This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Am I infected?

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer has been acting slow for the last few months. I was browsing normal websites last night, like news email and weather, when a suspicious looking window popped up. It was called "AV Security Suite." I tried to kill the process with Ctrl-Alt-Delete but it did not work. I am currently running Microsoft Security Essentials but it is acting strange. Is there any chance it could be fake or infected? I ran a full scan with Malwarebytes and am posting the log. I do not know how this could have happened. Can you help me? Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4052 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 6/26/2010 8:09:14 AM mbam-log-2010-06-26 (08-09-14).txt Scan type: Full scan (C:\|) Objects scanned: 286464 Time elapsed: 3 hour(s), 48 minute(s), 7 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 4 Registry Values Infected: 2 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\avsuite (Rogue.AntivirusSuite) -> No action taken. HKEY_CURRENT_USER\Software\avsuite (Rogue.AntivirusSuite) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\avsoft (Trojan.Fraudpack) -> No action taken. HKEY_CURRENT_USER\Software\avsoft (Trojan.Fraudpack) -> No action taken. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\tkebxowi (Rogue.AntivirusSuite.Gen) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\tkebxowi (Rogue.AntivirusSuite.Gen) -> No action taken. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Documents and Settings\Nancy Sullivan\Local Settings\Application Data\epgxyucrk\sxxabwttssd.exe (Rogue.AntivirusSuite.Gen) -> No action taken. C:\Documents and Settings\Nancy Sullivan\Local Settings\Temp\svchost.exe (Trojan.Agent) -> No action taken.
Hello Amandapanda88 and welcome to WhatTheTech. Please follow these guidelines:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until Iโ€™ve given you the โ€œAll clear.โ€ Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please follow my instructions carefully and in the order they are posted.
  • Any underlined text in my posts indicates a clickable link.
  • You should print any instructions I give you for ease of use and reference.
  • If you have any questions at all, please stop and ask before proceeding.
๐Ÿ–ผClick to load external image (Posted Image) Run Malwarebytes again, but this time let it fix what it finds.

๐Ÿ–ผClick to load external image (Posted Image) Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
๐Ÿ–ผClick to load external image (Posted Image) Download GMER Rootkit Scanner from here to your desktop.
  • Double click the exe file. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scanโ€ฆclick on NO.


    [external image: Posted Image]
    Click the image to enlarge it


  • In the right panel, you will see several boxes that have been checked. Uncheck the following โ€ฆ
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)a
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<โ€” ROOKIT" entries


If you have trouble running GEMR:
  • Make sure that your security software is disabled
  • Uncheck the box next to "Files" this time also
  • If you still can't run it, try in the Safe Mode
Please include the following in your next post:
  • DDS and Attach.txt logs
  • GMER log
Something strange is happening. Firefox is working, although slowly, but google chrome and IE are able to load gmail. Why would some browsers load only gmail? The wont even open othe google sites like google.com or google maps.


DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 4:01:18.33 on Mon 06/28/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1006.387 [GMT -5:00]

AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Nancy Sullivan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEDA.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Documents and Settings\Nancy Sullivan\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://google.com/
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.dell4me.com/mywaybiz
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/mywaybiz
uInternet Settings,ProxyServer = http=127.0.0.1:5577
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
BHO: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\nancy sullivan\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [EPSON NX100 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatieda.exe /fu "c:\windows\temp\E_SDB.tmp" /EF "HKCU"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [IntelWireless] c:\program files\intel\wireless\bin\ifrmewrk.exe /tf Intel PROSet/Wireless
mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\point32.exe"
mRun: [NeroCheck] c:\windows\system32\NeroCheck.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [HP Software Update] c:\program files\hewlett-packard\hp software update\HPWuSchd2.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\nancys~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\nancys~1\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\documents and settings\nancy sullivan\start menu\programs\startup\OneNote Table Of Contents.onetoc2
StartupFolder: c:\docume~1\nancys~1\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 2.0\program\quickstart.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\americ~1.lnk - c:\program files\america online 9.0\aoltray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photo2.walgreens.com/WalgreensActivia.cab
DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} - file://d:\cdviewer\CdViewer.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
Notify: IntelWireless - c:\program files\intel\wireless\bin\LgNotify.dll
AppInit_DLLs: c:\progra~1\google\google~4\GOEC62~1.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\nancys~1\applic~1\mozilla\firefox\profiles\mv9eilc8.default\
FF - prefs.js: browser.startup.homepage - hxxp://forums.whatthetech.com/Antivirus_System_PRO_t108501.html
FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\documents and settings\nancy sullivan\application data\move networks\plugins\npqmp071505000010.dll
FF - plugin: c:\documents and settings\nancy sullivan\local settings\application data\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\picasa3\npPicasa2.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

โ€”- FIREFOX POLICIES โ€”-
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-7-15 97928]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-7-15 26824]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 149040]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-7-16 875288]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-16 231704]
R2 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-7-15 76040]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-4 135664]
S3 DIGIRPS;Digi PortServer Driver;c:\windows\system32\drivers\digirlpt.sys [2006-12-2 42432]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-8-20 30192]
S3 SNDP202;Dual Mode Camera (8008 VGA);c:\windows\system32\drivers\sndp202.sys [2006-7-18 245120]

=============== Created Last 30 ================

2010-06-19 21:56:51 54156 โ€”ha-w- c:\windows\QTFont.qfn
2010-06-19 21:56:51 1409 โ€”-a-w- c:\windows\QTFont.for
2010-06-11 07:54:29 743424 โ€”โ€”w- c:\windows\system32\dllcache\iedvtool.dll

==================== Find3M ====================

2010-05-21 19:14:28 221568 โ€”โ€”w- c:\windows\system32\MpSigStub.exe
2010-05-05 13:30:57 173056 โ€”โ€”w- c:\windows\system32\dllcache\ie4uinit.exe
2010-05-02 05:22:50 1851264 โ€”-a-w- c:\windows\system32\win32k.sys
2010-05-02 05:22:50 1851264 โ€”โ€”w- c:\windows\system32\dllcache\win32k.sys
2010-04-29 20:39:38 38224 โ€”-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 20:39:26 20952 โ€”-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-20 05:30:08 285696 โ€”-a-w- c:\windows\system32\atmfd.dll
2010-04-20 05:30:08 285696 โ€”โ€”w- c:\windows\system32\dllcache\atmfd.dll
2010-04-03 11:39:36 2377576 โ€”-a-w- c:\windows\system32\dllcache\WMVCore.dll
2010-03-31 05:16:34 99176 โ€”-a-w- c:\windows\system32\PresentationHostProxy.dll
2010-03-31 05:10:40 295264 โ€”-a-w- c:\windows\system32\PresentationHost.exe
2006-02-12 20:00:06 56 โ€“shโ€“r- c:\windows\system32\55C4976812.sys
2006-02-12 20:00:08 3766 โ€“sha-w- c:\windows\system32\KGyGaAvL.sys
2009-05-17 17:16:47 32768 โ€“sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009051720090518\index.dat
2010-01-05 01:59:11 32768 โ€“sha-w- c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\index.dat

============= FINISH: 4:02:45.20 ===============






GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-06-28 12:54:30
Windows 5.1.2600 Service Pack 3
Running: hycwmozv.exe; Driver: C:\DOCUME~1\NANCYS~1\LOCALS~1\Temp\fxddqpob.sys


โ€”- Devices - GMER 1.0.15 โ€”-

Device \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)

Device \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\Tcpip \Device\IPMULTICAST avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \FileSystem\Fastfat \Fat EBF8CD20

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

โ€”- EOF - GMER 1.0.15 โ€”-
Amandapanda88,

๐Ÿ–ผClick to load external image (Posted Image) You have more than one antivirus (AV) program running. Your logs show both AVG and Microsoft Security Essentials (MSE) running. Running more than one AV program does not offer any more protection and often causes conflicts and slow downs with your computer. Please uninstall either AVG or MSE (I'd recommend keeping MSE) via Control Panel > Add/Remove Programs. Run the removal tool (links below) for whichever app you uninstall also:

AVG Removal Tool
Microsoft Security Essentials Removal Tool

๐Ÿ–ผClick to load external image (Posted Image) Go to Control Panel and select Internet Options
  • Select the Connections TAB
  • Select LAN settings button
  • Ensure there is no tick in the Proxy Server box
  • Select OK and restart Internet explorer
๐Ÿ–ผClick to load external image (Posted Image) You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM
  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

๐Ÿ–ผClick to load external image (Posted Image) Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View reportโ€ฆ at the bottom.
  • Click the Save reportโ€ฆ button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply
Please include the following in your next post:
  • Confirm that you removed one of the AV programs and the internet proxy
  • MBAM log
  • Kaspersky log
  • The Attach.txt log from DDS
  • How is the computer running now?
I wasn't really running AVG. I used to close it after rebooting. But I did unstall it like you said, and unchecked the internet proxy box. MBAM found no errors. Here is the log. Since it was clean I stopped. The computer seems to be running ok but the volume control down by the clock is strangely missing. Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4264 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 7/1/2010 12:20:07 PM mbam-log-2010-07-01 (12-20-07).txt Scan type: Quick scan Objects scanned: 162271 Time elapsed: 28 minute(s), 57 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi,

Please run the Kaspersky scan and post the log for me, along with a fresh set of logs from DDS (both DDS.txt and Attach.txt).

To get your volume control back in the taskbar follow the instructions in this link
The first time I tried Kaspersky, using Internet Explorer, it ran for over 3 hours and then stopped. The screen said it was 64% done. I could not access the report. Then I upgraded my Firefox from 3.5.10 to 3.6.6 and rebooted. The second time I tried Kaspersky, using Firefox. This ran successfully and generated the attached report. I have been noticing for several months that occasionaly a java icon is in the system tray area near the clock, and I don't know why. Do you think it would be a good idea to purchase the full version of Kaspersky? โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€“ KASPERSKY ONLINE SCANNER 7.0: scan report Saturday, July 3, 2010 Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Saturday, July 03, 2010 10:14:36 Records in database: 4254464 โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€“ Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Objects scanned: 164129 Threats found: 7 Infected objects found: 15 Suspicious objects found: 0 Scan duration: 04:41:43 File name / Threat / Threats count C:\Documents and Settings\Nancy Sullivan\Application Data\Sun\Java\Deployment\cache\6.0\44\690b50ac-79497877 Infected: Trojan-Downloader.Java.Agent.eo 1 C:\Documents and Settings\Nancy Sullivan\Application Data\Sun\Java\Deployment\cache\6.0\44\690b50ac-79497877 Infected: Exploit.Java.Agent.t 1 C:\Documents and Settings\Nancy Sullivan\Application Data\Sun\Java\Deployment\cache\6.0\44\690b50ac-79497877 Infected: Trojan-Downloader.Java.Agent.ep 1 C:\Documents and Settings\Nancy Sullivan\Application Data\Sun\Java\Deployment\cache\6.0\44\696d2fac-40dc0393 Infected: Exploit.Java.Agent.s 3 C:\Documents and Settings\Nancy Sullivan\Local Settings\Temp\jar_cache2041665759069945083.tmp Infected: Trojan-Downloader.Java.Agent.ah 2 C:\Documents and Settings\Nancy Sullivan\Local Settings\Temp\jar_cache226517768372090667.tmp Infected: Trojan-Downloader.Java.Agent.ah 2 C:\Documents and Settings\Nancy Sullivan\Local Settings\Temp\jar_cache8840940439660224512.tmp Infected: Trojan-Downloader.Java.Agent.fe 3 C:\Documents and Settings\Nancy Sullivan\Local Settings\Temp\plugtmp-16\plugin-kfmec.pdf Infected: Exploit.JS.Pdfka.cni 1 C:\Documents and Settings\Nancy Sullivan\Local Settings\Temporary Internet Files\Content.IE5\W6D0CXO7\rqsysd[1].pdf Infected: Exploit.JS.Pdfka.cni 1 Selected area has been scanned. โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€” DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 17:51:47.01 on Sat 07/03/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1006.604 [GMT -5:00] AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe c:\Program Files\Microsoft Security Essentials\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe svchost.exe svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE svchost.exe C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Canon\CAL\CALMAIN.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Dell\Media Experience\DMXLauncher.exe C:\Program Files\Microsoft IntelliPoint\point32.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe C:\Program Files\Logitech\QuickCam\Quickcam.exe C:\Program Files\Microsoft Security Essentials\msseces.exe C:\Program Files\DellSupport\DSAgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Documents and Settings\Nancy Sullivan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEDA.EXE C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\OpenOffice.org 2.0\program\soffice.exe C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Java\jre6\bin\java.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\Nancy Sullivan\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://google.com/ uSearch Page = hxxp://www.google.com uDefault_Page_URL = hxxp://www.dell4me.com/mywaybiz uSearch Bar = hxxp://www.google.com/ie uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/mywaybiz uInternet Settings,ProxyServer = http=127.0.0.1:5577 uInternet Settings,ProxyOverride = uSearchURL,(Default) = hxxp://www.google.com/keyword/%s mSearchAssistant = hxxp://www.google.com/ie BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Google Update] "c:\documents and settings\nancy sullivan\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [EPSON NX100 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatieda.exe /fu "c:\windows\temp\E_SDB.tmp" /EF "HKCU" mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [IntelWireless] c:\program files\intel\wireless\bin\ifrmewrk.exe /tf Intel PROSet/Wireless mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER mRun: [dla] c:\windows\system32\dla\tfswctrl.exe mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\point32.exe" mRun: [NeroCheck] c:\windows\system32\NeroCheck.exe mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe" mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe" mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter mRun: [HP Software Update] c:\program files\hewlett-packard\hp software update\HPWuSchd2.exe mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe" mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t StartupFolder: c:\docume~1\nancys~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\docume~1\nancys~1\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE StartupFolder: c:\documents and settings\nancy sullivan\start menu\programs\startup\OneNote Table Of Contents.onetoc2 StartupFolder: c:\docume~1\nancys~1\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 2.0\program\quickstart.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\americ~1.lnk - c:\program files\america online 9.0\aoltray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photo2.walgreens.com/WalgreensActivia.cab DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} - file://d:\cdviewer\CdViewer.cab Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: igfxcui - igfxdev.dll Notify: IntelWireless - c:\program files\intel\wireless\bin\LgNotify.dll AppInit_DLLs: c:\progra~1\google\google~4\GOEC62~1.DLL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\nancys~1\applic~1\mozilla\firefox\profiles\mv9eilc8.default\ FF - prefs.js: browser.startup.homepage - hxxp://forums.whatthetech.com/index.php?showtopic=112838&pid=664070&st=0&#entry664070 FF - plugin: c:\documents and settings\nancy sullivan\application data\move networks\plugins\npqmp071505000010.dll FF - plugin: c:\documents and settings\nancy sullivan\local settings\application data\google\update\1.2.183.29\npGoogleOneClick8.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\google\picasa3\npPicasa2.dll FF - plugin: c:\program files\google\picasa3\npPicasa3.dll FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: c:\program files\google\update\1.2.183.17\npGoogleOneClick8.dll FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} โ€”- FIREFOX POLICIES โ€”- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xnโ€“mgberp4a5d4ar", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xnโ€“p1ai", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xnโ€“mgbayh7gpa", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 151216] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-4 135664] S3 DIGIRPS;Digi PortServer Driver;c:\windows\system32\drivers\digirlpt.sys [2006-12-2 42432] S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-8-20 30192] S3 SNDP202;Dual Mode Camera (8008 VGA);c:\windows\system32\drivers\sndp202.sys [2006-7-18 245120] =============== Created Last 30 ================ 2010-06-19 21:56:51 54156 โ€”ha-w- c:\windows\QTFont.qfn 2010-06-19 21:56:51 1409 โ€”-a-w- c:\windows\QTFont.for 2010-06-11 07:54:29 743424 โ€”โ€”w- c:\windows\system32\dllcache\iedvtool.dll ==================== Find3M ==================== 2010-06-01 17:37:48 221568 โ€”โ€”w- c:\windows\system32\MpSigStub.exe 2010-05-05 13:30:57 173056 โ€”โ€”w- c:\windows\system32\dllcache\ie4uinit.exe 2010-05-02 05:22:50 1851264 โ€”-a-w- c:\windows\system32\win32k.sys 2010-05-02 05:22:50 1851264 โ€”โ€”w- c:\windows\system32\dllcache\win32k.sys 2010-04-20 05:30:08 285696 โ€”-a-w- c:\windows\system32\atmfd.dll 2010-04-20 05:30:08 285696 โ€”โ€”w- c:\windows\system32\dllcache\atmfd.dll 2006-02-12 20:00:06 56 โ€“shโ€“r- c:\windows\system32\55C4976812.sys 2006-02-12 20:00:08 3766 โ€“sha-w- c:\windows\system32\KGyGaAvL.sys 2009-05-17 17:16:47 32768 โ€“sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009051720090518\index.dat 2010-01-05 01:59:11 32768 โ€“sha-w- c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\index.dat ============= FINISH: 17:53:06.61 ===============
Amandapanda88,

Kaspersky is a very good program if your looking for a new AV.

๐Ÿ–ผClick to load external image (Posted Image) Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of OTL.txt into your next post. (I don't need to see the Extras log)
Please include the following in your next post:
  • Confirm that you removed one of the AV programs and the internet proxy
  • OTL log
I did indeed remove AVG and the internet proxy like you said. Do you think that Kaspersky provides better protection than MSE?



OTL logfile created on: 7/4/2010 7:19:43 PM - Run 1
OTL by OldTimer - Version 3.2.7.1 Folder = C:\Documents and Settings\Nancy Sullivan\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,006.00 Mb Total Physical Memory | 399.00 Mb Available Physical Memory | 40.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): C:\pagefile.sys 1512 3024 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 52.38 Gb Total Space | 2.78 Gb Free Space | 5.30% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: NAS2005
Current User Name: Nancy Sullivan
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Nancy Sullivan\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATIEDA.EXE (SEIKO EPSON CORPORATION)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
PRC - C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe (HP)
PRC - C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.)
PRC - C:\Program Files\OpenOffice.org 2.0\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 2.0\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
PRC - C:\Program Files\Microsoft IntelliPoint\point32.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intelยฎ Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Intel\Wireless\Bin\1XConfig.exe (Intel)
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
PRC - C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Nancy Sullivan\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\WINDOWS\Temp\logishrd\LVPrcInj01.dll (Logitech Inc.)


========== Win32 Services (SafeList) ==========

SRV - (MsMpSvc) โ€“ c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (GoogleDesktopManager-110309-193829) โ€“ C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) โ€“ C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (LVSrvLauncher) โ€“ C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (LVPrcSrv) โ€“ C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (LVCOMSer) โ€“ C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (Pml Driver HPZ12) โ€“ C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (DSBrokerService) โ€“ C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (CCALib8) โ€“ C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (WLANKEEPER) โ€“ C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intelยฎ Corporation)
SRV - (S24EventMonitor) โ€“ C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (EvtEng) โ€“ C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (RegSrvc) โ€“ C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (AOL ACS) โ€“ C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)


========== Driver Services (SafeList) ==========

DRV - (BVRPMPR5) โ€“ D:\INSTAL~E\Core\BVRPMPR5.SYS File not found
DRV - (MpFilter) โ€“ C:\WINDOWS\system32\drivers\MpFilter.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) โ€“ C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (amdagp) โ€“ C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) โ€“ C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (LVUSBSta) โ€“ C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (LVRS) โ€“ C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)
DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) โ€“ C:\WINDOWS\system32\drivers\LV302V32.SYS (Logitech Inc.)
DRV - (pepifilter) โ€“ C:\WINDOWS\system32\drivers\lv302af.sys (Logitech Inc.)
DRV - (LVPr2Mon) โ€“ C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (LVcKap) โ€“ C:\WINDOWS\system32\drivers\Lvckap.sys (Logitech Inc.)
DRV - (dsunidrv) โ€“ C:\WINDOWS\system32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) โ€“ C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (tifm) โ€“ C:\WINDOWS\system32\drivers\tifm.sys (Texas Instruments)
DRV - (ASCTRM) โ€“ C:\WINDOWS\System32\drivers\asctrm.sys (Windows ยฎ 2000 DDK provider)
DRV - (SynTP) โ€“ C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (tfsnudfa) โ€“ C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) โ€“ C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) โ€“ C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) โ€“ C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) โ€“ C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) โ€“ C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) โ€“ C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) โ€“ C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) โ€“ C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (drvmcdb) โ€“ C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) โ€“ C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (STAC97) Audio Driver (WDM) โ€“ C:\WINDOWS\system32\drivers\stac97.sys (SigmaTel, Inc.)
DRV - (w29n51) Intelยฎ โ€“ C:\WINDOWS\system32\drivers\w29n51.sys (Intelยฎ Corporation)
DRV - (s24trans) โ€“ C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (IWCA) โ€“ C:\WINDOWS\system32\drivers\iwca.sys (Intel Corporation)
DRV - (nv) โ€“ C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (sscdbhk5) โ€“ C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) โ€“ C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (bcm4sbxp) โ€“ C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (omci) โ€“ C:\WINDOWS\system32\drivers\omci.sys (Dell Inc)
DRV - (HSFHWICH) โ€“ C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (winachsf) โ€“ C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) โ€“ C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (SNDP202) Dual Mode Camera (8008 VGA) โ€“ C:\WINDOWS\system32\drivers\sndp202.sys ()
DRV - (wanatw) WAN Miniport (ATW) โ€“ C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (Sparrow) โ€“ C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) โ€“ C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) โ€“ C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) โ€“ C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) โ€“ C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) โ€“ C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) โ€“ C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) โ€“ C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) โ€“ C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) โ€“ C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) โ€“ C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) โ€“ C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) โ€“ C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) โ€“ C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) โ€“ C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (DIGIRPS) โ€“ C:\WINDOWS\system32\drivers\digirlpt.sys (Digi International, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5577

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://forums.whatthetech.com/index.php?showtopic=112838&pid=664070&st=0&#entry664070"
FF - prefs.js..extensions.enabledItems: [removed]:7

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/03 12:18:32 | 000,000,000 | โ€”D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/03 12:15:13 | 000,000,000 | โ€”D | M]

[2008/09/02 20:26:44 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Nancy Sullivan\Application Data\Mozilla\Extensions
[2010/07/03 11:47:18 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Nancy Sullivan\Application Data\Mozilla\Firefox\Profiles\mv9eilc8.default\extensions
[2010/07/03 11:37:15 | 000,000,000 | โ€”D | M] (Microsoft .NET Framework Assistant) โ€“ C:\Documents and Settings\Nancy Sullivan\Application Data\Mozilla\Firefox\Profiles\mv9eilc8.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/07/03 11:47:18 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2004/08/04 06:00:00 | 000,000,734 | โ€”- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe (HP)
O4 - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\point32.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\QuickCam\Quickcam.exe ()
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [EPSON NX100 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEDA.EXE (SEIKO EPSON CORPORATION)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe (America Online, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit, Inc.)
O4 - Startup: C:\Documents and Settings\Nancy Sullivan\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Documents and Settings\Nancy Sullivan\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Nancy Sullivan\Start Menu\Programs\Startup\OneNote Table Of Contents.onetoc2 ()
O4 - Startup: C:\Documents and Settings\Nancy Sullivan\Start Menu\Programs\Startup\OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/5/bโ€ฆheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo2.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} http://h20270.www2.hp.com/ediags/gmn2/instโ€ฆctDetection.cab (HpProductDetection Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashโ€ฆt/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodlโ€ฆindows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} file://D:\CDVIEWER\CdViewer.cab (AMI DicomDir TreeView Control 2.1)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\IntelWireless: DllName - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Blue Lace 16.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Blue Lace 16.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 18:15:00 | 000,000,000 | โ€”- | M] () - C:\AUTOEXEC.BAT โ€“ [ NTFS ]
O33 - MountPoints2\{77acc521-1b4f-11dc-a63f-0013ce85c3fd}\Shell - "" = AutoRun
O33 - MountPoints2\{77acc521-1b4f-11dc-a63f-0013ce85c3fd}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{77acc521-1b4f-11dc-a63f-0013ce85c3fd}\Shell\AutoRun\command - "" = E:\LaunchU3.exe โ€“ File not found
O33 - MountPoints2\{77acc524-1b4f-11dc-a63f-0013ce85c3fd}\Shell - "" = AutoRun
O33 - MountPoints2\{77acc524-1b4f-11dc-a63f-0013ce85c3fd}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{77acc524-1b4f-11dc-a63f-0013ce85c3fd}\Shell\AutoRun\command - "" = E:\LaunchU3.exe โ€“ File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] โ€“ "%1" %*
O35 - HKLM\..exefile [open] โ€“ "%1" %*
O37 - HKLM\โ€ฆcom [@ = comfile] โ€“ "%1" %*
O37 - HKLM\โ€ฆexe [@ = exefile] โ€“ "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2010/06/27 11:03:50 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\2009-12 malware fix stuff
[2010/06/26 03:47:13 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Nancy Sullivan\Local Settings\Application Data\epgxyucrk
[2010/04/22 15:33:51 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\photos for Phillips
[2010/04/13 22:03:56 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\UDL
[2010/04/13 22:02:44 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Epson Software
[2010/04/11 23:51:40 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Nancy Sullivan\Application Data\InstallShield
[2010/04/11 23:50:42 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\epson
[2010/04/11 23:44:59 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\EPSON
[2010/04/10 21:36:01 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Nancy Sullivan\My Documents\HRBlock

========== Files - Modified Within 90 Days ==========

[2010/07/04 19:19:00 | 000,000,440 | -Hโ€“ | M] () โ€“ C:\WINDOWS\tasks\User_Feed_Synchronization-{43B844AD-C92B-4D94-8956-E807FCE75F2F}.job
[2010/07/04 19:01:04 | 000,000,408 | -Hโ€“ | M] () โ€“ C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/07/04 18:56:48 | 000,002,206 | โ€”- | M] () โ€“ C:\WINDOWS\System32\wpa.dbl
[2010/07/04 18:55:54 | 000,000,868 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\Google Software Updater.job
[2010/07/04 18:55:02 | 000,054,156 | -Hโ€“ | M] () โ€“ C:\WINDOWS\QTFont.qfn
[2010/07/04 18:54:26 | 000,000,882 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/07/04 18:54:19 | 000,000,006 | -Hโ€“ | M] () โ€“ C:\WINDOWS\tasks\SA.DAT
[2010/07/04 18:54:13 | 1055,379,456 | -HS- | M] () โ€“ C:\hiberfil.sys
[2010/07/04 18:54:13 | 000,002,048 | โ€“S- | M] () โ€“ C:\WINDOWS\bootstat.dat
[2010/07/03 18:43:02 | 000,001,014 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-483835131-2526809281-402316753-1005UA.job
[2010/07/03 18:42:37 | 000,000,178 | -HS- | M] () โ€“ C:\Documents and Settings\Nancy Sullivan\ntuser.ini
[2010/07/03 18:42:36 | 008,650,752 | -Hโ€“ | M] () โ€“ C:\Documents and Settings\Nancy Sullivan\NTUSER.DAT
[2010/07/03 18:28:00 | 000,000,886 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/07/03 12:15:25 | 000,001,620 | โ€”- | M] () โ€“ C:\Documents and Settings\Nancy Sullivan\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/07/03 12:15:25 | 000,001,602 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/07/03 00:43:00 | 000,000,962 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-483835131-2526809281-402316753-1005Core.job
[2010/07/01 21:55:09 | 000,002,351 | โ€”- | M] () โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\Google Chrome.lnk
[2010/07/01 21:55:09 | 000,002,329 | โ€”- | M] () โ€“ C:\Documents and Settings\Nancy Sullivan\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/06/30 21:33:14 | 000,000,820 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/06/28 03:01:39 | 000,128,000 | โ€”- | M] () โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\6-27-2010 response number 1 from WhatTheTech.doc
[2010/06/27 11:07:11 | 000,293,376 | โ€”- | M] () โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\hycwmozv.exe
[2010/06/27 10:59:55 | 000,133,120 | โ€”- | M] () โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\6-27-2010 How to delete running stuff from WhatTheTech.doc
[2010/06/27 10:47:08 | 000,525,824 | โ€”- | M] () โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\dds.scr
[2010/06/26 08:47:36 | 000,157,696 | โ€”- | M] () โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\Mal-bytes log 6-26-2010.doc
[2010/06/26 07:12:33 | 000,080,896 | โ€”- | M] () โ€“ C:\Documents and Settings\Nancy Sullivan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/23 10:54:51 | 000,504,314 | โ€”- | M] () โ€“ C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/23 10:54:51 | 000,443,034 | โ€”- | M] () โ€“ C:\WINDOWS\System32\perfh009.dat
[2010/06/23 10:54:51 | 000,072,134 | โ€”- | M] () โ€“ C:\WINDOWS\System32\perfc009.dat
[2010/06/19 16:56:51 | 000,001,409 | โ€”- | M] () โ€“ C:\WINDOWS\QTFont.for
[2010/06/15 13:40:21 | 000,020,992 | โ€”- | M] () โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\Nick Falll 2010 schedule raw data.xls
[2010/06/12 08:25:43 | 000,236,760 | โ€”- | M] () โ€“ C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/12 05:10:39 | 000,001,374 | โ€”- | M] () โ€“ C:\WINDOWS\imsins.BAK
[2010/06/08 16:59:16 | 000,020,992 | โ€”- | M] () โ€“ C:\Documents and Settings\Nancy Sullivan\My Documents\topics discussed at Susans 5-2-2010.xls
[2010/05/11 00:02:54 | 000,001,915 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/04/29 15:39:38 | 000,038,224 | โ€”- | M] (Malwarebytes Corporation) โ€“ C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | โ€”- | M] (Malwarebytes Corporation) โ€“ C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/20 14:50:24 | 000,124,416 | โ€”- | M] () โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\Dugger birthdays.xls
[2010/04/18 17:20:18 | 002,005,424 | โ€”- | M] () โ€“ C:\WINDOWS\iis6.BAK
[2010/04/13 22:05:44 | 000,000,044 | โ€”- | M] () โ€“ C:\WINDOWS\EPNX100.ini
[2010/04/13 22:05:04 | 000,000,819 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\NX100 Series Information Center.lnk
[2010/04/13 22:03:59 | 000,001,808 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\Epson Easy Photo Print.lnk
[2010/04/13 21:54:10 | 000,000,665 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\EPSON Scan.lnk
[2010/04/11 23:53:40 | 000,018,674 | โ€”- | M] () โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\MLB scorecard colorful.xlsx
[2010/04/11 23:49:22 | 018,777,400 | โ€”- | M] () โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\epson13352.exe
[2010/04/11 20:41:48 | 000,561,152 | โ€”- | M] () โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\irs forms 2009.doc
[2010/04/11 19:24:53 | 000,001,661 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\H&R Block 2009.lnk
[2010/04/07 01:30:52 | 000,130,560 | โ€”- | M] () โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\TEMP Hotwire.doc

========== Files Created - No Company Name ==========

[2010/07/01 11:27:15 | 000,000,408 | -Hโ€“ | C] () โ€“ C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/06/27 11:08:39 | 000,293,376 | โ€”- | C] () โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\hycwmozv.exe
[2010/06/27 11:05:25 | 000,525,824 | โ€”- | C] () โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\dds.scr
[2010/06/27 10:59:55 | 000,133,120 | โ€”- | C] () โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\6-27-2010 How to delete running stuff from WhatTheTech.doc
[2010/06/27 10:57:17 | 000,128,000 | โ€”- | C] () โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\6-27-2010 response number 1 from WhatTheTech.doc
[2010/06/26 08:47:34 | 000,157,696 | โ€”- | C] () โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\Mal-bytes log 6-26-2010.doc
[2010/06/19 16:56:51 | 000,054,156 | -Hโ€“ | C] () โ€“ C:\WINDOWS\QTFont.qfn
[2010/06/19 16:56:51 | 000,001,409 | โ€”- | C] () โ€“ C:\WINDOWS\QTFont.for
[2010/06/15 13:39:10 | 000,020,992 | โ€”- | C] () โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\Nick Falll 2010 schedule raw data.xls
[2010/05/11 00:02:54 | 000,001,915 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/05/03 12:39:43 | 000,020,992 | โ€”- | C] () โ€“ C:\Documents and Settings\Nancy Sullivan\My Documents\topics discussed at Susans 5-2-2010.xls
[2010/04/13 22:05:04 | 000,000,819 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\NX100 Series Information Center.lnk
[2010/04/13 22:03:59 | 000,001,808 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\Epson Easy Photo Print.lnk
[2010/04/13 21:53:03 | 000,000,044 | โ€”- | C] () โ€“ C:\WINDOWS\EPNX100.ini
[2010/04/11 23:53:38 | 000,018,674 | โ€”- | C] () โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\MLB scorecard colorful.xlsx
[2010/04/11 23:51:43 | 000,073,220 | โ€”- | C] () โ€“ C:\WINDOWS\System32\EPPICPrinterDB.dat
[2010/04/11 23:51:43 | 000,031,053 | โ€”- | C] () โ€“ C:\WINDOWS\System32\EPPICPattern131.dat
[2010/04/11 23:51:43 | 000,029,114 | โ€”- | C] () โ€“ C:\WINDOWS\System32\EPPICPattern1.dat
[2010/04/11 23:51:43 | 000,027,417 | โ€”- | C] () โ€“ C:\WINDOWS\System32\EPPICPattern121.dat
[2010/04/11 23:51:43 | 000,021,021 | โ€”- | C] () โ€“ C:\WINDOWS\System32\EPPICPattern3.dat
[2010/04/11 23:51:43 | 000,015,670 | โ€”- | C] () โ€“ C:\WINDOWS\System32\EPPICPattern5.dat
[2010/04/11 23:51:43 | 000,013,280 | โ€”- | C] () โ€“ C:\WINDOWS\System32\EPPICPattern2.dat
[2010/04/11 23:51:43 | 000,010,673 | โ€”- | C] () โ€“ C:\WINDOWS\System32\EPPICPattern4.dat
[2010/04/11 23:51:43 | 000,006,226 | โ€”- | C] () โ€“ C:\WINDOWS\System32\EPPICLocal_ES.cfg
[2010/04/11 23:51:43 | 000,004,943 | โ€”- | C] () โ€“ C:\WINDOWS\System32\EPPICPattern6.dat
[2010/04/11 23:51:43 | 000,001,140 | โ€”- | C] () โ€“ C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2010/04/11 23:51:43 | 000,001,140 | โ€”- | C] () โ€“ C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2010/04/11 23:51:43 | 000,001,137 | โ€”- | C] () โ€“ C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2010/04/11 23:51:43 | 000,001,130 | โ€”- | C] () โ€“ C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2010/04/11 23:51:43 | 000,001,130 | โ€”- | C] () โ€“ C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2010/04/11 23:51:43 | 000,001,104 | โ€”- | C] () โ€“ C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2010/04/11 23:51:43 | 000,000,097 | โ€”- | C] () โ€“ C:\WINDOWS\System32\PICSDK.ini
[2010/04/11 23:51:42 | 000,012,669 | โ€”- | C] () โ€“ C:\WINDOWS\System32\EPPICLocal_EN.cfg
[2010/04/11 23:51:42 | 000,006,478 | โ€”- | C] () โ€“ C:\WINDOWS\System32\EPPICLocal_PT.cfg
[2010/04/11 23:51:42 | 000,006,478 | โ€”- | C] () โ€“ C:\WINDOWS\System32\EPPICLocal_BP.cfg
[2010/04/11 23:51:42 | 000,006,366 | โ€”- | C] () โ€“ C:\WINDOWS\System32\EPPICLocal_FR.cfg
[2010/04/11 23:51:42 | 000,006,366 | โ€”- | C] () โ€“ C:\WINDOWS\System32\EPPICLocal_CF.cfg
[2010/04/11 23:50:53 | 000,000,665 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\EPSON Scan.lnk
[2010/04/11 23:49:22 | 018,777,400 | โ€”- | C] () โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\epson13352.exe
[2010/04/11 20:41:47 | 000,561,152 | โ€”- | C] () โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\irs forms 2009.doc
[2010/04/10 21:39:40 | 000,001,661 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\H&R Block 2009.lnk
[2010/04/07 01:30:51 | 000,130,560 | โ€”- | C] () โ€“ C:\Documents and Settings\Nancy Sullivan\Desktop\TEMP Hotwire.doc
[2009/08/03 16:07:42 | 000,403,816 | โ€”- | C] () โ€“ C:\WINDOWS\System32\OGACheckControl.dll
[2008/12/26 02:00:06 | 000,066,482 | Rโ€” | C] () โ€“ C:\WINDOWS\System32\lvcoinst.ini
[2008/04/15 16:02:01 | 000,000,028 | โ€”- | C] () โ€“ C:\WINDOWS\pdf995.ini
[2008/04/01 20:56:04 | 000,012,633 | โ€”- | C] () โ€“ C:\WINDOWS\hpdj5700.ini
[2008/02/05 19:20:08 | 000,025,624 | โ€”- | C] () โ€“ C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/08/24 12:08:38 | 000,077,824 | Rโ€” | C] () โ€“ C:\WINDOWS\System32\HPZIDS01.dll
[2007/04/16 02:00:17 | 000,000,142 | โ€”- | C] () โ€“ C:\WINDOWS\wpd99.drv
[2007/04/16 01:59:59 | 000,051,716 | โ€”- | C] () โ€“ C:\WINDOWS\System32\pdf995mon.dll
[2006/12/02 19:26:21 | 000,000,754 | โ€”- | C] () โ€“ C:\WINDOWS\WORDPAD.INI
[2006/07/18 22:58:22 | 000,307,200 | โ€”- | C] () โ€“ C:\WINDOWS\System32\sndp2023.dll
[2006/07/18 22:58:22 | 000,286,720 | โ€”- | C] () โ€“ C:\WINDOWS\System32\sndp2022.dll
[2006/07/18 22:58:22 | 000,015,522 | โ€”- | C] () โ€“ C:\WINDOWS\sndp202.ini
[2006/07/18 22:58:21 | 000,245,120 | โ€”- | C] () โ€“ C:\WINDOWS\System32\drivers\sndp202.sys
[2006/07/18 22:58:21 | 000,045,056 | โ€”- | C] () โ€“ C:\WINDOWS\System32\dsndp202.dll
[2006/07/18 22:58:21 | 000,036,864 | โ€”- | C] () โ€“ C:\WINDOWS\System32\vsndp202.dll
[2006/07/18 22:50:18 | 000,028,747 | โ€”- | C] () โ€“ C:\WINDOWS\System32\KMemoryMMX.dll
[2006/07/18 22:50:18 | 000,024,632 | โ€”- | C] () โ€“ C:\WINDOWS\System32\KMemory.dll
[2006/07/18 22:50:17 | 000,024,653 | โ€”- | C] () โ€“ C:\WINDOWS\System32\KMemoryPIII.dll
[2006/07/18 22:50:17 | 000,020,546 | โ€”- | C] () โ€“ C:\WINDOWS\System32\KMemoryC.dll
[2006/07/18 22:49:49 | 000,000,002 | โ€”- | C] () โ€“ C:\WINDOWS\PhotoSuite.ini
[2006/07/18 22:49:45 | 000,458,752 | โ€”- | C] () โ€“ C:\WINDOWS\System32\Fpl.dll
[2006/07/18 22:49:45 | 000,122,880 | โ€”- | C] () โ€“ C:\WINDOWS\System32\EnrouteStitch.dll
[2006/07/18 22:49:45 | 000,019,968 | โ€”- | C] () โ€“ C:\WINDOWS\System32\CPUINF32.DLL
[2006/07/18 22:49:44 | 000,332,800 | โ€”- | C] () โ€“ C:\WINDOWS\System32\FPXLIB.DLL
[2006/07/18 22:49:44 | 000,122,880 | โ€”- | C] () โ€“ C:\WINDOWS\System32\JPEGLIB.DLL
[2006/05/10 21:43:47 | 000,002,760 | โ€”- | C] () โ€“ C:\WINDOWS\medsn_access.ini_Nancy Sullivan
[2006/02/12 15:04:35 | 000,000,087 | โ€”- | C] () โ€“ C:\WINDOWS\entpack.ini
[2005/11/22 16:44:55 | 000,000,056 | RHS- | C] () โ€“ C:\WINDOWS\System32\55C4976812.sys
[2005/11/22 16:44:54 | 000,003,766 | -HS- | C] () โ€“ C:\WINDOWS\System32\KGyGaAvL.sys
[2005/11/17 16:44:34 | 000,000,061 | โ€”- | C] () โ€“ C:\WINDOWS\smscfg.ini
[2005/11/17 16:33:32 | 000,000,138 | โ€”- | C] () โ€“ C:\WINDOWS\wininit.ini
[2005/11/17 15:47:54 | 000,000,390 | โ€”- | C] () โ€“ C:\WINDOWS\System32\OEMINFO.INI
[2005/01/28 09:08:34 | 000,000,000 | โ€”- | C] () โ€“ C:\WINDOWS\System32\px.ini
[2004/08/12 09:44:10 | 000,016,384 | โ€”- | C] () โ€“ C:\WINDOWS\System32\iwca.dll
[2004/08/11 18:24:19 | 000,000,791 | โ€”- | C] () โ€“ C:\WINDOWS\orun32.ini
[2004/08/11 18:11:31 | 000,001,793 | โ€”- | C] () โ€“ C:\WINDOWS\System32\fxsperf.ini
[2004/01/06 10:45:18 | 000,126,976 | โ€”- | C] () โ€“ C:\WINDOWS\System32\tibkicon.dll
[2003/02/19 22:20:16 | 000,225,280 | โ€”- | C] () โ€“ C:\WINDOWS\System32\tifmicon.dll
[2002/05/31 04:29:49 | 000,077,824 | โ€”- | C] () โ€“ C:\WINDOWS\System32\lxallcnp.dll
[2001/07/07 03:00:00 | 000,003,399 | โ€”- | C] () โ€“ C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2010/04/13 22:11:58 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\EPSON
[2008/04/15 16:02:21 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\pdf995
[2008/01/09 11:31:37 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\SupportSoft
[2010/04/10 21:18:30 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\TaxCut
[2010/04/13 22:03:57 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\UDL
[2007/03/10 00:41:00 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/09/10 23:36:51 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Nancy Sullivan\Application Data\eGames
[2009/12/26 21:30:30 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Nancy Sullivan\Application Data\JAM Software
[2005/11/23 01:24:04 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Nancy Sullivan\Application Data\Leadertech
[2006/11/16 18:25:40 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Nancy Sullivan\Application Data\Opera
[2008/04/15 16:02:04 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Nancy Sullivan\Application Data\pdf995
[2009/01/02 16:17:15 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Nancy Sullivan\Application Data\Snapfish
[2010/04/10 21:41:04 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Nancy Sullivan\Application Data\TaxCut
[2009/05/31 02:04:32 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Nancy Sullivan\Application Data\UBitMenu
[2007/03/10 00:41:07 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Nancy Sullivan\Application Data\Viewpoint
[2010/07/04 19:01:04 | 000,000,408 | -Hโ€“ | M] () โ€“ C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2010/07/04 19:19:00 | 000,000,440 | -Hโ€“ | M] () โ€“ C:\WINDOWS\Tasks\User_Feed_Synchronization-{43B844AD-C92B-4D94-8956-E807FCE75F2F}.job

========== Purity Check ==========


< End of report >
Amandapanda88,

This site has good information about different AV products.

๐Ÿ–ผClick to load external image (Posted Image) Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5577
    O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
    O33 - MountPoints2\{77acc521-1b4f-11dc-a63f-0013ce85c3fd}\Shell - "" = AutoRun
    O33 - MountPoints2\{77acc521-1b4f-11dc-a63f-0013ce85c3fd}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{77acc521-1b4f-11dc-a63f-0013ce85c3fd}\Shell\AutoRun\command - "" = E:\LaunchU3.exe โ€“ File not found
    O33 - MountPoints2\{77acc524-1b4f-11dc-a63f-0013ce85c3fd}\Shell - "" = AutoRun
    O33 - MountPoints2\{77acc524-1b4f-11dc-a63f-0013ce85c3fd}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{77acc524-1b4f-11dc-a63f-0013ce85c3fd}\Shell\AutoRun\command - "" = E:\LaunchU3.exe โ€“ File not found
    [2010/06/26 03:47:13 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Nancy Sullivan\Local Settings\Application Data\epgxyucrk
    
    :Files
    C:\Documents and Settings\Nancy Sullivan\Application Data\Sun\Java\Deployment\cache\6.0\44\690b50ac-79497877
    C:\Documents and Settings\Nancy Sullivan\Application Data\Sun\Java\Deployment\cache\6.0\44\690b50ac-79497877
    C:\Documents and Settings\Nancy Sullivan\Application Data\Sun\Java\Deployment\cache\6.0\44\690b50ac-79497877
    C:\Documents and Settings\Nancy Sullivan\Application Data\Sun\Java\Deployment\cache\6.0\44\696d2fac-40dc0393
    C:\Documents and Settings\Nancy Sullivan\Local Settings\Temp\jar_cache2041665759069945083.tmp
    C:\Documents and Settings\Nancy Sullivan\Local Settings\Temp\jar_cache226517768372090667.tmp
    C:\Documents and Settings\Nancy Sullivan\Local Settings\Temp\jar_cache8840940439660224512.tmp
    C:\Documents and Settings\Nancy Sullivan\Local Settings\Temp\plugtmp-16\plugin-kfmec.pdf
    C:\Documents and Settings\Nancy Sullivan\Local Settings\Temporary Internet Files\Content.IE5\W6D0CXO7\rqsysd[1].pdf
    
    :Commands
    [ClearAllRestorePoints]
    [EmptyFlash]
    [EmptyTemp]
    [Purity]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log
Please include the following in your next post:
  • OTL Fix log
  • How is the computer running?
Before I follow your last set of instructions I have a question. Why get rid of all the restore points? That seems like a scary thing to do.
That directive will clear your old restore points and create a new one. We remove the old ones because they will contain the malware from your infection(s) and if you used one, you would also restore the malware. There is no way to clean them, so we clear the old ones and start fresh.
I have to try it awhile to really answer your question about "How is the comupter running?" But the simple answer is that it seems to be running better each time I do one of your fixes. All processes killed ========== OTL ========== HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{77acc521-1b4f-11dc-a63f-0013ce85c3fd}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77acc521-1b4f-11dc-a63f-0013ce85c3fd}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{77acc521-1b4f-11dc-a63f-0013ce85c3fd}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77acc521-1b4f-11dc-a63f-0013ce85c3fd}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{77acc521-1b4f-11dc-a63f-0013ce85c3fd}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77acc521-1b4f-11dc-a63f-0013ce85c3fd}\ not found. File E:\LaunchU3.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{77acc524-1b4f-11dc-a63f-0013ce85c3fd}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77acc524-1b4f-11dc-a63f-0013ce85c3fd}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{77acc524-1b4f-11dc-a63f-0013ce85c3fd}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77acc524-1b4f-11dc-a63f-0013ce85c3fd}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{77acc524-1b4f-11dc-a63f-0013ce85c3fd}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77acc524-1b4f-11dc-a63f-0013ce85c3fd}\ not found. File E:\LaunchU3.exe not found. C:\Documents and Settings\Nancy Sullivan\Local Settings\Application Data\epgxyucrk folder moved successfully. ========== FILES ========== C:\Documents and Settings\Nancy Sullivan\Application Data\Sun\Java\Deployment\cache\6.0\44\690b50ac-79497877 moved successfully. File\Folder C:\Documents and Settings\Nancy Sullivan\Application Data\Sun\Java\Deployment\cache\6.0\44\690b50ac-79497877 not found. File\Folder C:\Documents and Settings\Nancy Sullivan\Application Data\Sun\Java\Deployment\cache\6.0\44\690b50ac-79497877 not found. C:\Documents and Settings\Nancy Sullivan\Application Data\Sun\Java\Deployment\cache\6.0\44\696d2fac-40dc0393 moved successfully. C:\Documents and Settings\Nancy Sullivan\Local Settings\Temp\jar_cache2041665759069945083.tmp moved successfully. C:\Documents and Settings\Nancy Sullivan\Local Settings\Temp\jar_cache226517768372090667.tmp moved successfully. C:\Documents and Settings\Nancy Sullivan\Local Settings\Temp\jar_cache8840940439660224512.tmp moved successfully. C:\Documents and Settings\Nancy Sullivan\Local Settings\Temp\plugtmp-16\plugin-kfmec.pdf moved successfully. C:\Documents and Settings\Nancy Sullivan\Local Settings\Temporary Internet Files\Content.IE5\W6D0CXO7\rqsysd[1].pdf moved successfully. ========== COMMANDS ========== Restore points cleared and new OTL Restore Point set! [EMPTYFLASH] User: Administrator User: All Users User: Default User ->Flash cache emptied: 41 bytes User: Guest ->Flash cache emptied: 5287 bytes User: LocalService ->Flash cache emptied: 403 bytes User: Nancy Sullivan ->Flash cache emptied: 1856857 bytes User: NetworkService Total Flash Files Cleaned = 2.00 mb [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 0 bytes User: Guest ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 47595 bytes ->Flash cache emptied: 0 bytes User: Nancy Sullivan ->Temp folder emptied: 304083447 bytes ->Temporary Internet Files folder emptied: 233136981 bytes ->Java cache emptied: 25863795 bytes ->FireFox cache emptied: 56865884 bytes ->Google Chrome cache emptied: 296569887 bytes ->Opera cache emptied: 25160 bytes ->Flash cache emptied: 0 bytes User: NetworkService ->Temp folder emptied: 774968 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 145596192 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 430427555 bytes Total Files Cleaned = 1,424.00 mb OTL by OldTimer - Version 3.2.7.1 log created on 07052010_004145 Files\Folders moved on Rebootโ€ฆ C:\Documents and Settings\NetworkService\Local Settings\Temp\MpCmdRun.log moved successfully. File\Folder C:\WINDOWS\temp\logishrd\LVPrcInj01.dll not found! Registry entries deleted on Rebootโ€ฆ
Amandapanda88,

Your logs look good now. All thats left is an important update and some cleanup:

๐Ÿ–ผClick to load external image (Posted Image) Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 6 and save it to your desktop.
  • Scroll down to where it says "Java SE Runtime Environment (JRE) 6 Update 20. The Java SE Runtime Environment (JRE) allows end-users to run Java applications."
  • Click the "Download" button to the right.
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: " I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Now go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Javaโ„ข 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u20-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH Checked
      Applications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.
๐Ÿ–ผClick to load external image (Posted Image) Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
  • Manually delete any remaining logs or tools.
๐Ÿ–ผClick to load external image (Posted Image) Finally, I'd like to make a couple of suggestions to help you stay clean in the future:
  • Restart any anti-malware programs that we disabled while we were cleaning your machine.
  • Keep your antivirus application current and updated. Also, hang on to MBAM. Scan with them at least weekly.
  • Consider running in a limited user account. See this post for more information.
  • Please carefully review the information in our Security - Best Practices and Prevention forum located HERE
Please post once more so I know you are all set and I can close this thread. Good luck and stay safe!
Thank you very much. Everything seems to be working now. I should mention that JRE 6 update 20 was not the latest version. So I used update 21. I want to thank you again for all your time and effort. Where do I send the cupcakes? :-)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI