This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan_Zlob and other infection leftovers

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Friends brought me a computer to clean up that been and infected about a month ago. Their son had done malware removal, but it was still running extremely slowly. Malwarebytes removed Trojan_Zlob and some other malware- slight improvement. I upgraded memory from 512mb to 2gb. That helped, but McAfee was still running very slowly. I ran checkdisk and repaired a few bad clusters- improving system performance. The machine only has Windows SP2 with SP3 ready to install. I would like to make sure that malware is removed so I can get a stable installation.

I am including my Malwarebytes and Hijackthis scans. Thank you for looking over my reports. - Jcatsmom :wavey:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4495

Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.11

8/28/2010 1:06:02 PM
mbam-log-2010-08-28 (13-06-02).txt

Scan type: Quick scan
Objects scanned: 152310
Time elapsed: 17 minute(s), 34 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 3
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\Program Files\Video ActiveX Object (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Video Add-on (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\VirusProtect 3.9 (Rogue.VirusProtect) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\Temp\TMP0000000C0EB4982FAA4F3843 (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Program Files\VirusProtect 3.9\vpp.ini (Rogue.VirusProtect) -> Quarantined and deleted successfully.




Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:13:05 PM, on 8/30/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.att.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/mywaybiz
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - (no file)
O2 - BHO: (no name) - {69B98C68-D2B8-4A4E-9CB7-E85B6F3A7014} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - (no file)
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…90/mcinsctl.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1151174868143
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by106fd.bay106.hotmail.msn.com/activex/HMAtchmt.ocx
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: eupeptic - {8670ee50-01f9-47da-ac1e-cf8549e9e521} - (no file)
O22 - SharedTaskScheduler: (no name) - {c0ca766d-060c-48e1-b536-205e321bd174} - (no file)
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 7866 bytes
Hello Jcatsmom and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem. Please read the following guidelines which will help to make cleaning your machine easier:
• Please do not install/uninstall any programs unless asked to.
• Please do not run any scans other than those requested
• Please follow all instructions in the order posted
• Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
• If you don't understand something, please don't hesitate to ask for clarification before proceeding
• The fixes are specific to your problem and should only be used for this issue on this machine.
• Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
Please note that I am still in training and my replies need to be checked by an expert in order for you to receive the best possible advice. This may result in a small delay between my posts but I shall try to keep this to a minimum.


I am looking through your log now and will reply as soon as possible.

Satchfan
Hello again Jcatsmom

I see that Malwarebytes got rid of some infections but there are still signs of infection in your log so I’d like you to run some more up-to-date programs to see what else may be there.


Run OTL

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in:

    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.


Download the GMER Rootkit Scanner

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • All drives/partitions except C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Logs to include with next post:

OTL.txt
Extras.txt
Gmer.txt


Thanks

Satchfan
Satchfan, thank you for responding to my request so quickly. I appreciate your help. This computer didn't get along well with Gmer. After hours of scanning the first time, I got a BSOD with an application error "failed to initialize properly 0x0000145". Ran it a second time successfully. Some time later got another BSOD "unkown hard error". I had not experienced any BSOD's previously. Thank you for your help. It's needed!

Here are my logs:

OTL logfile created on: 8/31/2010 12:43:43 PM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\Dee\Desktop\compuiter tools
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 75.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 800 2000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.28 Gb Total Space | 59.10 Gb Free Space | 82.91% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RECTORY
Current User Name: Dee
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Dee\Desktop\compuiter tools\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
PRC - c:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MPF\MpfSrv.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\MSC\McUICnt.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MSM\McSmtFwk.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe ()
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\SYSTEM32\HPZipm12.exe (HP)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Dee\Desktop\compuiter tools\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\McAfee\SiteAdvisor\sahook.dll ()
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\SYSTEM32\MSSCRIPT.OCX (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (mcmscsvc) – C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV - (McSysmon) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (MpfService) – C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (McProxy) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McNASvc) – c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\McAfee\SiteAdvisor\McSACore.exe ()
SRV - (Pml Driver HPZ12) – C:\WINDOWS\SYSTEM32\HPZipm12.exe (HP)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys File not found
DRV - (SAUSBHW) – C:\WINDOWS\System32\Drivers\sausb.sys File not found
DRV - (RPSKT) Security Services Driver (x86) – C:\WINDOWS\System32\DRIVERS\rp_skt32.sys File not found
DRV - (cpuz132) – C:\DOCUME~1\Dee\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (MPFP) – C:\WINDOWS\SYSTEM32\DRIVERS\Mpfp.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\SYSTEM32\DRIVERS\mferkdk.sys (McAfee, Inc.)
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (senfilt) – C:\WINDOWS\SYSTEM32\DRIVERS\senfilt.sys (Creative Technology Ltd.)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (nv) – C:\WINDOWS\SYSTEM32\DRIVERS\NV4_MINI.SYS (NVIDIA Corporation)
DRV - (WUSB54GV4SRV) – C:\WINDOWS\SYSTEM32\DRIVERS\rt2500usb.sys (Ralink Technology Inc.)
DRV - (GTNDIS5) – C:\WINDOWS\SYSTEM32\GTNDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (hp4200c) – C:\WINDOWS\SYSTEM32\DRIVERS\hp4200c.sys (Hewlett-Packard)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/login_verify…src=ym&rl;=1
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://my.att.net/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:2.8


FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/08/23 12:24:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/08/23 14:39:19 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/12 22:12:31 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/12 22:12:31 | 000,000,000 | —D | M]

[2008/12/02 20:50:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\Mozilla\Extensions
[2010/08/05 11:29:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\Mozilla\Firefox\Profiles\psq040np.default\extensions
[2008/12/06 21:11:39 | 000,000,000 | —D | M] (iGoogle Sidebar) – C:\Documents and Settings\Dee\Application Data\Mozilla\Firefox\Profiles\psq040np.default\extensions\{14d1580a-2611-11db-9628-00e08161165f}
[2010/07/17 11:20:17 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Dee\Application Data\Mozilla\Firefox\Profiles\psq040np.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/05/22 09:00:57 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Dee\Application Data\Mozilla\Firefox\Profiles\psq040np.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/08/26 10:04:19 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2004/08/04 05:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - No CLSID value found.
O2 - BHO: (no name) - {69B98C68-D2B8-4A4E-9CB7-E85B6F3A7014} - No CLSID value found.
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O3 - HKLM\..\Toolbar: (no name) - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {5BED3930-2E9E-76D8-BACC-80DF2188D455} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McENUI] C:\Program Files\McAfee\MHN\McENUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Plugin Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…90/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase4009.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1151174868143 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} Reg Error: Key error. (Reg Error: Key error.)
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} http://by106fd.bay106.hotmail.msn.com/activex/HMAtchmt.ocx (Hotmail Attachments Control)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O22 - SharedTaskScheduler: {8670ee50-01f9-47da-ac1e-cf8549e9e521} - eupeptic - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {c0ca766d-060c-48e1-b536-205e321bd174} - - Reg Error: Key error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Dee\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Dee\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 13:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\WMI.DLL (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54619756233228288)

========== Files/Folders - Created Within 90 Days ==========

[2010/08/30 08:05:34 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/08/30 07:24:11 | 000,000,000 | —D | C] – C:\Program Files\HD Tune
[2010/08/29 23:12:27 | 000,000,000 | -HSD | C] – C:\found.001
[2010/08/29 21:21:23 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Dee\PrivacIE
[2010/08/28 22:02:43 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Dee\IECompatCache
[2010/08/28 21:54:57 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Dee\IETldCache
[2010/08/28 21:33:30 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2010/08/28 13:06:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Dee\Desktop\compuiter tools
[2010/08/28 12:41:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Dee\Application Data\Malwarebytes
[2010/08/28 12:41:29 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/08/28 12:41:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/08/28 12:41:26 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/08/28 12:41:26 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/08/28 12:38:02 | 006,153,376 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Dee\Desktop\mbam-setup-1.46.exe
[2010/08/03 13:26:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Dee\Application Data\Sammsoft
[2010/07/25 14:58:34 | 000,000,000 | —D | C] – C:\Program Files\Advanced Registry Optimizer
[2010/07/24 10:08:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Dee\My Documents\Audible
[2008/07/24 14:20:40 | 010,420,936 | —- | C] (Microsoft Corporation) – C:\Program Files\xlviewer.exe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/08/31 12:30:05 | 000,010,491 | —- | M] () – C:\WINDOWS\System32\Config.MPF
[2010/08/31 12:13:29 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/08/31 12:10:20 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/31 12:10:17 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/08/30 23:36:28 | 004,194,304 | —- | M] () – C:\Documents and Settings\Dee\ntuser.dat
[2010/08/30 23:36:21 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Dee\NTUSER.INI
[2010/08/30 07:24:12 | 000,000,613 | —- | M] () – C:\Documents and Settings\Dee\Desktop\HD Tune.lnk
[2010/08/28 21:54:56 | 000,000,815 | —- | M] () – C:\Documents and Settings\Dee\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/08/28 12:41:32 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/08/28 12:38:13 | 006,153,376 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Dee\Desktop\mbam-setup-1.46.exe
[2010/08/28 08:04:57 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/08/23 19:18:06 | 000,008,359 | —- | M] () – C:\Documents and Settings\Dee\My Documents\Dee Eichler CV.wpd
[2010/08/05 19:12:44 | 000,000,151 | —- | M] () – C:\WINDOWS\Ulead32.ini
[2010/08/05 09:48:15 | 000,000,256 | —- | M] () – C:\WINDOWS\SYSTEM.INI
[2010/07/29 15:34:53 | 000,011,040 | —- | M] () – C:\Documents and Settings\Dee\My Documents\Cover sheet fax.wpd
[2010/07/28 21:49:56 | 000,004,121 | —- | M] () – C:\Documents and Settings\Dee\My Documents\Dee bill.wpd
[2010/07/24 10:53:50 | 000,224,816 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/07/24 09:52:38 | 000,062,448 | —- | M] () – C:\Documents and Settings\Dee\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/07/20 17:41:22 | 000,016,746 | —- | M] () – C:\Documents and Settings\Dee\My Documents\Letterhead.wpd
[2010/07/20 17:40:04 | 000,016,746 | —- | M] () – C:\Documents and Settings\Dee\My Documents\Dee Eichler.wpd
[2010/07/20 16:36:13 | 000,003,714 | —- | M] () – C:\Documents and Settings\Dee\My Documents\Christmas letter.wpd
[2010/07/15 15:18:22 | 000,120,136 | —- | M] (McAfee, Inc.) – C:\WINDOWS\System32\drivers\Mpfp.sys
[2010/07/15 03:02:32 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/07/15 01:00:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\McDefragTask.job
[2010/06/24 08:13:43 | 000,503,304 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/24 08:13:43 | 000,442,466 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2010/06/24 08:13:43 | 000,071,732 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2010/06/16 22:23:26 | 000,017,233 | —- | M] () – C:\Documents and Settings\Dee\My Documents\seminary.wpd
[2010/06/16 19:08:40 | 000,020,518 | —- | M] () – C:\Documents and Settings\Dee\My Documents\Info release.wpd
[2010/06/14 10:54:12 | 000,005,619 | —- | M] () – C:\Documents and Settings\Dee\My Documents\December 3.wpd
[2010/06/14 10:54:04 | 000,002,325 | —- | M] () – C:\Documents and Settings\Dee\My Documents\JOB STRESS (Your own or others)COMES FROM.wpd
[2010/06/14 09:56:07 | 000,001,690 | —- | M] () – C:\Documents and Settings\Dee\My Documents\Document1.wpd
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/30 07:24:12 | 000,000,613 | —- | C] () – C:\Documents and Settings\Dee\Desktop\HD Tune.lnk
[2010/08/28 12:41:32 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/20 17:41:17 | 000,016,746 | —- | C] () – C:\Documents and Settings\Dee\My Documents\Letterhead.wpd
[2010/06/16 19:08:40 | 000,020,518 | —- | C] () – C:\Documents and Settings\Dee\My Documents\Info release.wpd
[2008/04/23 15:42:50 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2008/04/16 13:39:35 | 000,219,648 | —- | C] () – C:\Documents and Settings\Dee\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/01/09 04:01:57 | 000,000,197 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2006/04/24 16:06:59 | 000,000,397 | R— | C] () – C:\WINDOWS\hpw9800k.ini
[2006/04/24 16:04:33 | 000,000,478 | —- | C] () – C:\WINDOWS\hpdj9800.ini
[2006/04/24 16:04:21 | 000,001,567 | —- | C] () – C:\WINDOWS\mariner.ini
[2005/10/31 09:04:21 | 000,003,668 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2005/08/23 11:03:17 | 000,306,688 | —- | C] () – C:\WINDOWS\System32\Lffpx7.dll
[2005/08/23 11:03:17 | 000,095,232 | —- | C] () – C:\WINDOWS\System32\Lfkodak.dll
[2005/08/03 11:01:08 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\GTW32N50.dll
[2005/08/03 11:00:54 | 000,001,635 | —- | C] () – C:\WINDOWS\System32\WLAN.INI
[2005/05/10 11:20:38 | 000,093,696 | —- | C] () – C:\WINDOWS\System32\hpgt42.dll
[2005/04/30 12:35:38 | 000,000,071 | —- | C] () – C:\WINDOWS\pex.INI
[2005/04/27 17:17:19 | 000,000,151 | —- | C] () – C:\WINDOWS\Ulead32.ini
[2005/04/27 16:44:22 | 000,000,848 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2005/04/26 21:17:56 | 000,061,678 | —- | C] () – C:\Documents and Settings\Dee\Application Data\PFP120JPR.{PB
[2005/04/26 21:17:56 | 000,012,358 | —- | C] () – C:\Documents and Settings\Dee\Application Data\PFP120JCM.{PB
[2005/04/26 19:23:35 | 000,006,602 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2005/04/25 20:10:41 | 000,000,126 | —- | C] () – C:\Documents and Settings\Dee\Local Settings\Application Data\fusioncache.dat
[2005/04/23 20:00:53 | 000,000,190 | —- | C] () – C:\WINDOWS\QTW.INI
[2005/04/23 19:55:15 | 000,000,073 | —- | C] () – C:\WINDOWS\ldg.ini
[2005/04/23 19:54:34 | 000,000,776 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/04/23 19:54:34 | 000,000,282 | —- | C] () – C:\WINDOWS\pib.ini
[2005/04/20 14:45:41 | 000,000,070 | —- | C] () – C:\WINDOWS\D96E1E82.ini
[2005/04/20 11:13:15 | 000,006,048 | —- | C] () – C:\WINDOWS\System32\MCC16.dll
[2005/04/20 11:11:40 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\BJInstaller.dll
[2005/04/20 11:11:40 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\BJAXSecurityManager.dll
[2005/04/18 16:38:05 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005/04/14 00:07:49 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/04/14 00:05:58 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/04/13 23:31:02 | 000,000,370 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/08/10 13:13:12 | 000,000,882 | —- | C] () – C:\WINDOWS\ORUN32.INI
[2004/08/04 05:00:00 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\FXSPERF.INI
[1980/01/01 00:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll

========== LOP Check ==========

[2009/11/23 11:53:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AT&T;
[2007/10/27 11:25:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BellSouth
[2010/05/03 10:54:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Driver Whiz
[2007/12/13 16:34:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2005/04/27 17:20:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2008/02/03 17:08:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/04/22 08:51:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo
[2009/11/23 11:53:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\AT&T;
[2007/10/27 11:25:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\BellSouth
[2006/10/24 22:06:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\Leadertech
[2010/08/03 13:26:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\Sammsoft
[2010/07/24 10:42:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\Ulead Systems
[2009/03/20 11:21:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Dee\Application Data\Viewpoint
[2005/04/18 16:09:59 | 000,000,258 | —- | M] () – C:\WINDOWS\Tasks\ISP signup reminder 1.job
[2010/07/15 01:00:00 | 000,000,344 | —- | M] () – C:\WINDOWS\Tasks\McDefragTask.job
[2010/05/11 14:59:29 | 000,000,322 | —- | M] () – C:\WINDOWS\Tasks\McQcTask.job
[2010/08/31 12:13:29 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2006/11/20 19:01:01 | 019,856,430 | —- | M] () – C:\BellSouthIW.re~
[2008/12/16 19:59:12 | 000,000,211 | -HS- | M] () – C:\BOOT.INI
[2004/08/10 13:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2005/04/13 23:34:32 | 000,004,403 | RH– | M] () – C:\DELL.SDR
[2005/08/23 10:43:27 | 000,547,952 | —- | M] () – C:\HPScanjet4200C.exe
[2004/08/10 13:14:36 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/10 13:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2005/04/14 00:03:13 | 000,000,770 | -H– | M] () – C:\IPH.PH
[2004/08/10 13:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 05:00:00 | 000,250,032 | RHS- | M] () – C:\NTLDR
[2010/08/31 12:10:15 | 838,860,800 | -HS- | M] () – C:\pagefile.sys
[2005/08/23 11:02:28 | 036,422,256 | —- | M] () – C:\sj655en.exe
[2008/02/28 19:28:53 | 000,000,495 | —- | M] () – C:\stub.log
[2005/04/14 00:03:22 | 000,000,087 | —- | M] () – C:\SystemInfo.ini
[1 C:\*.tmp files -> C:\*.tmp -> ]

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/10 13:03:42 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\DESKTOP.INI

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\filterpipelineprintproc.dll
[2005/05/10 16:14:32 | 000,067,072 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\hpzpp3xt.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/07/24 14:21:10 | 010,420,936 | —- | M] (Microsoft Corporation) – C:\Program Files\xlviewer.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/10 12:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2004/08/10 12:56:46 | 000,634,880 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2004/08/10 12:56:46 | 000,872,448 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2004/08/10 13:04:12 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\DESKTOP.INI

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005/04/18 20:29:30 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Dee\Application Data\Microsoft\Internet Explorer\Quick Launch\DESKTOP.INI
[2004/08/10 13:08:38 | 000,000,079 | —- | M] () – C:\Documents and Settings\Dee\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/08/28 12:43:23 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Dee\Desktop\ATF-Cleaner.exe
[2010/08/28 12:38:13 | 006,153,376 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Dee\Desktop\mbam-setup-1.46.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto >

< Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:18B7103A
< End of report >

OTL Extras logfile created on: 8/31/2010 12:43:43 PM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Documents and Settings\Dee\Desktop\compuiter tools
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 75.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 800 2000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.28 Gb Total Space | 59.10 Gb Free Space | 82.91% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RECTORY
Current User Name: Dee
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – File not found
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – File not found
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL – File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – File not found
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – File not found
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL – File not found
"C:\Program Files\Support.com\bin\tgcmd.exe" = C:\Program Files\Support.com\bin\tgcmd.exe:*:Disabled:BellSouth Bulletin and Job processor – File not found
"C:\Program Files\HP1610\HP Software Update\HPWUCli.exe" = C:\Program Files\HP1610\HP Software Update\HPWUCli.exe:*:Enabled:HP Software Update Client – (Hewlett-Packard)
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – (Lime Wire, LLC)
"C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe" = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Jukebox – (Yahoo! Inc.)
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" = C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent – (McAfee, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{14BEB6DF-A499-4A38-8E06-E173BCD5C087}" = ScannerCopy
"{17334AAF-C9E7-483B-9F45-E3FCAF07FFA7}" = Intel® PROSet for Wired Connections
"{1AD5F465-8282-4DAD-B957-E09C0B783D18}" = InstantShare
"{1B680FBA-E317-4E93-AF43-3B59798A4BE0}" = Copy
"{1E04F83B-2AB9-4301-9EF7-E86307F79C72}" = Google Earth
"{20FBC0A0-3160-4F14-83ED-3A74BB6B8C31}" = TrayApp
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{272EC8BA-5A08-4ea1-A189-684466A06B02}" = cp_dwShrek2Albums1
"{2E8428AD-6CD2-4031-916A-3CF9BBF2DEC9}" = Unload
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{3762DB2D-71BD-421F-9E55-C74DA7DF4D07}" = CueTour
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{47813E93-F2A0-484A-838E-47EC1B28D190}" = Adobe Stock Photos 1.0
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5DFDEAAA-E050-482E-A5B6-138CAE53F7BF}" = Radialpoint Security Services
"{5E8D588F-307C-4250-B622-26969027319A}" = PanoStandAlone
"{644D04A2-C682-4FD5-977D-03B804C4B9C5}" = CreativeProjects
"{646A65DD-23FC-418E-B9F0-E0500FB42CB1}" = PhotoGallery
"{68963635-14A4-48D9-B431-DF3A74D1AAE1}" = Destinations
"{700A6597-3CE6-49C1-AA75-846B24CDA66D}" = BufferChm
"{724517BD-1DE1-4986-BFCA-C1DFD379E3BC}" = cp_dwShrek2Cards1
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{7AD25C9F-9957-4D1C-95EF-9BCD09F6D31B}" = HPSystemDiagnostics
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{84CDF5A8-1D57-4B69-BAB6-1F11D8923375}" = SkinsHP1
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8BC3B99B-A6BE-4A0B-8535-B1B94BA4B1B1}" = DocProc
"{90840409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Excel Viewer 2003
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5B9D22C-755A-4AC6-9904-875E80838BB6}" = CP_AtenaShokunin1Config
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{B911B811-BA3E-46D4-90F8-6F3338359651}" = Director
"{BD29EBAC-AD7D-4b27-B727-4CC6AC52D36B}" = MarketResearch
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDFCF124-115F-4976-8BF4-08C89187A146}" = WebReg
"{CE0C8CC5-E396-442B-A50E-D1D374A9E820}" = DocumentViewer
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D271DAE0-8D68-4C97-8356-A126D48A1D8C}" = Ulead Photo Explorer 8.0 SE Basic
"{EC3B8CA2-49B8-4D38-BE9C-ABD0F6029168}" = Yahoo! Music Jukebox
"{F24862FD-DDC7-490D-AC02-8797B575D6A9}" = SpaMsiWrapper
"{FC22D020-3005-4715-8DF9-F3EDE81DEB3D}" = CreativeProjectsTemplates
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced Registry Optimizer_is1" = Advanced Registry Optimizer
"BellsouthHelpCenter4.0b_is1" = FastAccess® DSL Help Center 4.3
"blstoolbar" = AT&T; Toolbar
"HD Tune_is1" = HD Tune 2.54
"HijackThis" = HijackThis 2.0.2
"HP Photo & Imaging" = HP Image Zone 4.7
"HPExtendedCapabilities" = HP Extended Capabilities 4.7
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Internet Explorer Security Plugin 2006" = Internet Explorer Security Plugin 2006
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"MSC" = McAfee SecurityCenter
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PROSet" = Intel® PRO Network Adapters and Drivers
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/29/2010 10:18:56 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 8/29/2010 10:18:56 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 8/29/2010 10:18:56 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 8/29/2010 10:18:56 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 8/29/2010 10:18:56 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 8/29/2010 10:18:56 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 8/29/2010 10:18:56 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 8/29/2010 10:18:56 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 8/29/2010 10:18:56 PM | Computer Name = RECTORY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdo…authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 8/30/2010 2:12:32 PM | Computer Name = RECTORY | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

[ System Events ]
Error - 8/29/2010 11:13:20 PM | Computer Name = RECTORY | Source = Service Control Manager | ID = 7031
Description = The McAfee Proxy Service service terminated unexpectedly. It has
done this 2 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 8/29/2010 11:13:24 PM | Computer Name = RECTORY | Source = Service Control Manager | ID = 7031
Description = The McAfee Real-time Scanner service terminated unexpectedly. It
has done this 2 time(s). The following corrective action will be taken in 60000
milliseconds: Restart the service.

Error - 8/29/2010 11:13:31 PM | Computer Name = RECTORY | Source = Service Control Manager | ID = 7031
Description = The McAfee SystemGuards service terminated unexpectedly. It has done
this 2 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 8/29/2010 11:13:35 PM | Computer Name = RECTORY | Source = Service Control Manager | ID = 7031
Description = The McAfee Services service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 8/29/2010 11:14:39 PM | Computer Name = RECTORY | Source = Service Control Manager | ID = 7032
Description = The Service Control Manager tried to take a corrective action (Restart
the service) after the unexpected termination of the McAfee Services service, but
this action failed with the following error: %%1056

Error - 8/30/2010 12:57:50 AM | Computer Name = RECTORY | Source = Service Control Manager | ID = 7000
Description = The Security Services Driver (x86) service failed to start due to
the following error: %%2

Error - 8/30/2010 8:13:15 AM | Computer Name = RECTORY | Source = Service Control Manager | ID = 7000
Description = The Security Services Driver (x86) service failed to start due to
the following error: %%2

Error - 8/30/2010 1:52:22 PM | Computer Name = RECTORY | Source = Service Control Manager | ID = 7000
Description = The Security Services Driver (x86) service failed to start due to
the following error: %%2

Error - 8/30/2010 11:01:41 PM | Computer Name = RECTORY | Source = Service Control Manager | ID = 7000
Description = The Security Services Driver (x86) service failed to start due to
the following error: %%2

Error - 8/31/2010 1:10:30 PM | Computer Name = RECTORY | Source = Service Control Manager | ID = 7000
Description = The Security Services Driver (x86) service failed to start due to
the following error: %%2


< End of report >

Attachments:

Hello Jcatsmom

P2P - I see your friend has P2P software, (Limewire), although it is not installed on the machine. We are not here to pass judgment on file-sharing as a concept. However, we ask you to warn them that engaging in this activity and having this kind of software installed on the machine will always make it more susceptible to re-infection. This likely contributed to the current situation.

This page will give them further information.

Please note: Even if using a "safe" P2P program, it is only the program that is safe. They will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please advise them to see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you advise them to remove it from the Program Files folder.


Check for Java update and remove old versions.

This computer’s version of Java is out of date. Older versions have vulnerabilities that malware can use to infect the system.

Please follow these steps to update Java components and remove older versions.
1. Click Start, Settings and then click Control Panel
2. Double-click on the Java
3. Click on the ‘Update’ tab and then on Update now.
4. Still in the Java Control Panel, click on the General tab
5..Under Temporary Internet Files, click the Settings button.
6. Click on the Delete Files button. There are two options in the window to clear the cache – Leave BOTH of the following checked:
Applications and Applets
Trace and Log Files
7 Click OK on Delete Temporary Files Window
8 Click OK to leave the Temporary Files Window
9 Click OK to leave the Java Control Panel.
Still in the Control Panel, double-click on Add or Remove programs. (it may take time to produce the list of programs, so please be patient). Now remove all earlier versions of Java.


Download ComboFix from the following location:

Link


* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    [external image: Posted Image]


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Satchfan
Satchfan,
We have removed Limewire, as you recommended. I have also cleared the Java cache and uninstalled the old version. I am including the combofix log. McAfee kept blocking it from downloading
"About this Trojan Detected: Artemis!8E56C318E59D (Trojan), Artemis!8E56C318E59D (Trojan)
Location: C:\Documents and Settings\Dee\Local Settings\Temporary Internet Files\Content.IE5\7KKTC2SA\ComboFix[1].exe"

ComboFix 10-09-01.02 - Dee 09/01/2010 19:40:43.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2046.1637 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AT&T Internet Security Suite AT&T Anti-Virus *On-access scanning disabled* (Updated) {5B5A3BD7-8573-4672-AEA8-C9BB713B6755}
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: AT&T Internet Security Suite AT&T Firewall *disabled* {80593BF4-D969-4EC5-ADAE-A22F2DFC7A22}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Helper
c:\windows\system32\BSTIEPrintCtl1.dll

.
((((((((((((((((((((((((( Files Created from 2010-08-02 to 2010-09-02 )))))))))))))))))))))))))))))))
.

2010-08-31 03:11 . 2010-08-31 03:11 388096 —-a-r- c:\documents and settings\Dee\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-08-30 13:05 . 2010-08-30 13:05 ——– d—–w- c:\program files\Trend Micro
2010-08-30 12:24 . 2010-08-30 12:24 ——– d—–w- c:\program files\HD Tune
2010-08-30 04:12 . 2010-08-30 04:12 ——– d—–w- C:\found.001
2010-08-30 02:22 . 2010-08-30 02:22 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-08-30 02:21 . 2010-08-30 02:21 ——– d-sh–w- c:\documents and settings\Dee\PrivacIE
2010-08-29 15:48 . 2010-08-29 15:48 ——– d-sh–w- c:\documents and settings\Guest\IECompatCache
2010-08-29 15:47 . 2010-08-29 15:47 ——– d-sh–w- c:\documents and settings\Guest\PrivacIE
2010-08-29 03:02 . 2010-08-29 03:02 ——– d-sh–w- c:\documents and settings\Dee\IECompatCache
2010-08-29 02:54 . 2010-08-29 02:54 ——– d-sh–w- c:\documents and settings\Dee\IETldCache
2010-08-29 02:48 . 2010-08-29 02:48 ——– d-sh–w- c:\documents and settings\Guest\IETldCache
2010-08-29 02:33 . 2010-08-29 02:35 ——– dc-h–w- c:\windows\ie8
2010-08-28 17:41 . 2010-08-28 17:41 ——– d—–w- c:\documents and settings\Dee\Application Data\Malwarebytes
2010-08-28 17:41 . 2010-04-29 20:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-28 17:41 . 2010-08-28 17:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-08-28 17:41 . 2010-08-28 17:41 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-08-28 17:41 . 2010-04-29 20:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-08-04 17:01 . 2010-08-04 17:01 ——– d—–w- c:\documents and settings\Guest\Application Data\Sammsoft
2010-08-03 18:26 . 2010-08-03 18:26 ——– d—–w- c:\documents and settings\Dee\Application Data\Sammsoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-01 23:58 . 2010-01-08 14:46 ——– d—–w- c:\program files\McAfee
2010-08-31 17:13 . 2010-07-28 23:16 452104 —-a-w- c:\documents and settings\Dee\Application Data\Real\Update\setup3.12\setup.exe
2010-08-27 02:09 . 2009-11-24 00:21 ——– d—–w- c:\documents and settings\LocalService\Application Data\SACore
2010-08-05 16:24 . 2010-07-25 19:58 ——– d—–w- c:\program files\Advanced Registry Optimizer
2010-07-24 15:53 . 2008-04-22 13:48 ——– d—–w- c:\program files\Creative
2010-07-24 15:53 . 2005-04-14 04:55 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-07-24 15:49 . 2005-04-27 22:23 ——– d—–w- c:\program files\V5385 Digital Camera
2010-07-24 15:46 . 2009-03-06 18:44 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-07-24 15:46 . 2009-03-06 18:44 ——– d—–w- c:\program files\NOS
2010-07-24 15:46 . 2008-12-28 20:16 ——– d—–w- c:\program files\Coupons
2010-07-24 15:44 . 2005-04-14 04:55 ——– d—–w- c:\program files\Common Files\InstallShield
2010-07-24 15:42 . 2005-06-05 01:07 ——– d—–w- c:\documents and settings\Dee\Application Data\Ulead Systems
2010-07-24 15:40 . 2005-04-14 05:04 ——– d—–w- c:\program files\Common Files\Intuit
2010-07-24 15:35 . 2005-04-14 04:53 ——– d—–w- c:\program files\Java
2010-07-24 15:15 . 2006-04-12 23:59 ——– d—–w- c:\program files\Dell
2010-07-24 15:08 . 2008-04-22 14:01 ——– d—–w- c:\program files\Audible
2010-07-24 14:52 . 2005-05-08 18:17 62448 -c–a-w- c:\documents and settings\Dee\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-15 20:18 . 2010-01-08 14:49 120136 —-a-w- c:\windows\system32\drivers\Mpfp.sys
2010-07-02 14:03 . 2010-03-15 02:55 439816 —-a-w- c:\documents and settings\Dee\Application Data\Real\Update\setup3.10\setup.exe
2010-06-14 14:30 . 2004-08-04 10:00 743936 —-a-w- c:\windows\PCHEALTH\HELPCTR\BINARIES\helpsvc.exe
2008-07-24 19:21 . 2008-07-24 19:20 10420936 -c–a-w- c:\program files\xlviewer.exe
2008-01-10 19:50 . 2005-04-27 21:44 848 –sha-w- c:\windows\SYSTEM32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-08-23 185896]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-30 417792]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-02-11 1218008]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
backup=c:\windows\pss\ymetray.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-12 04:16 39792 -c–a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 10:00 15360 —-a-w- c:\windows\SYSTEM32\CTFMON.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2007-03-15 16:09 460784 —-a-w- c:\program files\DellSupport\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HelpCenter4.1]
2007-04-13 01:59 198184 -c–a-w- c:\program files\FastAccessDSL\HelpCenter43\bin\sprtcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 21:24 54840 —-a-w- c:\program files\HP1610\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hplampc]
2002-01-17 15:40 40448 —-a-w- c:\windows\SYSTEM32\hplampc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-09-20 15:32 77824 —-a-w- c:\windows\SYSTEM32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-09-20 15:36 114688 —-a-w- c:\windows\SYSTEM32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2005-09-20 15:35 94208 —-a-w- c:\windows\SYSTEM32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-10-13 16:24 1694208 —-a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-30 14:16 417792 —-a-w- c:\program files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2004-10-14 19:42 1404928 -c–a-w- c:\program files\Analog Devices\Core\smax4pnp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2008-08-23 17:23 185896 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead AutoDetector]
2003-11-18 22:20 45056 -c—-w- c:\program files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\monitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2006-11-04 00:20 866584 —-a-w- c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\HP1610\\HP Software Update\\HPWUCli.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [5/11/2010 3:04 PM 203280]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S3 hp4200c;%usbscan.SvcDesc%;c:\windows\SYSTEM32\DRIVERS\hp4200c.sys [8/23/2005 10:43 AM 9312]
S3 SAUSBHW;%SAUSBHW.SvcDesc%;c:\windows\system32\Drivers\sausb.sys –> c:\windows\system32\Drivers\sausb.sys [?]
S3 WUSB54GV4SRV;Linksys Wireless-G USB Network Adapter Driver;c:\windows\SYSTEM32\DRIVERS\rt2500usb.sys [8/3/2005 11:01 AM 79616]
.
Contents of the 'Scheduled Tasks' folder

2005-04-18 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\OOBEBALN.EXE [2004-08-04 10:00]

2010-07-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2010-05-11 17:22]

2010-05-11 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2010-05-11 17:22]

2010-09-02 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = https://login.yahoo.com/config/login_verify…src=ym&rl=1
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/mywaybiz
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
FF - ProfilePath - c:\documents and settings\Dee\Application Data\Mozilla\Firefox\Profiles\psq040np.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.att.net/
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true);user_pref(general.useragent.extra.zencast, .
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp–FreedomNeedsReboot - c:\program files\AT&T\AT&T Internet Security Suite\ZkRunOnceR.exe
MSConfigStartUp-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
MSConfigStartUp-AT&T Internet Security Suite - c:\program files\AT&T\AT&T Internet Security Suite\Rps.exe
MSConfigStartUp-dscactivate - c:\program files\Dell Support Center\gs_agent\custom\dsca.exe
MSConfigStartUp-ISW - c:\program files\AT&T\Internet Security Wizard\ISW.exe
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre1.6.0_03\bin\jusched.exe
MSConfigStartUp-Ulead Photo Express Calendar Checker - c:\program files\Ulead Systems\Ulead Photo Express 5 SE\calcheck.exe
AddRemove-Internet Explorer Security Plugin 2006 - c:\program files\Video ActiveX Object\iesuninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-01 19:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-09-01 19:48:48
ComboFix-quarantined-files.txt 2010-09-02 00:48

Pre-Run: 63,418,671,104 bytes free
Post-Run: 63,452,954,624 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 4F4A1B177035B60679B9AC97E300FB2F
Hi Jcatsmom

The ComboFix log shows that you have two antiviruse programs on your computer: AT&T and McAfee. Can you let me know when you installed them and if you understand why they are both on there..


Your computer is looking clean but let’s run a couple of checks just to be sure.


Run Malwarebytes’ Anti-Malware

You previously ran a scan with MBAM so had it on your system: if you no longer have it, you can download it from here: • Start Malwarebytes-Anti-Malware and update it, (“Update” tab}
• Once it is updated, click on “Scanner” tab, select Perform quick scan, then click Scan.
• When the scan is complete, click OK, then Show Results to view the results.
• Be sure that everything is checked, and click Remove Selected.
• When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
• The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
• Copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.


Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Please include the result of both scans and let me know how your computer is running.

Satchfan
Hi, Satchfan. The MalwareBytes scan was clean. I wrestled with the computer for hours, trying to get Kaspersky to run. I kept getting the message "Launch of the Java applicaton is interrupted! Please establish an uninterrupted Internet connection for work with this program." I used Java Ra to clean out old files, installed Java version 6 Update 21, tried to make sure Java scripting was allowed were needed, etc. Had McAfee totally disabled. I installed XP Service Pack 3 with no problem. Its updates didn't help either.

To answer your questions. This computer has one anti-virus program it is the Security Suite for AT&T, provided by McAfee. The computer seems to be running quite well now.

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4532

Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702

9/2/2010 5:59:59 PM
mbam-log-2010-09-02 (17-59-59).txt

Scan type: Quick scan
Objects scanned: 151772
Time elapsed: 16 minute(s), 58 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Satchfan, I decide to run Housecall online scan to check the computer since I can't run Kaspersky. It found one infection. I have attached a jpg of the results. I did not use House Call to fix it, awaiting your direction. Thanks!
One more note. I scanned for the program and found that it resides: C:\Program Files\BellSouth\HelpCenter Seems like this might be a false positive.
Satchfan, I uploaded the file to Jotti and the scan came back clean. Seems like the computer is ready to go back to its owners, after we remove the software tools. Please review the latest Combofix uninstall with me. Thanks!


Jotti's malware scan

Filename: SSGet.exe Status: Scan finished. 0 out of 19 scanners reported malware.Scan taken on: Sat 4 Sep 2010 01:12:35 (CET)
Hello Jcatsmom

You’ve done a good job and as you say, the computer appears to be clean.

We need to tidy up the computer by removing the tools that have been used.


First

Follow these steps to uninstall Combofix• Click START then RUN
• Now type Combofix /uninstall in the runbox and click OK.
Note the space between the X and the /, it needs to be there.
🖼Click to load external image (Posted Image)
• Please follow the prompts to uninstall Combofix.
• Once it's finished uninstalling itself you will receive a message saying Combofix was uninstalled successfully.

Next

Uninstall OTL
• Double-click OTL.exe
• Click the CleanUp! button.
• Select Yes when the Begin cleanup Process? prompt appears.
• If you are prompted to reboot during the cleanup, select Yes.
• The tool will delete itself once it finishes, if not delete it by yourself.
NOTE: If you receive a warning from your firewall or other security programs regarding OTL attempting to contact the internet, please allow it to do so.


Run ATF Cleaner

I see you have run ATF Cleaner before. I suggest you run it again now that the computer seems to be clean as it will tidy up and remove any temporary files.


Set the computer to automatically check for Windows updates.

It would appear that if you had to install SP3, this computer is not set to automatically check for updates.

To turn on Automatic Updates:
• Click Start, Settings and then click Control Panel.
• Double-click Automatic Updates.
• Choose Automatic (recommended).
I would also suggest that you recommend to the owner that they run Malwarebytes regularly, check for Java updates and remove old versions of Java when there is a new version installed.

Regards

Satchfan
Satchfan, Thank you for your help. I was able to run Kaspersky. I finally thought of trying to run it in Mozilla and that worked. I was able to get the Java certificate and allow it. The scan came back clean. McAfee had already uninstalled combofix the moment it could get its claws into it. The computer was automatically set to install Microsoft updates- at that convenient time of 3 a.m (which I've adjusted). The extra downloads you may have seen were prompted by running Eusing Free Registry Cleaner. Both it and another registry scanner saw that a number of Microsoft updates didn't have an uninstaller properly loaded, so it deleted them for reinstall. My friends are really pleased at how great the computer is working. Thanks again.-Jcatsmom
Hi Jcatsmom. You're welcome and I'm pleased that all seems to be working well and your friend is happy also. Safe computing Regards Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI