This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

unknown infection - AOL mail sending unwanted emails

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi All,

For about a week, Ive been having an issue with my AOL email. It has been sending automatic emails/replies to many of my incoming emails. I can see these emails in my Sent mail box, even though i did not send them. I am not getting any of these emails to my own email address. All of the emails have the same link: hxxp://Laguirendd85.servemp3.com

Two possibly related things: there has been no Spam in my Spam folder for days, which seems odd. Also, this may have happened after I downloaded music last week.

We have Symantec and I ran a full scan, which turned up little, then changed my password and security code from another computer - this did not help and the emails continued.

I contacted AOL and, on their advice, downloaded 4 things: McAfee Stinger, AdAware, Spybot and Hijack This. I ran the first three, each which turned up little/nothing (1-4 cookies). Now I ran the Hijack This program and need assistance interpreting it.

I would appreciate any assistance figuring out what to do based on the log (pasted below) or about the AOL issue in general. I'm a pretty basic computer user but trying to figure this out since I have had the email address for 10+ years and do not want to get a new one!

Many thanks!

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:14:36 PM, on 8/18/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AirPort\APAgent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: MHURLSearchHook Class - {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Program Files\Family Toolbar\tbhelper.dll
O2 - BHO: MHTBPos00 - {0C37B053-FD68-456a-82E1-D788EE342E6F} - C:\Program Files\Family Toolbar\tbcore3.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: MyHeritage New Tab - {D62EC836-BF1E-4CAC-81BE-FB9179835D8E} - C:\Program Files\Family Toolbar\mhxpcomi.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Family Toolbar - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Program Files\Family Toolbar\tbcore3.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AirPort Base Station Agent] "C:\Program Files\AirPort\APAgent.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1265050135935
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: mhtb - {669A2A3A-F19C-452D-800D-1240299756C1} - C:\Program Files\Family Toolbar\mhxpcomi.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe

–
End of file - 8629 bytes
Hi madi1115, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.


Go HERE to get a randomly named copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your desktop.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Double click on the file you downloaded. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER will not run in normal windows, please run it in Saffe Mode


Next

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.

Next
Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\system32\spool\prtprocs\w32x86\*.tmp
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • GMER log
  • MBRCheck log
  • both OTL logs
Thanks
Hi Oldman960, Thanks for your speedy reply. I began the process you suggested and things seem to be getting worse. I saved and opened GMER - it said "publisher could not be verified. Are you sure you want to run?" and I said yes AdAware (or something) popped up and said it (GMER) was trying to change registry settings but I allowed it. I deselected the 3 boxes on the GMER screen, as indicated. In the middle of the scan, the computer restarted then said that the computer has recovered from a serious error. I tried the process again with the same results (restart and recovery from serious error). A few times after that I tried to open the GMER program (but not run a scan) just to make sure i unchecked the right boxes. I kept getting a message stating that "Windows Explorer needs to shut down" and the screen looked like it would restart (icons disappearing from screen briefly) but then all icons reappeared. This happened a few times when i tried to click on GMER or any My Documents folder. Then the computer got very slow (i guess i clicked on GMER too many times and they were struggling to open). I shut down the computer. As it was shutting, one GMER screen finally opened and I noticed that the main screen had a list of drivers listed. I couldnt write them down because I needed to leave for work and could not start the computer again but not sure if this is a problem or not. If it helps to know, I had no visible problems with the computer running prior, only with my AOL mail (which is getting worse too.. now Im getting the unwanted emails with the same link). Thanks again!
Here is the output from MBRCheck:

MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows XP Home Edition
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000007d

Kernel Drivers (total 148):
0x804D7000 \WINDOWS\system32\ntoskrnl.exe
0x806FF000 \WINDOWS\system32\hal.dll
0xF7AAF000 \WINDOWS\system32\KDCOM.DLL
0xF79BF000 \WINDOWS\system32\BOOTVID.dll
0xF7560000 ACPI.sys
0xF7AB1000 \WINDOWS\System32\DRIVERS\WMILIB.SYS
0xF754F000 pci.sys
0xF75AF000 isapnp.sys
0xF75BF000 ohci1394.sys
0xF75CF000 \WINDOWS\System32\DRIVERS\1394BUS.SYS
0xF7B77000 pciide.sys
0xF782F000 \WINDOWS\System32\DRIVERS\PCIIDEX.SYS
0xF75DF000 MountMgr.sys
0xF7530000 ftdisk.sys
0xF7837000 PartMgr.sys
0xF75EF000 VolSnap.sys
0xF7518000 atapi.sys
0xF75FF000 disk.sys
0xF760F000 \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
0xF74F8000 fltmgr.sys
0xF74E6000 sr.sys
0xF761F000 Lbd.sys
0xF74CF000 KSecDD.sys
0xF7442000 Ntfs.sys
0xF7415000 NDIS.sys
0xF73FB000 Mup.sys
0xF762F000 agp440.sys
0xF764F000 \SystemRoot\System32\DRIVERS\nic1394.sys
0xF778F000 \SystemRoot\System32\DRIVERS\intelppm.sys
0xF71F8000 \SystemRoot\System32\DRIVERS\ati2mtag.sys
0xF71E4000 \SystemRoot\System32\DRIVERS\VIDEOPRT.SYS
0xF78BF000 \SystemRoot\System32\DRIVERS\usbuhci.sys
0xF71C0000 \SystemRoot\System32\DRIVERS\USBPORT.SYS
0xF718A000 \SystemRoot\System32\DRIVERS\HSFBS2S2.sys
0xF7167000 \SystemRoot\System32\DRIVERS\ks.sys
0xF7068000 \SystemRoot\System32\DRIVERS\HSFDPSP2.sys
0xF6FC0000 \SystemRoot\System32\DRIVERS\HSFCXTS2.sys
0xF78C7000 \SystemRoot\System32\Drivers\Modem.SYS
0xF6F66000 \SystemRoot\system32\drivers\ctaud2k.sys
0xF6F42000 \SystemRoot\system32\drivers\portcls.sys
0xF779F000 \SystemRoot\system32\drivers\drmk.sys
0xF6F16000 \SystemRoot\system32\drivers\ctoss2k.sys
0xF7AD9000 \SystemRoot\system32\drivers\ctprxy2k.sys
0xF6EAE000 \SystemRoot\System32\DRIVERS\e100b325.sys
0xF78CF000 \SystemRoot\System32\DRIVERS\fdc.sys
0xF77AF000 \SystemRoot\System32\DRIVERS\i8042prt.sys
0xF78D7000 \SystemRoot\System32\DRIVERS\kbdclass.sys
0xF77BF000 \SystemRoot\System32\DRIVERS\serial.sys
0xF7A83000 \SystemRoot\System32\DRIVERS\serenum.sys
0xF6E9A000 \SystemRoot\System32\DRIVERS\parport.sys
0xF77CF000 \SystemRoot\system32\DRIVERS\imapi.sys
0xF6E82000 \SystemRoot\System32\Drivers\AnyDVD.sys
0xF77DF000 \SystemRoot\System32\DRIVERS\cdrom.sys
0xF77EF000 \SystemRoot\System32\DRIVERS\redbook.sys
0xF78DF000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0xF7C78000 \SystemRoot\System32\DRIVERS\audstub.sys
0xF77FF000 \SystemRoot\System32\DRIVERS\rasl2tp.sys
0xF7A8F000 \SystemRoot\System32\DRIVERS\ndistapi.sys
0xF6E6B000 \SystemRoot\System32\DRIVERS\ndiswan.sys
0xF780F000 \SystemRoot\System32\DRIVERS\raspppoe.sys
0xF781F000 \SystemRoot\System32\DRIVERS\raspptp.sys
0xF78E7000 \SystemRoot\System32\DRIVERS\TDI.SYS
0xF6DBA000 \SystemRoot\System32\DRIVERS\psched.sys
0xF765F000 \SystemRoot\System32\DRIVERS\msgpc.sys
0xF78EF000 \SystemRoot\System32\DRIVERS\ptilink.sys
0xF78F7000 \SystemRoot\System32\DRIVERS\raspti.sys
0xF766F000 \SystemRoot\System32\DRIVERS\termdd.sys
0xF78FF000 \SystemRoot\System32\DRIVERS\mouclass.sys
0xF7ADB000 \SystemRoot\System32\DRIVERS\swenum.sys
0xF6D5C000 \SystemRoot\System32\DRIVERS\update.sys
0xF7A9B000 \SystemRoot\System32\DRIVERS\mssmbios.sys
0xF7907000 \SystemRoot\system32\DRIVERS\omci.sys
0xF76CF000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xF76DF000 \SystemRoot\System32\DRIVERS\usbhub.sys
0xF7ADF000 \SystemRoot\System32\DRIVERS\USBD.SYS
0xF73BE000 \SystemRoot\system32\drivers\MODEMCSA.sys
0xBA723000 \SystemRoot\system32\drivers\ha10kx2k.sys
0xBA701000 \SystemRoot\system32\drivers\emupia2k.sys
0xF7927000 \SystemRoot\System32\DRIVERS\flpydisk.sys
0xBA1EF000 \SystemRoot\System32\Drivers\SRTSP.SYS
0xF792F000 \SystemRoot\System32\DRIVERS\USBSTOR.SYS
0xF7A43000 \SystemRoot\System32\DRIVERS\hidusb.sys
0xF775F000 \SystemRoot\System32\DRIVERS\HIDCLASS.SYS
0xF7937000 \SystemRoot\System32\DRIVERS\HIDPARSE.SYS
0xB93BE000 \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
0xF7A53000 \SystemRoot\System32\DRIVERS\mouhid.sys
0xF6E5B000 \SystemRoot\System32\Drivers\SRTSPX.SYS
0xF7B19000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xF7BA9000 \SystemRoot\System32\Drivers\Null.SYS
0xF7B25000 \SystemRoot\System32\Drivers\Beep.SYS
0xF7967000 \SystemRoot\System32\drivers\vga.sys
0xF7B27000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF7B31000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xF7987000 \SystemRoot\System32\Drivers\Msfs.SYS
0xF798F000 \SystemRoot\System32\Drivers\Npfs.SYS
0xF6D48000 \SystemRoot\System32\DRIVERS\rasacd.sys
0xB9377000 \SystemRoot\System32\DRIVERS\ipsec.sys
0xB931E000 \SystemRoot\System32\DRIVERS\tcpip.sys
0xB92F1000 \SystemRoot\System32\Drivers\SYMTDI.SYS
0xB92CB000 \SystemRoot\System32\DRIVERS\ipnat.sys
0xF6E2B000 \SystemRoot\System32\DRIVERS\wanarp.sys
0xB92A3000 \SystemRoot\System32\DRIVERS\netbt.sys
0xF6E0B000 \SystemRoot\System32\DRIVERS\arp1394.sys
0xB9281000 \SystemRoot\System32\drivers\afd.sys
0xF6DFB000 \SystemRoot\System32\DRIVERS\netbios.sys
0xB9217000 \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
0xB91EC000 \SystemRoot\System32\DRIVERS\rdbss.sys
0xB917C000 \SystemRoot\System32\DRIVERS\mrxsmb.sys
0xF6DDB000 \SystemRoot\System32\Drivers\Fips.SYS
0xF79B7000 \SystemRoot\System32\Drivers\ElbyCDIO.sys
0xB911E000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
0xB9101000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
0xBA6E1000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xB90C1000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xF7B6B000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xF6D40000 \SystemRoot\System32\drivers\Dxapi.sys
0xF788F000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xF7C17000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\ati2dvag.dll
0xBF055000 \SystemRoot\System32\ati2cqag.dll
0xBF09B000 \SystemRoot\System32\atikvmag.dll
0xBF0DF000 \SystemRoot\System32\ati3duag.dll
0xBF323000 \SystemRoot\System32\ativvaxx.dll
0xB6F71000 \SystemRoot\System32\DRIVERS\ndisuio.sys
0xB6B75000 \SystemRoot\System32\Drivers\Fastfat.SYS
0xB6958000 \SystemRoot\system32\drivers\wdmaud.sys
0xB6DC1000 \SystemRoot\system32\drivers\sysaudio.sys
0xB67E5000 \SystemRoot\System32\DRIVERS\mrxdav.sys
0xF7AEF000 \SystemRoot\System32\Drivers\ParVdm.SYS
0xB679E000 \SystemRoot\System32\DRIVERS\HSF_FALL.sys
0xB6781000 \SystemRoot\System32\DRIVERS\HSF_FSKS.sys
0xB6678000 \SystemRoot\System32\Drivers\HTTP.sys
0xB65F0000 \SystemRoot\System32\DRIVERS\HSF_K56K.sys
0xB6CBD000 \SystemRoot\System32\DRIVERS\mdmxsdk.sys
0xB6E79000 \??\C:\WINDOWS\System32\drivers\PfModNT.sys
0xB6571000 \SystemRoot\System32\DRIVERS\srv.sys
0xB6540000 \SystemRoot\System32\DRIVERS\HSF_FAXX.sys
0xB652E000 \SystemRoot\System32\DRIVERS\HSF_SPKP.sys
0xB66F9000 \SystemRoot\System32\DRIVERS\HSF_TONE.sys
0xB6376000 \SystemRoot\System32\DRIVERS\HSF_V124.sys
0xF794F000 \SystemRoot\System32\Drivers\SYMREDRV.SYS
0xB56BF000 \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20100820.018\NAVEX15.SYS
0xB56AB000 \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20100820.018\NAVENG.SYS
0xB6326000 \SystemRoot\System32\DRIVERS\asyncmac.sys
0xB5680000 \SystemRoot\system32\drivers\kmixer.sys
0x7C900000 \WINDOWS\system32\ntdll.dll

Processes (total 45):
0 System Idle Process
4 System
600 C:\WINDOWS\system32\smss.exe
664 csrss.exe
696 C:\WINDOWS\system32\winlogon.exe
744 C:\WINDOWS\system32\services.exe
756 C:\WINDOWS\system32\lsass.exe
900 C:\WINDOWS\system32\ati2evxx.exe
932 C:\WINDOWS\system32\svchost.exe
1028 svchost.exe
1164 C:\WINDOWS\system32\svchost.exe
1224 C:\WINDOWS\system32\ati2evxx.exe
1404 C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
1544 svchost.exe
1680 svchost.exe
1724 C:\WINDOWS\explorer.exe
1792 C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
2012 C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
472 C:\WINDOWS\system32\spoolsv.exe
2044 svchost.exe
164 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
260 C:\Program Files\Bonjour\mDNSResponder.exe
1284 C:\Program Files\Java\jre6\bin\jqs.exe
1856 C:\WINDOWS\system32\svchost.exe
620 C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
1248 C:\Program Files\Canon\CAL\CALMAIN.exe
2228 alg.exe
2320 unsecapp.exe
2632 wmiprvse.exe
2768 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
2968 C:\Program Files\Common Files\Java\Java Update\jusched.exe
3072 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
3100 C:\Program Files\iTunes\iTunesHelper.exe
3164 C:\Program Files\AirPort\APAgent.exe
3192 C:\Program Files\Messenger\msmsgs.exe
3304 C:\WINDOWS\system32\ctfmon.exe
3332 C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
3384 C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
1156 C:\Program Files\iPod\bin\iPodService.exe
3832 C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
2436 C:\Program Files\Common Files\Java\Java Update\jucheck.exe
628 C:\Program Files\Internet Explorer\iexplore.exe
2180 C:\Program Files\Internet Explorer\iexplore.exe
3272 C:\Program Files\Internet Explorer\iexplore.exe
3524 C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\27WVMVID\MBRCheck[1].exe

\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: –> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (NTFS)

PhysicalDrive0 Model Number: WDCWD1200JB-75CRA0, Rev: 16.06V16
PhysicalDrive1 Model Number: IBM-DPTA-372050, Rev: P76GA30A

Size Device Name MBR Status
——————————————–
111 GB \\.\PhysicalDrive0 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
19 GB \\.\PhysicalDrive1 Unknown MBR code
SHA1: C840069D981CC9E20044B3F065A1EFDB39395611


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:

Done!


Here is the OTL file from OTL:

OTL logfile created on: 8/20/2010 9:59:59 PM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\user\My Documents\Madeline
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 504.00 Mb Available Physical Memory | 49.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.75 Gb Total Space | 41.08 Gb Free Space | 36.76% Space Free | Partition Type: NTFS
Drive D: | 19.11 Gb Total Space | 7.66 Gb Free Space | 40.06% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: USER-XMPDEXCAQK
Current User Name: user
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\user\My Documents\Madeline\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe (SlySoft, Inc.)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\AirPort\APAgent.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\user\My Documents\Madeline\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\SlySoft\AnyDVD\ADvdDiscHlp.dll (SlySoft, Inc.)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (SmcService) – C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
SRV - (SNAC) – C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE (Symantec Corporation)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Driver Services (SafeList) ==========

DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100820.018\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100820.018\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (AnyDVD) – C:\WINDOWS\system32\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (ElbyCDIO) – C:\WINDOWS\system32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (SRTSPL) – C:\WINDOWS\system32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\system32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\WINDOWS\system32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (COH_Mon) – C:\WINDOWS\system32\drivers\COH_Mon.sys (Symantec Corporation)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctdvda2k) – C:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (hap16v2k) – C:\WINDOWS\system32\drivers\haP16v2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\pfmodnt.sys (Creative Technology Ltd.)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (omci) – C:\WINDOWS\system32\drivers\omci.sys (Dell Computer Corporation)
DRV - (MODEMCSA) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (V124) – C:\WINDOWS\system32\drivers\HSF_V124.sys (Conexant)
DRV - (Tones) – C:\WINDOWS\system32\drivers\HSF_TONE.sys (Conexant)
DRV - (hsf_msft) – C:\WINDOWS\system32\drivers\HSF_MSFT.sys (Conexant)
DRV - (SpeakerPhone) – C:\WINDOWS\system32\drivers\HSF_SPKP.sys (Conexant)
DRV - (Rksample) – C:\WINDOWS\system32\drivers\HSF_SAMP.sys (Conexant)
DRV - (K56) – C:\WINDOWS\system32\drivers\HSF_K56K.sys (Conexant)
DRV - (Fallback) – C:\WINDOWS\system32\drivers\HSF_FALL.sys (Conexant)
DRV - (SoftFax) – C:\WINDOWS\system32\drivers\HSF_FAXX.sys (Conexant)
DRV - (Fsks) – C:\WINDOWS\system32\drivers\HSF_FSKS.sys (Conexant)
DRV - (basic2) – C:\WINDOWS\system32\drivers\HSF_BSC2.sys (Conexant)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\..\URLSearchHook: {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Program Files\Family Toolbar\tbhelper.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


[2010/02/13 14:34:17 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Mozilla\Extensions
[2010/02/13 14:34:17 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\Mozilla\Extensions\[removed]

O1 HOSTS File: ([2001/08/18 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (MHTBPos00 Class) - {0C37B053-FD68-456a-82E1-D788EE342E6F} - C:\Program Files\Family Toolbar\tbcore3.dll ()
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (CMySite Class) - {D62EC836-BF1E-4CAC-81BE-FB9179835D8E} - C:\Program Files\Family Toolbar\mhxpcomi.dll ()
O3 - HKLM\..\Toolbar: (Family Toolbar) - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Program Files\Family Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Family Toolbar) - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Program Files\Family Toolbar\tbcore3.dll ()
O4 - HKLM..\Run: [AirPort Base Station Agent] C:\Program Files\AirPort\APAgent.exe (Apple Inc.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKCU..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe (SlySoft, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\user\Start Menu\Programs\Startup\LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe (Lime Wire, LLC)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1265050135935 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.1.1
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtb {669A2A3A-F19C-452D-800D-1240299756C1} - C:\Program Files\Family Toolbar\mhxpcomi.dll ()
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/02/01 11:48:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2002/08/22 07:09:54 | 000,000,222 | —- | M] () - D:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{214cfe4a-1139-11df-9d60-0007e9d52671}\Shell\AutoRun\command - "" = G:\wd_windows_tools\setup.exe – File not found
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll ()
Drivers32: vidc.iyuv - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yuy2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvu9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56590081070202880)

========== Files/Folders - Created Within 30 Days ==========

[2010/08/19 23:10:40 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2010/08/18 20:48:13 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/08/18 07:22:14 | 000,064,288 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2010/08/18 07:22:09 | 000,095,024 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/08/18 07:08:29 | 000,000,000 | —D | C] – C:\Documents and Settings\user\Local Settings\Application Data\Sunbelt Software
[2010/08/18 07:05:17 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}
[2010/08/18 07:04:19 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2010/08/18 07:04:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2010/08/17 21:55:24 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/08/17 21:55:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/08/17 20:38:30 | 007,516,167 | —- | C] (McAfee Inc.) – C:\Documents and Settings\user\Desktop\stinger1010995.exe
[2010/08/15 16:29:16 | 000,000,000 | —D | C] – C:\Program Files\AirPort
[2010/07/29 20:56:08 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/02/01 13:41:09 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/08/20 21:18:01 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/08/20 21:09:00 | 000,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-299502267-484061587-839522115-1004UA.job
[2010/08/20 18:50:54 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/08/20 18:49:26 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/08/20 18:49:23 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/20 18:49:09 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/20 06:33:47 | 000,029,544 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/08/20 06:33:47 | 000,029,544 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/08/20 06:33:47 | 000,026,424 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/08/20 06:33:47 | 000,026,424 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/08/20 06:33:47 | 000,000,384 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2010/08/20 06:33:47 | 000,000,384 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2010/08/20 06:33:29 | 003,145,728 | -H– | M] () – C:\Documents and Settings\user\NTUSER.DAT
[2010/08/20 06:33:29 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\user\ntuser.ini
[2010/08/20 06:33:20 | 006,427,628 | -H– | M] () – C:\Documents and Settings\user\Local Settings\Application Data\IconCache.db
[2010/08/19 22:26:00 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/18 22:13:14 | 000,001,982 | —- | M] () – C:\Documents and Settings\user\Desktop\HiJackThis.lnk
[2010/08/18 10:09:00 | 000,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-299502267-484061587-839522115-1004Core.job
[2010/08/18 07:22:09 | 000,095,024 | —- | M] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/08/18 07:05:15 | 000,000,885 | —- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/08/18 07:05:15 | 000,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/08/17 20:38:42 | 007,516,167 | —- | M] (McAfee Inc.) – C:\Documents and Settings\user\Desktop\stinger1010995.exe
[2010/08/12 08:15:20 | 000,064,288 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2010/08/12 08:15:20 | 000,015,880 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2010/08/11 19:52:54 | 000,264,616 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/10 22:03:10 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/10 19:45:45 | 000,002,277 | —- | M] () – C:\Documents and Settings\user\Desktop\Google Chrome.lnk
[2010/08/10 19:45:45 | 000,002,255 | —- | M] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/07/29 20:57:17 | 000,001,804 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/07/27 02:30:35 | 008,462,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/18 20:48:14 | 000,001,982 | —- | C] () – C:\Documents and Settings\user\Desktop\HiJackThis.lnk
[2010/08/18 08:22:44 | 000,015,880 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2010/08/18 07:23:47 | 000,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/08/18 07:05:15 | 000,000,885 | —- | C] () – C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/08/18 07:05:15 | 000,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/07/29 20:57:17 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/03/17 21:15:53 | 000,000,040 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2010/02/10 18:31:12 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\CNMVS5p.DLL
[2010/02/05 22:06:24 | 000,006,656 | —- | C] () – C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2001/08/18 08:00:00 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2001/08/18 08:00:00 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2001/08/18 08:00:00 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2001/08/18 08:00:00 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2001/08/18 08:00:00 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll

========== LOP Check ==========

[2010/03/17 21:15:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SlySoft
[2010/06/28 20:55:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/02/02 20:33:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/08/18 07:05:24 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}
[2010/08/20 18:50:18 | 000,000,000 | —D | M] – C:\Documents and Settings\user\Application Data\LimeWire
[2010/08/20 18:50:54 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/08/20 18:48:52 | 000,001,116 | —- | M] () – C:\aaw7boot.log
[2010/02/01 11:48:29 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/02/01 15:17:29 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/02/01 11:48:29 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/02/01 11:48:29 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/02/01 11:48:29 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/02/01 15:14:23 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/02/21 14:33:17 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/08/20 18:48:58 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\system32\*.wt >

< %systemroot%\system32\*.ruy >

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010/02/01 11:48:11 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2004/02/03 15:00:00 | 000,017,920 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD5p.DLL
[2004/02/03 15:00:00 | 000,050,176 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP5p.DLL
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/03/08 05:31:44 | 000,348,160 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtmsft.dll
[2009/03/08 05:31:38 | 000,216,064 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtrans.dll
[2009/10/26 16:41:46 | 000,087,368 | —- | M] (Symantec Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\FwsVpn.dll
[2009/10/26 16:41:46 | 000,107,848 | —- | M] (Symantec Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\SymVPN.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2010/02/01 06:35:48 | 000,090,112 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/02/01 06:35:48 | 000,606,208 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/02/01 06:35:48 | 000,393,216 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\user32.dll /md5 >
[2008/04/13 20:12:08 | 000,578,560 | —- | M] (Microsoft Corporation) MD5=B26B135FF1B9F60C9388B4A7D16F600B – C:\WINDOWS\system32\user32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2_32.dll /md5 >
[2008/04/13 20:12:10 | 000,082,432 | —- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A – C:\WINDOWS\system32\ws2_32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2help.dll /md5 >
[2008/04/13 20:12:10 | 000,019,968 | —- | M] (Microsoft Corporation) MD5=9789E95E1D88EEB4B922BF3EA7779C28 – C:\WINDOWS\system32\ws2help.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-11 02:03:17

< >
< End of report >


Here is the Extras file from OTL:

OTL Extras logfile created on: 8/20/2010 9:59:59 PM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\user\My Documents\Madeline
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 504.00 Mb Available Physical Memory | 49.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.75 Gb Total Space | 41.08 Gb Free Space | 36.76% Space Free | Partition Type: NTFS
Drive D: | 19.11 Gb Total Space | 7.66 Gb Free Space | 40.06% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: USER-XMPDEXCAQK
Current User Name: user
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"5353:UDP" = 5353:UDP:*:Enabled:Bonjour

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe" = C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe:*:Enabled:SMC Service – (Symantec Corporation)
"C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE" = C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE:*:Enabled:SNAC Service – (Symantec Corporation)
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe" = C:\Program Files\Common Files\Symantec Shared\ccApp.exe:*:Enabled:Symantec Email – (Symantec Corporation)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – (Lime Wire, LLC)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\AirPort\APAgent.exe" = C:\Program Files\AirPort\APAgent.exe:*:Enabled:AirPort – (Apple Inc.)
"C:\Program Files\AirPort\APUtil.exe" = C:\Program Files\AirPort\APUtil.exe:*:Enabled:AirPort Utility – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 20
"{2EFCC193-D915-4CCB-9201-31773A27BC06}" = Symantec Endpoint Protection
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3D9892BB-A751-4E48-ADC8-E4289956CE1D}" = QuickTime
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{74487955-B85B-4040-A3B6-9EAC0A8AD198}" = AirPort
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91F7F3F3-CE80-48C3-8327-7D24A0A5716A}" = iTunes
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.3
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F7B0939E-58DF-11DF-B3A6-005056806466}" = Google Earth
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AnyDVD" = AnyDVD
"ATI Display Driver" = ATI Display Driver
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Camera Window DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Camera Window DC_DV 6 for ZoomBrowser EX
"CameraWindowMC" = Canon Camera Window MC 6 for ZoomBrowser EX
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"CANONBJ_Deinstall_CNMCP5p.DLL" = Canon i9900
"CSCLIB" = Canon Camera Support Core Library
"DVD-CLONER VII_is1" = DVD-CLONER V7.20 Build 993
"ENTERPRISER" = Microsoft Office Enterprise 2007
"EOS Utility" = Canon Utilities EOS Utility
"Family Toolbar" = Family Toolbar
"HijackThis" = HijackThis 2.0.2
"ie8" = Windows Internet Explorer 8
"LimeWire" = LimeWire 5.4.6
"LiveUpdate" = LiveUpdate 3.3 (Symantec Corporation)
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"PhotoStitch" = Canon Utilities PhotoStitch
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RemoteCaptureTask" = Canon RemoteCapture Task for ZoomBrowser EX
"Windows XP Service Pack" = Windows XP Service Pack 3
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/1/2010 4:51:48 PM | Computer Name = USER-XMPDEXCAQK | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

Error - 5/1/2010 5:04:26 PM | Computer Name = USER-XMPDEXCAQK | Source = Google Update | ID = 20
Description =

Error - 5/1/2010 5:13:26 PM | Computer Name = USER-XMPDEXCAQK | Source = Google Update | ID = 20
Description =

Error - 5/1/2010 5:51:59 PM | Computer Name = USER-XMPDEXCAQK | Source = SescLU | ID = 13
Description = LiveUpdate returned a non-critical error. Available content updates
may have failed to install.

Error - 5/1/2010 6:04:25 PM | Computer Name = USER-XMPDEXCAQK | Source = Google Update | ID = 20
Description =

Error - 5/1/2010 6:13:25 PM | Computer Name = USER-XMPDEXCAQK | Source = Google Update | ID = 20
Description =

Error - 5/1/2010 7:04:26 PM | Computer Name = USER-XMPDEXCAQK | Source = Google Update | ID = 20
Description =

Error - 5/1/2010 7:13:25 PM | Computer Name = USER-XMPDEXCAQK | Source = Google Update | ID = 20
Description =

Error - 6/20/2010 2:28:06 AM | Computer Name = USER-XMPDEXCAQK | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18928, fault address 0x0003cb5e.

Error - 6/27/2010 1:16:43 AM | Computer Name = USER-XMPDEXCAQK | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module mshtml.dll, version 8.0.6001.18928, fault address 0x001287e0.

[ System Events ]
Error - 8/18/2010 8:22:19 AM | Computer Name = USER-XMPDEXCAQK | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk1\D, has a bad block.

Error - 8/18/2010 8:22:22 AM | Computer Name = USER-XMPDEXCAQK | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk1\D, has a bad block.

Error - 8/19/2010 11:12:39 PM | Computer Name = USER-XMPDEXCAQK | Source = System Error | ID = 1003
Description = Error code 100000d1, parameter1 00000000, parameter2 0000001c, parameter3
00000001, parameter4 8550800c.

Error - 8/19/2010 11:22:24 PM | Computer Name = USER-XMPDEXCAQK | Source = System Error | ID = 1003
Description = Error code 1000007f, parameter1 0000000d, parameter2 00000000, parameter3
00000000, parameter4 00000000.

Error - 8/20/2010 6:46:22 AM | Computer Name = USER-XMPDEXCAQK | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service LiveUpdate
with arguments "" in order to run the server: {03E0E6C2-363B-11D3-B536-00902771A435}

Error - 8/20/2010 6:46:24 AM | Computer Name = USER-XMPDEXCAQK | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the LiveUpdate service to
connect.

Error - 8/20/2010 6:46:25 AM | Computer Name = USER-XMPDEXCAQK | Source = Service Control Manager | ID = 7000
Description = The LiveUpdate service failed to start due to the following error:
%%1053

Error - 8/20/2010 7:48:54 AM | Computer Name = USER-XMPDEXCAQK | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service LiveUpdate
with arguments "" in order to run the server: {03E0E6C2-363B-11D3-B536-00902771A435}

Error - 8/20/2010 7:49:00 AM | Computer Name = USER-XMPDEXCAQK | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the LiveUpdate service to
connect.

Error - 8/20/2010 7:49:06 AM | Computer Name = USER-XMPDEXCAQK | Source = Service Control Manager | ID = 7000
Description = The LiveUpdate service failed to start due to the following error:
%%1053


< End of report >


This is all gibberish to me.. quite thankful for your help!
Hi madi1115,

LimeWire
You have LimeWire, a P2P/file sharing program installed on your computer. P2P applications like it are the largest source of malware we see. It's not the program itself but what can de downloaded with it, usually from an unknown sourece, that is the problem. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx

http://www.internetworldstats.com/articles…cles/art053.htm

I would recommend that you uninstall LimeWire, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.



Do you have 2 hard drives or is D:\ a partition on your C:\ drive?


Please try GMER in safe mode, with just the "sections" and "c:\" drive checked

To reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.

Please post the GMER log if it will run.

Thanks
Will reply more fully later however, i ran the scan last night while in Safe Mode and fell asleep because it was taking long. When I woke up this morning the scan looked like it had completed (was no longer scanning) but there was no log (main screen was open with nothing). I also didnt see (in my quick search before work) that it had automatically saved a log file anywhere. I will try to run it again later when i return home but wanted to post this in case this means anything. Regardless, i will post with replies to questions and success/failure of my 2nd try. Thank you!
Hi again, I reran the scan and all it said when it finished was "GMER hasn't found any system modifications" - there was no log. The one thing Im wondering about was that "Files" was checked above "C drive" and "ADS" was checked below it. When I unchecked "Files" the box with "C drive" in it seemed to go grey so wasn't sure if that was wrong. Did I run the scan the wrong way? I have not yet uninstalled Limewire but most definitely will do so on the wknd.. it's not worth the problems it's caused. D:\ is an external hard drive (99% sure - we definitely didnt partition a hard drive since I dont even know what that means!)
Hi madi1115,

A partition is when you divide harddrive into 2 or more part. Each part will have it's own drive letter.

We'll look a little deeper.

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Right click on ComboFix.exe, click Run as Administrator & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the combofix log.

Thanks
I will paste the Combo Fix log below.

Two caveats (not sure if these are important). The program asked to download a Microsoft Windows Recovery System Console, which I allowed it to do.

Also, in disabling all the Antivirus etc stuff, I had a problem with SpyBot such that I COULD NOT find the "Teatimer" box to uncheck (no matter how many times i looked, walked away and came back to get a fresh view, etc). So i disabled Spybot using the icon in the lower right hand corner of the computer screen, but did not follow all the advanced steps listed in the link you provided. IF this is a problem, I'd appreciate some guidance as to what I could be doing wrong and I can re-do the scan after properly disabling SpyBot. Either way, do i have re-enable all the programs i disabled or will they come back automatically after a restart?

Thanks again!

ComboFix 10-08-24.0A - user 08/25/2010 7:53.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.434 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
.

((((((((((((((((((((((((( Files Created from 2010-07-25 to 2010-08-25 )))))))))))))))))))))))))))))))
.

2010-08-22 21:17 . 2010-08-22 21:17 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2010-08-19 02:13 . 2010-08-19 02:13 388096 —-a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-08-19 00:48 . 2010-08-19 00:48 ——– d—–w- c:\program files\Trend Micro
2010-08-18 12:22 . 2010-08-12 12:15 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-08-18 11:22 . 2010-08-12 12:15 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-08-18 11:22 . 2010-08-18 11:22 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-08-18 11:08 . 2010-08-18 11:08 ——– d—–w- c:\documents and settings\user\Local Settings\Application Data\Sunbelt Software
2010-08-18 11:05 . 2010-08-18 11:05 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}
2010-08-18 11:05 . 2010-08-12 12:16 2979848 -c–a-w- c:\documents and settings\All Users\Application Data\{ECC164E0-3133-4C70-A831-F08DB2940F70}\Ad-AwareInstall.exe
2010-08-18 11:04 . 2010-08-18 11:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-08-18 11:04 . 2010-08-18 11:04 ——– d—–w- c:\program files\Lavasoft
2010-08-18 01:55 . 2010-08-18 11:08 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-08-18 01:55 . 2010-08-18 02:01 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-08-15 20:29 . 2010-08-15 20:29 ——– d—–w- c:\program files\AirPort
2010-08-12 00:04 . 2010-08-12 00:04 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2010-08-08 14:54 . 2010-08-08 14:54 503808 —-a-w- c:\documents and settings\user\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-7729b842-n\msvcp71.dll
2010-08-08 14:54 . 2010-08-08 14:54 499712 —-a-w- c:\documents and settings\user\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-7729b842-n\jmc.dll
2010-08-08 14:54 . 2010-08-08 14:54 61440 —-a-w- c:\documents and settings\user\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-12289e07-n\decora-sse.dll
2010-08-08 14:54 . 2010-08-08 14:54 348160 —-a-w- c:\documents and settings\user\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-7729b842-n\msvcr71.dll
2010-08-08 14:54 . 2010-08-08 14:54 12800 —-a-w- c:\documents and settings\user\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-12289e07-n\decora-d3d.dll
2010-07-30 00:56 . 2010-07-30 00:56 ——– d—–w- c:\program files\iPod
2010-07-30 00:51 . 2010-07-30 00:51 73000 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-25 02:16 . 2010-02-13 18:33 ——– d—–w- c:\documents and settings\user\Application Data\LimeWire
2010-08-25 02:15 . 2010-02-01 17:45 384 —-a-w- c:\windows\system32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
2010-08-25 02:15 . 2010-02-01 17:45 384 —-a-w- c:\windows\system32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
2010-08-11 02:02 . 2010-02-15 04:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-07-30 00:57 . 2010-06-29 00:54 ——– d—–w- c:\program files\iTunes
2010-07-30 00:56 . 2010-02-03 00:30 ——– d—–w- c:\program files\Common Files\Apple
2010-06-30 12:31 . 2001-08-18 12:00 149504 —-a-w- c:\windows\system32\schannel.dll
2010-06-29 00:55 . 2010-06-29 00:54 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-06-29 00:47 . 2010-06-29 00:46 ——– d—–w- c:\program files\QuickTime
2010-06-29 00:36 . 2010-06-29 00:36 ——– d—–w- c:\program files\Bonjour
2010-06-24 12:22 . 2001-08-18 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2001-08-18 12:00 1851904 —-a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2001-08-18 12:00 354304 —-a-w- c:\windows\system32\drivers\srv.sys
2010-06-18 22:36 . 2010-06-18 22:36 503808 —-a-w- c:\documents and settings\user\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-7f6ffcda-n\msvcp71.dll
2010-06-18 22:36 . 2010-06-18 22:36 499712 —-a-w- c:\documents and settings\user\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-7f6ffcda-n\jmc.dll
2010-06-18 22:36 . 2010-06-18 22:36 348160 —-a-w- c:\documents and settings\user\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-7f6ffcda-n\msvcr71.dll
2010-06-18 22:36 . 2010-06-18 22:36 61440 —-a-w- c:\documents and settings\user\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-55cd5eee-n\decora-sse.dll
2010-06-18 22:36 . 2010-06-18 22:36 12800 —-a-w- c:\documents and settings\user\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-55cd5eee-n\decora-d3d.dll
2010-06-17 14:03 . 2001-08-18 12:00 80384 —-a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2010-02-01 15:46 744448 —-a-w- c:\windows\PCHEALTH\HELPCTR\Binaries\helpsvc.exe
2010-06-14 07:41 . 2001-08-18 12:00 1172480 —-a-w- c:\windows\system32\msxml3.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48}"= "c:\program files\Family Toolbar\tbhelper.dll" [2009-05-07 355840]

[HKEY_CLASSES_ROOT\clsid\{1c4ab6a5-595f-4e86-b15f-f93cce2bbd48}]
[HKEY_CLASSES_ROOT\URLSearchHook.MHURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{1EA6B471-CAD2-419a-9539-0586EEFE2D09}]
[HKEY_CLASSES_ROOT\URLSearchHook.MHURLSearchHook]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0C37B053-FD68-456a-82E1-D788EE342E6F}]
2009-05-07 21:46 2642432 —-a-w- c:\program files\Family Toolbar\tbcore3.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D62EC836-BF1E-4CAC-81BE-FB9179835D8E}]
2010-02-18 07:37 221184 —-a-w- c:\program files\Family Toolbar\mhxpcomi.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]

[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]

[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-02-03 135664]
"AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe" [2010-03-09 3328960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-10-26 115560]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-19 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
"AirPort Base Station Agent"="c:\program files\AirPort\APAgent.exe" [2009-11-11 771360]

c:\documents and settings\user\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-12-16 503808]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe"=
"c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"=
"c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AirPort\\APAgent.exe"=
"c:\\Program Files\\AirPort\\APUtil.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:UDP"= 5353:UDP:Bonjour

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [8/18/2010 7:22 AM 64288]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [5/26/2010 4:00 AM 102448]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/7/2010 2:58 PM 135664]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [10/26/2009 4:41 PM 23888]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [8/12/2010 8:15 AM 1355416]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [8/12/2010 8:15 AM 15008]
.
Contents of the 'Scheduled Tasks' folder

2010-08-25 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-08-12 12:15]

2010-07-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-08-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-07 18:58]

2010-08-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-07 18:58]

2010-08-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299502267-484061587-839522115-1004Core.job
- c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-03 00:49]

2010-08-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299502267-484061587-839522115-1004UA.job
- c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-03 00:49]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Handler: mhtb - {669A2A3A-F19C-452D-800D-1240299756C1} - c:\program files\Family Toolbar\mhxpcomi.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-Symantec Antvirus



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-25 08:02
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(692)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(2064)
c:\windows\system32\WININET.dll
c:\program files\SlySoft\AnyDVD\ADvdDiscHlp.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2010-08-25 08:04:58
ComboFix-quarantined-files.txt 2010-08-25 12:04

Pre-Run: 40,861,515,776 bytes free
Post-Run: 41,319,370,752 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

- - End Of File - - 580B3C1C47D8F19A3B11C8CFEF839EA0
Hi madi1115, The programs you disabled should restart when your computer was rebooted. All the scans that we have done so far have come back clean. Before we continue in this directions let's try a slightly different angle. Correct me if I am wrong. You use AOL mail and must go online and log on to access your mail, correct? Once you log in you notice the sent email right away or after you have been logged in for a time? If you forget your password, do you have an alternate email address that you use to reset your password? I don't use AOL mail but when you want to change your password is there any security checks you need to pass/perform before be allowed to do so? Please answer these questions as best as you can without revealing any personal info.
Clean computer sounds good and makes some some sense bc my boyfriend uses same computer and his AOL has not been infected/usurped. However, when Ive searched about others having the same problem everyone seems to be fine after changeing password but that didnt work for me so I dont know why my problem seems more difficult than others. You are correct about usage - i go to www.aol.com and log in to check mail. With respect to the sent emails, I didnt even realize it was sending them for awhile until someone told me. Then, I checked in my Sent mailbox and sure enough there are a bunch of these sent emails. Once in awhile i notice that one of them is bounced back to me and shows up in my inbox (maybe 1 per day) but otherwise Id have no clue about these emails being sent. Theyre randomly sent in response to emails i get so theyre sent out even when im not logged in. Also weird is that my Spam folder has been empty since the problem started (very atypical) To change password, all i have to do is click on "Forgot password" then it prompts me to answer an Account Security Code, then Im able to pick a new password. Ive changed both password and Seccuity Question twice - before and after scanning my computer and finding no problems. At some point should I go back to AOL? Although they were not very useful…
Hi madi1115,

Thanks for the info. Since the mail is being sent even when you are not logged in would suggest someone or something has access to your account.

If you can do without your mail or check it from a known clean computer we may be able to narrow it down to either your computer or a compromised account.

From a clean computer
  • log into your account and clean out everything you don't want including the Sent Items.
  • Reset both the Security Code and password.
  • If Aol or Internet Explorer or whichever browser you are using ask if you want to save the password, say No.
  • Log out of Aol.
Empty the Internet Temporary file (this is for IE) by clicking Tools >Internet Options.
  • Under Browsing History click delete
  • On the screen that appears click Delete files beside Temporary Internet files
  • Wait for it to finish then close the browser completely.

Open a new browser and log into AOL. Again if asked to save the password say No. Any new sent emails? Try this over a period of a few hours allowing enough time for your contacts to have sent you some mail. Log completely out of AOL each time. Do not log in from your computer yet.

We'll do a little cleanup on your computer.

Click your start button > Control Panel > Internet Options

  • Under Browsing History click delete
  • On the screen that appears click Delete All at the bottom.
  • Wait for it to finish.
Note: All items all the section on that screen will be delete. This includes any passwords that you have stored (for automatic login) and any saved web forms. The sites that you had set for automatic log in will require you to log in.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Files

:Commands
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the log produced.

Let us know how you made out or if you had any problems.

Thanks
Hi oldman960, With respect to the clean computer, I did as told (although deleting months of old mail, deleted mail and sent mail sent me into a panic - always comes in handy to have those old emails so Im hoping i wont need them!) Pretty quickly I again had a plethora of sent mail that I did not send. I'd say they're sent at a rate of 2-4 per hour. Most of them are automatic responses to bulk emails I get (e.g., macys.com or listservs to which i belong) and it says "automatic response" in the subject line of the sent email. Less frequently something gets sent to a friend in reply to a personal email I got. Regardless, it's always a reply to email I receive, never just email that's sent to randomly selected email contacts. With respect to the scan on my computer, the log is below. Is it weird to hope you find something wrong!??!? Regardless, happy wknd.. feel free to ignore me for awhile and enjoy :) All processes killed ========== FILES ========== ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: user ->Temp folder emptied: 182887 bytes ->Temporary Internet Files folder emptied: 11200896 bytes ->Java cache emptied: 35414742 bytes ->Google Chrome cache emptied: 78047740 bytes ->Flash cache emptied: 137835 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 1145664 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 49093 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 120.00 mb OTL by OldTimer - Version 3.2.10.0 log created on 08272010_184720 Files\Folders moved on Reboot… Registry entries deleted on Reboot…

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI