This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan.Hiloti.Gen + Rogue.AntivirusSuite+Google Re-directs + many more

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi There

About 10 days ago, I started to experience problems due to malware infections. It started with AVG announcing a threat had been blocked, yet at the same time, my printer started to randomly print blank pages and I had five DOS screens open and tile while I was accessing the internet. I immediately pulled the plug on the internet and did a hard shutdown. I restarted the computer in safe mode and did a full scan with AVG - it identified several Trojans, which it said it was able to remove. I also did a quick scan with MalwareBytes and it found two other Trojans that it said were removed.

Since that time, I continue to get different pieces of malware infecting the computer and many blocked threats - the most common blocked threat is something called Exploit Neosploit Toolkit (1179). My anti-virus software routinely cleans off a new infection with each scan, but I still am experiencing random re-directs when on Google (via FireFox)

I have also now started receiving a message upon start up that there is an error loading C:/Windows/msapdl.dll and have lost my volume controller from the taskbar. The very last threat that was removed was something identified as CAUnst.exe

I am not very computer literate, but hope you may be able to guide me through some tips and tricks for getting my computer back to normal.

I am posting a log from HiJack This and hope someone can provide me some support.

Many thanks,
Lee

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:19:37 AM, on 7/15/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Creative\ShareDLL\Mediadet.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TVersity\Media Server\MediaServer.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\msiexec.exe
C:\Documents and Settings\Lee or Sandra\My Documents\Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Phase One Media Reader] C:\PROGRA~1\PHASEO~1\CAPTUR~2\DCIMImp.exe /noscan /CheckAutoStart
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Gsezenip] rundll32.exe "C:\WINDOWS\ezoxoqoy.dll",Startup
O4 - HKCU\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P30 "EPSON Stylus Photo R300 Series" /M "Stylus Photo R300" /EF "HKCU"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Documents and Settings\Lee or Sandra\Desktop\utorrent.exe"
O4 - HKCU\..\Run: [Eruyuzikag] rundll32.exe "C:\WINDOWS\msapdl.dll",Startup
O4 - HKUS\S-1-5-18\..\Run: [kwnsixyp] C:\Documents and Settings\NetworkService\Local Settings\Application Data\xvupnppyo\dkstprdtssd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [kwnsixyp] C:\Documents and Settings\NetworkService\Local Settings\Application Data\xvupnppyo\dkstprdtssd.exe (User 'Default user')
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1159680962000
O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll
O18 - Protocol: intu-qt2008 - {05E53CE9-66C8-4A9E-A99F-FDB7A8E7B596} - C:\Program Files\QuickTax 2008\ic2008pp.dll
O18 - Protocol: intu-qt2009 - {03947252-2355-4E9B-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Google Update Service (gupdate1c9bc1444f2956a) (gupdate1c9bc1444f2956a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Spyware Terminator Clam Service (sp_clamsrv) - Crawler.com - C:\Program Files\WinClamAVShield\sp_clamsrv.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TVersityMediaServer - Unknown owner - C:\Program Files\TVersity\Media Server\MediaServer.exe

–
End of file - 9470 bytes
Hi VictoriaLee,

:welcome:

My name is NightWizard and I will be your helper. :)

While I go through your log, I would very much appreciate it if you read the following.

  • I aim provide you with the best instructions possible to resolve your issue. However, I ask that you understand that malware is complex and the process usually takes a few attempts before successfully cleaning everything out. In severe cases cleaning may not be possible and a reformat may be our only option.
  • If you are unresponsive to this thread within three days, the thread will be locked due to inactivity. However, if you will be away, let us know and we will be sure to keep the thread open.
  • Please do not make any new threads about this issue here or any other malware removal forum; it wastes other helpers' time and it can be dangerous for your PC.
  • If you don't understand a set of instructions or you are having trouble performing some of the fix, don't panic! Let me know and I will be happy to help in any way I can.
  • Please remember that the absence of symptoms does not mean you are clean. I request that you stick to this log until the very end - I will inform you when your system is clean.
  • Please do not use any tools other than the ones I instruct you to use. Some of the tools available can be dangerous if used incorrectly.

Please be advised that I am still in training at this forum. My posts will be checked by experts before I post in this thread. This is to ensure you get the best possible help available. This may cause delay however I will do my best to limit the time gaps between posts.



Thanks for choosing WhatTheTech and I will be back with a fix shortly! :)


-NightWizard
Hi VictoriaLee,

Lets get to it! :D Please do the following scans and post the requested logs:


1. OTL Scan
Please download OTL from one of the following links
  • LINK 1
  • LINK 2
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in;

    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\system32\spool\prtprocs\w32x86\*.tmp
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them if you need to start a new topic.



2. GMER Scan
Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.


    [external image: Posted Image]
    Click the image to enlarge it


  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries



In your next reply please include:
  • The OTL logs.
  • The GMER log.

Cheers! :thumbup:

-NightWizard
HI NightWizard I have one question before I run the scans you asked for. When I boot up, a window opens saying that there is an error loading C:\Windows\msapdl.dll I have been ignoring it (not clicking OK) because I was worried it was actually a malware message and may further infect things. The computer allows me to continue starting programs even though this message box is open. Since you said to close all windows prior to this scan - should I go ahead and click yes to this message box; then run the OTL scans? Lee
Hi NightWizard So…lots of issues with the computer today. I tried to boot up and it would only load as far as my wallpaper. I was able to start in Safe mode with networking and ran the scans. Now, I am unable to maintain an internet connection - it simply closes off within 40 or 50 seconds. I have saved the txt files to a flash drive and am now on my laptop (actually a Mac, not a PC). I hope these files give you want you need. The Gmer file seems very small compared to the three hours it took to run. There were several tabs with info and I have left it up on the computer just in case you need more than what I'm providing. Sadly, I now can't seem to copy and paste these txt files into the body of this message. I am going to attach the files and see if that works for you. I can also create PDF's of them and send those as well. Not sure what else I can do. Every time a open this message on my PC, it crashes before I can paste the files. Lee
Hi Lee,

Please do the following, if you are unable to use your internet then please use your USB flash drive to transfer tools and scripts over.

NOTE: If you have trouble running Combofix please try running it in safe mode.

To Enter Safemode
  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Safemode
  • Then press the Enter Key on your Keyboard
Tutorial if you need it How to boot into Safemode

1. Combofix
Please download Combofix from one of the following locations:

LINK 1
LINK 2

**IMPORTANT! Save Combofix to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://www.bleepingcomputer.com/forums/topic114351.html
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Cheers :thumbup:
Hi NightWizard So…here is the latest. As I said in my last post, I can only boot up in Safe Mode (which is what I had to do with the previous OTL scans) I downloaded the ComboFix to a flashdrive from my laptop and installed it on the desktop of my PC (in Safemode) I am running realtime AVG 9.0 but in safe mode there is no tray icon to close it off. When I tried to open AVG from the start menu, it couldn't find the shortcut and failed to open the control panel. I then did a CTL/ALT/DEL and tried to end the AVG processes form there. When I started up ComboFix it stated that AVG was still running and to proceed at my own peril. I then decided to remove AVG completely through the add/remove programs utility. After running the remove program feature, the computer stated that the uninstall failed. Interestingly, it also identified that AVG had not run since June 30th and had only been used "rarely" I have it set to run in real time and it also performs a complete scan every night. Since I've had these infection issues (in the last week) I must have run complete scans at least twice a day. Anyway - I tried starting up ComboFix again after the failed removal and it says AVG is still running. Not sure what else I can do and am reluctant to run CF "at my own peril" till I hear back from you. I have everything shut down for now, and will wait for your direction. Lee
Hi Lee, Please continue scanning in safe mode with combofix, when you are warned about AVG click OK to continue scanning. Thanks
Hi NightWizard I have run the combofix program. The good news is that my desktop has returned. At the same time, there have been numerous messages about .exe files failing to initialize. This includes Firefox. I also tried to open internet explorer, but it cannot find a connection (nor can my mail program) I tried to restore the connection through the tools menu, but there was no joy. It seems that several other programs will not initialize such as AVG as well. I have made a copy of the txt file and am attaching it to this reply.
Hi NightWizard I have run the combofix program. The good news is that my desktop has returned. At the same time, there have been numerous messages about .exe files failing to initialize. This includes Firefox. I also tried to open internet explorer, but it cannot find a connection (nor can my mail program) I tried to restore the connection through the tools menu, but there was no joy. It seems that several other programs will not initialize such as AVG as well. I have made a copy of the txt file and am attaching it to this reply. Lee
Hi Lee,

Please work your way through the following steps. Please do the following again in safemode for a greater chance of success.


P2P PROGRAMS

IMPORTANT I notice there are signs of one or more P2P (Person to Person) File Sharing Programs on your computer.

LimeWire
uTorrent


References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm

Note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

My recommendation is you go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).

If you choose not to remove them, please do not use them until this computer is clean.



1. CFScript:
I assume you still have ComboFix on your system.

Please open Notepad and copy/paste this code into the notepad:

Folder::
C:\Documents and Settings\NetworkService\Local Settings\Application Data\xvupnppyo

FCopy::
c:\windows\ServicePackFiles\i386\ws2help.dll | c:\windows\system32\ws2help.dll
c:\windows\ServicePackFiles\i386\ws2help.dll |  c:\windows\$NtServicePackUninstall$\ws2help.dll
c:\windows\ServicePackFiles\i386\ws2help.dll | c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ws2hel ​p.dll

Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop. Make sure your AV is disabled while we do this.

[external image: Posted Image]
Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.

ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.




2. Malwarebytes FULL scan:
Please open MalwareBytes AntiMalware
  • Once the program has loaded, select Perform Full Scan, then click Scan.
    The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to restart. Restart if it tells you to.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.



3. OTL scan:
Please open OTL again and do a quick scan. To do this click the button at the top that says "Quick Scan" and allow OTL to run :)




In your next reply please include:
  • The Combofix log.
  • The Malwarebytes log.
  • A new OTL log.

Cheers! :thumbup:
Hi NightWizard

I have to say, I am amazed right now. I didn't think my computer was going to recover, but things seem to be running very well - no internet crashes and no re-directs (at least in the short time I nave been on-line).

I actually removed AVG prior to running ComboFix, and am certainly open to suggestions for solid Real-time AV software. I also removed Limewire and UTorrent (they hadn't been used for a very long time anyway, so no reason for them to be there)

Here are the logs

Combofix

ComboFix 10-07-16.01 - Lee or Sandra 07/18/2010 11:02:34.2.1 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2047.1778 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Lee or Sandra\Desktop\CFScript.txt
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\NetworkService\Local Settings\Application Data\xvupnppyo
c:\windows\system32\hlp.dat

.
————— FCopy —————

c:\windows\ServicePackFiles\i386\ws2help.dll –> c:\windows\system32\ws2help.dll
c:\windows\ServicePackFiles\i386\ws2help.dll –> c:\windows\$NtServicePackUninstall$\ws2help.dll
.
((((((((((((((((((((((((( Files Created from 2010-06-18 to 2010-07-18 )))))))))))))))))))))))))))))))
.

2010-07-15 17:18 . 2010-07-15 17:18 ——– d—–w- c:\program files\Trend Micro
2010-07-15 17:04 . 2001-08-18 05:36 138752 —-a-w- c:\windows\system32\sendvol32.exe
2010-07-05 23:33 . 2010-07-05 23:38 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-07-05 03:26 . 2010-07-05 03:26 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2010-07-05 03:25 . 2010-07-05 03:25 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Google
2010-07-04 01:51 . 2010-07-04 08:57 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-07-02 21:45 . 2010-07-02 21:45 ——– d—–w- c:\documents and settings\NetworkService\Application Data\AdobeUM
2010-07-02 21:44 . 2010-07-02 21:45 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-07-02 21:44 . 2010-07-02 21:44 ——– d-s—w- c:\documents and settings\NetworkService\UserData
2010-07-02 21:20 . 2010-07-07 06:26 ——– d—–w- c:\documents and settings\Administrator\Application Data\Spyware Terminator
2010-06-30 21:22 . 2010-06-30 21:22 ——– d—–w- c:\windows\system32\LogFiles
2010-06-30 15:22 . 2010-07-16 16:21 0 —-a-w- c:\windows\Skiqafavinasowov.bin
2010-06-30 15:22 . 2010-07-09 05:16 120 —-a-w- c:\windows\Hzefodurexurivik.dat
2010-06-30 06:22 . 2010-07-02 22:52 ——– d—–w- c:\documents and settings\Lee or Sandra\Application Data\EA377B0C8D08E79FEBE0FBA0E7E9F7E7

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-18 17:56 . 2009-11-22 03:14 ——– d—–w- c:\documents and settings\Lee or Sandra\Application Data\uTorrent
2010-07-18 17:54 . 2008-02-26 05:44 ——– d—–w- c:\program files\Google
2010-07-17 20:45 . 2009-04-13 08:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2010-07-16 17:50 . 2010-03-20 15:24 0 —-a-w- c:\documents and settings\Lee or Sandra\Local Settings\Application Data\prvlcl.dat
2010-07-16 07:00 . 2007-04-01 05:34 ——– d—–w- c:\documents and settings\Lee or Sandra\Application Data\Spyware Terminator
2010-07-15 17:18 . 2010-07-15 17:18 388096 —-a-r- c:\documents and settings\Lee or Sandra\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-03 00:44 . 2010-03-04 20:18 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-02 20:39 . 2010-07-02 20:39 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-06-30 23:00 . 2007-04-01 05:33 ——– d—–w- c:\program files\Spyware Terminator
2010-06-30 16:06 . 2007-04-01 05:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2010-06-11 16:57 . 2008-05-11 18:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-05-25 06:35 . 2010-05-25 06:35 348160 —-a-w- c:\documents and settings\Lee or Sandra\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-5fa89df4-n\msvcr71.dll
2010-05-25 06:35 . 2010-05-25 06:35 503808 —-a-w- c:\documents and settings\Lee or Sandra\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-5fa89df4-n\msvcp71.dll
2010-05-25 06:35 . 2010-05-25 06:35 499712 —-a-w- c:\documents and settings\Lee or Sandra\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-5fa89df4-n\jmc.dll
2010-05-16 06:08 . 2010-05-16 06:08 73000 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2010-05-02 05:56 . 2003-07-16 20:51 1850880 —-a-w- c:\windows\system32\win32k.sys
2010-05-01 18:20 . 2006-10-01 07:03 73048 —-a-w- c:\documents and settings\Lee or Sandra\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-29 22:39 . 2010-03-04 20:18 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 22:39 . 2010-03-04 20:18 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-20 05:51 . 2003-07-16 20:24 285696 —-a-w- c:\windows\system32\atmfd.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus Photo R300 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE" [2003-06-04 99840]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-13 39408]
"uTorrent"="c:\documents and settings\Lee or Sandra\Desktop\utorrent.exe" [2009-11-22 289584]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"diagent"="c:\program files\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 135264]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-17 8491008]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2006-06-30 1106386]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2006-06-30 126976]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2006-06-30 1848150]
"EPSON Stylus Photo R300 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE" [2003-06-04 99840]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-07-26 1817600]
"nwiz"="nwiz.exe" [2007-09-17 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-17 81920]
"Phase One Media Reader"="c:\progra~1\PHASEO~1\CAPTUR~2\DCIMImp.exe" [2008-01-31 229376]
"Disc Detector"="c:\program files\Creative\ShareDLL\CtNotify.exe" [2001-12-26 191488]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]

c:\documents and settings\Lee or Sandra\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2008-12-25 385024]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-11-21 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\KEM.exe [2006-10-1 581632]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\TVersity\\Media Server\\MediaServer.exe"=
"c:\\Documents and Settings\\Lee or Sandra\\Desktop\\utorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [7/29/2008 12:00 AM 141312]
R2 P1C1394;Phase One 1394 Camera Driver;c:\windows\system32\drivers\p1c1394.sys [7/4/2008 5:57 PM 23168]
S2 gupdate1c9bc1444f2956a;Google Update Service (gupdate1c9bc1444f2956a);c:\program files\Google\Update\GoogleUpdate.exe [4/13/2009 1:45 AM 133104]
.
Contents of the 'Scheduled Tasks' folder

2010-07-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:34]

2010-07-18 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-13 08:43]

2010-07-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 08:45]

2010-07-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 08:45]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Handler: intu-qt2007 - {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - c:\program files\QuickTax 2007\ic2007pp.dll
FF - ProfilePath - c:\documents and settings\Lee or Sandra\Application Data\Mozilla\Firefox\Profiles\f0k5m4as.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-18 11:10
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Disc Detector = c:\program files\Creative\ShareDLL\CtNotify.exe?X???????????????????E?@?Disc Detector?A????? ?A?? ????B?e!@???@???@?? C?????E?@?????????@?B???A????? ?A?0?????B???@?????P?????@?? ????????A~??????????@??? ???????????????B????? HKCU\Software\Microsoft\Windows\CurrentVersion\Run
EPSON Stylus Photo R300 Series = c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P30 "EPSON Stylus Photo R300 Series" /M "Stylus Photo R300" /EF "HKCU"?????s????????????YB~????????????????p????????????????????YB~????p???????????8???????????X?C~????p???????j?C~p??????????????|???????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(772)
c:\windows\system32\relog_ap.dll

- - - - - - - > 'explorer.exe'(2304)
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\System32\CTsvcCDA.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\program files\TVersity\Media Server\MediaServer.exe
c:\windows\System32\MsPMSPSv.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Creative\ShareDLL\Mediadet.exe
c:\program files\Logitech\SetPoint\KHALMNPR.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-07-18 11:16:41 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-18 18:16
ComboFix2.txt 2010-07-18 05:16

Pre-Run: 61,271,339,008 bytes free
Post-Run: 61,277,233,152 bytes free

- - End Of File - - E34561234A84837995C5C429A324C3BD


MalwareBytes Log

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4311

Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 6.0.2900.2180

7/18/2010 11:59:49 AM
mbam-log-2010-07-18 (11-59-49).txt

Scan type: Full scan (C:\|)
Objects scanned: 235705
Time elapsed: 35 minute(s), 19 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


OTL ( I ran the basic quick scan, but did not copy and paste the special instructions from the first go-around)

OTL logfile created on: 7/18/2010 12:09:46 PM - Run 2
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Documents and Settings\Lee or Sandra\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 77.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 132.11 Gb Total Space | 57.08 Gb Free Space | 43.20% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 495.22 Mb Total Space | 404.55 Mb Free Space | 81.69% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: UPSTAIRS
Current User Name: Lee or Sandra
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/07/16 16:22:51 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Lee or Sandra\My Documents\Downloads\OTL.exe
PRC - [2010/04/16 08:33:40 | 000,144,672 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2009/09/22 14:31:56 | 000,856,064 | —- | M] () – C:\Program Files\TVersity\Media Server\MediaServer.exe
PRC - [2009/05/15 07:35:52 | 000,935,208 | —- | M] (Nero AG) – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2008/07/26 00:18:31 | 001,817,600 | —- | M] (Crawler.com) – C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
PRC - [2008/07/26 00:18:31 | 000,606,720 | —- | M] (Crawler.com) – C:\Program Files\Spyware Terminator\sp_rsser.exe
PRC - [2007/11/22 12:49:08 | 000,385,024 | —- | M] (Sony Corporation) – C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
PRC - [2007/06/13 03:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2006/06/30 06:31:10 | 001,106,386 | —- | M] (Acronis) – C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
PRC - [2006/06/29 19:06:32 | 001,848,150 | —- | M] (Acronis) – C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
PRC - [2006/06/29 19:06:00 | 000,126,976 | —- | M] (Acronis) – C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
PRC - [2006/06/29 19:05:58 | 000,204,800 | —- | M] (Acronis) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
PRC - [2005/09/23 22:05:26 | 000,029,696 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
PRC - [2004/10/28 09:29:48 | 000,581,632 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\SetPoint\KEM.exe
PRC - [2004/10/21 13:28:40 | 000,029,696 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\SetPoint\KHALMNPR.exe
PRC - [2003/06/04 04:00:00 | 000,099,840 | —- | M] (SEIKO EPSON CORPORATION) – C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2F1.EXE
PRC - [2002/04/30 02:00:00 | 000,167,424 | —- | M] (Creative Technology Ltd.) – C:\Program Files\Creative\ShareDLL\Mediadet.exe
PRC - [2002/04/03 01:01:00 | 000,135,264 | —- | M] (Creative Technology Ltd) – C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
PRC - [2001/12/26 02:00:00 | 000,191,488 | —- | M] (Creative Technology Ltd.) – C:\Program Files\Creative\ShareDLL\CTNotify.exe


========== Modules (SafeList) ==========

MOD - [2010/07/16 16:22:51 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Lee or Sandra\My Documents\Downloads\OTL.exe
MOD - [2006/08/25 08:45:55 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
MOD - [2004/10/28 09:27:18 | 000,086,016 | —- | M] () – C:\Program Files\Logitech\SetPoint\lgscroll.dll
MOD - [2004/08/03 23:01:17 | 000,102,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – C:\WINDOWS\System32\appmgmts.dll – (AppMgmt)
SRV - [2010/04/16 08:33:40 | 000,144,672 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2009/09/22 14:31:56 | 000,856,064 | —- | M] () [Auto | Running] – C:\Program Files\TVersity\Media Server\MediaServer.exe – (TVersityMediaServer)
SRV - [2009/05/15 07:35:52 | 000,935,208 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe – (Nero BackItUp Scheduler 4.0)
SRV - [2008/07/26 00:18:31 | 000,606,720 | —- | M] (Crawler.com) [Auto | Running] – C:\Program Files\Spyware Terminator\sp_rsser.exe – (sp_rssrv)
SRV - [2007/01/31 12:13:34 | 000,315,904 | —- | M] (Crawler.com) [Auto | Stopped] – C:\Program Files\WinClamAVShield\Sp_clamsrv.exe – (sp_clamsrv)
SRV - [2006/06/29 19:05:58 | 000,204,800 | —- | M] (Acronis) [Auto | Running] – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe – (AcrSch2Svc)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – C:\ComboFix\catchme.sys – (catchme)
DRV - [2008/07/29 00:00:20 | 000,141,312 | —- | M] () [Kernel | System | Running] – C:\WINDOWS\system32\drivers\sp_rsdrv2.sys – (sp_rsdrv2)
DRV - [2008/07/04 17:57:55 | 000,457,216 | —- | M] (Aladdin Knowledge Systems) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\hardlock.sys – (hardlock)
DRV - [2008/07/04 17:57:52 | 000,047,616 | —- | M] (Aladdin Knowledge Systems) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\Haspnt.sys – (Haspnt)
DRV - [2007/09/17 01:07:00 | 006,853,088 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2006/09/30 22:13:57 | 000,388,000 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\timntr.sys – (timounter)
DRV - [2006/09/30 22:13:57 | 000,032,288 | —- | M] (Acronis) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\tifsfilt.sys – (tifsfilter)
DRV - [2006/09/30 22:13:53 | 000,099,776 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\snapman.sys – (snapman)
DRV - [2006/05/05 19:21:00 | 000,004,608 | —- | M] (NVIDIA Corporation.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\nvport.sys – (nvport)
DRV - [2006/03/29 08:49:26 | 000,009,856 | —- | M] (Padus, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\pfc.sys – (pfc)
DRV - [2005/10/27 15:27:44 | 000,023,168 | —- | M] (Phase One A/S) [Kernel | Auto | Running] – C:\WINDOWS\System32\Drivers\p1c1394.sys – (P1C1394)
DRV - [2004/10/21 13:31:06 | 000,054,851 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\L8042mou.Sys – (L8042mou)
DRV - [2004/10/21 13:30:56 | 000,071,535 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\LMouKE.Sys – (LMouKE)
DRV - [2004/08/03 23:08:21 | 000,010,624 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\gameenum.sys – (gameenum)
DRV - [2003/08/14 08:58:12 | 001,296,384 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\P16X.sys – (P16X) Creative SB Live! Series (WDM)
DRV - [2001/08/22 08:42:58 | 000,013,632 | —- | M] (Dell Computer Corporation) [Kernel | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS – (OMCI)
DRV - [1999/12/17 01:00:00 | 000,006,752 | —- | M] (Creative Technology Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\system32\PFMODNT.SYS – (PfModNT)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.google.ca"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.825
FF - prefs.js..extensions.enabledItems: {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:2.9.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {551A6336-63D9-4FC7-A4E2-C28E2212894A}:1.9.1


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/05 19:15:06 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/05 16:38:05 | 000,000,000 | —D | M]

[2009/08/04 20:03:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\Mozilla\Extensions
[2010/07/15 10:07:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\Mozilla\Firefox\Profiles\f0k5m4as.default\extensions
[2010/05/16 16:29:18 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Lee or Sandra\Application Data\Mozilla\Firefox\Profiles\f0k5m4as.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2009/09/02 09:12:19 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Lee or Sandra\Application Data\Mozilla\Firefox\Profiles\f0k5m4as.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2007/08/28 00:10:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\Mozilla\Firefox\Profiles\f0k5m4as.default\extensions\[removed]
[2010/07/15 10:07:14 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2004/11/12 20:36:20 | 000,005,120 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Mozilla Firefox\plugins\NPAdbESD.dll
[2008/06/30 22:02:00 | 000,663,072 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\npOGAPlugin.dll

O1 HOSTS File: ([2010/07/18 11:10:34 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll File not found
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [diagent] C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CTNotify.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [Phase One Media Reader] C:\Program Files\Phase One\Capture One PRO\DCIMImp.exe (Phase One A/S, Copenhagen, Denmark)
O4 - HKLM..\Run: [SpywareTerminator] C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe (Crawler.com)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKCU..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [uTorrent] C:\Documents and Settings\Lee or Sandra\Desktop\utorrent.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Lee or Sandra\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1159680962000 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\intu-qt2007 {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-qt2008 {05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596} - C:\Program Files\QuickTax 2008\ic2008pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Lee or Sandra\Local Settings\Application Data\Microsoft\Wallpaper2.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Lee or Sandra\Local Settings\Application Data\Microsoft\Wallpaper2.bmp
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/30 15:39:42 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/06/25 22:29:08 | 000,000,090 | —- | M] () - E:\AUTORUN.INF – [ FAT ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2010/07/18 12:03:27 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/07/18 11:09:16 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/07/17 21:41:00 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/07/17 21:35:27 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/07/17 21:35:27 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/07/17 21:35:27 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/07/17 21:35:27 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/07/17 21:35:15 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/07/17 13:52:15 | 000,000,000 | —D | C] – C:\Qoobox
[2010/07/15 10:18:34 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/07/05 16:33:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NOS
[2010/07/05 01:04:31 | 000,000,000 | —D | C] – C:\Program Files\msn gaming zone
[2010/07/03 19:05:24 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/07/03 19:05:24 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/07/03 18:51:13 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/07/02 14:45:44 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\AdobeUM
[2010/07/02 14:44:31 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/06/30 14:22:09 | 000,000,000 | —D | C] – C:\WINDOWS\System32\LogFiles
[2010/06/29 23:39:49 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/06/29 23:39:48 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/06/29 23:22:07 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee or Sandra\Application Data\EA377B0C8D08E79FEBE0FBA0E7E9F7E7
[2010/06/11 09:39:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee or Sandra\Local Settings\Application Data\PCHealth
[2010/05/16 16:31:40 | 000,000,000 | —D | C] – C:\Program Files\Garmin GPS Plugin
[2010/05/16 16:31:38 | 000,000,000 | —D | C] – C:\Program Files\DIFX
[2010/05/16 16:31:35 | 000,000,000 | —D | C] – C:\Program Files\Garmin
[2010/05/16 16:29:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee or Sandra\Application Data\GARMIN
[2010/05/15 23:17:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/05/15 23:14:25 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/05/15 23:11:26 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/04/30 22:26:55 | 000,000,000 | —D | C] – C:\Program Files\QuickTax 2009
[2006/09/30 17:05:59 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\A3d.dll
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/07/18 12:07:05 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/07/18 12:07:02 | 000,000,482 | —- | M] () – C:\WINDOWS\System32\tversity.cookies
[2010/07/18 12:06:50 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/07/18 12:06:45 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/07/18 12:06:43 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/07/18 12:06:04 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Lee or Sandra\ntuser.ini
[2010/07/18 12:06:03 | 006,029,312 | —- | M] () – C:\Documents and Settings\Lee or Sandra\NTUSER.DAT
[2010/07/18 11:20:05 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/07/18 11:10:50 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/07/18 11:10:34 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/07/17 21:41:05 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/07/17 13:35:02 | 003,738,205 | R— | M] () – C:\Documents and Settings\Lee or Sandra\Desktop\ComboFix.exe
[2010/07/16 22:52:55 | 000,076,695 | —- | M] () – C:\Documents and Settings\Lee or Sandra\Desktop\outlookcontacts.csv
[2010/07/16 22:52:51 | 000,038,487 | —- | M] () – C:\Documents and Settings\Lee or Sandra\Application Data\Comma Separated Values (Windows).ADR
[2010/07/16 10:50:54 | 000,000,000 | —- | M] () – C:\Documents and Settings\Lee or Sandra\Local Settings\Application Data\prvlcl.dat
[2010/07/16 09:21:27 | 000,000,000 | —- | M] () – C:\WINDOWS\Skiqafavinasowov.bin
[2010/07/15 10:18:34 | 000,002,000 | —- | M] () – C:\Documents and Settings\Lee or Sandra\Desktop\HiJackThis.lnk
[2010/07/14 08:36:54 | 000,000,036 | —- | M] () – C:\Documents and Settings\Lee or Sandra\Local Settings\Application Data\housecall.guid.cache
[2010/07/12 21:38:58 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/07/08 22:16:35 | 000,000,120 | —- | M] () – C:\WINDOWS\Hzefodurexurivik.dat
[2010/07/06 23:40:31 | 000,010,397 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\Shopping for Ranch.xlsx
[2010/07/06 10:43:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/07/06 08:09:39 | 000,001,891 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/07/05 16:30:35 | 000,001,620 | —- | M] () – C:\Documents and Settings\Lee or Sandra\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/07/05 16:30:35 | 000,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/07/05 08:22:40 | 000,000,104 | —- | M] () – C:\Documents and Settings\Lee or Sandra\Desktop\E-mail.lnk
[2010/07/05 01:03:00 | 000,511,926 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/07/05 01:03:00 | 000,435,260 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/07/05 01:03:00 | 000,068,156 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/07/04 01:57:52 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/06/27 19:49:19 | 000,000,287 | —- | M] () – C:\Documents and Settings\Lee or Sandra\Application Data\default.rss
[2010/06/27 19:48:22 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/06/27 19:48:00 | 000,014,673 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\93 - Ami Dagan, Dan Dejong, Lee Aitchison, Jarett Vermette - The Smart Menu.docx.dat
[2010/06/24 11:16:06 | 000,002,587 | —- | M] () – C:\Documents and Settings\All Users\Desktop\ACDSee 10 Photo Manager.lnk
[2010/06/13 22:13:00 | 000,021,239 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\smart menu proforma v4_lee_June 12_2010.xlsx
[2010/06/11 18:48:15 | 000,274,168 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/06 13:52:28 | 000,065,536 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\Hat $.pub
[2010/06/06 13:51:34 | 000,065,536 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\Ladies T $.pub
[2010/06/06 13:44:07 | 000,065,536 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\T-shirt $.pub
[2010/06/06 13:39:12 | 000,065,024 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\Please Order shirts by Number.pub
[2010/06/06 13:34:11 | 000,046,592 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\Back Label - 8163.pub
[2010/06/06 13:32:55 | 000,046,592 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\Front Label - 8163.pub
[2010/05/25 15:27:16 | 000,013,824 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\Ducati Case - Q3.docx
[2010/05/25 15:22:06 | 000,114,544 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\MBA 544 Case #3 Ducati (Italy) vs Harley-Davidson (USA) Memo v3.docx
[2010/05/15 23:28:53 | 000,047,104 | —- | M] () – C:\Documents and Settings\Lee or Sandra\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/15 22:18:00 | 003,142,654 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\Brandon.avi
[2010/05/15 22:18:00 | 002,308,198 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\Second Years.avi
[2010/05/11 08:17:53 | 000,025,088 | —- | M] () – C:\Documents and Settings\Lee or Sandra\My Documents\Doug Retirement Program.doc
[2010/05/01 11:20:47 | 000,073,048 | —- | M] () – C:\Documents and Settings\Lee or Sandra\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/26 15:58:12 | 000,256,512 | —- | M] () – C:\WINDOWS\PEV.exe
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/07/17 21:41:04 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/07/17 21:41:00 | 000,260,272 | —- | C] () – C:\cmldr
[2010/07/17 21:35:27 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/07/17 21:35:27 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/07/17 21:35:27 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/07/17 21:35:27 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/07/17 21:35:27 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/07/17 13:51:12 | 003,738,205 | R— | C] () – C:\Documents and Settings\Lee or Sandra\Desktop\ComboFix.exe
[2010/07/16 22:52:51 | 000,038,487 | —- | C] () – C:\Documents and Settings\Lee or Sandra\Application Data\Comma Separated Values (Windows).ADR
[2010/07/16 22:52:42 | 000,076,695 | —- | C] () – C:\Documents and Settings\Lee or Sandra\Desktop\outlookcontacts.csv
[2010/07/15 10:18:34 | 000,002,000 | —- | C] () – C:\Documents and Settings\Lee or Sandra\Desktop\HiJackThis.lnk
[2010/07/14 08:36:54 | 000,000,036 | —- | C] () – C:\Documents and Settings\Lee or Sandra\Local Settings\Application Data\housecall.guid.cache
[2010/07/06 17:39:49 | 000,010,397 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\Shopping for Ranch.xlsx
[2010/07/05 16:30:35 | 000,001,620 | —- | C] () – C:\Documents and Settings\Lee or Sandra\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/07/05 16:30:35 | 000,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/07/05 08:22:40 | 000,000,104 | —- | C] () – C:\Documents and Settings\Lee or Sandra\Desktop\E-mail.lnk
[2010/07/03 18:51:13 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/06/30 08:22:33 | 000,000,120 | —- | C] () – C:\WINDOWS\Hzefodurexurivik.dat
[2010/06/30 08:22:33 | 000,000,000 | —- | C] () – C:\WINDOWS\Skiqafavinasowov.bin
[2010/06/27 19:49:07 | 000,014,673 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\93 - Ami Dagan, Dan Dejong, Lee Aitchison, Jarett Vermette - The Smart Menu.docx.dat
[2010/06/13 22:13:00 | 000,021,239 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\smart menu proforma v4_lee_June 12_2010.xlsx
[2010/06/06 13:51:34 | 000,065,536 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\Ladies T $.pub
[2010/06/06 13:45:36 | 000,065,536 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\Hat $.pub
[2010/06/06 13:44:07 | 000,065,536 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\T-shirt $.pub
[2010/06/06 13:39:12 | 000,065,024 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\Please Order shirts by Number.pub
[2010/06/06 13:34:10 | 000,046,592 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\Back Label - 8163.pub
[2010/06/06 13:32:55 | 000,046,592 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\Front Label - 8163.pub
[2010/05/25 15:27:16 | 000,013,824 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\Ducati Case - Q3.docx
[2010/05/25 15:22:06 | 000,114,544 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\MBA 544 Case #3 Ducati (Italy) vs Harley-Davidson (USA) Memo v3.docx
[2010/05/15 22:18:00 | 003,142,654 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\Brandon.avi
[2010/05/15 22:18:00 | 002,308,198 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\Second Years.avi
[2010/05/11 08:17:53 | 000,025,088 | —- | C] () – C:\Documents and Settings\Lee or Sandra\My Documents\Doug Retirement Program.doc
[2009/11/22 15:02:03 | 000,000,018 | —- | C] () – C:\WINDOWS\isbn0-7879-5674-0.ini
[2009/05/31 14:26:30 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/05/31 13:52:14 | 000,004,767 | —- | C] () – C:\WINDOWS\Irremote.ini
[2008/12/25 01:18:38 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/10/30 22:27:40 | 000,001,024 | —- | C] () – C:\WINDOWS\System32\grcauth2.dll
[2008/10/30 22:27:40 | 000,001,024 | —- | C] () – C:\WINDOWS\System32\grcauth1.dll
[2008/10/30 22:27:40 | 000,000,100 | —- | C] () – C:\WINDOWS\System32\prsgrc.dll
[2008/10/30 22:23:56 | 000,001,025 | —- | C] () – C:\WINDOWS\System32\sysprs7.dll
[2008/10/30 22:23:56 | 000,000,205 | —- | C] () – C:\WINDOWS\System32\lsprst7.dll
[2008/07/29 00:00:20 | 000,141,312 | —- | C] () – C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2008/07/04 17:57:52 | 000,000,383 | —- | C] () – C:\WINDOWS\System32\haspdos.sys
[2008/03/10 08:16:36 | 000,524,288 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/03/10 08:16:36 | 000,383,238 | —- | C] () – C:\WINDOWS\System32\libmp3lame-0.dll
[2007/09/17 01:07:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2007/09/17 01:07:00 | 001,478,656 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2007/09/17 01:07:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2007/09/17 01:07:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2007/09/17 01:07:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2007/08/27 23:19:04 | 001,936,528 | —- | C] () – C:\WINDOWS\System32\ltmm15.dll
[2007/07/25 19:53:34 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007/07/22 22:45:49 | 000,000,092 | —- | C] () – C:\WINDOWS\QTW.INI
[2006/11/04 22:22:40 | 000,000,147 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/11/04 22:22:39 | 000,034,816 | —- | C] () – C:\WINDOWS\System32\asxswai.dll
[2006/10/31 23:33:51 | 000,000,093 | —- | C] () – C:\WINDOWS\R300.ini
[2006/10/01 16:53:43 | 000,000,737 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/10/01 00:57:58 | 000,000,287 | —- | C] () – C:\WINDOWS\game.ini
[2006/09/30 17:06:11 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2006/09/30 17:05:59 | 000,047,616 | —- | C] () – C:\WINDOWS\System32\P16X.dll
[2006/09/30 17:05:59 | 000,002,158 | —- | C] () – C:\WINDOWS\System32\P16X.ini
[2006/09/30 17:05:59 | 000,000,026 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2006/09/30 17:05:56 | 000,002,572 | —- | C] () – C:\WINDOWS\MIXDEF.INI
[2006/09/30 17:05:55 | 000,000,064 | —- | C] () – C:\WINDOWS\P16x.ini
[2006/09/30 17:05:17 | 000,000,245 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2006/09/30 16:56:45 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2006/09/30 16:50:47 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/07/16 13:28:11 | 000,032,770 | —- | C] () – C:\WINDOWS\System32\ltinp32.dll
[2003/07/16 13:28:11 | 000,028,674 | —- | C] () – C:\WINDOWS\System32\prckrep.dll
[2003/07/16 13:28:11 | 000,025,602 | —- | C] () – C:\WINDOWS\System32\llpink_.dll
[1997/07/11 00:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[1997/07/11 00:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1997/07/11 00:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL

========== LOP Check ==========

[2009/06/26 22:38:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Abstract
[2007/12/31 19:12:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ACD Systems
[2006/09/30 20:26:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2008/07/23 08:39:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG7
[2009/06/26 22:34:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2006/09/30 22:24:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2008/10/30 22:26:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SafeNet Sentinel
[2010/06/30 09:06:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spyware Terminator
[2009/06/26 22:34:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2010/05/15 23:18:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/16 01:32:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/06/28 13:24:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2007/12/31 19:13:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\ACD Systems
[2010/07/02 15:52:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\EA377B0C8D08E79FEBE0FBA0E7E9F7E7
[2010/05/16 16:29:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\GARMIN
[2007/08/27 23:18:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\GetRightToGo
[2006/10/31 23:35:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\Leadertech
[2008/09/23 08:06:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\LimeWire
[2006/11/05 13:27:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\NCH Swift Sound
[2009/06/26 22:35:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\Nikon
[2008/08/23 01:08:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\Smartsims
[2010/07/16 00:00:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\Spyware Terminator
[2006/11/20 22:55:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\Uniblue
[2010/07/18 10:56:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\uTorrent
[2008/12/30 16:42:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee or Sandra\Application Data\yoclient

========== Purity Check ==========


< End of report >


Once again, thank you so much! (and if you have suggestions on AV tools I should be running, please let me know.)
Lee
Hi Lee,

It is great to hear things are running smoother! We still have a little to do before I set you on your way :)

Please work your way through the following:

1. OTL Fix
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll File not found
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
    O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
    
    :Services
    
    :Reg
    
    :Files
    c:\windows\Hzefodurexurivik.dat
    c:\windows\Skiqafavinasowov.bin
    C:\Documents and Settings\Lee or Sandra\Application Data\uTorrent
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Post the log you are presented with after the Reboot.



2. Update Java
  • To get the latest version of Java please go HERE.
  • Go to Start -> Control Panel -> Programs and Features.
  • Search in the list for all previous installed versions of Java. (J2SE Runtime Environment…. )
    They should have this icon next to any that are there: [external image: Posted Image]
    Select any found and choose Uninstall.
  • Then install the version you downloaded earlier.




2. Kaspersky Online Scan
Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply



In your next reply please include:
  • The log from OTL.
  • The Kaspersky log.
  • How are things running? Still good?

Cheers! :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI