0.1 aconti.net
O1 - Hosts: 127.0.0.1 secure.aconti.net
O1 - Hosts: 127.0.0.1 www.aconti.net #[Dialer.Aconti]
O1 - Hosts: 127.0.0.1 ads.active.com
O1 - Hosts: 127.0.0.1 am1.activemeter.com
O1 - Hosts: 127.0.0.1 www.activemeter.com #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1 ads.activepower.net
O1 - Hosts: 127.0.0.1 stat.active24stats.nl #[Tracking.Cookie]
O1 - Hosts: 127.0.0.1 ad2games.com
O1 - Hosts: 127.0.0.1 cms.ad2click.nl
O1 - Hosts: 127.0.0.1 ads.ad2games.com
O1 - Hosts: 127.0.0.1 content.ad20.net
O1 - Hosts: 16056 more lines…
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [Cmaudio] File not found
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe (HP)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [IPInSightMonitor 02] C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe (Visual Networks)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe (Silicon Integrated Systems Corp.)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\Run: [DWQueuedReporting] C:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE (Microsoft Corporation)
O4 - HKU\S-1-5-18..\Run: [DWQueuedReporting] C:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE (Microsoft Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [tscuninstall] C:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [tscuninstall] C:\WINDOWS\system32\tscupgrd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Kevin Lenertz\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPropertiesMyComputer = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileAssociate = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2025429265-2139871995-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2025429265-2139871995-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-2025429265-2139871995-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKU\S-1-5-21-2025429265-2139871995-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKU\S-1-5-21-2025429265-2139871995-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-2025429265-2139871995-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} Reg Error: Value error. (QuickTime Object)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} Reg Error: Value error. (Office Genuine Advantage Validation Tool)
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} Reg Error: Value error. (Reg Error: Value error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} Reg Error: Value error. (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} Reg Error: Value error. (Reg Error: Value error.)
O16 - DPF: {2CFB52FD-7CF2-479C-BF65-B27F8A834F31} Reg Error: Value error. (SecureSession Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} Reg Error: Value error. (YInstStarter Class)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} Reg Error: Value error. (Reg Error: Value error.)
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} Reg Error: Value error. (TTestGenXInstallObject)
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} Reg Error: Value error. (Reg Error: Value error.)
O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} http://picasaweb.google.com/s/v/59.04/uploader2.cab (UploadListView Class)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} Reg Error: Value error. (Office Update Installation Engine)
O16 - DPF: {515DA9EC-7B03-3F80-D87E-3DB976424323} Reg Error: Value error. (Reg Error: Value error.)
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} Reg Error: Value error. (Reg Error: Value error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} Reg Error: Value error. (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} Reg Error: Value error. (MUWebControl Class)
O16 - DPF: {7440672B-1B25-7D3F-E4E5-495D702279D7} Reg Error: Value error. (Reg Error: Value error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} Reg Error: Value error. (Reg Error: Value error.)
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} Reg Error: Value error. (YahooYMailTo Class)
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} Reg Error: Value error. (Reg Error: Value error.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} Reg Error: Value error. (Reg Error: Value error.)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} Reg Error: Value error. (YAddBook Class)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} Reg Error: Value error. (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} Reg Error: Value error. (Reg Error: Value error.)
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} Reg Error: Value error. (PhotosCtrl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} Reg Error: Value error. (Reg Error: Value error.)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} Reg Error: Value error. (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} Reg Error: Value error. (Reg Error: Value error.)
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} Reg Error: Value error. (Reg Error: Value error.)
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} Reg Error: Value error. (Reg Error: Value error.)
O16 - DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} Reg Error: Value error. (Reg Error: Value error.)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Yahoo! Chat Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\28fd0830899: DllName - C:\WINDOWS\system32\comuid32.dllcht1532.dll21lsrykyexn6gcx32.dlllyyhn62q32.dll9gct9jw7032.dll - C:\WINDOWS\System32\comuid32.dllcht1532.dll21lsrykyexn6gcx32.dlllyyhn62q32.dll9gct9jw7032.dll File not found
O20 - Winlogon\Notify\AtiExtEvent: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Kevin Lenertz\Application Data\Mozilla\Firefox\Desktop Background.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - Reg Error: Key error. File not found
O29 - HKLM SecurityProviders - (zwebauth.dll) - C:\WINDOWS\System32\ZWebAuth.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/01/04 20:32:14 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (sprestrt) - C:\WINDOWS\System32\sprestrt.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (sprestrt) - C:\WINDOWS\System32\sprestrt.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (sprestrt) - C:\WINDOWS\System32\sprestrt.exe (Microsoft Corporation)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/06/10 17:47:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Kevin Lenertz\Desktop\June 2010 Infection
[2010/06/09 06:52:34 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2010/05/28 18:21:37 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Kevin Lenertz\Recent
[2010/05/28 02:27:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Kevin Lenertz\Local Settings\Application Data\ykxpfvjde
[10 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/06/11 18:03:00 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{9BF836F3-575A-474D-9EC1-B1B79C716B20}.job
[2010/06/11 18:00:00 | 000,000,438 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{5163EA63-99B5-4BFC-A794-9858730E7E11}.job
[2010/06/11 17:16:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/11 12:16:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
[2010/06/11 10:16:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/11 06:16:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
[2010/06/10 19:29:08 | 000,000,460 | —- | M] () – C:\WINDOWS\tasks\COMODO System Cleaner Update.job
[2010/06/10 18:47:08 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/06/10 18:39:44 | 011,010,048 | -H– | M] () – C:\Documents and Settings\Kevin Lenertz\NTUSER.DAT
[2010/06/10 18:39:23 | 000,002,046 | —- | M] () – C:\Documents and Settings\Kevin Lenertz\Desktop\HiJackThis.lnk
[2010/06/10 18:16:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
[2010/06/10 17:45:30 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/06/10 17:44:39 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/06/10 17:42:21 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/10 17:41:47 | 000,181,718 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/06/10 17:41:31 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/06/10 17:41:29 | 2147,012,608 | -HS- | M] () – C:\hiberfil.sys
[2010/06/10 17:40:21 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Kevin Lenertz\ntuser.ini
[2010/06/10 17:40:12 | 010,229,140 | -H– | M] () – C:\Documents and Settings\Kevin Lenertz\Local Settings\Application Data\IconCache.db
[2010/06/10 00:16:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
[2010/06/09 21:30:19 | 003,277,099 | —- | M] () – C:\Documents and Settings\Kevin Lenertz\Desktop\Canon CoStoreSummer10final.pdf
[2010/06/09 19:42:06 | 000,288,496 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/09 19:38:57 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/06/09 19:27:39 | 000,601,140 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/09 19:27:39 | 000,512,420 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/06/09 19:27:39 | 000,097,120 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/06/07 22:33:43 | 000,021,504 | —- | M] () – C:\Documents and Settings\Kevin Lenertz\Desktop\John Wooden.doc
[2010/06/07 10:12:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/06/06 16:12:51 | 001,551,409 | —- | M] () – C:\WINDOWS\System32\WebEx Document Loader Port
[2010/06/05 18:16:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/06/05 11:50:24 | 000,029,261 | —- | M] () – C:\WINDOWS\hpoins03.dat
[2010/06/05 11:50:23 | 000,000,643 | —- | M] () – C:\WINDOWS\win.ini
[2010/06/05 11:43:51 | 000,181,760 | —- | M] () – C:\Documents and Settings\Kevin Lenertz\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/05 01:32:19 | 000,000,046 | —- | M] () – C:\WINDOWS\System32\_WKERNEL.FRE
[2010/06/03 01:48:12 | 000,608,415 | —- | M] () – C:\WINDOWS\System32\drivers\etc\HOSTS
[2010/05/31 16:25:31 | 000,096,772 | —- | M] () – C:\Documents and Settings\Kevin Lenertz\My Documents\DPE.DUS
[2010/05/31 16:10:33 | 000,000,372 | —- | M] () – C:\WINDOWS\tasks\HP DArC Task #Hewlett-Packard#hp officejet 5500 series#1258008452.job
[2010/05/23 09:52:26 | 000,023,040 | —- | M] () – C:\Documents and Settings\Kevin Lenertz\Desktop\Toastmasters - You Are What.doc
[10 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/10 18:39:23 | 000,002,046 | —- | C] () – C:\Documents and Settings\Kevin Lenertz\Desktop\HiJackThis.lnk
[2010/06/09 21:30:18 | 003,277,099 | —- | C] () – C:\Documents and Settings\Kevin Lenertz\Desktop\Canon CoStoreSummer10final.pdf
[2010/06/09 19:20:24 | 000,001,355 | —- | C] () – C:\WINDOWS\imsins.BAK
[2010/06/07 22:32:51 | 000,021,504 | —- | C] () – C:\Documents and Settings\Kevin Lenertz\Desktop\John Wooden.doc
[2010/05/31 16:10:32 | 000,000,372 | —- | C] () – C:\WINDOWS\tasks\HP DArC Task #Hewlett-Packard#hp officejet 5500 series#1258008452.job
[2010/05/28 18:17:46 | 2147,012,608 | -HS- | C] () – C:\hiberfil.sys
[2010/05/01 10:18:46 | 000,184,320 | —- | C] () – C:\WINDOWS\System32\comuid32.dllcht1532.dll21lsrykyexn6gcx32.dlllyyhn62q32.dll
[2010/02/01 19:33:27 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/11/11 23:37:34 | 000,565,248 | R— | C] () – C:\WINDOWS\System32\hpotscl.dll
[2009/11/06 11:58:04 | 000,178,975 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2009/10/20 01:48:14 | 000,000,272 | —- | C] () – C:\WINDOWS\_delis32.ini
[2009/10/20 01:48:05 | 000,001,712 | —- | C] () – C:\WINDOWS\_isenv31.ini
[2009/10/20 01:48:05 | 000,000,521 | —- | C] () – C:\WINDOWS\_iserr31.ini
[2009/10/18 12:43:51 | 000,156,672 | R— | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2009/09/14 23:06:46 | 000,014,848 | —- | C] () – C:\WINDOWS\System32\EuEpmGdi.dll
[2009/09/14 23:06:46 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\epmntdrv.sys
[2009/09/14 23:06:46 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\EuGdiDrv.sys
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/02/07 10:20:26 | 000,000,056 | —- | C] () – C:\WINDOWS\pccillin.ini
[2009/01/18 12:22:20 | 000,000,047 | —- | C] () – C:\WINDOWS\System32\09wutili.sys
[2008/11/21 14:47:52 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/11/21 14:45:16 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2008/09/10 02:22:56 | 000,000,000 | —- | C] () – C:\WINDOWS\QuickInstall.INI
[2008/04/28 11:11:16 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/04/28 11:11:16 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/04/28 11:11:16 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/04/28 11:11:16 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/04/28 11:11:16 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/04/28 11:11:16 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/04/28 11:11:16 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/04/28 11:11:16 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/04/28 11:11:16 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/04/21 11:34:41 | 000,000,034 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2008/03/15 08:36:58 | 000,167,936 | R— | C] () – C:\WINDOWS\System32\GBInf.dll
[2008/01/22 20:02:03 | 000,000,169 | —- | C] () – C:\WINDOWS\RtlRack.ini
[2008/01/22 19:26:02 | 000,000,164 | —- | C] () – C:\WINDOWS\avrack.ini
[2008/01/21 02:24:36 | 000,139,264 | R— | C] () – C:\WINDOWS\System32\IDEproperty.dll
[2008/01/21 01:35:43 | 000,032,768 | —- | C] () – C:\WINDOWS\SIS_LIB.DLL
[2007/11/06 16:00:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2007/11/06 16:00:00 | 001,486,848 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2007/11/06 16:00:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2007/11/06 16:00:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2007/11/06 16:00:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/07/16 21:06:55 | 000,018,296 | —- | C] () – C:\WINDOWS\System32\webleymon.dll
[2007/01/26 18:55:32 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2007/01/21 00:20:16 | 000,000,000 | —- | C] () – C:\WINDOWS\QFN.ini
[2007/01/21 00:20:16 | 000,000,000 | —- | C] () – C:\WINDOWS\QDQICK.ini
[2007/01/20 23:35:03 | 000,000,185 | —- | C] () – C:\WINDOWS\intuprof.ini
[2007/01/20 23:34:59 | 000,000,882 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2006/05/17 21:16:40 | 000,000,004 | —- | C] () – C:\WINDOWS\uccspecb.sys
[2006/04/27 17:51:07 | 000,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006/03/19 15:20:04 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2005/12/05 23:51:29 | 000,000,385 | —- | C] () – C:\WINDOWS\ncini.dll
[2005/11/06 19:13:22 | 000,000,022 | —- | C] () – C:\WINDOWS\kodakpcd.Kevin Lenertz.ini
[2005/07/04 22:04:20 | 000,003,840 | —- | C] () – C:\WINDOWS\System32\drivers\BANTExt.sys
[2005/05/01 11:44:19 | 000,000,739 | —- | C] () – C:\WINDOWS\STImgBrowser.INI
[2005/02/07 22:13:11 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/02/02 19:13:17 | 000,016,973 | —- | C] () – C:\WINDOWS\System32\ZWebAuth.dll
[2005/01/31 13:18:20 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/01/31 12:52:34 | 000,000,227 | —- | C] () – C:\WINDOWS\WININIT.INI
[2005/01/31 12:03:48 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\YCRWin32.dll
[2005/01/31 11:55:37 | 000,006,272 | —- | C] () – C:\WINDOWS\System32\drivers\ASLM75.SYS
[2005/01/31 11:23:56 | 000,018,253 | —- | C] () – C:\WINDOWS\System32\ssnvfx.ini
[2005/01/31 11:22:41 | 000,003,314 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2005/01/08 16:52:51 | 000,001,125 | —- | C] () – C:\WINDOWS\winamp.ini
[2005/01/07 09:32:04 | 000,000,000 | —- | C] () – C:\WINDOWS\ATIMMC.INI
[2004/10/26 15:39:05 | 003,375,104 | —- | C] () – C:\WINDOWS\System32\qt-mt331.dll
[2003/07/14 12:30:28 | 000,197,120 | —- | C] () – C:\WINDOWS\patchw32.dll
[2003/02/19 02:26:28 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\cmirmdrv.dll
[2003/02/16 13:55:13 | 000,696,320 | —- | C] () – C:\WINDOWS\System32\xvid.dll
[2002/11/26 21:12:16 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\lttls13n.dll
[2002/11/26 21:12:00 | 000,708,608 | —- | C] () – C:\WINDOWS\System32\ltcry13n.dll
[2002/11/26 21:11:42 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\lfkodak.dll
[2002/11/26 21:11:38 | 000,338,944 | —- | C] () – C:\WINDOWS\System32\lffpx7.dll
[2002/07/19 16:05:32 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\SecuiTechIE.dll

========== LOP Check ==========

[2010/05/28 18:11:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\ArcticLine
[2008/10/30 18:21:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Windows Desktop Search
[2008/10/30 18:19:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Windows Search
[2008/03/15 08:37:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Agilix
[2007/04/09 03:02:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fellowes
[2009/09/17 22:07:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Linksys
[2006/04/05 17:37:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2008/08/30 17:09:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2009/07/06 01:33:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2005/01/31 12:06:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visual Networks
[2008/05/02 01:16:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\YAHOO
[2009/09/27 02:24:42 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{35ACA973-70F0-495F-9092-74A130711865}
[2010/04/19 23:39:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2007/09/30 09:21:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Lenertz\Application Data\.purple
[2009/02/24 01:01:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Lenertz\Application Data\ArcticLine
[2010/03/23 23:49:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Lenertz\Application Data\Audacity
[2009/11/19 18:46:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Lenertz\Application Data\CBS Interactive
[2008/09/07 02:44:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Lenertz\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/05/23 12:57:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Lenertz\Application Data\Gold Wave Editor Pro
[2009/11/10 13:29:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Lenertz\Application Data\IObit
[2008/01/11 01:39:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Lenertz\Application Data\Juniper Networks
[2007/02/05 04:09:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Lenertz\Application Data\Leadertech
[2009/03/20 02:34:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Lenertz\Application Data\NetStat Agent
[2008/07/01 06:41:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Lenertz\Application Data\OfficeUpdate12
[2009/12/13 10:22:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Lenertz\Application Data\SystemRequirementsLab
[2010/05/06 19:12:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Lenertz\Application Data\Uniblue
[2010/04/08 11:54:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Lenertz\Application Data\Unity
[2008/08/22 00:04:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Lenertz\Application Data\Windows Desktop Search
[2008/08/30 15:17:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin Lenertz\Application Data\Windows Search
[2008/09/12 15:19:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Sophea\Application Data\Windows Desktop Search
[2010/06/10 18:16:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Daily 1).job
[2010/06/10 00:16:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Daily 2).job
[2010/06/11 06:16:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Daily 3).job
[2010/06/11 12:16:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Daily 4).job
[2010/06/05 18:16:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010/06/10 17:45:30 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2010/06/11 18:00:00 | 000,000,438 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{5163EA63-99B5-4BFC-A794-9858730E7E11}.job
[2010/06/11 18:03:00 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{9BF836F3-575A-474D-9EC1-B1B79C716B20}.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 179 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5B132D3E
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:288A91F8
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
< End of report >
If I'm interpreting the OTL.txt file correctly, judging from the number of ad services I appear to be hosting my problem could lie there.

Extras.txt Logfile:

OTL Extras logfile created on: 6/11/2010 5:36:50 PM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\Kevin Lenertz\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 54.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.28 Gb Total Space | 11.60 Gb Free Space | 30.31% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 39.06 Gb Total Space | 36.82 Gb Free Space | 94.26% Space Free | Partition Type: NTFS
Drive G: | 126.96 Gb Total Space | 75.96 Gb Free Space | 59.83% Space Free | Partition Type: NTFS
Drive H: | 67.74 Gb Total Space | 55.21 Gb Free Space | 81.51% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded

Computer Name: LENERTZ
Current User Name: Kevin Lenertz
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = YBrowser.HTML] – C:\Program Files\Yahoo!\browser\ybrowser.exe (Yahoo!, Inc.)

[HKEY_USERS\S-1-5-21-2025429265-2139871995-839522115-1003\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "F:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
http [open] – Reg Error: Key error.
https [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"67:UDP" = 67:UDP:*:Enabled:DHCP Discovery Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:Windows Shell – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server – (Yahoo! Inc.)
"H:\Program Files\EA GAMES\Medal of Honor Pacific Assault™\mohpa.exe" = H:\Program Files\EA GAMES\Medal of Honor Pacific Assault™\mohpa.exe:*:Enabled:Medal of Honor Pacific Assault™ – (Electronic Arts Inc.)
"C:\Program Files\HP\HP Software Update\HPWUCli.exe" = C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:HP Software Update Client – (Hewlett-Packard)
"G:\Program Files\Program Files\LimeWire\LimeWire.exe" = G:\Program Files\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – (Lime Wire, LLC)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe" = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Jukebox – (Yahoo! Inc.)
"F:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe" = F:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax – (Intuit, Inc.)
"F:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe" = F:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager – (Intuit, Inc.)
"F:\Program Files\TurboTax\Home & Business 2007\32bit\ttax.exe" = F:\Program Files\TurboTax\Home & Business 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax – (Intuit, Inc.)
"F:\Program Files\TurboTax\Home & Business 2007\32bit\updatemgr.exe" = F:\Program Files\TurboTax\Home & Business 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager – (Intuit, Inc.)
"G:\Program Files\Program Files\bearflix.exe" = G:\Program Files\Program Files\bearflix.exe:*:Enabled:BearFlix – (Musiclab, LLC)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"H:\Program Files\Ubisoft\Gearbox Software\Brothers in Arms - Hell's Highway\Binaries\biahh.exe" = H:\Program Files\Ubisoft\Gearbox Software\Brothers in Arms - Hell's Highway\Binaries\biahh.exe:*:Enabled:biahh – File not found
"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server – (Intuit Inc.)
"G:\Program Files\iTunes\iTunes.exe" = G:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:Windows Shell – (Microsoft Corporation)
"C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe" = C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe:LocalSubNet:Enabled:Pure Networks Platform Service – (Cisco Systems, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00647DE6-64B5-4058-95B6-CB5F6A66E32B}" = irock! 100 Series Voice & Audio Manager
"{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}" = Microsoft Games for Windows - LIVE Redistributable
"{08C519E7-DAE8-4FC4-A8C2-63D34D81F69A}" = Palm Music Assistant
"{092eeeee-9fdd-4895-a568-0818c96beb6c}" = AiO_Scan
"{097346E0-6A51-11D1-AD16-00A0C95E0503}(SBC)" = Visual IP InSight(SBC)
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1CAD83B0-87A3-4206-BF70-644546808731}" = Overland
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{22DE1881-9D24-4981-B5CC-EC7E9F2F4D52}" = Rhapsody Player Engine
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 18
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{2F1FD032-67D1-4569-923F-47EAF132BF0F}" = DocProc
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{33CF58F5-48D8-4575-83D6-96F574E4D83A}" = Nero DriveSpeed
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{359CFC0A-BEB1-440D-95BA-CF63A86DA34F}" = Nero Recode
"{368BA326-73AD-4351-84ED-3C0A7A52CC53}" = Nero Rescue Agent
"{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}" = HPSystemDiagnostics
"{3E908702-AF35-4611-9518-955DA24B7E07}" = Microsoft XML Parser and SDK
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{438D221C-5B5B-4E4B-B7BD-A86512E5B6C1}" = DAO
"{43DCF766-6838-4F9A-8C91-D92DA586DFA7}" = Microsoft Windows Journal Viewer
"{43E39830-1826-415D-8BAE-86845787B54B}" = Nero Vision
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{494C271C-1528-4886-A78C-BFB3C823A37B}" = MediaFACE 4.0 Image Library
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B35F00C-E63D-40DC-9839-DF15A33EAC46}" = Grand Theft Auto Vice City
"{4FB6F304-A91D-4919-98E5-D96E074EA9E5}" = SkinsHP1
"{5421155F-B033-49DB-9B33-8F80F233D4D5}" = GdiplusUpgrade
"{546C7D0B-1E12-4573-BCD0-F5B0D3C66A74}" = ArcSoft PhotoImpression 4
"{54e854d5-d5d4-452d-9c75-b39f5625b5fb}" = Readme
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{55D1BF8E-EA8F-4969-82B9-B577010CFBCD}" = Microsoft Baseline Security Analyzer 2.1
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{56CFA833-F44F-4199-8C58-7F8B38F2BC7B}" = Medal of Honor Pacific Assault™
"{595A3116-40BB-4E0F-A2E8-D7951DA56270}" = NeroExpress
"{5ADF6293-D60F-4425-AFA7-CEB820DB872B}" = QuickProjects
"{5B30AA25-BF39-4BE4-8FEE-51938BAB214D}" = TurboTax 2008 wcaiper
"{5C74694C-A687-E3EB-FF18-B018D4A76ECD}" = Adobe Media Player
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.5
"{5ECB3A3C-980B-4D12-9724-25DCB07A1F47}" = iTunes
"{60984004-ae09-4009-9acf-1eeea39b2207}" = 5500_Help
"{62AC81F6-BDD3-4110-9D36-3E9EAAB40999}" = Nero CoverDesigner
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{639858DD-4966-40F3-A706-7C838BCF3A2B}" = MaxBlast 3
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74224F8D-4A17-4816-9EDB-7BB854DE532C}" = NVIDIA PhysX v8.04.25
"{745A92AF-53B4-41A7-91C3-9B026B1D5897}" = InstantShare
"{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset
"{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}" = overland
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart
"{7829DB6F-A066-4E40-8912-CB07887C20BB}" = Nero BurnRights
"{787D1A33-A97B-4245-87C0-7174609A540C}" = HP Update
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7F581D1D-C9A7-4C77-B88A-27537173CEDF}" = MediaFACE 4.0
"{829698DE-9EAC-475E-9A05-B7BA807CA1EF}" = Director
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113606753}" = Monopoly
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8398B542-3CC4-44D9-83DF-696CCE70124B}" = Windows Support Tools
"{869200DB-287A-4DC0-B02B-2B6787FBCD4C}" = Nero DiscSpeed
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A253629-0511-4854-8B4E-46E57E66005C}" = Bonjour
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Standard
"{90260409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Web Components
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{90300409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content
"{939227BD-19D8-4684-8A04-31AC9F6A564C}" = Scan
"{94a0a859-8e01-45f2-9e7f-ac54c02d4f2c}" = 5500Trb
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{959B7040-8448-4705-B951-BDB603CF69A0}_is1" = PDF Converter 2.0
"{961034C0-58DF-11DF-97FD-005056806466}" = Google Earth Plug-in
"{9862E0CB-4727-4FFC-963A-E22A9E9EC10C}" = Creative ZEN V Series (R2)
"{9DA00558-6566-484C-87BC-1650BCF60446}" = ATI DVD Decoder
"{9DE1BE03-AFE2-4CDB-BFEB-D06D736CD01A}" = Apple Mobile Device Support
"{9E82B934-9A25-445B-B8DF-8012808074AC}" = Nero PhotoSnap
"{9EE54C1F-FC99-44D6-916A-0CA2D45E740F}" = Digimax Viewer 2.1
"{9F4EEA0C-7174-4BD3-89AF-7AB2F9F6AEDD}" = hpmdtab
"{9FC7D8E1-F14F-11D4-943A-00E02950B496}" = Microsoft Office XP Pro Step by Step Interactive
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A081DDB9-9451-4031-8672-868AD8E47049}" = Blackboard Backpack 3.0
"{A1C962E2-2426-49C6-A38B-9A07E40D607C}" = Microsoft Games for Windows - LIVE
"{A209525B-3377-43F4-B886-32F6B6E7356F}" = Nero WaveEditor
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A363B66C-1547-47bf-90F0-3834E70A841A}" = CreativeProjects
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.2
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AC76BA86-7AD7-5760-0000-705000000001}" = Adobe Reader Japanese Fonts
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B1ADF008-E898-4FE2-8A1F-690D9A06ACAF}" = DolbyFiles
"{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper
"{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B78120A0-CF84-4366-A393-4D0A59BC546C}" = Menu Templates - Starter Kit
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
"{BEB3AD23-250E-4BD2-BBC9-27D4BB42DE07}" = COMODO System - Cleaner
"{BF2A74BF-8D12-47F1-8B19-22B30AF6B0D1}" = Linksys EasyLink Advisor
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{c330461f-c4a9-4fc7-af5d-c158e0b56aa7}" = AiOSoftware
"{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}" = WebEx Support Manager for Internet Explorer
"{C38BC5B7-62D3-4880-82DD-A4803FD81921}" = PhotoGallery
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C5A7CB6C-E76D-408F-BA0E-85605420FE9D}" = SoundTrax
"{C63E7C60-25EB-11D3-8EDA-00A0C911E8E5}" = Microsoft Outlook Personal Folders Backup
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{cc9d78d9-5517-4d55-8a68-1006e4134c80}" = 5500Tour
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE4F8FFB-4063-4247-9F14-ECE61AFEFA25}" = TrayApp
"{CEB3A11A-03EA-11DA-BFBD-00065BBDC0B5}" = MSN Messenger 7.5
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus® for Adobe
"{CFD1B282-555D-494d-8231-4175C2AF08C2}" = PrintScreen
"{D025A639-B9C9-417D-8531-208859000AF8}" = NeroBurningROM
"{D1D8C9C4-89BE-4f37-9EC4-B80E3C239C41}" = Copy
"{D39CF926-9FDD-4A61-8B3C-724003F4C9C0}" = Debugging Tools for Windows
"{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}" = Windows Resource Kit Tools - SubInAcl.exe
"{d40e4a88-ebc8-4d52-be3c-a4917a057ef0}" = Fax
"{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}" = Full Tilt Poker
"{D545BB81-DEB0-49f7-BE26-197BC31AAF57}" = SkinsHP2
"{D9DCF92E-72EB-412D-AC71-3B01276E5F8B}" = Nero ShowTime
"{d9e29d2e-005f-4c58-8c9b-6724b6637b01}" = 5500
"{DC226AC9-0314-496C-BE6A-B6A132628466}" = SiSAGP driver
"{E0303B6A-C675-4102-95DA-C013625BFA99}" = GTA San Andreas
"{E371C150-A9F1-49CE-ACC1-51AEFD01C1D4}_is1" = Turbo Tax Audit Support Center 2.0
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E498385E-1C51-459A-B45F-1721E37AA1A0}" = Movie Templates - Starter Kit
"{E63E34A7-E552-412B-9E40-FD6FC5227ABA}_is1" = Uniblue RegistryBooster
"{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp
"{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
"{EC3B8CA2-49B8-4D38-BE9C-ABD0F6029168}" = Yahoo! Music Jukebox
"{ec7d7a6a-31cb-4810-826f-74171bef44f1}" = AIOMinimal
"{EFE1AB94-5466-4B6E-BE31-FF4C115FD25D}" = Max Payne 2
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F38FA38A-7E5A-4209-88ED-4DE21CD20EEF}" = HP PSC & OfficeJet 3.0
"{F7060FA4-DCD7-11D3-85BB-0050DA6DA088}" = IPFax
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FBBF532A-47AC-457d-AC06-0D3163D8911E}" = WebReg
"{FBCDFD61-7DCF-4E71-9226-873BA0053139}" = Nero InfoTool
"{FBDBC490-089D-4476-BF72-1F7A6368200A}" = Pure Networks Platform
"{FC274982-5AAD-4C20-848D-4424A5043010}_is1" = WinUtilities 9.62 Free Edition
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AMD AGP Driver" = AMD AGP Driver
"AnVir Task Manager" = AnVir Task Manager
"Ashampoo WinOptimizer 5_is1" = Ashampoo WinOptimizer 5.03
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.11 (Unicode)
"avast!" = avast! Antivirus
"BearFlix" = BearFlix
"Belarc Advisor 2.0" = Belarc Advisor 7.0
"BroadJump Client Foundation" = BroadJump Client Foundation
"CCleaner" = CCleaner
"C-Media Audio Driver" = C-Media WDM Audio Driver
"CodecInstaller" = CodecInstaller 2.7.0
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Creative Removable Disk Manager" = Creative Removable Disk Manager
"DECCHECK" = Microsoft Windows XP Video Decoder Checkup Utility
"Defraggler" = Defraggler
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DRM7Tool" = Personal License Update Wizard for Windows Media Player
"EASEUS Partition Master Professional Edition_is1" = EASEUS Partition Master 4.0 Professional
"ERUNT_is1" = ERUNT 1.1j
"Folder Marker_is1" = Folder Marker Pro v 3.0
"getPlus®_dll" = getPlus®_dll
"GNU Aspell_is1" = GNU Aspell 0.50-3
"GTK 2.0" = GTK+ Runtime 2.10.13 rev a (remove only)
"HijackThis" = HijackThis 2.0.2
"HP Photo & Imaging" = HP Photo & Imaging 3.1
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InCD!UninstallKey" = InCD
"InstallShield_{438D221C-5B5B-4E4B-B7BD-A86512E5B6C1}" = DAO
"InstallShield_{494C271C-1528-4886-A78C-BFB3C823A37B}" = MediaFACE 4.0 Image Library
"InstallShield_{7F581D1D-C9A7-4C77-B88A-27537173CEDF}" = MediaFACE 4.0
"InstallShield_{9DA00558-6566-484C-87BC-1650BCF60446}" = ATI DVD Decoder
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"LimeWire" = LimeWire 5.4.6
"Linksys EasyLink Advisor" = Linksys EasyLink Advisor
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Internet Gaming Zone" = MSN Gaming Zone
"Mozilla Firefox (3.5.3)" = Mozilla Firefox (3.5.3)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSN Music Assistant" = MSN Music Assistant
"MultiStage Recovery_is1" = MultiStage Recovery 3.6
"Nero - Burning Rom!UninstallKey" = Nero OEM
"NetStat Agent_is1" = NetStat Agent 2.1.3
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"Picasa 3" = Picasa 3
"ProcessScanner_is1" = Uniblue ProcessScanner
"ReadmeSoft AVI Codec Converter (AVI MOV MPEG ASF~1DCD84D2_is1" = avi2divx
"SBC Yahoo! Applications" = SBC Yahoo! Applications
"SBC.MCCInstall" = AT&T Self Support Tool
"SiSLan" = SiS 900 PCI Fast Ethernet Adapter Driver
"SysInfo" = Creative System Information
"SystemRequirementsLab" = System Requirements Lab
"TurboTax 2008" = TurboTax 2008
"TurboTax Deluxe 2007" = TurboTax Deluxe 2007
"TurboTax Home & Business 2007" = TurboTax Home & Business 2007
"UnityWebPlayer" = Unity Web Player
"What's Running_is1" = What's Running 2.2
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinX DVD Ripper_is1" = WinX DVD Ripper
"WMCSetup" = Windows Media Connect
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Toolbar" = Yahoo! Toolbar
"ZENcast Organizer" = ZENcast Organizer

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2025429265-2139871995-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Quicken 2002 New User Edition" = Quicken 2002 New User Edition
"Winamp Detect" = Winamp Detector Plug-in

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 5/23/2010 1:00:35 PM | Computer Name = LENERTZ | Source = avast! | ID = 33554522
Description = Internal error has occurred in module aswar scan function failed!,
function C00000FD.

Error - 5/28/2010 9:26:51 PM | Computer Name = LENERTZ | Source = avast! | ID = 33554522
Description = Internal error has occurred in module aswar scan function failed!,
function C00000FD.

Error - 5/30/2010 6:30:56 PM | Computer Name = LENERTZ | Source = avast! | ID = 33554522
Description = Internal error has occurred in module aswar scan function failed!,
function C00000FD.

Error - 6/1/2010 4:11:59 PM | Computer Name = LENERTZ | Source = avast! | ID = 33554522
Description = Internal error has occurred in module aswar scan function failed!,
function C00000FD.

Error - 6/5/2010 4:06:15 AM | Computer Name = LENERTZ | Source = avast! | ID = 33554522
Description = Internal error has occurred in module aswar scan function failed!,
function C00000FD.

Error - 6/5/2010 3:18:27 PM | Computer Name = LENERTZ | Source = avast! | ID = 33554522
Description = Internal error has occurred in module aswar scan function failed!,
function C00000FD.

Error - 6/6/2010 6:12:11 PM | Computer Name = LENERTZ | Source = avast! | ID = 33554522
Description = Internal error has occurred in module aswar scan function failed!,
function C00000FD.

Error - 6/9/2010 9:48:00 AM | Computer Name = LENERTZ | Source = avast! | ID = 33554522
Description = Internal error has occurred in module aswar scan function failed!,
function C00000FD.

Error - 6/9/2010 10:50:43 PM | Computer Name = LENERTZ | Source = avast! | ID = 33554522
Description = Internal error has occurred in module aswar scan function failed!,
function C00000FD.

Error - 6/10/2010 8:50:29 PM | Computer Name = LENERTZ | Source = avast! | ID = 33554522
Description = Internal error has occurred in module aswar scan function failed!,
function C00000FD.

[ Application Events ]
Error - 6/10/2010 9:21:55 PM | Computer Name = LENERTZ | Source = Windows Search Service | ID = 3083
Description = The protocol handler Search.OneIndexHandler.1 cannot be loaded. Error
description: Class not registered .

Error - 6/10/2010 9:23:57 PM | Computer Name = LENERTZ | Source = Windows Search Service | ID = 3083
Description = The protocol handler Search.OneIndexHandler.1 cannot be loaded. Error
description: Class not registered .

Error - 6/10/2010 9:28:09 PM | Computer Name = LENERTZ | Source = Windows Search Service | ID = 3083
Description = The protocol handler Search.OneIndexHandler.1 cannot be loaded. Error
description: Class not registered .

Error - 6/10/2010 9:35:13 PM | Computer Name = LENERTZ | Source = Windows Search Service | ID = 3083
Description = The protocol handler Search.OneIndexHandler.1 cannot be loaded. Error
description: Class not registered .

Error - 6/10/2010 9:37:21 PM | Computer Name = LENERTZ | Source = Windows Search Service | ID = 3083
Description = The protocol handler Search.OneIndexHandler.1 cannot be loaded. Error
description: Class not registered .

Error - 6/10/2010 9:39:26 PM | Computer Name = LENERTZ | Source = Windows Search Service | ID = 3083
Description = The protocol handler Search.OneIndexHandler.1 cannot be loaded. Error
description: Class not registered .

Error - 6/10/2010 9:46:30 PM | Computer Name = LENERTZ | Source = Windows Search Service | ID = 3083
Description = The protocol handler Search.OneIndexHandler.1 cannot be loaded. Error
description: Class not registered .

Error - 6/11/2010 8:36:00 PM | Computer Name = LENERTZ | Source = Windows Search Service | ID = 3083
Description = The protocol handler Search.OneIndexHandler.1 cannot be loaded. Error
description: Class not registered .

Error - 6/11/2010 8:57:53 PM | Computer Name = LENERTZ | Source = Windows Search Service | ID = 3083
Description = The protocol handler Search.OneIndexHandler.1 cannot be loaded. Error
description: Class not registered .

Error - 6/11/2010 8:57:57 PM | Computer Name = LENERTZ | Source = Windows Search Service | ID = 3083
Description = The protocol handler Search.OneIndexHandler.1 cannot be loaded. Error
description: Class not registered .

[ System Events ]
Error - 6/9/2010 10:33:01 PM | Computer Name = LENERTZ | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 6/9/2010 10:42:48 PM | Computer Name = LENERTZ | Source = NETLOGON | ID = 3095
Description = This computer is configured as a member of a workgroup, not as a member
of a domain. The Netlogon service does not need to run in this configuration.

Error - 6/9/2010 10:43:59 PM | Computer Name = LENERTZ | Source = WMPNetworkSvc | ID = 866293
Description = Service 'WMPNetworkSvc' did not start correctly because QueryService
encountered error '0x80004002'. In Windows Media Player, turn off media sharing,
and then turn it back on.

Error - 6/9/2010 10:44:44 PM | Computer Name = LENERTZ | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd

Error - 6/9/2010 10:44:52 PM | Computer Name = LENERTZ | Source = WMPNetworkSvc | ID = 866293
Description = Service 'WMPNetworkSvc' did not start correctly because QueryService
encountered error '0x80004002'. In Windows Media Player, turn off media sharing,
and then turn it back on.

Error - 6/10/2010 2:35:16 AM | Computer Name = LENERTZ | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 6/10/2010 8:42:33 PM | Computer Name = LENERTZ | Source = NETLOGON | ID = 3095
Description = This computer is configured as a member of a workgroup, not as a member
of a domain. The Netlogon service does not need to run in this configuration.

Error - 6/10/2010 8:43:32 PM | Computer Name = LENERTZ | Source = WMPNetworkSvc | ID = 866293
Description = Service 'WMPNetworkSvc' did not start correctly because QueryService
encountered error '0x80004002'. In Windows Media Player, turn off media sharing,
and then turn it back on.

Error - 6/10/2010 8:44:35 PM | Computer Name = LENERTZ | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd

Error - 6/10/2010 8:44:36 PM | Computer Name = LENERTZ | Source = WMPNetworkSvc | ID = 866293
Description = Service 'WMPNetworkSvc' did not start correctly because QueryService
encountered error '0x80004002'. In Windows Media Player, turn off media sharing,
and then turn it back on.


< End of report >
GMER report

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-06-12 14:44:25
Windows 5.1.2600 Service Pack 3
Running: lto777vq.exe; Driver: C:\DOCUME~1\KEVINL~1\LOCALS~1\Temp\kgtdapow.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB6B1A6B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xB6B1A574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xB6B1AA52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB6B1A14C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xB6B1A64E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xB6B1A08C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xB6B1A0F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB6B1A76E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB6B1A72E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xB6B1A8AE]

—- Kernel code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB923C360, 0x37388D, 0xE8000020]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Mozilla Firefox\firefox.exe[264] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\WINDOWS\system32\SearchIndexer.exe[3256] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs sisidex.sys (SISIDEX Driver/Windows ® 2000 DDK provider)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \FileSystem\Fastfat \Fat sisidex.sys (SISIDEX Driver/Windows ® 2000 DDK provider)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

—- Threads - GMER 1.0.15 —-

Thread System [4:2484] B3F5C1F0

—- EOF - GMER 1.0.15 —-
Given the number of alerts I've had lately this log should be bigger but this is the entire log. Avast Resident Protection Log: * * avast! Report * This file is generated automatically * * Task 'Resident protection' used * Started on Thursday, June 10, 2010 5:42:18 PM * VPS: 100610-0, 06/10/2010 * C:\WINDOWS\System32\comuid32.dllcht1532.dll21lsrykyexn6gcx32.dlllyyhn62q32.dll [L] Win32:Dracur-B [Cryp] (0) File was successfully deleted… * * Task stopped: Saturday, June 12, 2010 12:04:53 PM * Run-time was 1 day(s), 18 hour(s), 22 minute(s), 35 second(s) * * * avast! Report * This file is generated automatically * * Task 'Resident protection' used * Started on Saturday, June 12, 2010 2:41:00 PM * VPS: 100612-1, 06/12/2010 *
Hello cklenertz :),

Is this computer used for business purposes? There are quite a few programs suggesting that it is so.

——————–

Remove P2P software
  • IMPORTANT: I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

    BearFlix
    LimeWire 5.4.6


  • Our policy as pointed out in the Terms of Use:

    We will not support or allow the discussion of any peer to peer (P2P) applications, except for their removal.

  • Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
  • Go to Control Panel > Add/Remove Programs and uninstall the P2P program(s) listed above (in red).
  • Please remove them before we continue with fixing your computer.
——————–

I see that you have Registry Cleaner program(s) installed.

COMODO System - Cleaner
Uniblue RegistryBooster


Personally, I do not recommend any such programs. Here is an excerpt from a discussion on Registry Cleaners:

Most Registry Cleaners aren't bad as such, but they aren't perfect and even the best have been known to cause problems. The point we are trying to make is that the risk of using one far outweighs any benefit. If it does work perfectly you will not see any difference. If it doesn't work properly you may end up with an expensive doorstop.

See here for additional information. You may uninstall it through Add/Remove Programs at the Control Panel.

——————–

Check for additional security risks
  • Please download CKScanner© by askey127 and save to your desktop. Click here.
  • Double click on CKScanner.exe and click Search For Files.
  • After a very short time, when the cursor hourglass disappears, click Save List To File. You will be prompted, click OK.
  • Post the contents of ckfiles.txt in your reply, it is located on your desktop.
——————–

Post an Uninstall list
  • Open HijackThis.
  • Go to Open the Misc Tools section by clicking on the box.
  • Under the Systems tools, look for Open Uninstall Manager and click on it.
  • Click Save list… and save the text file in a convenient location.
  • Copy and paste the Uninstall list contents in your reply.
——————–

Please post back:
1. the answer to my question about your computer
2. CKScanner log
3. uninstall list
Hello cklenertz :), I usually close the topic after 3 days without any reply, and it has already been 2 days since my last post. Do you still need help? Any problems following my instructions? Need more time? If I do not get any response within the next 24 hours, this topic will be closed.
Hey Jack & Jill, Sorry for the delay. It is a little of both, home office and personal. Mostly personal these days as I typically use my laptop and an external HD for backup. CkScanner did not save the file to my desktop. I did a search and found it saved in the Mozilla folder. I was unable to uninstall BearFlix. I kept getting a message from Wise Uninstall "Could not open INSTALL.LOG file." I attempted to repair the install by reinstalling the program but when I uninstalled the reinstall, it did not take the original with it. HiJack This UNINSTALL LIST: Acrobat.com Acrobat.com Adobe AIR Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Media Player Adobe Media Player Adobe Reader 9.1.2 Adobe Reader Japanese Fonts Adobe Shockwave Player 11.5 Advertising Center AMD AGP Driver AnVir Task Manager Apple Application Support Apple Mobile Device Support Apple Software Update ArcSoft PhotoImpression 4 Ashampoo WinOptimizer 5.03 AT&T Self Support Tool ATI DVD Decoder Audacity 1.3.11 (Unicode) avast! Antivirus BearFlix Belarc Advisor 7.0 Blackboard Backpack 3.0 Bonjour BroadJump Client Foundation CCleaner C-Media WDM Audio Driver Compatibility Pack for the 2007 Office system Creative Removable Disk Manager Creative System Information Creative ZEN V Series (R2) DAO Debugging Tools for Windows Defraggler Digimax Viewer 2.1 DivX Player DolbyFiles EASEUS Partition Master 4.0 Professional ERUNT 1.1j Folder Marker Pro v 3.0 Full Tilt Poker GdiplusUpgrade GDR 3068 for SQL Server Database Services 2005 ENU (KB948109) GDR 3068 for SQL Server Tools and Workstation Components 2005 ENU (KB948109) getPlus® for Adobe getPlus®_dll Google Earth Google Earth Plug-in Google Update Helper Grand Theft Auto Vice City GTA San Andreas GTK+ Runtime 2.10.13 rev a (remove only) HighMAT Extension to Microsoft Windows XP CD Writing Wizard HiJackThis HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.0 (KB932471) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) HP Photo & Imaging 3.1 HP PSC & OfficeJet 3.0 HP Update InCD IPFax irock! 100 Series Voice & Audio Manager iTunes Java™ 6 Update 18 Java™ 6 Update 3 LAME v3.98.2 for Audacity Linksys EasyLink Advisor Linksys EasyLink Advisor Max Payne 2 MaxBlast 3 Medal of Honor Pacific Assault™ MediaFACE 4.0 MediaFACE 4.0 Image Library Menu Templates - Starter Kit Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 Microsoft Baseline Security Analyzer 2.1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Games for Windows - LIVE Microsoft Games for Windows - LIVE Redistributable Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office XP Media Content Microsoft Office XP Pro Step by Step Interactive Microsoft Office XP Professional Microsoft Office XP Professional with FrontPage Microsoft Office XP Standard Microsoft Office XP Web Components Microsoft Outlook Personal Folders Backup Microsoft Silverlight Microsoft SQL Server 2005 Express Edition (MSSMLBIZ) Microsoft SQL Server 2005 Tools Express Edition Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable Microsoft Windows Journal Viewer Microsoft Windows XP Video Decoder Checkup Utility Microsoft XML Parser and SDK Monopoly Movie Templates - Starter Kit Mozilla Firefox (3.5.3) MSN Gaming Zone MSN Messenger 7.5 MSN Music Assistant MSXML 4.0 SP2 (KB925672) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 4.0 SP2 Parser and SDK MSXML 6 Service Pack 2 (KB973686) MultiStage Recovery 3.6 Nero BurnRights Nero ControlCenter Nero CoverDesigner Nero DiscSpeed Nero DriveSpeed Nero InfoTool Nero Installer Nero OEM Nero PhotoSnap Nero Recode Nero Rescue Agent Nero ShowTime Nero StartSmart Nero Vision Nero WaveEditor NeroBurningROM NeroExpress neroxml NetStat Agent 2.1.3 NVIDIA Drivers NVIDIA PhysX v8.04.25 OGA Notifier 2.0.0048.0 overland Palm Music Assistant PDF Converter 2.0 Personal License Update Wizard for Windows Media Player Picasa 3 QuickTime Realtek AC'97 Audio Rhapsody Player Engine SBC Yahoo! Applications Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB974455) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Encoder (KB979332) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB978695) Security Update for Windows Search 4 - KB963093 Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) SiS 900 PCI Fast Ethernet Adapter Driver SiSAGP driver Skype™ 3.5 SoundTrax Spelling Dictionaries Support For Adobe Reader 9 System Requirements Lab Turbo Tax Audit Support Center 2.0 TurboTax 2008 TurboTax 2008 wcaiper TurboTax 2008 WinPerFedFormset TurboTax 2008 WinPerProgramHelp TurboTax 2008 WinPerReleaseEngine TurboTax 2008 WinPerTaxSupport TurboTax 2008 WinPerUserEducation TurboTax 2008 wrapper TurboTax Deluxe 2007 TurboTax Home & Business 2007 Unity Web Player Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB975364) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB976749) Update for Windows Internet Explorer 8 (KB980182) Update for Windows XP (KB955759) Update for Windows XP (KB971737) Update for Windows XP (KB973687) VC80CRTRedist - 8.0.50727.762 Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 Visual IP InSight(SBC) WD Diagnostics WebEx Support Manager for Internet Explorer What's Running 2.2 Winamp Windows Defender Windows Defender Signatures Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray Windows Genuine Advantage v1.3.0254.0 Windows Imaging Component Windows Media Connect Windows Media Encoder 9 Series Windows Media Encoder 9 Series Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 10 Windows Media Player 11 Windows Presentation Foundation Windows Resource Kit Tools - SubInAcl.exe Windows Search 4.0 Windows Support Tools Windows XP Service Pack 3 WinUtilities 9.62 Free Edition WinX DVD Ripper Yahoo! Music Jukebox ZENcast Organizer
CKScanner - Additional Security Risks - These are not necessarily bad c:\documents and settings\kevin lenertz\favorites\news, research, and information\blogs\dayam crackers.url scanner sequence 3.NA.11 —– EOF —–
Hello cklenertz :),

It is a little of both, home office and personal.

Do you have your own IT person or department to help you deal with your problems?
Hello cklenertz :),

WTT only provide help for home and personal computers, not any business computers. Since yours fall somewhere in between, there can be an exception, but I will need your agreement for me to provide help and that WTT will not be responsible any results from the malware removal procedure, including those affecting your business negatively. You will be responsible for them.

If you agree, please state so and continue below. If you do not agree, we should stop here and you may bring your computer to any local shop to solve your problem.

——————–

Please download Malwarebytes' Anti-Malware (MBAM)© from Malwarebytes and save it to your desktop. Click here.

Run MBAM
  • Double click on mbam-setup.exe and follow the prompts to install the program.
  • At the end of installation, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • MBAM will now check for updates. If your firewall prompts, please allow it. If you can't update it, select the Update tab. Under Update mirror, select one of the websites and click on Check for Updates.
  • Upon completion of update and loading, select the Scanner tab. Click on Perform full scan, then click on Scan.
  • Leave the default options as it is and click on Start Scan.
  • If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process.
  • When done, you will be prompted. Click OK, then click on Show Results.
  • Check (tick) all items except items in the C:\System Volume Information folder and click on Remove Selected.
  • After it has removed the items, a log in Notepad will open. Please post this log in your next reply. You can also find the log in the Logs tab. The bottom most log is the latest.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware. If you receive an (Error Loading) error on reboot, please reboot a second time . It is normal for this error to occur once and does not need to be reported unless it returns on future reboots.

——————–

Please post back:
1. the MBAM log
Hello cklenertz :),

I will be travelling in another 36 hours and be away for a week. Of these hours left, about half will be used for sleeping and getting ready for my trip. As such, I wish to try to complete your topic before I leave as I will only have limited internet access when I travel.

I hope you will be able to respond in a more timely manner so that we can finish this off soon. Our time difference is 14 hours, it is almost midnight here while your place is only almost nine o'clock in the morning. I will be on the computer most of the time from your time seven until ten o'clock morning and most of the evening and night. These periods would be the best time to solve your problem quickly in the coming 36 hours.

In case I need to leave before we can resolve your problem, I will request for someone to takeover the topic from me.

WTT only provide help for home and personal computers, not any business computers. Since yours fall somewhere in between, there can be an exception, but I will need your agreement for me to provide help and that WTT will not be responsible any results from the malware removal procedure, including those affecting your business negatively. You will be responsible for them.

If you agree, please state so and continue below. If you do not agree, we should stop here and you may bring your computer to any local shop to solve your problem.

May I know what is your decision?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI