This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser Redirect/Fake Microsoft Security Alert/Intermittent Internet A

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I started this topic earlier – but unfortunately was not able to respond timely to the offer of assistance due to a family illness…thanks in advance for your time.

This is the previous thread:

http://forums.whatthetech.com/index.php?sh…115017&st=0

—————————
hijackthis results:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:28:23 PM, on 11/1/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Common Files\AOL\1210613219\ee\AOLSoftware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\All Users\Application Data\Norton\NUA.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Common Files\AOL\1210613219\ee\aolsoftware.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\PROGRA~1\AOL9~1.5\waol.exe
C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Dedrie Smith\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=3080419
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=3080419
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HttpWatch Basic - {F1F69322-008F-4895-B2BF-AD194219825A} - C:\Program Files\HttpWatch\httpwatchsc.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1210613219\ee\AOLSoftware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [NortonUpdateAgent] C:\Documents and Settings\All Users\Application Data\Norton\NUA.exe
O4 - HKCU\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
O4 - HKCU\..\Run: [AOL Fast Start] "C:\PROGRA~1\AOL9~1.5\AOL.EXE" -b
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: HttpWatch Basic - {D103E85B-5D67-42c1-8C83-F01079DBAB26} - C:\Program Files\HttpWatch\httpwatch.dll
O9 - Extra 'Tools' menuitem: HttpWatch Basic - {D103E85B-5D67-42c1-8C83-F01079DBAB26} - C:\Program Files\HttpWatch\httpwatch.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6796.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6BAB93B7-1917-4214-A7D2-874FA6DB4740} (AOL Newport Editor Ctrl) - http://o.aolcdn.com/pictures/ap/Resources/…ns.10.6.0.8.cab
O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} (GameHouse Games Player) - http://aolsvc.aol.com/onlinegames/free-tri…houseplayer.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/bejewele…ploader_v10.cab
O20 - AppInit_DLLs: c:\windows\system32\hisakite.dll c:\windows\system32\zudalure.dll c:\windows\system32\rovozefa.dll c:\windows\system32\bulimane.dll c:\windows\system32\moriyava.dll c:\windows\system32\supilime.dll c:\windows\system32\bevoweja.dll c:\windows\system32\kiyajeru.dll c:\windows\system32\dehaseha.dll c:\windows\system32\natulevo.dll c:\windows\system32\vomuganu.dll c:\windows\system32\mayonibe.dll c:\windows\system32\dogatidi.dll c:\windows\system32\pekuhedo.dll,pemobupo.dll
O20 - Winlogon Notify: gemsafe - C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O21 - SSODL: bajiwupuh - {9e1630c6-7c5b-43f3-88fd-2ab16c3d94d1} - c:\windows\system32\teyufeve.dll (file missing)
O21 - SSODL: lolozimav - {289d3c51-2110-4650-8827-bb3d197b98ad} - c:\windows\system32\teyufeve.dll (file missing)
O21 - SSODL: fafejuvek - {c66ae819-8c35-4f9f-a643-63045cbebecf} - c:\windows\system32\moriyava.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: gahurihor - {018b02ca-d120-4bf3-be8d-a5c5d3e0b107} - (no file)
O22 - SharedTaskScheduler: mujuzedij - {002401d3-541f-4a08-a167-988bcde63d5e} - (no file)
O22 - SharedTaskScheduler: gahurihor - {b7be70e5-57a5-4aeb-a646-cd1061addc8c} - (no file)
O22 - SharedTaskScheduler: gahurihor - {0a42816f-86a2-4018-8e75-c7490c653054} - (no file)
O22 - SharedTaskScheduler: gahurihor - {95a847ee-8b44-460f-8d4e-6f242ea7682f} - (no file)
O22 - SharedTaskScheduler: mujuzedij - {b6c16ada-5ae0-431e-8797-578fa2dfd46f} - (no file)
O22 - SharedTaskScheduler: jugezatag - {da73c12d-3a42-4e3d-94f8-418ebe5fd807} - (no file)
O22 - SharedTaskScheduler: tokatiluy - {9e1630c6-7c5b-43f3-88fd-2ab16c3d94d1} - c:\windows\system32\teyufeve.dll (file missing)
O22 - SharedTaskScheduler: jugezatag - {289d3c51-2110-4650-8827-bb3d197b98ad} - c:\windows\system32\teyufeve.dll (file missing)
O22 - SharedTaskScheduler: gahurihor - {71a41e06-4419-479b-b44c-12ddf5528c1c} - (no file)
O22 - SharedTaskScheduler: tokatiluy - {1cf542fb-1517-4773-b966-ffd3dbab02dc} - (no file)
O22 - SharedTaskScheduler: mujuzedij - {d09ec36b-34df-4f50-a0ec-868f49b6094b} - (no file)
O22 - SharedTaskScheduler: tokatiluy - {6a1355d4-879e-4d83-b740-d59902b31b6c} - (no file)
O22 - SharedTaskScheduler: tokatiluy - {c66ae819-8c35-4f9f-a643-63045cbebecf} - c:\windows\system32\moriyava.dll (file missing)
O22 - SharedTaskScheduler: tokatiluy - {9675de18-8f52-4612-a8f9-c16451dbbefe} - (no file)
O22 - SharedTaskScheduler: gahurihor - {34c75cca-3d66-42ae-bf3f-f005b7bc0086} - (no file)
O22 - SharedTaskScheduler: tokatiluy - {298bd6e5-7f07-4e5a-b7a0-53082cab9b63} - (no file)
O22 - SharedTaskScheduler: jugezatag - {429a2580-6151-47fb-af1d-cc581c2bd535} - (no file)
O22 - SharedTaskScheduler: gahurihor - {f3e2d788-efd6-491f-a8b2-725b06fc5828} - (no file)
O22 - SharedTaskScheduler: gahurihor - {0b331eaa-ffcb-49bb-aeec-4919f87b373c} - (no file)
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: NTRU TSS v1.2.1.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
O23 - Service: WaveEnrollmentService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Authentication Manager\WaveEnrollmentService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 17430 bytes
Hello nocompguru :),

Sorry to hear about the unfortunate turn of event. Hope things will smooth out for you and your family.

Lets redo some of the steps I asked you to the last time.

Scan with OTL
  • Double click on OTL.exe to run it.
  • Make sure all the Use SafeList options is checked (ticked). There are six of them.
  • Check Scan All Users.
  • At the lower right corner, check LOP Check and Purity Check.
  • Click on Run Scan at the top left hand corner. This might take a while.
  • When done, two Notepad files will open. Please post the contents of these 2 Notepad files in your next reply. One log per reply please.
    Note: These files are saved as OTL.txt and Extras.txt on the desktop.
——————–

Check for additional security risks
  • Please download CKScanner© by askey127 and save to your desktop. Click here.
  • Double click on CKScanner.exe and click Search For Files.
  • After a very short time, when the cursor hourglass disappears, click Save List To File. You will be prompted, click OK.
  • Post the contents of ckfiles.txt in your reply, it is located on your desktop.
——————–

Please post back:
1. the OTL logs (OTL.txt and Extras.txt)
2. the CKScanner result
Thanks for your help, again!




OTL.txt
OTL logfile created on: 11/2/2010 8:31:24 PM - Run 3
OTL by OldTimer - Version 3.2.15.2 Folder = C:\Documents and Settings\Dedrie Smith\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 54.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 69.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.44 Gb Total Space | 30.06 Gb Free Space | 40.38% Space Free | Partition Type: NTFS

Computer Name: DLSCONSULTING | User Name: Dedrie Smith | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2010/10/13 16:11:06 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Dedrie Smith\Desktop\OTL.exe
PRC - [2010/09/07 15:40:04 | 001,819,504 | —- | M] (Symantec Corporation) – C:\Documents and Settings\All Users\Application Data\Norton\NUA.exe
PRC - [2010/03/23 10:54:55 | 000,028,496 | —- | M] (AOL Inc.) – C:\Program Files\AOL 9.5\waol.exe
PRC - [2010/03/23 10:54:54 | 000,054,608 | —- | M] (AOL Inc.) – C:\Program Files\AOL 9.5\shellmon.exe
PRC - [2010/02/10 09:19:09 | 000,041,800 | —- | M] (AOL Inc.) – C:\Program Files\Common Files\AOL\1210613219\ee\aolsoftware.exe
PRC - [2009/09/14 20:47:37 | 000,198,160 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2009/09/13 18:52:50 | 001,048,392 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2009/07/02 17:36:52 | 000,017,904 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2008/11/21 17:01:26 | 002,356,088 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
PRC - [2008/10/17 15:52:10 | 000,149,352 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE
PRC - [2008/05/12 11:44:01 | 001,251,720 | —- | M] () – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
PRC - [2008/01/11 17:50:16 | 000,030,312 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
PRC - [2007/11/08 23:50:10 | 001,552,384 | —- | M] () – C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
PRC - [2007/09/07 18:29:04 | 000,737,280 | —- | M] (Wave Systems Corp.) – C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
PRC - [2007/08/31 11:49:50 | 000,243,064 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
PRC - [2007/07/03 14:53:40 | 000,475,136 | —- | M] (Dell Inc.) – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
PRC - [2007/06/13 06:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/04/02 08:33:32 | 000,063,120 | —- | M] (AOL LLC) – C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe
PRC - [2006/11/03 19:02:14 | 000,050,688 | —- | M] (Avanquest Software ) – C:\Program Files\Digital Line Detect\DLG.exe
PRC - [2006/10/23 08:50:35 | 000,046,640 | R— | M] (AOL LLC) – C:\Program Files\Common Files\AOL\acs\AOLacsd.exe
PRC - [2004/07/27 17:50:42 | 000,221,184 | —- | M] (InstallShield Software Corporation) – C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
PRC - [2004/04/18 23:45:50 | 000,761,856 | —- | M] (InstallShield Software Corporation) – C:\Program Files\Common Files\InstallShield\Driver\10\Intel 32\IDriver.exe


========== Modules (SafeList) ==========

MOD - [2010/10/13 16:11:06 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Dedrie Smith\Desktop\OTL.exe
MOD - [2010/03/23 10:54:52 | 000,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msvcr71.dll
MOD - [2010/03/23 10:54:50 | 000,006,144 | —- | M] (AOL Inc.) – C:\Program Files\AOL 9.5\idleproc.dll
MOD - [2006/08/25 09:45:56 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
MOD - [2004/08/04 06:00:00 | 000,102,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – C:\WINDOWS\System32\hidserv.dll – (HidServ)
SRV - File not found [Auto | Stopped] – C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe – (Browser Defender Update Service)
SRV - File not found [Auto | Stopped] – C:\WINDOWS\System32\6to4v32.dll – (6to4)
SRV - [2009/07/02 17:36:52 | 000,017,904 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe – (MsMpSvc)
SRV - [2008/10/17 15:52:10 | 000,149,352 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe – (LiveUpdate Notice)
SRV - [2008/10/17 15:52:10 | 000,149,352 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe – (CLTNetCnService)
SRV - [2008/10/17 15:52:10 | 000,149,352 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe – (ccSetMgr)
SRV - [2008/10/17 15:52:10 | 000,149,352 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe – (ccEvtMgr)
SRV - [2008/05/23 14:51:16 | 000,016,680 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe – (GoToAssist)
SRV - [2008/05/12 11:44:01 | 001,251,720 | —- | M] () [On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe – (Symantec Core LC)
SRV - [2008/04/19 00:50:42 | 000,029,744 | —- | M] (Google) [On_Demand | Stopped] – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe – (GoogleDesktopManager-010708-104812)
SRV - [2008/04/19 00:50:19 | 000,654,848 | —- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2008/01/11 17:50:16 | 000,030,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe – (BcmSqlStartupSvc)
SRV - [2007/12/27 14:50:12 | 003,192,184 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE – (LiveUpdate)
SRV - [2007/12/27 14:46:30 | 000,055,640 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe – (comHost)
SRV - [2007/12/11 04:39:12 | 000,382,320 | —- | M] (SupportSoft, Inc.) [On_Demand | Stopped] – C:\Program Files\Common Files\supportsoft\bin\ssrc.exe – (SupportSoft RemoteAssist)
SRV - [2007/11/08 23:50:10 | 001,552,384 | —- | M] () [Auto | Running] – C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe – (tcsd_win32.exe)
SRV - [2007/09/13 15:31:44 | 000,192,512 | —- | M] (Wave Systems Corp.) [On_Demand | Stopped] – C:\Program Files\Wave Systems Corp\Authentication Manager\WaveEnrollmentService.exe – (WaveEnrollmentService)
SRV - [2007/09/07 18:29:04 | 000,737,280 | —- | M] (Wave Systems Corp.) [Auto | Running] – C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe – (TdmService)
SRV - [2007/08/31 18:39:18 | 000,486,400 | —- | M] (Wave Systems Corp.) [On_Demand | Stopped] – C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe – (SecureStorageService)
SRV - [2007/08/31 11:49:50 | 000,243,064 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe – (Automatic LiveUpdate Scheduler)
SRV - [2007/07/03 14:53:40 | 000,475,136 | —- | M] (Dell Inc.) [Auto | Running] – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe – (NICCONFIGSVC)
SRV - [2006/10/23 08:50:35 | 000,046,640 | R— | M] (AOL LLC) [Auto | Running] – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe – (AOL ACS)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | System | Stopped] – C:\WINDOWS\System32\drivers\oksobxup.sys – (oksobxup)
DRV - File not found [Kernel | System | Stopped] – C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{21C425F4-D933-43C8-9F1D-C785D864EFD2}\MpKslc38d941c.sys – (MpKslc38d941c)
DRV - [2010/06/22 14:52:12 | 000,010,344 | —- | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\symlcbrd.sys – (symlcbrd)
DRV - [2010/06/16 12:09:32 | 000,002,304 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\msdemgr.sys – (msdemgr)
DRV - [2009/07/13 04:00:00 | 000,875,728 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090806.023\NAVEX15.SYS – (NAVEX15)
DRV - [2009/07/13 04:00:00 | 000,087,888 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090806.023\NAVENG.SYS – (NAVENG)
DRV - [2009/06/16 04:00:00 | 000,101,936 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2009/02/25 05:00:00 | 000,371,248 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys – (eeCtrl)
DRV - [2009/02/19 12:31:42 | 000,031,280 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SymIM.sys – (SymIMMP)
DRV - [2009/02/19 12:31:42 | 000,031,280 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\SymIM.sys – (SymIM)
DRV - [2009/02/19 12:31:16 | 000,184,496 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\SYMTDI.SYS – (SYMTDI)
DRV - [2009/02/19 12:31:16 | 000,096,560 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMFW.SYS – (SYMFW)
DRV - [2009/02/19 12:31:16 | 000,038,576 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMIDS.SYS – (SYMIDS)
DRV - [2009/02/19 12:31:16 | 000,037,424 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMNDIS.SYS – (SYMNDIS)
DRV - [2009/02/19 12:31:16 | 000,022,320 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS – (SYMREDRV)
DRV - [2009/02/19 12:31:16 | 000,013,616 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMDNS.SYS – (SYMDNS)
DRV - [2009/02/09 18:59:18 | 000,251,768 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\SymcData\ipsdefs\20090730.002\SymIDSCo.sys – (SYMIDSCO)
DRV - [2009/01/08 21:53:46 | 000,124,464 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SYMEVENT.SYS – (SymEvent)
DRV - [2008/09/05 14:31:42 | 000,447,024 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys – (SPBBCDrv)
DRV - [2008/07/30 17:42:12 | 000,023,888 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\COH_Mon.sys – (COH_Mon)
DRV - [2007/12/27 14:43:48 | 000,036,056 | —- | M] (Symantec Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\CO_Mon.sys – (CO_Mon)
DRV - [2007/12/05 21:07:36 | 001,222,840 | —- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sthda.sys – (STHDA)
DRV - [2007/12/02 19:26:22 | 000,989,952 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_DPV.sys – (HSF_DPV)
DRV - [2007/12/02 19:26:20 | 000,731,136 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_CNXT.sys – (winachsf)
DRV - [2007/12/02 19:26:20 | 000,211,200 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSFHWAZL.sys – (HSFHWAZL)
DRV - [2007/11/30 23:57:12 | 000,317,616 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\srtspl.sys – (SRTSPL)
DRV - [2007/11/30 23:57:12 | 000,279,088 | —- | M] (Symantec Corporation) [File_System | System | Running] – C:\WINDOWS\system32\drivers\srtsp.sys – (SRTSP)
DRV - [2007/11/30 23:57:12 | 000,043,696 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\srtspx.sys – (SRTSPX)
DRV - [2007/11/28 17:18:24 | 000,062,208 | —- | M] (O2Micro) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\oz776.sys – (guardian2)
DRV - [2007/10/09 05:17:42 | 001,123,328 | —- | M] (Broadcom Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BCMWL5.SYS – (BCM43XX)
DRV - [2007/09/10 10:55:00 | 000,161,280 | —- | M] (Wave Systems Corp.) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\WavxDMgr.sys – (WavxDMgr)
DRV - [2007/09/07 10:57:14 | 000,026,608 | —- | M] (Dell Inc) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\PBADRV.sys – (PBADRV)
DRV - [2007/09/06 10:18:40 | 000,018,176 | —- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\WaveFDE.sys – (WaveFDE)
DRV - [2007/08/06 17:27:28 | 006,835,744 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2007/07/17 20:46:12 | 000,037,376 | —- | M] (REDC) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\rixdptsk.sys – (rismxdp)
DRV - [2007/07/17 20:46:10 | 000,056,832 | —- | M] (REDC) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\rimsptsk.sys – (rimsptsk)
DRV - [2007/07/17 20:46:08 | 000,039,936 | —- | M] (REDC) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\rimmptsk.sys – (rimmptsk)
DRV - [2007/07/17 15:16:36 | 000,161,792 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\b57xp32.sys – (b57w2k)
DRV - [2007/05/24 14:59:14 | 000,202,912 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SynTP.sys – (SynTP)
DRV - [2006/08/18 14:18:08 | 000,009,400 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLADResM.SYS – (DLADResM)
DRV - [2006/08/18 14:17:46 | 000,035,096 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLABMFSM.SYS – (DLABMFSM)
DRV - [2006/08/18 14:17:44 | 000,097,848 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS – (DLAUDF_M)
DRV - [2006/08/18 14:17:44 | 000,094,648 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS – (DLAUDFAM)
DRV - [2006/08/18 14:17:42 | 000,026,008 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS – (DLAOPIOM)
DRV - [2006/08/18 14:17:40 | 000,032,472 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLABOIOM.SYS – (DLABOIOM)
DRV - [2006/08/18 14:17:38 | 000,104,472 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS – (DLAIFS_M)
DRV - [2006/08/18 14:17:38 | 000,014,520 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAPoolM.SYS – (DLAPoolM)
DRV - [2006/08/11 12:05:58 | 000,051,768 | —- | M] (Roxio) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\DRVNDDM.SYS – (DRVNDDM)
DRV - [2006/08/11 11:35:18 | 000,012,920 | —- | M] (Roxio) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLACDBHM.SYS – (DLACDBHM)
DRV - [2006/08/11 11:35:16 | 000,028,184 | —- | M] (Roxio) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLARTL_M.SYS – (DLARTL_M)
DRV - [2006/07/21 12:21:26 | 000,099,176 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS – (DRVMCDB)
DRV - [2006/01/19 10:17:38 | 000,011,904 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\BrUsbSer.sys – (BrUsbSer)
DRV - [2006/01/19 05:44:46 | 000,053,248 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\BrSerIf.sys – (BrSerIf)
DRV - [2005/08/12 18:50:46 | 000,016,128 | —- | M] (Dell Inc) [Kernel | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS – (APPDRV)
DRV - [2004/10/15 12:50:20 | 000,015,295 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\BrScnUsb.sys – (BrScnUsb)
DRV - [2004/08/12 18:45:54 | 000,137,728 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Hdaudbus.sys – (HDAudBus)
DRV - [2004/08/04 00:07:44 | 000,043,008 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\amdagp.sys – (amdagp)
DRV - [2004/08/04 00:07:44 | 000,041,088 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sisagp.sys – (sisagp)
DRV - [2004/08/03 23:07:56 | 000,059,264 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\USBAUDIO.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2003/01/10 17:13:04 | 000,033,588 | R— | M] (America Online, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [2001/08/17 15:07:44 | 000,019,072 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sparrow.sys – (Sparrow)
DRV - [2001/08/17 15:07:42 | 000,030,688 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sym_u3.sys – (sym_u3)
DRV - [2001/08/17 15:07:40 | 000,028,384 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sym_hi.sys – (sym_hi)
DRV - [2001/08/17 15:07:36 | 000,032,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\symc8xx.sys – (symc8xx)
DRV - [2001/08/17 15:07:34 | 000,016,256 | —- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\symc810.sys – (symc810)
DRV - [2001/08/17 14:52:22 | 000,036,736 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ultra.sys – (ultra)
DRV - [2001/08/17 14:52:20 | 000,045,312 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql12160.sys – (ql12160)
DRV - [2001/08/17 14:52:20 | 000,040,320 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql1080.sys – (ql1080)
DRV - [2001/08/17 14:52:18 | 000,049,024 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql1280.sys – (ql1280)
DRV - [2001/08/17 14:52:16 | 000,179,584 | —- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys – (dac2w2k)
DRV - [2001/08/17 14:52:12 | 000,017,280 | —- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\mraid35x.sys – (mraid35x)
DRV - [2001/08/17 14:52:00 | 000,026,496 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\asc.sys – (asc)
DRV - [2001/08/17 14:51:58 | 000,014,848 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\asc3550.sys – (asc3550)
DRV - [2001/08/17 14:51:56 | 000,005,248 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\aliide.sys – (AliIde)
DRV - [2001/08/17 14:51:54 | 000,006,656 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\cmdide.sys – (CmdIde)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client;=dell-usuk&channel;=us-smb&ibd;=3080419
IE - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com
IE - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Search Defender"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.aol.com"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..keyword.URL: "http://www.search-results.com/web?o=15868&l;=dis&prt;=PRT&chn;=UN&geo;=US&ver;=UN&q;="


FF - HKLM\software\mozilla\Firefox\extensions\\{1E2593B2-E106-4697-BCE7-A9D30DE05D73}: C:\Program Files\HttpWatch\Firefox\ [2010/02/13 11:35:18 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/11/01 16:07:30 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/01 16:07:30 | 000,000,000 | —D | M]

[2009/11/29 17:09:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Extensions
[2009/11/29 17:09:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Extensions\[removed]
[2010/11/01 19:47:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Firefox\Profiles\btxfsm4e.default\extensions
[2009/10/30 00:12:16 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Firefox\Profiles\btxfsm4e.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/09/15 19:49:53 | 000,004,555 | —- | M] () – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Firefox\Profiles\btxfsm4e.default\searchplugins\aol-search.xml
[2010/06/24 11:10:08 | 000,002,425 | —- | M] () – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Firefox\Profiles\btxfsm4e.default\searchplugins\askcom.xml
[2010/10/11 12:36:23 | 000,002,698 | —- | M] () – C:\Documents and Settings\Dedrie Smith\Application Data\Mozilla\Firefox\Profiles\btxfsm4e.default\searchplugins\search-defender.xml
[2010/11/01 16:18:06 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/13 09:00:04 | 000,028,488 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\atgpcdec.dll
[2010/04/13 09:00:04 | 000,185,240 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\atgpcext.dll
[2010/04/13 09:00:23 | 000,046,408 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\atmccli.dll
[2009/08/25 09:05:45 | 000,098,712 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\ieatgpc.dll
[2010/04/13 09:00:02 | 000,061,848 | —- | M] (WebEx Communications, Inc) – C:\Program Files\Mozilla Firefox\plugins\npatgpc.dll
[2008/06/30 23:02:00 | 000,663,072 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\npOGAPlugin.dll
[2009/09/29 19:35:55 | 000,221,184 | —- | M] (CNN) – C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll

Hosts file not found
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Common Files\Symantec Shared\IDS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (HttpWatch Basic) - {F1F69322-008F-4895-B2BF-AD194219825A} - C:\Program Files\HttpWatch\httpwatchsc.dll (Simtec Limited)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1210613219\ee\aolsoftware.exe (AOL Inc.)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UserFaultCheck] File not found
O4 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008..\Run: [AOL Fast Start] C:\Program Files\AOL 9.5\aol.exe (AOL Inc.)
O4 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008..\Run: [NortonUpdateAgent] C:\Documents and Settings\All Users\Application Data\Norton\NUA.exe (Symantec Corporation)
O4 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: HttpWatch Basic - {D103E85B-5D67-42c1-8C83-F01079DBAB26} - C:\Program Files\HttpWatch\httpwatch.dll (Simtec Limited)
O9 - Extra 'Tools' menuitem : HttpWatch Basic - {D103E85B-5D67-42c1-8C83-F01079DBAB26} - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (MetaStreamCtl Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www2.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase6796.cab (Windows Live Safety Center Base Module)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://go.divx.com/plugin/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {6BAB93B7-1917-4214-A7D2-874FA6DB4740} http://o.aolcdn.com/pictures/ap/Resources/…ns.10.6.0.8.cab (AOL Newport Editor Ctrl)
O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} http://aolsvc.aol.com/onlinegames/free-tri…houseplayer.cab (GameHouse Games Player)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://aolsvc.aol.com/onlinegames/bejewele…ploader_v10.cab (PopCapLoader Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - AppInit_DLLs: (c:\windows\system32\hisakite.dll c:\windows\system32\zudalure.dll c:\windows\system32\rovozefa.dll c:\windows\system32\bulimane.dll c:\windows\system32\moriyava.dll c:\windows\system32\supilime.dll c:\windows\system32\bevoweja.dll c:\windows\system32\kiyajeru.dll c:\windows\system32\dehaseha.dll c:\windows\system32\natulevo.dll c:\windows\system32\vomuganu.dll c:\windows\system32\mayonibe.dll c:\windows\system32\dogatidi.dll c:\windows\system32\pekuhedo.dll) - C:\WINDOWS\System32\hisakite.dll File not found
O20 - AppInit_DLLs: (pemobupo.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (waveGina.dll) - C:\WINDOWS\System32\waveGina.dll (Wave Systems Corp.)
O20 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008 Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\gemsafe: DllName - C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll - C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll (Gemplus)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O21 - SSODL: bajiwupuh - {9e1630c6-7c5b-43f3-88fd-2ab16c3d94d1} - C:\WINDOWS\System32\teyufeve.dll File not found
O21 - SSODL: fafejuvek - {c66ae819-8c35-4f9f-a643-63045cbebecf} - C:\WINDOWS\System32\moriyava.dll File not found
O21 - SSODL: lolozimav - {289d3c51-2110-4650-8827-bb3d197b98ad} - C:\WINDOWS\System32\teyufeve.dll File not found
O22 - SharedTaskScheduler: {002401d3-541f-4a08-a167-988bcde63d5e} - mujuzedij - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {018b02ca-d120-4bf3-be8d-a5c5d3e0b107} - gahurihor - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {0a42816f-86a2-4018-8e75-c7490c653054} - gahurihor - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {0b331eaa-ffcb-49bb-aeec-4919f87b373c} - gahurihor - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {1cf542fb-1517-4773-b966-ffd3dbab02dc} - tokatiluy - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {289d3c51-2110-4650-8827-bb3d197b98ad} - jugezatag - C:\WINDOWS\System32\teyufeve.dll File not found
O22 - SharedTaskScheduler: {298bd6e5-7f07-4e5a-b7a0-53082cab9b63} - tokatiluy - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {34c75cca-3d66-42ae-bf3f-f005b7bc0086} - gahurihor - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {429a2580-6151-47fb-af1d-cc581c2bd535} - jugezatag - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {6a1355d4-879e-4d83-b740-d59902b31b6c} - tokatiluy - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {71a41e06-4419-479b-b44c-12ddf5528c1c} - gahurihor - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {95a847ee-8b44-460f-8d4e-6f242ea7682f} - gahurihor - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {9675de18-8f52-4612-a8f9-c16451dbbefe} - tokatiluy - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {9e1630c6-7c5b-43f3-88fd-2ab16c3d94d1} - tokatiluy - C:\WINDOWS\System32\teyufeve.dll File not found
O22 - SharedTaskScheduler: {b6c16ada-5ae0-431e-8797-578fa2dfd46f} - mujuzedij - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {b7be70e5-57a5-4aeb-a646-cd1061addc8c} - gahurihor - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {c66ae819-8c35-4f9f-a643-63045cbebecf} - tokatiluy - C:\WINDOWS\System32\moriyava.dll File not found
O22 - SharedTaskScheduler: {d09ec36b-34df-4f50-a0ec-868f49b6094b} - mujuzedij - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {da73c12d-3a42-4e3d-94f8-418ebe5fd807} - jugezatag - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {f3e2d788-efd6-491f-a8b2-725b06fc5828} - gahurihor - Reg Error: Key error. File not found
O24 - Desktop WallPaper: C:\WINDOWS\dell.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (wvauth) - C:\WINDOWS\System32\wvauth.dll (Wave Systems Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 18:15:00 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{4c007d35-8876-11de-a2c1-001c234864d1}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4c007d35-8876-11de-a2c1-001c234864d1}\Shell\AutoRun\command - "" = E:\autorun.exe – File not found
O33 - MountPoints2\{4c007d35-8876-11de-a2c1-001c234864d1}\Shell\phone\command - "" = E:\autorun.exe – File not found
O33 - MountPoints2\{a1485048-13f7-11df-a37e-001f3a4cf431}\Shell\Auto\command - "" = E:\launcher.exe – File not found
O33 - MountPoints2\{a1485048-13f7-11df-a37e-001f3a4cf431}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{a1485049-13f7-11df-a37e-001f3a4cf431}\Shell\Auto\command - "" = E:\launcher.exe – File not found
O33 - MountPoints2\{a1485049-13f7-11df-a37e-001f3a4cf431}\Shell\AutoRun - "" = Auto&Play;
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/11/02 13:21:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Dedrie Smith\My Documents\TS0134
[2010/11/02 00:53:45 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Sun
[2010/10/26 22:51:15 | 000,000,000 | —D | C] – C:\Program Files\AOL Toolbar
[2010/10/26 22:51:06 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Software Update Utility
[2010/10/26 22:47:35 | 000,000,000 | —D | C] – C:\Program Files\AOL 9.5
[2010/10/13 16:10:50 | 000,574,464 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Dedrie Smith\Desktop\OTL.exe
[2010/10/12 20:48:44 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Dedrie Smith\Desktop\HiJackThis.exe
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/11/02 13:21:45 | 000,133,528 | —- | M] () – C:\Documents and Settings\Dedrie Smith\My Documents\TS0134.zip
[2010/11/02 12:16:52 | 000,161,168 | —- | M] () – C:\Documents and Settings\Dedrie Smith\My Documents\Weeklyworksheet11-1-10.pdf
[2010/11/02 10:05:52 | 000,000,408 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/11/02 10:03:38 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/11/02 10:01:18 | 000,093,584 | —- | M] () – C:\WINDOWS\System32\nvModes.001
[2010/11/02 09:59:37 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/11/02 09:59:27 | 2145,521,664 | -HS- | M] () – C:\hiberfil.sys
[2010/11/02 00:53:45 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/10/31 00:47:49 | 003,634,519 | —- | M] () – C:\Documents and Settings\Dedrie Smith\My Documents\Dogs_Home_TV_Ad_(every_home_needs_a_Harvey)2.wmv
[2010/10/26 22:55:43 | 000,000,612 | —- | M] () – C:\Documents and Settings\Dedrie Smith\Application Data\Microsoft\Internet Explorer\Quick Launch\AOL 9.5.lnk
[2010/10/20 18:58:33 | 000,093,584 | —- | M] () – C:\WINDOWS\System32\nvModes.dat
[2010/10/19 21:47:05 | 000,443,392 | —- | M] () – C:\Documents and Settings\Dedrie Smith\Desktop\CKScanner.exe
[2010/10/13 16:11:06 | 000,574,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Dedrie Smith\Desktop\OTL.exe
[2010/10/12 20:49:03 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Dedrie Smith\Desktop\HiJackThis.exe
[2010/10/12 19:06:12 | 000,000,008 | RHS- | M] () – C:\Documents and Settings\Dedrie Smith\ntuser.pol
[2010/10/11 21:40:08 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/10/11 21:19:36 | 000,020,043 | —- | M] () – C:\WINDOWS\System32\nvwsapps.xml
[2010/10/11 20:50:32 | 000,000,144 | —- | M] () – C:\Documents and Settings\Dedrie Smith\Application Data\dsfsds.bat
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/11/02 13:21:41 | 000,133,528 | —- | C] () – C:\Documents and Settings\Dedrie Smith\My Documents\TS0134.zip
[2010/11/02 12:16:49 | 000,161,168 | —- | C] () – C:\Documents and Settings\Dedrie Smith\My Documents\Weeklyworksheet11-1-10.pdf
[2010/10/31 00:47:06 | 003,634,519 | —- | C] () – C:\Documents and Settings\Dedrie Smith\My Documents\Dogs_Home_TV_Ad_(every_home_needs_a_Harvey)2.wmv
[2010/10/26 22:55:43 | 000,000,612 | —- | C] () – C:\Documents and Settings\Dedrie Smith\Application Data\Microsoft\Internet Explorer\Quick Launch\AOL 9.5.lnk
[2010/10/19 21:46:45 | 000,443,392 | —- | C] () – C:\Documents and Settings\Dedrie Smith\Desktop\CKScanner.exe
[2010/10/12 19:01:38 | 000,000,008 | RHS- | C] () – C:\Documents and Settings\Dedrie Smith\ntuser.pol
[2010/10/11 20:50:31 | 000,000,144 | —- | C] () – C:\Documents and Settings\Dedrie Smith\Application Data\dsfsds.bat
[2010/06/16 12:09:32 | 000,002,304 | —- | C] () – C:\WINDOWS\System32\msdemgr.sys
[2009/02/20 23:53:56 | 000,000,135 | —- | C] () – C:\Documents and Settings\Dedrie Smith\Local Settings\Application Data\fusioncache.dat
[2009/01/13 16:40:52 | 014,564,931 | —- | C] () – C:\Program Files\ysitebuilder.exe
[2008/11/28 01:07:47 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2008/07/17 23:34:22 | 000,000,000 | —- | C] () – C:\Program Files\Firefox Setup 3.0.1.exe
[2008/07/06 14:39:18 | 000,000,811 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2008/07/06 14:39:18 | 000,000,094 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2008/07/06 14:38:18 | 000,000,419 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2008/07/06 14:38:18 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2008/07/06 14:36:58 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\BrMuSNMP.dll
[2008/06/22 19:32:45 | 000,018,274 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/06/03 11:58:27 | 000,009,728 | —- | C] () – C:\Documents and Settings\Dedrie Smith\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/05/11 21:34:56 | 000,000,000 | —- | C] () – C:\Documents and Settings\Dedrie Smith\Local Settings\Application Data\WavXMapDrive.bat
[2008/04/19 01:08:35 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/04/19 00:42:15 | 000,056,056 | —- | C] () – C:\WINDOWS\System32\DLAAPI_W.DLL
[2008/04/19 00:42:15 | 000,000,120 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/04/19 00:30:19 | 000,080,368 | —- | C] () – C:\WINDOWS\System32\pbadrvdll.dll
[2008/04/19 00:27:42 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\bioapi_mds300.dll
[2008/04/19 00:27:42 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\bioapi100.dll
[2008/04/19 00:23:00 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2008/04/19 00:22:56 | 000,753,664 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2008/04/18 23:55:26 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2008/04/18 23:55:26 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2008/04/18 23:55:25 | 001,478,656 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2008/04/18 23:55:25 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2008/04/18 23:55:12 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2008/04/18 23:53:43 | 000,001,122 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2008/02/04 19:23:10 | 000,693,792 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2007/09/13 15:42:30 | 000,499,712 | —- | C] () – C:\WINDOWS\System32\AmRes_ru.dll
[2007/09/13 15:42:30 | 000,471,040 | —- | C] () – C:\WINDOWS\System32\AmRes_pt-BR.dll
[2007/09/13 15:42:28 | 000,487,424 | —- | C] () – C:\WINDOWS\System32\AmRes_it.dll
[2007/09/13 15:42:28 | 000,487,424 | —- | C] () – C:\WINDOWS\System32\AmRes_fr.dll
[2007/09/13 15:42:28 | 000,462,848 | —- | C] () – C:\WINDOWS\System32\AmRes_ko.dll
[2007/09/13 15:42:28 | 000,458,752 | —- | C] () – C:\WINDOWS\System32\AmRes_ja.dll
[2007/09/13 15:42:26 | 000,487,424 | —- | C] () – C:\WINDOWS\System32\AmRes_es.dll
[2007/09/13 15:42:26 | 000,487,424 | —- | C] () – C:\WINDOWS\System32\AmRes_de.dll
[2007/09/13 15:42:26 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\AmRes_en.dll
[2007/09/13 15:42:26 | 000,434,176 | —- | C] () – C:\WINDOWS\System32\AmRes_zh-CHT.dll
[2007/09/13 15:36:24 | 000,438,272 | —- | C] () – C:\WINDOWS\System32\AmRes_zh-CHS.dll
[2007/09/12 16:05:08 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\Internationalization_pt.dll
[2007/09/12 16:04:46 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\Internationalization_zh-CHT.dll
[2007/09/12 16:04:26 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\Internationalization_ko.dll
[2007/09/12 16:04:06 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\Internationalization_es.dll
[2007/09/12 16:03:44 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\Internationalization_ru.dll
[2007/09/12 16:03:24 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\Internationalization_ja.dll
[2007/09/12 16:03:04 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\Internationalization_it.dll
[2007/09/12 16:02:44 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\Internationalization_de.dll
[2007/09/12 16:02:22 | 000,102,400 | —- | C] () – C:\WINDOWS\System32\Internationalization_fr.dll
[2007/09/12 16:02:02 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\Internationalization_zh-CHS.dll
[2007/09/10 10:53:26 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\wxvault.dll
[2007/06/15 11:19:20 | 000,835,584 | —- | C] () – C:\WINDOWS\System32\DemoLicense.dll
[2007/01/03 11:24:36 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/01/03 11:22:46 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/01/03 11:22:14 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/11/07 05:25:58 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2006/09/17 00:36:50 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/17 00:36:50 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2006/08/14 12:02:10 | 000,072,192 | —- | C] () – C:\WINDOWS\System32\xltZlib.dll
[2006/06/12 09:01:16 | 000,348,160 | —- | C] () – C:\WINDOWS\tsp.dll
[2004/09/10 14:34:00 | 000,917,504 | —- | C] () – C:\WINDOWS\System32\lmgr10.dll
[2004/09/10 14:34:00 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ADsSecurity.dll
[2004/08/11 18:24:19 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/11 18:11:31 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/11 18:07:24 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI

========== LOP Check ==========

[2008/04/19 00:34:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Wave Systems Corp
[2009/10/24 23:33:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\05524319
[2010/01/11 22:11:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\112FD
[2009/11/09 00:09:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\18269
[2010/03/12 10:52:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\23146
[2009/10/22 21:11:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\24100714
[2009/10/24 23:33:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\24368225
[2009/10/22 21:11:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\26039020
[2010/02/10 00:18:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\30109
[2009/10/28 08:19:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\33834324
[2009/10/21 22:45:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\37198230
[2009/10/25 20:30:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\48452831
[2009/10/24 23:33:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\52948836
[2009/10/21 22:45:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\72663832
[2009/10/25 00:50:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\78977644
[2010/01/08 21:37:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\A186
[2008/07/08 19:15:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2008/06/13 12:57:05 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2008/05/23 14:52:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2010/01/22 01:27:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\D1A5
[2008/10/16 00:04:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ExtendMedia
[2010/03/17 19:21:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameHouse
[2009/10/10 23:06:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
[2008/04/19 00:27:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NTRU Cryptosystems
[2008/06/10 23:46:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2010/10/08 19:43:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2010/10/19 21:11:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/10/26 22:51:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/09/10 09:31:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Wave Systems Corp
[2009/02/13 22:27:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/10/30 18:09:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{BA892C10-A262-42D0-B6AD-2ADE4916F871}
[2008/05/12 13:34:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\acccore
[2008/06/23 14:25:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Canon
[2010/02/07 11:11:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Coby Media Manager
[2009/02/13 23:21:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\iPod Copy Expert
[2008/07/20 21:30:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Mobipocket
[2008/07/06 14:40:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\PC-FAX TX
[2008/10/30 18:09:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\PhotoWorks
[2008/06/13 13:04:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\ScanSoft
[2008/10/30 18:08:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Seven Zip
[2009/01/22 11:20:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Skinux
[2009/01/21 17:22:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Snapfish
[2008/04/19 00:34:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Wave Systems Corp
[2010/06/08 09:50:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\webex
[2008/05/15 10:12:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Dedrie Smith\Application Data\Windows Desktop Search
[2008/04/19 00:34:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Default User\Application Data\Wave Systems Corp
[2010/06/23 17:48:54 | 000,000,450 | —- | M] () – C:\WINDOWS\Tasks\EasyShare Registration Task.job
[2010/11/02 10:05:52 | 000,000,408 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\qrbktbal.sys:changelist
@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\moyhzgde.sys:changelist
@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\mdkmbdhm.sys:changelist
@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\kbtlinqq.sys:changelist
@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\jniyjvsh.sys:changelist
@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\hudaxxum.sys:changelist
@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\axjlnrvq.sys:changelist
@Alternate Data Stream - 566 bytes -> C:\WINDOWS\System32\drivers\aqnlfvxs.sys:changelist
@Alternate Data Stream - 368 bytes -> C:\WINDOWS\System32\drivers\ukixszmw.sys:changelist
@Alternate Data Stream - 368 bytes -> C:\WINDOWS\System32\drivers\pbkutgqb.sys:changelist
@Alternate Data Stream - 2886 bytes -> C:\WINDOWS\System32\drivers\dfvrfjfh.sys:changelist
@Alternate Data Stream - 2394 bytes -> C:\WINDOWS\System32\drivers\hzmbkdfs.sys:changelist
@Alternate Data Stream - 2194 bytes -> C:\WINDOWS\System32\drivers\pzcbqmtc.sys:changelist
@Alternate Data Stream - 2094 bytes -> C:\WINDOWS\System32\drivers\baydmjwe.sys:changelist
@Alternate Data Stream - 1594 bytes -> C:\WINDOWS\System32\drivers\zwewnaus.sys:changelist
@Alternate Data Stream - 1594 bytes -> C:\WINDOWS\System32\drivers\zomwmskw.sys:changelist
@Alternate Data Stream - 1594 bytes -> C:\WINDOWS\System32\drivers\zmtxlczd.sys:changelist
@Alternate Data Stream - 1594 bytes -> C:\WINDOWS\System32\drivers\uhfnajas.sys:changelist
@Alternate Data Stream - 1594 bytes -> C:\WINDOWS\System32\drivers\pykjaewj.sys:changelist
@Alternate Data Stream - 1594 bytes -> C:\WINDOWS\System32\drivers\oybfwpmi.sys:changelist
@Alternate Data Stream - 1594 bytes -> C:\WINDOWS\System32\drivers\diketwvy.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\voakaxjx.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\ukzevqef.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\tgctseaf.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\qhkkhbcn.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\oxogayzn.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\oosdjhyl.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\nltagavr.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\lohomwre.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\kugfpeya.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\ivfhaoiq.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\exmvswjr.sys:changelist
@Alternate Data Stream - 1494 bytes -> C:\WINDOWS\System32\drivers\eabfohna.sys:changelist
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >

Extras.Txt
OTL Extras logfile created on: 11/2/2010 8:31:24 PM - Run 3
OTL by OldTimer - Version 3.2.15.2 Folder = C:\Documents and Settings\Dedrie Smith\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 54.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 69.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.44 Gb Total Space | 30.06 Gb Free Space | 40.38% Space Free | Partition Type: NTFS

Computer Name: DLSCONSULTING | User Name: Dedrie Smith | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_USERS\S-1-5-21-2334342494-3678532155-2428501450-1008\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare – (Eastman Kodak Company)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01B845D4-B73E-4CF7-A377-94BC7BB4F77B}" = HttpWatch Basic 6.2.39
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{07D618CD-B016-438A-ADC9-A75BD23F85CE}" = Wave Support Software
"{0B0A2153-58A6-4244-B458-25EDF5FCD809}" = Private Information Manager
"{0C2AF762-0565-4C91-9F55-B8B53BB82A38}" = Microsoft Office Accounting 2008 Equifax Addin
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{177D1318-3E4B-4A7C-A300-AC4E21BE090B}" = Broadcom Management Programs
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{24A494F3-5B5F-4183-9F7D-9CE82812C1FC}" = tsp patch
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{270940EA-C235-40D9-B2AE-2D450356DF8E}" = Microsoft Office Accounting 2008
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{31478BE1-CDE5-4753-A8B2-F6D4BC1FBE09}" = Component Framework
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{342126E1-173C-4585-BFBE-3EBDD20E3E9E}" = Mobipocket Reader 6.2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3643EF5F-D28D-4B25-9FA1-8859FC303710}" = Coby Media Manager
"{3A6BE9F4-5FC8-44BB-BE7B-32A29607FEF6}" = Preboot Manager
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{40036C98-9777-45C2-9183-304B82B549BA}" = Symantec Real Time Storage Protection Component
"{415CDA53-9100-476F-A7B2-476691E117C7}" = HP Smart Web Printing
"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
"{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}" = HPSSupply
"{48B3FB4D-CE22-488C-8E9F-24EBB77EAC0F}" = Microsoft Security Essentials
"{4BF18ED6-C888-4BCF-A4AF-AC7A16305BC1}" = GemSafe Standard Edition 5.1
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{51AE9E42-640D-4C14-A9B6-43F64AA4E3E2}" = Document Manager Lite
"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001
"{53333479-6A52-4816-8497-5C52B67ED339}" = EMBASSY Security Setup
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{543E938C-BDC4-4933-A612-01293996845F}" = UnloadSupport
"{55A6283C-638A-4EE0-B491-51118554BDA2}" = Norton Confidential Core
"{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer
"{5EC5F187-9D2B-4051-8906-88656819A869}" = Dell Drivers MSI
"{5FA793A6-0071-42C1-9355-8F69A428C44F}" = Microsoft Office Accounting ADP Payroll Addin
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{62120008-8E1E-4807-860D-A8B48F8552DB}" = Norton Protection Center
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77772678-817F-4401-9301-ED1D01A8DA56}" = SPBBC 32bit
"{77FFBA7E-0973-4F39-BBDB-AC2F537578D2}" = Norton AntiVirus
"{797EE0CA-8165-405C-B5CE-F11EC20F1BB0}" = Microsoft VC9 runtime libraries
"{7A2CF4CC-21A9-461D-85E3-7B4589302F65}" = SymNet
"{7A647B7A-9FE7-44A2-9041-C04528D44EB9}" = NBC Direct Beta
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{3EC77D26-799B-4CD8-914F-C1565E796173}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_SMALLBUSINESSR_{430971B1-C31E-45DA-81E0-72C095BAB72C}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_SMALLBUSINESSR_{F7A31780-33C4-4E39-951A-5EC9B91D7BF1}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{FAD8A83E-9BAC-4179-9268-A35948034D85}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-00CA-0000-0000-0000000FF1CE}" = Microsoft Office Small Business 2007
"{91120000-00CA-0000-0000-0000000FF1CE}_SMALLBUSINESSR_{BEE75E01-DD3F-4D5F-B96C-609E6538D419}" = 2007 Microsoft Office Suite Service Pack 1 (SP1)
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9593C6E5-205E-45C3-B785-05CF146CA76A}" = biolsp patch
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9EDA3DD1-130D-4EE1-A3D2-5A3D795CC8C9}" = MFCLOC
"{A093D83F-429A-4AB2-A0CD-1F7E9C7B764A}" = Trusted Drive Manager
"{A0A77CDC-2419-4D5C-AD2C-E09E5926B806}" = Microsoft Antimalware
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AB40272D-92AB-4F30-B36B-22EDE16F8FE5}" = HP Update
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{ABBA2EA4-740E-4052-902B-9CA70B081E3F}" = Dell Embassy Trust Suite by Wave Systems
"{AC76BA86-1033-0000-BA7E-000000000003}" = Adobe Acrobat 8 Standard
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B24E05CC-46FF-4787-BBB8-5CD516AFB118}" = ccCommon
"{B32C4059-6E7A-41EF-AD20-56DF1872B923}" = Business Contact Manager for Outlook 2007 SP1
"{B391EECE-DFEA-4FC5-9D40-47FA43E2DBE6}" = Microsoft Office Accounting 2008 PayPal Addin
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B52D7A21-03E5-4C0C-82FA-FD8EB4C92149}" = AxessManager
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1C185CA-C531-49F5-A6FA-B838405A049D}" = Norton Internet Security
"{C1E693A4-B1D5-4DCD-B68D-2087835B7184}" = ScanSoft OmniPage SE 4.0
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1E829E9-88B8-47C6-A75E-0D40E2C09D50}" = Secure Update
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{DCC72248-D3D2-4846-8499-A400053A430E}" = TWC User Controls
"{E0F1D3B6-F50E-49AE-A942-FFDFFA16F9A9}" = PhotoStreamer 2
"{E3DF6916-2472-43D9-8B3C-9F2F0AAB01B5}" = Microsoft Office Accounting 2008 Fixed Asset Manager
"{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}" = Norton AntiVirus Help
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E738A392-F690-4A9D-808E-7BAF80E0B398}" = ESC Home Page Plugin
"{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}" = tooltips
"{E80F62FF-5D3C-4A19-8409-9721F2928206}" = LiveUpdate (Symantec Corporation)
"{EB4DF30B-102B-4F0C-927A-D50E037A325D}" = AuthenTec Fingerprint Sensor Minimum Install
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{EC84E3E6-C2D6-4DFB-81E0-448324C8FDF4}" = Security Wizards
"{ECC22AFA-B905-4A6A-8072-10F52B9E09B7}" = Wave Infrastructure Installer
"{EEAFE1E5-076B-430A-96D9-B567792AFA88}" = EMBASSY Security Center
"{EF05BA0F-AC15-4D12-AC5C-276225F5E751}" = Gemalto
"{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}" = AppCore
"{F1802FA6-54E9-4B24-BD2A-B50866819795}" = EMBASSY Trust Suite by Wave Systems
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F5C63795-2708-4D15-BF18-5ABBFF7DFFC8}" = iTunes
"{F63A3748-B93D-4360-9AD4-B064481A5C7B}" = Modem Diagnostic Tool
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FBEC50B7-537C-4A0E-8B0B-F7A8F8BF13CE}" = upekmsi
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FEC193E4-6C5F-40E9-A249-7D8C8404A9EC}" = NTRU TCG Software Stack
"ActiveTouchMeetingClient" = WebEx
"Adobe Acrobat 8 Standard" = Adobe Acrobat 8.1.2 Standard
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AIM_6" = AIM 6
"AOL Pictures" = AOL Pictures Tools (version 10.6.0.8)
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"Business Contact Manager" = Business Contact Manager for Outlook 2007 SP1
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2C06&SUBSYS;_14F1000F" = Conexant HDA D330 MDC V.92 Modem
"Google Desktop" = Google Desktop
"GoToAssist" = GoToAssist 8.0.0.514
"InstallShield_{07D618CD-B016-438A-ADC9-A75BD23F85CE}" = Wave Support Software
"InstallShield_{0B0A2153-58A6-4244-B458-25EDF5FCD809}" = Private Information Manager
"InstallShield_{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"InstallShield_{51AE9E42-640D-4C14-A9B6-43F64AA4E3E2}" = Document Manager Lite
"InstallShield_{53333479-6A52-4816-8497-5C52B67ED339}" = EMBASSY Security Setup
"InstallShield_{D1E829E9-88B8-47C6-A75E-0D40E2C09D50}" = Secure Update
"InstallShield_{E738A392-F690-4A9D-808E-7BAF80E0B398}" = ESC Home Page Plugin
"InstallShield_{EC84E3E6-C2D6-4DFB-81E0-448324C8FDF4}" = Security Wizards
"InstallShield_{EEAFE1E5-076B-430A-96D9-B567792AFA88}" = EMBASSY Security Center
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Office Accounting 2008" = Microsoft Office Accounting 2008
"Microsoft Security Essentials" = Microsoft Security Essentials
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Mozilla Firefox (3.5.13)" = Mozilla Firefox (3.5.13)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NVIDIA Drivers" = NVIDIA Drivers
"PhotoStreamer 2" = PhotoStreamer 2
"PsuedoLiveUpdate" = LiveUpdate (Symantec Corporation)
"RealPlayer 12.0" = RealPlayer
"SMALLBUSINESSR" = Microsoft Office Small Business 2007
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SynTPDeinstKey" = Dell Touchpad
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VideoLAN VLC media player 0.8.6i
"WIC" = Windows Imaging Component
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Extras" = Yahoo! Browser Services
"Yahoo! Mail" = Yahoo! Internet Mail
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! SiteBuilder" = Yahoo! SiteBuilder
"YInstHelper" = Yahoo! Install Manager

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2334342494-3678532155-2428501450-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Media Player" = Move Media Player
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.7.1

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/1/2010 8:17:47 PM | Computer Name = DLSCONSULTING | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module unknown, version 0.0.0.0, fault address 0x019f0f53.

Error - 11/1/2010 8:19:38 PM | Computer Name = DLSCONSULTING | Source = MsiInstaller | ID = 11706
Description = Product: ScanSoft OmniPage SE 4.0 – Error 1706.No valid source could
be found for product ScanSoft OmniPage SE 4.0. The Windows Installer cannot continue.

Error - 11/1/2010 8:20:29 PM | Computer Name = DLSCONSULTING | Source = MsiInstaller | ID = 11706
Description = Product: ScanSoft OmniPage SE 4.0 – Error 1706.No valid source could
be found for product ScanSoft OmniPage SE 4.0. The Windows Installer cannot continue.

Error - 11/1/2010 11:16:25 PM | Computer Name = DLSCONSULTING | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module unknown, version 0.0.0.0, fault address 0x02e70f12.

Error - 11/2/2010 10:12:26 AM | Computer Name = DLSCONSULTING | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80072efe, P2 endsearch, P3 search, P4 2.0.6212.0,
P5 mpsigdwn.dll, P6 2.0.6212.0, P7 microsoft antimalware (bcf43643-a118-4432-aede-d861fcbcfcde),
P8 NIL, P9 NIL, P10 NIL.

Error - 11/2/2010 11:26:03 AM | Computer Name = DLSCONSULTING | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x001a3bef.

Error - 11/2/2010 12:16:27 PM | Computer Name = DLSCONSULTING | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module unknown, version 0.0.0.0, fault address 0x03110f42.

Error - 11/2/2010 3:18:43 PM | Computer Name = DLSCONSULTING | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module unknown, version 0.0.0.0, fault address 0x031c0fa0.

Error - 11/2/2010 3:18:56 PM | Computer Name = DLSCONSULTING | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module unknown, version 0.0.0.0, fault address 0x031c0faf.

Error - 11/2/2010 3:19:02 PM | Computer Name = DLSCONSULTING | Source = Application Error | ID = 1001
Description = Fault bucket 663107094.

[ OSession Events ]
Error - 2/1/2009 3:54:38 AM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 211714
seconds with 960 seconds of active time. This session ended with a crash.

Error - 2/18/2009 1:47:45 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 706
seconds with 660 seconds of active time. This session ended with a crash.

Error - 2/24/2009 3:14:22 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6316.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 11411
seconds with 5220 seconds of active time. This session ended with a crash.

Error - 2/25/2009 3:41:54 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 1812
seconds with 240 seconds of active time. This session ended with a crash.

Error - 5/11/2009 11:51:31 AM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 2796
seconds with 540 seconds of active time. This session ended with a crash.

Error - 6/18/2009 8:18:53 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6504.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 14
seconds with 0 seconds of active time. This session ended with a crash.

Error - 7/11/2010 3:05:25 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6215.1000. This session
lasted 273 seconds with 0 seconds of active time. This session ended with a crash.

Error - 7/11/2010 3:05:36 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6215.1000. This session
lasted 3 seconds with 0 seconds of active time. This session ended with a crash.

Error - 7/11/2010 3:05:55 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6215.1000. This session
lasted 7 seconds with 0 seconds of active time. This session ended with a crash.

Error - 7/11/2010 3:06:03 PM | Computer Name = DLSCONSULTING | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6215.1000. This session
lasted 2 seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 11/2/2010 1:16:14 PM | Computer Name = DLSCONSULTING | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 11/2/2010 2:08:35 PM | Computer Name = DLSCONSULTING | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 11/2/2010 2:08:36 PM | Computer Name = DLSCONSULTING | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 11/2/2010 2:16:14 PM | Computer Name = DLSCONSULTING | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 11/2/2010 3:16:14 PM | Computer Name = DLSCONSULTING | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 11/2/2010 3:20:56 PM | Computer Name = DLSCONSULTING | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error - 11/2/2010 4:16:15 PM | Computer Name = DLSCONSULTING | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 11/2/2010 5:16:15 PM | Computer Name = DLSCONSULTING | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 11/2/2010 5:18:57 PM | Computer Name = DLSCONSULTING | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service winmgmt with
arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error - 11/2/2010 6:16:16 PM | Computer Name = DLSCONSULTING | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}


< End of report >

ckscanner.txt

CKScanner - Additional Security Risks - These are not necessarily bad
c:\documents and settings\dedrie smith\my documents\resumes\transtech\brent mccracken.doc
c:\documents and settings\dedrie smith\my documents\resumes\transtech\~$ent mccracken.doc
scanner sequence 3.AA.11
—– EOF —–
Hello nocompguru :),

When you uninstalled Norton Antivirus the last time, it did not seem to work. I guess it is within the same package as Norton Internet Security. This means you still have two Antivirus programs active, the other being Microsoft Security Essentials. Please choose one and uninstall the other to prevent conflict and hogging of resources.

——————–

Please download Malwarebytes' Anti-Malware (MBAM)© from Malwarebytes and save it to your desktop. Click here.

Run MBAM
  • Double click on mbam-setup.exe and follow the prompts to install the program.
  • At the end of installation, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • MBAM will now check for updates. If your firewall prompts, please allow it. If you can't update it, select the Update tab. Under Update mirror, select one of the websites and click on Check for Updates.
  • Upon completion of update and loading, select the Scanner tab. Click on Perform full scan, then click on Scan.
  • Leave the default options as it is and click on Start Scan.
  • If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process.
  • When done, you will be prompted. Click OK, then click on Show Results.
  • Check (tick) all items except items in the C:\System Volume Information folder and click on Remove Selected.
  • After it has removed the items, a log in Notepad will open. Please post this log in your next reply. You can also find the log in the Logs tab. The bottom most log is the latest.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware. If you receive an (Error Loading) error on reboot, please reboot a second time . It is normal for this error to occur once and does not need to be reported unless it returns on future reboots.

——————–

Please close all programs and do not run any others before and during the GMER scan. Do not use the computer for anything else until after the scan is completed.

Please download GMER and save it to your desktop. Click here.
  • Please disable your real time protection of any Antivirus, Antispyware or Antimalware programs temporarily when running GMER. They may cause the computer to freeze.
  • If you need help to disable your protection programs see here and here.
  • Double click the .exe file. If asked to allow the gmer driver file with a sys extension to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan, click on No.
  • In the right panel, you will see several boxes that have been checked (ticked).
    • Uncheck IAT/EAT
    • Uncheck All other Drives/Partitions except C:\ (leave C:\ checked)
    • Uncheck Show All (don't miss this one)
  • Then click the Scan button and wait for it to finish.
  • Once done, click on the Save… button and save it as "Gmer.txt" at a convenient location. Post the contents of that report.
  • Enable back your security softwares as soon as you completed the GMER steps.
    Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries.
If you are having problems running this version of GMER, please try running GMER in Safe Mode. You can get into Safe Mode using the F8 key during the startup of your computer after a reboot.

——————–

Please post back:
1. the MBAM result
2. GMER log
Hi I tried to locate Norton to ininstall, but I can't locate it - on my list it goes from netwaiting to nvidia drivers – any other suggestions for finding it to uninstall?
Hello nocompguru :),

To completely remove Norton products, please download the Norton Removal Tool. Click here. Choose the Norton program version you have or had and follow the steps.

Then continue with the steps I provided earlier.
Thanks…I'll keep trying … alwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 5026 Windows 5.1.2600 Service Pack 2 Internet Explorer 6.0.2900.2180 11/3/2010 2:02:57 AM mbam-log-2010-11-03 (02-02-57).txt Scan type: Full scan (C:\|) Objects scanned: 269089 Time elapsed: 3 hour(s), 20 minute(s), 51 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 10 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Documents and Settings\All Users\Application Data\05524319 (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\24100714 (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\24368225 (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\26039020 (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\33834324 (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\37198230 (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\48452831 (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\52948836 (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\72663832 (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\78977644 (Rogue.Multiple) -> Quarantined and deleted successfully. Files Infected: C:\Documents and Settings\Dedrie Smith\Local Settings\Temp\dOUl.exe (Trojan.Kates) -> Quarantined and deleted successfully. C:\Documents and Settings\Dedrie Smith\My Documents\MoveMediaPlayer_07103010.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\Documents and Settings\Dedrie Smith\Application Data\dsfsds.bat (Malware.Trace) -> Quarantined and deleted successfully. I will do the GMER when I get out of work tomorrow…thanks again!
Yes - I have a software that keeps trying to load all of the sudden – ScanSoft Omni Page – it starts up everytime I boot up – I've looked online to try to figure out what it's from – but it won't let me delete it. So I cancel out of that program – the run the GMER – then it just hangs for a while and I get the blue screen of death – actually I don't know what that blue screen is – but that's what I've always called it.
Hello nocompguru :),

Try run GMER in Safe Mode. You may want to print out the instructions due to not having Internet access during Safe Mode.

Restart in Safe Mode
  • Reboot your computer and tap on the F8 key repeatedly during startup.
  • A menu will appear. Select to start Windows in Safe Mode by using the arrow keys. Click here for tutorial on how to boot up in Safe Mode if you need help.
——————–

What error message appear when it BSOD?

Please provide the error message information as shown in the picture:

[external image: Posted Image]

The stop error will be always be displayed, but the other information may or may not be available. Just provide whatever is available.

——————–

Please post back:
1. the GMER result from Safe Mode
2. the BSOD error message
Hi – just checking in to let you know I'm still having some difficulty – my internet access is very sketchy at the moment…I have a friend who knows a bit more about these machines that I do that is coming by tomorrow to try and help me out. Hopefully I'll be able to post the GMER info tomorrow. Thanks!
Hello nocompguru :), You can share with me the problems you are facing, I will help you overcome them. We can go through the steps one by one, if you wish.
I think I finally got past the blue screen of death…the last time it came up it said Bad_Pool_Caller and the STOP: 0x000000C2 (0X0000007, OX00000CD4, OX00000000, OXC0000185)

I also think I have successfully completed the GMER…hopefully this is what you needed…

GMER 1.0.15.15477 - http://www.gmer.net
Rootkit quick scan 2010-11-09 00:11:57
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\DEDRIE~1\LOCALS~1\Temp\axlcrpod.sys


—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 sector 01: copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR

—- Devices - GMER 1.0.15 —-

Device \Device\Ide\IdeDeviceP1T0L0-e -> \??\IDE#DiskST980811AS______________________________3.CDE___#5&b6f79f4&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found

—- EOF - GMER 1.0.15 —-

Let me know if I didn't do this correctly…and Thanks again!!
Hello nocompguru :),

Great work with GMER.

Please download ERUNT© by Lars Hederer from one of the links below and save it to your desktop.

Link 1
Link 2
Link 3

Backup your registry with ERUNT
  • Double click on erunt-setup.exe and run the installation setup.
  • Follow the setup instructions until you reach Select Additional Tasks, uncheck (untick) Create NTREGOPT desktop icon.
  • Continue until you get prompted to run ERUNT at startup. Choose No.
  • Next, make sure Launch ERUNT is checked (ticked) and click Finish.
  • Click OK when ERUNT is launched, and accept all default setting. ERUNT will then backup the registry.
——————–

Fix with OTL
  • Please disable your real time protection of any Antivirus, Antispyware or Antimalware programs temporarily. They will interfere and may cause unexpected results.
  • If you need help to disable your protection programs see here and here.
  • Double click on OTL.exe to run it.
  • Copy and paste the following text into the white box below Custom Scans/Fixes:
    :otl
    SRV - File not found [Auto | Stopped] – C:\WINDOWS\System32\6to4v32.dll – (6to4)
    DRV - File not found [Kernel | System | Stopped] – C:\WINDOWS\System32\drivers\oksobxup.sys – (oksobxup)
    IE - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - Reg Error: Key error. File not found
    FF - prefs.js..browser.search.defaultengine: "Ask.com"
    FF - prefs.js..browser.search.defaultenginename: "Ask.com"
    FF - prefs.js..browser.search.order.1: "Ask.com"
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O3 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
    O4 - HKLM..\Run: [UserFaultCheck] File not found
    O15 - HKU\S-1-5-21-2334342494-3678532155-2428501450-1008\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
    O20 - AppInit_DLLs: (c:\windows\system32\hisakite.dll c:\windows\system32\zudalure.dll c:\windows\system32\rovozefa.dll c:\windows\system32\bulimane.dll c:\windows\system32\moriyava.dll c:\windows\system32\supilime.dll c:\windows\system32\bevoweja.dll c:\windows\system32\kiyajeru.dll c:\windows\system32\dehaseha.dll c:\windows\system32\natulevo.dll c:\windows\system32\vomuganu.dll c:\windows\system32\mayonibe.dll c:\windows\system32\dogatidi.dll c:\windows\system32\pekuhedo.dll) - C:\WINDOWS\System32\hisakite.dll File not found
    O20 - AppInit_DLLs: (pemobupo.dll) - File not found
    O21 - SSODL: bajiwupuh - {9e1630c6-7c5b-43f3-88fd-2ab16c3d94d1} - C:\WINDOWS\System32\teyufeve.dll File not found
    O21 - SSODL: fafejuvek - {c66ae819-8c35-4f9f-a643-63045cbebecf} - C:\WINDOWS\System32\moriyava.dll File not found
    O21 - SSODL: lolozimav - {289d3c51-2110-4650-8827-bb3d197b98ad} - C:\WINDOWS\System32\teyufeve.dll File not found
    O22 - SharedTaskScheduler: {002401d3-541f-4a08-a167-988bcde63d5e} - mujuzedij - Reg Error: Key error. File not found
    O22 - SharedTaskScheduler: {018b02ca-d120-4bf3-be8d-a5c5d3e0b107} - gahurihor - Reg Error: Key error. File not found
    O22 - SharedTaskScheduler: {0a42816f-86a2-4018-8e75-c7490c653054} - gahurihor - Reg Error: Key error. File not found
    O22 - SharedTaskScheduler: {0b331eaa-ffcb-49bb-aeec-4919f87b373c} - gahurihor - Reg Error: Key error. File not found
    O22 - SharedTaskScheduler: {1cf542fb-1517-4773-b966-ffd3dbab02dc} - tokatiluy - Reg Error: Key error. File not found
    O22 - SharedTaskScheduler: {289d3c51-2110-4650-8827-bb3d197b98ad} - jugezatag - C:\WINDOWS\System32\teyufeve.dll File not found
    O22 - SharedTaskScheduler: {298bd6e5-7f07-4e5a-b7a0-53082cab9b63} - tokatiluy - Reg Error: Key error. File not found
    O22 - SharedTaskScheduler: {34c75cca-3d66-42ae-bf3f-f005b7bc0086} - gahurihor - Reg Error: Key error. File not found
    O22 - SharedTaskScheduler: {429a2580-6151-47fb-af1d-cc581c2bd535} - jugezatag - Reg Error: Key error. File not found
    O22 - SharedTaskScheduler: {6a1355d4-879e-4d83-b740-d59902b31b6c} - tokatiluy - Reg Error: Key error. File not found
    O22 - SharedTaskScheduler: {71a41e06-4419-479b-b44c-12ddf5528c1c} - gahurihor - Reg Error: Key error. File not found
    O22 - SharedTaskScheduler: {95a847ee-8b44-460f-8d4e-6f242ea7682f} - gahurihor - Reg Error: Key error. File not found
    O22 - SharedTaskScheduler: {9675de18-8f52-4612-a8f9-c16451dbbefe} - tokatiluy - Reg Error: Key error. File not found
    O22 - SharedTaskScheduler: {9e1630c6-7c5b-43f3-88fd-2ab16c3d94d1} - tokatiluy - C:\WINDOWS\System32\teyufeve.dll File not found
    O22 - SharedTaskScheduler: {b6c16ada-5ae0-431e-8797-578fa2dfd46f} - mujuzedij - Reg Error: Key error. File not found
    O22 - SharedTaskScheduler: {b7be70e5-57a5-4aeb-a646-cd1061addc8c} - gahurihor - Reg Error: Key error. File not found
    O22 - SharedTaskScheduler: {c66ae819-8c35-4f9f-a643-63045cbebecf} - tokatiluy - C:\WINDOWS\System32\moriyava.dll File not found
    O22 - SharedTaskScheduler: {d09ec36b-34df-4f50-a0ec-868f49b6094b} - mujuzedij - Reg Error: Key error. File not found
    O22 - SharedTaskScheduler: {da73c12d-3a42-4e3d-94f8-418ebe5fd807} - jugezatag - Reg Error: Key error. File not found
    O22 - SharedTaskScheduler: {f3e2d788-efd6-491f-a8b2-725b06fc5828} - gahurihor - Reg Error: Key error. File not found
    O33 - MountPoints2\{4c007d35-8876-11de-a2c1-001c234864d1}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{4c007d35-8876-11de-a2c1-001c234864d1}\Shell\AutoRun\command - "" = E:\autorun.exe – File not found
    O33 - MountPoints2\{4c007d35-8876-11de-a2c1-001c234864d1}\Shell\phone\command - "" = E:\autorun.exe – File not found
    O33 - MountPoints2\{a1485048-13f7-11df-a37e-001f3a4cf431}\Shell\Auto\command - "" = E:\launcher.exe – File not found
    O33 - MountPoints2\{a1485048-13f7-11df-a37e-001f3a4cf431}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{a1485049-13f7-11df-a37e-001f3a4cf431}\Shell\Auto\command - "" = E:\launcher.exe – File not found
    O33 - MountPoints2\{a1485049-13f7-11df-a37e-001f3a4cf431}\Shell\AutoRun - "" = Auto&Play
    [2010/10/11 20:50:32 | 000,000,144 | —- | M] () – C:\Documents and Settings\Dedrie Smith\Application Data\dsfsds.bat
    [2009/10/24 23:33:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\05524319
    [2009/10/22 21:11:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\24100714
    [2009/10/24 23:33:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\24368225
    [2009/10/22 21:11:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\26039020
    [2009/10/28 08:19:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\33834324
    [2009/10/21 22:45:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\37198230
    [2009/10/25 20:30:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\48452831
    [2009/10/24 23:33:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\52948836
    [2009/10/21 22:45:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\72663832
    [2009/10/25 00:50:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\78977644
    [2009/10/10 23:06:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IObit
    
    :files
    dir C:\Documents and Settings\All Users\Application Data\112FD /s /c
    dir C:\Documents and Settings\All Users\Application Data\18269 /s /c
    dir C:\Documents and Settings\All Users\Application Data\23146 /s /c
    dir C:\Documents and Settings\All Users\Application Data\30109 /s /c
    dir C:\Documents and Settings\All Users\Application Data\A186 /s /c
    dir C:\Documents and Settings\All Users\Application Data\D1A5 /s /c
    dir C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} /s /c
    dir C:\Documents and Settings\All Users\Application Data\{BA892C10-A262-42D0-B6AD-2ADE4916F871} /s /c
    
    :commands
    [CREATERESTOREPOINT]
    [EMPTYFLASH]
    [resethosts]
    [emptytemp]
  • Click Run Fix.
  • Please post the contents of the fix log file back here if you are prompted to open the file. It can also be found at C:\_OTL\Moved Files as MMDDYYY_HHMMSS.log where MMDDYYY is date format and HHMMSS is time format.
  • If requested to reboot, please do so. The log file will open after restart.
  • Enable back your security softwares as soon as you completed the OTL fix steps.
——————–

Please describe if you are still having issues, along with the details.

——————–

Please post back:
1. the OTL fix log
2. details of problem
Thank you. I am out of town for work until Monday, Nov 8 – unfortunately I do not travel with my personal computer (since I have another one I have to carry for work)…sorry in advance if this is going to be a problem, the trip was unexpected.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI