This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Yahoo and Malware

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My biggest problem is that when I use Opera recently, I have tabs up but when I click on them, they do not open. When the cursor goes by the individual tabs, it shows what the page is. but they do not open. Also, there is no address bar so I cannot open a new page other than the default page. I go to the "view" and check to see if the address bar is checked and it is so it should work. I was gone for over a week to a funeral and my wife was home. It did not work right when I got back. I ran Avast and it found 11 viruses. I got rid of them. I also ran Malwarebytes and have superantispyware on the computer. Since then, I have found no malware. Ever since Yahoo started the new email, I have had problems with it. It is extremely slow ( even more than one minute) to load between emails. One time Opera said that the new email did not work well with Opera and offered to use the older one. However, since then it has not asked that and I do not know how to get the old version. This also happens in IE. Why doesn't Yahoo fix this? How can I get the old version to load every time? I am thinking of just using gmail although I like the yahoo groups much better than Google groups. I found out how to use the old version by going to Options in upper right hand corner. and then clicking on classic Yahoo email. I get a notice that I need a new IE browser but when I try to download IAE8, it says I cannot use it with my system (XP). I want to use a virtual sandbox for Opera so I can dump any memory if I do get malware. Does anyone know what program would work for Opera? Thanks GB
Hello GB,


My name is Blottedisk and I will be helping you with your log.

  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Options box to the right of your topic title and selecting Track This Topic.
  • Please avoid installing/uninstalling or updating any programs and attempting any unsupervised fixes or scans. This can make helping you impossible.
  • Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice. This may cause a delay in response time, but I will do my best to keep it as short as possible.

The forum is busy and we need to have replies as soon as possible. If I haven't had a reply after 3 days I will bump the topic and if you do not reply by the following day after that then the thread will be locked due to inactivity. However, if you will be away, let us know and we will be sure to keep the thread open.

Please bear with me, I will post back to you shortly with instructions.

Thanks :thumbup:
Hi again GB,


I don't really know of any sandbox program for Opera. Anyway, let's try to clean your machine and see if your issues are solved. In any case, when we finish with this topic, you can go back to the Browser forum for support. Now, please follow these steps in order:


Step 1 | Please download OTL from one of the following mirrors:

This is THE Mirror

——————————————————————–

  • Save it to your desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemdrive%\*.sys /90 /md5
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.

Step 2 | Please download GMER from one of the following locations and save it to your desktop:

Main Mirror - This version will download a randomly named file (Recommended)
Zipped Mirror - This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.

——————————————————————–

  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.

Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

[external image: Posted Image]

  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system…click NO.
  • Make sure all options are checked except:
  • IAT/EAT
  • Drives/Partition other than Systemdrive, which is typically C:\
  • Show All (This is important, so do not miss it.)

[external image: Posted Image]
Click the image to enlarge it

  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save… button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.
– If you encounter any problems, try running GMER in Safe Mode.



Please post back with:

OTL logs
GMER log
tHANKS A LOT FOR HELPING. I really appreciate it. Here is the OTL logfile.

OTL logfile created on: 9/12/2010 7:46:55 PM - Run 5
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 50.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WIXP | %ProgramFiles% = C:\Program Files
Drive C: | 38.25 Gb Total Space | 16.16 Gb Free Space | 42.24% Space Free | Partition Type: NTFS
Drive D: | 1.09 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 3.82 Gb Total Space | 3.77 Gb Free Space | 98.59% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KHALSA-FAMILY
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Uniblue\SpeedUpMyPC\sump.exe (Uniblue Systems Limited)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Giganology\Gigaget\Gigaget.exe (Giganology Inc.)
PRC - C:\WIXP\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OTL.exe (OldTimer Tools)
MOD - c:\Program Files\McAfee\SiteAdvisor\sahook.dll (McAfee, Inc.)
MOD - C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll (BillP Studios)
MOD - C:\WIXP\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)
MOD - C:\WIXP\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – C:\WIXP\System32\appmgmts.dll File not found
SRV - (0082101281009065mcinstcleanup) McAfee Application Installer Cleanup (0082101281009065) – C:\WIXP\Temp\0082101281009065mcinst.exe (McAfee, Inc.)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (McAfee SiteAdvisor Service) – c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (wuauserv) – C:\WINDOWS\system32\wuauserv.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (BIOSCHK) – C:\DOCUME~1\OWNER~1.KHA\LOCALS~1\Temp\TII69D.tmp\disk1\BIOSCHK.SYS File not found
DRV - (aswTdi) – C:\WIXP\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\WIXP\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\WIXP\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMon2) – C:\WIXP\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\WIXP\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (Aavmker4) – C:\WIXP\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (BANTExt) – C:\WIXP\System32\Drivers\BANTExt.sys ()
DRV - (portD) – C:\WIXP\system32\drivers\portd2k.sys (CMS Peripherals, Inc.)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WIXP\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (AN983) – C:\WIXP\system32\drivers\an983.sys (ADMtek Incorporated.)
DRV - (OMCI) – C:\WIXP\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\URLSearchHook: {db35fda8-77e3-4784-92c2-ee7345e91af4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/08/31 20:54:19 | 000,000,000 | —D | M]

[2009/12/21 14:30:16 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/07/14 20:21:35 | 000,000,698 | —- | M]) - C:\WIXP\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (GigagetIEHelper Class) - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WIXP\system32\gigagetbho_v10.dll (Giganology Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (xplorer2 Toolbar) - {db35fda8-77e3-4784-92c2-ee7345e91af4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (xplorer2 Toolbar) - {db35fda8-77e3-4784-92c2-ee7345e91af4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (xplorer2 Toolbar) - {DB35FDA8-77E3-4784-92C2-EE7345E91AF4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\RunOnce: [SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC\launcher.exe (Uniblue Systems Limited)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getAllurl.htm ()
O8 - Extra context menu item: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm ()
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O9 - Extra Button: Add to TimeLeft Auction Watch - {21196042-830F-419f-A594-F9D456A6C29A} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Add to TimeLeft Auction Watch - {21196042-830F-419f-A594-F9D456A6C29A} - Reg Error: Key error. File not found
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O12 - Plugin for: .pdf - C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll (Adobe Systems Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase6770.cab (Windows Live Safety Center Base Module)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} http://download.mcafee.com/molbin/iss-loc/…094/mcfscan.cab (McFreeScan Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WIXP\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WIXP\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WIXP\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WIXP\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WIXP\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WIXP\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 18:29:56 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WIXP\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WIXP\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: wuauserv - C:\WINDOWS\system32\wuauserv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56308606093492224)

========== Files/Folders - Created Within 30 Days ==========

[2010/09/12 19:17:34 | 000,576,000 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OTL.exe
[2010/09/04 04:38:26 | 000,000,000 | —D | C] – C:\WIXP\McAfee.com
[2010/08/18 15:06:31 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WIXP\System32\ptpusb.dll
[2010/08/18 15:06:28 | 000,159,232 | —- | C] (Microsoft Corporation) – C:\WIXP\System32\ptpusd.dll
[2010/08/18 15:06:27 | 000,015,104 | —- | C] (Microsoft Corporation) – C:\WIXP\System32\dllcache\usbscan.sys
[2010/08/17 21:55:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\health coaching

========== Files - Modified Within 30 Days ==========

[2010/09/12 19:17:35 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OTL.exe
[2010/09/12 19:02:01 | 000,000,884 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskMachineUA.job
[2010/09/12 19:02:00 | 000,001,006 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskUserS-1-5-21-602162358-1383384898-725345543-1003UA.job
[2010/09/12 17:05:56 | 000,011,647 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Call.odt
[2010/09/12 16:48:26 | 003,407,872 | -H– | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\NTUSER.DAT
[2010/09/12 16:46:53 | 000,016,896 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\hc50 Telephone Roster July 2010.doc
[2010/09/12 16:40:19 | 000,000,880 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskMachineCore.job
[2010/09/12 16:39:35 | 000,000,006 | -H– | M] () – C:\WIXP\tasks\SA.DAT
[2010/09/12 16:39:23 | 000,002,048 | –S- | M] () – C:\WIXP\bootstat.dat
[2010/09/12 16:37:47 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\ntuser.ini
[2010/09/12 16:32:59 | 005,885,966 | -H– | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\IconCache.db
[2010/09/12 15:28:15 | 000,125,491 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\property%20condition%20report%20sunnycrest[1].pdf
[2010/09/12 12:02:01 | 000,000,954 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskUserS-1-5-21-602162358-1383384898-725345543-1003Core.job
[2010/09/11 21:11:01 | 000,021,006 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\exercise log.odt
[2010/09/11 09:40:28 | 000,018,805 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Food Journal.odt
[2010/09/10 12:01:07 | 000,010,926 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\90 day goals.odt
[2010/09/10 10:11:11 | 000,011,792 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\COMPLETION LOG.odt
[2010/09/10 10:03:33 | 000,011,764 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\blank.odt
[2010/09/10 09:04:08 | 000,001,317 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\simple completion log.rtf
[2010/09/09 21:33:58 | 140,467,400 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OOo_3.2.1_Win_x86_install_en-US.exe
[2010/09/09 17:01:15 | 000,019,377 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\THE CALL FOCUS FORM_090410.odt
[2010/09/06 16:25:46 | 000,007,827 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\call focus form.odt
[2010/09/06 00:44:29 | 000,009,878 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\MLK.rtf
[2010/08/31 20:50:23 | 000,017,261 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\COACHING SUBJECT HEADLINES.odt
[2010/08/31 20:49:54 | 000,010,875 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\GOALS.odt
[2010/08/29 00:21:39 | 000,024,304 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Coaching Agreement for Karen.odt
[2010/08/23 19:53:15 | 000,031,855 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Agenda_ClubMtg_2003Ver_201008.odt
[2010/08/23 15:19:58 | 000,000,164 | -H– | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\.~lock.Agenda_ClubMtg_2003Ver_201008.doc#
[2010/08/23 12:00:31 | 000,041,472 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Agenda_ClubMtg_2003Ver_201008.doc
[2010/08/23 11:54:59 | 000,021,991 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\TMschedule_080310.doc_1.odt
[2010/08/23 10:54:11 | 000,000,164 | -H– | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\.~lock.TMschedule_080310.doc#
[2010/08/23 10:49:14 | 002,116,917 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\TechPresentProj5.pdf
[2010/08/23 10:48:09 | 000,024,576 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\SpeakerInfoSheet_ResForTM_082310.doc
[2010/08/21 21:22:17 | 000,048,128 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Call4PapersNInfo_Word2003_20100814.doc
[2010/08/21 18:06:29 | 000,014,066 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Program_Draft_20100624.pdf
[2010/08/20 18:27:20 | 000,212,561 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Final Result - 1191.pdf
[2010/08/19 20:07:29 | 000,021,141 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Karen's goals.odt
[2010/08/19 19:39:12 | 000,007,285 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\gremlin.odg
[2010/08/18 15:14:11 | 000,109,075 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\id.jpg
[2010/08/18 15:04:32 | 000,341,267 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\app.jpg
[2010/08/18 15:02:58 | 000,328,561 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\app 001.jpg
[2010/08/18 14:21:59 | 000,000,610 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010/08/18 14:21:59 | 000,000,592 | —- | M] () – C:\Documents and Settings\All Users.WIXP\Desktop\Opera.lnk
[2010/08/18 12:09:15 | 000,153,773 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\HCUVO1R2.pdf
[2010/08/17 21:42:00 | 000,013,713 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Suggested Client Intake Checklist.pdf
[2010/08/16 20:15:44 | 000,013,593 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Sandwich cookies.odt
[2010/08/16 15:43:59 | 000,009,523 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\DellDriverDownloadManager.application
[2010/08/14 21:21:47 | 000,214,677 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\diamond_feng_shui_life.pdf
[2010/08/14 14:45:18 | 000,040,996 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\PERIOD.pdf
[2010/08/14 12:22:19 | 000,008,258 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\explaining_your_program_supplement.pdf

========== Files Created - No Company Name ==========

[2010/09/12 15:28:48 | 000,125,491 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\property%20condition%20report%20sunnycrest[1].pdf
[2010/09/11 21:10:59 | 000,021,006 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\exercise log.odt
[2010/09/11 09:40:27 | 000,018,805 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Food Journal.odt
[2010/09/10 12:01:06 | 000,010,926 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\90 day goals.odt
[2010/09/10 09:04:08 | 000,001,317 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\simple completion log.rtf
[2010/09/09 21:35:57 | 000,011,764 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\blank.odt
[2010/09/09 21:13:32 | 140,467,400 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OOo_3.2.1_Win_x86_install_en-US.exe
[2010/09/09 17:01:15 | 000,019,377 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\THE CALL FOCUS FORM_090410.odt
[2010/09/06 16:25:46 | 000,007,827 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\call focus form.odt
[2010/09/06 00:44:29 | 000,009,878 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\MLK.rtf
[2010/08/31 20:50:48 | 000,011,792 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\COMPLETION LOG.odt
[2010/08/31 20:50:22 | 000,017,261 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\COACHING SUBJECT HEADLINES.odt
[2010/08/31 20:49:32 | 000,010,875 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\GOALS.odt
[2010/08/28 22:05:17 | 000,024,304 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Coaching Agreement for Karen.odt
[2010/08/26 21:05:15 | 000,021,991 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\TMschedule_080310.doc_1.odt
[2010/08/23 15:19:58 | 000,000,164 | -H– | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\.~lock.Agenda_ClubMtg_2003Ver_201008.doc#
[2010/08/23 14:51:36 | 000,031,855 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Agenda_ClubMtg_2003Ver_201008.odt
[2010/08/23 12:00:30 | 000,041,472 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Agenda_ClubMtg_2003Ver_201008.doc
[2010/08/23 10:54:11 | 000,000,164 | -H– | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\.~lock.TMschedule_080310.doc#
[2010/08/23 10:49:14 | 002,116,917 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\TechPresentProj5.pdf
[2010/08/23 10:48:08 | 000,024,576 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\SpeakerInfoSheet_ResForTM_082310.doc
[2010/08/21 21:22:17 | 000,048,128 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Call4PapersNInfo_Word2003_20100814.doc
[2010/08/21 18:06:29 | 000,014,066 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Program_Draft_20100624.pdf
[2010/08/20 18:27:20 | 000,212,561 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Final Result - 1191.pdf
[2010/08/19 21:18:04 | 000,011,647 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Call.odt
[2010/08/19 20:07:26 | 000,021,141 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Karen's goals.odt
[2010/08/19 19:39:09 | 000,007,285 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\gremlin.odg
[2010/08/18 15:13:28 | 000,109,075 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\id.jpg
[2010/08/18 15:03:51 | 000,341,267 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\app.jpg
[2010/08/18 15:02:15 | 000,328,561 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\app 001.jpg
[2010/08/18 12:09:38 | 000,153,773 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\HCUVO1R2.pdf
[2010/08/17 21:41:58 | 000,013,713 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Suggested Client Intake Checklist.pdf
[2010/08/16 20:15:43 | 000,013,593 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Sandwich cookies.odt
[2010/08/16 15:39:56 | 000,009,523 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\DellDriverDownloadManager.application
[2010/08/14 21:21:47 | 000,214,677 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\diamond_feng_shui_life.pdf
[2010/08/14 14:45:18 | 000,040,996 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\PERIOD.pdf
[2010/08/14 12:22:19 | 000,008,258 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\explaining_your_program_supplement.pdf
[2010/06/30 16:40:57 | 000,000,348 | —- | C] () – C:\Program Files\rwbpg.txt
[2010/05/17 19:54:09 | 000,000,754 | —- | C] () – C:\WIXP\WORDPAD.INI
[2010/05/07 01:03:11 | 000,000,237 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\burnaware.ini
[2010/04/07 05:46:10 | 000,000,036 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\housecall.guid.cache
[2010/03/08 13:21:09 | 000,006,144 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/03 06:41:44 | 000,003,840 | —- | C] () – C:\WIXP\System32\drivers\BANTExt.sys
[2010/01/22 13:22:54 | 000,767,952 | —- | C] () – C:\WIXP\BDTSupport.dll.old
[2009/12/22 03:33:43 | 000,755,200 | —- | C] () – C:\WIXP\System32\ir50_32.dll
[2009/12/22 03:33:43 | 000,338,432 | —- | C] () – C:\WIXP\System32\ir41_qcx.dll
[2009/12/22 03:33:43 | 000,200,192 | —- | C] () – C:\WIXP\System32\ir50_qc.dll
[2009/12/22 03:33:43 | 000,183,808 | —- | C] () – C:\WIXP\System32\ir50_qcx.dll
[2009/12/22 03:33:43 | 000,120,320 | —- | C] () – C:\WIXP\System32\ir41_qc.dll
[2002/09/03 08:58:49 | 000,027,440 | —- | C] () – C:\WIXP\System32\drivers\secdrv.sys

========== LOP Check ==========

[2010/07/30 15:58:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\Alwil Software
[2009/12/24 11:19:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\Applications
[2010/01/25 18:20:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\Citrix
[2009/12/27 21:39:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\IObit
[2010/02/23 01:40:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\Karen's Power Tools
[2010/07/22 11:02:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\TEMP
[2009/12/30 16:58:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Foxit
[2010/04/20 13:56:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Foxit Software
[2010/04/05 21:06:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\IObit
[2010/02/23 01:29:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\NesterSoft
[2010/05/17 20:58:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\OpenOffice.org
[2010/01/01 22:26:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Opera
[2009/12/24 12:38:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Thinstall
[2010/03/24 15:08:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Uniblue
[2010/07/18 15:06:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\WinPatrol

========== Purity Check ==========



========== Custom Scans ==========


< >

< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\1e589ebbbe9f21a79d69b300cc4bbc\i386\sp2.cab:AGP440.sys
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\WIXP\Driver Cache\i386\sp2.cab:AGP440.sys
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\WIXP\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2008/04/13 10:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\agp440.sys
[2008/04/13 10:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WIXP\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\agp440.sys
[2004/08/04 00:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WIXP\ERDNT\cache\agp440.sys
[2004/08/04 00:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WIXP\ServicePackFiles\i386\agp440.sys
[2004/08/04 00:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WIXP\system32\drivers\agp440.sys
[2002/09/03 08:31:57 | 000,025,472 | —- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF – C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\1e589ebbbe9f21a79d69b300cc4bbc\i386\sp2.cab:atapi.sys
[2002/09/03 09:04:09 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2002/09/03 09:04:09 | 010,158,890 | —- | M] () .cab file – C:\WIXP\Driver Cache\i386\sp1.cab:atapi.sys
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\WIXP\Driver Cache\i386\sp2.cab:atapi.sys
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\WIXP\ServicePackFiles\i386\sp2.cab:atapi.sys
[2002/09/03 08:27:33 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WINDOWS\system32\drivers\atapi.sys
[2002/09/03 08:27:33 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WIXP\$NtServicePackUninstall$\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WIXP\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys
[2004/08/03 23:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WIXP\ERDNT\cache\atapi.sys
[2004/08/03 23:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WIXP\ServicePackFiles\i386\atapi.sys
[2004/08/03 23:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WIXP\system32\drivers\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 16:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\eventlog.dll
[2008/04/13 16:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WIXP\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\eventlog.dll
[2004/08/04 01:56:44 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WIXP\ERDNT\cache\eventlog.dll
[2004/08/04 01:56:44 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WIXP\ServicePackFiles\i386\eventlog.dll
[2004/08/04 01:56:44 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WIXP\system32\eventlog.dll
[2002/09/03 08:32:41 | 000,049,152 | —- | M] (Microsoft Corporation) MD5=BF3C8CF53C77B48206B39910B6D6CBCC – C:\WINDOWS\system32\eventlog.dll
[2002/09/03 08:32:41 | 000,049,152 | —- | M] (Microsoft Corporation) MD5=BF3C8CF53C77B48206B39910B6D6CBCC – C:\WIXP\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 16:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\netlogon.dll
[2008/04/13 16:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WIXP\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\netlogon.dll
[2002/09/03 08:48:22 | 000,399,360 | —- | M] (Microsoft Corporation) MD5=3ADD563ED7A1C66E6F5E0F7A661AA96D – C:\WINDOWS\system32\netlogon.dll
[2002/09/03 08:48:22 | 000,399,360 | —- | M] (Microsoft Corporation) MD5=3ADD563ED7A1C66E6F5E0F7A661AA96D – C:\WIXP\$NtServicePackUninstall$\netlogon.dll
[2009/02/06 10:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 10:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2009/02/06 10:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WIXP\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 10:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WIXP\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004/08/04 01:56:46 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WIXP\ERDNT\cache\netlogon.dll
[2004/08/04 01:56:46 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WIXP\ServicePackFiles\i386\netlogon.dll
[2004/08/04 01:56:46 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WIXP\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 01:56:46 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WIXP\ERDNT\cache\scecli.dll
[2004/08/04 01:56:46 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WIXP\ServicePackFiles\i386\scecli.dll
[2004/08/04 01:56:46 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WIXP\system32\scecli.dll
[2002/09/03 08:58:25 | 000,174,592 | —- | M] (Microsoft Corporation) MD5=97418A5C642A5C748A28BD7CF6860B57 – C:\WINDOWS\system32\scecli.dll
[2002/09/03 08:58:25 | 000,174,592 | —- | M] (Microsoft Corporation) MD5=97418A5C642A5C748A28BD7CF6860B57 – C:\WIXP\$NtServicePackUninstall$\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WIXP\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2009/12/21 07:12:44 | 000,094,208 | —- | M] () – C:\WIXP\system32\config\default.sav
[2009/12/21 07:12:44 | 000,602,112 | —- | M] () – C:\WIXP\system32\config\software.sav
[2009/12/21 07:12:44 | 000,393,216 | —- | M] () – C:\WIXP\system32\config\system.sav

< %systemdrive%\*.sys /90 /md5 >
[2010/09/12 16:39:18 | 1608,515,584 | -HS- | M] () Unable to obtain MD5 – C:\pagefile.sys

========== Alternate Data Streams ==========

@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users.WIXP\Application Data\TEMP:5C321E34
< End of report >
I could not figure out how to disable Avast so it was on. Here is the logfile for GMER.\

Thanks
GB

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-09-12 20:41:32
Windows 5.1.2600 Service Pack 2
Running: 74bq0e9s.exe; Driver: C:\DOCUME~1\OWNER~1.KHA\LOCALS~1\Temp\fwlcqpog.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB1226CD2]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xB1226B8E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteKey [0xB1227142]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xB122706C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB1226764]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xB1226C68]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xB12266A4]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xB1226708]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB1226D88]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRenameKey [0xB1227210]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB1226D48]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xB1226EC8]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xB12EA320]

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xB1233B9C]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xB12339C0]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xB1233AFA]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject

—- Kernel code sections - GMER 1.0.15 —-

PAGE ntoskrnl.exe!ObInsertObject 80564423 5 Bytes JMP B1230F6C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntoskrnl.exe!NtCreateSection 8056469B 7 Bytes JMP B12339C4 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntoskrnl.exe!ZwCreateProcessEx 80581EFE 7 Bytes JMP B1233BA0 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntoskrnl.exe!ObMakeTemporaryObject 805A1132 5 Bytes JMP B122F5B4 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntoskrnl.exe!ZwLoadDriver 805A40FA 7 Bytes JMP B1233AFE \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

Device \FileSystem\Fastfat \FatCdrom aswSP.SYS (avast! self protection module/ALWIL Software)

AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device A mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device A Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)

AttachedDevice A fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device A Cdfs.SYS (CD-ROM File System Driver/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
Hi GB :)


Before we delve into this, can you tell us, is there some particular reason that you have chosen not to update that system? According to your log, you are a service pack behind in your critical updates. This is NOT GOOD. Remember to visit Microsoft's Windows Update Site Frequently - . This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.


Please go to your desktop, open the file extras.txt, copy it's contents and paste them in your next reply. Also, please do the following:


Step 1 | Right click on the avast! icon in system tray (looks like this: [external image: Posted Image]) and choose (Stop On-Access Protection).


Step 2 | Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.


Step 3 | Let's perform an ESET Online Scan

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

  • Please go here then click on: [external image: Posted Image]
    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.
  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed make sure you first copy the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic.
  • Now click on: [external image: Posted Image] (Selecting Uninstall application on close if you so wish)


Please post back with:


Extras.txt
Malwarebyte's Antimalware log
Eset logfile (log.txt)
Blottedisk

I am confused on this. I should have updated Windows. Sometimes, I do not because they put in a lot of unnecessary updates and then it takes so long and uses up bandwidth. I did update Windows like you said.

Here is where I got confused. I could not find extras.txt on my desktop. I did a search and it seems like it is the OTL logfile. Any, it is the same logfile I sent before. I will include it here however.

I already had Malwarebytes on my computer before and ran it before I contacted whatthe tech. It found no malware then and found no malware now. I would not update. I got an error code: 732 ( 0,0 ) on this.


I tried to download ESET 4 different times. Whenever I clicked on the ESET button, I got the same exact screen. Below are the logs. Thanks for helping.

GB


OTL Extras logfile created on: 6/7/2010 4:53:27 PM - Run 2
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 0.00 Gb Available Physical Memory | 8.00% Memory free
3.00 Gb Paging File | 1.00 Gb Available in Paging File | 36.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WIXP | %ProgramFiles% = C:\Program Files
Drive C: | 38.25 Gb Total Space | 18.41 Gb Free Space | 48.13% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KHALSA-FAMILY
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = Opera.HTML] – C:\Program Files\Opera\Opera.exe (Opera Software)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = Opera.HTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
https [open] – "C:\Program Files\Opera\Opera.exe" (Opera Software)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe" = C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe:*:Enabled:Microsoft Office Live Meeting 2007 – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe" = C:\Program Files\Microsoft Office\Live Meeting 8\Console\PWConsole.exe:*:Enabled:Microsoft Office Live Meeting 2007 – (Microsoft Corporation)
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser – (Opera Software)
"C:\Program Files\Giganology\Gigaget\Gigaget.exe" = C:\Program Files\Giganology\Gigaget\Gigaget.exe:*:Enabled:Gigaget – (Giganology Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1A3E23D7-7A1E-43EC-B35D-EB8A31BED943}" = FinalBurner Free v2.20.0.187
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21199F32-B676-4FE2-A443-EF7DB6B8FD4F}" = Opera 10.10
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{326957C7-83FD-4550-A59A-849B7B4297DE}" = Microsoft Easy Assist v2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6ADD0603-16EF-400D-9F9E-486432835002}" = OpenOffice.org 3.2
"{818ABC3C-635C-4651-8183-D0E9640B7DD1}" = HP Update
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{95632566-071E-4A02-92C1-4BD907065736}" = BounceBack Express
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{BE66348A-E83F-4982-941F-DFF2F742B851}" = Microsoft Office Live Meeting 2007
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{E55B3271-7CA8-4D0C-AE06-69A24856E996}_is1" = Uniblue SpeedUpMyPC
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F7B0939E-58DF-11DF-B3A6-005056806466}" = Google Earth
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Audacity_is1" = Audacity 1.2.6
"avast!" = avast! Antivirus
"Belarc Advisor" = Belarc Advisor 8.1
"BurnAware Free_is1" = BurnAware Free 2.4.6
"EB88B6218325D2AB47CFFBF7170236B60A6198FF" = Windows Driver Package - Microsoft Corporation (usbvideo) Image (05/25/2007 1.0.3656.0)
"ESET Online Scanner" = ESET Online Scanner v3
"Eusing Free Registry Cleaner" = Eusing Free Registry Cleaner
"Foxit Reader" = Foxit Reader
"gigaget_is1" = Gigaget
"GoToAssist" = GoToAssist 8.0.0.514
"HijackThis" = HijackThis 2.0.2
"Karen's Countdown Timer II" = Karen's Countdown Timer II
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"TIMELEFT3_is1" = TimeLeft
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 2
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"xplorer2 Toolbar" = xplorer2 Toolbar
"xplorer2l" = xplorer² lite

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/7/2010 3:39:43 PM | Computer Name = KHALSA-FAMILY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 6/7/2010 3:39:43 PM | Computer Name = KHALSA-FAMILY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 6/7/2010 3:39:44 PM | Computer Name = KHALSA-FAMILY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 6/7/2010 3:39:44 PM | Computer Name = KHALSA-FAMILY | Source = crypt32 | ID = 131077
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/3921C115C15D0ECA5CCB5BC4F07D21D8050B566A.crt>
with error: This network connection does not exist.

Error - 6/7/2010 3:39:44 PM | Computer Name = KHALSA-FAMILY | Source = crypt32 | ID = 131077
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/3921C115C15D0ECA5CCB5BC4F07D21D8050B566A.crt>
with error: This network connection does not exist.

Error - 6/7/2010 3:39:44 PM | Computer Name = KHALSA-FAMILY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 6/7/2010 3:39:44 PM | Computer Name = KHALSA-FAMILY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 6/7/2010 3:39:44 PM | Computer Name = KHALSA-FAMILY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 6/7/2010 3:39:44 PM | Computer Name = KHALSA-FAMILY | Source = crypt32 | ID = 131077
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/3921C115C15D0ECA5CCB5BC4F07D21D8050B566A.crt>
with error: This network connection does not exist.

Error - 6/7/2010 3:39:44 PM | Computer Name = KHALSA-FAMILY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

[ System Events ]
Error - 6/4/2010 7:57:22 PM | Computer Name = KHALSA-FAMILY | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\OLYMPUS\OLYMPUS
Master 2\Plugins\MDP_JPEG.omdp. Reference error message: The operation completed
successfully. .

Error - 6/4/2010 7:57:22 PM | Computer Name = KHALSA-FAMILY | Source = SideBySide | ID = 16842784
Description = Dependent Assembly Microsoft.VC80.CRT could not be found and Last
Error was The referenced assembly is not installed on your system.

Error - 6/4/2010 7:57:22 PM | Computer Name = KHALSA-FAMILY | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC80.CRT. Reference error
message: The referenced assembly is not installed on your system. .

Error - 6/4/2010 7:57:22 PM | Computer Name = KHALSA-FAMILY | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\OLYMPUS\OLYMPUS
Master 2\Plugins\MDP_QT.omdp. Reference error message: The operation completed successfully.
.

Error - 6/4/2010 7:57:22 PM | Computer Name = KHALSA-FAMILY | Source = SideBySide | ID = 16842784
Description = Dependent Assembly Microsoft.VC80.CRT could not be found and Last
Error was The referenced assembly is not installed on your system.

Error - 6/4/2010 7:57:22 PM | Computer Name = KHALSA-FAMILY | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC80.CRT. Reference error
message: The referenced assembly is not installed on your system. .

Error - 6/4/2010 7:57:22 PM | Computer Name = KHALSA-FAMILY | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\OLYMPUS\OLYMPUS
Master 2\Plugins\MDP_Raw.omdp. Reference error message: The operation completed
successfully. .

Error - 6/4/2010 7:57:22 PM | Computer Name = KHALSA-FAMILY | Source = SideBySide | ID = 16842784
Description = Dependent Assembly Microsoft.VC80.CRT could not be found and Last
Error was The referenced assembly is not installed on your system.

Error - 6/4/2010 7:57:22 PM | Computer Name = KHALSA-FAMILY | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC80.CRT. Reference error
message: The referenced assembly is not installed on your system. .

Error - 6/4/2010 7:57:22 PM | Computer Name = KHALSA-FAMILY | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\OLYMPUS\OLYMPUS
Master 2\Plugins\MDP_Tiff.omdp. Reference error message: The operation completed
successfully. .


< End of report >

Malwarebytes' Anti-Malware 1.42
Database version: 3425
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

9/14/2010 9:38:13 PM
mbam-log-2010-09-14 (21-38-12).txt

Scan type: Quick Scan
Objects scanned: 185013
Time elapsed: 29 minute(s), 25 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Hi GB,


Thanks for the info :thumbup:


The reason why the extras.txt log was not generated this time is because there is already an extras.txt file in your desktop from a previous topic here at Whatthetech. Just before that thread was closed resolved, you were given the instructions to open OTL and press the CLEANUP button to remove OTL as well as the logs; however it seems it didn't work properly. So, let's run OTL again with different settings.


Regarding to Malwarebyte's, not only your database version, but your Malwarebyte's Antimalware is really out-of-date. As malware databases are updated everyday, running a scan with a program which database is so old is useless. Please go to Start –> Control Pannel –> Add or Remove Programs and uninstall Malwarebyte's Antimalware. After that reboot the machine, and follow my previous instructions to download and run Malwarebyte's again, posting the generated log in your next reply. After that, please follow these steps in order:


Step 1 | Lets take another OTL log. Double click on the OTL icon to run it. Make sure all other windows are closed and to let it run uninterrupted.

  • Check the All option under the Extra Registry Section
  • Push the [external image: Posted Image] button.
  • Two reports will open, copy and paste them in your next reply:

OTListIt.txt <– Will be opened
Extras.txt <– Will be minimized


Step 2 | Please go to Kaspersky website and perform an online antivirus scan. Note: Internet Explorer should be used.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan and then put the kettle on!
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place like your Desktop. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Copy and paste the report into your next.

[external image: Posted Image]




Please, post back with the following logs:


Malwarebyte's log
OTL.txt
Extras.txt
Kaspersky log
Blottedisk

I was a little confused by this. I removed and then downloaded Malwarebytes. It found no malware. I will post the log below. I downloaded Kaspersky. I ran it once and saw a report in the formerly blank square. However, when I went to save it, I could not find it. I ran it again for another few hours the next day. It did not have the report in the blank square. All it had was this which was an infected file:

C:/ProgramFiles/PowerTools/Ba…
Threats
Exploit.Java.Agent.f

I found out that Kaspersky saved the file but it kept on being saved in Opera when I was using IE since Opera is not working properly. Anyway, whenever I try to open the logfile, Opera opens up but I cannot get the logfile. I think I sent both OTL files to you. There was no Extras.txt on the desktop where I saved OTL.

Again, thanks for helping.
GB


Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4638

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

9/17/2010 2:29:47 AM
mbam-log-2010-09-17 (02-29-47).txt

Scan type: Quick scan
Objects scanned: 234562
Time elapsed: 28 minute(s), 25 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


OTL logfile created on: 9/18/2010 3:03:39 PM - Run 6
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 0.00 Gb Available Physical Memory | 31.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WIXP | %ProgramFiles% = C:\Program Files
Drive C: | 38.25 Gb Total Space | 15.81 Gb Free Space | 41.33% Space Free | Partition Type: NTFS
Drive D: | 1.09 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 3.82 Gb Total Space | 3.77 Gb Free Space | 98.59% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KHALSA-FAMILY
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\Uniblue\SpeedUpMyPC\sump.exe (Uniblue Systems Limited)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Outlook Express\msimn.exe (Microsoft Corporation)
PRC - C:\WIXP\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll (BillP Studios)
MOD - C:\WIXP\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)
MOD - C:\WIXP\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – C:\WIXP\System32\appmgmts.dll File not found
SRV - (0082101281009065mcinstcleanup) McAfee Application Installer Cleanup (0082101281009065) – C:\WIXP\Temp\0082101281009065mcinst.exe (McAfee, Inc.)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (McAfee SiteAdvisor Service) – c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (wuauserv) – C:\WINDOWS\system32\wuauserv.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (BIOSCHK) – C:\DOCUME~1\OWNER~1.KHA\LOCALS~1\Temp\TII69D.tmp\disk1\BIOSCHK.SYS File not found
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (aswTdi) – C:\WIXP\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\WIXP\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\WIXP\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMon2) – C:\WIXP\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\WIXP\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (Aavmker4) – C:\WIXP\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (BANTExt) – C:\WIXP\System32\Drivers\BANTExt.sys ()
DRV - (portD) – C:\WIXP\system32\drivers\portd2k.sys (CMS Peripherals, Inc.)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WIXP\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (AN983) – C:\WIXP\system32\drivers\an983.sys (ADMtek Incorporated.)
DRV - (OMCI) – C:\WIXP\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\URLSearchHook: {db35fda8-77e3-4784-92c2-ee7345e91af4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/08/31 20:54:19 | 000,000,000 | —D | M]

[2009/12/21 14:30:16 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/07/14 20:21:35 | 000,000,698 | —- | M]) - C:\WIXP\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (GigagetIEHelper Class) - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WIXP\system32\gigagetbho_v10.dll (Giganology Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (xplorer2 Toolbar) - {db35fda8-77e3-4784-92c2-ee7345e91af4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (xplorer2 Toolbar) - {db35fda8-77e3-4784-92c2-ee7345e91af4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (xplorer2 Toolbar) - {DB35FDA8-77E3-4784-92C2-EE7345E91AF4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\RunOnce: [SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC\launcher.exe (Uniblue Systems Limited)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getAllurl.htm ()
O8 - Extra context menu item: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm ()
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O9 - Extra Button: Add to TimeLeft Auction Watch - {21196042-830F-419f-A594-F9D456A6C29A} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Add to TimeLeft Auction Watch - {21196042-830F-419f-A594-F9D456A6C29A} - Reg Error: Key error. File not found
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O12 - Plugin for: .pdf - C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll (Adobe Systems Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase6770.cab (Windows Live Safety Center Base Module)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} http://download.mcafee.com/molbin/iss-loc/…094/mcfscan.cab (McFreeScan Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WIXP\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WIXP\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WIXP\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WIXP\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WIXP\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WIXP\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 18:29:56 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WIXP\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WIXP\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: wuauserv - C:\WINDOWS\system32\wuauserv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54619756233228288)

========== Files/Folders - Created Within 30 Days ==========

[2010/09/17 01:53:33 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WIXP\System32\drivers\mbamswissarmy.sys
[2010/09/17 01:53:30 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WIXP\System32\drivers\mbam.sys
[2010/09/12 19:17:34 | 000,576,000 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OTL.exe
[2010/09/04 04:38:26 | 000,000,000 | —D | C] – C:\WIXP\McAfee.com

========== Files - Modified Within 30 Days ==========

[2010/09/18 15:02:00 | 000,001,006 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskUserS-1-5-21-602162358-1383384898-725345543-1003UA.job
[2010/09/18 15:02:00 | 000,000,884 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskMachineUA.job
[2010/09/18 13:05:11 | 000,000,880 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskMachineCore.job
[2010/09/18 13:05:02 | 000,000,006 | -H– | M] () – C:\WIXP\tasks\SA.DAT
[2010/09/18 13:04:47 | 000,002,048 | –S- | M] () – C:\WIXP\bootstat.dat
[2010/09/18 12:02:00 | 000,000,954 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskUserS-1-5-21-602162358-1383384898-725345543-1003Core.job
[2010/09/18 05:50:30 | 000,002,932 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Kaspersky log sept 18.html
[2010/09/18 05:45:43 | 000,002,932 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Kaspersky log.html
[2010/09/17 01:53:36 | 000,000,714 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/09/17 01:53:36 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users.WIXP\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/16 08:19:35 | 000,000,610 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010/09/16 08:19:35 | 000,000,592 | —- | M] () – C:\Documents and Settings\All Users.WIXP\Desktop\Opera.lnk
[2010/09/16 08:03:33 | 003,407,872 | -H– | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\NTUSER.DAT
[2010/09/16 08:03:06 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\ntuser.ini
[2010/09/14 12:54:03 | 000,001,042 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\changes.rtf
[2010/09/13 21:25:11 | 000,000,449 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Gmail - Fw North 10 … - [removed]
[2010/09/13 19:35:02 | 005,886,304 | -H– | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\IconCache.db
[2010/09/13 19:31:41 | 000,002,206 | —- | M] () – C:\WIXP\System32\wpa.dbl
[2010/09/13 09:21:14 | 000,072,080 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\g2mdlhlpx.exe
[2010/09/12 20:09:58 | 000,293,376 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\74bq0e9s.exe
[2010/09/12 19:17:35 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OTL.exe
[2010/09/12 17:05:56 | 000,011,647 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Call.odt
[2010/09/12 16:46:53 | 000,016,896 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\hc50 Telephone Roster July 2010.doc
[2010/09/12 15:28:15 | 000,125,491 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\property%20condition%20report%20sunnycrest[1].pdf
[2010/09/11 21:11:01 | 000,021,006 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\exercise log.odt
[2010/09/11 09:40:28 | 000,018,805 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Food Journal.odt
[2010/09/10 12:01:07 | 000,010,926 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\90 day goals.odt
[2010/09/10 10:11:11 | 000,011,792 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\COMPLETION LOG.odt
[2010/09/10 10:03:33 | 000,011,764 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\blank.odt
[2010/09/10 09:04:08 | 000,001,317 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\simple completion log.rtf
[2010/09/09 21:33:58 | 140,467,400 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OOo_3.2.1_Win_x86_install_en-US.exe
[2010/09/09 17:01:15 | 000,019,377 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\THE CALL FOCUS FORM_090410.odt
[2010/09/06 16:25:46 | 000,007,827 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\call focus form.odt
[2010/09/06 00:44:29 | 000,009,878 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\MLK.rtf
[2010/08/31 20:50:23 | 000,017,261 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\COACHING SUBJECT HEADLINES.odt
[2010/08/31 20:49:54 | 000,010,875 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\GOALS.odt
[2010/08/29 00:21:39 | 000,024,304 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Coaching Agreement for Karen.odt
[2010/08/23 19:53:15 | 000,031,855 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Agenda_ClubMtg_2003Ver_201008.odt
[2010/08/23 15:19:58 | 000,000,164 | -H– | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\.~lock.Agenda_ClubMtg_2003Ver_201008.doc#
[2010/08/23 12:00:31 | 000,041,472 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Agenda_ClubMtg_2003Ver_201008.doc
[2010/08/23 11:54:59 | 000,021,991 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\TMschedule_080310.doc_1.odt
[2010/08/23 10:54:11 | 000,000,164 | -H– | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\.~lock.TMschedule_080310.doc#
[2010/08/23 10:49:14 | 002,116,917 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\TechPresentProj5.pdf
[2010/08/23 10:48:09 | 000,024,576 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\SpeakerInfoSheet_ResForTM_082310.doc
[2010/08/21 21:22:17 | 000,048,128 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Call4PapersNInfo_Word2003_20100814.doc
[2010/08/21 18:06:29 | 000,014,066 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Program_Draft_20100624.pdf
[2010/08/20 18:27:20 | 000,212,561 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Final Result - 1191.pdf
[2010/08/19 20:07:29 | 000,021,141 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Karen's goals.odt
[2010/08/19 19:39:12 | 000,007,285 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\gremlin.odg

========== Files Created - No Company Name ==========

[2010/09/18 05:50:30 | 000,002,932 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Kaspersky log sept 18.html
[2010/09/18 05:41:19 | 000,002,932 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Kaspersky log.html
[2010/09/17 01:53:36 | 000,000,714 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/09/17 01:53:36 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users.WIXP\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/14 12:54:03 | 000,001,042 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\changes.rtf
[2010/09/13 21:25:11 | 000,000,449 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Gmail - Fw North 10 … - [removed]
[2010/09/13 09:21:14 | 000,072,080 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\g2mdlhlpx.exe
[2010/09/12 20:09:56 | 000,293,376 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\74bq0e9s.exe
[2010/09/12 15:28:48 | 000,125,491 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\property%20condition%20report%20sunnycrest[1].pdf
[2010/09/11 21:10:59 | 000,021,006 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\exercise log.odt
[2010/09/11 09:40:27 | 000,018,805 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Food Journal.odt
[2010/09/10 12:01:06 | 000,010,926 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\90 day goals.odt
[2010/09/10 09:04:08 | 000,001,317 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\simple completion log.rtf
[2010/09/09 21:35:57 | 000,011,764 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\blank.odt
[2010/09/09 21:13:32 | 140,467,400 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OOo_3.2.1_Win_x86_install_en-US.exe
[2010/09/09 17:01:15 | 000,019,377 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\THE CALL FOCUS FORM_090410.odt
[2010/09/06 16:25:46 | 000,007,827 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\call focus form.odt
[2010/09/06 00:44:29 | 000,009,878 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\MLK.rtf
[2010/08/31 20:50:48 | 000,011,792 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\COMPLETION LOG.odt
[2010/08/31 20:50:22 | 000,017,261 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\COACHING SUBJECT HEADLINES.odt
[2010/08/31 20:49:32 | 000,010,875 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\GOALS.odt
[2010/08/28 22:05:17 | 000,024,304 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Coaching Agreement for Karen.odt
[2010/08/26 21:05:15 | 000,021,991 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\TMschedule_080310.doc_1.odt
[2010/08/23 15:19:58 | 000,000,164 | -H– | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\.~lock.Agenda_ClubMtg_2003Ver_201008.doc#
[2010/08/23 14:51:36 | 000,031,855 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Agenda_ClubMtg_2003Ver_201008.odt
[2010/08/23 12:00:30 | 000,041,472 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Agenda_ClubMtg_2003Ver_201008.doc
[2010/08/23 10:54:11 | 000,000,164 | -H– | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\.~lock.TMschedule_080310.doc#
[2010/08/23 10:49:14 | 002,116,917 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\TechPresentProj5.pdf
[2010/08/23 10:48:08 | 000,024,576 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\SpeakerInfoSheet_ResForTM_082310.doc
[2010/08/21 21:22:17 | 000,048,128 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Call4PapersNInfo_Word2003_20100814.doc
[2010/08/21 18:06:29 | 000,014,066 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Program_Draft_20100624.pdf
[2010/08/20 18:27:20 | 000,212,561 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Final Result - 1191.pdf
[2010/08/19 21:18:04 | 000,011,647 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Call.odt
[2010/08/19 20:07:26 | 000,021,141 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Karen's goals.odt
[2010/08/19 19:39:09 | 000,007,285 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\gremlin.odg
[2010/06/30 16:40:57 | 000,000,348 | —- | C] () – C:\Program Files\rwbpg.txt
[2010/05/17 19:54:09 | 000,000,754 | —- | C] () – C:\WIXP\WORDPAD.INI
[2010/05/07 01:03:11 | 000,000,237 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\burnaware.ini
[2010/04/07 05:46:10 | 000,000,036 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\housecall.guid.cache
[2010/03/08 13:21:09 | 000,006,144 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/03 06:41:44 | 000,003,840 | —- | C] () – C:\WIXP\System32\drivers\BANTExt.sys
[2010/01/22 13:22:54 | 000,767,952 | —- | C] () – C:\WIXP\BDTSupport.dll.old
[2002/09/03 08:58:49 | 000,027,440 | —- | C] () – C:\WIXP\System32\drivers\secdrv.sys

========== LOP Check ==========

[2010/07/30 15:58:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\Alwil Software
[2009/12/24 11:19:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\Applications
[2010/01/25 18:20:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\Citrix
[2009/12/27 21:39:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\IObit
[2010/02/23 01:40:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\Karen's Power Tools
[2010/07/22 11:02:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WIXP\Application Data\TEMP
[2009/12/30 16:58:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Foxit
[2010/04/20 13:56:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Foxit Software
[2010/04/05 21:06:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\IObit
[2010/02/23 01:29:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\NesterSoft
[2010/05/17 20:58:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\OpenOffice.org
[2010/01/01 22:26:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Opera
[2009/12/24 12:38:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Thinstall
[2010/03/24 15:08:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Uniblue
[2010/07/18 15:06:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\WinPatrol

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\1e589ebbbe9f21a79d69b300cc4bbc\i386\sp2.cab:AGP440.sys
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\WIXP\Driver Cache\i386\sp2.cab:AGP440.sys
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\WIXP\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2008/04/13 10:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\agp440.sys
[2008/04/13 10:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WIXP\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\agp440.sys
[2004/08/04 00:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WIXP\ERDNT\cache\agp440.sys
[2004/08/04 00:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WIXP\ServicePackFiles\i386\agp440.sys
[2004/08/04 00:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WIXP\system32\drivers\agp440.sys
[2002/09/03 08:31:57 | 000,025,472 | —- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF – C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\1e589ebbbe9f21a79d69b300cc4bbc\i386\sp2.cab:atapi.sys
[2002/09/03 09:04:09 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2002/09/03 09:04:09 | 010,158,890 | —- | M] () .cab file – C:\WIXP\Driver Cache\i386\sp1.cab:atapi.sys
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\WIXP\Driver Cache\i386\sp2.cab:atapi.sys
[2004/08/04 02:05:44 | 018,738,937 | —- | M] () .cab file – C:\WIXP\ServicePackFiles\i386\sp2.cab:atapi.sys
[2002/09/03 08:27:33 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WINDOWS\system32\drivers\atapi.sys
[2002/09/03 08:27:33 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WIXP\$NtServicePackUninstall$\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WIXP\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys
[2004/08/03 23:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WIXP\ERDNT\cache\atapi.sys
[2004/08/03 23:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WIXP\ServicePackFiles\i386\atapi.sys
[2004/08/03 23:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WIXP\system32\drivers\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 16:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\eventlog.dll
[2008/04/13 16:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WIXP\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\eventlog.dll
[2004/08/04 01:56:44 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WIXP\ERDNT\cache\eventlog.dll
[2004/08/04 01:56:44 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WIXP\ServicePackFiles\i386\eventlog.dll
[2004/08/04 01:56:44 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WIXP\system32\eventlog.dll
[2002/09/03 08:32:41 | 000,049,152 | —- | M] (Microsoft Corporation) MD5=BF3C8CF53C77B48206B39910B6D6CBCC – C:\WINDOWS\system32\eventlog.dll
[2002/09/03 08:32:41 | 000,049,152 | —- | M] (Microsoft Corporation) MD5=BF3C8CF53C77B48206B39910B6D6CBCC – C:\WIXP\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 16:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\netlogon.dll
[2008/04/13 16:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WIXP\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\netlogon.dll
[2002/09/03 08:48:22 | 000,399,360 | —- | M] (Microsoft Corporation) MD5=3ADD563ED7A1C66E6F5E0F7A661AA96D – C:\WINDOWS\system32\netlogon.dll
[2002/09/03 08:48:22 | 000,399,360 | —- | M] (Microsoft Corporation) MD5=3ADD563ED7A1C66E6F5E0F7A661AA96D – C:\WIXP\$NtServicePackUninstall$\netlogon.dll
[2009/02/06 10:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 10:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2009/02/06 10:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WIXP\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 10:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WIXP\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004/08/04 01:56:46 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WIXP\ERDNT\cache\netlogon.dll
[2004/08/04 01:56:46 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WIXP\ServicePackFiles\i386\netlogon.dll
[2004/08/04 01:56:46 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WIXP\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 01:56:46 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WIXP\ERDNT\cache\scecli.dll
[2004/08/04 01:56:46 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WIXP\ServicePackFiles\i386\scecli.dll
[2004/08/04 01:56:46 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WIXP\system32\scecli.dll
[2002/09/03 08:58:25 | 000,174,592 | —- | M] (Microsoft Corporation) MD5=97418A5C642A5C748A28BD7CF6860B57 – C:\WINDOWS\system32\scecli.dll
[2002/09/03 08:58:25 | 000,174,592 | —- | M] (Microsoft Corporation) MD5=97418A5C642A5C748A28BD7CF6860B57 – C:\WIXP\$NtServicePackUninstall$\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WIXP\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/12/21 21:42:44 | 000,357,888 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WIXP\system32\dxtmsft.dll
[2009/12/21 21:42:45 | 000,205,312 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WIXP\system32\dxtrans.dll
[2009/12/21 21:42:45 | 000,251,392 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WIXP\system32\iepeers.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2009/12/21 07:12:44 | 000,094,208 | —- | M] () – C:\WIXP\system32\config\default.sav
[2009/12/21 07:12:44 | 000,602,112 | —- | M] () – C:\WIXP\system32\config\software.sav
[2009/12/21 07:12:44 | 000,393,216 | —- | M] () – C:\WIXP\system32\config\system.sav

< %systemdrive%\*.sys /90 /md5 >
[2010/09/18 13:04:42 | 1608,515,584 | -HS- | M] () Unable to obtain MD5 – C:\pagefile.sys

========== Alternate Data Streams ==========

@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users.WIXP\Application Data\TEMP:5C321E34
< End of report >


OTL logfile created on: 9/18/2010 3:03:39 PM - Run 6
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 0.00 Gb Available Physical Memory | 31.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 70.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WIXP | %ProgramFiles% = C:\Program Files
Drive C: | 38.25 Gb Total Space | 15.81 Gb Free Space | 41.33% Space Free | Partition Type: NTFS
Drive D: | 1.09 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 3.82 Gb Total Space | 3.77 Gb Free Space | 98.59% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KHALSA-FAMILY
Current User Name: Owner
Hi gbsk,


Thanks for the logs :thumbup:
It's important that you follow the instructions I give you in each post to the letter.


Please follow my previous OTL instructions again, but this time be sure to Check the All option under the Extra Registry Section like this:

[external image: Posted Image]
Click on the image to enlarge it.

Note: The OTL version in the image is the spanish one; however it should be pretty self-explanatory.

This way both OTL.txt and Extras.txt will be generated. Include them in your next reply.


Next, please start up Internet Explorer.

  • Click on "Tools" on the toolbar at the top of the screen. A drop-down menu will appear.
  • Click on "Internet Options"
  • Click on the "Programs" tab on the "Internet Options" screen.
  • Click on the box beside "Tell me if Internet Explorer is not the default web browser" and click on "OK." If the "Make default" box is grayed out, Internet Explorer is already your default browser. If it isn't, continue to the next step.
  • Close Internet Explorer and start it again and you'll be asked if you want to make Internet Explorer your default browser. Click on "Yes"
  • Go to your desktop and double-click the Kaspersky results (they will be opened within a new Internet Explorer session).
  • Copy and paste the results in your next reply.

Please post back with:

OTL.txt
Extras.txt
Kaspersky results
Blottedisk,

Sorry about the OTL. My fault. Here is another logfile for OTL. The OTL file was on the desktop. The extras.txt was not on the desktop. I did a search and it said no results so I have no idea where or if it happened. I will do the Kaspersky now and send it when it finishes.

Thanks
GB

OTL logfile created on: 9/19/2010 12:28:03 PM - Run 7
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 0.00 Gb Available Physical Memory | 27.00% Memory free
3.00 Gb Paging File | 1.00 Gb Available in Paging File | 52.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WIXP | %ProgramFiles% = C:\Program Files
Drive C: | 38.25 Gb Total Space | 15.84 Gb Free Space | 41.41% Space Free | Partition Type: NTFS
Drive D: | 1.09 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 3.82 Gb Total Space | 3.76 Gb Free Space | 98.52% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KHALSA-FAMILY
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\Uniblue\SpeedUpMyPC\sump.exe (Uniblue Systems Limited)
PRC - C:\Program Files\Foxit Software\Foxit Reader\Foxit Reader.exe (Foxit Software)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Skype\Toolbars\Shared\SkypeNames2.exe (Skype Technologies S.A.)
PRC - C:\Program Files\Outlook Express\msimn.exe (Microsoft Corporation)
PRC - C:\WIXP\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll (BillP Studios)
MOD - C:\WIXP\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)
MOD - C:\WIXP\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – C:\WIXP\System32\appmgmts.dll File not found
SRV - (0082101281009065mcinstcleanup) McAfee Application Installer Cleanup (0082101281009065) – C:\WIXP\Temp\0082101281009065mcinst.exe (McAfee, Inc.)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (McAfee SiteAdvisor Service) – c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (wuauserv) – C:\WINDOWS\system32\wuauserv.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (BIOSCHK) – C:\DOCUME~1\OWNER~1.KHA\LOCALS~1\Temp\TII69D.tmp\disk1\BIOSCHK.SYS File not found
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (aswTdi) – C:\WIXP\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\WIXP\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\WIXP\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMon2) – C:\WIXP\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\WIXP\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (Aavmker4) – C:\WIXP\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (BANTExt) – C:\WIXP\System32\Drivers\BANTExt.sys ()
DRV - (portD) – C:\WIXP\system32\drivers\portd2k.sys (CMS Peripherals, Inc.)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WIXP\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (AN983) – C:\WIXP\system32\drivers\an983.sys (ADMtek Incorporated.)
DRV - (OMCI) – C:\WIXP\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WIXP\system32\shdocvw.dll (Microsoft Corporation)
IE - HKCU\..\URLSearchHook: {db35fda8-77e3-4784-92c2-ee7345e91af4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2010/06/07 15:15:38 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/08/31 20:54:19 | 000,000,000 | —D | M]

[2009/12/21 14:30:16 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2009/11/24 13:45:26 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/08/19 13:17:43 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}
[2009/08/04 10:12:44 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2009/11/24 13:45:02 | 000,023,512 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll
[2009/11/24 13:45:03 | 000,137,176 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll
[2009/08/04 10:12:25 | 000,410,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll
[2009/11/24 13:45:09 | 000,064,984 | —- | M] (mozilla.org) – C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[2006/05/16 21:40:18 | 000,077,824 | —- | M] (Adobe Systems Inc.) – C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
[2009/06/27 18:34:32 | 000,131,072 | —- | M] (Apple Computer, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
[2009/06/27 18:34:32 | 000,131,072 | —- | M] (Apple Computer, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
[2009/06/27 18:34:32 | 000,131,072 | —- | M] (Apple Computer, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
[2009/06/27 18:34:32 | 000,131,072 | —- | M] (Apple Computer, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
[2009/06/27 18:34:32 | 000,131,072 | —- | M] (Apple Computer, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
[2009/06/27 18:34:32 | 000,131,072 | —- | M] (Apple Computer, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
[2009/06/27 18:34:32 | 000,131,072 | —- | M] (Apple Computer, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
[2009/06/24 03:27:00 | 000,001,394 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom.xml
[2009/06/24 03:27:00 | 000,002,193 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\answers.xml
[2009/06/24 03:27:00 | 000,001,534 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\creativecommons.xml
[2009/06/24 03:27:00 | 000,002,344 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay.xml
[2009/06/24 03:27:00 | 000,002,371 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\google.xml
[2009/06/24 03:27:00 | 000,001,178 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia.xml
[2009/06/24 03:27:00 | 000,000,792 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo.xml

O1 HOSTS File: ([2010/07/14 20:21:35 | 000,000,698 | —- | M]) - C:\WIXP\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (GigagetIEHelper Class) - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WIXP\system32\gigagetbho_v10.dll (Giganology Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (xplorer2 Toolbar) - {db35fda8-77e3-4784-92c2-ee7345e91af4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (xplorer2 Toolbar) - {db35fda8-77e3-4784-92c2-ee7345e91af4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WIXP\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WIXP\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (xplorer2 Toolbar) - {DB35FDA8-77E3-4784-92C2-EE7345E91AF4} - C:\Program Files\xplorer2\tbxpl1.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [HotKeysCmds] C:\WIXP\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WIXP\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\RunOnce: [SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC\launcher.exe (Uniblue Systems Limited)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O8 - Extra context menu item: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getAllurl.htm ()
O8 - Extra context menu item: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm ()
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O9 - Extra Button: Add to TimeLeft Auction Watch - {21196042-830F-419f-A594-F9D456A6C29A} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Add to TimeLeft Auction Watch - {21196042-830F-419f-A594-F9D456A6C29A} - Reg Error: Key error. File not found
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WIXP\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WIXP\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WIXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WIXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WIXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WIXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WIXP\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WIXP\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WIXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WIXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WIXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WIXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WIXP\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WIXP\system32\mswsock.dll (Microsoft Corporation)
O12 - Plugin for: .pdf - C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll (Adobe Systems Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase6770.cab (Windows Live Safety Center Base Module)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} http://download.mcafee.com/molbin/iss-loc/…094/mcfscan.cab (McFreeScan Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WIXP\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WIXP\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WIXP\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WIXP\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WIXP\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WIXP\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WIXP\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WIXP\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WIXP\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WIXP\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WIXP\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WIXP\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WIXP\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WIXP\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WIXP\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WIXP\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WIXP\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WIXP\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WIXP\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WIXP\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WIXP\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WIXP\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WIXP\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WIXP\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WIXP\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WIXP\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WIXP\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WIXP\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WIXP\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WIXP\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WIXP\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WIXP\system32\userinit.exe) - C:\WIXP\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WIXP\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WIXP\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WIXP\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WIXP\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WIXP\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WIXP\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WIXP\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WIXP\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WIXP\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WIXP\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WIXP\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WIXP\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WIXP\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WIXP\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WIXP\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WIXP\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WIXP\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WIXP\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WIXP\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WIXP\system32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\WIXP\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WIXP\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WIXP\System32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WIXP\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WIXP\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WIXP\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WIXP\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WIXP\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WIXP\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WIXP\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WIXP\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WIXP\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 18:29:56 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/09/17 01:53:33 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WIXP\System32\drivers\mbamswissarmy.sys
[2010/09/17 01:53:30 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WIXP\System32\drivers\mbam.sys
[2010/09/12 19:17:34 | 000,576,000 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OTL.exe
[2010/09/04 04:38:26 | 000,000,000 | —D | C] – C:\WIXP\McAfee.com

========== Files - Modified Within 30 Days ==========

[2010/09/19 12:02:00 | 000,001,006 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskUserS-1-5-21-602162358-1383384898-725345543-1003UA.job
[2010/09/19 12:02:00 | 000,000,954 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskUserS-1-5-21-602162358-1383384898-725345543-1003Core.job
[2010/09/19 12:02:00 | 000,000,884 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskMachineUA.job
[2010/09/19 10:02:00 | 000,000,880 | —- | M] () – C:\WIXP\tasks\GoogleUpdateTaskMachineCore.job
[2010/09/18 22:15:35 | 002,576,379 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Nine-Free-Programs-Ebook-2E.pdf
[2010/09/18 15:28:43 | 000,011,997 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\brainstorming new bus conctract,etc.odt
[2010/09/18 13:05:02 | 000,000,006 | -H– | M] () – C:\WIXP\tasks\SA.DAT
[2010/09/18 13:04:47 | 000,002,048 | –S- | M] () – C:\WIXP\bootstat.dat
[2010/09/18 05:50:30 | 000,002,932 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Kaspersky log sept 18.html
[2010/09/18 05:45:43 | 000,002,932 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Kaspersky log.html
[2010/09/17 01:53:36 | 000,000,714 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/09/17 01:53:36 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users.WIXP\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/16 08:19:35 | 000,000,610 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk
[2010/09/16 08:19:35 | 000,000,592 | —- | M] () – C:\Documents and Settings\All Users.WIXP\Desktop\Opera.lnk
[2010/09/16 08:03:33 | 003,407,872 | -H– | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\NTUSER.DAT
[2010/09/16 08:03:06 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\ntuser.ini
[2010/09/14 12:54:03 | 000,001,042 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\changes.rtf
[2010/09/13 21:25:11 | 000,000,449 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Gmail - Fw North 10 … - [removed]
[2010/09/13 19:35:02 | 005,886,304 | -H– | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\IconCache.db
[2010/09/13 19:31:41 | 000,002,206 | —- | M] () – C:\WIXP\System32\wpa.dbl
[2010/09/13 09:21:14 | 000,072,080 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\g2mdlhlpx.exe
[2010/09/12 20:09:58 | 000,293,376 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\74bq0e9s.exe
[2010/09/12 19:17:35 | 000,576,000 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OTL.exe
[2010/09/12 17:05:56 | 000,011,647 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Call.odt
[2010/09/12 16:46:53 | 000,016,896 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\hc50 Telephone Roster July 2010.doc
[2010/09/12 15:28:15 | 000,125,491 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\property%20condition%20report%20sunnycrest[1].pdf
[2010/09/11 21:11:01 | 000,021,006 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\exercise log.odt
[2010/09/11 09:40:28 | 000,018,805 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Food Journal.odt
[2010/09/10 12:01:07 | 000,010,926 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\90 day goals.odt
[2010/09/10 10:11:11 | 000,011,792 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\COMPLETION LOG.odt
[2010/09/10 10:03:33 | 000,011,764 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\blank.odt
[2010/09/10 09:04:08 | 000,001,317 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\simple completion log.rtf
[2010/09/09 21:33:58 | 140,467,400 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OOo_3.2.1_Win_x86_install_en-US.exe
[2010/09/09 17:01:15 | 000,019,377 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\THE CALL FOCUS FORM_090410.odt
[2010/09/06 16:25:46 | 000,007,827 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\call focus form.odt
[2010/09/06 00:44:29 | 000,009,878 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\MLK.rtf
[2010/08/31 20:50:23 | 000,017,261 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\COACHING SUBJECT HEADLINES.odt
[2010/08/31 20:49:54 | 000,010,875 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\GOALS.odt
[2010/08/29 00:21:39 | 000,024,304 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Coaching Agreement for Karen.odt
[2010/08/23 19:53:15 | 000,031,855 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Agenda_ClubMtg_2003Ver_201008.odt
[2010/08/23 15:19:58 | 000,000,164 | -H– | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\.~lock.Agenda_ClubMtg_2003Ver_201008.doc#
[2010/08/23 12:00:31 | 000,041,472 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Agenda_ClubMtg_2003Ver_201008.doc
[2010/08/23 11:54:59 | 000,021,991 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\TMschedule_080310.doc_1.odt
[2010/08/23 10:54:11 | 000,000,164 | -H– | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\.~lock.TMschedule_080310.doc#
[2010/08/23 10:49:14 | 002,116,917 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\TechPresentProj5.pdf
[2010/08/23 10:48:09 | 000,024,576 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\SpeakerInfoSheet_ResForTM_082310.doc
[2010/08/21 21:22:17 | 000,048,128 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Call4PapersNInfo_Word2003_20100814.doc
[2010/08/21 18:06:29 | 000,014,066 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Program_Draft_20100624.pdf
[2010/08/20 18:27:20 | 000,212,561 | —- | M] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Final Result - 1191.pdf

========== Files Created - No Company Name ==========

[2010/09/18 22:15:27 | 002,576,379 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Nine-Free-Programs-Ebook-2E.pdf
[2010/09/18 15:28:42 | 000,011,997 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\brainstorming new bus conctract,etc.odt
[2010/09/18 05:50:30 | 000,002,932 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Kaspersky log sept 18.html
[2010/09/18 05:41:19 | 000,002,932 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Kaspersky log.html
[2010/09/17 01:53:36 | 000,000,714 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/09/17 01:53:36 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users.WIXP\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/14 12:54:03 | 000,001,042 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\changes.rtf
[2010/09/13 21:25:11 | 000,000,449 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Gmail - Fw North 10 … - [removed]
[2010/09/13 09:21:14 | 000,072,080 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\g2mdlhlpx.exe
[2010/09/12 20:09:56 | 000,293,376 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\74bq0e9s.exe
[2010/09/12 15:28:48 | 000,125,491 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\property%20condition%20report%20sunnycrest[1].pdf
[2010/09/11 21:10:59 | 000,021,006 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\exercise log.odt
[2010/09/11 09:40:27 | 000,018,805 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Food Journal.odt
[2010/09/10 12:01:06 | 000,010,926 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\90 day goals.odt
[2010/09/10 09:04:08 | 000,001,317 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\simple completion log.rtf
[2010/09/09 21:35:57 | 000,011,764 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\blank.odt
[2010/09/09 21:13:32 | 140,467,400 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\OOo_3.2.1_Win_x86_install_en-US.exe
[2010/09/09 17:01:15 | 000,019,377 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\THE CALL FOCUS FORM_090410.odt
[2010/09/06 16:25:46 | 000,007,827 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\call focus form.odt
[2010/09/06 00:44:29 | 000,009,878 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\MLK.rtf
[2010/08/31 20:50:48 | 000,011,792 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\COMPLETION LOG.odt
[2010/08/31 20:50:22 | 000,017,261 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\COACHING SUBJECT HEADLINES.odt
[2010/08/31 20:49:32 | 000,010,875 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\GOALS.odt
[2010/08/28 22:05:17 | 000,024,304 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\Coaching Agreement for Karen.odt
[2010/08/26 21:05:15 | 000,021,991 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\TMschedule_080310.doc_1.odt
[2010/08/23 15:19:58 | 000,000,164 | -H– | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\.~lock.Agenda_ClubMtg_2003Ver_201008.doc#
[2010/08/23 14:51:36 | 000,031,855 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Agenda_ClubMtg_2003Ver_201008.odt
[2010/08/23 12:00:30 | 000,041,472 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Agenda_ClubMtg_2003Ver_201008.doc
[2010/08/23 10:54:11 | 000,000,164 | -H– | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Desktop\.~lock.TMschedule_080310.doc#
[2010/08/23 10:49:14 | 002,116,917 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\TechPresentProj5.pdf
[2010/08/23 10:48:08 | 000,024,576 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\SpeakerInfoSheet_ResForTM_082310.doc
[2010/08/21 21:22:17 | 000,048,128 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Call4PapersNInfo_Word2003_20100814.doc
[2010/08/21 18:06:29 | 000,014,066 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Program_Draft_20100624.pdf
[2010/08/20 18:27:20 | 000,212,561 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\My Documents\Final Result - 1191.pdf
[2010/06/30 16:40:57 | 000,000,348 | —- | C] () – C:\Program Files\rwbpg.txt
[2010/05/17 19:54:09 | 000,000,754 | —- | C] () – C:\WIXP\WORDPAD.INI
[2010/05/07 01:03:11 | 000,000,237 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Application Data\burnaware.ini
[2010/04/07 05:46:10 | 000,000,036 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\housecall.guid.cache
[2010/03/08 13:21:09 | 000,006,144 | —- | C] () – C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/03 06:41:44 | 000,003,840 | —- | C] () – C:\WIXP\System32\drivers\BANTExt.sys
[2010/01/22 13:22:54 | 000,767,952 | —- | C] () – C:\WIXP\BDTSupport.dll.old
[2002/09/03 08:58:49 | 000,027,440 | —- | C] () – C:\WIXP\System32\drivers\secdrv.sys

========== Alternate Data Streams ==========

@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users.WIXP\Application Data\TEMP:5C321E34
< End of report >
Blottedisk Here is what you said. Click on the box beside "Tell me if Internet Explorer is not the default web browser" and click on "OK." If the "Make default" box is grayed out, Internet Explorer is already your default browser. If it isn't, continue to the next step. I did check the bopx and then OK box. However, no gray area opened up. I shut down IE and then reopened it but it did not ask if I wanted IE to be the default browser. I found better directions. Set default web browser on XP 1. Click Start > Settings > Control Panel 2. In Control panel, double click on “Add Remove programs” icon. 3. Click “Set program access and defaults” tab on the left. 4. Click arrow on the right for “custom” option. 5. Click to select web browser you want as default & click OK. Kasperksky did open in IE but it was a web page. There were no links to reports or anything like that. I copied the whole web page. Below are the results. KASPERSKY ONLINE SCANNER 7.0: scan report Saturday, September 18, 2010 Operating system: Microsoft Windows XP Home Edition Service Pack 2 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Friday, September 17, 2010 08:56:15 Records in database: 4215744 Scan settings scan using the following database extended Scan archives yes Scan e-mail databases yes Scan area My Computer A:\ C:\ D:\ E:\ Scan statistics Objects scanned 115637 Threats found 1 Infected objects found 1 Suspicious objects found 0 Scan duration 06:33:32 File name Threat Threats count C:\Program Files\PowerTools Lite\Backups\0001D9\35217071-261c0e95 Infected: Exploit.Java.Agent.f 1 Selected area has been scanned.
Thanks GB :thumbup:


I notice you're using PowerTools. Here at WTT we don't reccomend the use of Registry Cleaner and Tweak Tools. The usefulness of these programs is highly overrated and can be dangerous. Here is an excerpt from a discussion on regcleaners:

Most reg cleaners aren't bad as such, but they aren't perfect and even the best have been known to cause problems. The point we are trying to make is that the risk of using one far outweighs any benefit. If it does work perfectly you will not see any difference. If it doesn't work properly you may end up with an expensive doorstop.



This post by MVP Bill Castner is very informative: http://forums.whatthetech.com/index.php?s=…st&p=418272

Also this blog entry by expert miekimoes: http://miekiemoes.blogspot.com/2008/02/reg…weaking_13.html


I recommend that you uninstall PowerTools from your computer.


Next

Please run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    
    :Files
    C:\Program Files\PowerTools Lite\Backups\0001D9
    
    :Commands
    [purity]
    [EmptyFlash]
    [emptytemp]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered, reboot when it is done.
  • It will produce a log for you on reboot, please post that log in your next reply.
Blottedisk

I did notice that OYL said something about Power Tools as malware. I did delete Power Tools before running OTL. I did not see it under Add/Remove Programs. AI did a search and found it., I did keep a countdown timer by Karen though. I downloaded it in March according to opening the file. The malware did not start until late Aug. or early Sept. Thanks for the info on Registry Cleaners. I do not think I ever used Power Tools before though. I do have another Registry Cleaner on the computer though. I have never had a bad experience with a registry cleaner and have never had to restore a file I have removed with a registry cleaner. I do watch what I remove. Some registery cleanings have saved me from losing data or reformatting the HD. Right now I am using Eusing, Here are some reviews on CNET.

http://download.cnet.com/Eusing-Free-Regis…4-10521691.html

After I restarted computer after using OTL, the computer seems faster. I still cannot use Opera. I will contact the Opera forum to see what may be the problem.

Thanks for helping,
GB



All processes killed
========== OTL ==========
========== FILES ==========
File\Folder C:\Program Files\PowerTools Lite\Backups\0001D9 not found.
========== COMMANDS ==========

[EMPTYFLASH]

User: Administrator

User: Administrator.KHALSA-FAMILY
->Flash cache emptied: 0 bytes

User: All Users

User: All Users.WIXP

User: Default User

User: Default User.WIXP

User: GB
->Flash cache emptied: 0 bytes

User: Guest

User: HAKK
->Flash cache emptied: 0 bytes

User: LocalService

User: LocalService.NT AUTHORITY

User: NetworkService

User: NetworkService.NT AUTHORITY

User: Owner
->Flash cache emptied: 0 bytes

User: Owner.KHALSA-FAMILY
->Flash cache emptied: 104232 bytes

User: OWNER~1~KHA

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes

User: Administrator.KHALSA-FAMILY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Opera cache emptied: 1798716 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: All Users.WIXP

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User.WIXP
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: GB
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: HAKK
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Opera cache emptied: 10649489 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: NetworkService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: Owner
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Opera cache emptied: 141966 bytes
->Flash cache emptied: 0 bytes

User: Owner.KHALSA-FAMILY
->Temp folder emptied: 417555420 bytes
->Temporary Internet Files folder emptied: 906746887 bytes
->Java cache emptied: 341625 bytes
->Google Chrome cache emptied: 6096348 bytes
->Opera cache emptied: 15623139 bytes
->Flash cache emptied: 0 bytes

User: OWNER~1~KHA

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 117435403 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 63066233 bytes

Total Files Cleaned = 1,468.00 mb


OTL by OldTimer - Version 3.2.12.0 log created on 09202010_190110

Files\Folders moved on Reboot…
File\Folder C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temp\Temporary Internet Files\Content.IE5\SJUJOZY5\CA4DWNSJ.com%2Fnfl%2Fblog%2Fshutdown_corner%2Fpost%2FJets-looking-to-address-alleged-harassment-of-fe%3Furn%3Dnfl-269361&r=0&SIG=10vq1brkm;x-cookie=r9b9onc68gaye&o=4&f=z1 not found!
File\Folder C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temp\Temporary Internet Files\Content.IE5\SJUJOZY5\eNp9klGOwyAMRE9UAoSIRnsYRMBpkWi8wk5Xvf0Cf7ui_TKIN4zHADExluTzFIim15mmAgR82fF
gutxKiuS0UEKKYo0xSlTsC_6IAj4eeEybJxBFzess5YCixPCTIrjDP90dfITidkSuhYG4Ko1ZpBkov7N_
VYrAl3BvDn[1].css not found!
File\Folder C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temp\Temporary Internet Files\Content.IE5\SJUJOZY5\Type=click&FlightID=298855&AdID=408384&TargetID=77741&Segments=730,2247,2743,2823,3285,4875,6041,9129,9496,9779,9781,9853,10381,16
113,17173,17251,18517,18982,20139,23[1].htm not found!
File\Folder C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temp\Temporary Internet Files\Content.IE5\QP8HGJOD\aclk%3Fsa%3Dl%26ai%3DBiygHZuaOTNDIPKDilQeL97z_DZSm5uYB7KOloRT816nSSgAQARgBIAA4AVCAx-HEBGDJ5qeGtKOgF4IBF2NhLXB1Yi0zMDMyMTE3NzUzODc5NjI1oAH04JnsA7IBGHd3dy5zb3V0aGJlbm
R0[2] not found!
File\Folder C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temp\Temporary Internet Files\Content.IE5\QP8HGJOD\CAOXQ91U.com%2Fnfl%2Fblog%2Fshutdown_corner%2Fpost%2FJets-looking-to-address-alleged-harassment-of-fe%3Furn%3Dnfl-269361&r=0&SIG=10vq1brkm;x-cookie=r9b9onc68gaye&o=4&f=z1 not found!
File\Folder C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temp\Temporary Internet Files\Content.IE5\C5YVCVGP\CA6PGZIX.com%2Fnfl%2Fblog%2Fshutdown_corner%2Fpost%2FJets-looking-to-address-alleged-harassment-of-fe%3Furn%3Dnfl-269361&r=0&SIG=10vq1brkm;x-cookie=r9b9onc68gaye&o=4&f=z1 not found!
File\Folder C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DS509M1\Type=click&FlightID=298854&AdID=408383&TargetID=72775&Segments=730,2247,2743,2823,3285,9496,9779,9781,9853,10381,13086,13087,13088
,13090,13091,13303,16113,16337,17173[1].htm not found!
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temp\~DF28AF.tmp moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temp\~DF81F4.tmp moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temp\~DFF52C.tmp moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temp\~DFFA13.tmp moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\W7ZZIO5X\CAZM29V7.g moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\W7ZZIO5X\empty[1].htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\OZ3P13BO\content[2].htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\OZ3P13BO\Donation2[1].donation=form1&df_id=6100&s_src=3WDW10123TVXX&s_subsrc=092010_advact moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\OZ3P13BO\eddylist_list.kck[2].htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\OZ3P13BO\like[4].php moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\OZ3P13BO\overlay[1].css moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\O5OOT6N3\banner_code[1].html moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\O5OOT6N3\CA9QJNT7.io moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\O5OOT6N3\CAYRWDY1.htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\O5OOT6N3\CAYV8LK5.htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\O5OOT6N3\index[1].php moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\O5OOT6N3\index[2].php moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\O5OOT6N3\login_status[1].php moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\O5OOT6N3\mastersoon[1].htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\O5OOT6N3\personalization[1].css moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\O5OOT6N3\viewemail[1].htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\O1K5234B\CALG3AZ1.htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\O1K5234B\like[3].php moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\O1K5234B\main[1].css moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\O1K5234B\rakesofmallowbtf[1].htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\MXKJ2H85\bclick[1] moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\MXKJ2H85\CAGXCXSF.htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\MXKJ2H85\CAYFWPYV.htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\MXKJ2H85\embed_code[1].htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\KT630TMF\CAK9IFG9.htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\KT630TMF\iframe[2].htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\KT630TMF\like[3].php moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\KT630TMF\like[4].php moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\FUJ155ZJ\CAKHEPTA.htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\FUJ155ZJ\rakesofmallowatf[1].htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\FUJ155ZJ\registry-cleaners-and-system-tweaking_13[1].html moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\CPQJSHUV\aceUACping[1].htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\CPQJSHUV\ad[1] moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\CPQJSHUV\CAL0MD93.htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\CPQJSHUV\xd_receiver[1].htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\ANBFNWDH\25149-30[1].htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\ANBFNWDH\ad[2] moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\ANBFNWDH\CAK9URC9.htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\ANBFNWDH\common[1].css moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\ANBFNWDH\like[3].php moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\ANBFNWDH\like[4].php moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\ANBFNWDH\Michael-Vick-sparkles-again-promptly-gets-bench[1] moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\ANBFNWDH\nav[1].htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\ANBFNWDH\protoaculous.1.8.2.min[1].js moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\ANBFNWDH\st[1] moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\8PWQWWOE\CA3TXZQQ.htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\8PWQWWOE\CAUBQ92H.htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\8DEBCHIN\dg.specificclick[1].rand%3D4j0m5fbrs4dg1 moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\8DEBCHIN\index3[1].htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\6WMXVDOC\facebook_share[1].htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\0X6385E7\CA1LRJQ8.htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\0X6385E7\CA8H858J.htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\0X6385E7\CAAJ41U3 moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\0X6385E7\CAIBMV61 moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\0X6385E7\CAXZ3HOW.htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\0X6385E7\dg.specificclick[1].com%2F&r= moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\0X6385E7\DtCol[1].htm moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\0X6385E7\like[6].php moved successfully.
C:\Documents and Settings\Owner.KHALSA-FAMILY\Local Settings\Temporary Internet Files\Content.IE5\0X6385E7\news_newmessage[1] moved successfully.
File move failed. C:\WIXP\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot…
Blottedisk I just tried to go to Opera forums but IE will not display the Opera forum webpages. I get a "cannot find server" page. I get any other webpage. I originally went to whathetech browser forum to ask about this and they suggested I go to the malware area and that is when you got involved. I still must have something on the computer because I cannot access the Opera webpages. If people want to download Opera itself they have to do it originally from another browser. Opera will open but there are no address bars that display even though I have it checked when I go to "view". Thanks GB

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI