This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HJT log

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Very odd acting computer. Log posted below:


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:42:40 PM, on 10/23/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16671)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
C:\ProgramData\Macrovision\FLEXnet Connect\11\ISUSPM.exe
C:\temp\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
O2 - BHO: Internet Explorer Plugin - {442F8009-0D92-4493-B20C-41BB7D391E03} - mamdyh67.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20100915164755.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\RunOnce: [STToasterLauncher] C:\program files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\ProgramData\Macrovision\FLEXnet Connect\11\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [{2120E6A6-9905-B04C-1A99-0C3B556CFA34}] C:\Users\allen\AppData\Roaming\Agzoon\udval.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWow64\Macromed\Flash\FlashUtil10b.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWow64\Macromed\Flash\FlashUtil10b.exe (User 'Default user')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O23 - Service: McAfee Application Installer Cleanup (0144181287884503) (0144181287884503mcinstcleanup) - McAfee, Inc. - C:\Windows\TEMP\014418~1.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files (x86)\Common Files\Motive\McciCMService.exe
O23 - Service: McciCMService64 - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 9735 bytes
Hello DanaF :welcome:

Before we begin, I would like to make a few things clear so that we can fix your problem as efficiently as possible:
  • Be sure to follow all my instructions carefully! If there is anything you don''t understand, don't hesitate to ask.
  • Please do not do anything or perform other steps unless I have asked you to do so.
  • Please make sure you post all logs I ask you to, and make sure that the entire log gets posted.


Step 1

[external image: Posted Image] Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

Step 2

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan bot paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Things I would like to see in your reply:
  • MBAM Log
  • OTL.txt and Extras.txt
Mbam log: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4938 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 10/24/2010 9:41:02 PM mbam-log-2010-10-24 (21-41-02).txt Scan type: Quick scan Objects scanned: 138628 Time elapsed: 4 minute(s), 5 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 6 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 4 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: c:\Windows\System32\Iasv32.dll (Trojan.Agent) -> Delete on reboot. Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{442f8009-0d92-4493-b20c-41bb7d391e03} (Password.Stealer) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{fe4c2c37-edc8-4c00-b864-3c38cf3ba834} (Adware.Adshot) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{442f8009-0d92-4493-b20c-41bb7d391e03} (Password.Stealer) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{442f8009-0d92-4493-b20c-41bb7d391e03} (Password.Stealer) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{442f8009-0d92-4493-b20c-41bb7d391e03} (Password.Stealer) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ias (Trojan.Agent) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{2120e6a6-9905-b04c-1a99-0c3b556cfa34} (Trojan.ZbotR.Gen) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Windows\Temp\eueidifw.exe (Trojan.FakeAV) -> Quarantined and deleted successfully. C:\Windows\System32\certstore.dat (Trojan.Agent) -> Quarantined and deleted successfully. C:\Windows\System32\Iasv32.dll (Trojan.Agent) -> Delete on reboot. C:\Windows\Temp\skahgfhasd.bat (Malware.Trace) -> Quarantined and deleted successfully.
OTL.log

OTL logfile created on: 10/24/2010 9:45:30 PM - Run 1
OTL by OldTimer - Version 3.2.17.1 Folder = E:\
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 76.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 581.48 Gb Total Space | 549.96 Gb Free Space | 94.58% Space Free | Partition Type: NTFS
Drive E: | 951.08 Mb Total Space | 925.15 Mb Free Space | 97.27% Space Free | Partition Type: FAT32

Computer Name: ALLEN-PC | User Name: allen | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2010/10/24 21:42:00 | 000,575,488 | —- | M] (OldTimer Tools) – E:\OTL.exe
PRC - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
PRC - [2009/09/18 02:10:26 | 000,335,600 | —- | M] (SoftThinks - Dell) – C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
PRC - [2009/09/17 15:05:00 | 000,656,624 | —- | M] (SoftThinks) – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
PRC - [2009/06/09 12:11:14 | 000,155,648 | —- | M] (Stardock Corporation) – C:\Program Files\Dell\DellDock\DockLogin.exe
PRC - [2009/05/21 10:59:08 | 000,206,064 | —- | M] (SupportSoft, Inc.) – C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/09/26 11:19:04 | 000,210,208 | —- | M] (Acresso Corporation) – C:\ProgramData\Macrovision\FLEXnet Connect\11\ISUSPM.exe


========== Modules (SafeList) ==========

MOD - [2010/10/24 21:42:00 | 000,575,488 | —- | M] (OldTimer Tools) – E:\OTL.exe
MOD - [2010/08/21 01:21:32 | 001,680,896 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
MOD - [2009/07/13 21:15:31 | 000,154,624 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\imagehlp.dll
MOD - [2009/07/13 21:09:00 | 000,002,048 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\normaliz.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - File not found [Auto | Stopped] – C:\Windows\SysNative\FastUv32.dll – (FastUserSwitchingCompatibility)
SRV:64bit: - [2010/08/24 14:57:38 | 000,245,352 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe – (mfefire)
SRV:64bit: - [2010/08/24 14:57:38 | 000,200,056 | —- | M] () [Unknown | Running] – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe – (McShield)
SRV:64bit: - [2010/08/24 14:57:38 | 000,149,032 | —- | M] (McAfee, Inc.) [Unknown | Running] – C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe – (mfevtp)
SRV:64bit: - [2010/04/15 09:45:10 | 000,509,416 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files\McAfee\VirusScan\mcods.exe – (McODS)
SRV:64bit: - [2010/03/24 02:59:44 | 000,031,232 | —- | M] () [Auto | Running] – C:\Windows\SysNative\qmpehsoe.dll – (qmpehsoe)
SRV:64bit: - [2010/03/10 10:14:44 | 000,355,440 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (MSK80Service)
SRV:64bit: - [2010/03/10 10:14:44 | 000,355,440 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (McProxy)
SRV:64bit: - [2010/03/10 10:14:44 | 000,355,440 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (McNASvc)
SRV:64bit: - [2010/03/10 10:14:44 | 000,355,440 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (McNaiAnn)
SRV:64bit: - [2010/03/10 10:14:44 | 000,355,440 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (mcmscsvc)
SRV:64bit: - [2010/03/10 10:14:44 | 000,355,440 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (McMPFSvc)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/06/09 12:11:14 | 000,155,648 | —- | M] (Stardock Corporation) [Auto | Running] – C:\Program Files\Dell\DellDock\DockLogin.exe – (DockLoginService)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/12/20 23:21:30 | 000,016,680 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe – (GoToAssist)
SRV - [2009/09/17 15:05:00 | 000,656,624 | —- | M] (SoftThinks) [Auto | Running] – C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE – (SftService)
SRV - [2009/06/10 17:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/05/21 10:59:08 | 000,206,064 | —- | M] (SupportSoft, Inc.) [Auto | Running] – C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe – (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010/08/24 14:57:38 | 000,529,000 | —- | M] (McAfee, Inc.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\mfehidk.sys – (mfehidk)
DRV:64bit: - [2010/08/24 14:57:38 | 000,441,072 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\mfefirek.sys – (mfefirek)
DRV:64bit: - [2010/08/24 14:57:38 | 000,283,232 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\mfewfpk.sys – (mfewfpk)
DRV:64bit: - [2010/08/24 14:57:38 | 000,190,136 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\mfeavfk.sys – (mfeavfk)
DRV:64bit: - [2010/08/24 14:57:38 | 000,121,248 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\mfeapfk.sys – (mfeapfk)
DRV:64bit: - [2010/08/24 14:57:38 | 000,094,736 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mferkdet.sys – (mferkdet)
DRV:64bit: - [2010/08/24 14:57:38 | 000,075,032 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\mfenlfk.sys – (mfenlfk)
DRV:64bit: - [2010/08/24 14:57:38 | 000,062,800 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\cfwids.sys – (cfwids)
DRV:64bit: - [2010/07/28 21:10:42 | 010,610,400 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2010/05/10 09:15:56 | 000,082,544 | —- | M] (VIA Technologies, Inc. ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\viacr64.sys – (VIACRX64)
DRV:64bit: - [2010/03/04 13:43:00 | 000,346,144 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2009/10/22 02:23:18 | 000,043,008 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MREMP50a64.sys – (MREMP50a64)
DRV:64bit: - [2009/10/22 02:23:18 | 000,040,960 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MRESP50a64.sys – (MRESP50a64)
DRV:64bit: - [2009/10/09 22:41:20 | 000,109,056 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\sdbus.sys – (sdbus)
DRV:64bit: - [2009/08/06 03:29:38 | 000,686,080 | —- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CHDRT64.sys – (CnxtHdAudService)
DRV:64bit: - [2009/07/13 21:52:21 | 000,106,576 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2009/07/13 21:52:21 | 000,028,752 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/09 06:00:00 | 000,055,280 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2009/06/15 15:06:42 | 000,172,704 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CtClsFlt.sys – (CtClsFlt)
DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | —- | M] () [File_System | On_Demand | Running] – C:\Windows\SysNative\wbem\ntfs.mof – (Ntfs)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2006/11/01 14:51:00 | 000,151,656 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysNative\drivers\WimFltr.sys – (WimFltr)
DRV - [2009/10/22 02:23:18 | 000,021,248 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Motive\MREMP50.sys – (MREMP50)
DRV - [2009/10/22 02:23:18 | 000,020,096 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Motive\MRESP50.sys – (MRESP50)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[2010/09/16 09:33:38 | 000,002,075 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\google_search.xml

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho64.dll ()
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20100915164755.dll (McAfee, Inc.)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20100915164755.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [ATT-SST_McciTrayApp] C:\Program Files\ATT-SST\McciTrayApp.exe (Alcatel-Lucent)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe File not found
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKCU..\Run: [ISUSPM] C:\ProgramData\Macrovision\FLEXnet Connect\11\ISUSPM.exe (Acresso Corporation)
O4 - HKLM..\RunOnce: [STToasterLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\ToasterLauncher.exe ()
O4 - Startup: C:\Users\allen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files (x86)\Dell\DellDock\DellDock.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - Reg Error: Key error. - C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: FastUserSwitchingCompatibility - C:\Windows\SysNative\FastUv32.dll File not found
NetSvcs:64bit: qmpehsoe - C:\Windows\SysNative\qmpehsoe.dll ()

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/10/24 21:34:51 | 000,000,000 | —D | C] – C:\Users\allen\AppData\Roaming\Malwarebytes
[2010/10/24 21:34:45 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/10/24 21:34:44 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/10/24 21:34:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/10/24 21:34:44 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/10/23 21:32:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Intel
[2010/10/23 21:32:36 | 000,000,000 | —D | C] – C:\Intel
[2010/10/23 21:29:27 | 000,000,000 | —D | C] – C:\temp
[2010/10/13 19:23:07 | 000,000,000 | —D | C] – C:\Windows\Sun
[2010/03/25 11:30:03 | 008,653,312 | —- | C] (Dell, Inc. ) – C:\Users\allen\AppData\Roaming\DataSafeDotNet.exe
[5 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/10/24 21:42:45 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/10/24 21:42:28 | 3193,544,704 | -HS- | M] () – C:\hiberfil.sys
[2010/10/24 21:39:56 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/10/24 21:39:56 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/10/24 21:34:48 | 000,001,011 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/23 21:45:45 | 000,746,100 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/10/23 21:45:45 | 000,628,082 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/10/23 21:45:45 | 000,108,260 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/10/23 21:22:30 | 000,001,008 | —- | M] () – C:\ProgramData\.wtav
[2010/10/23 21:18:53 | 000,000,340 | —- | M] () – C:\Windows\tasks\At32.job
[2010/10/23 08:51:11 | 000,000,344 | —- | M] () – C:\Windows\tasks\At9.job
[2010/10/23 08:51:11 | 000,000,340 | —- | M] () – C:\Windows\tasks\At33.job
[2010/10/23 08:51:10 | 000,000,344 | —- | M] () – C:\Windows\tasks\At8.job
[2010/10/23 08:51:10 | 000,000,344 | —- | M] () – C:\Windows\tasks\At7.job
[2010/10/23 08:51:10 | 000,000,344 | —- | M] () – C:\Windows\tasks\At6.job
[2010/10/23 08:51:10 | 000,000,344 | —- | M] () – C:\Windows\tasks\At5.job
[2010/10/23 08:51:10 | 000,000,344 | —- | M] () – C:\Windows\tasks\At4.job
[2010/10/23 08:51:10 | 000,000,344 | —- | M] () – C:\Windows\tasks\At3.job
[2010/10/23 08:51:10 | 000,000,344 | —- | M] () – C:\Windows\tasks\At24.job
[2010/10/23 08:51:10 | 000,000,344 | —- | M] () – C:\Windows\tasks\At2.job
[2010/10/23 08:51:10 | 000,000,344 | —- | M] () – C:\Windows\tasks\At1.job
[2010/10/23 08:51:10 | 000,000,340 | —- | M] () – C:\Windows\tasks\At48.job
[2010/10/23 08:51:10 | 000,000,340 | —- | M] () – C:\Windows\tasks\At31.job
[2010/10/23 08:51:10 | 000,000,340 | —- | M] () – C:\Windows\tasks\At30.job
[2010/10/23 08:51:10 | 000,000,340 | —- | M] () – C:\Windows\tasks\At29.job
[2010/10/23 08:51:10 | 000,000,340 | —- | M] () – C:\Windows\tasks\At28.job
[2010/10/23 08:51:10 | 000,000,340 | —- | M] () – C:\Windows\tasks\At27.job
[2010/10/23 08:51:10 | 000,000,340 | —- | M] () – C:\Windows\tasks\At26.job
[2010/10/23 08:51:10 | 000,000,340 | —- | M] () – C:\Windows\tasks\At25.job
[2010/10/22 22:17:00 | 000,000,344 | —- | M] () – C:\Windows\tasks\At23.job
[2010/10/22 22:00:00 | 000,000,340 | —- | M] () – C:\Windows\tasks\At47.job
[2010/10/22 21:17:00 | 000,000,344 | —- | M] () – C:\Windows\tasks\At22.job
[2010/10/22 21:00:00 | 000,000,340 | —- | M] () – C:\Windows\tasks\At46.job
[2010/10/22 20:17:00 | 000,000,344 | —- | M] () – C:\Windows\tasks\At21.job
[2010/10/22 20:00:00 | 000,000,340 | —- | M] () – C:\Windows\tasks\At45.job
[2010/10/22 19:17:00 | 000,000,344 | —- | M] () – C:\Windows\tasks\At20.job
[2010/10/22 19:00:00 | 000,000,340 | —- | M] () – C:\Windows\tasks\At44.job
[2010/10/22 18:17:00 | 000,000,344 | —- | M] () – C:\Windows\tasks\At19.job
[2010/10/22 18:00:00 | 000,000,340 | —- | M] () – C:\Windows\tasks\At43.job
[2010/10/22 17:17:00 | 000,000,344 | —- | M] () – C:\Windows\tasks\At18.job
[2010/10/22 17:00:00 | 000,000,340 | —- | M] () – C:\Windows\tasks\At42.job
[2010/10/22 16:17:00 | 000,000,344 | —- | M] () – C:\Windows\tasks\At17.job
[2010/10/22 16:00:00 | 000,000,340 | —- | M] () – C:\Windows\tasks\At41.job
[2010/10/22 15:17:00 | 000,000,344 | —- | M] () – C:\Windows\tasks\At16.job
[2010/10/22 15:00:00 | 000,000,340 | —- | M] () – C:\Windows\tasks\At40.job
[2010/10/22 14:17:00 | 000,000,344 | —- | M] () – C:\Windows\tasks\At15.job
[2010/10/22 14:10:41 | 454,695,563 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/10/20 14:00:00 | 000,000,340 | —- | M] () – C:\Windows\tasks\At39.job
[2010/10/20 13:17:00 | 000,000,344 | —- | M] () – C:\Windows\tasks\At14.job
[2010/10/20 13:00:00 | 000,000,340 | —- | M] () – C:\Windows\tasks\At38.job
[2010/10/20 12:17:00 | 000,000,344 | —- | M] () – C:\Windows\tasks\At13.job
[2010/10/20 12:00:00 | 000,000,340 | —- | M] () – C:\Windows\tasks\At37.job
[2010/10/20 11:17:00 | 000,000,344 | —- | M] () – C:\Windows\tasks\At12.job
[2010/10/20 11:00:00 | 000,000,340 | —- | M] () – C:\Windows\tasks\At36.job
[2010/10/20 10:17:00 | 000,000,344 | —- | M] () – C:\Windows\tasks\At11.job
[2010/10/20 10:00:00 | 000,000,340 | —- | M] () – C:\Windows\tasks\At35.job
[2010/10/20 09:17:00 | 000,000,344 | —- | M] () – C:\Windows\tasks\At10.job
[2010/10/20 09:00:00 | 000,000,340 | —- | M] () – C:\Windows\tasks\At34.job
[2010/10/14 03:20:30 | 000,337,776 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/10/13 19:18:57 | 000,000,112 | —- | M] () – C:\ProgramData\y0jdqI.dat
[5 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/10/24 21:34:48 | 000,001,011 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/13 16:58:36 | 000,000,340 | —- | C] () – C:\Windows\tasks\At48.job
[2010/10/13 16:58:36 | 000,000,340 | —- | C] () – C:\Windows\tasks\At47.job
[2010/10/13 16:58:35 | 000,000,340 | —- | C] () – C:\Windows\tasks\At46.job
[2010/10/13 16:58:35 | 000,000,340 | —- | C] () – C:\Windows\tasks\At45.job
[2010/10/13 16:58:35 | 000,000,340 | —- | C] () – C:\Windows\tasks\At44.job
[2010/10/13 16:58:34 | 000,000,340 | —- | C] () – C:\Windows\tasks\At43.job
[2010/10/13 16:58:34 | 000,000,340 | —- | C] () – C:\Windows\tasks\At42.job
[2010/10/13 16:58:34 | 000,000,340 | —- | C] () – C:\Windows\tasks\At41.job
[2010/10/13 16:58:34 | 000,000,340 | —- | C] () – C:\Windows\tasks\At40.job
[2010/10/13 16:58:33 | 000,000,340 | —- | C] () – C:\Windows\tasks\At39.job
[2010/10/13 16:58:33 | 000,000,340 | —- | C] () – C:\Windows\tasks\At38.job
[2010/10/13 16:58:33 | 000,000,340 | —- | C] () – C:\Windows\tasks\At37.job
[2010/10/13 16:58:32 | 000,000,340 | —- | C] () – C:\Windows\tasks\At36.job
[2010/10/13 16:58:32 | 000,000,340 | —- | C] () – C:\Windows\tasks\At35.job
[2010/10/13 16:58:32 | 000,000,340 | —- | C] () – C:\Windows\tasks\At34.job
[2010/10/13 16:58:31 | 000,000,340 | —- | C] () – C:\Windows\tasks\At33.job
[2010/10/13 16:58:31 | 000,000,340 | —- | C] () – C:\Windows\tasks\At32.job
[2010/10/13 16:58:31 | 000,000,340 | —- | C] () – C:\Windows\tasks\At31.job
[2010/10/13 16:58:30 | 000,000,340 | —- | C] () – C:\Windows\tasks\At30.job
[2010/10/13 16:58:30 | 000,000,340 | —- | C] () – C:\Windows\tasks\At29.job
[2010/10/13 16:58:30 | 000,000,340 | —- | C] () – C:\Windows\tasks\At28.job
[2010/10/13 16:58:29 | 000,000,340 | —- | C] () – C:\Windows\tasks\At27.job
[2010/10/13 16:58:29 | 000,000,340 | —- | C] () – C:\Windows\tasks\At26.job
[2010/10/13 16:58:29 | 000,000,340 | —- | C] () – C:\Windows\tasks\At25.job
[2010/10/13 16:58:29 | 000,000,112 | —- | C] () – C:\ProgramData\y0jdqI.dat
[2010/10/13 16:56:56 | 000,000,344 | —- | C] () – C:\Windows\tasks\At24.job
[2010/10/13 16:56:55 | 000,000,344 | —- | C] () – C:\Windows\tasks\At23.job
[2010/10/13 16:56:55 | 000,000,344 | —- | C] () – C:\Windows\tasks\At22.job
[2010/10/13 16:56:55 | 000,000,344 | —- | C] () – C:\Windows\tasks\At21.job
[2010/10/13 16:56:55 | 000,000,344 | —- | C] () – C:\Windows\tasks\At20.job
[2010/10/13 16:56:54 | 000,000,344 | —- | C] () – C:\Windows\tasks\At19.job
[2010/10/13 16:56:54 | 000,000,344 | —- | C] () – C:\Windows\tasks\At18.job
[2010/10/13 16:56:54 | 000,000,344 | —- | C] () – C:\Windows\tasks\At17.job
[2010/10/13 16:56:54 | 000,000,344 | —- | C] () – C:\Windows\tasks\At16.job
[2010/10/13 16:56:53 | 000,000,344 | —- | C] () – C:\Windows\tasks\At15.job
[2010/10/13 16:56:53 | 000,000,344 | —- | C] () – C:\Windows\tasks\At14.job
[2010/10/13 16:56:52 | 000,000,344 | —- | C] () – C:\Windows\tasks\At13.job
[2010/10/13 16:56:52 | 000,000,344 | —- | C] () – C:\Windows\tasks\At12.job
[2010/10/13 16:56:52 | 000,000,344 | —- | C] () – C:\Windows\tasks\At11.job
[2010/10/13 16:56:51 | 000,000,344 | —- | C] () – C:\Windows\tasks\At9.job
[2010/10/13 16:56:51 | 000,000,344 | —- | C] () – C:\Windows\tasks\At8.job
[2010/10/13 16:56:51 | 000,000,344 | —- | C] () – C:\Windows\tasks\At10.job
[2010/10/13 16:56:50 | 000,000,344 | —- | C] () – C:\Windows\tasks\At7.job
[2010/10/13 16:56:50 | 000,000,344 | —- | C] () – C:\Windows\tasks\At6.job
[2010/10/13 16:56:50 | 000,000,344 | —- | C] () – C:\Windows\tasks\At5.job
[2010/10/13 16:56:49 | 000,000,344 | —- | C] () – C:\Windows\tasks\At4.job
[2010/10/13 16:56:49 | 000,000,344 | —- | C] () – C:\Windows\tasks\At3.job
[2010/10/13 16:56:48 | 000,000,344 | —- | C] () – C:\Windows\tasks\At2.job
[2010/10/13 16:56:48 | 000,000,344 | —- | C] () – C:\Windows\tasks\At1.job
[2010/09/15 14:47:39 | 000,001,008 | —- | C] () – C:\ProgramData\.wtav
[2010/07/28 20:14:38 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2010/07/28 20:14:38 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2010/03/21 13:22:17 | 000,003,584 | —- | C] () – C:\Users\allen\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll

========== LOP Check ==========

[2010/10/13 20:59:05 | 000,000,000 | —D | M] – C:\Users\allen\AppData\Roaming\Agzoon
[2010/09/23 13:19:36 | 000,000,000 | —D | M] – C:\Users\allen\AppData\Roaming\Bivagy
[2010/03/20 18:18:22 | 000,000,000 | —D | M] – C:\Users\allen\AppData\Roaming\Windows Live Writer
[2010/10/23 08:51:10 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At1.job
[2010/10/20 09:17:00 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At10.job
[2010/10/20 10:17:00 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At11.job
[2010/10/20 11:17:00 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At12.job
[2010/10/20 12:17:00 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At13.job
[2010/10/20 13:17:00 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At14.job
[2010/10/22 14:17:00 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At15.job
[2010/10/22 15:17:00 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At16.job
[2010/10/22 16:17:00 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At17.job
[2010/10/22 17:17:00 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At18.job
[2010/10/22 18:17:00 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At19.job
[2010/10/23 08:51:10 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At2.job
[2010/10/22 19:17:00 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At20.job
[2010/10/22 20:17:00 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At21.job
[2010/10/22 21:17:00 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At22.job
[2010/10/22 22:17:00 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At23.job
[2010/10/23 08:51:10 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At24.job
[2010/10/23 08:51:10 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At25.job
[2010/10/23 08:51:10 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At26.job
[2010/10/23 08:51:10 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At27.job
[2010/10/23 08:51:10 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At28.job
[2010/10/23 08:51:10 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At29.job
[2010/10/23 08:51:10 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At3.job
[2010/10/23 08:51:10 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At30.job
[2010/10/23 08:51:10 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At31.job
[2010/10/23 21:18:53 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At32.job
[2010/10/23 08:51:11 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At33.job
[2010/10/20 09:00:00 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At34.job
[2010/10/20 10:00:00 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At35.job
[2010/10/20 11:00:00 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At36.job
[2010/10/20 12:00:00 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At37.job
[2010/10/20 13:00:00 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At38.job
[2010/10/20 14:00:00 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At39.job
[2010/10/23 08:51:10 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At4.job
[2010/10/22 15:00:00 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At40.job
[2010/10/22 16:00:00 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At41.job
[2010/10/22 17:00:00 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At42.job
[2010/10/22 18:00:00 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At43.job
[2010/10/22 19:00:00 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At44.job
[2010/10/22 20:00:00 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At45.job
[2010/10/22 21:00:00 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At46.job
[2010/10/22 22:00:00 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At47.job
[2010/10/23 08:51:10 | 000,000,340 | —- | M] () – C:\Windows\Tasks\At48.job
[2010/10/23 08:51:10 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At5.job
[2010/10/23 08:51:10 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At6.job
[2010/10/23 08:51:10 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At7.job
[2010/10/23 08:51:10 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At8.job
[2010/10/23 08:51:11 | 000,000,344 | —- | M] () – C:\Windows\Tasks\At9.job
[2010/10/18 18:48:43 | 000,032,626 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/12/21 01:06:15 | 000,003,278 | RH– | M] () – C:\dell.sdr
[2010/10/24 21:42:28 | 3193,544,704 | -HS- | M] () – C:\hiberfil.sys
[2010/09/20 18:13:04 | 000,651,776 | —- | M] () – C:\hotfix.exe
[2010/10/24 21:42:38 | 4258,062,336 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessT >

< End of report >
Extras.txt

OTL Extras logfile created on: 10/24/2010 9:45:30 PM - Run 1
OTL by OldTimer - Version 3.2.17.1 Folder = E:\
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 76.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 581.48 Gb Total Space | 549.96 Gb Free Space | 94.58% Space Free | Partition Type: NTFS
Drive E: | 951.08 Mb Total Space | 925.15 Mb Free Space | 97.27% Space Free | Partition Type: FAT32

Computer Name: ALLEN-PC | User Name: allen | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\System32\ieframe.DLL (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.url [@ = InternetShortcut] – C:\Windows\System32\ieframe.DLL (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{26A24AE4-039D-4CA4-87B4-2F86416014FF}" = Java™ 6 Update 14 (64-bit)
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{E60B7350-EA5F-41E0-9D6F-E508781E36D2}" = Dell Dock
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"ATT-SST" = AT&T Self Support Tool
"CNXT_AUDIO_HDA" = Conexant HD Audio
"HDMI" = Intel® Graphics Media Accelerator Driver
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{04F3038E-4120-44CC-B330-E05F737246A5}" = Roxio Update Manager
"{052bac4a-6f79-46d4-a024-1ce1b4f73cd4}" = Microsoft Visual C++ 2005 Redistributable
"{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
"{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}" = Dell DataSafe Online
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 21
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
"{67635FB6-2F63-4FFB-830B-D4C01597EBA4}" = Microsoft Office Suite Activation Assistant
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack
"{A33E7B0C-B99C-4EC9-B702-8A328B161AF9}" = Roxio Burn
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.2
"{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}" = Roxio Burn
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Dell Webcam Central" = Dell Webcam Central
"GoToAssist" = GoToAssist 8.0.0.514
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MSC" = McAfee SecurityCenter
"WinLiveSuite_Wave3" = Windows Live Essentials
"Yahoo! Mail" = att.net Internet Mail

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/23/2010 12:30:21 AM | Computer Name = allen-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "c:\program files (x86)\windows
live\photo gallery\MovieMaker.Exe".Error in manifest or policy file "c:\program
files (x86)\windows live\photo gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 9/23/2010 12:30:33 AM | Computer Name = allen-PC | Source = SideBySide | ID = 16842811
Description = Activation context generation failed for "c:\program files (x86)\microsoft\search
enhancement pack\search helper\searchhelper.dll".Error in manifest or policy file
"c:\program files (x86)\microsoft\search enhancement pack\search helper\searchhelper.dll"
on line 2. Invalid Xml syntax.

Error - 9/23/2010 11:05:26 AM | Computer Name = allen-PC | Source = Application Error | ID = 1000
Description = Faulting application name: svchost.exe, version: 6.1.7600.16385, time
stamp: 0x4a5bc3c1 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0x0000000000feb010 Faulting process id: 0x94 Faulting
application start time: 0x01cb5a9824fd257a Faulting application path: C:\Windows\system32\svchost.exe
Faulting
module path: unknown Report Id: fe9c2555-c723-11df-9e2e-00262d195e6a

Error - 9/24/2010 12:30:10 AM | Computer Name = allen-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "c:\program files (x86)\windows
live\photo gallery\MovieMaker.Exe".Error in manifest or policy file "c:\program
files (x86)\windows live\photo gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 9/24/2010 12:30:15 AM | Computer Name = allen-PC | Source = SideBySide | ID = 16842811
Description = Activation context generation failed for "c:\program files (x86)\microsoft\search
enhancement pack\search helper\searchhelper.dll".Error in manifest or policy file
"c:\program files (x86)\microsoft\search enhancement pack\search helper\searchhelper.dll"
on line 2. Invalid Xml syntax.

Error - 9/24/2010 1:08:20 PM | Computer Name = allen-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 8.0.7600.16385,
time stamp: 0x4a5bc69e Faulting module name: AcroIEHelper.dll_unloaded, version:
0.0.0.0, time stamp: 0x49a847f1 Exception code: 0xc0000005 Fault offset: 0x755a556c
Faulting
process id: 0x938 Faulting application start time: 0x01cb5c01cb23b888 Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
AcroIEHelper.dll Report Id: 543c6b4e-c7fe-11df-9e2e-00262d195e6a

Error - 9/24/2010 10:30:27 PM | Computer Name = allen-PC | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 8.0.7600.16385,
time stamp: 0x4a5bc69e Faulting module name: ntdll.dll, version: 6.1.7600.16559,
time stamp: 0x4ba9b29c Exception code: 0xc0000005 Fault offset: 0x000222f3 Faulting
process id: 0xd20 Faulting application start time: 0x01cb5c599ca61df1 Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\Windows\SysWOW64\ntdll.dll Report Id: db66c871-c84c-11df-9047-00262d195e6a

Error - 9/25/2010 12:30:32 AM | Computer Name = allen-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "c:\program files (x86)\windows
live\photo gallery\MovieMaker.Exe".Error in manifest or policy file "c:\program
files (x86)\windows live\photo gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 9/25/2010 12:30:58 AM | Computer Name = allen-PC | Source = SideBySide | ID = 16842811
Description = Activation context generation failed for "c:\program files (x86)\microsoft\search
enhancement pack\search helper\searchhelper.dll".Error in manifest or policy file
"c:\program files (x86)\microsoft\search enhancement pack\search helper\searchhelper.dll"
on line 2. Invalid Xml syntax.

Error - 9/26/2010 12:49:38 PM | Computer Name = allen-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "c:\program files (x86)\windows
live\photo gallery\MovieMaker.Exe".Error in manifest or policy file "c:\program
files (x86)\windows live\photo gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

[ Media Center Events ]
Error - 3/27/2010 3:16:53 PM | Computer Name = allen-PC | Source = MCUpdate | ID = 0
Description = 3:16:52 PM - Failed to retrieve SportsSchedule (Error: Unable to connect
to the remote server)

Error - 3/27/2010 3:16:55 PM | Computer Name = allen-PC | Source = MCUpdate | ID = 0
Description = 3:16:54 PM - Failed to retrieve SportsV2 (Error: Unable to connect
to the remote server)

Error - 3/27/2010 3:16:57 PM | Computer Name = allen-PC | Source = MCUpdate | ID = 0
Description = 3:16:56 PM - Failed to retrieve Broadband (Error: Unable to connect
to the remote server)

Error - 5/7/2010 1:18:51 PM | Computer Name = allen-PC | Source = MCUpdate | ID = 0
Description = 1:17:23 PM - Failed to retrieve SportsSchedule (Error: Unable to connect
to the remote server)

Error - 6/10/2010 1:27:17 PM | Computer Name = allen-PC | Source = MCUpdate | ID = 0
Description = 1:27:17 PM - Failed to retrieve Directory (Error: Unable to connect
to the remote server)

Error - 6/10/2010 1:27:20 PM | Computer Name = allen-PC | Source = MCUpdate | ID = 0
Description = 1:27:19 PM - Failed to retrieve NetTV (Error: Unable to connect to
the remote server)

Error - 6/10/2010 1:27:22 PM | Computer Name = allen-PC | Source = MCUpdate | ID = 0
Description = 1:27:21 PM - Failed to retrieve MCEClientUX (Error: Unable to connect
to the remote server)

Error - 6/10/2010 1:27:24 PM | Computer Name = allen-PC | Source = MCUpdate | ID = 0
Description = 1:27:23 PM - Failed to retrieve SportsSchedule (Error: Unable to connect
to the remote server)

Error - 6/10/2010 1:27:26 PM | Computer Name = allen-PC | Source = MCUpdate | ID = 0
Description = 1:27:25 PM - Failed to retrieve SportsV2 (Error: Unable to connect
to the remote server)

Error - 6/10/2010 1:27:31 PM | Computer Name = allen-PC | Source = MCUpdate | ID = 0
Description = 1:27:27 PM - Failed to retrieve Broadband (Error: Unable to connect
to the remote server)

[ System Events ]
Error - 10/4/2010 11:02:56 AM | Computer Name = allen-PC | Source = Service Control Manager | ID = 7031
Description = The User Profile Service service terminated unexpectedly. It has
done this 1 time(s). The following corrective action will be taken in 120000 milliseconds:
Restart the service.

Error - 10/4/2010 11:02:56 AM | Computer Name = allen-PC | Source = Service Control Manager | ID = 7031
Description = The Task Scheduler service terminated unexpectedly. It has done this
1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 10/4/2010 11:02:56 AM | Computer Name = allen-PC | Source = Service Control Manager | ID = 7031
Description = The System Event Notification Service service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in
120000 milliseconds: Restart the service.

Error - 10/4/2010 11:02:56 AM | Computer Name = allen-PC | Source = Service Control Manager | ID = 7031
Description = The Shell Hardware Detection service terminated unexpectedly. It
has done this 1 time(s). The following corrective action will be taken in 60000
milliseconds: Restart the service.

Error - 10/4/2010 11:02:56 AM | Computer Name = allen-PC | Source = Service Control Manager | ID = 7031
Description = The Themes service terminated unexpectedly. It has done this 1 time(s).
The following corrective action will be taken in 60000 milliseconds: Restart the
service.

Error - 10/4/2010 11:02:56 AM | Computer Name = allen-PC | Source = Service Control Manager | ID = 7031
Description = The Windows Management Instrumentation service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in
120000 milliseconds: Restart the service.

Error - 10/4/2010 11:02:56 AM | Computer Name = allen-PC | Source = Service Control Manager | ID = 7031
Description = The Windows Update service terminated unexpectedly. It has done this
1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 10/4/2010 11:03:57 AM | Computer Name = allen-PC | Source = Service Control Manager | ID = 7032
Description = The Service Control Manager tried to take a corrective action (Restart
the service) after the unexpected termination of the Server service, but this action
failed with the following error: %%1056

Error - 10/4/2010 11:04:57 AM | Computer Name = allen-PC | Source = Service Control Manager | ID = 7032
Description = The Service Control Manager tried to take a corrective action (Restart
the service) after the unexpected termination of the Windows Management Instrumentation
service, but this action failed with the following error: %%1056

Error - 10/4/2010 11:04:57 AM | Computer Name = allen-PC | Source = Service Control Manager | ID = 7032
Description = The Service Control Manager tried to take a corrective action (Restart
the service) after the unexpected termination of the IKE and AuthIP IPsec Keying
Modules service, but this action failed with the following error: %%1056


< End of report >
hi

Step 1

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    SRV:64bit: - File not found [Auto | Stopped] – C:\Windows\SysNative\FastUv32.dll – (FastUserSwitchingCompatibility)
    SRV:64bit: - [2010/03/24 02:59:44 | 000,031,232 | —- | M] () [Auto | Running] – C:\Windows\SysNative\qmpehsoe.dll – (qmpehsoe)
    [2010/10/23 21:22:30 | 000,001,008 | —- | M] () – C:\ProgramData\.wtav
    [2010/10/13 19:18:57 | 000,000,112 | —- | M] () – C:\ProgramData\y0jdqI.dat
    
    :Files
    C:\Windows\tasks\At*.job
    
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

Step 2

Download ComboFix here :

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Here is a guide on how to disable them

    Click me

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.


Things I would like to see in your reply:
  • OTL log
  • Combofix.txt
The Combofix you linked claims to not be compatible with this version of windows. This computer is running 64-bit Windows 7.

Additionally, I was unable to find a simple way to kill McAfee Security. I'll look into this a bit more however.

Here's the OTL log as I was able to do everything you asked up to using Combofix:

OTL logfile created on: 10/25/2010 9:32:48 PM - Run 2
OTL by OldTimer - Version 3.2.17.1 Folder = E:\
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 68.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 581.48 Gb Total Space | 550.32 Gb Free Space | 94.64% Space Free | Partition Type: NTFS
Drive E: | 951.08 Mb Total Space | 944.36 Mb Free Space | 99.29% Space Free | Partition Type: FAT32

Computer Name: ALLEN-PC | User Name: allen | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2010/10/24 21:42:00 | 000,575,488 | —- | M] (OldTimer Tools) – E:\OTL.exe
PRC - [2009/09/18 02:10:26 | 000,335,600 | —- | M] (SoftThinks - Dell) – C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
PRC - [2009/09/17 15:05:00 | 000,656,624 | —- | M] (SoftThinks) – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
PRC - [2009/06/09 12:11:14 | 000,155,648 | —- | M] (Stardock Corporation) – C:\Program Files\Dell\DellDock\DockLogin.exe
PRC - [2008/09/26 11:19:04 | 000,210,208 | —- | M] (Acresso Corporation) – C:\ProgramData\Macrovision\FLEXnet Connect\11\ISUSPM.exe


========== Modules (SafeList) ==========

MOD - [2010/10/24 21:42:00 | 000,575,488 | —- | M] (OldTimer Tools) – E:\OTL.exe
MOD - [2010/08/21 01:21:32 | 001,680,896 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
MOD - [2009/07/13 21:15:31 | 000,154,624 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\imagehlp.dll
MOD - [2009/07/13 21:09:00 | 000,002,048 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\normaliz.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/08/24 14:57:38 | 000,245,352 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe – (mfefire)
SRV:64bit: - [2010/08/24 14:57:38 | 000,200,056 | —- | M] () [Unknown | Running] – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe – (McShield)
SRV:64bit: - [2010/08/24 14:57:38 | 000,149,032 | —- | M] (McAfee, Inc.) [Unknown | Running] – C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe – (mfevtp)
SRV:64bit: - [2010/04/15 09:45:10 | 000,509,416 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files\McAfee\VirusScan\mcods.exe – (McODS)
SRV:64bit: - [2010/03/10 10:14:44 | 000,355,440 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (MSK80Service)
SRV:64bit: - [2010/03/10 10:14:44 | 000,355,440 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (McProxy)
SRV:64bit: - [2010/03/10 10:14:44 | 000,355,440 | —- | M] (McAfee, Inc.) [Auto | Stopped] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (McNASvc)
SRV:64bit: - [2010/03/10 10:14:44 | 000,355,440 | —- | M] (McAfee, Inc.) [Auto | Stopped] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (McNaiAnn)
SRV:64bit: - [2010/03/10 10:14:44 | 000,355,440 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (mcmscsvc)
SRV:64bit: - [2010/03/10 10:14:44 | 000,355,440 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (McMPFSvc)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/06/09 12:11:14 | 000,155,648 | —- | M] (Stardock Corporation) [Auto | Running] – C:\Program Files\Dell\DellDock\DockLogin.exe – (DockLoginService)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/12/20 23:21:30 | 000,016,680 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe – (GoToAssist)
SRV - [2009/09/17 15:05:00 | 000,656,624 | —- | M] (SoftThinks) [Auto | Running] – C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE – (SftService)
SRV - [2009/06/10 17:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/05/21 10:59:08 | 000,206,064 | —- | M] (SupportSoft, Inc.) [Auto | Stopped] – C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe – (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010/08/24 14:57:38 | 000,529,000 | —- | M] (McAfee, Inc.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\mfehidk.sys – (mfehidk)
DRV:64bit: - [2010/08/24 14:57:38 | 000,441,072 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\mfefirek.sys – (mfefirek)
DRV:64bit: - [2010/08/24 14:57:38 | 000,283,232 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\mfewfpk.sys – (mfewfpk)
DRV:64bit: - [2010/08/24 14:57:38 | 000,190,136 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\mfeavfk.sys – (mfeavfk)
DRV:64bit: - [2010/08/24 14:57:38 | 000,121,248 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\mfeapfk.sys – (mfeapfk)
DRV:64bit: - [2010/08/24 14:57:38 | 000,094,736 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mferkdet.sys – (mferkdet)
DRV:64bit: - [2010/08/24 14:57:38 | 000,075,032 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\mfenlfk.sys – (mfenlfk)
DRV:64bit: - [2010/08/24 14:57:38 | 000,062,800 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\cfwids.sys – (cfwids)
DRV:64bit: - [2010/07/28 21:10:42 | 010,610,400 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2010/05/10 09:15:56 | 000,082,544 | —- | M] (VIA Technologies, Inc. ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\viacr64.sys – (VIACRX64)
DRV:64bit: - [2010/03/04 13:43:00 | 000,346,144 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2009/10/22 02:23:18 | 000,043,008 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MREMP50a64.sys – (MREMP50a64)
DRV:64bit: - [2009/10/22 02:23:18 | 000,040,960 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Motive\MRESP50a64.sys – (MRESP50a64)
DRV:64bit: - [2009/10/09 22:41:20 | 000,109,056 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\sdbus.sys – (sdbus)
DRV:64bit: - [2009/08/06 03:29:38 | 000,686,080 | —- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CHDRT64.sys – (CnxtHdAudService)
DRV:64bit: - [2009/07/13 21:52:21 | 000,106,576 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2009/07/13 21:52:21 | 000,028,752 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/09 06:00:00 | 000,055,280 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2009/06/15 15:06:42 | 000,172,704 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CtClsFlt.sys – (CtClsFlt)
DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | —- | M] () [File_System | On_Demand | Running] – C:\Windows\SysNative\wbem\ntfs.mof – (Ntfs)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2006/11/01 14:51:00 | 000,151,656 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysNative\drivers\WimFltr.sys – (WimFltr)
DRV - [2009/10/22 02:23:18 | 000,021,248 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Motive\MREMP50.sys – (MREMP50)
DRV - [2009/10/22 02:23:18 | 000,020,096 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Motive\MRESP50.sys – (MRESP50)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[2010/09/16 09:33:38 | 000,002,075 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\google_search.xml

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho64.dll ()
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20100915164755.dll (McAfee, Inc.)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20100915164755.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [ATT-SST_McciTrayApp] C:\Program Files\ATT-SST\McciTrayApp.exe (Alcatel-Lucent)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe File not found
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKCU..\Run: [ISUSPM] C:\ProgramData\Macrovision\FLEXnet Connect\11\ISUSPM.exe (Acresso Corporation)
O4 - HKLM..\RunOnce: [STToasterLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\ToasterLauncher.exe ()
O4 - Startup: C:\Users\allen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files (x86)\Dell\DellDock\DellDock.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - Reg Error: Key error. - C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/10/24 21:34:51 | 000,000,000 | —D | C] – C:\Users\allen\AppData\Roaming\Malwarebytes
[2010/10/24 21:34:45 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/10/24 21:34:44 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/10/24 21:34:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/10/24 21:34:44 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/10/23 21:32:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\Intel
[2010/10/23 21:32:36 | 000,000,000 | —D | C] – C:\Intel
[2010/10/23 21:29:27 | 000,000,000 | —D | C] – C:\temp
[2010/10/13 19:23:07 | 000,000,000 | —D | C] – C:\Windows\Sun
[2010/03/25 11:30:03 | 008,653,312 | —- | C] (Dell, Inc. ) – C:\Users\allen\AppData\Roaming\DataSafeDotNet.exe

========== Files - Modified Within 30 Days ==========

[2010/10/25 21:31:48 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/10/25 21:31:40 | 3193,544,704 | -HS- | M] () – C:\hiberfil.sys
[2010/10/25 21:31:06 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/10/25 21:31:06 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/10/24 21:34:48 | 000,001,011 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/23 21:45:45 | 000,746,100 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/10/23 21:45:45 | 000,628,082 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/10/23 21:45:45 | 000,108,260 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/10/22 14:10:41 | 454,695,563 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/10/14 03:20:30 | 000,337,776 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2010/10/24 21:34:48 | 000,001,011 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/28 20:14:38 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2010/07/28 20:14:38 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2010/03/21 13:22:17 | 000,003,584 | —- | C] () – C:\Users\allen\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll

========== LOP Check ==========

[2010/10/13 20:59:05 | 000,000,000 | —D | M] – C:\Users\allen\AppData\Roaming\Agzoon
[2010/09/23 13:19:36 | 000,000,000 | —D | M] – C:\Users\allen\AppData\Roaming\Bivagy
[2010/03/20 18:18:22 | 000,000,000 | —D | M] – C:\Users\allen\AppData\Roaming\Windows Live Writer
[2010/10/18 18:48:43 | 000,032,626 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >
]
hi

Forget about combofix, i forgot you have a 64 bit system.

Step 1

Update MalwareBytes AntiMalware and Run a Quick Scan.
Post the log it produces

Step 2

Please download JavaRa to your desktop and unzip it to it's own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

Next

Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply


Things i would like to see in your reply:
  • Malwarebytes Results.
  • Kaspersky WebScanner Report
  • Update on how your computer is running
Computer does seem improved. What's more, IE seems to now be wroking correctly. Here's the MalwareBytes log: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4968 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 10/27/2010 9:45:33 PM mbam-log-2010-10-27 (21-45-33).txt Scan type: Quick scan Objects scanned: 141428 Time elapsed: 4 minute(s), 56 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Here's the scanner report: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Wednesday, October 27, 2010 Operating system: Microsoft (build 7600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Wednesday, October 27, 2010 21:18:20 Records in database: 4181002 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Objects scanned: 102573 Threats found: 1 Infected objects found: 1 Suspicious objects found: 0 Scan duration: 01:04:34 File name / Threat / Threats count C:\Program Files (x86)\Mozilla Firefox\searchplugins\google_search.xml Infected: Trojan.Win32.Clicker.hd 1 Selected area has been scanned.
hi

Please download OTM
  • Save it to your desktop.
  • Please double-click OTM to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Files
    C:\Program Files (x86)\Mozilla Firefox\searchplugins\google_search.xml
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]
  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM and reboot your PC.
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
All processes killed ========== FILES ========== C:\Program Files (x86)\Mozilla Firefox\searchplugins\google_search.xml moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: allen ->Temp folder emptied: 111015327 bytes ->Temporary Internet Files folder emptied: 72318599 bytes ->Java cache emptied: 128094 bytes ->Flash cache emptied: 405 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 57071992 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 49353 bytes %systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 749 bytes RecycleBin emptied: 431275884 bytes Total Files Cleaned = 641.00 mb OTM by OldTimer - Version 3.1.17.1 log created on 10282010_213423 Files moved on Reboot… C:\Users\allen\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot…
hi

Congratulations your logs appear clean :thumbsup:

Reset and Re-enable your System Restore

  • Open OTL
  • Under the Custom Scans/Fixes box at the bottom, paste the following:
    :Commands
    [clearallrestorepoints]
    [createrestorepoint]
  • Click the Run Fix button at the top
  • It might ask you to reboot, if so click YES

NEXT

  • Open OTL to run it. (Vista users, right click on OTL and "Run as administrator")
  • Click on the CleanUp button.
  • Click Yes to begin the cleanup process and remove tools, including this application
  • You may be asked to reboot the machine to finish the cleanup process - if so, choose Yes


Recommendations

See Here for a list of recommendations for free Antivirus\AntiSpyware applications.


  • Keep Your windows up to date by regularly checking their website at:
    http://windowsupdate.microsoft.com/

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.


  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
    Here

    If you choose to use Firefox, I highly recommend these add-ons to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
    • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling

  • Click Here to learn how to keep a backup of your important files

  • FileHippo Update Checkker is an extremely helpful program that will tell you which of your programs need to be updated. Its important to keep programs up to date so that malware doesn't exploit any old security flaws.


Thank you :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI