This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Redirects to random sites

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When clicking on some Google result links, Im redirected to random ad sites etc. Not all of them, and not every time, but enough for it to be really annoying!! Im sure youve come across this before.
Here are my HijackThis log files.
Thanking you,

Steve



<< Scan saved at 08:21:43, on 15/08/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\PROGRA~1\MICROS~3\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/webhp?sourceid=nav…GB&ie=UTF-8
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Vimicro USB PC Camera LTI301P
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKCU\..\Run: [{CCA5C00B-C673-35A0-3B50-26A450212ADE}] "C:\Documents and Settings\HP_Administrator\Application Data\Ybno\ysvy.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - S-1-5-18 Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'SYSTEM')
O4 - S-1-5-18 Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Startup: Microsoft Outlook.lnk = ?
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) - https://moneymanager.egg.com/Pinsafe/accounttracking.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file:///C:/Program%20Files/AutoCAD%20LT%202002/AcDcToday.ocx
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file:///C:/Program%20Files/AutoCAD%20LT%202002/InstBanr.ocx
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://upload.members.freewebs.com/Misc/Au…geUploader5.cab
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file:///C:/Program%20Files/AutoCAD%20LT%202002/InstFred.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/Facebo…Uploader4_5.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file:///C:/Program%20Files/AutoCAD%20LT%202002/AcPreview.ocx
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
O16 - DPF: {FF1CD9A3-00CD-45C1-8182-4EEC229A182D} (Plaxo Auto-Import Utility) - https://www.plaxo.com/activex/plx_upldr-2k-xp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{94353BF2-884E-406B-8885-257F5503C4C8}: NameServer = 212.139.132.105 212.139.132.107
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Intel® Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: Google Update Service (gupdate1c9b03d370cb7a6) (gupdate1c9b03d370cb7a6) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: UPnPService - Magix AG - C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 16337 bytes>>>
Hi stevedevil,

:welcome:

My name is NightWizard and I will be your helper. :)

While I go through your log, I would very much appreciate it if you read the following.

  • I aim provide you with the best instructions possible to resolve your issue. However, I ask that you understand that malware is complex and the process usually takes a few attempts before successfully cleaning everything out. In severe cases cleaning may not be possible and a reformat may be our only option.
  • If you are unresponsive to this thread within three days, the thread will be locked due to inactivity. However, if you will be away, let us know and we will be sure to keep the thread open.
  • Please do not make any new threads about this issue here or any other malware removal forum; it wastes other helpers' time and it can be dangerous for your PC.
  • If you don't understand a set of instructions or you are having trouble performing some of the fix, don't panic! Let me know and I will be happy to help in any way I can.
  • Please remember that the absence of symptoms does not mean you are clean. I request that you stick to this log until the very end - I will inform you when your system is clean.
  • Please do not use any tools other than the ones I instruct you to use. Some of the tools available can be dangerous if used incorrectly.

Please be advised that I am still in training at this forum. My posts will be checked by experts before I post in this thread. This is to ensure you get the best possible help available. This may cause delay however I will do my best to limit the time gaps between posts.



Thanks for choosing WhatTheTech and I will be back with a fix shortly! :)


-NightWizard
Hi stevedevil,

Please work your way through the following:


1. OTL Scan:

[external image: Posted Image]Please download OTL from one of the following links
  • LINK 1
  • LINK 2
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in;

    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\system32\spool\prtprocs\w32x86\*.tmp
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them if you need to start a new topic.



1. GMER Scan:
Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.


    [external image: Posted Image]
    Click the image to enlarge it


  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries




In your next reply please include:
  • The OTL logs.
  • The GMER log.
Cheers :thumbup:
Hi stevedevil,

Please work your way through the following:

1. OTL Fix
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    FF - HKLM\software\mozilla\Firefox\extensions\\{6E19037A-12E3-4295-8915-ED48BC341614}: C:\Program Files\RelevantKnowledge
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [KernelFaultCheck] File not found
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
    O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
    O27 - HKLM IFEO\RapportMgmtService.exe: Debugger - ZASRAKOMONDOHUI31338.EXE File not found
    O27 - HKLM IFEO\RapportService.exe: Debugger - ZASRAKOMONDOHUI31338.EXE File not found
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [emptytemp]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the log from OTL presented after to Reboot.


2. Updated Malwarebytes Scan
Please launch Malwarebytes Anti-malware.
  • Once the program has loaded click the "Update taband then "Check for Updates" if any are found they will be downloaded. When prompted click Ok to install the updates.
  • After updating navigate to the main menu and check Perform Full Scan, then click Scan.
    The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to restart. Restart if it tells you to.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.


In your next reply please include:
  • The OTL log.
  • The MBAM log.
Cheers :thumbup:
MBAM LOG: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4437 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 16/08/2010 21:54:17 mbam-log-2010-08-16 (21-54-17).txt Scan type: Full scan (C:\|D:\|) Objects scanned: 347179 Time elapsed: 2 hour(s), 4 minute(s), 30 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 20 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\Software\SolutionAV (Rogue.AntivirSolutionPro) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP849\A0250206.dll (Adware.RelevantKnowledge) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP849\A0250207.exe (Adware.RelevantKnowledge) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP849\A0250208.exe (Adware.RelevantKnowledge) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP849\A0250209.exe (Adware.RelevantKnowledge) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP849\A0250210.dll (Adware.RelevantKnowledge) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP849\A0251177.dll (Adware.RelevantKnowledge) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP852\A0254154.dll (Adware.RelevantKnowledge) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP852\A0254155.dll (Adware.RelevantKnowledge) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP852\A0254156.dll (Adware.RelevantKnowledge) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP852\A0254157.dll (Adware.RelevantKnowledge) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP852\A0254158.exe (Adware.RelevantKnowledge) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP852\A0254159.exe (Adware.RelevantKnowledge) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP906\A0270087.dll (Adware.RelevantKnowledge) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP906\A0270088.dll (Adware.RelevantKnowledge) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP906\A0270089.dll (Adware.RelevantKnowledge) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP906\A0270090.exe (Adware.RelevantKnowledge) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP906\A0270091.exe (Adware.RelevantKnowledge) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP906\A0270092.exe (Adware.RelevantKnowledge) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP906\A0270093.dll (Adware.RelevantKnowledge) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP906\A0270094.dll (Adware.RelevantKnowledge) -> Quarantined and deleted successfully. OTL log: All processes killed ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{6E19037A-12E3-4295-8915-ED48BC341614} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6E19037A-12E3-4295-8915-ED48BC341614}\ not found. File C:\Program Files\RelevantKnowledge not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoCDBurning deleted successfully. Starting removal of ActiveX control {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RapportMgmtService.exe\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RapportService.exe\ deleted successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: All Users User: Application Data User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32768 bytes ->Flash cache emptied: 41 bytes User: HP_Administrator ->Temp folder emptied: 54076462 bytes ->Temporary Internet Files folder emptied: 432801621 bytes ->Java cache emptied: 10684914 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 15861240 bytes User: LocalService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 40671821 bytes User: LogMeInRemoteUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32768 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 3022998 bytes ->Java cache emptied: 26440 bytes ->Flash cache emptied: 5979 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 19569 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 93847775 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 244294742 bytes Total Files Cleaned = 854.00 mb OTL by OldTimer - Version 3.2.9.1 log created on 08162010_192525 Files\Folders moved on Reboot… C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Google Toolbar\GoogleToolbarWelcome.log moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\Z2V4JGBU\index[2].htm moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\XMGSN1MM\profile[1].htm moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\RKWXVFYI\like[1].htm moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\N6JYKSE5\facebook_com[1].htm moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\DM06U158\redirectiframe[1].html moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\BY8ST8V9\iframe[1].htm moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\96MU3AL9\11[5].htm moved successfully. Registry entries deleted on Reboot… Thanks STEVE.
Hi stevedevil,

Please work your way through these steos:

1. Update Java:
Java is out of date and older versions contain vulnerabilities. Please update to the newest version.

Download the newest version from HERE.

It's important to remove older versions of Java since it does not do so automatically and old versions still leave you vulnerable.
Go to Start > Control Panel > Software and open Add or Remove Programs.
Search in the list for all previous installed versions of Java. (J2SE Runtime Environment).
They will have this icon next to them: [external image: Posted Image]
Select each in turn and click Remove.

Once old versions are gone, please install the newest version.


2. Kaspersky Online Scan:
Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply


In your next reply please include:
  • The Kaspersky log.
  • A fresh OTL log.
Also how is your computer running now?


Cheers :thumbup:
Hello,
my PC is still getting hijacked, the Google results page links lead to ad pages etc.
Steve.

KasReport log:
KASPERSKY ONLINE SCANNER 7.0: scan report
Wednesday, August 18, 2010
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Wednesday, August 18, 2010 01:54:29
Records in database: 4138097
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
L:\

Scan statistics:
Objects scanned: 186297
Threats found: 5
Infected objects found: 24
Suspicious objects found: 1
Scan duration: 06:44:19


File name / Threat / Threats count
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\01563BE1.tmp Infected: Email-Worm.Win32.Nyxem.e 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0ADA79D6.tmp Infected: Email-Worm.Win32.Nyxem.e 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0B98304D.tmp Infected: Email-Worm.Win32.Nyxem.e 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0EDB1013.tmp Infected: Email-Worm.Win32.Nyxem.e 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\13E4113C.wma Infected: Trojan-Downloader.WMA.Wimad.d 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\17C32338.tmp Infected: Email-Worm.Win32.Nyxem.e 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\29502D1E.tmp Infected: Email-Worm.Win32.Nyxem.e 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2DD7532F.tmp Infected: Email-Worm.Win32.Nyxem.e 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2E4910B1.tmp Infected: Email-Worm.Win32.Nyxem.e 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\34EB6367.tmp Infected: Email-Worm.Win32.Nyxem.e 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3578243E.tmp Infected: Email-Worm.Win32.Nyxem.e 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A85593B.tmp Infected: Email-Worm.Win32.Nyxem.e 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3B8A781B.tmp Infected: Email-Worm.Win32.Nyxem.e 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3CEE5894.tmp Infected: Email-Worm.Win32.Nyxem.e 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\431B39C7.tmp Infected: Email-Worm.Win32.Nyxem.e 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4FD460BA.tmp Infected: Email-Worm.Win32.Nyxem.e 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5260486F.tmp Infected: Email-Worm.Win32.Nyxem.e 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\55CC0182.tmp Infected: Email-Worm.Win32.Nyxem.e 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5B105486.tmp Infected: Email-Worm.Win32.Nyxem.e 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\613D757B.tmp Infected: Email-Worm.Win32.Nyxem.e 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7AA11A60.tmp Infected: Email-Worm.Win32.Nyxem.e 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7C50316D.tmp Infected: Email-Worm.Win32.Nyxem.e 1
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Outlook\archive.pst Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Outlook\archive.pst Infected: Trojan-Spy.HTML.Bayfraud.jk 1
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Outlook\archive.pst Infected: Trojan-Spy.HTML.Bayfraud.ev 1

Selected area has been scanned.


<<>>>

OTL2 log:
OTL logfile created on: 18/08/2010 17:11:13 - Run 2
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\HP_Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,022.00 Mb Total Physical Memory | 623.00 Mb Available Physical Memory | 61.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 142.19 Gb Total Space | 36.43 Gb Free Space | 25.62% Space Free | Partition Type: NTFS
Drive D: | 6.84 Gb Total Space | 0.67 Gb Free Space | 9.84% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PLAYFORD
Current User Name: HP_Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/08/15 19:54:52 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe
PRC - [2010/07/15 17:17:26 | 002,065,760 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2010/07/15 17:17:23 | 000,515,424 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/07/15 17:17:22 | 000,620,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/07/15 17:17:20 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2010/07/15 17:16:24 | 000,723,296 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/07/15 17:16:22 | 001,101,152 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/06/09 17:16:58 | 000,116,104 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\ramaint.exe
PRC - [2010/06/09 17:16:39 | 000,378,248 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\LMIGuardian.exe
PRC - [2010/06/07 01:14:29 | 000,202,256 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2009/09/24 15:41:58 | 000,434,176 | —- | M] (Sony Ericsson Mobile Communications AB) – C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
PRC - [2009/04/30 13:23:26 | 000,090,112 | —- | M] () – C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
PRC - [2009/04/07 11:22:06 | 000,102,400 | —- | M] (Samsung Electronics Co., Ltd.) – C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
PRC - [2009/01/19 16:00:26 | 000,632,048 | —- | M] (eBay Inc.) – C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
PRC - [2008/11/09 21:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/04/14 01:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/06/23 18:55:25 | 000,068,856 | —- | M] (Google Inc.) – C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2007/04/17 14:03:50 | 000,063,048 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
PRC - [2007/04/17 14:03:50 | 000,063,040 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\LogMeIn.exe
PRC - [2006/06/01 16:25:00 | 000,180,224 | —- | M] (Intel Corporation) – C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\ELService.exe
PRC - [2006/04/13 02:05:00 | 000,090,112 | —- | M] (Sonic Solutions) – C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
PRC - [2006/02/21 18:59:00 | 000,143,360 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2006/02/21 18:58:34 | 000,081,920 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2005/02/28 10:53:04 | 000,053,248 | —- | M] (Vimicro) – C:\WINDOWS\VM_STI.EXE
PRC - [2004/09/13 12:49:42 | 001,192,050 | —- | M] (Ahead Software AG) – C:\Program Files\Ahead\InCD\InCDsrv.exe
PRC - [2004/07/20 10:34:28 | 000,851,968 | —- | M] (Brother Industries, Ltd.) – C:\Program Files\Brother\ControlCenter2\brctrcen.exe
PRC - [2004/04/14 15:46:50 | 000,057,393 | —- | M] (ScanSoft, Inc.) – C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
PRC - [2003/07/08 12:22:00 | 000,962,663 | —- | M] () – C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
PRC - [2003/05/05 19:30:22 | 000,065,536 | —- | M] (Brother Industries, Ltd.) – C:\WINDOWS\system32\Brmfrmps.exe
PRC - [2002/12/20 17:18:40 | 000,200,704 | —- | M] (FUJI PHOTO FILM CO., LTD.) – C:\Program Files\FinePixViewer\QuickDCF.exe
PRC - [2002/04/12 01:00:00 | 000,057,344 | —- | M] (brother Industries Ltd) – C:\WINDOWS\system32\brsvc01a.exe
PRC - [2001/12/13 01:01:00 | 000,045,056 | —- | M] (brother Industries Ltd) – C:\WINDOWS\system32\brss01a.exe


========== Modules (SafeList) ==========

MOD - [2010/08/15 19:54:52 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe
MOD - [2010/03/20 09:35:52 | 000,118,784 | —- | M] (RealPlayer) – C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
MOD - [2009/08/13 14:55:04 | 001,748,992 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll
MOD - [2009/07/03 06:57:43 | 000,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msvcr71.dll
MOD - [2008/07/03 11:06:55 | 000,106,768 | —- | M] (Microsoft Corporation) – C:\Program Files\J River\Media Jukebox 12\msscript.ocx
MOD - [2006/10/31 14:35:00 | 001,470,464 | —- | M] () – C:\WINDOWS\system32\nview.dll
MOD - [2006/10/31 14:35:00 | 000,286,720 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\nvwrseng.dll
MOD - [2006/10/31 14:35:00 | 000,081,920 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\nvwddi.dll
MOD - [2006/05/03 22:53:54 | 000,174,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\framedyn.dll
MOD - [2005/05/10 16:04:08 | 000,503,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msvcp71.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe – (Automatic LiveUpdate Scheduler)
SRV - [2010/07/15 17:17:20 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/06/09 17:16:58 | 000,116,104 | —- | M] (LogMeIn, Inc.) [Auto | Running] – C:\Program Files\LogMeIn\x86\RaMaint.exe – (LMIMaint)
SRV - [2009/04/30 13:23:26 | 000,090,112 | —- | M] () [Auto | Running] – C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe – (OMSI download service)
SRV - [2009/04/07 10:39:44 | 000,233,472 | —- | M] (Teruten) [Disabled | Stopped] – C:\WINDOWS\system32\FsUsbExService.Exe – (FsUsbExService)
SRV - [2008/11/09 21:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Running] – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)
SRV - [2008/04/07 10:17:30 | 000,430,592 | —- | M] (Nokia.) [On_Demand | Stopped] – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe – (ServiceLayer)
SRV - [2007/04/17 14:03:50 | 000,063,040 | —- | M] (LogMeIn, Inc.) [Auto | Running] – C:\Program Files\LogMeIn\x86\LogMeIn.exe – (LogMeIn)
SRV - [2007/02/10 13:45:26 | 001,174,152 | —- | M] (Symantec Corporation) [Disabled | Stopped] – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe – (Symantec Core LC)
SRV - [2006/12/14 18:00:00 | 000,544,768 | —- | M] (Magix AG) [On_Demand | Stopped] – C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe – (UPnPService)
SRV - [2006/06/01 16:25:00 | 000,180,224 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\ELService.exe – (ELService) Intel®
SRV - [2006/02/21 18:58:34 | 000,081,920 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®
SRV - [2005/11/17 16:18:52 | 001,527,900 | —- | M] (MAGIX®) [On_Demand | Stopped] – C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe – (FirebirdServerMAGIXInstance)
SRV - [2004/09/13 12:49:42 | 001,192,050 | —- | M] (Ahead Software AG) [Auto | Stopped] – C:\Program Files\Ahead\InCD\InCDsrv.exe – (InCDsrvR) InCD Helper (read only)
SRV - [2004/09/13 12:49:42 | 001,192,050 | —- | M] (Ahead Software AG) [Auto | Running] – C:\Program Files\Ahead\InCD\InCDsrv.exe – (InCDsrv)
SRV - [2003/05/05 19:30:22 | 000,065,536 | —- | M] (Brother Industries, Ltd.) [Auto | Running] – C:\WINDOWS\System32\Brmfrmps.exe – (brmfrmps)
SRV - [2002/04/12 01:00:00 | 000,057,344 | —- | M] (brother Industries Ltd) [Auto | Running] – C:\WINDOWS\system32\brsvc01a.exe – (Brother XP spl Service)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | Boot | Stopped] – C:\WINDOWS\System32\DRIVERS\ftsata2.sys – (ftsata2)
DRV - [2010/07/15 17:17:25 | 000,243,024 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgtdix.sys – (AvgTdiX)
DRV - [2010/07/15 17:16:24 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgldx86.sys – (AvgLdx86)
DRV - [2010/06/09 17:16:41 | 000,083,360 | —- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] – C:\WINDOWS\System32\LMIRfsClientNP.dll – (LMIRfsClientNP)
DRV - [2010/06/02 16:59:19 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\WINDOWS\system32\drivers\avgmfx86.sys – (AvgMfx86)
DRV - [2009/07/03 12:31:14 | 000,005,632 | —- | M] () [File_System | System | Running] – C:\WINDOWS\System32\drivers\StarOpen.sys – (StarOpen)
DRV - [2009/04/07 10:39:44 | 000,036,608 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\FsUsbExDisk.Sys – (FsUsbExDisk)
DRV - [2008/10/18 12:40:44 | 000,047,640 | —- | M] (LogMeIn, Inc.) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys – (LMIRfsDriver)
DRV - [2008/05/16 12:33:14 | 000,115,752 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s0016unic.sys – (s0016unic) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM)
DRV - [2008/05/16 12:33:14 | 000,025,512 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s0016nd5.sys – (s0016nd5) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS)
DRV - [2008/05/16 12:33:14 | 000,015,016 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s0016mdfl.sys – (s0016mdfl)
DRV - [2008/05/16 12:33:12 | 000,120,744 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s0016mdm.sys – (s0016mdm)
DRV - [2008/05/16 12:33:12 | 000,114,216 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s0016mgmt.sys – (s0016mgmt) Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM)
DRV - [2008/05/16 12:33:12 | 000,110,632 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s0016obex.sys – (s0016obex)
DRV - [2008/05/16 12:33:12 | 000,089,256 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s0016bus.sys – (s0016bus) Sony Ericsson Device 0016 driver (WDM)
DRV - [2008/04/13 19:45:12 | 000,060,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\usbaudio.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 17:36:05 | 000,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus)
DRV - [2008/02/28 15:31:50 | 000,012,856 | —- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] – C:\Program Files\LogMeIn\x86\rainfo.sys – (LMIInfo)
DRV - [2007/10/30 20:09:15 | 000,035,363 | —- | M] () [Kernel | Auto | Running] – C:\WINDOWS\system32\windrvNT.sys – (windrvNT)
DRV - [2007/09/17 16:53:26 | 000,021,632 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\pccsmcfd.sys – (pccsmcfd)
DRV - [2007/05/02 11:11:18 | 000,109,704 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ss_mdm.sys – (ss_mdm)
DRV - [2007/05/02 11:11:18 | 000,015,112 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ss_mdfl.sys – (ss_mdfl)
DRV - [2007/05/02 11:11:16 | 000,083,592 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ss_bus.sys – (ss_bus) SAMSUNG Mobile USB Device 1.0 driver (WDM)
DRV - [2007/04/03 13:57:52 | 000,098,696 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s116obex.sys – (s116obex)
DRV - [2007/04/03 13:57:48 | 000,108,680 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s116mdm.sys – (s116mdm)
DRV - [2007/04/03 13:57:48 | 000,015,112 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s116mdfl.sys – (s116mdfl)
DRV - [2007/02/06 10:00:00 | 000,383,800 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl)
DRV - [2006/10/31 14:35:00 | 003,964,256 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2006/09/24 14:28:46 | 000,005,248 | —- | M] (Windows ® 2000 DDK provider) [Kernel | Boot | Running] – C:\WINDOWS\system32\speedfan.sys – (speedfan)
DRV - [2006/09/13 23:21:37 | 000,010,344 | —- | M] (Symantec Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\symlcbrd.sys – (symlcbrd)
DRV - [2006/07/24 17:15:04 | 004,353,024 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006/05/09 15:36:44 | 000,009,728 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ELacpi.sys – (ELacpi)
DRV - [2006/05/09 15:36:42 | 000,007,040 | —- | M] (Intel Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\Elmon.sys – (ELmon)
DRV - [2006/05/09 15:36:22 | 000,006,912 | —- | M] (Intel Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\Elkbd.sys – (ELkbd)
DRV - [2006/05/09 15:36:20 | 000,006,400 | —- | M] (Intel Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\Elmou.sys – (ELmou)
DRV - [2006/05/09 15:36:18 | 000,010,112 | —- | M] (Intel Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\Elhid.sys – (ELhid)
DRV - [2006/05/01 11:53:08 | 000,061,600 | R— | M] (MCCI) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\SE2Bbus.sys – (SE2Bbus) Sony Ericsson Device 043 Driver driver (WDM)
DRV - [2006/02/21 18:44:30 | 000,250,368 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\WINDOWS\System32\DRIVERS\iastor.sys – (iaStor)
DRV - [2005/12/12 18:27:00 | 000,019,072 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\PS2.sys – (Ps2)
DRV - [2005/07/19 06:17:32 | 000,094,459 | R— | M] (VM) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\usbVM31b.sys – (ZSMC301b)
DRV - [2004/09/13 12:54:46 | 000,028,672 | —- | M] (Ahead Software AG) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\InCDpass.sys – (InCDPass)
DRV - [2004/09/13 12:54:06 | 000,093,440 | —- | M] (Ahead Software AG) [File_System | Disabled | Running] – C:\WINDOWS\System32\drivers\InCDfs.sys – (InCDfs)
DRV - [2004/09/13 10:54:54 | 000,027,648 | —- | M] (Ahead Software AG) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\InCDrm.sys – (incdrm)
DRV - [2004/08/03 15:31:34 | 000,020,992 | —- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RTL8139.sys – (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2004/06/12 06:27:18 | 000,051,712 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BrSerIf.sys – (BrSerIf)
DRV - [2004/01/10 05:28:18 | 000,011,648 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BrUsbSer.sys – (BrUsbSer)
DRV - [2003/12/19 13:15:50 | 000,015,263 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BrScnUsb.sys – (BrScnUsb)
DRV - [2003/07/17 17:48:44 | 000,046,167 | —- | M] (Analog Deivces) [Kernel | Auto | Stopped] – C:\WINDOWS\system32\drivers\adildr.sys – (ADILOADER) General Purpose USB Driver (adildr.sys)
DRV - [2003/03/27 14:38:44 | 000,127,145 | —- | M] (Analog Devices Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\adiusbaw.sys – (adiusbaw)
DRV - [2003/03/06 15:48:08 | 000,003,840 | —- | M] () [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\BANTExt.sys – (BANTExt)
DRV - [2002/10/15 23:41:06 | 000,102,220 | —- | M] (Sony Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\sonypvs1.sys – (sonypvs1)
DRV - [2002/06/21 19:42:50 | 000,008,224 | —- | M] (MicroStaff Co.,Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\MASPINT.SYS – (MASPINT)
DRV - [1997/06/17 05:00:00 | 000,004,064 | —- | M] (Adobe Systems Incorporated) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\drivers\ATMHELPR.SYS – (ATMhelpr)
DRV - [1996/04/03 20:33:26 | 000,005,248 | —- | M] () [Kernel | Boot | Running] – C:\WINDOWS\system32\giveio.sys – (giveio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/webhp?sourceid=nav…GB&ie;=UTF-8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/06/07 01:16:13 | 000,000,000 | —D | M]

[2010/05/02 07:10:55 | 000,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Extensions
[2010/05/02 07:10:55 | 000,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Extensions\[removed]

O1 HOSTS File: ([2004/08/10 05:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (MediaBar) - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files\BearShareTb\BearShareDx.dll ()
O2 - BHO: (Shareaza Web Download Hook) - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files\Shareaza\RazaWebHook32.dll (Shareaza Development Team)
O2 - BHO: (eBay Toolbar Helper) - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll (eBay Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (MediaBar) - {0974BA1E-64EC-11DE-B2A5-E43756D89593} - C:\Program Files\BearShareTb\BearShareDx.dll ()
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (eBay Toolbar) - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll (eBay Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE (Vimicro)
O4 - HKLM..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [DMAScheduler] c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe (Sonic Solutions)
O4 - HKLM..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe (eBay Inc.)
O4 - HKLM..\Run: [HPBootOp] C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE (FUJI PHOTO FILM CO., LTD.)
O4 - HKLM..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe (Brother Industories, Ltd.)
O4 - HKLM..\Run: [Sony Ericsson PC Suite] C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe (Sony Ericsson Mobile Communications AB)
O4 - HKLM..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe (Scansoft, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [{CCA5C00B-C673-35A0-3B50-26A450212ADE}] C:\Documents and Settings\HP_Administrator\Application Data\Ybno\ysvy.exe File not found
O4 - HKCU..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKCU..\Run: [Sony Ericsson PC Suite] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe (Sony Ericsson Mobile Communications AB)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe (FUJI PHOTO FILM CO., LTD.)
O4 - Startup: C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\Microsoft Outlook.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Download with &Shareaza; - C:\Program Files\Shareaza\RazaWebHook32.dll (Shareaza Development Team)
O8 - Extra context menu item: eBay Search - C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll (eBay Inc.)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} https://moneymanager.egg.com/Pinsafe/accounttracking.cab (AccountTracking Profile Manager Class)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo…toUploader3.cab (Reg Error: Key error.)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo…otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} file:///C:/Program%20Files/AutoCAD%20LT%202002/AcDcToday.ocx (AcDcToday Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} file:///C:/Program%20Files/AutoCAD%20LT%202002/InstBanr.ocx (NOXLATE-BANR)
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} http://upload.members.freewebs.com/Misc/Au…geUploader5.cab (Image Uploader Control)
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} file:///C:/Program%20Files/AutoCAD%20LT%202002/InstFred.ocx (InstaFred)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} http://upload.facebook.com/controls/Facebo…Uploader4_5.cab (Facebook Photo Uploader 4)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} file:///C:/Program%20Files/AutoCAD%20LT%202002/AcPreview.ocx (AcPreview Control)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/RACtrl.cab (Performance Viewer Activex Control)
O16 - DPF: {FF1CD9A3-00CD-45C1-8182-4EEC229A182D} https://www.plaxo.com/activex/plx_upldr-2k-xp.cab (Plaxo Auto-Import Utility)
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\System32\LMIinit.dll (LogMeIn, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/10/10 09:20:36 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/27 08:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/04/30 00:01:14 | 000,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play;
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2010/08/18 06:32:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/08/18 06:32:36 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/08/16 19:25:25 | 000,000,000 | —D | C] – C:\_OTL
[2010/08/15 19:54:52 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe
[2010/08/14 22:17:09 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Yahoo!
[2010/08/14 12:33:50 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Real
[2010/08/01 23:25:16 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/08/01 20:10:08 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/08/01 20:09:41 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/07/27 18:39:13 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/07/27 18:39:12 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/07/24 08:49:35 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Desktop\desktop stuff
[2010/07/15 17:17:22 | 000,012,536 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/07/10 10:23:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/06/07 01:15:35 | 000,000,000 | —D | C] – C:\Program Files\Common Files\xing shared
[2010/05/31 10:14:27 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Malwarebytes
[2010/05/31 10:14:21 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/05/31 10:14:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/05/31 10:14:18 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/05/31 10:14:18 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/05/31 10:10:29 | 000,243,024 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/05/31 10:10:22 | 000,216,400 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/05/31 10:10:20 | 000,029,584 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/05/31 10:10:11 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2010/05/31 10:05:02 | 000,000,000 | —D | C] – C:\Program Files\Windows Installer Clean Up
[2010/05/31 09:52:00 | 000,000,000 | RH-D | C] – C:\Documents and Settings\HP_Administrator\Recent
[2010/05/31 09:25:32 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/05/31 09:19:29 | 000,000,000 | —D | C] – C:\Program Files\WinDirStat
[1 C:\Documents and Settings\HP_Administrator\My Documents\*.tmp files -> C:\Documents and Settings\HP_Administrator\My Documents\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/08/18 16:43:03 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/18 09:43:03 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/18 09:29:31 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/08/18 06:39:05 | 000,000,308 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3678580082-3974553247-2410094170-1007.job
[2010/08/18 06:39:05 | 000,000,300 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3678580082-3974553247-2410094170-1007.job
[2010/08/18 05:47:57 | 063,551,383 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/08/18 05:46:37 | 000,000,444 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{0A88FCC8-DED9-48CD-8F2C-3866008FFDBE}.job
[2010/08/17 17:32:04 | 000,000,186 | —- | M] () – C:\WINDOWS\System\hpsysdrv.DAT
[2010/08/17 17:28:01 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/17 17:26:26 | 000,081,284 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/08/17 17:25:39 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/17 17:25:19 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/17 07:20:11 | 015,728,640 | —- | M] () – C:\Documents and Settings\HP_Administrator\ntuser.dat
[2010/08/17 07:20:11 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\HP_Administrator\ntuser.ini
[2010/08/16 04:20:12 | 000,000,588 | —- | M] () – C:\WINDOWS\tasks\HP_Administrator scan and fix.job
[2010/08/15 20:15:17 | 000,293,376 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\rn8dcdbz.exe
[2010/08/15 19:54:52 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\Desktop\OTL.exe
[2010/08/15 07:45:31 | 000,002,469 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\HiJackThis.lnk
[2010/08/14 22:17:05 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/08/13 00:41:53 | 000,000,485 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Shortcut to Family history.lnk
[2010/08/04 23:51:00 | 000,074,149 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\snow_on_vegas_121808.jpg
[2010/08/04 01:10:13 | 000,071,168 | —- | M] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/24 22:22:09 | 000,081,026 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Picture1.jpg
[2010/07/15 17:17:25 | 000,243,024 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/07/15 17:17:22 | 000,012,536 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/07/15 17:16:24 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/07/14 16:53:28 | 000,000,803 | —- | M] () – C:\Documents and Settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2010/07/04 02:00:00 | 000,000,578 | —- | M] () – C:\WINDOWS\tasks\HP_Administrator backup.job
[2010/06/28 07:06:17 | 000,000,202 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/06/27 08:36:10 | 000,000,000 | -H– | M] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\IconCache.db
[2010/06/12 09:51:59 | 000,000,079 | —- | M] () – C:\WINDOWS\BRPP2KA.INI
[2010/06/12 09:51:58 | 000,000,871 | —- | M] () – C:\WINDOWS\BRWMARK.INI
[2010/06/12 09:49:54 | 000,000,152 | —- | M] () – C:\WINDOWS\brpcfx.ini
[2010/06/12 09:49:53 | 000,000,850 | —- | M] () – C:\WINDOWS\Brpfx04a.ini
[2010/06/12 09:49:50 | 000,000,050 | —- | M] () – C:\WINDOWS\System32\BRIDF04A.dat
[2010/06/11 18:30:51 | 000,384,596 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/06/11 18:30:51 | 000,054,280 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/06/11 18:30:49 | 000,442,244 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/11 18:28:06 | 000,542,432 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/11 07:30:51 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/06/11 07:29:54 | 000,000,581 | —- | M] () – C:\WINDOWS\win.ini
[2010/06/09 17:16:41 | 000,083,360 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\System32\LMIRfsClientNP.dll
[2010/06/09 17:16:40 | 000,087,424 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\System32\LMIinit.dll
[2010/06/09 17:16:40 | 000,029,568 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\System32\LMIport.dll
[2010/06/09 07:02:49 | 000,886,784 | —- | M] () – C:\Documents and Settings\HP_Administrator\My Documents\ipd.pub
[2010/06/07 01:14:35 | 000,278,528 | —- | M] (Real Networks, Inc) – C:\WINDOWS\System32\pncrt.dll
[2010/06/02 16:59:19 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/05/31 10:10:20 | 000,113,461 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/05/22 07:46:47 | 000,131,584 | —- | M] () – C:\Documents and Settings\HP_Administrator\My Documents\2010 sched.doc
[1 C:\Documents and Settings\HP_Administrator\My Documents\*.tmp files -> C:\Documents and Settings\HP_Administrator\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/15 20:15:17 | 000,293,376 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\rn8dcdbz.exe
[2010/08/13 00:41:53 | 000,000,485 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Shortcut to Family history.lnk
[2010/08/04 23:51:00 | 000,074,149 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\snow_on_vegas_121808.jpg
[2010/08/01 23:25:17 | 000,002,469 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\HiJackThis.lnk
[2010/07/24 22:19:37 | 000,081,026 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Picture1.jpg
[2010/06/19 17:37:00 | 000,000,300 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3678580082-3974553247-2410094170-1007.job
[2010/06/11 07:20:53 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2010/06/09 06:31:54 | 000,886,784 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\ipd.pub
[2010/05/31 10:10:20 | 000,113,461 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/05/31 10:10:11 | 063,551,383 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/05/22 07:46:47 | 000,131,584 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\2010 sched.doc
[2009/12/26 14:20:09 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\FsUsbExDevice.Dll
[2009/12/26 14:20:09 | 000,036,608 | —- | C] () – C:\WINDOWS\System32\FsUsbExDisk.Sys
[2009/12/05 13:34:31 | 000,120,200 | —- | C] () – C:\WINDOWS\System32\DLLDEV32i.dll
[2009/07/10 01:52:51 | 000,000,076 | —- | C] () – C:\WINDOWS\System32\w3url.dll
[2009/07/03 12:24:52 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2009/04/10 06:55:42 | 000,000,215 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2008/03/07 14:54:49 | 000,000,040 | —- | C] () – C:\WINDOWS\opt_2460.ini
[2008/03/07 14:54:47 | 000,000,051 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2008/01/14 19:13:38 | 000,000,025 | —- | C] () – C:\WINDOWS\wpd99.drv
[2008/01/14 19:13:36 | 000,051,716 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2007/10/30 20:09:15 | 000,035,363 | —- | C] () – C:\WINDOWS\System32\windrvNT.sys
[2007/10/25 15:53:57 | 000,000,120 | —- | C] () – C:\WINDOWS\PbkUser.INI
[2007/09/12 10:19:56 | 000,008,520 | —- | C] () – C:\WINDOWS\System32\ractrlkeyhook.dll
[2007/06/03 15:36:38 | 000,000,044 | —- | C] () – C:\WINDOWS\liveup.ini
[2007/04/07 16:44:10 | 000,000,063 | —- | C] () – C:\WINDOWS\mdm.ini
[2007/04/07 16:27:13 | 000,005,937 | —- | C] () – C:\WINDOWS\mgxoschk.ini
[2007/02/20 20:01:26 | 000,003,654 | —- | C] () – C:\WINDOWS\System32\drivers\Sonyhcp.dll
[2007/02/13 18:40:35 | 000,307,200 | —- | C] () – C:\WINDOWS\System32\fxstudio.dll
[2007/02/13 18:40:34 | 000,282,624 | —- | C] () – C:\WINDOWS\System32\animation2.dll
[2007/01/24 19:08:53 | 000,022,016 | —- | C] () – C:\WINDOWS\exeshl.dll
[2007/01/24 19:08:53 | 000,000,049 | —- | C] () – C:\WINDOWS\netctrl.ini
[2007/01/24 19:08:00 | 000,233,472 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2007/01/24 19:07:59 | 000,532,480 | —- | C] () – C:\WINDOWS\System32\NCTAudioEditor2.dll
[2006/12/20 00:31:42 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\suppdll.dll
[2006/12/19 20:33:48 | 000,000,154 | —- | C] () – C:\WINDOWS\adidsl.ini
[2006/12/19 20:33:48 | 000,000,021 | —- | C] () – C:\WINDOWS\Fast800.ini
[2006/12/19 20:33:40 | 000,126,976 | —- | C] () – C:\WINDOWS\System32\coclassfast.dll
[2006/12/19 20:33:40 | 000,046,892 | —- | C] () – C:\WINDOWS\System32\adadix16.dll
[2006/12/19 17:31:24 | 000,079,360 | —- | C] () – C:\WINDOWS\System32\acdbres.dll
[2006/12/17 16:57:31 | 000,000,000 | —- | C] () – C:\WINDOWS\Brownie.ini
[2006/12/17 13:31:50 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\MSVCRT10.DLL
[2006/12/17 13:31:50 | 000,000,036 | —- | C] () – C:\WINDOWS\kpcms.ini
[2006/12/17 13:09:48 | 000,003,840 | —- | C] () – C:\WINDOWS\System32\drivers\BANTExt.sys
[2006/12/17 12:37:12 | 000,000,202 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/12/17 11:50:52 | 000,036,864 | R— | C] () – C:\WINDOWS\System32\RunSetup.dll
[2006/12/17 11:02:10 | 000,000,850 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2006/12/17 11:02:10 | 000,000,152 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2006/12/17 11:00:35 | 000,027,019 | —- | C] () – C:\WINDOWS\maxlink.ini
[2006/12/17 10:54:45 | 000,030,208 | —- | C] () – C:\WINDOWS\System32\WNASPI32.DLL
[2006/12/17 10:54:45 | 000,000,296 | —- | C] () – C:\WINDOWS\msfsetup.ini
[2006/12/16 16:30:42 | 000,000,936 | —- | C] () – C:\WINDOWS\adiras.ini
[2006/12/16 15:00:28 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/12/16 14:52:37 | 000,000,871 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2006/12/16 14:52:37 | 000,000,079 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2006/12/16 14:52:37 | 000,000,030 | —- | C] () – C:\WINDOWS\System32\brss01a.ini
[2006/09/13 23:32:57 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/09/13 23:11:49 | 000,028,848 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2006/09/13 23:07:29 | 000,014,308 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2006/09/13 23:07:23 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2006/09/13 22:59:44 | 000,000,157 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/09/13 22:53:55 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2006/09/13 22:51:18 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/09/13 22:51:18 | 001,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/09/13 22:51:18 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/09/13 22:51:18 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/09/13 22:51:18 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/09/13 22:33:34 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/09/13 22:26:48 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2006/09/13 22:26:48 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2006/09/13 22:26:32 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2006/06/16 12:58:18 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/05 14:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/12/21 11:13:56 | 000,191,136 | —- | C] () – C:\WINDOWS\System32\plx_upldr.dll
[2004/07/08 14:37:36 | 000,000,567 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/10/03 19:50:11 | 000,072,192 | —- | C] () – C:\WINDOWS\System32\anti_deb.dll
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/03/04 11:16:34 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\Jpeg32.dll
[2000/09/18 17:50:28 | 000,202,752 | —- | C] () – C:\WINDOWS\System32\Zlib.dll
[1999/01/22 19:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1996/04/03 20:33:26 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys

========== LOP Check ==========

[2010/05/31 10:09:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2007/10/20 11:50:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2009/10/30 22:58:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\D213
[2007/11/09 18:28:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\eBay
[2008/06/19 07:08:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogMeIn
[2009/12/05 13:37:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MAGIX
[2010/03/17 10:27:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2007/04/10 01:36:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\nabocorp
[2009/07/03 12:59:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/12/26 14:26:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2008/01/14 19:13:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pdf995
[2010/05/31 09:15:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RegCure
[2006/12/17 11:00:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2008/03/14 18:54:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Teleca
[2009/01/18 16:14:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WholeSecurity
[2010/07/10 10:24:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2009/08/31 23:51:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\YAHOO
[2010/08/18 05:46:37 | 000,000,444 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{0A88FCC8-DED9-48CD-8F2C-3866008FFDBE}.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 16 bytes -> C:\Documents and Settings\HP_Administrator\My Documents\My Music From Internet:Shareaza.GUID
< End of report >



Many Thanks
Steve
Hi stevedevil,

Please do the following:

1. Microsoft Office, Compact Files:
Please open Microsoft Office.
  • In folder view Right Click Personal folders.
  • Click "Properties for Personal Folders"
  • Click the "Advanced" button.
  • Click "Compact Now" and allow outlook to compact your emails.


2. OTL Fix:
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Files
    C:\Documents and Settings\All Users\Application Data\Symantec
    
    :Commands
    [emptytemp]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the log from OTL presented after to Reboot.


3. Norton Removal Tool:
Download the Norton Removal Tool from HERE and save it to your desktop.

Next Double click on Norton_Removal_Tool.exe to run the tool.

Follow the on-screen instructions.
Your computer may be restarted more than once, and you may be asked to repeat some steps after the computer restarts.



In your next reply please include:
  • How the compacting of the emails went.
  • The OTL log.
  • How your computer is running now.
Cheers :thumbup:
Hello. The email compacting took about 3 seconds to perform, is that normal? The OTL is here: All processes killed ========== FILES ========== C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\{5FE70C07-974B-4399-ADB8-A6C64A0FE4BD} folder moved successfully. C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine folder moved successfully. C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus folder moved successfully. C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate folder moved successfully. C:\Documents and Settings\All Users\Application Data\Symantec folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Application Data User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: HP_Administrator ->Temp folder emptied: 116278051 bytes ->Temporary Internet Files folder emptied: 455500225 bytes ->Java cache emptied: 133227 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 3151 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: LogMeInRemoteUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 428172 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 2849 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 1046 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 546.00 mb OTL by OldTimer - Version 3.2.9.1 log created on 08202010_064852 Files\Folders moved on Reboot… C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Google Toolbar\GoogleToolbarWelcome.log moved successfully. File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temp\9B.tmp not found! File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temp\~DFE3D0.tmp not found! File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temp\~DFE795.tmp not found! C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\RJ2YH1ZH\like[1].htm moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\QU2W00HR\iframe[1].htm moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\MBOJW3UT\ai[6].htm moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\LRY4OSCJ\redirectiframe[1].html moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\73UWJOWF\11[1].htm moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\5UTDRJW2\index[1].htm moved successfully. C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\2UO9R8HI\home[1].htm moved successfully. Registry entries deleted on Reboot… The only two problems I have, which have been there since my first contact, are in Google search results. When I click a random one of them, it leads to a rogue ads page maybe 50% of the time, depending which links are infected I guess. And the other problem is that every 10 minutes or so, another rogue page just loads itself, without any clicking at all. Thanks for your help, Steve.
Hi stevedevil,

Please read through these instructions to familarize yourself with what to expect when this tool runs


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Results of Combo Fix scan. Thanks, Steve ############################################################## ComboFix 10-08-19.02 - HP_Administrator 21/08/2010 9:47.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1022.559 [GMT 1:00] Running from: c:\documents and settings\[removed]\Desktop\PC FIX whatthetech\ComboFix.exe AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users\Application Data\hpe393.dll c:\documents and settings\All Users\Application Data\hpe77.dll c:\documents and settings\HP_Administrator\Application Data\Ybno\ysvy.exe D:\Autorun.inf Infected copy of c:\windows\system32\drivers\intelppm.sys was found and disinfected Restored copy from - Kitty had a snack :P . ((((((((((((((((((((((((( Files Created from 2010-07-21 to 2010-08-21 ))))))))))))))))))))))))))))))) . 2010-08-18 05:33 . 2010-08-18 05:33 503808 —-a-w- c:\documents and settings\HP_Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-3ad91433-n\msvcp71.dll 2010-08-18 05:33 . 2010-08-18 05:33 499712 —-a-w- c:\documents and settings\HP_Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-3ad91433-n\jmc.dll 2010-08-18 05:33 . 2010-08-18 05:33 348160 —-a-w- c:\documents and settings\HP_Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-3ad91433-n\msvcr71.dll 2010-08-18 05:33 . 2010-08-18 05:33 61440 —-a-w- c:\documents and settings\HP_Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-6a28839e-n\decora-sse.dll 2010-08-18 05:33 . 2010-08-18 05:33 12800 —-a-w- c:\documents and settings\HP_Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-6a28839e-n\decora-d3d.dll 2010-08-18 05:32 . 2010-08-18 05:32 ——– d—–w- c:\program files\Common Files\Java 2010-08-18 05:32 . 2010-08-18 05:31 423656 —-a-w- c:\windows\system32\deployJava1.dll 2010-08-16 18:25 . 2010-08-16 18:25 ——– d—–w- C:\_OTL 2010-08-14 21:17 . 2010-08-14 21:17 ——– d—–w- c:\documents and settings\NetworkService\Application Data\Yahoo! 2010-08-01 22:25 . 2010-08-01 22:25 388096 —-a-r- c:\documents and settings\HP_Administrator\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2010-08-01 22:25 . 2010-08-01 22:25 ——– d—–w- c:\program files\Trend Micro 2010-08-01 19:09 . 2010-08-01 19:28 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe 2010-07-27 16:40 . 2010-07-27 16:40 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-08-21 08:03 . 2009-12-05 21:31 1324 —-a-w- c:\windows\system32\d3d9caps.dat 2010-08-21 01:28 . 2007-03-10 09:12 ——– d—–w- c:\program files\LogMeIn 2010-08-20 06:11 . 2006-09-13 22:19 ——– d—–w- c:\program files\Common Files\Symantec Shared 2010-08-18 05:28 . 2006-09-13 21:36 ——– d—–w- c:\program files\Java 2010-08-15 18:57 . 2008-05-11 17:07 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\Ybno 2010-08-15 09:19 . 2008-02-14 15:24 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\Medu 2010-08-08 05:30 . 2008-02-13 20:52 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\Fixe 2010-08-07 07:02 . 2007-10-07 11:43 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\Meum 2010-07-15 16:17 . 2010-05-31 09:10 243024 —-a-w- c:\windows\system32\drivers\avgtdix.sys 2010-07-15 16:17 . 2010-07-15 16:17 12536 —-a-w- c:\windows\system32\avgrsstx.dll 2010-07-15 16:16 . 2010-05-31 09:10 216400 —-a-w- c:\windows\system32\drivers\avgldx86.sys 2010-07-10 09:24 . 2010-07-10 09:23 ——– d—–w- c:\documents and settings\All Users\Application Data\WinZip 2010-06-30 16:14 . 2006-12-17 11:38 ——– d—–w- c:\program files\Folder Lock 2010-06-28 17:58 . 2009-08-19 05:31 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\HpUpdate 2010-06-23 16:31 . 2010-06-23 16:31 501936 —-a-w- c:\documents and settings\All Users\Application Data\Google\Google Toolbar\Update\gtb1FE.tmp.exe 2010-06-14 14:31 . 2004-08-09 21:00 744448 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe 2010-06-12 13:27 . 2006-12-17 09:58 57 —-a-w- c:\documents and settings\All Users\Application Data\Brother\BrLog\BrCollectDir\BR_cat.bat 2010-06-12 08:49 . 2006-12-17 10:02 50 —-a-w- c:\windows\system32\BRIDF04A.dat 2010-06-09 16:16 . 2007-06-03 22:05 83360 —-a-w- c:\windows\system32\LMIRfsClientNP.dll 2010-06-09 16:16 . 2007-03-10 09:12 29568 —-a-w- c:\windows\system32\LMIport.dll 2010-06-09 16:16 . 2007-03-10 09:12 87424 —-a-w- c:\windows\system32\LMIinit.dll 2010-06-07 00:16 . 2010-06-07 00:16 49152 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll 2010-06-07 00:16 . 2010-06-07 00:16 45056 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll 2010-06-07 00:16 . 2010-06-07 00:16 45056 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll 2010-06-07 00:16 . 2010-06-07 00:16 45056 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll 2010-06-07 00:16 . 2010-06-07 00:16 45056 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll 2010-06-07 00:16 . 2010-06-07 00:16 308808 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll 2010-06-07 00:16 . 2010-06-07 00:16 14848 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll 2010-06-07 00:16 . 2010-06-07 00:16 341600 —-a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll 2010-06-02 15:59 . 2010-05-31 09:10 29584 —-a-w- c:\windows\system32\drivers\avgmfx86.sys 2010-05-31 09:05 . 2010-05-31 09:05 3584 —-a-r- c:\documents and settings\HP_Administrator\Application Data\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0974BA1E-64EC-11DE-B2A5-E43756D89593}] 2009-08-10 14:06 91576 —-a-w- c:\program files\BearShareTb\BearShareDx.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{0974BA1E-64EC-11DE-B2A5-E43756D89593}"= "c:\program files\BearShareTb\BearShareDx.dll" [2009-08-10 91576] [HKEY_CLASSES_ROOT\clsid\{0974ba1e-64ec-11de-b2a5-e43756d89593}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-23 68856] "Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2009-09-24 434176] "AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2009-04-07 102400] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512] "RTHDCPL"="RTHDCPL.EXE" [2006-07-21 16261632] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-02-21 143360] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-31 7634944] "nwiz"="nwiz.exe" [2006-10-31 1622016] "DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 90112] "Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568] "HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 249856] "REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248] "SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648] "PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393] "IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960] "SetDefPrt"="c:\program files\Brother\Brmfl04a\BrStDvPt.exe" [2004-05-25 49152] "ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2004-07-20 851968] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "BigDogPath"="c:\windows\VM_STI.EXE" [2005-02-28 53248] "eBayToolbar"="c:\program files\eBay\eBay Toolbar2\eBayTBDaemon.exe" [2009-01-19 632048] "LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 63048] "Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 159744] "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888] "AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-07-15 2065760] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-06-07 202256] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552] c:\documents and settings\Default User\Start Menu\Programs\Startup\ Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-9-13 27136] PinMcLnk.lnk - c:\hp\bin\cloaker.exe [2006-9-13 27136] c:\documents and settings\LogMeInRemoteUser\Start Menu\Programs\Startup\ Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-9-13 27136] PinMcLnk.lnk - c:\hp\bin\cloaker.exe [2006-9-13 27136] c:\documents and settings\All Users\Start Menu\Programs\Startup\ DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2006-12-19 962663] Exif Launcher.lnk - c:\program files\FinePixViewer\QuickDCF.exe [2006-12-17 200704] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2010-07-15 16:17 12536 —-a-w- c:\windows\system32\avgrsstx.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit] 2010-06-09 16:16 87424 —-a-w- c:\windows\system32\LMIinit.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\StubInstaller.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\LimeWire\\LimeWire.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"= "c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Java\\jre6\\bin\\java.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Samsung\\Samsung New PC Studio\\npsasvr.exe"= "c:\\Program Files\\Samsung\\Samsung New PC Studio\\npsvsvr.exe"= "c:\\Program Files\\Shareaza\\Shareaza.exe"= "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"= "c:\\Program Files\\AVG\\AVG9\\avgupd.exe"= "c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"= R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [31/05/2010 10:10 216400] R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [31/05/2010 10:10 243024] R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [15/07/2010 17:17 308136] R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [03/06/2007 23:05 12856] S2 gupdate1c9b03d370cb7a6;Google Update Service (gupdate1c9b03d370cb7a6);c:\program files\Google\Update\GoogleUpdate.exe [29/03/2009 08:08 133104] S2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [10/02/2010 18:28 90112] S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe [05/12/2009 13:37 1527900] S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [26/12/2009 14:20 36608] S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [03/07/2009 06:35 89256] S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [03/07/2009 06:35 15016] S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [03/07/2009 06:35 120744] S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [03/07/2009 06:35 114216] S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [03/07/2009 06:35 25512] S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [03/07/2009 06:35 110632] S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [03/07/2009 06:35 115752] S3 UPnPService;UPnPService;c:\program files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [05/12/2009 13:35 544768] S4 ATMhelpr;ATMhelpr;c:\windows\system32\drivers\ATMHELPR.SYS [08/02/2007 10:21 4064] S4 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [26/12/2009 14:20 233472] . Contents of the 'Scheduled Tasks' folder 2010-08-14 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34] 2010-08-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-03-29 07:08] 2010-08-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-03-29 07:08] 2010-08-21 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-3678580082-3974553247-2410094170-1007.job - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09] 2010-08-21 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3678580082-3974553247-2410094170-1007.job - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09] 2010-08-21 c:\windows\Tasks\User_Feed_Synchronization-{0A88FCC8-DED9-48CD-8F2C-3866008FFDBE}.job - c:\windows\system32\msfeedssync.exe [2006-10-17 03:31] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.co.uk/webhp?sourceid=navclient&hl;=en-GB&ie;=UTF-8 uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8 uSearchAssistant = hxxp://www.google.com/ie IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200 IE: Download with &Shareaza; - c:\program files\Shareaza\RazaWebHook32.dll/3000 IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 IE: eBay Search - c:\program files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html TCP: {94353BF2-884E-406B-8885-257F5503C4C8} = 212.139.132.105 212.139.132.107 DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} - hxxps://moneymanager.egg.com/Pinsafe/accounttracking.cab DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} - hxxp://upload.members.freewebs.com/Misc/Aurigma/ImageUploader5.cab . . ——- File Associations ——- . .scr=AutoCADLTScriptFile . - - - - ORPHANS REMOVED - - - - AddRemove-HijackThis - k:\diagnostics\Anti-Malware\HijackThis.exe ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{399560AD-16A1-1C42-B8ABCDA82BB95BD1}\{612A140D-0F00-4178-3873E27B58551793}\{AE627BFA-B567-4F9A-57DD34442A0D5150}*] "S6KI1YERXJTIP3T5RVDI41UR2G1"=hex:01,00,01,00,00,00,00,00,26,ff,b1,c2,08,0b,50, 9e,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{40886FA5-87BC-FDA7-0C1FAC01C243999B}\{19E564B2-522B-7AA8-1ACCCD0705265332}\{1F2DE655-6E2E-2DD5-8638E8D01A513D14}*] "{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1"=hex:01,00,01,00,0c,00,00,00,1b,4d,cb, 1b,d3,8d,9a,6f,6e,df,a3,29,73,6d,df,a4,56,29,2c,43,d1,a5,77,24,19,dc,2c,ad,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4A198D38-1B44-C07B-9EC195CD26A56314}\{73310DCC-C68F-341A-0D6AC2DC6E4B9C08}\{8FC8D867-026E-4653-C922EAC5C8EDCF7A}*] "S6KI1YERXJTIP3T5RVDI41UR2G1"=hex:01,00,01,00,00,00,00,00,26,ff,b1,c2,08,0b,50, 9e,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5C082286-DD56-6B96-110FABAC317C22E3}\{17077DA0-F2D9-EF48-DBC13F521337D931}\{A783887F-564D-BBBA-662193019693FEBC}*] "{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1"=hex:01,00,01,00,0c,00,00,00,1b,4d,cb, 1b,d3,8d,9a,6f,6e,df,a3,29,73,6d,df,a4,56,29,2c,43,d1,a5,77,24,19,dc,2c,ad,\ [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C9791B2E-5B50-94A2-6150B4CB461D6075}\{0B8A9361-9405-15CE-FD3AFA34C9DB9BA2}\{54850B20-C302-5B9E-ABC602476860E9F3}*] "S6KI1YERXJTIP3T5RVDI41UR2G1"=hex:01,00,01,00,00,00,00,00,26,ff,b1,c2,08,0b,50, 9e,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F9E7FB8A-7FC0-F5C6-C2C005BCC6E52A75}\{38D64012-6403-EA81-41E60280EAB79558}\{8D4E630B-001F-4733-DF87B943421629E7}*] "{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1"=hex:01,00,01,00,0c,00,00,00,1b,4d,cb, 1b,d3,8d,9a,6f,6e,df,a3,29,73,6d,df,a4,56,29,2c,43,d1,a5,77,24,19,dc,2c,ad,\ [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'winlogon.exe'(816) c:\windows\system32\LMIinit.dll c:\windows\system32\LMIRfsClientNP.dll . Completion time: 2010-08-21 10:02:07 ComboFix-quarantined-files.txt 2010-08-21 09:02 Pre-Run: 39,236,186,112 bytes free Post-Run: 39,194,132,480 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect - - End Of File - - D5B3328E55361875AF05F33CDCF57D78
Hi stevedevil,

Please work your way through the following:


1. CFScript:
Please open Notepad and copy/paste this code into the notepad:
Folder::
c:\documents and settings\HP_Administrator\Application Data\Ybno

RegNull::
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{399560AD-16A1-1C42-B8ABCDA82BB95BD1}\{612A140D-0F00-4178-3873E27B58551793}\{AE627BFA-B567-4F9A-57DD34442A0D5150}*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{40886FA5-87BC-FDA7-0C1FAC01C243999B}\{19E564B2-522B-7AA8-1ACCCD0705265332}\{1F2DE655-6E2E-2DD5-8638E8D01A513D14}*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4A198D38-1B44-C07B-9EC195CD26A56314}\{73310DCC-C68F-341A-0D6AC2DC6E4B9C08}\{8FC8D867-026E-4653-C922EAC5C8EDCF7A}*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5C082286-DD56-6B96-110FABAC317C22E3}\{17077DA0-F2D9-EF48-DBC13F521337D931}\{A783887F-564D-BBBA-662193019693FEBC}*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C9791B2E-5B50-94A2-6150B4CB461D6075}\{0B8A9361-9405-15CE-FD3AFA34C9DB9BA2}\{54850B20-C302-5B9E-ABC602476860E9F3}*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F9E7FB8A-7FC0-F5C6-C2C005BCC6E52A75}\{38D64012-6403-EA81-41E60280EAB79558}\{8D4E630B-001F-4733-DF87B943421629E7}*]

Save this as CFScript.txt and change the 'Save as type' to 'All Files' and place it on your desktop. Make sure your AV is disabled while we do this.

[external image: Posted Image]
Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.

ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.


In your next reply please include:
  • The Combofix log.
  • How is your computer running now? Still getting redirects?
Cheers :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI