Hi NightWizard
I have to say, I am amazed right now. I didn't think my computer was going to recover, but things seem to be running very well - no internet crashes and no re-directs (at least in the short time I nave been on-line).
I actually removed AVG prior to running ComboFix, and am certainly open to suggestions for solid Real-time AV software. I also removed Limewire and UTorrent (they hadn't been used for a very long time anyway, so no reason for them to be there)
Here are the logs
Combofix
ComboFix 10-07-16.01 - Lee or Sandra 07/18/2010 11:02:34.2.1 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2047.1778 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Lee or Sandra\Desktop\CFScript.txt
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\NetworkService\Local Settings\Application Data\xvupnppyo
c:\windows\system32\hlp.dat
.
————— FCopy —————
c:\windows\ServicePackFiles\i386\ws2help.dll –> c:\windows\system32\ws2help.dll
c:\windows\ServicePackFiles\i386\ws2help.dll –> c:\windows\$NtServicePackUninstall$\ws2help.dll
.
((((((((((((((((((((((((( Files Created from 2010-06-18 to 2010-07-18 )))))))))))))))))))))))))))))))
.
2010-07-15 17:18 . 2010-07-15 17:18 ——– d—–w- c:\program files\Trend Micro
2010-07-15 17:04 . 2001-08-18 05:36 138752 —-a-w- c:\windows\system32\sendvol32.exe
2010-07-05 23:33 . 2010-07-05 23:38 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-07-05 03:26 . 2010-07-05 03:26 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2010-07-05 03:25 . 2010-07-05 03:25 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Google
2010-07-04 01:51 . 2010-07-04 08:57 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-07-02 21:45 . 2010-07-02 21:45 ——– d—–w- c:\documents and settings\NetworkService\Application Data\AdobeUM
2010-07-02 21:44 . 2010-07-02 21:45 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-07-02 21:44 . 2010-07-02 21:44 ——– d-s—w- c:\documents and settings\NetworkService\UserData
2010-07-02 21:20 . 2010-07-07 06:26 ——– d—–w- c:\documents and settings\Administrator\Application Data\Spyware Terminator
2010-06-30 21:22 . 2010-06-30 21:22 ——– d—–w- c:\windows\system32\LogFiles
2010-06-30 15:22 . 2010-07-16 16:21 0 —-a-w- c:\windows\Skiqafavinasowov.bin
2010-06-30 15:22 . 2010-07-09 05:16 120 —-a-w- c:\windows\Hzefodurexurivik.dat
2010-06-30 06:22 . 2010-07-02 22:52 ——– d—–w- c:\documents and settings\Lee or Sandra\Application Data\EA377B0C8D08E79FEBE0FBA0E7E9F7E7
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-18 17:56 . 2009-11-22 03:14 ——– d—–w- c:\documents and settings\Lee or Sandra\Application Data\uTorrent
2010-07-18 17:54 . 2008-02-26 05:44 ——– d—–w- c:\program files\Google
2010-07-17 20:45 . 2009-04-13 08:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2010-07-16 17:50 . 2010-03-20 15:24 0 —-a-w- c:\documents and settings\Lee or Sandra\Local Settings\Application Data\prvlcl.dat
2010-07-16 07:00 . 2007-04-01 05:34 ——– d—–w- c:\documents and settings\Lee or Sandra\Application Data\Spyware Terminator
2010-07-15 17:18 . 2010-07-15 17:18 388096 —-a-r- c:\documents and settings\Lee or Sandra\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-03 00:44 . 2010-03-04 20:18 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-02 20:39 . 2010-07-02 20:39 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-06-30 23:00 . 2007-04-01 05:33 ——– d—–w- c:\program files\Spyware Terminator
2010-06-30 16:06 . 2007-04-01 05:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2010-06-11 16:57 . 2008-05-11 18:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-05-25 06:35 . 2010-05-25 06:35 348160 —-a-w- c:\documents and settings\Lee or Sandra\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-5fa89df4-n\msvcr71.dll
2010-05-25 06:35 . 2010-05-25 06:35 503808 —-a-w- c:\documents and settings\Lee or Sandra\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-5fa89df4-n\msvcp71.dll
2010-05-25 06:35 . 2010-05-25 06:35 499712 —-a-w- c:\documents and settings\Lee or Sandra\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-5fa89df4-n\jmc.dll
2010-05-16 06:08 . 2010-05-16 06:08 73000 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2010-05-02 05:56 . 2003-07-16 20:51 1850880 —-a-w- c:\windows\system32\win32k.sys
2010-05-01 18:20 . 2006-10-01 07:03 73048 —-a-w- c:\documents and settings\Lee or Sandra\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-29 22:39 . 2010-03-04 20:18 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 22:39 . 2010-03-04 20:18 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-20 05:51 . 2003-07-16 20:24 285696 —-a-w- c:\windows\system32\atmfd.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus Photo R300 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE" [2003-06-04 99840]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-13 39408]
"uTorrent"="c:\documents and settings\Lee or Sandra\Desktop\utorrent.exe" [2009-11-22 289584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"diagent"="c:\program files\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 135264]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-17 8491008]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2006-06-30 1106386]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2006-06-30 126976]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2006-06-30 1848150]
"EPSON Stylus Photo R300 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE" [2003-06-04 99840]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-07-26 1817600]
"nwiz"="nwiz.exe" [2007-09-17 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-17 81920]
"Phase One Media Reader"="c:\progra~1\PHASEO~1\CAPTUR~2\DCIMImp.exe" [2008-01-31 229376]
"Disc Detector"="c:\program files\Creative\ShareDLL\CtNotify.exe" [2001-12-26 191488]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
c:\documents and settings\Lee or Sandra\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2008-12-25 385024]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-11-21 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\KEM.exe [2006-10-1 581632]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\TVersity\\Media Server\\MediaServer.exe"=
"c:\\Documents and Settings\\Lee or Sandra\\Desktop\\utorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [7/29/2008 12:00 AM 141312]
R2 P1C1394;Phase One 1394 Camera Driver;c:\windows\system32\drivers\p1c1394.sys [7/4/2008 5:57 PM 23168]
S2 gupdate1c9bc1444f2956a;Google Update Service (gupdate1c9bc1444f2956a);c:\program files\Google\Update\GoogleUpdate.exe [4/13/2009 1:45 AM 133104]
.
Contents of the 'Scheduled Tasks' folder
2010-07-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:34]
2010-07-18 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-13 08:43]
2010-07-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 08:45]
2010-07-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 08:45]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Handler: intu-qt2007 - {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - c:\program files\QuickTax 2007\ic2007pp.dll
FF - ProfilePath - c:\documents and settings\Lee or Sandra\Application Data\Mozilla\Firefox\Profiles\f0k5m4as.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-07-18 11:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Disc Detector = c:\program files\Creative\ShareDLL\CtNotify.exe?X???????????????????E?@?Disc Detector?A????? ?A?? ????B?e!@???@???@?? C?????E?@?????????@?B???A????? ?A?0?????B???@?????P?????@?? ????????A~??????????@??? ???????????????B?????
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
EPSON Stylus Photo R300 Series = c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P30 "EPSON Stylus Photo R300 Series" /M "Stylus Photo R300" /EF "HKCU"?????s????????????YB~????????????????p????????????????????YB~????p???????????8???????????X?C~????p???????j?C~p??????????????|???????
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'lsass.exe'(772)
c:\windows\system32\relog_ap.dll
- - - - - - - > 'explorer.exe'(2304)
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\System32\CTsvcCDA.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\program files\TVersity\Media Server\MediaServer.exe
c:\windows\System32\MsPMSPSv.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Creative\ShareDLL\Mediadet.exe
c:\program files\Logitech\SetPoint\KHALMNPR.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-07-18 11:16:41 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-18 18:16
ComboFix2.txt 2010-07-18 05:16
Pre-Run: 61,271,339,008 bytes free
Post-Run: 61,277,233,152 bytes free
- - End Of File - - E34561234A84837995C5C429A324C3BD
MalwareBytes Log
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4311
Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 6.0.2900.2180
7/18/2010 11:59:49 AM
mbam-log-2010-07-18 (11-59-49).txt
Scan type: Full scan (C:\|)
Objects scanned: 235705
Time elapsed: 35 minute(s), 19 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
OTL ( I ran the basic quick scan, but did not copy and paste the special instructions from the first go-around)
OTL logfile created on: 7/18/2010 12:09:46 PM - Run 2
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Documents and Settings\Lee or Sandra\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 77.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 132.11 Gb Total Space | 57.08 Gb Free Space | 43.20% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 495.22 Mb Total Space | 404.55 Mb Free Space | 81.69% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: UPSTAIRS
Current User Name: Lee or Sandra
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010/07/16 16:22:51 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Lee or Sandra\My Documents\Downloads\OTL.exe
PRC - [2010/04/16 08:33:40 | 000,144,672 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2009/09/22 14:31:56 | 000,856,064 | —- | M] () – C:\Program Files\TVersity\Media Server\MediaServer.exe
PRC - [2009/05/15 07:35:52 | 000,935,208 | —- | M] (Nero AG) – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2008/07/26 00:18:31 | 001,817,600 | —- | M] (Crawler.com) – C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
PRC - [2008/07/26 00:18:31 | 000,606,720 | —- | M] (Crawler.com) – C:\Program Files\Spyware Terminator\sp_rsser.exe
PRC - [2007/11/22 12:49:08 | 000,385,024 | —- | M] (Sony Corporation) – C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
PRC - [2007/06/13 03:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2006/06/30 06:31:10 | 001,106,386 | —- | M] (Acronis) – C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
PRC - [2006/06/29 19:06:32 | 001,848,150 | —- | M] (Acronis) – C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
PRC - [2006/06/29 19:06:00 | 000,126,976 | —- | M] (Acronis) – C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
PRC - [2006/06/29 19:05:58 | 000,204,800 | —- | M] (Acronis) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
PRC - [2005/09/23 22:05:26 | 000,029,696 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
PRC - [2004/10/28 09:29:48 | 000,581,632 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\SetPoint\KEM.exe
PRC - [2004/10/21 13:28:40 | 000,029,696 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\SetPoint\KHALMNPR.exe
PRC - [2003/06/04 04:00:00 | 000,099,840 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2F1.EXE
PRC - [2002/04/30 02:00:00 | 000,167,424 | —- | M] (Creative Technology Ltd.) – C:\Program Files\Creative\ShareDLL\Mediadet.exe
PRC - [2002/04/03 01:01:00 | 000,135,264 | —- | M] (Creative Technology Ltd) – C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
PRC - [2001/12/26 02:00:00 | 000,191,488 | —- | M] (Creative Technology Ltd.) – C:\Program Files\Creative\ShareDLL\CTNotify.exe
========== Modules (SafeList) ==========
MOD - [2010/07/16 16:22:51 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Lee or Sandra\My Documents\Downloads\OTL.exe
MOD - [2006/08/25 08:45:55 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
MOD - [2004/10/28 09:27:18 | 000,086,016 | —- | M] () – C:\Program Files\Logitech\SetPoint\lgscroll.dll
MOD - [2004/08/03 23:01:17 | 000,102,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] – C:\WINDOWS\System32\appmgmts.dll – (AppMgmt)
SRV - [2010/04/16 08:33:40 | 000,144,672 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2009/09/22 14:31:56 | 000,856,064 | —- | M] () [Auto | Running] – C:\Program Files\TVersity\Media Server\MediaServer.exe – (TVersityMediaServer)
SRV - [2009/05/15 07:35:52 | 000,935,208 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe – (Nero BackItUp Scheduler 4.0)
SRV - [2008/07/26 00:18:31 | 000,606,720 | —- | M] (Crawler.com) [Auto | Running] – C:\Program Files\Spyware Terminator\sp_rsser.exe – (sp_rssrv)
SRV - [2007/01/31 12:13:34 | 000,315,904 | —- | M] (Crawler.com) [Auto | Stopped] – C:\Program Files\WinClamAVShield\Sp_clamsrv.exe – (sp_clamsrv)
SRV - [2006/06/29 19:05:58 | 000,204,800 | —- | M] (Acronis) [Auto | Running] – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe – (AcrSch2Svc)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] – C:\ComboFix\catchme.sys – (catchme)
DRV - [2008/07/29 00:00:20 | 000,141,312 | —- | M] () [Kernel | System | Running] – C:\WINDOWS\system32\drivers\sp_rsdrv2.sys – (sp_rsdrv2)
DRV - [2008/07/04 17:57:55 | 000,457,216 | —- | M] (Aladdin Knowledge Systems) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\hardlock.sys – (hardlock)
DRV - [2008/07/04 17:57:52 | 000,047,616 | —- | M] (Aladdin Knowledge Systems) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\Haspnt.sys – (Haspnt)
DRV - [2007/09/17 01:07:00 | 006,853,088 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2006/09/30 22:13:57 | 000,388,000 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\timntr.sys – (timounter)
DRV - [2006/09/30 22:13:57 | 000,032,288 | —- | M] (Acronis) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\tifsfilt.sys – (tifsfilter)
DRV - [2006/09/30 22:13:53 | 000,099,776 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\snapman.sys – (snapman)
DRV - [2006/05/05 19:21:00 | 000,004,608 | —- | M] (NVIDIA Corporation.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\nvport.sys – (nvport)
DRV - [2006/03/29 08:49:26 | 000,009,856 | —- | M] (Padus, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\pfc.sys – (pfc)
DRV - [2005/10/27 15:27:44 | 000,023,168 | —- | M] (Phase One A/S) [Kernel | Auto | Running] – C:\WINDOWS\System32\Drivers\p1c1394.sys – (P1C1394)
DRV - [2004/10/21 13:31:06 | 000,054,851 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\L8042mou.Sys – (L8042mou)
DRV - [2004/10/21 13:30:56 | 000,071,535 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\LMouKE.Sys – (LMouKE)
DRV - [2004/08/03 23:08:21 | 000,010,624 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\gameenum.sys – (gameenum)
DRV - [2003/08/14 08:58:12 | 001,296,384 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\P16X.sys – (P16X) Creative SB Live! Series (WDM)
DRV - [2001/08/22 08:42:58 | 000,013,632 | —- | M] (Dell Computer Corporation) [Kernel | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS – (OMCI)
DRV - [1999/12/17 01:00:00 | 000,006,752 | —- | M] (Creative Technology Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\system32\PFMODNT.SYS – (PfModNT)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.ca/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "
http://www.google.ca"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.825
FF - prefs.js..extensions.enabledItems: {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:2.9.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {551A6336-63D9-4FC7-A4E2-C28E2212894A}:1.9.1
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/05 19:15:06 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/05 16:38:05 | 000,000,000 | —D | M]
[2009/08/04 20:03:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\Mozilla\Extensions
[2010/07/15 10:07:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\Mozilla\Firefox\Profiles\f0k5m4as.default\extensions
[2010/05/16 16:29:18 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Lee or Sandra\Application Data\Mozilla\Firefox\Profiles\f0k5m4as.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2009/09/02 09:12:19 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Lee or Sandra\Application Data\Mozilla\Firefox\Profiles\f0k5m4as.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2007/08/28 00:10:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\Mozilla\Firefox\Profiles\f0k5m4as.default\extensions\[removed]
[2010/07/15 10:07:14 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2004/11/12 20:36:20 | 000,005,120 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Mozilla Firefox\plugins\NPAdbESD.dll
[2008/06/30 22:02:00 | 000,663,072 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\npOGAPlugin.dll
O1 HOSTS File: ([2010/07/18 11:10:34 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll File not found
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [diagent] C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CTNotify.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [Phase One Media Reader] C:\Program Files\Phase One\Capture One PRO\DCIMImp.exe (Phase One A/S, Copenhagen, Denmark)
O4 - HKLM..\Run: [SpywareTerminator] C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe (Crawler.com)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKCU..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [uTorrent] C:\Documents and Settings\Lee or Sandra\Desktop\utorrent.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Lee or Sandra\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdat…b?1159680962000 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\intu-qt2007 {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-qt2008 {05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596} - C:\Program Files\QuickTax 2008\ic2008pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Lee or Sandra\Local Settings\Application Data\Microsoft\Wallpaper2.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Lee or Sandra\Local Settings\Application Data\Microsoft\Wallpaper2.bmp
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/30 15:39:42 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/06/25 22:29:08 | 000,000,090 | —- | M] () - E:\AUTORUN.INF – [ FAT ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 90 Days ==========
[2010/07/18 12:03:27 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/07/18 11:09:16 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/07/17 21:41:00 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/07/17 21:35:27 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/07/17 21:35:27 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/07/17 21:35:27 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/07/17 21:35:27 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/07/17 21:35:15 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/07/17 13:52:15 | 000,000,000 | —D | C] – C:\Qoobox
[2010/07/15 10:18:34 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/07/05 16:33:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NOS
[2010/07/05 01:04:31 | 000,000,000 | —D | C] – C:\Program Files\msn gaming zone
[2010/07/03 19:05:24 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/07/03 19:05:24 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/07/03 18:51:13 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/07/02 14:45:44 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\AdobeUM
[2010/07/02 14:44:31 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/06/30 14:22:09 | 000,000,000 | —D | C] – C:\WINDOWS\System32\LogFiles
[2010/06/29 23:39:49 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/06/29 23:39:48 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/06/29 23:22:07 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee or Sandra\Application Data\EA377B0C8D08E79FEBE0FBA0E7E9F7E7
[2010/06/11 09:39:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee or Sandra\Local Settings\Application Data\PCHealth
[2010/05/16 16:31:40 | 000,000,000 | —D | C] – C:\Program Files\Garmin GPS Plugin
[2010/05/16 16:31:38 | 000,000,000 | —D | C] – C:\Program Files\DIFX
[2010/05/16 16:31:35 | 000,000,000 | —D | C] – C:\Program Files\Garmin
[2010/05/16 16:29:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee or Sandra\Application Data\GARMIN
[2010/05/15 23:17:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/05/15 23:14:25 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/05/15 23:11:26 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/04/30 22:26:55 | 000,000,000 | —D | C] – C:\Program Files\QuickTax 2009
[2006/09/30 17:05:59 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\A3d.dll
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 90 Days ==========
[2010/07/18 12:07:05 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/07/18 12:07:02 | 000,000,482 | —- | M] () – C:\WINDOWS\System32\tversity.cookies
[2010/07/18 12:06:50 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/07/18 12:06:45 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/07/18 12:06:43 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/07/18 12:06:04 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Lee or Sandra\ntuser.ini
[2010/07/18 12:06:03 | 006,029,312 | —- | M] () – C:\Documents and Settings\Lee or Sandra\NTUSER.DAT
[2010/07/18 11:20:05 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/07/18 11:10:50 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/07/18 11:10:34 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/07/17 21:41:05 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/07/17 13:35:02 | 003,738,205 | R— | M] () – C:\Documents and Settings\Lee or Sandra\Desktop\ComboFix.exe
[2010/07/16 22:52:55 | 000,076,695 | —- | M] () – C:\Documents and Settings\Lee or Sandra\Desktop\outlookcontacts.csv
[2010/07/16 22:52:51 | 000,038,487 | —- | M] () – C:\Documents and Settings\Lee or Sandra\Application Data\Comma Separated Values (Windows).ADR
[2010/07/16 10:50:54 | 000,000,000 | —- | M] () – C:\Documents and Settings\Lee or Sandra\Local Settings\Application Data\prvlcl.dat
[2010/07/16 09:21:27 | 000,000,000 | —- | M] () – C:\WINDOWS\Skiqafavinasowov.bin
[2010/07/15 10:18:34 | 000,002,000 | —- | M] () – C:\Documents and Settings\Lee or Sandra\Desktop\HiJackThis.lnk
[2010/07/14 08:36:54 | 000,000,036 | —- | M] () – C:\Documents and Settings\Lee or Sandra\Local Settings\Application Data\housecall.guid.cache
[2010/07/12 21:38:58 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/07/08 22:16:35 | 000,000,120 | —- | M] () – C:\WINDOWS\Hzefodurexurivik.dat
[2010/07/06 23:40:31 | 000,010,397 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\Shopping for Ranch.xlsx
[2010/07/06 10:43:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/07/06 08:09:39 | 000,001,891 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/07/05 16:30:35 | 000,001,620 | —- | M] () – C:\Documents and Settings\Lee or Sandra\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/07/05 16:30:35 | 000,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/07/05 08:22:40 | 000,000,104 | —- | M] () – C:\Documents and Settings\Lee or Sandra\Desktop\E-mail.lnk
[2010/07/05 01:03:00 | 000,511,926 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/07/05 01:03:00 | 000,435,260 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/07/05 01:03:00 | 000,068,156 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/07/04 01:57:52 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/06/27 19:49:19 | 000,000,287 | —- | M] () – C:\Documents and Settings\Lee or Sandra\Application Data\default.rss
[2010/06/27 19:48:22 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/06/27 19:48:00 | 000,014,673 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\93 - Ami Dagan, Dan Dejong, Lee Aitchison, Jarett Vermette - The Smart Menu.docx.dat
[2010/06/24 11:16:06 | 000,002,587 | —- | M] () – C:\Documents and Settings\All Users\Desktop\ACDSee 10 Photo Manager.lnk
[2010/06/13 22:13:00 | 000,021,239 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\smart menu proforma v4_lee_June 12_2010.xlsx
[2010/06/11 18:48:15 | 000,274,168 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/06 13:52:28 | 000,065,536 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\Hat $.pub
[2010/06/06 13:51:34 | 000,065,536 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\Ladies T $.pub
[2010/06/06 13:44:07 | 000,065,536 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\T-shirt $.pub
[2010/06/06 13:39:12 | 000,065,024 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\Please Order shirts by Number.pub
[2010/06/06 13:34:11 | 000,046,592 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\Back Label - 8163.pub
[2010/06/06 13:32:55 | 000,046,592 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\Front Label - 8163.pub
[2010/05/25 15:27:16 | 000,013,824 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\Ducati Case - Q3.docx
[2010/05/25 15:22:06 | 000,114,544 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\MBA 544 Case #3 Ducati (Italy) vs Harley-Davidson (USA) Memo v3.docx
[2010/05/15 23:28:53 | 000,047,104 | —- | M] () – C:\Documents and Settings\Lee or Sandra\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/15 22:18:00 | 003,142,654 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\Brandon.avi
[2010/05/15 22:18:00 | 002,308,198 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\Second Years.avi
[2010/05/11 08:17:53 | 000,025,088 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\Doug Retirement Program.doc
[2010/05/01 11:20:47 | 000,073,048 | —- | M] () – C:\Documents and Settings\Lee or Sandra\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/26 15:58:12 | 000,256,512 | —- | M] () – C:\WINDOWS\PEV.exe
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/07/17 21:41:04 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/07/17 21:41:00 | 000,260,272 | —- | C] () – C:\cmldr
[2010/07/17 21:35:27 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/07/17 21:35:27 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/07/17 21:35:27 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/07/17 21:35:27 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/07/17 21:35:27 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/07/17 13:51:12 | 003,738,205 | R— | C] () – C:\Documents and Settings\Lee or Sandra\Desktop\ComboFix.exe
[2010/07/16 22:52:51 | 000,038,487 | —- | C] () – C:\Documents and Settings\Lee or Sandra\Application Data\Comma Separated Values (Windows).ADR
[2010/07/16 22:52:42 | 000,076,695 | —- | C] () – C:\Documents and Settings\Lee or Sandra\Desktop\outlookcontacts.csv
[2010/07/15 10:18:34 | 000,002,000 | —- | C] () – C:\Documents and Settings\Lee or Sandra\Desktop\HiJackThis.lnk
[2010/07/14 08:36:54 | 000,000,036 | —- | C] () – C:\Documents and Settings\Lee or Sandra\Local Settings\Application Data\housecall.guid.cache
[2010/07/06 17:39:49 | 000,010,397 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\Shopping for Ranch.xlsx
[2010/07/05 16:30:35 | 000,001,620 | —- | C] () – C:\Documents and Settings\Lee or Sandra\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/07/05 16:30:35 | 000,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/07/05 08:22:40 | 000,000,104 | —- | C] () – C:\Documents and Settings\Lee or Sandra\Desktop\E-mail.lnk
[2010/07/03 18:51:13 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/06/30 08:22:33 | 000,000,120 | —- | C] () – C:\WINDOWS\Hzefodurexurivik.dat
[2010/06/30 08:22:33 | 000,000,000 | —- | C] () – C:\WINDOWS\Skiqafavinasowov.bin
[2010/06/27 19:49:07 | 000,014,673 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\93 - Ami Dagan, Dan Dejong, Lee Aitchison, Jarett Vermette - The Smart Menu.docx.dat
[2010/06/13 22:13:00 | 000,021,239 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\smart menu proforma v4_lee_June 12_2010.xlsx
[2010/06/06 13:51:34 | 000,065,536 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\Ladies T $.pub
[2010/06/06 13:45:36 | 000,065,536 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\Hat $.pub
[2010/06/06 13:44:07 | 000,065,536 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\T-shirt $.pub
[2010/06/06 13:39:12 | 000,065,024 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\Please Order shirts by Number.pub
[2010/06/06 13:34:10 | 000,046,592 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\Back Label - 8163.pub
[2010/06/06 13:32:55 | 000,046,592 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\Front Label - 8163.pub
[2010/05/25 15:27:16 | 000,013,824 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\Ducati Case - Q3.docx
[2010/05/25 15:22:06 | 000,114,544 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\MBA 544 Case #3 Ducati (Italy) vs Harley-Davidson (USA) Memo v3.docx
[2010/05/15 22:18:00 | 003,142,654 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\Brandon.avi
[2010/05/15 22:18:00 | 002,308,198 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\Second Years.avi
[2010/05/11 08:17:53 | 000,025,088 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\Doug Retirement Program.doc
[2009/11/22 15:02:03 | 000,000,018 | —- | C] () – C:\WINDOWS\isbn0-7879-5674-0.ini
[2009/05/31 14:26:30 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/05/31 13:52:14 | 000,004,767 | —- | C] () – C:\WINDOWS\Irremote.ini
[2008/12/25 01:18:38 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/10/30 22:27:40 | 000,001,024 | —- | C] () – C:\WINDOWS\System32\grcauth2.dll
[2008/10/30 22:27:40 | 000,001,024 | —- | C] () – C:\WINDOWS\System32\grcauth1.dll
[2008/10/30 22:27:40 | 000,000,100 | —- | C] () – C:\WINDOWS\System32\prsgrc.dll
[2008/10/30 22:23:56 | 000,001,025 | —- | C] () – C:\WINDOWS\System32\sysprs7.dll
[2008/10/30 22:23:56 | 000,000,205 | —- | C] () – C:\WINDOWS\System32\lsprst7.dll
[2008/07/29 00:00:20 | 000,141,312 | —- | C] () – C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2008/07/04 17:57:52 | 000,000,383 | —- | C] () – C:\WINDOWS\System32\haspdos.sys
[2008/03/10 08:16:36 | 000,524,288 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/03/10 08:16:36 | 000,383,238 | —- | C] () – C:\WINDOWS\System32\libmp3lame-0.dll
[2007/09/17 01:07:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2007/09/17 01:07:00 | 001,478,656 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2007/09/17 01:07:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2007/09/17 01:07:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2007/09/17 01:07:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2007/08/27 23:19:04 | 001,936,528 | —- | C] () – C:\WINDOWS\System32\ltmm15.dll
[2007/07/25 19:53:34 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007/07/22 22:45:49 | 000,000,092 | —- | C] () – C:\WINDOWS\QTW.INI
[2006/11/04 22:22:40 | 000,000,147 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/11/04 22:22:39 | 000,034,816 | —- | C] () – C:\WINDOWS\System32\asxswai.dll
[2006/10/31 23:33:51 | 000,000,093 | —- | C] () – C:\WINDOWS\R300.ini
[2006/10/01 16:53:43 | 000,000,737 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/10/01 00:57:58 | 000,000,287 | —- | C] () – C:\WINDOWS\game.ini
[2006/09/30 17:06:11 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2006/09/30 17:05:59 | 000,047,616 | —- | C] () – C:\WINDOWS\System32\P16X.dll
[2006/09/30 17:05:59 | 000,002,158 | —- | C] () – C:\WINDOWS\System32\P16X.ini
[2006/09/30 17:05:59 | 000,000,026 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2006/09/30 17:05:56 | 000,002,572 | —- | C] () – C:\WINDOWS\MIXDEF.INI
[2006/09/30 17:05:55 | 000,000,064 | —- | C] () – C:\WINDOWS\P16x.ini
[2006/09/30 17:05:17 | 000,000,245 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2006/09/30 16:56:45 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2006/09/30 16:50:47 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/07/16 13:28:11 | 000,032,770 | —- | C] () – C:\WINDOWS\System32\ltinp32.dll
[2003/07/16 13:28:11 | 000,028,674 | —- | C] () – C:\WINDOWS\System32\prckrep.dll
[2003/07/16 13:28:11 | 000,025,602 | —- | C] () – C:\WINDOWS\System32\llpink_.dll
[1997/07/11 00:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[1997/07/11 00:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1997/07/11 00:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL
========== LOP Check ==========
[2009/06/26 22:38:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Abstract
[2007/12/31 19:12:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ACD Systems
[2006/09/30 20:26:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2008/07/23 08:39:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG7
[2009/06/26 22:34:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2006/09/30 22:24:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2008/10/30 22:26:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SafeNet Sentinel
[2010/06/30 09:06:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spyware Terminator
[2009/06/26 22:34:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2010/05/15 23:18:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/16 01:32:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/06/28 13:24:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2007/12/31 19:13:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\ACD Systems
[2010/07/02 15:52:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\EA377B0C8D08E79FEBE0FBA0E7E9F7E7
[2010/05/16 16:29:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\GARMIN
[2007/08/27 23:18:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\GetRightToGo
[2006/10/31 23:35:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\Leadertech
[2008/09/23 08:06:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\LimeWire
[2006/11/05 13:27:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\NCH Swift Sound
[2009/06/26 22:35:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\Nikon
[2008/08/23 01:08:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\Smartsims
[2010/07/16 00:00:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\Spyware Terminator
[2006/11/20 22:55:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\Uniblue
[2010/07/18 10:56:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\uTorrent
[2008/12/30 16:42:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\yoclient
========== Purity Check ==========
< End of report >
Once again, thank you so much! (and if you have suggestions on AV tools I should be running, please let me know.)
Lee