This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

IE redirects and messages about registry problems

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am having serious problems with my pc. There are not too many symptoms to describe here but, IE is very slow to open (if at all) and it redirects me to various pages including a fake walmart ad. Whatever I have also, has interfered with me being able to post to any type of forums - will not save. I was also sent to a site called zamm.com at one point. Further, I am unable to access Windows Update. At times, the machine freezes altogether. I have successfully downloaded DDS, GMER and RSIT, but when I attempt to run DDS or GMER they hang the machine indefinately (i.e. overnight). I was able to run HijackThis and I have included the HJT Log for review.

I hope that this information is helpful and any assistance will be greatly appreciated.

Thanks.

Logfile of random's system information tool 1.08 (written by random/random)
Run by [removed] at 2010-12-26 12:04:43
Microsoft Windows XP Professional Service Pack 2
System drive C: has 25 GB (66%) free of 38 GB
Total RAM: 511 MB (27% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:05:49 PM, on 12/26/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
C:\Program Files\Trend Micro\UniClient\UiFrmWrk\uiWatchDog.exe
C:\Program Files\Trend Micro\AMSP\coreFrameworkHost.exe
C:\ICVERIFY\ICWin404\Jcard\JCardService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINNT\System32\nvsvc32.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINNT\SOUNDMAN.EXE
C:\WINNT\system32\rundll32.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Trend Micro\UniClient\UiFrmWrk\uiSeAgnt.exe
C:\WINNT\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\ICVERIFY\ICWin404\Jre1.6.0\bin\javaw.exe
C:\Documents and Settings\dj\Desktop\RSIT.exe
C:\Program Files\trend micro\DJ.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.111.11:80
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Trend Micro NSC BHO - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\TmIEPlg.dll
O2 - BHO: Trend Micro Toolbar BHO - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O2 - BHO: TmBpIeBHO - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.5.1234\6.5.1234\TmBpIe32.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Trend Micro Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINNT\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINNT\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINNT\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [Cdamuli] rundll32.exe "C:\WINNT\avaxujabowi.dll",Startup
O4 - HKLM\..\Run: [Trend Micro Client Framework] "C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe"
O4 - HKLM\..\Run: [Trend Micro Titanium] "C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe" -set Silent "1" SplashURL ""
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [DriverScanner] "C:\Program Files\Uniblue\DriverScanner\launcher.exe" delay 20000
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3299935F-2C5A-499A-9908-95CFFF6EF8C1} (Quicksilver Class) - http://ca1mikpws003.ops.placeware.com/etc/…quicksilver.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1095708580546
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = extremepittsburgh.local
O17 - HKLM\Software\..\Telephony: DomainName = extremepittsburgh.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = extremepittsburgh.local
O18 - Protocol: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.5.1234\6.5.1234\TmBpIe32.dll
O18 - Protocol: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\TmIEPlg.dll
O18 - Protocol: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll
O18 - Protocol: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINNT\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINNT\System32\browseui.dll
O23 - Service: Trend Micro Solution Platform (Amsp) - Trend Micro Inc. - C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: icvmlt32 - Unknown owner - C:\ICVERIFY\ICWin404\PCVXWinServiceManager.exe
O23 - Service: JCard Service - Unknown owner - C:\ICVERIFY\ICWin404\Jcard\JCardService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: PEVSystemStart - Unknown owner - C:\iexplorer\PEV.cfxxe

–
End of file - 7157 bytes

======Scheduled tasks folder======

C:\WINNT\tasks\GoogleUpdateTaskMachineCore.job
C:\WINNT\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CA1377B-DC1D-4A52-9585-6E06050FAC53}]
TmIEPlugInBHO Class - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\TmIEPlg.dll [2010-12-22 185680]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{43C6D902-A1C5-45c9-91F6-FD9E90337E18}]
TSToolbarBHO - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll [2010-12-22 189776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-12-02 297648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll [2010-10-27 843832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC}]
TmBpIeBHO Class - C:\Program Files\Trend Micro\AMSP\Module\20002\6.5.1234\6.5.1234\TmBpIe32.dll [2010-12-22 234832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-12-02 297648]
{CCAC5586-44D7-4c43-B64A-F042461A97D2} - Trend Micro Toolbar - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll [2010-12-22 189776]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"=C:\WINNT\IME\imjp8_1\IMJPMIG.EXE [2004-08-04 208952]
"PHIME2002ASync"=C:\WINNT\System32\IME\TINTLGNT\TINTSETP.EXE [2003-03-31 455168]
"PHIME2002A"=C:\WINNT\System32\IME\TINTLGNT\TINTSETP.EXE [2003-03-31 455168]
"NvCplDaemon"=C:\WINNT\System32\NvCpl.dll [2003-10-06 5058560]
"nwiz"=nwiz.exe /install []
"SoundMan"=C:\WINNT\SOUNDMAN.EXE [2003-02-27 47104]
"Synchronization Manager"=C:\WINNT\system32\mobsync.exe [2004-08-04 143360]
"Cdamuli"=C:\WINNT\avaxujabowi.dll,Startup []
"Trend Micro Client Framework"=C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe [2010-12-22 112632]
"Trend Micro Titanium"=C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe [2010-12-22 1062224]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"=C:\WINNT\System32\NVMCTRAY.DLL [2003-10-06 49152]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-06-19 68856]
"ctfmon.exe"=C:\WINNT\system32\ctfmon.exe [2004-08-04 15360]
"DriverScanner"=C:\Program Files\Uniblue\DriverScanner\launcher.exe delay 20000 []

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINNT\system32\WgaLogon.dll [2009-03-10 239496]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmdb.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\klmdb.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-12-22 18:34:26 —-A—- C:\WINNT\system32\drivers\tmtdi.sys
2010-12-22 18:34:10 —-A—- C:\WINNT\system32\drivers\tmevtmgr.sys
2010-12-22 18:34:10 —-A—- C:\WINNT\system32\drivers\tmcomm.sys
2010-12-22 18:34:10 —-A—- C:\WINNT\system32\drivers\tmactmon.sys
2010-12-22 18:27:47 —-D—- C:\Documents and Settings\All Users\Application Data\Trend Micro
2010-12-20 19:04:30 —-D—- C:\Documents and Settings\dj\Application Data\Uniblue
2010-12-20 18:56:22 —-D—- C:\Documents and Settings\dj\Application Data\Registry Mechanic
2010-12-20 18:50:13 —-AD—- C:\Documents and Settings\All Users\Application Data\TEMP
2010-12-17 20:18:22 —-D—- C:\Program Files\trend micro
2010-12-17 20:18:21 —-D—- C:\rsit
2010-12-17 19:53:52 —-ASH—- C:\hiberfil.sys
2010-12-09 21:08:06 —-SD—- C:\iexplorer
2010-12-09 20:53:57 —-SHD—- C:\RECYCLER
2010-12-09 20:27:17 —-A—- C:\TDSSKiller.2.4.2.1_09.12.2010_20.27.17_log.txt
2010-12-09 19:00:00 —-A—- C:\TDSSKiller.2.4.2.1_09.12.2010_19.00.00_log.txt
2010-12-09 18:27:17 —-A—- C:\Boot.bak
2010-12-09 18:27:08 —-RASHD—- C:\cmdcons
2010-12-09 18:20:01 —-A—- C:\TDSSKiller.2.4.2.1_09.12.2010_18.20.01_log.txt
2010-12-09 18:08:51 —-A—- C:\TDSSKiller.2.4.2.1_09.12.2010_18.08.51_log.txt
2010-12-09 17:56:36 —-AH—- C:\WINNT\system32\findstub.dll
2010-12-09 17:56:34 —-A—- C:\TDSSKiller.2.4.2.1_09.12.2010_17.56.34_log.txt
2010-12-09 17:45:22 —-A—- C:\WINNT\zip.exe
2010-12-09 17:45:22 —-A—- C:\WINNT\SWXCACLS.exe
2010-12-09 17:45:22 —-A—- C:\WINNT\SWSC.exe
2010-12-09 17:45:22 —-A—- C:\WINNT\SWREG.exe
2010-12-09 17:45:22 —-A—- C:\WINNT\sed.exe
2010-12-09 17:45:22 —-A—- C:\WINNT\PEV.exe
2010-12-09 17:45:22 —-A—- C:\WINNT\NIRCMD.exe
2010-12-09 17:45:22 —-A—- C:\WINNT\MBR.exe
2010-12-09 17:45:22 —-A—- C:\WINNT\grep.exe
2010-12-09 17:44:54 —-D—- C:\WINNT\ERDNT
2010-12-09 17:43:29 —-D—- C:\Qoobox
2010-12-09 17:39:23 —-D—- C:\WINNT\pss
2010-12-09 17:36:52 —-A—- C:\WINNT\system32\drivers\USBSTOR.SYS
2010-12-08 20:48:33 —-HD—- C:\WINNT\PIF

======List of files/folders modified in the last 1 months======

2010-12-26 12:04:43 —-D—- C:\WINNT\Prefetch
2010-12-26 12:03:56 —-D—- C:\WINNT\Temp
2010-12-26 12:03:29 —-D—- C:\WINNT\system32\CatRoot2
2010-12-26 12:02:08 —-D—- C:\WINNT\security
2010-12-22 23:01:07 —-A—- C:\WINNT\SchedLgU.Txt
2010-12-22 22:54:52 —-D—- C:\WINNT
2010-12-22 22:52:40 —-D—- C:\Program Files\Common Files
2010-12-22 22:48:44 —-D—- C:\WINNT\system32
2010-12-22 22:48:11 —-D—- C:\Program Files\CrossLoop
2010-12-22 20:15:23 —-D—- C:\WINNT\system32\drivers\etc
2010-12-22 19:13:39 —-SD—- C:\WINNT\Tasks
2010-12-22 19:13:32 —-RD—- C:\Program Files
2010-12-22 18:41:16 —-SHD—- C:\WINNT\Installer
2010-12-22 18:34:50 —-HD—- C:\WINNT\inf
2010-12-22 18:34:50 —-D—- C:\WINNT\system32\drivers
2010-12-22 18:33:56 —-A—- C:\WINNT\system32\PerfStringBackup.INI
2010-12-22 18:28:45 —-D—- C:\WINNT\WinSxS
2010-12-22 18:28:45 —-D—- C:\Program Files\Common Files\Microsoft Shared
2010-12-22 18:17:59 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2010-12-22 17:47:18 —-SHD—- C:\WINNT\CSC
2010-12-20 18:37:45 —-D—- C:\Program Files\Common Files\Symantec Shared
2010-12-20 18:37:09 —-D—- C:\Program Files\Java
2010-12-20 18:32:09 —-D—- C:\Program Files\Microsoft AntiSpyware
2010-12-17 19:44:43 —-A—- C:\WINNT\ntbtlog.txt
2010-12-09 20:48:56 —-HDC—- C:\WINNT\$NtUninstallKB933360$
2010-12-09 19:51:33 —-N—- C:\WINNT\system.ini
2010-12-09 19:38:54 —-RSHDC—- C:\WINNT\system32\dllcache
2010-12-09 19:38:46 —-D—- C:\Documents and Settings\dj\Application Data\Adobe
2010-12-09 19:33:57 —-D—- C:\WINNT\AppPatch
2010-12-09 18:27:18 —-RASH—- C:\boot.ini
2010-12-08 19:33:21 —-D—- C:\WINNT\addins
2010-12-07 08:44:31 —-D—- C:\Program Files\verify-it
2010-12-06 15:15:29 —-A—- C:\WINNT\QUICKEN.INI
2010-12-02 13:05:49 —-A—- C:\WINNT\system32\MRT.INI
2010-12-02 13:03:42 —-A—- C:\WINNT\system32\MRT.exe
2010-11-29 19:50:09 —-HDC—- C:\WINNT\$NtUninstallKB890046$

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 agp440;Intel AGP Bus Filter; C:\WINNT\System32\DRIVERS\agp440.sys [2004-08-04 42368]
R1 intelppm;Intel Processor Driver; C:\WINNT\System32\DRIVERS\intelppm.sys [2004-08-04 36096]
R1 tmtdi;Trend Micro TDI Driver; C:\WINNT\system32\DRIVERS\tmtdi.sys [2010-12-22 92112]
R2 tmactmon;tmactmon; C:\WINNT\system32\DRIVERS\tmactmon.sys [2010-12-22 80464]
R2 tmcomm;tmcomm; C:\WINNT\system32\DRIVERS\tmcomm.sys [2010-12-22 189520]
R2 tmevtmgr;tmevtmgr; C:\WINNT\system32\DRIVERS\tmevtmgr.sys [2010-12-22 64080]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINNT\system32\drivers\ALCXWDM.SYS [2003-02-27 701676]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINNT\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 nv;nv; C:\WINNT\System32\DRIVERS\nv4_mini.sys [2003-10-06 1550043]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINNT\System32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINNT\System32\DRIVERS\usbuhci.sys [2004-08-04 20480]
S3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\WINNT\System32\DRIVERS\bcm4sbxp.sys [2002-12-17 42368]
S3 catchme;catchme; \??\C:\DOCUME~1\dj\LOCALS~1\Temp\catchme.sys []
S3 OSIUSB2;USB Cable Service B; C:\WINNT\system32\DRIVERS\slabser.sys []
S3 USBSTOR;USB Mass Storage Driver; C:\WINNT\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Amsp;Trend Micro Solution Platform; C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe [2010-10-01 196320]
R2 JCard Service;JCard Service; C:\ICVERIFY\ICWin404\Jcard\JCardService.exe [2010-03-26 148776]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 MSSQL$ICV;SQL Server (ICV); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2007-02-10 29178224]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINNT\System32\nvsvc32.exe [2003-10-06 81920]
R2 SQLBrowser;SQL Server Browser; C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2007-02-10 242544]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2007-02-10 89968]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-29 135664]
S2 PEVSystemStart;PEVSystemStart; C:\iexplorer\PEV.cfxxe [2010-04-26 256512]
S3 aspnet_state;ASP.NET State Service; C:\WINNT\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINNT\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-21 182768]
S3 icvmlt32;icvmlt32; C:\ICVERIFY\ICWin404\PCVXWinServiceManager.exe [2010-03-26 54568]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2005-10-14 45272]

—————–EOF—————–
UPDATE - ADDED OTL FILE BELOW

OTL logfile created on: 12/26/2010 3:26:55 PM - Run 1
OTL by OldTimer - Version 3.2.18.0 Folder = C:\Documents and Settings\dj\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 226.00 Mb Available Physical Memory | 44.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 37.27 Gb Total Space | 24.87 Gb Free Space | 66.72% Space Free | Partition Type: NTFS
Drive G: | 24.15 Gb Total Space | 19.03 Gb Free Space | 78.82% Space Free | Partition Type: NTFS
Drive O: | 24.15 Gb Total Space | 19.03 Gb Free Space | 78.82% Space Free | Partition Type: NTFS
Drive P: | 24.15 Gb Total Space | 19.03 Gb Free Space | 78.82% Space Free | Partition Type: NTFS
Drive Q: | 24.15 Gb Total Space | 19.03 Gb Free Space | 78.82% Space Free | Partition Type: NTFS

Computer Name: BACKOFFICE3 | User Name: DJ | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\dj\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\trend micro\UniClient\UiFrmwrk\uiSeAgnt.exe (Trend Micro Inc.)
PRC - C:\Program Files\trend micro\UniClient\UiFrmwrk\uiWatchDog.exe (Trend Micro Inc.)
PRC - C:\Program Files\trend micro\AMSP\coreFrameworkHost.exe (Trend Micro Inc.)
PRC - C:\Program Files\trend micro\AMSP\coreServiceShell.exe (Trend Micro Inc.)
PRC - C:\ICVERIFY\ICWin404\Jcard\JCardService.exe ()
PRC - C:\ICVERIFY\ICWin404\jre1.6.0\bin\javaw.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\WINNT\explorer.exe (Microsoft Corporation)
PRC - C:\WINNT\SOUNDMAN.EXE (Realtek Semiconductor Corp.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\dj\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINNT\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (wuauserv) – C:\WINDOWS\system32\wuauserv.dll File not found
SRV - (PEVSystemStart) – C:\iexplorer\PEV.cfx File not found
SRV - (HidServ) – C:\WINNT\System32\hidserv.dll File not found
SRV - (Amsp) – C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe (Trend Micro Inc.)
SRV - (JCard Service) – C:\ICVERIFY\ICWin404\Jcard\JCardService.exe ()
SRV - (icvmlt32) – C:\ICVERIFY\ICWin404\PCVXWinServiceManager.exe ()


========== Driver Services (SafeList) ==========

DRV - (OSIUSB2) – C:\WINNT\System32\DRIVERS\slabser.sys File not found
DRV - (catchme) – C:\DOCUME~1\dj\LOCALS~1\Temp\catchme.sys File not found
DRV - (tmcomm) – C:\WINNT\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (tmtdi) – C:\WINNT\system32\drivers\tmtdi.sys (Trend Micro Inc.)
DRV - (tmactmon) – C:\WINNT\system32\drivers\tmactmon.sys (Trend Micro Inc.)
DRV - (tmevtmgr) – C:\WINNT\system32\drivers\tmevtmgr.sys (Trend Micro Inc.)
DRV - (gameenum) – C:\WINNT\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINNT\system32\drivers\rtl8139.sys (Realtek Semiconductor Corporation)
DRV - (nv) – C:\WINNT\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINNT\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (bcm4sbxp) – C:\WINNT\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (ms_mpu401) – C:\WINNT\system32\drivers\msmpu401.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 192.168.111.11:80

FF - HKLM\software\mozilla\Firefox\Extensions\\{22181a4d-af90-4ca3-a569-faed9118d6bc}: C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension [2010/12/22 18:31:37 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{22C7F6C6-8D67-4534-92B5-529A0EC09405}: C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\firefoxextension\ [2010/12/22 18:33:47 | 000,000,000 | —D | M]


O1 HOSTS File: ([2010/12/09 19:51:03 | 000,000,027 | —- | M]) - C:\WINNT\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\trend micro\AMSP\module\20004\1.5.1381\6.5.1234\TmIEPlg.dll (Trend Micro Inc.)
O2 - BHO: (TSToolbarBHO) - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\trend micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (TmBpIeBHO Class) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\trend micro\AMSP\module\20002\6.5.1234\6.5.1234\TmBpIe32.dll (Trend Micro Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Trend Micro Toolbar) - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\trend micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [Cdamuli] C:\WINNT\avaxujabowi.DLL File not found
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINNT\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINNT\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINNT\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [PHIME2002A] C:\WINNT\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINNT\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SoundMan] C:\WINNT\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Trend Micro Client Framework] C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [Trend Micro Titanium] C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe (Trend Micro Inc.)
O4 - HKCU..\Run: [DriverScanner] C:\Program Files\Uniblue\DriverScanner\launcher.exe File not found
O4 - HKCU..\Run: [NvMediaCenter] C:\WINNT\System32\NVMCTRAY.DLL (NVIDIA Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe (Intuit Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {3299935F-2C5A-499A-9908-95CFFF6EF8C1} http://ca1mikpws003.ops.placeware.com/etc/…quicksilver.cab (Quicksilver Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://v5.windowsupdate.microsoft.com/v5co…b?1095708580546 (WUWebControl Class)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…7875.3813541667 (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.10
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = extremepittsburgh.local
O18 - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\trend micro\AMSP\module\20002\6.5.1234\6.5.1234\TmBpIe32.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\trend micro\AMSP\module\20004\1.5.1381\6.5.1234\TmIEPlg.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtb {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\trend micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtbim {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\trend micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll (Trend Micro Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINNT\explorer.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/09/11 13:28:50 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINNT\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: wuauserv - C:\WINDOWS\system32\wuauserv.dll File not found
NetSvcs: Ip6FwHlp - File not found

Drivers32: msacm.iac2 - C:\WINNT\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINNT\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINNT\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINNT\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINNT\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINNT\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINNT\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINNT\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINNT\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17746534284132352)

========== Files/Folders - Created Within 30 Days ==========

[2010/12/26 15:24:06 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Documents and Settings\dj\Desktop\OTL.exe
[2010/12/22 20:19:42 | 001,912,872 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\dj\Desktop\HousecallLauncher.exe
[2010/12/22 18:36:46 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Trend Micro
[2010/12/22 18:34:26 | 000,092,112 | —- | C] (Trend Micro Inc.) – C:\WINNT\System32\drivers\tmtdi.sys
[2010/12/22 18:34:10 | 000,189,520 | —- | C] (Trend Micro Inc.) – C:\WINNT\System32\drivers\tmcomm.sys
[2010/12/22 18:34:10 | 000,080,464 | —- | C] (Trend Micro Inc.) – C:\WINNT\System32\drivers\tmactmon.sys
[2010/12/22 18:34:10 | 000,064,080 | —- | C] (Trend Micro Inc.) – C:\WINNT\System32\drivers\tmevtmgr.sys
[2010/12/22 18:32:13 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Trend Micro
[2010/12/22 18:27:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Trend Micro
[2010/12/22 17:54:27 | 055,768,336 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\All Users\Desktop\Trend_Micro.exe
[2010/12/22 17:54:20 | 000,000,000 | —D | C] – C:\Documents and Settings\dj\Desktop\TrendMicro_Downloader(TIMAX)
[2010/12/22 17:53:52 | 002,472,224 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\dj\Desktop\TrendMicro_Downloader(TIMAX).exe
[2010/12/20 19:04:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Uniblue
[2010/12/20 19:04:30 | 000,000,000 | —D | C] – C:\Documents and Settings\dj\Application Data\Uniblue
[2010/12/20 18:56:22 | 000,000,000 | —D | C] – C:\Documents and Settings\dj\Application Data\Registry Mechanic
[2010/12/20 18:50:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/12/20 18:47:28 | 015,992,432 | —- | C] (PC Tools ) – C:\Documents and Settings\dj\Desktop\rminstall.exe
[2010/12/17 20:33:25 | 000,000,000 | —D | C] – C:\Documents and Settings\dj\Desktop\gmer
[2010/12/17 20:18:22 | 000,000,000 | —D | C] – C:\Program Files\trend micro
[2010/12/17 20:18:21 | 000,000,000 | —D | C] – C:\rsit
[2010/12/09 21:08:06 | 000,000,000 | –SD | C] – C:\iexplorer
[2010/12/09 20:53:57 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/12/09 19:11:37 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/12/09 18:27:08 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/12/09 17:45:22 | 000,212,480 | —- | C] (SteelWerX) – C:\WINNT\SWXCACLS.exe
[2010/12/09 17:45:22 | 000,161,792 | —- | C] (SteelWerX) – C:\WINNT\SWREG.exe
[2010/12/09 17:45:22 | 000,136,704 | —- | C] (SteelWerX) – C:\WINNT\SWSC.exe
[2010/12/09 17:45:22 | 000,031,232 | —- | C] (NirSoft) – C:\WINNT\NIRCMD.exe
[2010/12/09 17:44:54 | 000,000,000 | —D | C] – C:\WINNT\ERDNT
[2010/12/09 17:43:29 | 000,000,000 | —D | C] – C:\Qoobox
[2010/12/09 17:39:23 | 000,000,000 | —D | C] – C:\WINNT\pss
[2010/12/08 20:48:33 | 000,000,000 | -H-D | C] – C:\WINNT\PIF
[2010/12/06 20:24:58 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/12/06 17:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/12/06 17:03:15 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[4 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> ]
[1 C:\WINNT\System32\*.tmp files -> C:\WINNT\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/12/26 15:24:08 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\dj\Desktop\OTL.exe
[2010/12/26 15:17:13 | 000,000,886 | —- | M] () – C:\WINNT\tasks\GoogleUpdateTaskMachineUA.job
[2010/12/26 14:26:49 | 000,060,416 | —- | M] () – C:\Documents and Settings\dj\Desktop\I am having serious problems with my pc.doc
[2010/12/26 14:16:51 | 000,012,598 | —- | M] () – C:\WINNT\System32\wpa.dbl
[2010/12/26 14:16:13 | 000,000,882 | —- | M] () – C:\WINNT\tasks\GoogleUpdateTaskMachineCore.job
[2010/12/26 14:15:59 | 000,002,048 | –S- | M] () – C:\WINNT\bootstat.dat
[2010/12/26 14:15:58 | 536,399,872 | -HS- | M] () – C:\hiberfil.sys
[2010/12/26 14:05:47 | 000,000,162 | -H– | M] () – C:\Documents and Settings\dj\My Documents\~$am having serious problems with my pc.doc
[2010/12/26 14:05:46 | 000,057,856 | —- | M] () – C:\Documents and Settings\dj\My Documents\I am having serious problems with my pc.doc
[2010/12/22 20:31:16 | 000,000,036 | —- | M] () – C:\Documents and Settings\dj\Local Settings\Application Data\housecall.guid.cache
[2010/12/22 20:19:42 | 001,912,872 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\dj\Desktop\HousecallLauncher.exe
[2010/12/22 18:41:03 | 000,000,932 | —- | M] () – C:\Documents and Settings\dj\Desktop\Trend Micro Titanium Maximum Security.lnk
[2010/12/22 18:33:57 | 000,462,088 | —- | M] () – C:\WINNT\System32\perfh009.dat
[2010/12/22 18:33:57 | 000,084,162 | —- | M] () – C:\WINNT\System32\perfc009.dat
[2010/12/22 18:26:06 | 000,189,520 | —- | M] (Trend Micro Inc.) – C:\WINNT\System32\drivers\tmcomm.sys
[2010/12/22 18:26:06 | 000,092,112 | —- | M] (Trend Micro Inc.) – C:\WINNT\System32\drivers\tmtdi.sys
[2010/12/22 18:26:06 | 000,080,464 | —- | M] (Trend Micro Inc.) – C:\WINNT\System32\drivers\tmactmon.sys
[2010/12/22 18:26:06 | 000,064,080 | —- | M] (Trend Micro Inc.) – C:\WINNT\System32\drivers\tmevtmgr.sys
[2010/12/22 18:14:17 | 055,768,336 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\All Users\Desktop\Trend_Micro.exe
[2010/12/22 17:53:52 | 002,472,224 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\dj\Desktop\TrendMicro_Downloader(TIMAX).exe
[2010/12/20 18:47:28 | 015,992,432 | —- | M] (PC Tools ) – C:\Documents and Settings\dj\Desktop\rminstall.exe
[2010/12/17 20:33:12 | 000,288,107 | —- | M] () – C:\Documents and Settings\dj\Desktop\gmer.zip
[2010/12/17 20:17:12 | 000,339,991 | —- | M] () – C:\Documents and Settings\dj\Desktop\RSIT.exe
[2010/12/17 19:20:53 | 000,624,128 | —- | M] () – C:\Documents and Settings\dj\Desktop\dds.scr
[2010/12/17 19:17:20 | 000,000,000 | —- | M] () – C:\Documents and Settings\dj\defogger_reenable
[2010/12/17 19:16:40 | 000,050,477 | —- | M] () – C:\Documents and Settings\dj\Desktop\Defogger.exe
[2010/12/09 19:51:03 | 000,000,027 | —- | M] () – C:\WINNT\System32\drivers\etc\hosts
[2010/12/09 19:20:12 | 003,987,287 | R— | M] () – C:\Documents and Settings\dj\Desktop\iexplorer.exe
[2010/12/09 18:27:18 | 000,000,323 | RHS- | M] () – C:\boot.ini
[2010/12/09 17:56:36 | 000,048,640 | -H– | M] () – C:\WINNT\System32\findstub.dll
[2010/12/06 21:52:32 | 000,006,144 | -HS- | M] () – C:\WINNT\System32\access.ctl
[2010/12/06 15:15:29 | 000,001,364 | —- | M] () – C:\WINNT\QUICKEN.INI
[2010/12/06 13:46:13 | 000,034,304 | —- | M] () – C:\Documents and Settings\dj\My Documents\instructor addresses.doc
[2010/12/02 13:05:49 | 000,000,182 | —- | M] () – C:\WINNT\System32\MRT.INI
[2010/11/30 12:22:52 | 000,031,232 | —- | M] () – C:\Documents and Settings\dj\My Documents\new nursery schedule.doc
[2010/11/29 18:40:19 | 006,153,376 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\dj\Desktop\mbam-setup.exe
[2010/11/29 18:36:31 | 000,364,032 | —- | M] () – C:\Documents and Settings\dj\Desktop\rkill.com
[2010/11/29 18:35:17 | 000,000,228 | —- | M] () – C:\Documents and Settings\dj\Desktop\shell.reg
[4 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> ]
[1 C:\WINNT\System32\*.tmp files -> C:\WINNT\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/12/26 14:26:48 | 000,060,416 | —- | C] () – C:\Documents and Settings\dj\Desktop\I am having serious problems with my pc.doc
[2010/12/26 14:05:47 | 000,000,162 | -H– | C] () – C:\Documents and Settings\dj\My Documents\~$am having serious problems with my pc.doc
[2010/12/26 14:05:45 | 000,057,856 | —- | C] () – C:\Documents and Settings\dj\My Documents\I am having serious problems with my pc.doc
[2010/12/22 20:20:09 | 000,000,036 | —- | C] () – C:\Documents and Settings\dj\Local Settings\Application Data\housecall.guid.cache
[2010/12/22 18:39:59 | 000,000,932 | —- | C] () – C:\Documents and Settings\dj\Desktop\Trend Micro Titanium Maximum Security.lnk
[2010/12/17 20:33:07 | 000,288,107 | —- | C] () – C:\Documents and Settings\dj\Desktop\gmer.zip
[2010/12/17 20:17:07 | 000,339,991 | —- | C] () – C:\Documents and Settings\dj\Desktop\RSIT.exe
[2010/12/17 19:53:52 | 536,399,872 | -HS- | C] () – C:\hiberfil.sys
[2010/12/17 19:20:53 | 000,624,128 | —- | C] () – C:\Documents and Settings\dj\Desktop\dds.scr
[2010/12/17 19:17:20 | 000,000,000 | —- | C] () – C:\Documents and Settings\dj\defogger_reenable
[2010/12/17 19:16:32 | 000,050,477 | —- | C] () – C:\Documents and Settings\dj\Desktop\Defogger.exe
[2010/12/09 19:19:06 | 003,987,287 | R— | C] () – C:\Documents and Settings\dj\Desktop\iexplorer.exe
[2010/12/09 18:27:17 | 000,000,207 | —- | C] () – C:\Boot.bak
[2010/12/09 18:27:11 | 000,260,272 | RHS- | C] () – C:\cmldr
[2010/12/09 17:56:36 | 000,048,640 | -H– | C] () – C:\WINNT\System32\findstub.dll
[2010/12/09 17:45:22 | 000,256,512 | —- | C] () – C:\WINNT\PEV.exe
[2010/12/09 17:45:22 | 000,098,816 | —- | C] () – C:\WINNT\sed.exe
[2010/12/09 17:45:22 | 000,089,088 | —- | C] () – C:\WINNT\MBR.exe
[2010/12/09 17:45:22 | 000,080,412 | —- | C] () – C:\WINNT\grep.exe
[2010/12/09 17:45:22 | 000,068,096 | —- | C] () – C:\WINNT\zip.exe
[2010/12/06 21:52:32 | 000,006,144 | -HS- | C] () – C:\WINNT\System32\access.ctl
[2010/12/06 13:46:13 | 000,034,304 | —- | C] () – C:\Documents and Settings\dj\My Documents\instructor addresses.doc
[2010/11/30 12:22:52 | 000,031,232 | —- | C] () – C:\Documents and Settings\dj\My Documents\new nursery schedule.doc
[2010/11/29 18:35:15 | 000,000,228 | —- | C] () – C:\Documents and Settings\dj\Desktop\shell.reg
[2010/10/25 06:15:01 | 000,000,182 | —- | C] () – C:\WINNT\System32\MRT.INI
[2010/09/09 09:25:27 | 000,000,000 | —- | C] () – C:\WINNT\icverify.INI
[2007/09/04 14:36:57 | 000,000,754 | —- | C] () – C:\WINNT\WORDPAD.INI
[2006/06/15 14:42:25 | 000,000,058 | —- | C] () – C:\WINNT\sview.ini
[2006/06/15 14:42:01 | 000,002,734 | —- | C] () – C:\WINNT\pviewm.ini
[2005/02/05 13:17:39 | 000,000,607 | —- | C] () – C:\WINNT\ICVPAD.INI
[2004/10/05 12:23:18 | 000,000,151 | —- | C] () – C:\WINNT\icsetup.INI
[2004/08/12 18:42:09 | 000,000,064 | —- | C] () – C:\WINNT\qwimp.ini
[2004/08/12 18:42:06 | 000,000,554 | —- | C] () – C:\WINNT\intuprof.ini
[2004/08/11 17:17:10 | 000,001,364 | —- | C] () – C:\WINNT\QUICKEN.INI
[2004/08/06 09:35:09 | 000,000,000 | —- | C] () – C:\WINNT\VPC32.INI
[2004/07/30 02:00:50 | 000,000,000 | —- | C] () – C:\Documents and Settings\dj\Application Data\dm.ini
[2004/06/14 13:26:52 | 000,000,370 | —- | C] () – C:\WINNT\ODBC.INI
[2003/10/06 14:16:00 | 000,027,136 | —- | C] () – C:\WINNT\System32\nvcod.dll
[2003/09/11 13:37:55 | 000,000,556 | —- | C] () – C:\WINNT\System32\oeminfo.ini
[2003/09/11 13:37:32 | 000,000,061 | —- | C] () – C:\WINNT\smscfg.ini
[2003/09/11 13:06:31 | 000,363,520 | —- | C] () – C:\WINNT\System32\psisdecd.dll
[2003/09/11 11:04:19 | 000,000,164 | —- | C] () – C:\WINNT\avrack.ini
[2003/09/11 06:20:18 | 000,004,236 | —- | C] () – C:\WINNT\ODBCINST.INI
[2003/01/07 14:05:08 | 000,002,695 | —- | C] () – C:\WINNT\System32\OUTLPERF.INI
[2000/03/08 10:08:20 | 000,219,924 | —- | C] () – C:\WINNT\System32\VSentry.dll

========== LOP Check ==========

[2007/11/01 13:31:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2009/07/21 12:11:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Medtronic Emergency Response Systems
[2010/12/22 19:14:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/07/21 12:16:06 | 000,000,000 | —D | M] – C:\Documents and Settings\dj\Application Data\Medtronic Emergency Response Systems
[2010/12/20 18:56:22 | 000,000,000 | —D | M] – C:\Documents and Settings\dj\Application Data\Registry Mechanic
[2010/12/20 19:04:30 | 000,000,000 | —D | M] – C:\Documents and Settings\dj\Application Data\Uniblue

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2003/09/11 13:28:50 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2004/09/21 11:24:39 | 000,000,207 | —- | M] () – C:\Boot.bak
[2010/12/09 18:27:18 | 000,000,323 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2003/09/11 13:28:50 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/12/26 14:15:58 | 536,399,872 | -HS- | M] () – C:\hiberfil.sys
[2003/09/11 13:28:50 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2003/09/11 13:28:50 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/09/21 11:16:43 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/09/21 11:16:43 | 000,250,032 | RHS- | M] () – C:\ntldr
[2010/12/26 14:15:50 | 805,306,368 | -HS- | M] () – C:\pagefile.sys
[2004/10/05 14:04:00 | 000,001,116 | —- | M] () – C:\paychexhelp.pyx
[2005/04/26 07:25:48 | 001,671,168 | —- | M] () – C:\paychexsview.exe
[2006/06/15 14:41:56 | 000,001,318 | —- | M] () – C:\paychexsview.ini
[2010/12/26 14:21:52 | 000,000,386 | —- | M] () – C:\rkill.log
[2010/12/09 17:57:47 | 000,014,314 | —- | M] () – C:\TDSSKiller.2.4.2.1_09.12.2010_17.56.34_log.txt
[2010/12/09 18:10:29 | 000,030,878 | —- | M] () – C:\TDSSKiller.2.4.2.1_09.12.2010_18.08.51_log.txt
[2010/12/09 18:22:25 | 000,029,294 | —- | M] () – C:\TDSSKiller.2.4.2.1_09.12.2010_18.20.01_log.txt
[2010/12/09 19:01:28 | 000,029,272 | —- | M] () – C:\TDSSKiller.2.4.2.1_09.12.2010_19.00.00_log.txt
[2010/12/09 20:28:32 | 000,029,496 | —- | M] () – C:\TDSSKiller.2.4.2.1_09.12.2010_20.27.17_log.txt

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2003/09/11 13:28:23 | 000,000,067 | -HS- | M] () – C:\WINNT\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2005/06/20 13:24:58 | 000,066,048 | —- | M] (Hewlett-Packard Corporation) – C:\WINNT\system32\spool\prtprocs\w32x86\hpzpp3xy.DLL
[2003/06/18 16:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINNT\system32\spool\prtprocs\w32x86\mdippr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2003/09/11 06:17:01 | 000,094,208 | —- | M] () – C:\WINNT\system32\config\default.sav
[2003/09/11 06:17:01 | 000,626,688 | —- | M] () – C:\WINNT\system32\config\software.sav
[2003/09/11 06:17:01 | 000,417,792 | —- | M] () – C:\WINNT\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2004/09/21 11:24:16 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2004/09/21 17:14:56 | 000,000,175 | -HS- | M] () – C:\Documents and Settings\dj\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/07/30 02:00:55 | 000,000,079 | —- | M] () – C:\Documents and Settings\dj\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/12/17 19:16:40 | 000,050,477 | —- | M] () – C:\Documents and Settings\dj\Desktop\Defogger.exe
[2010/12/22 20:19:42 | 001,912,872 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\dj\Desktop\HousecallLauncher.exe
[2010/12/09 19:20:12 | 003,987,287 | R— | M] () – C:\Documents and Settings\dj\Desktop\iexplorer.exe
[2010/11/29 18:40:19 | 006,153,376 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\dj\Desktop\mbam-setup.exe
[2010/12/26 15:24:08 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\dj\Desktop\OTL.exe
[2010/12/20 18:47:28 | 015,992,432 | —- | M] (PC Tools ) – C:\Documents and Settings\dj\Desktop\rminstall.exe
[2010/12/17 20:17:12 | 000,339,991 | —- | M] () – C:\Documents and Settings\dj\Desktop\RSIT.exe
[2010/12/22 17:53:52 | 002,472,224 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\dj\Desktop\TrendMicro_Downloader(TIMAX).exe
[2010/11/06 09:51:33 | 000,057,344 | —- | M] (First Data) – C:\Documents and Settings\dj\Desktop\UnlockAccount.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-12-02 18:05:49

========== Alternate Data Streams ==========

@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1

< End of report >
UPDATE - ADDED OTL EXTRAS FILE BELOW

OTL Extras logfile created on: 12/26/2010 3:26:55 PM - Run 1
OTL by OldTimer - Version 3.2.18.0 Folder = C:\Documents and Settings\dj\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 226.00 Mb Available Physical Memory | 44.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 37.27 Gb Total Space | 24.87 Gb Free Space | 66.72% Space Free | Partition Type: NTFS
Drive G: | 24.15 Gb Total Space | 19.03 Gb Free Space | 78.82% Space Free | Partition Type: NTFS
Drive O: | 24.15 Gb Total Space | 19.03 Gb Free Space | 78.82% Space Free | Partition Type: NTFS
Drive P: | 24.15 Gb Total Space | 19.03 Gb Free Space | 78.82% Space Free | Partition Type: NTFS
Drive Q: | 24.15 Gb Total Space | 19.03 Gb Free Space | 78.82% Space Free | Partition Type: NTFS

Computer Name: BACKOFFICE3 | User Name: DJ | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0CB3C535-1171-4A20-B549-E2CB5DEB9723}" = MySQL Connector/ODBC 3.51
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (ICV)
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{43DCF766-6838-4F9A-8C91-D92DA586DFA7}" = Microsoft Windows Journal Viewer
"{52504CE6-E909-4113-B232-4AFEC6543A61}" = B44Inst
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{54DE0B75-6CD9-44C4-B10A-1F25DA9899D8}" = Quicken 2004
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7A016113-9DA9-42D7-97C4-62FDF92AB407}" = ICVERIFY for Windows 4.0.4
"{7C05EEDD-E565-4E2B-ADE4-0C784C17311C}" = Crystal Reports for .NET Framework 2.0 (x86)
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8398B542-3CC4-44D9-83DF-696CCE70124B}" = Windows Support Tools
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{901C0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Access 2002 Runtime
"{91CA0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Small Business Edition 2003
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA53316F-C568-4069-9EFC-CA3D39E418A6}" = ICVERIFY User Manager
"{ABBD4BA8-6703-40D2-AB1E-5BB1F7DB49A4}" = Trend Micro Titanium Maximum Security
"{ABBD4BA9-6703-40D2-AB1E-5BB1F7DB49A4}" = Trend Micro™ Titanium™ Maximum Security
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D1AE488B-1616-11D6-B144-0050DA81E919}" = ICVERIFY for Windows
"{E9F44C98-B8B6-480F-AF7B-E42A0A46F4E3}" = Microsoft SQL Server VSS Writer
"{F9B3DD02-B0B3-42E9-8650-030DFF0D133D}" = Microsoft SQL Server Native Client
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AdobeESD" = Adobe Download Manager 1.2 (Remove Only)
"CrossLoop_is1" = CrossLoop 2.01
"Excel MySQL Import, Export & Convert Software_is1" = Excel MySQL Import, Export & Convert Software 7.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{52504CE6-E909-4113-B232-4AFEC6543A61}" = Broadcom 440x Driver Installer
"InstallShield_{54DE0B75-6CD9-44C4-B10A-1F25DA9899D8}" = Quicken 2004
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft Office Live Meeting" = Microsoft Office Live Meeting
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
"NVIDIA Display Driver" = NVIDIA Display Driver
"ODEUNST #1" = Verify-IT ™ Version 5.1
"Windows XP Service Pack" = Windows XP Service Pack 2

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/22/2010 8:20:43 PM | Computer Name = BACKOFFICE3 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.17055, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/22/2010 8:23:41 PM | Computer Name = BACKOFFICE3 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.17055, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/22/2010 8:24:30 PM | Computer Name = BACKOFFICE3 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.17055, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/22/2010 8:25:56 PM | Computer Name = BACKOFFICE3 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.17055, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/22/2010 8:26:08 PM | Computer Name = BACKOFFICE3 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.17055, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/22/2010 8:26:27 PM | Computer Name = BACKOFFICE3 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.17055, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/22/2010 8:26:28 PM | Computer Name = BACKOFFICE3 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.17055, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/22/2010 8:26:28 PM | Computer Name = BACKOFFICE3 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.17055, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/22/2010 9:27:19 PM | Computer Name = BACKOFFICE3 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The connection with the server was terminated abnormally

Error - 12/22/2010 9:27:21 PM | Computer Name = BACKOFFICE3 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

[ System Events ]
Error - 12/26/2010 1:45:12 PM | Computer Name = BACKOFFICE3 | Source = Service Control Manager | ID = 7023
Description = The Automatic Updates service terminated with the following error:
%%126

Error - 12/26/2010 3:16:46 PM | Computer Name = BACKOFFICE3 | Source = Service Control Manager | ID = 7023
Description = The Automatic Updates service terminated with the following error:
%%126


< End of report >
UPDATE - ADDED NEW HJT FILE

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:50:42 PM, on 12/26/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
C:\Program Files\Trend Micro\UniClient\UiFrmWrk\uiWatchDog.exe
C:\Program Files\Trend Micro\AMSP\coreFrameworkHost.exe
C:\ICVERIFY\ICWin404\Jcard\JCardService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINNT\System32\nvsvc32.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINNT\SOUNDMAN.EXE
C:\WINNT\system32\RUNDLL32.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Trend Micro\UniClient\UiFrmWrk\uiSeAgnt.exe
C:\ICVERIFY\ICWin404\Jre1.6.0\bin\javaw.exe
C:\WINNT\explorer.exe
C:\Documents and Settings\dj\Desktop\OTL.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\dj\Desktop\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.111.11:80
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Trend Micro NSC BHO - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\TmIEPlg.dll
O2 - BHO: Trend Micro Toolbar BHO - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O2 - BHO: TmBpIeBHO - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.5.1234\6.5.1234\TmBpIe32.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Trend Micro Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINNT\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINNT\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINNT\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [Cdamuli] rundll32.exe "C:\WINNT\avaxujabowi.dll",Startup
O4 - HKLM\..\Run: [Trend Micro Client Framework] "C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe"
O4 - HKLM\..\Run: [Trend Micro Titanium] "C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe" -set Silent "1" SplashURL ""
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [DriverScanner] "C:\Program Files\Uniblue\DriverScanner\launcher.exe" delay 20000
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3299935F-2C5A-499A-9908-95CFFF6EF8C1} (Quicksilver Class) - http://ca1mikpws003.ops.placeware.com/etc/…quicksilver.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1095708580546
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = extremepittsburgh.local
O17 - HKLM\Software\..\Telephony: DomainName = extremepittsburgh.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = extremepittsburgh.local
O18 - Protocol: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.5.1234\6.5.1234\TmBpIe32.dll
O18 - Protocol: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\TmIEPlg.dll
O18 - Protocol: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll
O18 - Protocol: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINNT\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINNT\System32\browseui.dll
O23 - Service: Trend Micro Solution Platform (Amsp) - Trend Micro Inc. - C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: icvmlt32 - Unknown owner - C:\ICVERIFY\ICWin404\PCVXWinServiceManager.exe
O23 - Service: JCard Service - Unknown owner - C:\ICVERIFY\ICWin404\Jcard\JCardService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: PEVSystemStart - Unknown owner - C:\iexplorer\PEV.cfxxe
–
End of file - 7099 bytes
Posted Image

You have a badly infected computer that I don't know if it can be cleaned or not.


Please don't attach the scans / logs, use "copy/paste".


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:


Note: Close all browsers before running ATF Cleaner: IE, FireFox, etc.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Next:

Internet Explorer (Windows)
1. Click "Tools", then click "Internet Options". This will bring up the Internet Options window.

2. Click the "Connections" tab, then click the "LAN Settings" button.

3. Uncheck the box labeled "Use a proxy server for your LAN". Click "OK", and click "OK" in the previous window. This will remove the proxy server settings in Internet Explorer.



Firefox (Windows)
1. Click "Tools", then click "Options" to bring up the Options window.

2. Click the "Advanced" button, then click the "Network" tab.

3. Click the "Settings" button, located next to "Configure how Firefox connects to the Internet".

4. Click the radio button labeled "No proxy". Click "OK" twice. This will remove the proxy server settings in Firefox.

Next:

Disable Internet Explorer Proxy Settings and Reset TCP/IP and Winsock

Disable Internet Explorer Proxy Settings and Reset TCP/IP

It is very important that these steps be carried out exactly as shown otherwise the fix will not work.
If you have any questions please ask before moving on.
  • Please start Notepad and using your mouse make sure you select and copy all the information below in the Code box into your new document.
  • Then save the file as "fixme.bat" to your Desktop
  • In the drop down box for Save as type: make sure you select All Files (*.*) and keep the quotes on the name as well. Then close the new file.
    @ECHO OFF
    reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v ProxyServer /f
    reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v ProxyOverride /f
    reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v ProxyEnable  /t REG_DWORD /d 0 /f
    reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v GlobalUserOffline /t REG_DWORD /d 0 /f
    netsh int ip reset resetlog.txt
    netsh winsock reset catalog
  • On Windows XP you can double-click the file to run it.
  • On Vista/Win7 you need to Right click the file and choose Run as administrator to run it. With User Account Control on it should ask permission to run it. Click Yes
  • This will flash a black DOS box very quickly and go away, this is normal.
  • Restart your computer now.
  • Launch Internet Explorer and see if you can connect to the Internet.
  • Post a new HijackThis log
LDTate, Thank you for getting back to me and sorry about the delay in responding; I had to go out of town for a day, unexpectedly. So, I followed your instructions and unfortunately now my PC will not boot. It gets caught in a loop upon restarting - gets to the WIndows XP start screen for just about 3 seconds then there is an exceptionally fast flashing BSOD before it begins to reboot (over and over). I also tried choosing "Safemode with Networking" but this did not help. Any ideas? Thanks again, bb
Note To start the computer from the Windows XP CD-ROM, you must configure the basic input/output system (BIOS) of the computer to start from your CD-ROM.

To run the Recovery Console from the Windows XP startup disks or the Windows XP CD-ROM, follow these steps:
Insert the Windows XP startup disk into the floppy disk drive, or insert the Windows XP CD-ROM into the CD drive, and then restart the computer.

Click to select any options that are required to start the computer from the CD drive if you are prompted.
When the "Welcome to Setup" screen appears, press R to start the Recovery Console.
If you have a dual-boot or multiple-boot computer, select the installation that you must access from the Recovery Console.
When you are prompted, type the Administrator password. If the administrator password is blank, just press ENTER.
At the command prompt, type the appropriate commands to diagnose and repair your Windows XP installation.


At the C:\windows prompt type in: Fixboot and tap enter key
Type in Exit and try to reboot normal.

If that doesn't work, go through the same steps but use: FIXMBR and tap enter key
Type in Exit and try to reboot normal.
Thanks. Once in the Recovery Consol after rebooting from the CD, this is what I see C:\WINNT Which Windows Installation would you like to log onto (To Exit, press ENTER)? Also, I was never prompted for a password.
K, before proceeding… When I type: Fitboot It asks… The target partition is D:. Are you sure you want to write a new bootsector to partition D:? Is that expected?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI