This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

RegRun.exe and ipawaruy.dll

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Well, my wife just went to a recipe site of all things and now her computer is infected. She has Malware Bytes Anit-malware, Comodo firewall, WinPatroll and AVG antivirus running. And this junk STILL got through.
I am so sick and tired of the people doing this. If I ever have the chance to meet one of the idiots face to face……

OK, thanks for letting me vent. Now on to the real business.

Here's the HJT log. Thanks in advance for your help.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:10:26 PM, on 12/4/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Outlook on the Desktop\OutlookDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\PROGRA~1\MICROS~4\Office10\OUTLOOK.EXE
C:\Documents and Settings\Jill Hadley\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Stephen Loves Jill
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Fire-Trust SiteHound - {C86AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - (no file)
O2 - BHO: (no name) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [Sjokorecewekif] rundll32.exe "C:\WINDOWS\ipawaruy.dll",Startup
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [OutlookOnDesktop] C:\Outlook on the Desktop\OutlookDesktop.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-514355335-4051444915-1532494702-1005\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (User '?')
O4 - HKUS\S-1-5-21-514355335-4051444915-1532494702-1005\..\Run: [OutlookOnDesktop] C:\Outlook on the Desktop\OutlookDesktop.exe (User '?')
O4 - HKUS\S-1-5-21-514355335-4051444915-1532494702-1005\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User '?')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: &Search - http://tbedits.mywebsearch.com/one-toolbar…mp;n=2010062122
O9 - Extra button: (no name) - {11316B13-33F0-4C9F-BD55-09994CCFA8EB} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} - http://www.photodex.com/pxplay.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: !SASWinLogon - Invalid registry found
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

–
End of file - 8665 bytes
Back so soon lol

Please do the following.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.







[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER won't run try with devices unchecked.If still no go try in safe mode.



In your next reply please post the following.
  • Both OTL logs
  • GMER log
Yes… back so soon. Unfortunately. :)

Here are the OTL logs…

OTL logfile created on: 12/4/2010 6:34:13 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Jill Hadley\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 523.00 Mb Available Physical Memory | 51.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.32 Gb Total Space | 24.29 Gb Free Space | 16.83% Space Free | Partition Type: NTFS
Drive W: | 111.73 Gb Total Space | 35.35 Gb Free Space | 31.64% Space Free | Partition Type: NTFS
Drive X: | 9.41 Gb Total Space | 2.71 Gb Free Space | 28.84% Space Free | Partition Type: FAT

Computer Name: MOM | User Name: Jill Hadley | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Jill Hadley\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Outlook on the Desktop\OutlookDesktop.exe (SMR Computer Services)
PRC - C:\WINDOWS\system32\ZuneBusEnum.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Jill Hadley\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll (BillP Studios)
MOD - C:\WINDOWS\ipawaruy.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe ()
SRV - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (ZuneNetworkSvc) – c:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (ZuneWlanCfgSvc) – C:\WINDOWS\system32\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (ZuneBusEnum) – C:\WINDOWS\system32\ZuneBusEnum.exe (Microsoft Corporation)
SRV - (ELService) – C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe (Intel Corporation)
SRV - (IAANTMon) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (XDva201) – C:\WINDOWS\System32\XDva201.sys File not found
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys File not found
DRV - (SABProcEnum) – C:\Program Files\Internet Explorer\SABProcEnum.sys File not found
DRV - (PalmUSBD) – C:\WINDOWS\System32\drivers\PalmUSBD.sys File not found
DRV - (EagleNT) – C:\WINDOWS\System32\drivers\EagleNT.sys File not found
DRV - (Ad-Watch Connect Filter) – C:\WINDOWS\System32\drivers\NSDriver.sys File not found
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Inspect) – C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (cmdGuard) – C:\WINDOWS\system32\drivers\cmdGuard.sys (COMODO)
DRV - (cmdHlp) – C:\WINDOWS\system32\drivers\cmdhlp.sys (COMODO)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (JL2005C) – C:\WINDOWS\system32\drivers\jl2005c.sys (Windows ® 2000 DDK provider)
DRV - (WinUSB) – C:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (SocketLock) – C:\WINDOWS\system32\socketlock.sys ()
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (ELhid) – C:\WINDOWS\system32\drivers\ELhid.sys (Intel Corporation)
DRV - (ELmon) – C:\WINDOWS\system32\drivers\ELmon.sys (Intel Corporation)
DRV - (ELkbd) – C:\WINDOWS\system32\drivers\ELkbd.sys (Intel Corporation)
DRV - (ELmou) – C:\WINDOWS\system32\drivers\ELmou.sys (Intel Corporation)
DRV - (ELacpi) – C:\WINDOWS\system32\drivers\ELacpi.sys (Intel Corporation)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (DRVMCDB) – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (e1express) Intel® – C:\WINDOWS\system32\drivers\e1e5132.sys (Intel Corporation)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (DRVNDDM) – C:\WINDOWS\system32\drivers\DRVNDDM.SYS (Sonic Solutions)
DRV - (iastor) – C:\WINDOWS\system32\drivers\iastor.sys (Intel Corporation)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://news.yahoo.com [binary data]

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://news.yahoo.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.myspace.com/"
FF - prefs.js..network.proxy.no_proxies_on: "local,*.local"

FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/10/31 16:34:50 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{DA13D27F-371F-4A39-A5F6-453BBE384945}: C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\{DA13D27F-371F-4A39-A5F6-453BBE384945} [2010/12/04 14:22:17 | 000,000,000 | —D | M]

[2009/05/20 10:35:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\Mozilla\Firefox\Profiles\3g8lv8zo.default\extensions
[2010/05/03 10:11:14 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2008/06/18 00:43:04 | 000,086,016 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2009/11/06 18:12:11 | 000,238,776 | —- | M] (Pando Networks) – C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll

O1 HOSTS File: ([2010/10/14 11:03:50 | 000,000,934 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.runescape.com
O1 - Hosts: 127.0.0.1 www.halo3.com
O1 - Hosts: 127.0.0.1 www.galaxiesablaze.com
O1 - Hosts: 127.0.0.1 www.mortalkombat.com
O1 - Hosts: 127.0.0.1 www.mortalkombatdeception.com
O1 - Hosts: 127.0.0.1 http://simpsonizeme.com/#
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (no name) - {C86AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - No CLSID value found.
O2 - BHO: (no name) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [Sjokorecewekif] C:\WINDOWS\ipawaruy.DLL ()
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [OutlookOnDesktop] C:\Outlook on the Desktop\OutlookDesktop.exe (SMR Computer Services)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} Reg Error: Key error. (Reg Error: Key error.)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadblocker.com/activex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} http://www.photodex.com/pxplay.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Filter\x-sdch {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - Reg Error: Key error. File not found
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - Reg Error: Key error. File not found
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - Reg Error: Key error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 03:43:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe – File not found
O33 - MountPoints2\{8506fe83-105e-11dd-9942-00137211e15b}\Shell - "" = AutoRun
O33 - MountPoints2\{8506fe83-105e-11dd-9942-00137211e15b}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{8506fe83-105e-11dd-9942-00137211e15b}\Shell\AutoRun\command - "" = J:\LaunchU3.exe – File not found
O33 - MountPoints2\{afb2743b-c69b-11db-9879-00137211e15b}\Shell - "" = AutoRun
O33 - MountPoints2\{afb2743b-c69b-11db-9879-00137211e15b}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{afb2743b-c69b-11db-9879-00137211e15b}\Shell\AutoRun\command - "" = J:\LaunchU3.exe – File not found
O33 - MountPoints2\{bf1206f8-2b44-11de-9a62-00137211e15b}\Shell - "" = AutoRun
O33 - MountPoints2\{bf1206f8-2b44-11de-9a62-00137211e15b}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{bf1206f8-2b44-11de-9a62-00137211e15b}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.dll (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.JDCT - C:\WINDOWS\System32\jl_jdct.drv (JEILIN Tech.)

CREATERESTOREPOINT
Error starting restore point: System Restore is disabled.
Error closing restore point: System Restore is disabled.

========== Files/Folders - Created Within 30 Days ==========

[2010/12/04 18:31:54 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Jill Hadley\Desktop\OTL.exe
[2010/12/04 17:44:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Jill Hadley\Desktop\backups
[2010/12/04 17:39:58 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Jill Hadley\Desktop\HijackThis.exe
[2010/12/04 14:22:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\{DA13D27F-371F-4A39-A5F6-453BBE384945}
[2010/12/04 14:06:21 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Documents\Server
[2010/11/09 22:18:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Jill Hadley\Application Data\Arkadium
[2010/11/09 22:17:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2010/11/09 22:17:19 | 000,000,000 | —D | C] – C:\Program Files\Mahjongg Dimensions Deluxe
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/12/04 18:31:54 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jill Hadley\Desktop\OTL.exe
[2010/12/04 18:07:24 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/12/04 18:01:41 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/12/04 18:01:20 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/12/04 18:01:18 | 1071,812,608 | -HS- | M] () – C:\hiberfil.sys
[2010/12/04 17:39:59 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Jill Hadley\Desktop\HijackThis.exe
[2010/12/04 17:15:19 | 000,039,472 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/12/04 12:04:14 | 000,002,501 | —- | M] () – C:\Documents and Settings\Jill Hadley\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Word.lnk
[2010/12/02 21:35:05 | 000,000,072 | —- | M] () – C:\WINDOWS\MSPConv.INI
[2010/11/29 17:42:18 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/11/29 17:42:06 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/11/23 12:29:09 | 000,000,162 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/11/22 10:43:41 | 000,153,600 | —- | M] () – C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/19 13:52:34 | 000,028,160 | —- | M] () – C:\10 Rules for Dating.doc
[2010/11/19 13:34:39 | 000,057,856 | —- | M] () – C:\10 BAND REPORT.doc
[2010/11/13 08:20:36 | 000,020,992 | —- | M] () – C:\CrawlersnCruisers Show Pacard.doc
[2010/11/13 04:20:53 | 000,028,160 | —- | M] () – C:\CrawlersnCruisers Voting Sheets.doc
[2010/11/12 00:01:19 | 000,024,064 | —- | M] () – C:\Documents and Settings\Jill Hadley\My Documents\CnC AACStyle Gift Cards.doc
[2010/11/10 22:37:22 | 006,604,800 | —- | M] () – C:\CrawlersnCruisers Invitation.doc
[2010/11/09 22:17:41 | 000,001,871 | —- | M] () – C:\Documents and Settings\Jill Hadley\Desktop\Mahjongg Dimensions Deluxe.lnk
[2010/11/07 15:37:07 | 000,001,901 | —- | M] () – C:\WINDOWS\panose.bin
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/12/02 21:35:05 | 000,000,072 | —- | C] () – C:\WINDOWS\MSPConv.INI
[2010/11/18 20:26:42 | 000,028,160 | —- | C] () – C:\10 Rules for Dating.doc
[2010/11/16 18:42:42 | 000,057,856 | —- | C] () – C:\10 BAND REPORT.doc
[2010/11/13 08:20:36 | 000,020,992 | —- | C] () – C:\CrawlersnCruisers Show Pacard.doc
[2010/11/13 04:20:53 | 000,028,160 | —- | C] () – C:\CrawlersnCruisers Voting Sheets.doc
[2010/11/12 00:01:18 | 000,024,064 | —- | C] () – C:\Documents and Settings\Jill Hadley\My Documents\CnC AACStyle Gift Cards.doc
[2010/11/09 22:17:41 | 000,001,871 | —- | C] () – C:\Documents and Settings\Jill Hadley\Desktop\Mahjongg Dimensions Deluxe.lnk
[2007/08/27 12:09:53 | 000,000,475 | —- | C] () – C:\WINDOWS\KA.ini
[2007/07/19 15:30:33 | 000,000,217 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2007/03/30 13:31:20 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\dec_jl6.dll
[2007/02/06 12:14:16 | 000,000,968 | —- | C] () – C:\WINDOWS\hegames.ini
[2007/01/25 14:09:01 | 000,000,058 | —- | C] () – C:\WINDOWS\System32\EAL32.INI
[2007/01/25 13:57:50 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\PRTSERV.dll
[2006/12/03 09:46:38 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2006/10/07 12:11:48 | 000,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2006/09/09 18:06:07 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\MSVCRT10.DLL
[2006/09/09 18:05:55 | 000,000,122 | —- | C] () – C:\WINDOWS\KPCMS.INI
[2006/08/03 19:11:28 | 000,003,712 | —- | C] () – C:\WINDOWS\System32\socketlock.sys
[2006/08/03 17:27:25 | 000,000,187 | —- | C] () – C:\Documents and Settings\Jill Hadley\Application Data\G-Force Prefs (WindowsMediaPlayer).txt
[2006/05/18 08:10:28 | 000,003,072 | —- | C] () – C:\Documents and Settings\Jill Hadley\Application Data\dvd.bmk
[2006/04/30 19:22:53 | 000,153,600 | —- | C] () – C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/04/30 18:27:43 | 000,000,162 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/04/16 21:14:07 | 000,001,296 | —- | C] () – C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\FASTWiz.html
[2006/04/16 21:13:37 | 000,029,167 | —- | C] () – C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\FASTWiz.log
[2006/04/16 00:52:03 | 000,000,104 | RHS- | C] () – C:\WINDOWS\System32\6F1BB25984.sys
[2006/04/15 18:19:06 | 000,005,852 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/04/15 18:04:28 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/04/15 17:54:36 | 000,000,161 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2006/04/15 17:53:33 | 000,000,706 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2006/04/15 17:50:45 | 000,000,342 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/04/15 17:15:04 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/04/15 16:50:39 | 000,000,134 | —- | C] () – C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\fusioncache.dat
[2006/04/05 17:02:02 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/04/05 16:56:15 | 000,000,126 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/04/05 16:27:18 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/04/05 16:26:48 | 000,000,387 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/11/10 07:56:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/16 03:37:24 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/08/16 03:33:38 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/08/16 03:18:42 | 000,378,368 | —- | C] () – C:\WINDOWS\ipawaruy.dll
[2005/08/05 13:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/03/28 08:14:38 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\hpzids01.dll
[2001/07/06 15:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[1999/03/21 19:00:00 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

========== LOP Check ==========

[2010/10/31 16:37:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/10/31 16:37:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2010/10/31 15:53:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/10/31 16:36:12 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2006/07/27 12:50:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HotSync
[2010/10/31 15:52:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2007/02/17 22:26:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2007/07/10 11:51:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/07/26 16:47:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/06/06 10:40:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2010/11/09 22:18:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\Arkadium
[2010/10/31 16:38:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\AVG10
[2008/12/10 00:37:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\CVS
[2010/02/27 12:38:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\Facebook
[2006/07/27 12:48:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\HotSync
[2006/05/18 22:59:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\Leadertech
[2006/08/09 07:39:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\Morpheus
[2007/03/20 16:57:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\Netscape
[2010/02/08 13:29:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\Opera
[2006/07/11 13:44:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\PgcEdit
[2010/07/14 18:58:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\SiteHound
[2006/04/25 12:52:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\Snapfish
[2007/05/17 16:31:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\Viewpoint
[2006/07/13 16:28:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\WildTangent
[2009/05/30 08:27:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\WinPatrol
[2010/08/19 16:20:29 | 000,000,516 | —- | M] () – C:\WINDOWS\Tasks\Install.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/05/27 12:24:00 | 000,049,642 | —- | M] () – C:\0544Smudge.JPG
[2010/11/19 13:34:39 | 000,057,856 | —- | M] () – C:\10 BAND REPORT.doc
[2010/11/19 13:52:34 | 000,028,160 | —- | M] () – C:\10 Rules for Dating.doc
[2006/07/26 23:32:48 | 014,899,994 | —- | M] () – C:\3[1].20_full_release_troubleshooter.exe
[2007/12/26 12:35:44 | 000,000,035 | —- | M] () – C:\aa.txt
[2006/07/27 12:52:59 | 000,006,407 | —- | M] () – C:\additdiag.txt
[2009/01/07 14:21:56 | 000,085,999 | —- | M] () – C:\Assessing.JPG
[2009/01/07 15:22:11 | 000,024,161 | —- | M] () – C:\Assessing30.JPG
[2005/08/16 03:43:04 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/03/23 07:22:27 | 035,960,792 | —- | M] () – C:\avg75free_519a1276.exe
[2008/05/29 09:08:22 | 047,787,248 | —- | M] () – C:\avg_free_stf_en_8_100a1295.exe
[2007/05/13 19:50:07 | 386,508,799 | —- | M] () – C:\BARNYARD_DOMESTIC_WS.ISO
[2010/05/03 11:20:03 | 000,000,237 | RHS- | M] () – C:\boot.ini
[2009/01/06 06:47:30 | 000,591,988 | —- | M] (Michael Scrivo ) – C:\CalendarSetup.exe
[2007/07/06 14:50:27 | 000,055,840 | —- | M] () – C:\cd5b9f47eb3d41ef430ed81d82ef9830.jpg
[2009/04/17 06:13:21 | 000,005,522 | —- | M] () – C:\Christina'sWedding.nra
[2009/05/27 18:59:23 | 075,755,808 | —- | M] (COMODO) – C:\CIS_Setup_3.9.95478.509_XP_Vista_x32.exe
[2007/10/09 14:52:44 | 007,667,225 | —- | M] () – C:\Clean Truck.psd
[2005/08/16 03:43:04 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/10/13 08:04:26 | 006,603,776 | —- | M] () – C:\CrawlersnCruisers Donation Request Form.doc
[2010/11/10 22:37:22 | 006,604,800 | —- | M] () – C:\CrawlersnCruisers Invitation.doc
[2010/10/21 11:43:42 | 000,023,040 | —- | M] () – C:\CrawlersnCruisers Show Entry.doc
[2010/11/13 08:20:36 | 000,020,992 | —- | M] () – C:\CrawlersnCruisers Show Pacard.doc
[2010/11/13 04:20:53 | 000,028,160 | —- | M] () – C:\CrawlersnCruisers Voting Sheets.doc
[2010/10/13 21:03:21 | 000,200,061 | —- | M] () – C:\CrawlersnCruisersFlyer.jpg
[2010/10/25 10:58:38 | 016,563,712 | —- | M] () – C:\CrawlersnCruisersFlyer.p65
[2010/09/14 20:28:27 | 000,232,770 | —- | M] () – C:\CrawlersnCruisersFlyer.pdf
[2010/10/27 12:04:20 | 000,062,022 | —- | M] () – C:\CrawlersnCruisersReg.pdf
[2006/04/05 16:32:26 | 000,006,454 | RH– | M] () – C:\dell.sdr
[2005/10/11 20:03:19 | 049,804,091 | —- | M] () – C:\DreamweaverMX.zip
[2007/09/30 17:55:39 | 004,891,686 | —- | M] () – C:\Engines.psd
[2007/04/07 08:01:15 | 006,006,832 | —- | M] (Mozilla) – C:\Firefox Setup 2.0.0.3.exe
[2008/12/20 17:42:37 | 000,191,495 | —- | M] () – C:\FlamesLeft.jpg
[2008/12/20 17:41:44 | 000,189,105 | —- | M] () – C:\FlamesRight.jpg
[2010/12/04 18:01:18 | 1071,812,608 | -HS- | M] () – C:\hiberfil.sys
[2009/05/27 19:21:15 | 000,147,825 | —- | M] () – C:\hosts.zip
[2009/01/09 22:05:48 | 002,116,123 | —- | M] () – C:\IMG_2262.JPG
[2009/01/09 21:03:17 | 000,104,453 | —- | M] () – C:\IMG_2263.JPG
[2009/01/09 22:06:12 | 002,081,506 | —- | M] () – C:\IMG_2264.JPG
[2009/01/09 22:06:20 | 002,104,156 | —- | M] () – C:\IMG_2265.JPG
[2009/01/09 22:07:26 | 002,141,540 | —- | M] () – C:\IMG_2267.JPG
[2009/01/09 22:07:36 | 002,270,194 | —- | M] () – C:\IMG_2268.JPG
[2009/01/09 22:07:56 | 002,175,939 | —- | M] () – C:\IMG_2269.JPG
[2009/01/09 22:08:20 | 002,192,996 | —- | M] () – C:\IMG_2270.JPG
[2009/07/09 16:00:30 | 003,597,248 | —- | M] () – C:\IMG_3932.JPG
[2009/07/09 16:00:32 | 003,903,126 | —- | M] () – C:\IMG_3933.JPG
[2006/06/01 13:02:46 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2005/08/16 03:43:04 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2006/04/05 16:50:09 | 000,000,837 | -H– | M] () – C:\IPH.PH
[2002/04/17 02:55:30 | 000,064,056 | R— | M] () – C:\ITCEdscr.TTF
[2009/08/17 21:46:21 | 000,210,626 | —- | M] () – C:\JillBedZ.JPG
[2008/03/06 20:40:27 | 000,029,696 | —- | M] () – C:\KC Golf Proposal.doc
[2010/08/19 08:28:56 | 000,019,968 | —- | M] () – C:\Kids christmas wishlist.doc
[2008/03/07 16:34:40 | 000,582,000 | —- | M] () – C:\MCPR.exe
[2008/04/14 15:01:20 | 000,061,059 | —- | M] () – C:\MeBed.jpg
[2005/08/16 03:43:04 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2008/12/22 16:40:10 | 386,447,359 | —- | M] () – C:\NIMSB169.ISO
[2004/08/10 04:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/05 14:57:25 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/12/04 18:01:17 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2007/03/20 16:57:06 | 000,001,809 | —- | M] () – C:\photodex-presenter-install.log
[2002/04/17 02:55:36 | 000,082,680 | —- | M] () – C:\Pristina.TTF
[2009/01/07 12:34:05 | 000,105,082 | —- | M] () – C:\reflection.JPG
[2009/01/07 12:25:52 | 000,131,077 | —- | M] () – C:\reflection1.JPG
[2009/01/07 16:32:32 | 000,276,630 | —- | M] () – C:\ReflectionFlames copy.JPG
[2009/01/07 15:31:46 | 006,465,338 | —- | M] () – C:\ReflectionFlames.psd
[2009/01/07 00:14:33 | 000,112,632 | —- | M] () – C:\reflections.JPG
[2010/09/16 16:31:40 | 000,175,035 | —- | M] () – C:\SSPX6845.jpg
[2010/09/16 12:44:04 | 000,083,652 | —- | M] () – C:\SSPX6846.jpg
[2010/09/16 12:44:02 | 000,091,209 | —- | M] () – C:\SSPX6847.jpg
[2010/05/01 23:21:18 | 000,010,240 | —- | M] () – C:\stewardship program.doc
[2005/10/31 09:56:00 | 000,700,416 | —- | M] (LimeWire) – C:\StubInstaller.exe
[2008/06/27 20:36:19 | 006,467,096 | —- | M] () – C:\SUPERAntiSpyware.exe
[2006/04/05 16:50:15 | 000,000,087 | —- | M] () – C:\SystemInfo.ini
[2009/01/28 21:36:46 | 000,073,257 | —- | M] () – C:\Template%20left.jpg
[2009/01/28 21:37:00 | 000,074,439 | —- | M] () – C:\Template%20right.jpg
[2009/02/23 12:55:06 | 003,525,632 | —- | M] () – C:\The Life and Times Of Andrew.ppt
[2010/11/18 20:25:10 | 000,145,920 | -HS- | M] () – C:\Thumbs.db
[2009/01/07 12:51:09 | 001,978,204 | —- | M] () – C:\TransSRT.PSD
[2007/10/09 12:58:44 | 000,396,129 | —- | M] () – C:\Truck7855.JPG
[2006/11/29 13:41:42 | 000,030,720 | —- | M] () – C:\TYMMusic.doc
[2008/12/19 20:20:55 | 000,829,494 | —- | M] () – C:\Wolverine.BMP
[2008/12/19 20:37:02 | 000,151,985 | —- | M] () – C:\Wolverine.jpg
[2009/05/27 19:10:09 | 000,887,176 | —- | M] (BillP Studios) – C:\wpsetup.exe
[2010/01/24 10:45:10 | 000,190,730 | —- | M] () – C:\xmen3complete.jpg
[2010/07/26 16:53:22 | 000,000,150 | —- | M] () – C:\YServer.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2005/08/16 03:42:12 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2005/07/08 19:50:38 | 000,069,120 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp40i.dll
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2004/05/12 13:52:24 | 000,417,792 | —- | M] () – C:\WINDOWS\Nero PhotoShow.scr
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2005/08/16 03:27:08 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/08/16 03:27:08 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/08/16 03:27:08 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/09/05 15:03:05 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/05/20 10:48:12 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\Jill Hadley\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/08/16 03:50:28 | 000,000,079 | —- | M] () – C:\Documents and Settings\Jill Hadley\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/12/04 17:39:59 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Jill Hadley\Desktop\HijackThis.exe
[2010/12/04 18:31:54 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jill Hadley\Desktop\OTL.exe
[2010/07/26 16:59:08 | 000,204,496 | —- | M] (Malwarebytes) – C:\Documents and Settings\Jill Hadley\Desktop\StartUpLite.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >
[2004/08/10 04:00:00 | 000,000,791 | —- | M] () – C:\WINDOWS\addins\fxsext.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2006/04/15 16:50:46 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Jill Hadley\Favorites\Desktop.ini
[1999/07/03 17:38:40 | 000,000,526 | —- | M] () – C:\Documents and Settings\Jill Hadley\Favorites\My Documents.lnk

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >
Pool of Radiance remove.exe

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2009/05/18 15:35:24 | 000,000,067 | -HS- | M] () – C:\Documents and Settings\Jill Hadley\Cookies\desktop.ini
[2010/12/04 18:35:28 | 000,098,304 | -HS- | M] () – C:\Documents and Settings\Jill Hadley\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-10 09:03:58

< >

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 171 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D2F2F703
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:44DAF2F1

< End of report >



OTL Extras logfile created on: 12/4/2010 6:34:13 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Jill Hadley\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 523.00 Mb Available Physical Memory | 51.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.32 Gb Total Space | 24.29 Gb Free Space | 16.83% Space Free | Partition Type: NTFS
Drive W: | 111.73 Gb Total Space | 35.35 Gb Free Space | 31.64% Space Free | Partition Type: NTFS
Drive X: | 9.41 Gb Total Space | 2.71 Gb Free Space | 28.84% Space Free | Partition Type: FAT

Computer Name: MOM | User Name: Jill Hadley | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 4

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – File not found
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – File not found
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL – File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – (Lime Wire, LLC)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Disabled:AOL – File not found
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Disabled:AOL – File not found
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Disabled:AOL – File not found
"C:\Program Files\HP\HP Officejet Pro K550 Series\Toolbox\HPWUTBX.exe" = C:\Program Files\HP\HP Officejet Pro K550 Series\Toolbox\HPWUTBX.exe:*:Enabled:Toolbox for HP Printing System for Windows – (Hewlett-Packard Company)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – File not found
"C:\Program Files\Opera\opera.exe" = C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser – File not found
"C:\Program Files\MySpace\IM\MySpaceIM.exe" = C:\Program Files\MySpace\IM\MySpaceIM.exe:*:Enabled:MySpaceIM – File not found
"C:\Program Files\AVG\AVG10\avgdiagex.exe" = C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostics 2011 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgnsx.exe" = C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgemcx.exe" = C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{0076E1AC-9E7B-4B9F-A62A-4CC9511AD8E3}" = Zune Language Pack (FR)
"{0323CB96-221A-4042-84A3-93EDE47099FC}" = AVG 2011
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio RecordNow Data
"{0D2E80C8-0875-43EB-9623-47118E2DFBCA}" = Quicken 2007
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Roxio DLA
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1A258E63-8DF5-4ADB-9832-38A0121D65EB}" = AVG 2011
"{1C875160-7E87-45C6-85C5-4FE2A840A3B8}" = Maxtor Quick Start
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Roxio MyDVD LE
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 20
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
"{4667B940-BB01-428B-986E-A0CC46497BF7}" = ELIcon
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CEA6811-DFAD-4892-828D-49941FE3B779}" = Intel® PROSet for Wired Connections
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}" = Sonic Activation Module
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}" = Digital Content Portal
"{6D9785D9-FF53-4C06-9C2A-E4173D41A2FD}_is1" = Outlook on the Desktop 1.5.0
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{78EFA95D-3310-4035-815B-A46BA4D0C6FA}" = VOB2MPG 2.3
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8C22F265-DE76-44D1-8A79-A71D819137DA}" = Intel® Quick Resume Technology Drivers
"{8E49C988-C8F1-4197-AA6B-94E49751F5D7}" = Microsoft IntelliType Pro 6.3
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{903CE8F7-6C7B-41E6-A1CF-3BF1176264EC}" = Intel® Viiv™
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel Matrix Storage Manager
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio RecordNow Audio
"{AC60C8C1-855E-45AB-8D95-1D16F8A38E78}" = UGuide
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio RecordNow Copy
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{BA7A3288-228D-4031-A93A-B5F6B3415E15}" = Misc
"{BCE72AED-3332-4863-9567-C5DCB9052CA2}" = Netflix Movie Viewer
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}" = Canon Utilities ZoomBrowser EX
"{C7DDA8E7-AD3D-4F51-AC1E-B0FF57002192}" = Microsoft IntelliPoint 6.3
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{EDE721EC-870A-11D8-9D75-000129760D75}" = PowerDirector Express
"{EE4ACABF-531E-419A-9225-B8E0FA4955AF}" = Zune Language Pack (ES)
"{F1CD25A0-5401-40B2-BAA9-E267408B16DF}" = Toolbox
"{F5346614-B7C4-4E94-826A-E2363155233D}" = EasyCleaner
"{FD8E178D-8B4E-42DA-B434-EFF270329B1C}" = COMODO Internet Security
"{FF70513F-E3A7-402F-84FB-B7810A064BE2}" = Zune
"12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
"2G_1.2" = JumpStart 2nd Grade v1.2
"989E4C3B-B2C9-4486-9A09-D5A8F953837C" = Bejeweled 2 Deluxe
"Adobe Acrobat 4.0" = Adobe Acrobat 4.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe PageMaker 6.5" = Adobe PageMaker 6.5
"Adobe Photoshop 5.0 Limited Edition" = Adobe Photoshop 5.0 Limited Edition
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AVG" = AVG 2011
"CleanUp!" = CleanUp!
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Dell Game Console" = Dell Game Console
"Dual Mode Camera_is1" = Uninstall Dual Mode Camera
"DVD Shrink_is1" = DVD Shrink 3.2
"DVDFab Decrypter_is1" = DVDFab Decrypter 2.9.7.9
"Easy Chef's Million Recipes" = Easy Chef's Million Recipes
"EmeraldQFE2" = Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
"EPSON Printer and Utilities" = EPSON Printer Software
"ERUNT_is1" = ERUNT 1.1j
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"HP Officejet Pro K550 Series" = HP Officejet Pro K550 Series
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{1C875160-7E87-45C6-85C5-4FE2A840A3B8}" = Maxtor Quick Start
"InstallShield_{F11A403B-0DE9-4953-B790-7A2F014FBB2B}" = Canon Utilities PhotoStitch 3.1
"Intel® Quick Resume Technology" = Intel® Quick Resume Technology Drivers
"LimeWire" = LimeWire 4.16.0
"Mahjongg Dimensions Deluxe" = Mahjongg Dimensions Deluxe (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Morpheus" = Morpheus 5.2 (remove only)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSPUB4" = Microsoft Publisher 97
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"Nero PhotoShow Express" = Nero PhotoShow Express
"NeroVision!UninstallKey" = NeroVision Express 2
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NMIX!UninstallKey" = NeroMIX
"NVIDIA Drivers" = NVIDIA Drivers
"PRC_1.0" = JumpStart Parent Resource Center v1.0
"Print Server Driver" = Print Server Driver
"PROSet" = Intel® PRO Network Connections Drivers
"Putt-Putt Travels Through Time" = Putt-Putt Travels Through Time
"Tetris" = Tetris (remove only)
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinPatrol" = WinPatrol 2009
"winusb0100" = Microsoft WinUsb 1.0
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01007" = Microsoft User-Mode Driver Framework Feature Pack 1.7
"Zune" = Zune

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/4/2010 6:02:56 PM | Computer Name = MOM | Source = WinMgmt | ID = 27
Description = WinMgmt could not open the repository file. This could be due to
insufficient security access to the "\System32\WBEM\Repository", insufficient
disk space or insufficient memory.

Error - 12/4/2010 6:02:56 PM | Computer Name = MOM | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 12/4/2010 7:15:14 PM | Computer Name = MOM | Source = WinMgmt | ID = 27
Description = WinMgmt could not open the repository file. This could be due to
insufficient security access to the "\System32\WBEM\Repository", insufficient
disk space or insufficient memory.

Error - 12/4/2010 7:15:14 PM | Computer Name = MOM | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 12/4/2010 7:34:41 PM | Computer Name = MOM | Source = WinMgmt | ID = 27
Description = WinMgmt could not open the repository file. This could be due to
insufficient security access to the "\System32\WBEM\Repository", insufficient
disk space or insufficient memory.

Error - 12/4/2010 7:34:41 PM | Computer Name = MOM | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 12/4/2010 7:45:59 PM | Computer Name = MOM | Source = WinMgmt | ID = 27
Description = WinMgmt could not open the repository file. This could be due to
insufficient security access to the "\System32\WBEM\Repository", insufficient
disk space or insufficient memory.

Error - 12/4/2010 7:46:00 PM | Computer Name = MOM | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

Error - 12/4/2010 8:01:34 PM | Computer Name = MOM | Source = WinMgmt | ID = 27
Description = WinMgmt could not open the repository file. This could be due to
insufficient security access to the "\System32\WBEM\Repository", insufficient
disk space or insufficient memory.

Error - 12/4/2010 8:01:34 PM | Computer Name = MOM | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.

[ IntelDH Events ]
Error - 11/15/2010 4:17:45 PM | Computer Name = MOM | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 11/18/2010 10:29:35 PM | Computer Name = MOM | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 11/19/2010 3:22:19 PM | Computer Name = MOM | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 11/22/2010 11:43:05 PM | Computer Name = MOM | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 12/3/2010 11:30:55 PM | Computer Name = MOM | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 12/4/2010 4:19:20 PM | Computer Name = MOM | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 12/4/2010 6:02:57 PM | Computer Name = MOM | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 12/4/2010 7:15:15 PM | Computer Name = MOM | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 12/4/2010 7:34:42 PM | Computer Name = MOM | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

Error - 12/4/2010 7:46:01 PM | Computer Name = MOM | Source = IntelQRTD | ID = 7
Description = Could not attach to EL Acpi driver.

[ System Events ]
Error - 11/23/2010 3:22:11 AM | Computer Name = MOM | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.5 for the Network Card with network
address 00137211E15B has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).

Error - 11/23/2010 2:29:11 PM | Computer Name = MOM | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service upnphost with
arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}

Error - 12/4/2010 4:19:15 PM | Computer Name = MOM | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 12/4/2010 4:20:17 PM | Computer Name = MOM | Source = System Error | ID = 1003
Description = Error code 100000d1, parameter1 00000018, parameter2 00000002, parameter3
00000000, parameter4 f73af25f.

Error - 12/4/2010 4:20:52 PM | Computer Name = MOM | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service ehRecvr with
arguments "-Service" in order to run the server: {F4396DC6-E851-4D3A-8D01-34E6949F3500}

Error - 12/4/2010 6:02:52 PM | Computer Name = MOM | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 12/4/2010 7:15:10 PM | Computer Name = MOM | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 12/4/2010 7:34:40 PM | Computer Name = MOM | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 12/4/2010 7:45:56 PM | Computer Name = MOM | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 12/4/2010 8:01:31 PM | Computer Name = MOM | Source = SRService | ID = 104
Description = The System Restore initialization process failed.


< End of report >



And the Gmer log

GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-12-04 21:51:57
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 WDC_WD16 rev.10.0
Running: gmer.exe; Driver: C:\DOCUME~1\JILLHA~1\LOCALS~1\Temp\pxtdypow.sys


—- System - GMER 1.0.15 —-

SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xED0EB620] <– ROOTKIT !!!

—- Kernel code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF627B360, 0x20FDBD, 0xE8000020]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Internet Explorer\iexplore.exe[152] kernel32.dll!CreateProcessInternalW 7C8197B0 5 Bytes JMP 0015737C
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154F5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9ACD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD12D C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254656 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5027 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4F59 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4FC4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4E2A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4E8C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E508A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4EEE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 3E2EDB80 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3E538F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[152] ws2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 0015613F
.text C:\Program Files\Internet Explorer\iexplore.exe[152] ws2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00155F43
.text C:\Program Files\Internet Explorer\iexplore.exe[152] ws2_32.dll!send 71AB4C27 5 Bytes JMP 00155ACB
.text C:\Program Files\Internet Explorer\iexplore.exe[152] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00155CC8
.text C:\Program Files\Internet Explorer\iexplore.exe[152] ws2_32.dll!recv 71AB676F 5 Bytes JMP 00155B3E
.text C:\Program Files\Internet Explorer\iexplore.exe[152] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00155C19
.text C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[1104] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 005017E0 C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO Internet Security/COMODO)
.text C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[1104] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 005181B0 C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO Internet Security/COMODO)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] kernel32.dll!CreateProcessInternalW 7C8197B0 5 Bytes JMP 0015737C
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154F5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9ACD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD12D C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E254656 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5027 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4F59 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4FC4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4E2A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4E8C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E508A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4EEE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 3E2EDB80 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3E538F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] ws2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 0015613F
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] ws2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00155F43
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] ws2_32.dll!send 71AB4C27 5 Bytes JMP 00155ACB
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00155CC8
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] ws2_32.dll!recv 71AB676F 5 Bytes JMP 00155B3E
.text C:\Program Files\Internet Explorer\iexplore.exe[2400] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00155C19
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] kernel32.dll!CreateProcessInternalW 7C8197B0 5 Bytes JMP 0015737C
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154F5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB24 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5027 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4F59 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4FC4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4E2A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4E8C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E508A C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4EEE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] ws2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 0015613F
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] ws2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00155F43
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] ws2_32.dll!send 71AB4C27 5 Bytes JMP 00155ACB
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00155CC8
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] ws2_32.dll!recv 71AB676F 5 Bytes JMP 00155B3E
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00155C19
.text C:\WINDOWS\Explorer.EXE[3276] kernel32.dll!CreateProcessInternalW 7C8197B0 5 Bytes JMP 00B48369
.text C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[3600] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 00719AB0 C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO Internet Security/COMODO)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\Ip socketlock.sys
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\Tcp socketlock.sys
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Avgtdix \Device\AvgTdi socketlock.sys

AttachedDevice \Driver\Tcpip \Device\Udp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\Udp socketlock.sys
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\Tcpip \Device\RawIp socketlock.sys
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \FileSystem\Fastfat \Fat B5AF1D20
Device \FileSystem\Fastfat \Fat B5B01428

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)

—- Services - GMER 1.0.15 —-

Service system32\drivers\ovfsthidtikbcepoqouqduthtseojxdsnrykbn.sys (*** hidden *** ) [SYSTEM] ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@start 1
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@type 1
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@group file system
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@imagepath \systemroot\system32\drivers\ovfsthidtikbcepoqouqduthtseojxdsnrykbn.sys
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@inst 0
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@ver sni060409
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@cid 01
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@bid 3630642939-514355335-4051444915-1532494702
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@aid 998
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@sid 3
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@feed 0x22 0x64 0x78 0x36 …
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@cmddelay 28801
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@logoffset 4087
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\[removed] ovfsthwi.dll
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\[removed] ovfsthff.dll
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\drivers\ovfsthidtikbcepoqouqduthtseojxdsnrykbn.sys
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthsvjupfblextaporxbcbahnriymgargnv.dll
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthwpcwvsmitrpkcbvmkejyhekmbquxlgyk.dat
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthnjqpfrxqtswnfkvwfjlxspvynteypelv.dll
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthwcrcqmjnkiheoifiivvknytmohgldrrd.dll
Reg HKLM\SYSTEM\ControlSet001\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthgmkwrqvurcnlxsvfpaowtsswrtpgasxd.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@imagepath \systemroot\system32\drivers\ovfsthidtikbcepoqouqduthtseojxdsnrykbn.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@inst 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@ver sni060409
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@cid 01
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@bid 3630642939-514355335-4051444915-1532494702
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@aid 998
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@sid 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@feed 0x22 0x64 0x78 0x36 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@cmddelay 28801
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@logoffset 4087
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\[removed] ovfsthwi.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\[removed] ovfsthff.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\drivers\ovfsthidtikbcepoqouqduthtseojxdsnrykbn.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthsvjupfblextaporxbcbahnriymgargnv.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthwpcwvsmitrpkcbvmkejyhekmbquxlgyk.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthnjqpfrxqtswnfkvwfjlxspvynteypelv.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthwcrcqmjnkiheoifiivvknytmohgldrrd.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthgmkwrqvurcnlxsvfpaowtsswrtpgasxd.dat
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@imagepath \systemroot\system32\drivers\ovfsthidtikbcepoqouqduthtseojxdsnrykbn.sys
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu@inst 0
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@ver sni060409
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@cid 01
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@bid 3630642939-514355335-4051444915-1532494702
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@aid 998
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@sid 3
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@feed 0x22 0x64 0x78 0x36 …
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@cmddelay 28801
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main@logoffset 4087
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\[removed] ovfsthwi.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\[removed] ovfsthff.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\drivers\ovfsthidtikbcepoqouqduthtseojxdsnrykbn.sys
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthsvjupfblextaporxbcbahnriymgargnv.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthwpcwvsmitrpkcbvmkejyhekmbquxlgyk.dat
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthnjqpfrxqtswnfkvwfjlxspvynteypelv.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthwcrcqmjnkiheoifiivvknytmohgldrrd.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu\[removed] \systemroot\system32\ovfsthgmkwrqvurcnlxsvfpaowtsswrtpgasxd.dat
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}@ Wireless
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}@ProcessGroupPolicy ProcessWIRELESSPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}@DllName gptext.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}@ Folder Redirection
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}@ProcessGroupPolicyEx ProcessGroupPolicyEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}@DllName fdeploy.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}@NoMachinePolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}@NoSlowLink 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}@PerUserLocalSettings 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}@NoGPOListChanges 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}@NoBackgroundPolicy 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}@GenerateGroupPolicy GenerateGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}@EventSources (Folder Redirection,Application)?
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@ Microsoft Disk Quota
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@NoMachinePolicy 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@NoSlowLink 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@NoBackgroundPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@PerUserLocalSettings 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@RequiresSuccessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@EnableAsynchronousProcessing 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@DllName dskquota.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@ProcessGroupPolicy ProcessGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}@ QoS Packet Scheduler
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}@ProcessGroupPolicy ProcessPSCHEDPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}@DllName gptext.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}@ Scripts
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}@ProcessGroupPolicy ProcessScriptsGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}@ProcessGroupPolicyEx ProcessScriptsGroupPolicyEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}@GenerateGroupPolicy GenerateScriptsGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}@DllName gptext.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}@NoSlowLink 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}@NotifyLinkTransition 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@ Internet Explorer Zonemapping
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@DllName C:\WINDOWS\system32\iedkcs32.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@ProcessGroupPolicy ProcessGroupPolicyForZoneMap
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@RequiresSucessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@DisplayName @C:\WINDOWS\system32\iedkcs32.dll.mui,-3051
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}@RequiresSuccessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@ Internet Explorer User Accelerators
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@DisplayName @C:\WINDOWS\system32\iedkcs32.dll.mui,-3051
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@DllName C:\WINDOWS\system32\iedkcs32.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@ProcessGroupPolicy ProcessGroupPolicyForActivities
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@ProcessGroupPolicyEx ProcessGroupPolicyForActivitiesEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}@RequiresSuccessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@ProcessGroupPolicy SceProcessSecurityPolicyGPO
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@GenerateGroupPolicy SceGenerateGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@ExtensionRsopPlanningDebugLevel 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@ProcessGroupPolicyEx SceProcessSecurityPolicyGPOEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@ExtensionDebugLevel 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@DllName scecli.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@ Security
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@EnableAsynchronousProcessing 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@MaxNoGPOListChangesInterval 960
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@ProcessGroupPolicyEx ProcessGroupPolicyEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@GenerateGroupPolicy GenerateGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@ProcessGroupPolicy ProcessGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@DllName C:\WINDOWS\system32\iedkcs32.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@ Internet Explorer Branding
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@NoSlowLink 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@NoBackgroundPolicy 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@NoMachinePolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}@DisplayName @C:\WINDOWS\system32\iedkcs32.dll.mui,-3014
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@ProcessGroupPolicy SceProcessEFSRecoveryGPO
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@DllName scecli.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@ EFS recovery
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}@RequiresSuccessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}@ 802.3 Group Policy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}@DisplayName @dot3gpclnt.dll,-100
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}@ProcessGroupPolicyEx ProcessLANPolicyEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}@GenerateGroupPolicy GenerateLANPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}@DllName dot3gpclnt.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@ Microsoft Offline Files
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@DllName %SystemRoot%\System32\cscui.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@EnableAsynchronousProcessing 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@NoBackgroundPolicy 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@NoGPOListChanges 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@NoMachinePolicy 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@NoSlowLink 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@PerUserLocalSettings 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@ProcessGroupPolicy ProcessGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}@RequiresSuccessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@ Software Installation
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@DllName appmgmts.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@ProcessGroupPolicyEx ProcessGroupPolicyObjectsEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@GenerateGroupPolicy GenerateGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@NoBackgroundPolicy 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@RequiresSucessfulRegistry 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@NoSlowLink 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@PerUserLocalSettings 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@EventSources (Application Management,Application)?(MsiInstaller,Application)?
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@ Internet Explorer Machine Accelerators
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@DisplayName @C:\WINDOWS\system32\iedkcs32.dll.mui,-3051
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@DllName C:\WINDOWS\system32\iedkcs32.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@ProcessGroupPolicy ProcessGroupPolicyForActivities
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@ProcessGroupPolicyEx ProcessGroupPolicyForActivitiesEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}@RequiresSuccessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}@ IP Security
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}@ProcessGroupPolicy ProcessIPSECPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}@DllName gptext.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}@NoGPOListChanges 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@HelpAssistant 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@TsInternetUser 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@SQLAgentCmdExec 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@NetShowServices 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@IWAM_ 65536
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@IUSR_ 65536
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@VUSR_ 65536
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList@ASPNET 0

—- EOF - GMER 1.0.15 —-
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Here is the ComboFix log…

ComboFix 10-12-04.02 - Jill Hadley 12/05/2010 17:42:45.1.2 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Jill Hadley\Application Data\Adobe\AdobeUpdate .exe
c:\documents and settings\Jill Hadley\Application Data\Adobe\plugs
c:\documents and settings\Jill Hadley\Local Settings\Application Data\{DA13D27F-371F-4A39-A5F6-453BBE384945}
c:\documents and settings\Jill Hadley\Local Settings\Application Data\{DA13D27F-371F-4A39-A5F6-453BBE384945}\chrome.manifest
c:\documents and settings\Jill Hadley\Local Settings\Application Data\{DA13D27F-371F-4A39-A5F6-453BBE384945}\chrome\content\_cfg.js
c:\documents and settings\Jill Hadley\Local Settings\Application Data\{DA13D27F-371F-4A39-A5F6-453BBE384945}\chrome\content\overlay.xul
c:\documents and settings\Jill Hadley\Local Settings\Application Data\{DA13D27F-371F-4A39-A5F6-453BBE384945}\install.rdf
C:\Thumbs.db
c:\windows\Downloaded Program Files\popcaploader.inf

Infected copy of c:\windows\system32\winlogon.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\winlogon.exe

Infected copy of c:\windows\explorer.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\explorer.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu
——-\Service_ovfsthixgobwqwbdmcjtbvspylqevspvnxxexu


((((((((((((((((((((((((( Files Created from 2010-11-05 to 2010-12-05 )))))))))))))))))))))))))))))))
.

2010-11-10 04:18 . 2010-11-10 04:18 ——– d—–w- c:\documents and settings\Jill Hadley\Application Data\Arkadium
2010-11-10 04:17 . 2010-11-10 04:17 ——– d—–w- c:\documents and settings\All Users\Application Data\Trymedia
2010-11-10 04:17 . 2010-11-10 04:17 ——– d—–w- c:\program files\Mahjongg Dimensions Deluxe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-29 23:42 . 2009-05-22 22:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-29 23:42 . 2009-05-22 22:07 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-09-18 17:23 . 2005-08-16 09:18 974848 —-a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2005-08-16 09:18 974848 —-a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2005-08-16 09:18 954368 —-a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2005-08-16 09:18 953856 —-a-w- c:\windows\system32\mfc40u.dll
2010-09-11 04:41 . 2010-09-11 04:41 285480 —-a-w- c:\windows\system32\guard32.dll
2010-09-11 04:40 . 2010-09-11 04:40 91560 —-a-w- c:\windows\system32\drivers\inspect.sys
2010-09-11 04:40 . 2010-09-11 04:40 25240 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-09-11 04:40 . 2010-09-11 04:40 239240 —-a-w- c:\windows\system32\drivers\cmdGuard.sys
2010-09-11 04:40 . 2010-09-11 04:40 15592 —-a-w- c:\windows\system32\drivers\cmderd.sys
2010-09-10 05:58 . 2005-08-16 09:18 916480 —-a-w- c:\windows\system32\wininet.dll
2010-09-10 05:58 . 2005-08-16 09:18 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:58 . 2005-08-16 09:18 1469440 ——w- c:\windows\system32\inetcpl.cpl
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-12-04 2424560]
"OutlookOnDesktop"="c:\outlook on the desktop\OutlookDesktop.exe" [2008-12-11 332288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-04-20 337216]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2009-01-07 1496968]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-09-11 2500552]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-08 20:18 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TabUserW.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\TabUserW.exe.lnk
backup=c:\windows\pss\TabUserW.exe.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-04 05:42 36272 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLA]
2005-09-08 10:20 122940 —-a-w- c:\windows\system32\DLA\DLACTRLW.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
2005-09-29 19:01 67584 —-a-w- c:\windows\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPWUTOOLBOX]
2005-07-23 07:18 352256 —-a-w- c:\program files\HP\HP Officejet Pro K550 Series\Toolbox\HPWUTBX.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2005-06-17 12:56 139264 —-a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2005-06-10 15:44 249856 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2005-06-10 15:44 81920 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mssSort]
2005-01-10 13:53 45056 —-a-w- c:\program files\Maxtor\Maxtor Quick Start\msssort.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 16:50 155648 —-a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoShow Deluxe Media Manager]
2004-05-12 20:04 196608 —-a-w- c:\progra~1\Ahead\Ahead\data\Xtras\mssysmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-01-05 22:18 413696 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2005-03-23 04:20 339968 —-a-w- c:\windows\stsystra.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 16:43 248040 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]
2008-11-10 18:23 157312 —-a-w- c:\program files\Zune\ZuneLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ehRecvr"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\HP Officejet Pro K550 Series\\Toolbox\\HPWUTBX.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=

R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2010-03-27 12872]
R3 XDva201;XDva201;c:\windows\system32\XDva201.sys [x]
R4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-12-21 135664]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2010-09-11 239240]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2010-09-11 25240]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-03-27 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2010-06-18 67656]
S2 SocketLock;Raw Socket Lock Driver;c:\windows\system32\socketlock.sys [2006-08-04 3712]

.
Contents of the 'Scheduled Tasks' folder

2010-12-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-07-01 15:22]

2010-08-19 c:\windows\Tasks\Install.job
- c:\windows\system32\Adobe\Shockwave 11\nssstub.exe [2010-06-01 23:14]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.myspace.com/
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} -
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-Wdf01000.sys
MSConfigStartUp-CheckRegDefragService - c:\progra~1\REGIST~2\rbcs.exe
MSConfigStartUp-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
MSConfigStartUp-mcagent_exe - c:\program files\McAfee.com\Agent\mcagent.exe
MSConfigStartUp-MySpaceIM - c:\program files\MySpace\IM\MySpaceIM.exe
MSConfigStartUp-Pando Media Booster - c:\program files\Pando Networks\Media Booster\PMB.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
AddRemove-HijackThis - c:\bwht202\HijackThis.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-05 17:50
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}]
@DACL=(02 0000)
@="Wireless"
"ProcessGroupPolicy"="ProcessWIRELESSPolicy"
"DllName"=expand:"gptext.dll"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}]
@DACL=(02 0000)
@="Folder Redirection"
"ProcessGroupPolicyEx"="ProcessGroupPolicyEx"
"DllName"=expand:"fdeploy.dll"
"NoMachinePolicy"=dword:00000001
"NoSlowLink"=dword:00000001
"PerUserLocalSettings"=dword:00000001
"NoGPOListChanges"=dword:00000000
"NoBackgroundPolicy"=dword:00000000
"GenerateGroupPolicy"="GenerateGroupPolicy"
"EventSources"=multi:"(Folder Redirection,Application)\00\00"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}]
@DACL=(02 0000)
@="Microsoft Disk Quota"
"NoMachinePolicy"=dword:00000000
"NoUserPolicy"=dword:00000001
"NoSlowLink"=dword:00000001
"NoBackgroundPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
"PerUserLocalSettings"=dword:00000000
"RequiresSuccessfulRegistry"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000000
"DllName"=expand:"dskquota.dll"
"ProcessGroupPolicy"="ProcessGroupPolicy"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}]
@DACL=(02 0000)
@="QoS Packet Scheduler"
"ProcessGroupPolicy"="ProcessPSCHEDPolicy"
"DllName"=expand:"gptext.dll"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}]
@DACL=(02 0000)
@="Scripts"
"ProcessGroupPolicy"="ProcessScriptsGroupPolicy"
"ProcessGroupPolicyEx"="ProcessScriptsGroupPolicyEx"
"GenerateGroupPolicy"="GenerateScriptsGroupPolicy"
"DllName"=expand:"gptext.dll"
"NoSlowLink"=dword:00000001
"NoGPOListChanges"=dword:00000001
"NotifyLinkTransition"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}]
@DACL=(02 0000)
@="Internet Explorer Zonemapping"
"DllName"="c:\\WINDOWS\\system32\\iedkcs32.dll"
"ProcessGroupPolicy"="ProcessGroupPolicyForZoneMap"
"NoGPOListChanges"=dword:00000001
"RequiresSucessfulRegistry"=dword:00000001
"DisplayName"="@c:\\WINDOWS\\system32\\iedkcs32.dll.mui,-3051"
"RequiresSuccessfulRegistry"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}]
@DACL=(02 0000)
@="Internet Explorer User Accelerators"
"DisplayName"="@c:\\WINDOWS\\system32\\iedkcs32.dll.mui,-3051"
"DllName"="c:\\WINDOWS\\system32\\iedkcs32.dll"
"NoGPOListChanges"=dword:00000001
"ProcessGroupPolicy"="ProcessGroupPolicyForActivities"
"ProcessGroupPolicyEx"="ProcessGroupPolicyForActivitiesEx"
"RequiresSuccessfulRegistry"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}]
@DACL=(02 0000)
"ProcessGroupPolicy"="SceProcessSecurityPolicyGPO"
"GenerateGroupPolicy"="SceGenerateGroupPolicy"
"ExtensionRsopPlanningDebugLevel"=dword:00000001
"ProcessGroupPolicyEx"="SceProcessSecurityPolicyGPOEx"
"ExtensionDebugLevel"=dword:00000001
"DllName"=expand:"scecli.dll"
@="Security"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
"MaxNoGPOListChangesInterval"=dword:000003c0

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}]
@DACL=(02 0000)
"ProcessGroupPolicyEx"="ProcessGroupPolicyEx"
"GenerateGroupPolicy"="GenerateGroupPolicy"
"ProcessGroupPolicy"="ProcessGroupPolicy"
"DllName"="c:\\WINDOWS\\system32\\iedkcs32.dll"
@="Internet Explorer Branding"
"NoSlowLink"=dword:00000001
"NoBackgroundPolicy"=dword:00000000
"NoGPOListChanges"=dword:00000001
"NoMachinePolicy"=dword:00000001
"DisplayName"="@c:\\WINDOWS\\system32\\iedkcs32.dll.mui,-3014"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}]
@DACL=(02 0000)
"ProcessGroupPolicy"="SceProcessEFSRecoveryGPO"
"DllName"=expand:"scecli.dll"
@="EFS recovery"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
"RequiresSuccessfulRegistry"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}]
@DACL=(02 0000)
@="802.3 Group Policy"
"DisplayName"=expand:"@dot3gpclnt.dll,-100"
"ProcessGroupPolicyEx"="ProcessLANPolicyEx"
"GenerateGroupPolicy"="GenerateLANPolicy"
"DllName"=expand:"dot3gpclnt.dll"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}]
@DACL=(02 0000)
@="Microsoft Offline Files"
"DllName"=expand:"%SystemRoot%\\System32\\cscui.dll"
"EnableAsynchronousProcessing"=dword:00000000
"NoBackgroundPolicy"=dword:00000000
"NoGPOListChanges"=dword:00000000
"NoMachinePolicy"=dword:00000000
"NoSlowLink"=dword:00000000
"NoUserPolicy"=dword:00000001
"PerUserLocalSettings"=dword:00000000
"ProcessGroupPolicy"="ProcessGroupPolicy"
"RequiresSuccessfulRegistry"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}]
@DACL=(02 0000)
@="Software Installation"
"DllName"=expand:"appmgmts.dll"
"ProcessGroupPolicyEx"="ProcessGroupPolicyObjectsEx"
"GenerateGroupPolicy"="GenerateGroupPolicy"
"NoBackgroundPolicy"=dword:00000000
"RequiresSucessfulRegistry"=dword:00000000
"NoSlowLink"=dword:00000001
"PerUserLocalSettings"=dword:00000001
"EventSources"=multi:"(Application Management,Application)\00(MsiInstaller,Application)\00\00"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}]
@DACL=(02 0000)
@="Internet Explorer Machine Accelerators"
"DisplayName"="@c:\\WINDOWS\\system32\\iedkcs32.dll.mui,-3051"
"DllName"="c:\\WINDOWS\\system32\\iedkcs32.dll"
"NoGPOListChanges"=dword:00000001
"ProcessGroupPolicy"="ProcessGroupPolicyForActivities"
"ProcessGroupPolicyEx"="ProcessGroupPolicyForActivitiesEx"
"RequiresSuccessfulRegistry"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}]
@DACL=(02 0000)
@="IP Security"
"ProcessGroupPolicy"="ProcessIPSECPolicy"
"DllName"=expand:"gptext.dll"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000000

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList]
@DACL=(02 0000)
"HelpAssistant"=dword:00000000
"TsInternetUser"=dword:00000000
"SQLAgentCmdExec"=dword:00000000
"NetShowServices"=dword:00000000
"IWAM_"=dword:00010000
"IUSR_"=dword:00010000
"VUSR_"=dword:00010000
"ASPNET"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(524)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(468)
c:\windows\system32\WININET.dll
c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL
c:\progra~1\WINDOW~3\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\windows\eHome\ehSched.exe
c:\program files\Intel\Intel Matrix Storage Manager\iaantmon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\ZuneBusEnum.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\program files\Microsoft IntelliType Pro\dpupdchk.exe
.
**************************************************************************
.
Completion time: 2010-12-05 18:00:15 - machine was rebooted
ComboFix-quarantined-files.txt 2010-12-05 23:59

Pre-Run: 26,525,294,592 bytes free
Post-Run: 26,465,828,864 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
[spybotsd]
timeout.old=30

- - End Of File - - A18BB7B555438C45753639C4BC7F0B42
  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.



Next

I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Wow, this one took a while. lol Here's the Eset log… ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - delete file error:The process cannot access the file because it is being used by another process. OnlineScanner.ocx - copy file error :The process cannot access the file because it is being used by another process. OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6415 # api_version=3.0.2 # EOSSerial=0a9692d3f4eb8d44be81da4aa489a46b # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-12-07 02:49:29 # local_time=2010-12-06 08:49:29 (-0600, Central Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=crash # scanned=120074 # found=8 # cleaned=8 # scan_time=3416 C:\Documents and Settings\All Users\Documents\Server\hlp.dat Win32/Bamital.DZ trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\WINDOWS\explorer.exe.vir Win32/Bamital.EV trojan (deleted - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\WINDOWS\system32\winlogon.exe.vir Win32/Bamital.EV trojan (deleted - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1\A0000027.exe Win32/Bamital.EV trojan (deleted - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1\A0000028.exe Win32/Bamital.EV trojan (deleted - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1\A0000030.exe Win32/Bamital.EV trojan (deleted - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1\A0000031.exe Win32/Bamital.EV trojan (deleted - quarantined) 00000000000000000000000000000000 C C:\WINDOWS\tontrx.dll a variant of Win32/Cimag.EW trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C And the MBAM log Malwarebytes' Anti-Malware 1.50 www.malwarebytes.org Database version: 5257 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 12/6/2010 5:29:46 PM mbam-log-2010-12-06 (17-29-46).txt Scan type: Quick scan Objects scanned: 150510 Time elapsed: 5 minute(s), 18 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
The computer seems to be running better. I have not gotten any error messages today. One thing I found curious when I tried to run the Eset scanner. It told me I needed to uninstall AVG in order for it to run. So, when I went to disable AVG, it reported that no components were installed. However, the systray icon did not show the usual exclamation mark to advise something is disabled. Not only that, I could not remove AVG through the control panel. I had to download an AVG remover from AVG's web site.

Any how. Here's the OTL log…

OTL logfile created on: 12/7/2010 12:24:45 PM - Run 2
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Jill Hadley\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 648.00 Mb Available Physical Memory | 63.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.32 Gb Total Space | 24.56 Gb Free Space | 17.02% Space Free | Partition Type: NTFS
Drive W: | 111.73 Gb Total Space | 35.37 Gb Free Space | 31.66% Space Free | Partition Type: NTFS
Drive X: | 9.41 Gb Total Space | 2.71 Gb Free Space | 28.84% Space Free | Partition Type: FAT

Computer Name: MOM | User Name: Jill Hadley | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Jill Hadley\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
PRC - C:\WINDOWS\system32\ZuneBusEnum.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Jill Hadley\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (cmdAgent) – C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV - (ZuneNetworkSvc) – c:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (ZuneWlanCfgSvc) – C:\WINDOWS\system32\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (ZuneBusEnum) – C:\WINDOWS\system32\ZuneBusEnum.exe (Microsoft Corporation)
SRV - (ELService) – C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe (Intel Corporation)
SRV - (IAANTMon) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (XDva201) – C:\WINDOWS\System32\XDva201.sys File not found
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys File not found
DRV - (SABProcEnum) – C:\Program Files\Internet Explorer\SABProcEnum.sys File not found
DRV - (PalmUSBD) – C:\WINDOWS\System32\drivers\PalmUSBD.sys File not found
DRV - (EagleNT) – C:\WINDOWS\System32\drivers\EagleNT.sys File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (Ad-Watch Connect Filter) – C:\WINDOWS\System32\drivers\NSDriver.sys File not found
DRV - (Inspect) – C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (cmdGuard) – C:\WINDOWS\system32\drivers\cmdGuard.sys (COMODO)
DRV - (cmdHlp) – C:\WINDOWS\system32\drivers\cmdhlp.sys (COMODO)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (JL2005C) – C:\WINDOWS\system32\drivers\jl2005c.sys (Windows ® 2000 DDK provider)
DRV - (WinUSB) – C:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (SocketLock) – C:\WINDOWS\system32\socketlock.sys ()
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (ELhid) – C:\WINDOWS\system32\drivers\ELhid.sys (Intel Corporation)
DRV - (ELmon) – C:\WINDOWS\system32\drivers\ELmon.sys (Intel Corporation)
DRV - (ELkbd) – C:\WINDOWS\system32\drivers\ELkbd.sys (Intel Corporation)
DRV - (ELmou) – C:\WINDOWS\system32\drivers\ELmou.sys (Intel Corporation)
DRV - (ELacpi) – C:\WINDOWS\system32\drivers\ELacpi.sys (Intel Corporation)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (DRVMCDB) – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (e1express) Intel® – C:\WINDOWS\system32\drivers\e1e5132.sys (Intel Corporation)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (DRVNDDM) – C:\WINDOWS\system32\drivers\DRVNDDM.SYS (Sonic Solutions)
DRV - (iastor) – C:\WINDOWS\system32\drivers\iastor.sys (Intel Corporation)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://news.yahoo.com [binary data]

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://news.yahoo.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.myspace.com/"
FF - prefs.js..network.proxy.no_proxies_on: "local,*.local"


[2009/05/20 10:35:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Jill Hadley\Application Data\Mozilla\Firefox\Profiles\3g8lv8zo.default\extensions
[2010/05/03 10:11:14 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2008/06/18 00:43:04 | 000,086,016 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2009/11/06 18:12:11 | 000,238,776 | —- | M] (Pando Networks) – C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll

O1 HOSTS File: ([2010/12/05 17:50:27 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (no name) - {C86AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - No CLSID value found.
O2 - BHO: (no name) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [OutlookOnDesktop] C:\Outlook on the Desktop\OutlookDesktop.exe (SMR Computer Services)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} Reg Error: Key error. (Reg Error: Key error.)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadblocker.com/activex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} http://www.photodex.com/pxplay.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll File not found
O18 - Protocol\Filter\x-sdch {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 03:43:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/12/06 17:57:41 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2010/12/06 17:51:58 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/12/05 17:39:23 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/12/05 17:35:41 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/12/05 17:35:41 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/12/05 17:35:41 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/12/05 17:35:41 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/12/05 17:18:37 | 000,000,000 | —D | C] – C:\Qoobox
[2010/12/04 18:31:54 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Jill Hadley\Desktop\OTL.exe
[2010/12/04 17:44:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Jill Hadley\Desktop\backups
[2010/12/04 17:39:58 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Jill Hadley\Desktop\HijackThis.exe
[2010/12/04 14:06:21 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Documents\Server
[2010/11/09 22:18:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Jill Hadley\Application Data\Arkadium
[2010/11/09 22:17:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2010/11/09 22:17:19 | 000,000,000 | —D | C] – C:\Program Files\Mahjongg Dimensions Deluxe
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/12/07 12:13:10 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/12/06 20:51:44 | 000,001,493 | —- | M] () – C:\Documents and Settings\Jill Hadley\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Explorer.lnk
[2010/12/05 17:50:27 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/12/05 17:50:21 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/12/05 17:49:32 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/12/05 17:49:30 | 1071,812,608 | -HS- | M] () – C:\hiberfil.sys
[2010/12/05 17:39:27 | 000,000,353 | RHS- | M] () – C:\boot.ini
[2010/12/05 17:15:35 | 003,984,562 | R— | M] () – C:\Documents and Settings\Jill Hadley\Desktop\ComboFix.exe
[2010/12/04 18:31:54 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Jill Hadley\Desktop\OTL.exe
[2010/12/04 17:39:59 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Jill Hadley\Desktop\HijackThis.exe
[2010/12/04 17:15:19 | 000,039,472 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/12/04 12:04:14 | 000,002,501 | —- | M] () – C:\Documents and Settings\Jill Hadley\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Word.lnk
[2010/12/02 21:35:05 | 000,000,072 | —- | M] () – C:\WINDOWS\MSPConv.INI
[2010/11/29 17:42:18 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/11/29 17:42:06 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/11/23 12:29:09 | 000,000,162 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/11/22 10:43:41 | 000,153,600 | —- | M] () – C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/19 13:52:34 | 000,028,160 | —- | M] () – C:\10 Rules for Dating.doc
[2010/11/19 13:34:39 | 000,057,856 | —- | M] () – C:\10 BAND REPORT.doc
[2010/11/13 08:20:36 | 000,020,992 | —- | M] () – C:\CrawlersnCruisers Show Pacard.doc
[2010/11/13 04:20:53 | 000,028,160 | —- | M] () – C:\CrawlersnCruisers Voting Sheets.doc
[2010/11/12 00:01:19 | 000,024,064 | —- | M] () – C:\Documents and Settings\Jill Hadley\My Documents\CnC AACStyle Gift Cards.doc
[2010/11/10 22:37:22 | 006,604,800 | —- | M] () – C:\CrawlersnCruisers Invitation.doc
[2010/11/09 22:17:41 | 000,001,871 | —- | M] () – C:\Documents and Settings\Jill Hadley\Desktop\Mahjongg Dimensions Deluxe.lnk
[2010/11/08 10:32:38 | 000,296,448 | —- | M] () – C:\Documents and Settings\Jill Hadley\Desktop\gmer.exe
[2010/11/08 01:20:24 | 000,089,088 | —- | M] () – C:\WINDOWS\MBR.exe
[2010/11/07 15:37:07 | 000,001,901 | —- | M] () – C:\WINDOWS\panose.bin
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/12/05 17:39:27 | 000,000,237 | —- | C] () – C:\Boot.bak
[2010/12/05 17:39:24 | 000,260,272 | RHS- | C] () – C:\cmldr
[2010/12/05 17:35:41 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/12/05 17:35:41 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/12/05 17:35:41 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/12/05 17:35:41 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/12/05 17:35:41 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/12/05 17:15:21 | 003,984,562 | R— | C] () – C:\Documents and Settings\Jill Hadley\Desktop\ComboFix.exe
[2010/12/02 21:35:05 | 000,000,072 | —- | C] () – C:\WINDOWS\MSPConv.INI
[2010/11/18 20:26:42 | 000,028,160 | —- | C] () – C:\10 Rules for Dating.doc
[2010/11/16 18:42:42 | 000,057,856 | —- | C] () – C:\10 BAND REPORT.doc
[2010/11/13 08:20:36 | 000,020,992 | —- | C] () – C:\CrawlersnCruisers Show Pacard.doc
[2010/11/13 04:20:53 | 000,028,160 | —- | C] () – C:\CrawlersnCruisers Voting Sheets.doc
[2010/11/12 00:01:18 | 000,024,064 | —- | C] () – C:\Documents and Settings\Jill Hadley\My Documents\CnC AACStyle Gift Cards.doc
[2010/11/09 22:17:41 | 000,001,871 | —- | C] () – C:\Documents and Settings\Jill Hadley\Desktop\Mahjongg Dimensions Deluxe.lnk
[2010/11/08 10:32:38 | 000,296,448 | —- | C] () – C:\Documents and Settings\Jill Hadley\Desktop\gmer.exe
[2007/08/27 12:09:53 | 000,000,475 | —- | C] () – C:\WINDOWS\KA.ini
[2007/07/19 15:30:33 | 000,000,217 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2007/03/30 13:31:20 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\dec_jl6.dll
[2007/02/06 12:14:16 | 000,000,968 | —- | C] () – C:\WINDOWS\hegames.ini
[2007/01/25 14:09:01 | 000,000,058 | —- | C] () – C:\WINDOWS\System32\EAL32.INI
[2007/01/25 13:57:50 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\PRTSERV.dll
[2006/12/03 09:46:38 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2006/10/07 12:11:48 | 000,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2006/09/09 18:06:07 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\MSVCRT10.DLL
[2006/09/09 18:05:55 | 000,000,122 | —- | C] () – C:\WINDOWS\KPCMS.INI
[2006/08/03 19:11:28 | 000,003,712 | —- | C] () – C:\WINDOWS\System32\socketlock.sys
[2006/08/03 17:27:25 | 000,000,187 | —- | C] () – C:\Documents and Settings\Jill Hadley\Application Data\G-Force Prefs (WindowsMediaPlayer).txt
[2006/05/18 08:10:28 | 000,003,072 | —- | C] () – C:\Documents and Settings\Jill Hadley\Application Data\dvd.bmk
[2006/04/30 19:22:53 | 000,153,600 | —- | C] () – C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/04/30 18:27:43 | 000,000,162 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/04/16 21:14:07 | 000,001,296 | —- | C] () – C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\FASTWiz.html
[2006/04/16 21:13:37 | 000,029,167 | —- | C] () – C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\FASTWiz.log
[2006/04/16 00:52:03 | 000,000,104 | RHS- | C] () – C:\WINDOWS\System32\6F1BB25984.sys
[2006/04/15 18:19:06 | 000,005,852 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/04/15 18:04:28 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/04/15 17:54:36 | 000,000,161 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2006/04/15 17:53:33 | 000,000,706 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2006/04/15 17:50:45 | 000,000,342 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/04/15 17:15:04 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/04/15 16:50:39 | 000,000,134 | —- | C] () – C:\Documents and Settings\Jill Hadley\Local Settings\Application Data\fusioncache.dat
[2006/04/05 17:02:02 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/04/05 16:56:15 | 000,000,126 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/04/05 16:27:18 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/04/05 16:26:48 | 000,000,387 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/11/10 07:56:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/16 03:37:24 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/08/16 03:33:38 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/08/05 13:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/03/28 08:14:38 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\hpzids01.dll
[2001/07/06 15:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[1999/03/21 19:00:00 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

========== Alternate Data Streams ==========

@Alternate Data Stream - 171 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D2F2F703
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:44DAF2F1

< End of report >
Not heard of ESET having problems with AVG before,make sure you reinstall an antivirus.You appear clean of infections,please do the following.



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)









Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.








Clean out your temp files.
Download Attribune's ATF Cleaner and save to your desktop.
Double-click ATF-Cleaner.exe to run the program.
Under Main "Select Files to Delete" choose: Select All.
Click the Empty Selected button.

If you use Firefox or Opera browser click that browser at the top and choose: Select All
Click the Empty Selected button.
If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program
.







[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 22 and save it to your desktop.
  • Scroll down to where it says JDK 6 Update 22 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6u22 with JavaFX 1 License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u22-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.







Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing
Well, I'm not sure what's going on. But I can not use Microsoft update now. It keeps telling me I need to validate my copy of Windows. But it does not download the Active X validation tool. Also, I tried to use the Secunia scanner and it tells me that Java is not installed. However, I installed the latest version using the instructions you gave me. Other than that the machine is running good. Faster than I've seen it in a while.
Download the diagnostic tool MGADiag and save it to your desktop.

* Double-click on MGADiag.exe.
* Click Run and Run again.
* Click Continue, then Copy.

Paste the report in your next reply.
Here's the MGADiag report. Diagnostic Report (1.9.0027.0): —————————————– Windows Validation Data–> Validation Status: Genuine Validation Code: 0 Cached Validation Code: N/A Windows Product Key: *****-*****-RVF66-GP7VM-8CFT3 Windows Product Key Hash: tJB30tZY737ZFJYewUg2SpzsCb0= Windows Product ID: 76487-OEM-2211906-00825 Windows Product ID Type: 2 Windows License Type: OEM SLP Windows OS version: 5.1.2600.2.00010100.3.0.med ID: {7AD58066-FB97-431A-BEAB-5CFAA94DEECA}(3) Is Admin: Yes TestCab: 0x0 LegitcheckControl ActiveX: Registered, 1.9.40.0 Signed By: Microsoft Product Name: N/A Architecture: N/A Build lab: N/A TTS Error: N/A Validation Diagnostic: FCEE394C-458-80041014_025D1FF3-344-80041014_025D1FF3-229-80041014_025D1FF3-230-1_025D1FF3-238-2 Resolution Status: N/A Vista WgaER Data–> ThreatID(s): N/A Version: N/A Windows XP Notifications Data–> Cached Result: 0 File Exists: Yes Version: 1.9.40.0 WgaTray.exe Signed By: Microsoft WgaLogon.dll Signed By: Microsoft OGA Notifications Data–> Cached Result: N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 OGAExec.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: N/A, hr = 0x80070002 OGA Data–> Office Status: 114 Blocked VLK 2 Microsoft Office XP Professional with FrontPage - 114 Blocked VLK 2 OGA Version: Registered, 2.0.48.0 Signed By: Microsoft Office Diagnostics: FCEE394C-458-80041014_025D1FF3-344-80041014_025D1FF3-229-80041014_025D1FF3-230-1_025D1FF3-238-2 Browser Data–> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32) Default Browser: C:\Program Files\Internet Explorer\IEXPLORE.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data–> Other data–> Office Details: {7AD58066-FB97-431A-BEAB-5CFAA94DEECA}1.9.0027.05.1.2600.2.00010100.3.0.medx32*****-*****-*****-*****-8CFT376487-OEM-2211906-008252S-1-5-21-514355335-4051444915-1532494702Dell System,Dell Computer,Dell System,Dell SystemE21732A70184606D04090409Central Standard Time(GMT-06:00)02Dell XPS DXPO51114 Licensing Data–> N/A Windows Activation Technologies–> N/A HWID Data–> N/A OEM Activation 1.0 Data–> BIOS string matches: yes Marker string from BIOS: 1ABDD:Dell Inc|1ABDD:Microsoft Corporation Marker string from OEMBIOS.DAT: Dell System,Dell Computer,Dell System,Dell System OEM Activation 2.0 Data–> N/A
Well, none of the suggestions on that link fit my problem. My copy of windows is activated. It just needs to be validated. When I try to validate it never offers to download the active x validation tool. I did download and install Windows Genuine Advantage Notifications Tool. It reported that my copy is valid. But when I go to the windows update site it still says I need to validate my copy. I have no idea what's going on.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI