This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Baseline Hijack log question

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I got a trojan virus a few days ago and I've used Malwarebytes to delete it; and I've used a registry cleaning software to clean up my registry files. The malware program finds the virus and deletes it, but it still seems to be hiding somewhere on my system because I keep having problems with my internet browsers starting and my computer doesn't start up right either since I got this virus. The look of my Windows and my taskbar will all of a sudden change also. I have run Hijack this tonight and saved the log. Can someone please tell me which items to fix because I don't really understand this logโ€ฆ The registry files that the registry cleaning software finds that need to be fixed usually begin with something like HHkey and I don't really know what that is either. Thanks! The log is attached.
:welcome:

Hijackthis has become somewhat outdated and may not be showing everything , we don't use it much anymore. Run these programs and lets see whats going on. Please copy and paste the logs into this thread, do not attach them unless we specify to do so. Please do not run any other scanners or removal tools on your own . Please do not install or uninstall any software or hardware until we are done.


[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scanโ€ฆclick on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following โ€ฆ
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<โ€” ROOKIT" entries








Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click Ok to load a custom scan from a file or Cancel to cancel"
  • Click the Ok button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic
I ran the scan (it took all day on Friday) and my computer ran extremely slow afterward. As directed, I am attaching the Gmer.txt file to this post. Please let me know what I should do next โ€ฆ
Thanks!

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-10-09 07:15:33
Windows 5.1.2600 Service Pack 3
Running: bnteqnq2.exe; Driver: C:\DOCUME~1\TERESA~1\LOCALS~1\Temp\pfloapoc.sys


โ€”- System - GMER 1.0.15 โ€”-

SSDT 89BFB580 ZwAssignProcessToJobObject
SSDT 89BFC100 ZwDebugActiveProcess
SSDT 89BFBB30 ZwDuplicateObject
SSDT 89BFACC0 ZwOpenProcess
SSDT 89BFAFC0 ZwOpenThread
SSDT 89BFB9C0 ZwProtectVirtualMemory
SSDT 89BFB860 ZwSetContextThread
SSDT 89BFB6E0 ZwSetInformationThread
SSDT 89BF8700 ZwSetSecurityObject
SSDT 89BFB420 ZwSuspendProcess
SSDT 89BFB2C0 ZwSuspendThread
SSDT 89BFAE50 ZwTerminateProcess
SSDT 89BFB150 ZwTerminateThread
SSDT 89BFBF50 ZwWriteVirtualMemory

โ€”- Kernel code sections - GMER 1.0.15 โ€”-

.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB8736360, 0x3475F7, 0xE8000020]
init C:\WINDOWS\system32\drivers\Senfilt.sys entry point in "init" section [0xA7D27A00]

โ€”- User code sections - GMER 1.0.15 โ€”-

.text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[296] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 4 Bytes [C2, 04, 00, 00]
.text C:\WINDOWS\System32\svchost.exe[1276] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00D9000A
.text C:\WINDOWS\System32\svchost.exe[1276] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00DA000A
.text C:\WINDOWS\System32\svchost.exe[1276] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00D8000C
.text C:\WINDOWS\System32\svchost.exe[1276] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 00EE000A
.text C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE[1356] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes JMP 32604F4E C:\Program Files\Common Files\Microsoft Shared\office12\mso.dll (2007 Microsoft Office component/Microsoft Corporation)
.text C:\WINDOWS\Explorer.EXE[1812] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00FF000A
.text C:\WINDOWS\Explorer.EXE[1812] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0196000A
.text C:\WINDOWS\Explorer.EXE[1812] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00FE000C
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1908] msvcrt.dll!??2@YAPAXI@Z 77C29CC5 5 Bytes JMP 0A90D480 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1908] msvcrt.dll!??3@YAXPAX@Z 77C29CDD 5 Bytes JMP 0A90D2D0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1908] msvcrt.dll!?set_new_handler@@YAP6AXXZP6AXXZ@Z 77C29D9F 5 Bytes JMP 0A90D500 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1908] msvcrt.dll!_aligned_offset_malloc 77C29DAF 5 Bytes JMP 0A90D3E0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1908] msvcrt.dll!_aligned_free 77C29E33 5 Bytes JMP 0A90D2D0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1908] msvcrt.dll!_aligned_malloc 77C29E52 5 Bytes JMP 0A90D3C0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1908] msvcrt.dll!_aligned_offset_realloc 77C29E6E 5 Bytes JMP 0A90D420 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1908] msvcrt.dll!_aligned_realloc 77C29FC6 5 Bytes JMP 0A90D400 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1908] msvcrt.dll!_expand 77C29FE5 5 Bytes JMP 0A90D3A0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1908] msvcrt.dll!_heapadd 77C2BC9F 5 Bytes JMP 0A90D550 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1908] msvcrt.dll!_heapchk 77C2BCB3 5 Bytes JMP 0A90D560 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1908] msvcrt.dll!_heapset + 1 77C2BD83 4 Bytes JMP 0A90D581 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1908] msvcrt.dll!_heapmin 77C2BD8C 5 Bytes JMP 0A90D650 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1908] msvcrt.dll!_heapused 77C2BE3A 5 Bytes JMP 0A90D620 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1908] msvcrt.dll!_heapwalk 77C2BE4D 5 Bytes JMP 0A90D590 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1908] msvcrt.dll!_msize 77C2BF6C 5 Bytes JMP 0A90D2E0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1908] msvcrt.dll!calloc 77C2C0C3 5 Bytes JMP 0A90D270 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1908] msvcrt.dll!free 77C2C21B 5 Bytes JMP 0A90D2D0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1908] msvcrt.dll!malloc 77C2C407 5 Bytes JMP 0A90D230 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe[1908] msvcrt.dll!realloc 77C2C437 5 Bytes JMP 0A90D2B0 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\SHSMP.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\WINDOWS\system32\wuauclt.exe[2964] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0114000A
.text C:\WINDOWS\system32\wuauclt.exe[2964] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0115000A
.text C:\WINDOWS\system32\wuauclt.exe[2964] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0113000C
.text C:\Program Files\Mozilla Firefox\firefox.exe[4052] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 02D5000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[4052] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 02D6000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[4052] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 02D4000C
.text C:\Program Files\Mozilla Firefox\firefox.exe[4052] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[4052] GDI32.dll!TextOutW 77F17EAC 5 Bytes JMP 0185CCF5
.text C:\Program Files\Mozilla Firefox\firefox.exe[4052] GDI32.dll!ExtTextOutW 77F18086 5 Bytes JMP 0185D22F
.text C:\Program Files\Mozilla Firefox\firefox.exe[4052] GDI32.dll!TextOutA 77F1BA4F 5 Bytes JMP 0185CC28
.text C:\Program Files\Mozilla Firefox\firefox.exe[4052] GDI32.dll!ExtTextOutA 77F1D3FA 5 Bytes JMP 0185D14A
.text C:\Program Files\Mozilla Firefox\firefox.exe[4052] GDI32.dll!GetGlyphIndicesA 77F3DFE3 5 Bytes JMP 0185D5E6
.text C:\Program Files\Mozilla Firefox\firefox.exe[4052] GDI32.dll!GetGlyphIndicesW 77F52604 5 Bytes JMP 0185D6B0
.text C:\Program Files\Mozilla Firefox\firefox.exe[4052] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 0185C197
.text C:\Program Files\Mozilla Firefox\firefox.exe[4052] USER32.dll!DrawTextExW 7E42B415 5 Bytes JMP 0185D062
.text C:\Program Files\Mozilla Firefox\firefox.exe[4052] USER32.dll!DrawTextW 7E42D7E2 5 Bytes JMP 0185CE9E
.text C:\Program Files\Mozilla Firefox\firefox.exe[4052] USER32.dll!SetClipboardData 7E430F9E 5 Bytes JMP 0185CB15
.text C:\Program Files\Mozilla Firefox\firefox.exe[4052] USER32.dll!DrawTextA 7E43C702 5 Bytes JMP 0185CDC2
.text C:\Program Files\Mozilla Firefox\firefox.exe[4052] USER32.dll!DrawTextExA 7E43C739 5 Bytes JMP 0185CF7A

โ€”- Devices - GMER 1.0.15 โ€”-

AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)

Device \FileSystem\Udfs \UdfsCdRom DLAIFS_M.SYS (Drive Letter Access Component/Roxio)
Device \FileSystem\Udfs \UdfsDisk DLAIFS_M.SYS (Drive Letter Access Component/Roxio)

AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys (ESET Antivirus Network Redirector/ESET)

Device \FileSystem\Fastfat \Fat A6467D20

AttachedDevice \FileSystem\Fastfat \Fat eamon.sys (Amon monitor/ESET)

Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Roxio)

โ€”- EOF - GMER 1.0.15 โ€”-

Attachments:

Log looks ok, it is just a scanner, it does not remove anything, just reboot your system. I still need to see the OTL log, please copy and paste it in, do not attach it
My internet browsers are locking up on me so I am sending this from another computer. This seems to be the biggest problem since my computer got the virus. Below is the OTL txt log:
OTL logfile created on: 10/11/2010 9:01:28 PM - Run 1
OTL by OldTimer - Version 3.2.15.0 Folder = C:\Documents and Settings\Teresa Robinett\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 77.00% Memory free
9.00 Gb Paging File | 8.00 Gb Available in Paging File | 92.00% Paging File free
Paging file location(s): C:\pagefile.sys 6000 10000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.76 Gb Total Space | 123.70 Gb Free Space | 53.14% Space Free | Partition Type: NTFS
Drive D: | 3.75 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF1.02
Drive F: | 698.64 Gb Total Space | 462.87 Gb Free Space | 66.25% Space Free | Partition Type: NTFS
Drive G: | 122.01 Mb Total Space | 16.53 Mb Free Space | 13.55% Space Free | Partition Type: FAT32

Computer Name: D43KL5H1 | User Name: Teresa Robinett | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | File Age = 90 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Teresa Robinett\Local Settings\Temp\JobMonitor\JobMonitor.exe ()
PRC - C:\Documents and Settings\Teresa Robinett\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
PRC - F:\tax\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe (Amazon.com)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
PRC - C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\dwwin.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\OFFLB.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\DW\DW20.EXE (Microsoft Corporation)
PRC - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe (Broadcom Corporation)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
PRC - C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe ()
PRC - C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe (Adobe Sytems Incorporated)
PRC - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe (Adobe Systems Incorporated)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Teresa Robinett\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\wtsapi32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\winsta.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\rtutils.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\onex.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msvcp60.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\iphlpapi.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\eappcfg.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\eappprxy.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\dot3api.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\dot3dlg.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\credui.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\WINDOWS\system32\xpsp2res.dll (Microsoft Corporation)
MOD - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\pdfshell.dll (Adobe Systems, Inc.)
MOD - C:\Program Files\Pro Imaging Powertoys\Microsoft RAW Image Thumbnailer and Viewer for Windows XP\CRawViewerExtension.dll (Microsoft Corporation)
MOD - C:\Program Files\Pro Imaging Powertoys\Microsoft RAW Image Thumbnailer and Viewer for Windows XP\msvcr71.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) โ€“ C:\WINDOWS\System32\hidserv.dll File not found
SRV - (PCToolsSSDMonitorSvc) โ€“ C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
SRV - (Amazon Download Agent) โ€“ F:\tax\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe (Amazon.com)
SRV - (IntuitUpdateService) โ€“ C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (EhttpSrv) โ€“ C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe (ESET)
SRV - (ekrn) โ€“ C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)
SRV - (FLEXnet Licensing Service) โ€“ C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (IAANTMON) Intelยฎ โ€“ C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (ASFIPmon) โ€“ C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe (Broadcom Corporation)
SRV - (Adobe Version Cue CS2) โ€“ C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe (Adobe Systems Incorporated)


========== Driver Services (SafeList) ==========

DRV - (epfwtdir) โ€“ C:\WINDOWS\system32\drivers\epfwtdir.sys (ESET)
DRV - (ehdrv) โ€“ C:\WINDOWS\system32\drivers\ehdrv.sys (ESET)
DRV - (eamon) โ€“ C:\WINDOWS\system32\drivers\eamon.sys (ESET)
DRV - (amdagp) โ€“ C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) โ€“ C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (HDAudBus) โ€“ C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ยฎ Server 2003 DDK provider)
DRV - (nv) โ€“ C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (iaStor) โ€“ C:\WINDOWS\system32\drivers\iaStor.sys (Intel Corporation)
DRV - (b57w2k) โ€“ C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (SenFiltService) โ€“ C:\WINDOWS\system32\drivers\senfilt.sys (Sensaura)
DRV - (ADIHdAudAddService) โ€“ C:\WINDOWS\system32\drivers\ADIHdAud.sys (Analog Devices, Inc.)
DRV - (DLADResM) โ€“ C:\WINDOWS\system32\drivers\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) โ€“ C:\WINDOWS\system32\drivers\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) โ€“ C:\WINDOWS\system32\drivers\DLAUDF_M.SYS (Roxio)
DRV - (DLAUDFAM) โ€“ C:\WINDOWS\system32\drivers\DLAUDFAM.SYS (Roxio)
DRV - (DLAOPIOM) โ€“ C:\WINDOWS\system32\drivers\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) โ€“ C:\WINDOWS\system32\drivers\DLABOIOM.SYS (Roxio)
DRV - (DLAPoolM) โ€“ C:\WINDOWS\system32\drivers\DLAPoolM.SYS (Roxio)
DRV - (DLAIFS_M) โ€“ C:\WINDOWS\system32\drivers\DLAIFS_M.SYS (Roxio)
DRV - (DRVMCDB) โ€“ C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (DLARTL_M) โ€“ C:\WINDOWS\system32\drivers\DLARTL_M.SYS (Roxio)
DRV - (DLACDBHM) โ€“ C:\WINDOWS\System32\Drivers\DLACDBHM.SYS (Roxio)
DRV - (DRVNDDM) โ€“ C:\WINDOWS\system32\drivers\DRVNDDM.SYS (Roxio)
DRV - (BASFND) โ€“ C:\Program Files\Broadcom\ASFIPMon\BASFND.sys (Broadcom Corporation)
DRV - (Sparrow) โ€“ C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) โ€“ C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) โ€“ C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) โ€“ C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) โ€“ C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) โ€“ C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) โ€“ C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) โ€“ C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) โ€“ C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) โ€“ C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) โ€“ C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) โ€“ C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) โ€“ C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) โ€“ C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) โ€“ C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=6080905
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=6080905

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=6080905
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/05 10:29:22 | 000,000,000 | โ€”D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/05 10:28:59 | 000,000,000 | โ€”D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2009/07/06 11:42:16 | 000,000,000 | โ€”D | M]

[2010/10/05 10:29:42 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Mozilla\Extensions
[2010/10/11 11:02:08 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Mozilla\Firefox\Profiles\ttld2jb8.default\extensions
[2010/10/05 10:31:22 | 000,000,000 | โ€”D | M] (Microsoft .NET Framework Assistant) โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Mozilla\Firefox\Profiles\ttld2jb8.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/10/05 10:28:59 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/10/05 06:14:12 | 000,420,575 | Rโ€” | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14506 more linesโ€ฆ
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (SnagIt) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dll (TechSmith Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Version Cue CS2] C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe (Adobe Sytems Incorporated)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKCU..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\ARO.exe (Sammsoft)
O4 - HKCU..\Run: [EFI Job Monitor] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\efjm.DLL (EFI)
O4 - HKCU..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk = C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewikiโ€ฆ - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} file://C:\Program Files\AutoCAD LT 2002\AcDcToday.ocx (AcDcToday Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashโ€ฆr/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} file://C:\Program Files\AutoCAD LT 2002\InstBanr.ocx (NOXLATE-BANR)
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} file://C:\Program Files\AutoCAD LT 2002\InstFred.ocx (InstaFred)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} file://C:\Program Files\AutoCAD LT 2002\AcPreview.ocx (AcPreview Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (\\.\globalroot\systemroot\system32\userinit.exe) - \\.\globalroot\systemroot\system32\userinit.exe ()
O24 - Desktop WallPaper: C:\Documents and Settings\Teresa Robinett\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Teresa Robinett\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 18:15:00 | 000,000,000 | โ€”- | M] () - C:\AUTOEXEC.BAT โ€“ [ NTFS ]
O32 - AutoRun File - [2007/07/02 02:34:56 | 000,000,045 | โ€”- | M] () - F:\autorun.inf โ€“ [ NTFS ]
O33 - MountPoints2\{0ec43794-b499-11dd-b944-002219024a05}\Shell\AutoRun\command - "" = F:\Launch.exe โ€“ [2004/10/21 06:38:02 | 000,126,976 | โ€”- | M] (Macrovision Corporation)
O33 - MountPoints2\{67fe1f85-8a73-11dd-b939-002219024a05}\Shell\AutoRun\command - "" = F:\Launch.exe โ€“ [2004/10/21 06:38:02 | 000,126,976 | โ€”- | M] (Macrovision Corporation)
O33 - MountPoints2\{73ef2016-77b4-11df-8fe8-002219024a05}\Shell\AutoRun\command - "" = F:\Launch.exe โ€“ [2004/10/21 06:38:02 | 000,126,976 | โ€”- | M] (Macrovision Corporation)
O33 - MountPoints2\{73ef2090-77b4-11df-8fe8-002219024a05}\Shell\AutoRun\command - "" = F:\Launch.exe โ€“ [2004/10/21 06:38:02 | 000,126,976 | โ€”- | M] (Macrovision Corporation)
O33 - MountPoints2\{77d78f92-cf97-11df-8ff0-806d6172696f}\Shell\AutoRun\command - "" = F:\Launch.exe โ€“ [2004/10/21 06:38:02 | 000,126,976 | โ€”- | M] (Macrovision Corporation)
O33 - MountPoints2\{9e9823f9-3c14-11df-8fdf-002219024a05}\Shell\AutoRun\command - "" = F:\Launch.exe โ€“ [2004/10/21 06:38:02 | 000,126,976 | โ€”- | M] (Macrovision Corporation)
O33 - MountPoints2\{ba0f3827-c3d1-11de-8fd3-002219024a05}\Shell\AutoRun\command - "" = F:\Launch.exe โ€“ [2004/10/21 06:38:02 | 000,126,976 | โ€”- | M] (Macrovision Corporation)
O33 - MountPoints2\{c29af4f2-4342-11de-8fc6-806d6172696f}\Shell\AutoRun\command - "" = F:\Launch.exe โ€“ [2004/10/21 06:38:02 | 000,126,976 | โ€”- | M] (Macrovision Corporation)
O33 - MountPoints2\{d8d6b155-9994-11df-8feb-002219024a05}\Shell\AutoRun\command - "" = F:\Launch.exe โ€“ [2004/10/21 06:38:02 | 000,126,976 | โ€”- | M] (Macrovision Corporation)
O33 - MountPoints2\{ec417767-3489-11df-8fdd-002219024a05}\Shell\AutoRun\command - "" = F:\Launch.exe โ€“ [2004/10/21 06:38:02 | 000,126,976 | โ€”- | M] (Macrovision Corporation)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] โ€“ "%1" %*
O35 - HKLM\..exefile [open] โ€“ "%1" %*
O37 - HKLM\โ€ฆcom [@ = comfile] โ€“ "%1" %*
O37 - HKLM\โ€ฆexe [@ = exefile] โ€“ "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)


SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73fa19d0-2d75-11d2-995d-00c04f98bbc9} - Web Folders
ActiveX: {767881FA-6E75-236B-7233-AD1092512AA5} - Java (Sun)
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install
ActiveX: {8b15971b-5355-4c82-8c07-7e181ea07608} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser
ActiveX: {8C0BC842-28D4-ADF8-D1A6-461A137542AA} - NetShow
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {94de52c8-2d59-4f1b-883e-79663d2d9a8c} - Fax Provider
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
ActiveX: {DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D} - Microsoft .NET Framework 1.1 Security Update (KB953297)
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\INF\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (69537929998893056)

========== Files/Folders - Created Within 90 Days ==========

[2010/10/11 13:13:34 | 000,576,512 | โ€”- | C] (OldTimer Tools) โ€“ C:\Documents and Settings\Teresa Robinett\Desktop\OTL.exe
[2010/10/06 21:31:05 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\PC Tools
[2010/10/06 21:16:49 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Trend Micro
[2010/10/06 05:30:47 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/10/05 10:29:22 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Teresa Robinett\Local Settings\Application Data\Mozilla
[2010/10/05 10:29:22 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Mozilla
[2010/10/05 10:28:58 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Mozilla Firefox
[2010/10/05 10:14:30 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Eusing Free Registry Cleaner
[2010/10/05 10:11:34 | 001,101,824 | โ€”- | C] (Woodbury Associates Limited) โ€“ C:\WINDOWS\System32\UniBox210.ocx
[2010/10/05 10:11:34 | 000,880,640 | โ€”- | C] (Woodbury Associates Limited) โ€“ C:\WINDOWS\System32\UniBox10.ocx
[2010/10/05 10:11:34 | 000,212,992 | โ€”- | C] (Woodbury Associates Limited) โ€“ C:\WINDOWS\System32\UniBoxVB12.ocx
[2010/10/05 10:02:34 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Registry Mechanic
[2010/10/05 09:59:07 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Registry Mechanic
[2010/10/05 09:59:07 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Common Files\PC Tools
[2010/10/05 09:59:06 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\TEMP
[2010/10/05 07:23:13 | 000,000,000 | -H-D | C] โ€“ C:\WINDOWS\ie8
[2010/10/05 06:54:20 | 001,913,056 | โ€”- | C] (Trend Micro Inc.) โ€“ C:\Documents and Settings\Teresa Robinett\Desktop\HousecallLauncher.exe
[2010/10/04 18:57:30 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\LocalService\Application Data\Sun
[2010/10/04 11:43:08 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Spybot - Search & Destroy
[2010/10/04 11:43:08 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/10/04 11:41:18 | 016,409,960 | โ€”- | C] (Safer Networking Limited ) โ€“ C:\Program Files\spybotsd162.exe
[2010/10/04 11:37:45 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Sammsoft
[2010/10/04 11:37:35 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Advanced Registry Optimizer
[2010/10/04 11:37:10 | 002,829,864 | โ€”- | C] (Sammsoft ) โ€“ C:\Program Files\AROTrial_bt.exe
[2010/10/04 06:57:09 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Malwarebytes
[2010/10/04 06:55:12 | 000,038,224 | โ€”- | C] (Malwarebytes Corporation) โ€“ C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/10/04 06:55:11 | 000,020,952 | โ€”- | C] (Malwarebytes Corporation) โ€“ C:\WINDOWS\System32\drivers\mbam.sys
[2010/10/04 06:55:11 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/10/04 06:55:10 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Malwarebytes' Anti-Malware
[2010/10/04 06:54:43 | 006,153,352 | โ€”- | C] (Malwarebytes Corporation ) โ€“ C:\Documents and Settings\Teresa Robinett\Desktop\mbam-setup.exe
[2010/10/02 07:18:32 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2010/10/02 06:47:48 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/10/02 06:47:47 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/10/02 05:39:57 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/10/02 05:39:55 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/08/09 12:14:19 | 000,000,000 | -HSD | C] โ€“ C:\Documents and Settings\Teresa Robinett\IECompatCache
[2009/11/09 05:42:43 | 001,925,024 | โ€”- | C] (Adobe Systems Incorporated) โ€“ C:\Program Files\install_flash_player.exe

========== Files - Modified Within 90 Days ==========

[2010/10/11 19:27:00 | 000,001,018 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1950046468-2080206288-3658921974-1007UA.job
[2010/10/11 19:12:00 | 000,000,886 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/10/11 18:12:00 | 000,000,882 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/10/11 16:21:02 | 000,001,332 | โ€”- | M] () โ€“ C:\Documents and Settings\Teresa Robinett\Desktop\Clean Registry for Free!.lnk
[2010/10/11 16:21:00 | 000,001,714 | โ€”- | M] () โ€“ C:\Documents and Settings\Teresa Robinett\Desktop\Job Monitor.lnk
[2010/10/11 16:20:59 | 000,002,337 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
[2010/10/11 16:20:53 | 000,000,298 | -HS- | M] () โ€“ C:\WINDOWS\tasks\xzwh.job
[2010/10/11 16:20:53 | 000,000,006 | -Hโ€“ | M] () โ€“ C:\WINDOWS\tasks\SA.DAT
[2010/10/11 16:20:49 | 000,002,048 | โ€“S- | M] () โ€“ C:\WINDOWS\bootstat.dat
[2010/10/11 15:11:02 | 000,000,464 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\RMSmartUpdate.job
[2010/10/11 13:27:01 | 000,000,966 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1950046468-2080206288-3658921974-1007Core.job
[2010/10/11 13:13:37 | 000,576,512 | โ€”- | M] (OldTimer Tools) โ€“ C:\Documents and Settings\Teresa Robinett\Desktop\OTL.exe
[2010/10/11 09:37:22 | 000,002,206 | โ€”- | M] () โ€“ C:\WINDOWS\System32\wpa.dbl
[2010/10/08 13:55:58 | 000,293,376 | โ€”- | M] () โ€“ C:\Documents and Settings\Teresa Robinett\Desktop\bnteqnq2.exe
[2010/10/07 22:01:42 | 015,466,496 | -Hโ€“ | M] () โ€“ C:\Documents and Settings\Teresa Robinett\NTUSER.DAT
[2010/10/07 22:01:39 | 000,000,178 | -HS- | M] () โ€“ C:\Documents and Settings\Teresa Robinett\ntuser.ini
[2010/10/06 21:16:50 | 000,001,734 | โ€”- | M] () โ€“ C:\Documents and Settings\Teresa Robinett\Desktop\HijackThis.lnk
[2010/10/06 16:21:00 | 000,067,072 | RHS- | M] () โ€“ C:\WINDOWS\System32\tftpd.dll
[2010/10/05 10:29:23 | 000,000,000 | โ€”- | M] () โ€“ C:\WINDOWS\nsreg.dat
[2010/10/05 10:29:01 | 000,001,620 | โ€”- | M] () โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/10/05 10:29:01 | 000,001,602 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/10/05 10:26:42 | 000,002,358 | โ€”- | M] () โ€“ C:\Documents and Settings\Teresa Robinett\Desktop\Google Chrome.lnk
[2010/10/05 10:26:42 | 000,002,336 | โ€”- | M] () โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/10/05 10:14:31 | 000,000,740 | โ€”- | M] () โ€“ C:\Documents and Settings\Teresa Robinett\Desktop\Eusing Free Registry Cleaner.lnk
[2010/10/05 07:24:50 | 000,000,815 | โ€”- | M] () โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/10/05 06:54:29 | 000,000,036 | โ€”- | M] () โ€“ C:\Documents and Settings\Teresa Robinett\Local Settings\Application Data\housecall.guid.cache
[2010/10/05 06:14:12 | 000,420,575 | Rโ€” | M] () โ€“ C:\WINDOWS\System32\drivers\etc\hosts
[2010/10/05 05:44:47 | 000,420,575 | Rโ€” | M] () โ€“ C:\WINDOWS\System32\drivers\etc\hosts.20101005-061412.backup
[2010/10/04 12:56:12 | 000,420,575 | Rโ€” | M] () โ€“ C:\WINDOWS\System32\drivers\etc\hosts.20101005-054447.backup
[2010/10/04 11:43:13 | 000,000,951 | โ€”- | M] () โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/10/04 11:43:13 | 000,000,933 | โ€”- | M] () โ€“ C:\Documents and Settings\Teresa Robinett\Desktop\Spybot - Search & Destroy.lnk
[2010/10/04 11:41:30 | 016,409,960 | โ€”- | M] (Safer Networking Limited ) โ€“ C:\Program Files\spybotsd162.exe
[2010/10/04 11:37:36 | 000,001,696 | โ€”- | M] () โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Microsoft\Internet Explorer\Quick Launch\Check PC For Errors.lnk
[2010/10/04 11:37:13 | 002,829,864 | โ€”- | M] (Sammsoft ) โ€“ C:\Program Files\AROTrial_bt.exe
[2010/10/04 06:55:14 | 000,000,696 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/04 05:12:11 | 001,289,904 | โ€”- | M] () โ€“ C:\WINDOWS\System32\FNTCACHE.DAT
[2010/10/02 05:34:10 | 000,000,135 | โ€”- | M] () โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\srsf.bat
[2010/09/17 01:12:40 | 001,913,056 | โ€”- | M] (Trend Micro Inc.) โ€“ C:\Documents and Settings\Teresa Robinett\Desktop\HousecallLauncher.exe
[2010/08/05 08:46:04 | 000,037,336 | โ€”- | M] () โ€“ C:\WINDOWS\System32\CleanMFT32.exe

========== Files Created - No Company Name ==========

[2010/10/11 16:21:02 | 000,001,332 | โ€”- | C] () โ€“ C:\Documents and Settings\Teresa Robinett\Desktop\Clean Registry for Free!.lnk
[2010/10/08 13:55:58 | 000,293,376 | โ€”- | C] () โ€“ C:\Documents and Settings\Teresa Robinett\Desktop\bnteqnq2.exe
[2010/10/06 21:16:50 | 000,001,734 | โ€”- | C] () โ€“ C:\Documents and Settings\Teresa Robinett\Desktop\HijackThis.lnk
[2010/10/06 16:21:00 | 000,067,072 | RHS- | C] () โ€“ C:\WINDOWS\System32\tftpd.dll
[2010/10/06 16:21:00 | 000,000,298 | -HS- | C] () โ€“ C:\WINDOWS\tasks\xzwh.job
[2010/10/05 10:29:23 | 000,000,000 | โ€”- | C] () โ€“ C:\WINDOWS\nsreg.dat
[2010/10/05 10:29:01 | 000,001,620 | โ€”- | C] () โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/10/05 10:29:01 | 000,001,602 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/10/05 10:26:42 | 000,002,358 | โ€”- | C] () โ€“ C:\Documents and Settings\Teresa Robinett\Desktop\Google Chrome.lnk
[2010/10/05 10:26:42 | 000,002,336 | โ€”- | C] () โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/10/05 10:14:31 | 000,000,740 | โ€”- | C] () โ€“ C:\Documents and Settings\Teresa Robinett\Desktop\Eusing Free Registry Cleaner.lnk
[2010/10/05 10:11:49 | 000,000,464 | โ€”- | C] () โ€“ C:\WINDOWS\tasks\RMSmartUpdate.job
[2010/10/05 10:11:34 | 000,037,336 | โ€”- | C] () โ€“ C:\WINDOWS\System32\CleanMFT32.exe
[2010/10/05 06:54:29 | 000,000,036 | โ€”- | C] () โ€“ C:\Documents and Settings\Teresa Robinett\Local Settings\Application Data\housecall.guid.cache
[2010/10/04 11:43:13 | 000,000,951 | โ€”- | C] () โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/10/04 11:43:13 | 000,000,933 | โ€”- | C] () โ€“ C:\Documents and Settings\Teresa Robinett\Desktop\Spybot - Search & Destroy.lnk
[2010/10/04 11:37:36 | 000,001,696 | โ€”- | C] () โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Microsoft\Internet Explorer\Quick Launch\Check PC For Errors.lnk
[2010/10/04 06:55:14 | 000,000,696 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/02 05:34:09 | 000,000,135 | โ€”- | C] () โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\srsf.bat
[2010/04/07 06:26:23 | 000,000,000 | โ€”- | C] () โ€“ C:\WINDOWS\the.ini
[2010/03/24 11:56:00 | 000,038,493 | โ€”- | C] () โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Comma Separated Values (Windows).ADR
[2010/03/24 10:22:15 | 000,009,378 | โ€”- | C] () โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Tab Separated Values (Windows).EML
[2010/03/24 10:04:33 | 000,009,381 | โ€”- | C] () โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Comma Separated Values (Windows).EML
[2010/03/20 20:33:14 | 001,337,728 | โ€”- | C] () โ€“ C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/08/25 11:05:57 | 006,154,256 | โ€”- | C] () โ€“ C:\Program Files\CADtools6.zip
[2009/06/15 05:22:02 | 000,000,138 | โ€”- | C] () โ€“ C:\Documents and Settings\Teresa Robinett\Local Settings\Application Data\fusioncache.dat
[2009/02/05 12:25:23 | 009,041,248 | โ€”- | C] () โ€“ C:\Program Files\winzip120.exe
[2008/10/30 05:34:00 | 022,468,912 | โ€”- | C] () โ€“ C:\Program Files\snagit.exe
[2008/09/29 12:30:31 | 000,008,192 | โ€”- | C] () โ€“ C:\Documents and Settings\Teresa Robinett\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/09/24 13:24:34 | 000,079,360 | โ€”- | C] () โ€“ C:\WINDOWS\System32\acdbres.dll
[2008/09/05 01:31:07 | 000,000,061 | โ€”- | C] () โ€“ C:\WINDOWS\smscfg.ini
[2008/09/05 01:29:20 | 000,000,234 | โ€”- | C] () โ€“ C:\WINDOWS\wininit.ini
[2008/09/05 01:11:15 | 000,001,122 | โ€”- | C] () โ€“ C:\WINDOWS\System32\OEMINFO.INI
[2004/08/11 18:24:19 | 000,000,791 | โ€”- | C] () โ€“ C:\WINDOWS\orun32.ini
[2004/08/11 18:11:31 | 000,001,793 | โ€”- | C] () โ€“ C:\WINDOWS\System32\fxsperf.ini
[2000/09/18 16:50:28 | 000,202,752 | โ€”- | C] () โ€“ C:\WINDOWS\System32\Zlib.dll

========== LOP Check ==========

[2010/03/27 20:16:03 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\Amazon
[2009/07/06 11:42:14 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\ESET
[2008/10/30 05:35:58 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\TechSmith
[2010/10/11 15:11:01 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\TEMP
[2009/02/05 12:27:18 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\All Users\Application Data\WinZip
[2008/11/03 12:02:21 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Opera
[2010/10/05 10:02:34 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Registry Mechanic
[2010/10/04 11:37:45 | 000,000,000 | โ€”D | M] โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Sammsoft
[2010/10/11 15:11:02 | 000,000,464 | โ€”- | M] () โ€“ C:\WINDOWS\Tasks\RMSmartUpdate.job
[2010/10/11 16:20:53 | 000,000,298 | -HS- | M] () โ€“ C:\WINDOWS\Tasks\xzwh.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2004/08/11 18:15:00 | 000,000,000 | โ€”- | M] () โ€“ C:\AUTOEXEC.BAT
[2008/09/15 11:02:46 | 000,000,211 | RHS- | M] () โ€“ C:\boot.ini
[2004/08/11 18:15:00 | 000,000,000 | โ€”- | M] () โ€“ C:\CONFIG.SYS
[2008/09/05 01:12:32 | 000,007,447 | RHโ€“ | M] () โ€“ C:\dell.sdr
[2008/09/24 13:14:58 | 000,004,128 | โ€”- | M] () โ€“ C:\INFCACHE.1
[2004/08/11 18:15:00 | 000,000,000 | -Hโ€“ | M] () โ€“ C:\IO.SYS
[2004/08/11 18:15:00 | 000,000,000 | -Hโ€“ | M] () โ€“ C:\MSDOS.SYS
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () โ€“ C:\NTDETECT.COM
[2010/04/26 06:45:36 | 000,250,048 | RHS- | M] () โ€“ C:\ntldr
[2010/10/11 16:20:43 | 1996,488,703 | -HS- | M] () โ€“ C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | โ€”- | M] () โ€“ C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | โ€”- | M] () โ€“ C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | โ€”- | M] () โ€“ C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | โ€”- | M] () โ€“ C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/11 18:14:22 | 000,000,067 | -HS- | M] () โ€“ C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | โ€”- | M] (Microsoft Corporation) โ€“ C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 06:50:03 | 000,597,504 | โ€”- | M] (Microsoft Corporation) โ€“ C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2010/10/04 11:37:13 | 002,829,864 | โ€”- | M] (Sammsoft ) โ€“ C:\Program Files\AROTrial_bt.exe
[2009/08/25 11:05:57 | 006,154,256 | โ€”- | M] () โ€“ C:\Program Files\CADtools6.zip
[2009/11/09 05:42:43 | 001,925,024 | โ€”- | M] (Adobe Systems Incorporated) โ€“ C:\Program Files\install_flash_player.exe
[2008/10/30 05:34:03 | 022,468,912 | โ€”- | M] () โ€“ C:\Program Files\snagit.exe
[2010/10/04 11:41:30 | 016,409,960 | โ€”- | M] (Safer Networking Limited ) โ€“ C:\Program Files\spybotsd162.exe
[2009/02/05 12:25:23 | 009,041,248 | โ€”- | M] () โ€“ C:\Program Files\winzip120.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/11 18:06:14 | 000,094,208 | โ€”- | M] () โ€“ C:\WINDOWS\system32\config\default.sav
[2010/04/26 06:38:36 | 016,777,216 | -HS- | M] () โ€“ C:\WINDOWS\system32\config\gudxoooz.sav
[2004/08/11 18:06:14 | 000,659,456 | โ€”- | M] () โ€“ C:\WINDOWS\system32\config\software.sav
[2004/08/11 18:06:14 | 000,876,544 | โ€”- | M] () โ€“ C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/04/26 06:52:33 | 000,000,272 | -HS- | M] () โ€“ C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/26 07:05:11 | 000,000,119 | -HS- | M] () โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/11 18:20:42 | 000,000,079 | โ€”- | M] () โ€“ C:\Documents and Settings\Teresa Robinett\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/10/08 13:55:58 | 000,293,376 | โ€”- | M] () โ€“ C:\Documents and Settings\Teresa Robinett\Desktop\bnteqnq2.exe
[2010/09/17 01:12:40 | 001,913,056 | โ€”- | M] (Trend Micro Inc.) โ€“ C:\Documents and Settings\Teresa Robinett\Desktop\HousecallLauncher.exe
[2010/04/29 17:03:06 | 006,153,352 | โ€”- | M] (Malwarebytes Corporation ) โ€“ C:\Documents and Settings\Teresa Robinett\Desktop\mbam-setup.exe
[2010/10/11 13:13:37 | 000,576,512 | โ€”- | M] (OldTimer Tools) โ€“ C:\Documents and Settings\Teresa Robinett\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >
[2004/08/04 06:00:00 | 000,000,791 | โ€”- | M] () โ€“ C:\WINDOWS\addins\fxsext.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2010/04/26 07:05:11 | 000,000,122 | -HS- | M] () โ€“ C:\Documents and Settings\Teresa Robinett\Favorites\Desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2010/10/11 20:53:54 | 000,491,520 | โ€”- | M] () โ€“ C:\Documents and Settings\Teresa Robinett\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< %systemroot%\system32\winlog\*.* >

< %systemroot%\system32\Language\*.* >

< %systemroot%\system32\Settings\*.* >

< %systemroot%\system32\*.quo >

< %SYSTEMROOT%\AppPatch\*.exe >

< %SYSTEMROOT%\inf\*.exe >
[2008/04/13 20:12:38 | 000,208,896 | โ€”- | M] (Microsoft Corporation) โ€“ C:\WINDOWS\inf\unregmp2.exe

< %SYSTEMROOT%\Installer\*.exe >

< %systemroot%\system32\config\*.bak2 >

< %systemroot%\system32\Computers\*.* >

< %SystemRoot%\system32\Sound\*.* >

< %SystemRoot%\system32\SpecialImg\*.* >

< %SystemRoot%\system32\code\*.* >

< %SystemRoot%\system32\draft\*.* >

< %SystemRoot%\system32\MSSSys\*.* >

< %ProgramFiles%\Javascript\*.* >

< %systemroot%\pchealth\helpctr\System\*.exe /s >

< %systemroot%\Web\*.exe >

< %systemroot%\system32\msn\*.* >

< %systemroot%\system32\*.tro >

< %AppData%\Microsoft\Installer\msupdates\*.* >

< %ProgramFiles%\Messenger\*.exe >
[2008/04/13 20:12:28 | 001,695,232 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Program Files\Messenger\msmsgs.exe

< %systemroot%\system32\systhem32\*.* >

< %systemroot%\system\*.exe >

< %USERPROFILE%\Templates\*.tmp >

< %SYSTEMDRIVE%\explorexxx.exe\*.* >

< %Windir%\Installer\*.tmp >

< %systemroot%\System32\*.xco >

< %ProgramFiles%\system32\*.* >

< %systemroot%\System32\windos\*.* >

< %SystemRoot%\system32\sandbox\*.* >

< %SystemRoot%\system32\*.amo >

< %SystemRoot%\system32\Windows Live\*.* >

< %ProgramFiles%\logs\*.* >

< %ProgramFiles%\Bifrost\*.* >

< %SystemRoot%\system32\*.goo >

< %systemroot%\system32\IME\*.* >

< %systemroot%\BackUp\*.* >

< %systemroot%\system32\*.ico >

< %systemroot%\system\*.dat >

< %systemroot%\system\*.exe >

< %AppData%\Macromedia\Common\*.* >

< %SYSTEMDRIVE%\dir\*.* /s >

< %systemroot%\system32\ras\*.exe >

< %SYSTEMDRIVE%\MFILES\*.* >

< %SYSTEMDRIVE%\mDNSRespon.exe\*.* >

< %systemroot%\system32\services\*.* >

< %systemroot%\Spooler\*.* >

< %ProgramFiles%\system32\*.* >

< %systemroot%\system32\Setup\*.dll /x >

< %systemroot%\system32\*.mine >

< %SYSTEMDRIVE%\cleansweep.exe\*.* >

< %systemroot%\system32\ras\*.dll >

< %systemroot%\system32\ras\*.drv >

< %systemroot%\*.iq >

< %systemroot%\system32\XP\*.* >

< %SYSTEMDRIVE%\Extracted\*.* >

< %systemroot%\system32\windows\*.* >

< %systemroot%\logs\*.* >

< %SYSTEMDRIVE%\Win.Msi\*.* >

< %systemroot%\regedit\*.* >

< %systemroot%\system32\skype\*.* >

< %AppData%\Adobe\dlluplwin25\*.* >

< %UserProfile%\*.dat >
[2010/10/07 22:01:42 | 015,466,496 | -Hโ€“ | M] () โ€“ C:\Documents and Settings\Teresa Robinett\NTUSER.DAT

< %UserProfile%\*.dll >

< %systemroot%\system32\*.sxo >

< %SYSTEMDRIVE%\Gazma\*.* /s >

< %systemroot%\system32\spynet\*.* >

< %systemroot%\system32\System\*.* >

< %appdata%\Microsoft\Windows\*.* >

< %systemroot%\system32\WinDir\*.* >

< %systemroot%\_\*.* >

< %systemroot%\system32\windows32\*.* >

< %ProgramFiles%\win\*.* >

< %AppData%\Microsoft\CD Burning\*.* >

< %systemroot%\*.cab >

< %systemroot%\K.Backup\*.* >

< %ProgramFiles%\Massenger\*.* >

< %systemroot%\System32\*.doc >

< %systemroot%\Office12\*.* >

< %systemroot%\System32\Rundl32.exe\*.* >

< %ProgramFiles%\yahoo.net\*.* >

< %systemroot%\system32\*.igo >

< %systemroot%\*.rew >

< %systemroot%\System32\spool\DRIVERS\W32X86\3\*.exe >
[2004/07/16 00:50:00 | 000,495,616 | โ€”- | M] (CANON INC.) โ€“ C:\WINDOWS\system32\spool\drivers\w32x86\3\CPC10D.EXE
[2004/07/16 00:50:00 | 000,872,448 | โ€”- | M] (CANON INC.) โ€“ C:\WINDOWS\system32\spool\drivers\w32x86\3\CPC10Q.EXE
[2004/07/16 00:50:00 | 000,450,560 | โ€”- | M] (CANON INC.) โ€“ C:\WINDOWS\system32\spool\drivers\w32x86\3\CPC10V.EXE

< %USERPROFILE%\.COMMgr\*.* >

< %USERPROFILE%\Desktop\*.bat >

< %PROGRAMFILES%\Common Files\Real\visualizations\*.* >

< %PROGRAMFILES%\Internet Explorer\*.Jmp >

< %PROGRAMFILES%\Windows NT\system\*.dll >

< %systemroot%\system32\*.ext >

< %systemroot%\system32\Com\*.cfg >

< %systemroot%\system32\btz\*.* >

< %systemroot%\system32\EMP\*.* >

< %systemroot%\system32\expo\*.* >

< %systemroot%\system32\inet2\*.* >

< %systemroot%\system32\xrem\*.* >

< %ProgramFiles%\Microsoft\*.* >

< %systemroot%\usgwmt\*.* >

< %ProgramFiles%\B\*.* >

< %SYSTEMDRIVE%\lspp\*.* >

< %systemroot%\Kral\*.* >

< %SYSTEMDRIVE%\windowsdvd.exe\*.* >

< %systemroot%\system32\*.ipo >

< %SYSTEMDRIVE%\usxxxxxxxx.exe\*.* >

< %systemroot%\system32\*.mof >

< %systemroot%\*.atm >

< %systemroot%\system32\svhost\*.* >

< %ProgramFiles%\system32\*.* >

< %ProgramFiles%\Docmentt\*.* >

< %systemroot%\Help\*.vbs >

< %ProgramFiles%\Windows WinSxs\*.* /s >

< %ProgramFiles%\Outlook Express\IDT\*.* /s >

< %ProgramFiles%\Microsoft Office\365\*.* /s >

< %ProgramFiles%\Windows Live\*.* >

< %systemroot%\system32\win32\*.* >

< %SYSTEMDRIVE%\RECYCLER\*.* >

< %systemroot%\Fresh1\*.* >

< %ProgramFiles%\Kekj\*.* /s >

< %systemroot%\GDU\*.* >

< %systemroot%\KA\*.* >

< %systemroot%\R\*.* >

< %systemroot%\system32\*.fyo >

< %USERPROFILE%\System\*.* >

< %systemroot%\Source\*.* >

< %systemroot%\system32\ac\*.* >

< %ProgramFiles%\MSDN\*.* >

< %AppData%\AdobeUM\winvcldll54\*.* /s >

< %ProgramFiles%\Internet Explorer\*.ico >

< %systemroot%\system32\*.ojo >

< %systemroot%\system32\d323s\*.* >

< %systemroot%\system32\re\*.* >

< %UserProfile%\Microsoft\*.dll >

< %UserProfile%\Microsoft\*.log >

< %systemroot%\Bios\*.* >

< %ProgramFiles%\Spool\*.* >

< %ProgramFiles%\promp3\*.* >

< %SYSTEMDRIVE%\Driver\*.* /s >

< %SYSTEMDRIVE%\inetserver.exe\*.* >

< %systemroot%\java\trustlib\*.* >

< %ProgramFiles%\Common Files\designer\*.exe >

< %ProgramFiles%\*. >
[2009/08/25 11:06:51 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Adobe
[2009/02/18 12:34:02 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Adobe Media Player
[2010/10/04 11:37:36 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Advanced Registry Optimizer
[2008/09/05 01:27:01 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Analog Devices
[2008/12/29 06:54:01 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\AutoCAD LT 2002
[2008/09/05 01:26:39 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Broadcom
[2008/09/15 15:06:50 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Canon
[2010/10/05 09:59:07 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Common Files
[2004/08/11 18:12:04 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\ComPlus Applications
[2008/09/05 01:29:48 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\CyberLink
[2008/09/05 01:29:27 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Dell
[2009/07/07 18:01:49 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\ESET
[2010/10/05 10:22:51 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Eusing Free Registry Cleaner
[2010/02/16 15:52:47 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Google
[2008/09/19 15:10:56 | 000,000,000 | -H-D | M] โ€“ C:\Program Files\InstallShield Installation Information
[2008/09/05 01:26:33 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Intel
[2010/10/05 07:24:30 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Internet Explorer
[2008/09/05 01:25:30 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Java
[2010/10/04 06:55:15 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Malwarebytes' Anti-Malware
[2010/04/26 06:55:22 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Messenger
[2004/08/11 18:15:24 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\microsoft frontpage
[2008/09/19 13:41:04 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Microsoft Office
[2008/09/19 13:41:02 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Microsoft Visual Studio
[2008/09/19 13:41:10 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Microsoft Works
[2008/09/19 13:40:54 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Microsoft.NET
[2010/04/26 07:00:30 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Movie Maker
[2010/10/05 10:29:01 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Mozilla Firefox
[2010/03/20 20:32:55 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\MSBuild
[2004/08/11 18:11:30 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\MSN
[2004/08/11 18:11:36 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\MSN Gaming Zone
[2008/09/05 01:23:22 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\MSXML 6.0
[2010/04/26 06:47:08 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\NetMeeting
[2008/12/11 13:06:45 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\New Folder
[2004/08/11 18:11:50 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Online Services
[2010/04/26 06:59:28 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Outlook Express
[2009/06/15 05:21:54 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Pro Imaging Powertoys
[2010/03/20 20:32:49 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Reference Assemblies
[2010/10/05 15:11:02 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Registry Mechanic
[2008/09/05 01:29:19 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Roxio
[2008/09/05 01:29:14 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Sonic
[2010/10/04 11:44:25 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Spybot - Search & Destroy
[2008/10/30 05:35:57 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\TechSmith
[2010/10/06 21:16:49 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Trend Micro
[2010/03/27 20:17:30 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\TurboTax
[2004/08/11 18:20:34 | 000,000,000 | -H-D | M] โ€“ C:\Program Files\Uninstall Information
[2008/09/24 13:24:35 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Volo View Express
[2008/09/24 13:25:04 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\WexTech
[2010/04/26 06:52:15 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Windows Media Player
[2010/04/26 06:47:05 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\Windows NT
[2004/08/11 18:13:20 | 000,000,000 | -H-D | M] โ€“ C:\Program Files\WindowsUpdate
[2008/09/25 10:04:44 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\WinZip
[2004/08/11 18:15:24 | 000,000,000 | โ€”D | M] โ€“ C:\Program Files\xerox

< %systemroot%\system32\*.tso >

< %ALLUSERSPROFILE%\Documents\Server\*.* >

< %systemroot%\*.pif >
[2004/08/04 06:00:00 | 000,000,707 | โ€”- | M] () โ€“ C:\WINDOWS\_default.pif

< %systemroot%\system32\n7533\*.* >

< %systemroot%\Us18336\*.* >

< %systemroot%\system32\*.zip >

< %systemroot%\system32\*.wgo >

< %ProgramFiles%\Microsoft Office\OFFICE11\*.* >

< %systemroot%\system32\dllcache\*.com >

< %systemroot%\system32\dllchache\*.* >

< %systemroot%\system32\038840\*.* >

< %systemroot%\system32\13E92A\*.* >

< %systemroot%\system32\1CB5AD\*.* >

< %systemroot%\system32\52682A\*.* >

< %USERPROFILE%\My Documents\*.htm >

< %SYSTEMDRIVE%\Mr_CF\*.* >

< %USERPROFILE%\My Documents\*.dll >

< %USERPROFILE%\My Documents\*.ccc >

< %systemroot%\system32\Sis\*.* >

< %systemroot%\Microsft\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-04-26 11:01:39

========== Alternate Data Streams ==========

@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1

< End of report >


Here is the Extras txt log:
OTL Extras logfile created on: 10/11/2010 9:01:28 PM - Run 1
OTL by OldTimer - Version 3.2.15.0 Folder = C:\Documents and Settings\Teresa Robinett\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 77.00% Memory free
9.00 Gb Paging File | 8.00 Gb Available in Paging File | 92.00% Paging File free
Paging file location(s): C:\pagefile.sys 6000 10000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.76 Gb Total Space | 123.70 Gb Free Space | 53.14% Space Free | Partition Type: NTFS
Drive D: | 3.75 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF1.02
Drive F: | 698.64 Gb Total Space | 462.87 Gb Free Space | 66.25% Space Free | Partition Type: NTFS
Drive G: | 122.01 Mb Total Space | 16.53 Mb Free Space | 13.55% Space Free | Partition Type: FAT32

Computer Name: D43KL5H1 | User Name: Teresa Robinett | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | File Age = 90 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] โ€“ C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] โ€“ "%1" %*
cmdfile [open] โ€“ "%1" %*
comfile [open] โ€“ "%1" %*
exefile [open] โ€“ "%1" %*
htmlfile โ€“ "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] โ€“ "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] โ€“ "%1" %*
regfile [merge] โ€“ Reg Error: Key error.
scrfile [config] โ€“ "%1"
scrfile [install] โ€“ rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] โ€“ "%1" /S
txtfile โ€“ Reg Error: Key error.
Unknown [openas] โ€“ %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] โ€“ %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] โ€“ %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] โ€“ %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] โ€“ %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe" = C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe:*:Enabled:CyberLink PowerDVD DX โ€“ (CyberLink Corp.)
"C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" = C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe:*:Enabled:CyberLink PowerDVD DX Resident Program โ€“ (CyberLink Corp.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe" = C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe:*:Enabled:CyberLink PowerDVD DX โ€“ (CyberLink Corp.)
"C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" = C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe:*:Enabled:CyberLink PowerDVD DX Resident Program โ€“ (CyberLink Corp.)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook โ€“ (Microsoft Corporation)
"C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe" = C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe:*:Enabled:Adobe Version Cue CS2 โ€“ (Adobe Systems Incorporated)
"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server โ€“ (Intuit Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0134A1A1-C283-4A47-91A1-92F19F960372}" = Adobe Creative Suite 2
"{0394CDC8-FABD-4ED8-B104-03393876DFDF}" = Roxio Creator Tools
"{07159635-9DFE-4105-BFC0-2817DB540C68}" = Roxio Activation Module
"{0D397393-9B50-4C52-84D5-77E344289F87}" = Roxio Creator Data
"{0E92C4A1-405F-11D8-A7E6-0060081EB30F}" = Color Network ScanGear Ver.1.5
"{177D1318-3E4B-4A7C-A300-AC4E21BE090B}" = Broadcom Management Programs
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{2E5A5B57-57FC-4C79-A239-9DB280ADEC2A}" = Microsoft RAW Image Thumbnailer and Viewer for Windows XP Version 1.0 (Build 50)
"{2EEBAC31-3EEF-4118-91CB-1A286A507DB2}" = ESET NOD32 Antivirus
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Javaโ„ข 6 Update 5
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3818E081-EAA2-012B-AD94-000000000000}" = TurboTax 2009 WinBizFedFormset
"{3830D551-EAA2-012B-AD9A-000000000000}" = TurboTax 2009 WinBizReleaseEngine
"{383CBC31-EAA2-012B-AD9D-000000000000}" = TurboTax 2009 WinBizTaxSupport
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{3C5A81D1-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{5783F2D7-0109-0409-0000-0060B0CE6BBA}" = AutoCAD LT 2002
"{619CDD8A-14B6-43A1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{7F4C8163-F259-49A0-A018-2857A90578BC}" = Adobe InDesign CS2
"{83FFCFC7-88C6-41C6-8752-958A45325C82}" = Roxio Creator Audio
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_STANDARDR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_STANDARDR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_STANDARDR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_STANDARDR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_STANDARDR_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_STANDARDR_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_STANDARDR_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_STANDARDR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_STANDARDR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intelยฎ Matrix Storage Manager
"{91120000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2007
"{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{92FD71D5-ED7E-40B2-8DF3-4B5E6F684367}" = Dell ETS Factory Installation
"{9455959E-D588-EFAE-329C-F66CC797F32A}" = Adobe Media Player
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = iSEEK AnswerWorks English Runtime
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-1033-0000-7760-000000000003}" = Adobe Acrobat 8 Professional
"{ADBE46EE-54E0-4610-B436-D7E93D829100}" = Adobe Version Cue CS2
"{ADDD6985-3A28-44D0-A1BA-FDD19A820491}" = SnagIt 9
"{B2F5D08C-7E79-4FCD-AAF4-57AD35FF0601}" = Adobe Illustrator CS2
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B4551840-1AB7-11D4-AFE2-00A0C9D7760D}" = Network ScanGear Ver.1.00
"{B74D4E10-6884-0000-0000-000000000103}" = Adobe Bridge 1.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C49DAA9C-5BA8-459A-8244-E57B69DF0F04}" = Suite Specific
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B7}" = WinZip 12.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E56D5DC8-4C73-44B1-B650-AAD75C7A2701}" = Broadcom ASF Management Applications
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"Adobe Acrobat 8 Professional" = Adobe Acrobat 8 Professional
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"Advanced Registry Optimizer_is1" = Advanced Registry Optimizer
"Amazon Games & Software Downloader_is1" = Amazon Games & Software Downloader
"AnswerWorks" = AnswerWorks Runtime
"Eusing Free Registry Cleaner" = Eusing Free Registry Cleaner
"HijackThis" = HijackThis 2.0.2
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.10)" = Mozilla Firefox (3.6.10)
"NVIDIA Drivers" = NVIDIA Drivers
"Registry Mechanic_is1" = Registry Mechanic 10.0
"SearchAssist" = SearchAssist
"STANDARDR" = Microsoft Office Standard 2007
"TurboTax 2009" = TurboTax 2009
"TurboTax Business 2009" = TurboTax Business 2009
"Volo View Express" = Volo View Express
"WIC" = Windows Imaging Component
"Windows XP Service Pack" = Windows XP Service Pack 3

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/11/2010 9:40:26 AM | Computer Name = D43KL5H1 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 10/11/2010 9:40:26 AM | Computer Name = D43KL5H1 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 10/11/2010 9:40:26 AM | Computer Name = D43KL5H1 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 10/11/2010 9:40:26 AM | Computer Name = D43KL5H1 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 10/11/2010 9:40:26 AM | Computer Name = D43KL5H1 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 10/11/2010 9:52:25 AM | Computer Name = D43KL5H1 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x00023845.

Error - 10/11/2010 4:21:17 PM | Computer Name = D43KL5H1 | Source = Microsoft Office 12 | ID = 2001
Description = Rejected Safe Mode action : Microsoft Office Outlook.

Error - 10/11/2010 8:40:04 PM | Computer Name = D43KL5H1 | Source = Application Hang | ID = 1002
Description = Hanging application OUTLOOK.EXE, version 12.0.6316.5000, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 10/11/2010 8:44:11 PM | Computer Name = D43KL5H1 | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.2.3909, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 10/11/2010 8:45:30 PM | Computer Name = D43KL5H1 | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.2.3909, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ OSession Events ]
Error - 2/6/2009 8:21:04 AM | Computer Name = D43KL5H1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6214.1000, Microsoft Office Version: 12.0.6215.1000. This session lasted 57883
seconds with 2220 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 10/9/2010 8:26:46 AM | Computer Name = D43KL5H1 | Source = DCOM | ID = 10010
Description = The server {FFF2D28F-E4EE-44D9-8104-8E71556757F6} did not register
with DCOM within the required timeout.

Error - 10/9/2010 8:38:52 AM | Computer Name = D43KL5H1 | Source = DCOM | ID = 10010
Description = The server {FFF2D28F-E4EE-44D9-8104-8E71556757F6} did not register
with DCOM within the required timeout.

Error - 10/9/2010 8:50:52 AM | Computer Name = D43KL5H1 | Source = DCOM | ID = 10010
Description = The server {FFF2D28F-E4EE-44D9-8104-8E71556757F6} did not register
with DCOM within the required timeout.

Error - 10/9/2010 9:02:52 AM | Computer Name = D43KL5H1 | Source = DCOM | ID = 10010
Description = The server {FFF2D28F-E4EE-44D9-8104-8E71556757F6} did not register
with DCOM within the required timeout.

Error - 10/9/2010 9:14:52 AM | Computer Name = D43KL5H1 | Source = DCOM | ID = 10010
Description = The server {FFF2D28F-E4EE-44D9-8104-8E71556757F6} did not register
with DCOM within the required timeout.

Error - 10/9/2010 9:26:52 AM | Computer Name = D43KL5H1 | Source = DCOM | ID = 10010
Description = The server {FFF2D28F-E4EE-44D9-8104-8E71556757F6} did not register
with DCOM within the required timeout.

Error - 10/9/2010 9:38:52 AM | Computer Name = D43KL5H1 | Source = DCOM | ID = 10010
Description = The server {FFF2D28F-E4EE-44D9-8104-8E71556757F6} did not register
with DCOM within the required timeout.

Error - 10/9/2010 9:50:52 AM | Computer Name = D43KL5H1 | Source = DCOM | ID = 10010
Description = The server {FFF2D28F-E4EE-44D9-8104-8E71556757F6} did not register
with DCOM within the required timeout.

Error - 10/11/2010 9:39:13 AM | Computer Name = D43KL5H1 | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 10/11/2010 8:33:48 PM | Computer Name = D43KL5H1 | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.1.102 on
the Network Card with network address 002219024A05.


< End of report >

Thanks again for the help!
I see you have been playing around with Registry Cleaners, not a good idea unless your a windows expert, remove the wrong entries and you can make your system inoperable, remove not needed entries and not matter what you have read you will see no difference in system performance. You should uninstall those programs .

There are a few things on your log that are questionable, lets do this



Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Here is the log from the combofix log: ComboFix 10-10-11.05 - Teresa Robinett 10/12/2010 16:18:07.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2820 [GMT -4:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} * Resident AV is active . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Teresa Robinett\Application Data\srsf.bat F:\Autorun.inf Infected copy of c:\windows\system32\drivers\isapnp.sys was found and disinfected Restored copy from - Kitty had a snack :p . ((((((((((((((((((((((((( Files Created from 2010-09-12 to 2010-10-12 ))))))))))))))))))))))))))))))) . 2010-10-07 01:31 . 2010-10-07 01:31 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\All Users\Application Data\PC Tools 2010-10-07 01:16 . 2010-10-07 01:16 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Trend Micro 2010-10-06 20:26 . 2010-10-06 20:26 โ€”โ€”โ€“ d-shโ€“w- c:\windows\system32\config\systemprofile\PrivacIE 2010-10-06 20:21 . 2010-10-06 20:21 67072 โ€“sha-r- c:\windows\system32\tftpd.dll 2010-10-06 09:30 . 2010-10-06 09:31 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe 2010-10-05 14:29 . 2010-10-05 14:29 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\Teresa Robinett\Local Settings\Application Data\Mozilla 2010-10-05 14:14 . 2010-10-05 14:22 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Eusing Free Registry Cleaner 2010-10-05 14:11 . 2010-08-05 12:46 37336 โ€”-a-w- c:\windows\system32\CleanMFT32.exe 2010-10-05 14:11 . 2008-04-02 19:54 1101824 โ€”-a-w- c:\windows\system32\UniBox210.ocx 2010-10-05 14:11 . 2008-04-02 19:53 212992 โ€”-a-w- c:\windows\system32\UniBoxVB12.ocx 2010-10-05 14:11 . 2008-04-02 19:53 880640 โ€”-a-w- c:\windows\system32\UniBox10.ocx 2010-10-05 14:11 . 2008-09-18 01:17 658432 โ€”-a-w- c:\windows\system32\MSCOMCT2.OCX 2010-10-05 14:02 . 2010-10-05 14:02 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\Teresa Robinett\Application Data\Registry Mechanic 2010-10-05 13:59 . 2010-10-05 14:11 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Common Files\PC Tools 2010-10-05 13:59 . 2010-10-12 19:11 โ€”โ€”โ€“ dโ€”a-w- c:\documents and settings\All Users\Application Data\TEMP 2010-10-05 11:23 . 2010-10-05 11:23 โ€”โ€”โ€“ dc-hโ€“w- c:\windows\ie8 2010-10-04 15:43 . 2010-10-05 10:02 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2010-10-04 15:43 . 2010-10-04 15:44 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Spybot - Search & Destroy 2010-10-04 15:41 . 2010-10-04 15:41 16409960 โ€”-a-w- c:\program files\spybotsd162.exe 2010-10-04 15:37 . 2010-10-04 15:37 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\Teresa Robinett\Application Data\Sammsoft 2010-10-04 15:37 . 2010-10-04 15:37 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Advanced Registry Optimizer 2010-10-04 15:37 . 2010-10-04 15:37 2829864 โ€”-a-w- c:\program files\AROTrial_bt.exe 2010-10-04 10:57 . 2010-10-04 10:57 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\Teresa Robinett\Application Data\Malwarebytes 2010-10-04 10:55 . 2010-04-29 19:39 38224 โ€”-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-10-04 10:55 . 2010-10-04 10:55 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\All Users\Application Data\Malwarebytes 2010-10-04 10:55 . 2010-04-29 19:39 20952 โ€”-a-w- c:\windows\system32\drivers\mbam.sys 2010-10-04 10:55 . 2010-10-04 10:55 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Malwarebytes' Anti-Malware 2010-10-02 11:18 . 2010-10-02 11:19 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe 2010-10-02 09:29 . 2010-10-02 09:29 โ€”โ€”โ€“ d-shโ€“w- c:\windows\system32\config\systemprofile\IETldCache . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032] "Google Update"="c:\documents and settings\Teresa Robinett\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-25 133104] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-05 68856] "EFI Job Monitor"="c:\windows\System32\spool\DRIVERS\W32X86\3\efjm.dll" [2004-08-10 2510848] "AROReminder"="c:\program files\Advanced Registry Optimizer\ARO.exe" [2009-10-22 2132480] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe Version Cue CS2"="c:\program files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [2005-04-04 856064] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-01-13 8523776] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat.exe [2008-9-29 295606] Adobe Acrobat Synchronizer.lnk - c:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-23 734872] Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664] WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-9-11 525664] [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"= "c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [5/14/2009 3:47 PM 107256] R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [5/14/2009 3:49 PM 94360] R2 Amazon Download Agent;Amazon Download Agent;f:\tax\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [3/27/2010 8:15 PM 401920] R2 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;c:\program files\Broadcom\ASFIPMon\AsfIpMon.exe [6/20/2007 3:30 PM 79168] R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [5/14/2009 3:47 PM 731840] R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [10/5/2010 10:11 AM 583640] S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/16/2010 3:52 PM 135664] . Contents of the 'Scheduled Tasks' folder 2010-10-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-16 19:52] 2010-10-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-16 19:52] 2010-10-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1950046468-2080206288-3658921974-1007Core.job - c:\documents and settings\Teresa Robinett\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-25 10:19] 2010-10-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1950046468-2080206288-3658921974-1007UA.job - c:\documents and settings\Teresa Robinett\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-25 10:19] 2010-10-12 c:\windows\Tasks\RMSmartUpdate.job - c:\program files\Registry Mechanic\Update.exe [2010-10-05 12:46] . . โ€”โ€”- Supplementary Scan โ€”โ€”- . uStart Page = hxxp://www.yahoo.com/ uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=6080905 uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Google Sidewikiโ€ฆ - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html Trusted Zone: intuit.com\ttlc FF - ProfilePath - c:\documents and settings\Teresa Robinett\Application Data\Mozilla\Firefox\Profiles\ttld2jb8.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - prefs.js: network.proxy.type - 0 FF - plugin: c:\documents and settings\Teresa Robinett\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ โ€”- FIREFOX POLICIES โ€”- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xnโ€“mgbaam7a8h", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xnโ€“mgberp4a5d4ar", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); . . โ€”โ€”- File Associations โ€”โ€”- . .scr=AutoCADLTScriptFile . - - - - ORPHANS REMOVED - - - - WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file) . Completion time: 2010-10-12 16:24:40 ComboFix-quarantined-files.txt 2010-10-12 20:24 Pre-Run: 132,882,403,328 bytes free Post-Run: 133,532,905,472 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect - - End Of File - - EE28D27D8B44F622BB2DDC41099CB465
Hi,

Got to tell ya, these dirtbags that write this garbage are infecting anything they can , next will be the filling in your teeth . isapnp.sys, was infected, its related to this. PNP ISA Bus Driver

I need to go over your CF log , it takes some time, in the meantime do this please.


Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean





Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please
I've run both programs and TFC found some things but Malware bytes did not. However, I have been running this everyday. I did check for and download the updates before running it again tonight. The last time it found the trojan virus was on 10-6. So below is the log from tonight and below that will be the log from 10-6 where it found the virus. Tonight's log: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4806 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 10/12/2010 8:38:10 PM mbam-log-2010-10-12 (20-38-10).txt Scan type: Quick scan Objects scanned: 146591 Time elapsed: 2 minute(s), 6 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Here is the log from Wednesday, 10-6: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4739 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 10/6/2010 6:48:31 PM mbam-log-2010-10-06 (18-48-31).txt Scan type: Full scan (C:\|) Objects scanned: 232950 Time elapsed: 35 minute(s), 17 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 4 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed],[removed] -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.244,93.188.160.54 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{270af4e2-4890-43e6-8d31-6bd790c04da5}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed],[removed] -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{270af4e2-4890-43e6-8d31-6bd790c04da5}\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.244,93.188.160.54 -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job (Trojan.Downloader) -> Quarantined and deleted successfully. C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
Good Morning,

TFC is just a temp file cleaner, running it and getting rid of a lot of junk will sometimes speed things up, also sometimes malware hides there.



This is what running Malwarebytes removed, your computer was hijacked by cybercriminals from the uKraine


93.188.162.0 - 93.188.162.255
Promnet Ltd.

Ondrej Voloshin
Ekaterininskaya str., 41, 65000, Odessa, Ukraine
[removed]
+380504414402


The rest of your log looks fine, lets sweep for leftovers


Please run this free online virus scanner from ESET
  • Note: You will need to use Internet explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is ticked, and the option Scan unwanted applications is checked
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic


Post the ESET log and let me know how things are running now
I have run the Eset online scanner and below is the log: ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=3c0e65b7dfecc34b9595c48eed0b9cbf # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-10-13 09:56:33 # local_time=2010-10-13 05:56:33 (-0500, Eastern Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=2560 16777215 100 0 0 0 0 0 # compatibility_mode=8200 39157141 100 100 0 44544371 0 0 # scanned=122067 # found=0 # cleaned=0 # scan_time=1753 # nod_component=V3 Build:0x30000000 Thanks again for checking the other logs and finding where I got the virus. I was looking for a font at the time. I probably downloaded a font originating from that country because that's when Internet Explorer just shut down and I started getting error messages and computer problemsโ€ฆ
It seems to be running better and I haven't had any taskbar or window style changes. And I did notice it was running faster after it rebooted once TFC had run. Thanks for taking the time to figure this out because I never would have been able to find all of the places it was hiding in. Hopefully I won't have any other problems. Do you know if the purchased version of Malwarebytes will scan files as they download or if there is a program our company can get that will scan files as they download? Thanks.
Hi,

The paid version of Malwarebytes includes a protection module. What happens if you go into a bad site, you will get a PAGE NOT FOUND error and then a pop up from Malwarebytes telling you it blocked the site. Its very inexpensive, somewhere around $20 I believe and this is a one time charge, not yearly and the more licenses you buy the price goes down.

TFC is a nice program, run it once a week or so to clean out the clutter.

You have OTL installed, click on the Cleanup feature to remove a lot of things we used to clean your system including backups and such.


Combofix <โ€”Is not a general cleaning tool, just run it with supervision or you can damage your system


The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.





  • How did I get infected in the first place ?
    Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <โ€“ Do this first to prevent yourself from being reinfected.
  • WhattheTech
  • Grinler BleepingComputer
  • GeeksTo Go
  • Dslreports



Keep in mind if you install some of these programs. Only ONE Anti Virus and only ONE Firewall is recommended, more is overkill and can cause you problems. You can install all the Spyware programs I have listed without any problems. If you install Spyware Blaster and Spyware Guard, they will conflict with the TeaTimer in Spybot , you can still install Spybot Search and Destroy but do not enable the TeaTimer .



Here are some free programs to install, all free and highly regarded by the fine people in the Malware Removal Community
  • Spybot Search and Destroy 1.6
    Check for Updates/ Immunize and run a Full System Scan on a regular basis. If you install Spyware Blaster ( Recommended ) then do not enable the TeaTimer in Spybot Search and Destroy.
  • WinPatrol Keep this fine program activated to block a lot of threats
  • Spyware Blaster It will prevent most spyware from ever being installed. No scan to run, just update about once a week and enable all protection.
  • Spyware Guard It offers realtime protection from spyware installation attempts, again, no scan to run, just install it and let it do its thing.
  • IE-Spyad
    IE-Spyad places over 6000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • Firefox 3 It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.


Safe Surfn
Ken
I don't know if this is related to the virus, but I've never had this problem before: this morning, I tried to open a file from a folder on an external drive that I've backed up all of my files to from my C drive that was infected with the virus and I got a microsoft error that said the file was corrupt and I need to run chkdsk utility. I tried to open a Word file also that I had saved on Friday and E-mailed and I got the same message. And I can't save over the file either. I went under the drive properties, tools, and tried to scan for errors. IT looked like it was running a scan, but then I got a message that it couldn't complete the scan. I didn't have either of the checkmark boxes checked, I just hit the scan button. I've run malwarebytes on both drives and it didn't find anything. I'm running spybot now. Do you know if this is related to the other problems I was having? I've unplugged the drive and plugged it back in and restarted my computer and I still have the same problemsโ€ฆ Thanksโ€ฆ

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI