This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Can't access search engines

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The computer I'm having problems with had a problem with a virus a couple of weeks ago. I believe the faulty program was called Internet Security Essentials - one of those ones that put up an alert like "Warning! An infection has been found on your computer. Download this product to fix it!" I wasn't the one using it at the time, so the computer ended up infected. I deleted the files the virus added to the temp folder and the start menu and scanned with Malwarebyte's Anti-Malware to see if there was anything else. It found a trojan named Fakehost. Supposedly it fixed the problem, but I still can't access Google, Bing, or any other search engines, but other sites haven't been affected.

I scanned with HijackThis, but upon starting the scan an alert came up saying that it was denied write access to the Hosts file.

Here's the log from hijackthis:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:45:15 PM, on 3/9/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Documents and Settings\LORI\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp_adb…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_adb…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: 96.44.181.245 www.google.com
O1 - Hosts: 96.44.181.245 google.com
O1 - Hosts: 96.44.181.245 google.com.au
O1 - Hosts: 96.44.181.245 www.google.com.au
O1 - Hosts: 96.44.181.245 google.be
O1 - Hosts: 96.44.181.245 www.google.be
O1 - Hosts: 96.44.181.245 google.com.br
O1 - Hosts: 96.44.181.245 www.google.com.br
O1 - Hosts: 96.44.181.245 google.ca
O1 - Hosts: 96.44.181.245 www.google.ca
O1 - Hosts: 96.44.181.245 google.ch
O1 - Hosts: 96.44.181.245 www.google.ch
O1 - Hosts: 96.44.181.245 google.de
O1 - Hosts: 96.44.181.245 www.google.de
O1 - Hosts: 96.44.181.245 google.dk
O1 - Hosts: 96.44.181.245 www.google.dk
O1 - Hosts: 96.44.181.245 google.fr
O1 - Hosts: 96.44.181.245 www.google.fr
O1 - Hosts: 96.44.181.245 google.ie
O1 - Hosts: 96.44.181.245 www.google.ie
O1 - Hosts: 96.44.181.245 google.it
O1 - Hosts: 96.44.181.245 www.google.it
O1 - Hosts: 96.44.181.245 google.co.jp
O1 - Hosts: 96.44.181.245 www.google.co.jp
O1 - Hosts: 96.44.181.245 google.nl
O1 - Hosts: 96.44.181.245 www.google.nl
O1 - Hosts: 96.44.181.245 google.no
O1 - Hosts: 96.44.181.245 www.google.no
O1 - Hosts: 96.44.181.245 google.co.nz
O1 - Hosts: 96.44.181.245 www.google.co.nz
O1 - Hosts: 96.44.181.245 google.pl
O1 - Hosts: 96.44.181.245 www.google.pl
O1 - Hosts: 96.44.181.245 google.se
O1 - Hosts: 96.44.181.245 www.google.se
O1 - Hosts: 96.44.181.245 google.co.uk
O1 - Hosts: 96.44.181.245 www.google.co.uk
O1 - Hosts: 96.44.181.245 google.co.za
O1 - Hosts: 96.44.181.245 www.google.co.za
O1 - Hosts: 96.44.181.245 www.google-analytics.com
O1 - Hosts: 96.44.181.245 www.bing.com
O1 - Hosts: 96.44.181.245 search.yahoo.com
O1 - Hosts: 96.44.181.245 www.search.yahoo.com
O1 - Hosts: 96.44.181.245 uk.search.yahoo.com
O1 - Hosts: 96.44.181.245 ca.search.yahoo.com
O1 - Hosts: 96.44.181.245 de.search.yahoo.com
O1 - Hosts: 96.44.181.245 fr.search.yahoo.com
O1 - Hosts: 96.44.181.245 au.search.yahoo.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10c.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: palmOne Registration.lnk = C:\Program Files\palmOne\register.exe
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\palmOne\Hotsync.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O24 - Desktop Component 0: (no name) - http://rds.yahoo.com/S=96062883/K=stone+mo…e_mountains.jpg
O24 - Desktop Component 1: (no name) - http://rds.yahoo.com/S=96062883/K=stone+mo…92/14099299.jpg
O24 - Desktop Component 2: (no name) - http://rds.yahoo.com/S=96062883/K=stone+mo…89/11438933.jpg

–
End of file - 16694 bytes


Replies will be slow, as this computer is at my parent's house, where no one else is savvy enough to keep something like this from happening in the first place, unfortunately. There shouldn't be a problem with my not responding within the three day time limit, as I will be watching this thread from home, but I want any potential helpers to know I'm not trying to waste your time. Thanks in advance.
Hello and Welcome to the forums!

My name is Carolyn and I'll be glad to help you with your computer problems.

Please do not run any other tool untill instructed to do so!
Please reply to this thread, do not start another!
Please tell me about any problems that have occurred during the fix.
Please tell me of any other symptoms you may be having as these can help also.
Please try as much as possible not to run anything while executing a fix.

If you follow these instructions, everything should go smoothly.

Step 1

HostsXpert
Please download HostsXpert …© Funkytoad.com. Save it to your desktop.
If you use (WinRar, Winzip, etc)… to extract files to the desktop, then skip to the Run HostsXpert section.
Unzip HostsXpert
  • Right click on HostsXpert.zip and select Extract All….
  • Click Next on the "Welcome to the Compressed (zipped) Folders Extraction Wizard", screen.
  • Click on the Browse button… click on Desktop… then click OK.
  • Once done, check (tick) the Show extracted files box and click Finish.
  • Once extracted, HostsXpert folder will open.
Run HostsXpert
  • Double click on HostsXpert.exe to start it.
  • Check to see if the button (top left hand side) says Make Writable?
    • If Yes… click on it and continue to next instruction.
      If No… just continue to next instruction
  • Click on Restore MS Hosts File to restore your Hosts file to its default condition.
  • Click OK… at the confirm restore prompt.
  • Click on the Download button (lower left side).
    Click on MVPs Hosts… button.
    Click on Replace… button. Press OK in the pop up box.
    HostsXpert will now download the MVPs Hosts entries and update your Hosts file.
    When finished…
  • Click on File Handling… button.
  • Click on Make Read Only? to set the file attributes.
  • Close and Exit HostsXpert.

—————————————————–

Step 2

[external image: Posted Image]
Download DDS and save it to your desktop from here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop.

—————————————————–

Please include the following logs in your next reply (post all logs as text, no attachments please):
  • DDS.txt
  • Attach.txt
When I go to restore the MSHosts file, an error comes up saying that HostsXpert can't create the hosts file. Tried again after disabling Norton to no effect. HostsXpert also had a couple of alerts about the host file being hidden and marked as a system file and changing those attributes. I also attempted to change the hidden attribute manually and it seems that access to the hosts file is denied. Is the malware that started the problem keeping it from being changed, or is this normal? Also, can you name an example of a script blocker? I have a feeling that there's not one installed on this computer, but I need to be sure. Should I run DDS anyway? Speaking of which, your first download link for DDS does not work. Might wanna update the text you copied that from. :)

Is the malware that started the problem keeping it from being changed, or is this normal?


It is the malware that has modified the Hosts file. We'll deal with that later.

Thank you for the heads up regarding the broken DDS download link.

Instead of using DDS, let's use another tool:

OTL
Please download OTL … by Old Timer . Save it to your Desktop.
  • Double click on OTL.exe to run it.
  • Click the Scan All Users checkbox.
    Leave the remaining selections to the default settings.
  • Click on Run Scan at the top left hand corner.
  • When done, two Notepad files will open.
    • OTL.txt <– Will be opened, maximized
    • Extras.txt <– Will be minimized on task bar.
  • Please post the contents of both OTL.txt and Extras.txt files in your next reply.
Contents of OTL.text:

OTL logfile created on: 3/10/2011 3:48:42 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\LORI\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 292.00 Mb Available Physical Memory | 57.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 24.78 Gb Free Space | 33.28% Space Free | Partition Type: NTFS

Computer Name: ROSCOE | User Name: LORI | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/03/10 15:47:07 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\LORI\Desktop\OTL.exe
PRC - [2010/03/04 14:08:20 | 000,099,720 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
PRC - [2009/09/29 09:17:50 | 000,013,088 | —- | M] (Intuit Inc.) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
PRC - [2008/06/17 08:35:43 | 001,251,720 | —- | M] () – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/02/11 16:22:14 | 000,191,848 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE
PRC - [2008/02/11 16:22:14 | 000,169,320 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE
PRC - [2008/02/11 16:22:14 | 000,053,096 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE
PRC - [2008/01/29 16:38:31 | 000,583,048 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
PRC - [2007/10/01 13:50:08 | 000,214,408 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
PRC - [2007/09/13 16:49:48 | 000,202,088 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\CCPROXY.EXE
PRC - [2007/07/12 12:43:50 | 000,226,904 | —- | M] (Macrovision Corporation) – C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe
PRC - [2007/05/23 11:13:38 | 000,139,888 | —- | M] (Symantec Corporation) – C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVAPSVC.EXE
PRC - [2006/12/15 12:36:28 | 000,750,720 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
PRC - [2006/01/19 11:06:18 | 000,102,400 | —- | M] (Musicmatch, Inc.) – C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe
PRC - [2006/01/19 11:06:16 | 000,416,768 | —- | M] (Musicmatch, Inc.) – C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
PRC - [2004/09/02 01:54:52 | 000,180,269 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2003/03/20 19:13:18 | 001,167,872 | —- | M] () – C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.exe
PRC - [2002/07/01 09:50:00 | 000,028,672 | —- | M] (Logitech Inc. ) – C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE
PRC - [2001/11/07 11:45:11 | 000,196,608 | —- | M] (HP) – C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb04.exe


========== Modules (SafeList) ==========

MOD - [2011/03/10 15:47:07 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\LORI\Desktop\OTL.exe
MOD - [2010/08/23 11:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2008/02/11 16:22:14 | 000,379,240 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\CCL40.DLL
MOD - [2005/09/23 17:38:24 | 000,123,488 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\AntiSpam\asOEHook.dll
MOD - [2002/07/01 09:50:00 | 000,024,576 | —- | M] (Logitech Inc. ) – C:\Program Files\Logitech\MouseWare\system\LGMOUSHK.DLL


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – – (RoxLiveShare9)
SRV - [2010/03/04 14:08:20 | 002,106,760 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE – (LiveUpdate)
SRV - [2010/03/04 14:08:20 | 000,099,720 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe – (Automatic LiveUpdate Scheduler)
SRV - [2009/09/29 09:17:50 | 000,013,088 | —- | M] (Intuit Inc.) [Auto | Running] – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe – (IntuitUpdateService)
SRV - [2008/06/17 08:35:43 | 001,251,720 | —- | M] () [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe – (Symantec Core LC)
SRV - [2008/02/11 16:22:14 | 000,191,848 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe – (ccEvtMgr)
SRV - [2008/02/11 16:22:14 | 000,169,320 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe – (ccSetMgr)
SRV - [2008/01/29 16:38:31 | 000,583,048 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe – (LiveUpdate Notice Service)
SRV - [2007/10/01 13:50:08 | 000,214,408 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe – (SNDSrvc)
SRV - [2007/09/13 16:49:48 | 000,202,088 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccProxy.exe – (ccProxy)
SRV - [2007/05/23 11:13:38 | 000,139,888 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe – (navapsvc)
SRV - [2007/03/07 14:47:46 | 000,076,848 | —- | M] () [On_Demand | Stopped] – C:\Program Files\DellSupport\brkrsvc.exe – (DSBrokerService)
SRV - [2007/01/16 10:25:28 | 000,045,696 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Norton Internet Security\comHost.exe – (comHost)
SRV - [2006/12/15 12:36:28 | 000,750,720 | —- | M] (Symantec Corporation) [On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE – (NSCService)
SRV - [2006/02/03 17:29:36 | 000,072,328 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Norton Internet Security\ccPwdSvc.exe – (ccISPwdSvc)
SRV - [2005/12/19 19:41:56 | 000,198,416 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe – (SAVScan)
SRV - [2005/11/03 19:06:21 | 001,160,848 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe – (SPBBCSvc)
SRV - [2003/03/03 13:33:40 | 000,143,360 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\NCS\Sync\NetSvc.exe – (NetSvc)


========== Driver Services (SafeList) ==========

DRV - [2010/09/15 13:07:08 | 000,270,712 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20110307.001\symidsco.sys – (SYMIDSCO)
DRV - [2010/02/16 08:30:28 | 001,324,720 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100506.005\NAVEX15.SYS – (NAVEX15)
DRV - [2010/02/16 08:30:28 | 000,371,248 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\eengine\eeCtrl.sys – (eeCtrl)
DRV - [2010/02/16 08:30:28 | 000,084,912 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100506.005\NAVENG.SYS – (NAVENG)
DRV - [2009/08/27 03:00:00 | 000,102,448 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\eengine\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2009/01/31 19:09:10 | 000,124,464 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.SYS – (SymEvent)
DRV - [2008/04/13 13:45:29 | 000,010,624 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\gameenum.sys – (gameenum)
DRV - [2007/12/08 09:24:14 | 000,016,694 | —- | M] (PalmSource, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\PalmUSBD.sys – (PalmUSBD)
DRV - [2007/10/01 13:49:26 | 000,189,320 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\SYMTDI.SYS – (SYMTDI)
DRV - [2007/10/01 13:49:20 | 000,023,944 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS – (SYMREDRV)
DRV - [2007/10/01 13:49:16 | 000,031,624 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMIDS.SYS – (SYMIDS)
DRV - [2007/10/01 13:49:10 | 000,028,040 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMNDIS.SYS – (SYMNDIS)
DRV - [2007/10/01 13:49:04 | 000,098,184 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMFW.SYS – (SYMFW)
DRV - [2007/10/01 13:48:56 | 000,012,680 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMDNS.SYS – (SYMDNS)
DRV - [2007/04/09 19:44:52 | 000,391,256 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys – (SPBBCDrv)
DRV - [2007/02/25 11:10:48 | 000,005,376 | –S- | M] (Gteko Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys – (dsunidrv)
DRV - [2006/10/05 15:07:28 | 000,004,736 | —- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys – (DSproct)
DRV - [2006/06/04 02:47:49 | 000,010,344 | —- | M] (Symantec Corporation) [Kernel | Auto | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\symlcbrd.sys – (symlcbrd)
DRV - [2005/12/19 19:41:58 | 000,054,968 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Norton Internet Security\Norton AntiVirus\Savrtpel.sys – (SAVRTPEL)
DRV - [2005/12/19 19:41:56 | 000,337,592 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Norton Internet Security\Norton AntiVirus\savrt.sys – (SAVRT)
DRV - [2005/03/30 06:57:25 | 000,008,413 | —- | M] (RealNetworks, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\mcstrm.sys – (MCSTRM)
DRV - [2004/08/04 00:29:49 | 000,019,455 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys – (iAimFP4)
DRV - [2004/08/04 00:29:47 | 000,012,063 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys – (iAimFP3)
DRV - [2004/08/04 00:29:45 | 000,023,615 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys – (iAimTV4)
DRV - [2004/08/04 00:29:43 | 000,033,599 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys – (iAimTV3)
DRV - [2004/08/04 00:29:42 | 000,019,551 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys – (iAimTV1)
DRV - [2004/08/04 00:29:41 | 000,029,311 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys – (iAimTV0)
DRV - [2004/08/04 00:29:37 | 000,012,415 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys – (iAimFP0)
DRV - [2004/08/04 00:29:37 | 000,012,127 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys – (iAimFP1)
DRV - [2004/08/04 00:29:37 | 000,011,775 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys – (iAimFP2)
DRV - [2004/08/04 00:29:36 | 000,161,020 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys – (i81x)
DRV - [2004/08/04 00:29:26 | 000,327,040 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtaa.sys – (ati2mtaa)
DRV - [2003/11/17 15:59:20 | 000,212,224 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWBS2.sys – (HSFHWBS2)
DRV - [2003/11/17 15:58:02 | 000,680,704 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys – (winachsf)
DRV - [2003/11/17 15:56:26 | 001,042,432 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys – (HSF_DP)
DRV - [2003/08/14 10:58:12 | 001,296,384 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\P16X.sys – (P16X) Creative SB Live! Series (WDM)
DRV - [2002/11/08 13:45:06 | 000,017,217 | —- | M] (Dell Computer Corporation) [Kernel | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys – (omci)
DRV - [2002/07/02 11:20:51 | 000,070,382 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\LMouFlt2.sys – (LMouFlt2)
DRV - [2002/07/02 11:20:51 | 000,040,508 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\LHIDUSB.SYS – (LHidUsb)
DRV - [2002/07/02 11:20:51 | 000,023,854 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\LHIDFLT2.SYS – (LHidFlt2)
DRV - [2002/07/02 11:20:51 | 000,006,030 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\LKbdFlt2.sys – (LKbdFlt2)
DRV - [2002/07/02 11:20:50 | 000,050,830 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\L8042Pr2.sys – (l8042pr2)
DRV - [2001/08/17 12:11:06 | 000,066,591 | —- | M] (3Com Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS – (EL90XBC)
DRV - [1999/12/17 01:00:00 | 000,006,752 | —- | M] (Creative Technology Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\SYSTEM32\PFMODNT.SYS – (PfModNT)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell4me.com/myway
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.se1.attbb.net
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = sas.se1.attbb.net:8000

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell4me.com/myway
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.se1.attbb.net
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = sas.se1.attbb.net:8000

IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-36674038-2814320496-617243875-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_adb…//www.yahoo.com
IE - HKU\S-1-5-21-36674038-2814320496-617243875-1007\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKU\S-1-5-21-36674038-2814320496-617243875-1007\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKU\S-1-5-21-36674038-2814320496-617243875-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
IE - HKU\S-1-5-21-36674038-2814320496-617243875-1007\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-36674038-2814320496-617243875-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-36674038-2814320496-617243875-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "http://www.comcast.com"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: [removed]:0.2.2
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.14.2

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/09 21:23:44 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/09 21:23:43 | 000,000,000 | —D | M]

[2009/02/24 20:54:58 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\LORI\Application Data\Mozilla\Extensions
[2011/03/09 21:41:29 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\LORI\Application Data\Mozilla\Firefox\Profiles\37sv5xp0.default\extensions
[2009/09/10 17:48:24 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\LORI\Application Data\Mozilla\Firefox\Profiles\37sv5xp0.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/09 21:41:20 | 000,000,000 | —D | M] (Flashblock) – C:\Documents and Settings\LORI\Application Data\Mozilla\Firefox\Profiles\37sv5xp0.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2007/06/04 08:47:38 | 000,000,000 | —D | M] (ReloadEvery) – C:\Documents and Settings\LORI\Application Data\Mozilla\Firefox\Profiles\37sv5xp0.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
[2011/03/09 21:41:21 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\LORI\Application Data\Mozilla\Firefox\Profiles\37sv5xp0.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011/03/09 21:41:20 | 000,000,000 | —D | M] (Adblock Plus Pop-up Addon) – C:\Documents and Settings\LORI\Application Data\Mozilla\Firefox\Profiles\37sv5xp0.default\extensions\[removed]
[2009/02/24 20:55:00 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2011/02/26 21:32:44 | 000,002,134 | RHS- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 96.44.181.245 www.google.com
O1 - Hosts: 96.44.181.245 google.com
O1 - Hosts: 96.44.181.245 google.com.au
O1 - Hosts: 96.44.181.245 www.google.com.au
O1 - Hosts: 96.44.181.245 google.be
O1 - Hosts: 96.44.181.245 www.google.be
O1 - Hosts: 96.44.181.245 google.com.br
O1 - Hosts: 96.44.181.245 www.google.com.br
O1 - Hosts: 96.44.181.245 google.ca
O1 - Hosts: 96.44.181.245 www.google.ca
O1 - Hosts: 96.44.181.245 google.ch
O1 - Hosts: 96.44.181.245 www.google.ch
O1 - Hosts: 96.44.181.245 google.de
O1 - Hosts: 96.44.181.245 www.google.de
O1 - Hosts: 96.44.181.245 google.dk
O1 - Hosts: 96.44.181.245 www.google.dk
O1 - Hosts: 96.44.181.245 google.fr
O1 - Hosts: 96.44.181.245 www.google.fr
O1 - Hosts: 96.44.181.245 google.ie
O1 - Hosts: 96.44.181.245 www.google.ie
O1 - Hosts: 96.44.181.245 google.it
O1 - Hosts: 96.44.181.245 www.google.it
O1 - Hosts: 96.44.181.245 google.co.jp
O1 - Hosts: 96.44.181.245 www.google.co.jp
O1 - Hosts: 23 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (CNisExtBho Class) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll (Symantec Corporation)
O2 - BHO: (CNavExtBho Class) - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVSHEXT.DLL (Symantec Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Norton Internet Security 2006) - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton AntiVirus) - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVSHEXT.DLL (Symantec Corporation)
O3 - HKU\S-1-5-21-36674038-2814320496-617243875-1007\..\Toolbar\WebBrowser: (Norton Internet Security 2006) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-36674038-2814320496-617243875-1007\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKU\S-1-5-21-36674038-2814320496-617243875-1007\..\Toolbar\WebBrowser: (Norton AntiVirus) - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVSHEXT.DLL (Symantec Corporation)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [diagent] C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [EM_EXEC] C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE (Logitech Inc. )
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb04.exe (HP)
O4 - HKLM..\Run: [MimBoot] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mimboot.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKU\S-1-5-21-36674038-2814320496-617243875-1007..\Run: [ISUSPM] C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe (Macrovision Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\palmOne\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe (Logitech)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg.exe ()
O4 - Startup: C:\Documents and Settings\LORI\Start Menu\Programs\Startup\palmOne Registration.lnk = C:\Program Files\palmOne\register.exe (palmOne/Leader Technologies)
O4 - Startup: C:\Documents and Settings\LORI\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = _ [binary data]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-36674038-2814320496-617243875-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Google; Search - c:\program files\google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Backward Links - c:\program files\google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Similar Pages - c:\program files\google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Translate into English - c:\program files\google\GoogleToolbar1.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Value error. File not found
O9 - Extra Button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O15 - HKU\S-1-5-21-36674038-2814320496-617243875-1007\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O15 - HKU\S-1-5-21-36674038-2814320496-617243875-1007\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?LinkId=39204&clcid;=0x409 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc2.cab (Office Update Installation Engine)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} https://webdl.symantec.com/activex/symdlmgr.cab (Symantec Download Manager)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 () - http://rds.yahoo.com/S=96062883/K=stone+mo…e_mountains.jpg
O24 - Desktop Components:1 () - http://rds.yahoo.com/S=96062883/K=stone+mo…92/14099299.jpg
O24 - Desktop Components:2 () - http://rds.yahoo.com/S=96062883/K=stone+mo…89/11438933.jpg
O24 - Desktop Components:3 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\LORI\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\LORI\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O29 - HKLM SecurityProviders - (xlibgfl254.dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/09/03 08:59:58 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{61125a10-b887-11db-9654-000cf1f9b53b}\Shell\AutoRun\command - "" = setupSNK.exe
O33 - MountPoints2\{c9c2f4e2-a45a-11dc-97cb-000cf1f9b53b}\Shell - "" = AutoRun
O33 - MountPoints2\{c9c2f4e2-a45a-11dc-97cb-000cf1f9b53b}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\LaunchU3.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/03/10 15:47:05 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\LORI\Desktop\OTL.exe
[2011/03/10 14:28:36 | 000,000,000 | —D | C] – C:\Documents and Settings\LORI\Desktop\HostsXpert
[2011/03/09 22:51:35 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2011/03/09 21:26:23 | 000,000,000 | —D | C] – C:\Documents and Settings\LORI\My Documents\Downloads
[2011/03/09 21:08:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/03/09 21:06:14 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/03/09 21:02:13 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2011/03/09 20:58:34 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/03/09 20:49:10 | 080,298,280 | —- | C] (Apple Inc.) – C:\Documents and Settings\LORI\Desktop\iTunesSetup.exe
[2011/03/09 20:30:11 | 000,000,000 | —D | C] – C:\ie-spyad_zo
[2011/03/09 20:25:37 | 000,000,000 | —D | C] – C:\ZonedOut
[2011/03/09 19:40:20 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\LORI\Desktop\HiJackThis.exe
[2011/03/06 08:40:52 | 000,000,000 | —D | C] – C:\Documents and Settings\LORI\Desktop\edgar file
[2011/03/06 07:32:28 | 000,000,000 | —D | C] – C:\Documents and Settings\LORI\Desktop\Jean
[2011/03/06 07:08:59 | 000,000,000 | —D | C] – C:\Documents and Settings\LORI\Desktop\james goldsby
[2011/02/26 22:47:11 | 000,000,000 | —D | C] – C:\Documents and Settings\LORI\My Documents\Abigail
[2011/02/17 18:24:27 | 000,000,000 | —D | C] – C:\Program Files\iPod(2)
[2011/02/17 18:14:44 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/02/15 22:01:45 | 000,249,325 | —- | C] (John El Self) – C:\Documents and Settings\LORI\My Documents\tswin - Copy.exe
[2011/02/09 07:21:46 | 000,000,000 | —D | C] – C:\Documents and Settings\LORI\My Documents\letters
[2004/07/09 13:32:18 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\A3d.dll
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/10 15:47:07 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\LORI\Desktop\OTL.exe
[2011/03/10 14:27:00 | 000,353,485 | —- | M] () – C:\Documents and Settings\LORI\Desktop\HostsXpert.zip
[2011/03/10 11:43:49 | 000,000,420 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{0428D3CE-B20B-489A-8274-759974D2F6B6}.job
[2011/03/09 22:50:28 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2011/03/09 22:46:17 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2011/03/09 22:46:16 | 535,875,584 | -HS- | M] () – C:\hiberfil.sys
[2011/03/09 21:08:30 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/03/09 21:02:19 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/03/09 20:51:16 | 080,298,280 | —- | M] (Apple Inc.) – C:\Documents and Settings\LORI\Desktop\iTunesSetup.exe
[2011/03/09 19:40:22 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\LORI\Desktop\HiJackThis.exe
[2011/03/09 19:34:32 | 000,042,606 | —- | M] () – C:\Documents and Settings\LORI\Application Data\wklnhst.dat
[2011/03/09 03:02:29 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/03/08 16:53:17 | 000,002,483 | —- | M] () – C:\Documents and Settings\LORI\Desktop\Microsoft Word.lnk
[2011/03/06 14:50:08 | 000,000,376 | —- | M] () – C:\WINDOWS\ODBC.INI
[2011/03/06 14:17:31 | 000,000,395 | —- | M] () – C:\WINDOWS\hegames.ini
[2011/03/04 20:31:20 | 000,000,546 | —- | M] () – C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - LORI.job
[2011/03/01 00:47:20 | 000,242,328 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/27 08:00:08 | 006,830,263 | —- | M] () – C:\Documents and Settings\LORI\My Documents\w_E_20101215_07.mp3
[2011/02/27 07:04:54 | 000,002,387 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TurboTax 2009.lnk
[2011/02/26 22:43:36 | 000,000,802 | —- | M] () – C:\Documents and Settings\LORI\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/02/26 21:51:49 | 000,000,751 | —- | M] () – C:\Documents and Settings\LORI\Start Menu\Programs\Startup\palmOne Registration.lnk
[2011/02/26 21:32:44 | 000,002,134 | RHS- | M] () – C:\WINDOWS\System32\drivers\ETC\hosts
[2011/02/18 16:36:58 | 004,184,352 | —- | M] (Apple, Inc.) – C:\WINDOWS\System32\usbaaplrc.dll
[2011/02/09 08:53:52 | 000,270,848 | —- | M] () – C:\WINDOWS\System32\dllcache\sbe.dll
[2011/02/09 08:53:52 | 000,186,880 | —- | M] () – C:\WINDOWS\System32\dllcache\encdec.dll
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/03/10 14:26:48 | 000,353,485 | —- | C] () – C:\Documents and Settings\LORI\Desktop\HostsXpert.zip
[2011/03/09 21:08:30 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/03/09 21:02:18 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/03/06 17:24:51 | 535,875,584 | -HS- | C] () – C:\hiberfil.sys
[2011/02/28 22:47:48 | 000,151,768 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/02/27 08:00:03 | 006,830,263 | —- | C] () – C:\Documents and Settings\LORI\My Documents\w_E_20101215_07.mp3
[2011/02/19 00:18:48 | 002,035,589 | —- | C] () – C:\Documents and Settings\LORI\My Documents\Copy of TMS 2011-E.pdf
[2011/02/09 08:53:52 | 000,270,848 | —- | C] () – C:\WINDOWS\System32\dllcache\sbe.dll
[2011/02/09 08:53:52 | 000,186,880 | —- | C] () – C:\WINDOWS\System32\dllcache\encdec.dll
[2010/12/09 21:51:31 | 000,047,932 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/01/31 18:15:24 | 000,000,256 | —- | C] () – C:\WINDOWS\System32\pool.bin
[2007/12/08 08:19:37 | 000,000,000 | —- | C] () – C:\WINDOWS\QuickInstall.INI
[2007/08/09 18:53:19 | 000,000,395 | —- | C] () – C:\WINDOWS\hegames.ini
[2007/02/12 03:14:32 | 000,000,000 | —- | C] () – C:\Documents and Settings\LORI\Application Data\Install.dat
[2007/02/04 12:14:19 | 000,000,087 | —- | C] () – C:\WINDOWS\encore_launcher.ini
[2006/11/01 00:42:40 | 000,029,784 | —- | C] () – C:\Program Files\popcorn Terms.html
[2006/05/20 05:04:22 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/03/17 04:35:19 | 000,000,210 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2006/02/26 15:19:40 | 000,003,052 | —- | C] () – C:\WINDOWS\mozver.dat
[2005/06/09 04:22:37 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005/01/21 05:27:26 | 000,000,000 | —- | C] () – C:\Documents and Settings\LORI\Application Data\dm.ini
[2004/09/29 03:42:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/09/24 15:22:16 | 000,012,435 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2004/08/07 16:30:28 | 000,102,912 | —- | C] () – C:\Documents and Settings\LORI\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/07/20 05:39:16 | 000,042,606 | —- | C] () – C:\Documents and Settings\LORI\Application Data\wklnhst.dat
[2004/07/19 15:22:45 | 000,000,127 | —- | C] () – C:\Documents and Settings\LORI\Local Settings\Application Data\fusioncache.dat
[2004/07/19 07:19:07 | 000,081,920 | R— | C] () – C:\WINDOWS\bwUnin-6.1.4.36-8876480L.exe
[2004/07/19 07:18:09 | 000,096,768 | —- | C] () – C:\WINDOWS\System32\LGUICOM.DLL
[2004/07/09 13:49:57 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/07/09 13:43:09 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2004/07/09 13:37:01 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/07/09 13:34:05 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2004/07/09 13:34:03 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/07/09 13:32:31 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2004/07/09 13:32:31 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2004/07/09 13:32:18 | 000,047,616 | —- | C] () – C:\WINDOWS\System32\P16X.dll
[2004/07/09 13:32:18 | 000,002,572 | —- | C] () – C:\WINDOWS\MIXDEF.INI
[2004/07/09 13:32:18 | 000,002,158 | —- | C] () – C:\WINDOWS\System32\P16X.ini
[2004/07/09 13:32:18 | 000,000,064 | —- | C] () – C:\WINDOWS\P16x.ini
[2004/07/09 13:32:18 | 000,000,026 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2004/07/09 13:31:51 | 000,000,245 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2004/07/09 13:28:22 | 000,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/07/09 13:20:51 | 000,028,768 | —- | C] () – C:\WINDOWS\System32\javaw.exe
[2004/07/09 13:20:51 | 000,024,670 | —- | C] () – C:\WINDOWS\System32\java.exe
[2004/07/09 13:13:06 | 000,002,048 | –S- | C] () – C:\WINDOWS\BOOTSTAT.DAT
[2004/07/09 13:10:38 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/07/09 13:10:32 | 000,463,628 | —- | C] () – C:\WINDOWS\System32\PERFH009.DAT
[2004/07/09 13:10:32 | 000,080,654 | —- | C] () – C:\WINDOWS\System32\PERFC009.DAT
[2004/07/09 13:10:21 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/07/09 12:50:14 | 000,000,550 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/03/26 16:59:22 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/09/03 09:05:08 | 000,242,328 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2002/09/03 08:59:14 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2002/09/03 08:56:30 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2002/09/03 08:31:46 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.BIN
[2002/09/03 08:31:44 | 000,004,594 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.DAT
[2002/08/29 05:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\MLANG.DAT
[2002/08/29 05:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\PERFI009.DAT
[2002/08/29 05:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\DSSEC.DAT
[2002/08/29 05:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\MIB.BIN
[2002/08/29 05:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\PERFD009.DAT
[2002/08/29 05:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2002/08/29 05:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\NOISE.DAT
[1980/01/01 00:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\LORI\My Documents\MOV00006.MPG:SummaryInformation

< End of report >

Contents of Extras.txt:

OTL Extras logfile created on: 3/10/2011 3:48:42 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\LORI\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 292.00 Mb Available Physical Memory | 57.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 24.78 Gb Free Space | 33.28% Space Free | Partition Type: NTFS

Computer Name: ROSCOE | User Name: LORI | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hta [@ = Reg Error: Value error.] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Yahoo!\Messenger\YPager.exe" = C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger
"C:\Program Files\TurboTax\Premier 2006\32bit\ttax.exe" = C:\Program Files\TurboTax\Premier 2006\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax
"C:\Program Files\TurboTax\Premier 2006\32bit\updatemgr.exe" = C:\Program Files\TurboTax\Premier 2006\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager
"C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe" = C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax
"C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe" = C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager
"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server – (Intuit Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02807340-8FA2-44B6-ABA1-E443E4FF0A20}" = VZAccess Manager for RIM
"{04410044-9149-45C6-A806-F2BF9CFCE762}" = Microsoft Encarta Encyclopedia Standard 2004
"{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}" = Symantec KB-DocID:2003093015493306
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{1248C09A-BD6B-47F5-BF3F-CD2B700D9FCB}" = ccCommon
"{12E2B9E9-05B1-407d-B0FD-B5F350535125}" = Norton Internet Security
"{13413C6C-C640-40B8-917E-CA3062826B18}" = PIXELA ImageMixer
"{17B66E83-1BC9-11D5-A54A-0090278A1BB8}" = Microsoft FrontPage Client - English
"{1A655D51-1423-48A3-B748-8F5A0BE294C8}" = Microsoft Visual J# .NET Redistributable Package 1.1
"{1D643CD7-4DD6-11D7-A4E0-000874180BB3}" = Microsoft Money 2004
"{20ACB2F8-3BCA-45A8-80A2-9D3CB5C25F43}" = Safari
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Dell Media Experience
"{268A38CA-BB13-48FD-B312-424296DA0676}" = SymNet
"{2818095F-FB6C-42C8-827E-0A406CC9AFF5}" = Quicken 2006
"{2A697B53-0DE3-42DA-B41D-C3F804B1C538}" = iTunes
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
"{2EBF25F1-F8A2-40EA-92BE-931C142A44E2}" = CC_ccProxyExt
"{30738666-9805-4926-A78F-91DA33B6C437}" = ccPxyCore
"{33BEE6F3-9987-4F98-A069-97A64EC8321A}" = Microsoft Works Suite Add-in for Microsoft Word
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{3B29A786-5803-4E9E-9B58-3014A5B4E519}" = Norton AntiSpam
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{3C9AE630-EAA2-012B-AEB0-000000000000}" = TurboTax 2009 wsciper
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{48185814-A224-447a-81DA-71BD20580E1B}" = Norton Internet Security
"{4ABB4D92-0682-4887-A0BC-CE5F920DDD23}" = Watchtower Library 2009 - English
"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement
"{5677563D-0CB1-485F-9E18-C5025306BB3F}" = Norton AntiSpam
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = Logitech MouseWare 9.70
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.1
"{68D60342-7686-45C9-B8EB-40EF843D0460}" = Dell Networking Guide
"{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{77772678-817F-4401-9301-ED1D01A8DA56}" = SPBBC
"{7C5B4583-7CBF-4289-B195-03B553959DEA}" = VoiceOver Kit
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{81A34902-9D0B-4920-A25C-4CDC5D14B328}" = Jasc Paint Shop Pro 8 Dell Edition
"{82A5BF38-8461-4A5C-B2C9-24F5256D92A6}" = Norton Protection Center
"{85D3CC30-8859-481A-9654-FD9B74310BEF}" = Musicmatch® Jukebox
"{8704D51E-25B7-4F23-81E7-AA4F54790210}" = Microsoft Streets and Trips 2004
"{8C64E145-54BA-11D6-91B1-00500462BE80}" = Microsoft Money 2004 System Pack
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{93352A14-437E-4DB2-9CB8-463D0649B5DE}" = MA111 Configuration Utility
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{96E16100-A77F-4B31-B9AD-FFBA040EE1BD}" = Sound Blaster Live!
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A71D5E81-B967-43DB-93D7-FD31BFB95748}" = MobileMe Control Panel
"{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet
"{A93C9E60-29B6-49da-BA21-F70AC6AADE20}" = Norton Internet Security
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0.8
"{AD6ACA58-30FE-4336-A5B0-461FD60AF727}" = FileOpen Client
"{AEC1BAC4-EEF5-4675-92FC-E26B2D293EEB}" = 2009 National Plumbing and HVAC Estimator
"{AFF1EA96-9C23-4249-B7D4-CD4B54D4582F}" = TurboTax ItsDeductible 2006
"{B7C61755-DB48-4003-948F-3D34DB8EAF69}" = MSRedist
"{B9966F27-9678-4620-9579-925E3084647E}" = Microsoft Works
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C6F5B6CF-609C-428E-876F-CA83176C021B}" = Norton AntiVirus 2006
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2121C6-C94D-4A73-8EA4-6943F33EE335}" = Picture Package Music Transfer
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D361C406-ED11-4A88-AD42-4A749BBAE6F9}" = Hoyle Card Games 2007
"{D4D24FE5-FAB3-4FE2-AFFC-623955F4DF3A}" = Visual Studio.NET Baseline - English
"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
"{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}" = LiveUpdate Notice (Symantec Corporation)
"{DBA8B9E1-C6FF-4624-9598-73D3B41A0903}" = Microsoft Picture It! Photo Premium 9
"{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}" = Norton Internet Security
"{E5EE9939-259F-4DE2-8023-5C49E16A4F43}" = Norton Internet Security
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E85FA9A1-C241-4698-893B-DD99509B8DB0}" = Norton WMI Update
"{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}" = WexTech AnswerWorks
"{F64306A5-4C32-41bb-B153-53986527FAB4}" = Norton WMI Update
"{FC4ED75D-916C-4A8C-BB67-3C6F6E06D62B}" = Banctec Service Agreement
"{FF8157AA-F640-45BD-B7C2-BAA1016B267A}" = palmOne
"Ad-Aware SE Personal" = Ad-Aware SE Personal
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AdobeESD" = Adobe Download Manager 2.0 (Remove Only)
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"ComcastHSI" = Comcast High-Speed Internet Install Wizard
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Dogz" = Dogz (remove only)
"hp deskjet 950c series" = hp deskjet 950c series (Remove only)
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Kar Racing" = Kar Racing
"Kogi" = Kogi
"LiveUpdate" = LiveUpdate 3.0 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"MSN Music Assistant" = MSN Music Assistant
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
"PictureIt_v9" = Microsoft Picture It! Photo Premium 9
"Police Chase" = Police Chase
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0" = RealPlayer
"Shockwave" = Shockwave
"SpongeBob SquarePants" = SpongeBob SquarePants® Operation Krabby Patty
"StreetPlugin" = Learn2 Player (Uninstall Only)
"SymSetup.{A93C9E60-29B6-49da-BA21-F70AC6AADE20}" = Norton Internet Security 2006 (Symantec Corporation)
"Talking Typing Teacher" = Talking Typing Teacher
"TurboTax 2009" = TurboTax 2009
"WGA" = Windows Genuine Advantage Validation Tool
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WordSmart Phonics_is1" = WordSmart Phonics 2.0
"WordSmart Vocabulary_is1" = WordSmart 4.7
"Works2004Setup" = Microsoft Works 2004 Setup Launcher

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/8/2011 8:21:13 AM | Computer Name = ROSCOE | Source = Bonjour Service | ID = 100
Description = 204: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 3/8/2011 8:21:13 AM | Computer Name = ROSCOE | Source = Bonjour Service | ID = 100
Description = 232: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 3/8/2011 8:21:32 AM | Computer Name = ROSCOE | Source = Bonjour Service | ID = 100
Description = 232: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 3/8/2011 8:21:32 AM | Computer Name = ROSCOE | Source = Bonjour Service | ID = 100
Description = 204: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 3/8/2011 8:23:10 AM | Computer Name = ROSCOE | Source = Bonjour Service | ID = 100
Description = 204: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 3/8/2011 8:23:10 AM | Computer Name = ROSCOE | Source = Bonjour Service | ID = 100
Description = 232: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 3/9/2011 7:44:25 AM | Computer Name = ROSCOE | Source = Bonjour Service | ID = 100
Description = 232: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 3/9/2011 7:44:25 AM | Computer Name = ROSCOE | Source = Bonjour Service | ID = 100
Description = 204: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 3/9/2011 8:32:58 PM | Computer Name = ROSCOE | Source = Bonjour Service | ID = 100
Description = 204: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

Error - 3/9/2011 8:32:58 PM | Computer Name = ROSCOE | Source = Bonjour Service | ID = 100
Description = 232: ERROR: read_msg errno 10054 (An existing connection was forcibly
closed by the remote host.)

[ System Events ]
Error - 3/9/2011 11:52:46 PM | Computer Name = ROSCOE | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service LiveUpdate
with arguments "" in order to run the server: {03E0E6C2-363B-11D3-B536-00902771A435}

Error - 3/9/2011 11:52:49 PM | Computer Name = ROSCOE | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the stisvc service.

Error - 3/9/2011 11:52:49 PM | Computer Name = ROSCOE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the LiveUpdate service to
connect.

Error - 3/9/2011 11:52:49 PM | Computer Name = ROSCOE | Source = Service Control Manager | ID = 7000
Description = The LiveUpdate service failed to start due to the following error:
%%1053

Error - 3/9/2011 11:59:01 PM | Computer Name = ROSCOE | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service LiveUpdate
with arguments "" in order to run the server: {03E0E6C2-363B-11D3-B536-00902771A435}

Error - 3/9/2011 11:59:04 PM | Computer Name = ROSCOE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the LiveUpdate service to
connect.

Error - 3/9/2011 11:59:05 PM | Computer Name = ROSCOE | Source = Service Control Manager | ID = 7000
Description = The LiveUpdate service failed to start due to the following error:
%%1053

Error - 3/9/2011 11:59:32 PM | Computer Name = ROSCOE | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service LiveUpdate
with arguments "" in order to run the server: {03E0E6C2-363B-11D3-B536-00902771A435}

Error - 3/9/2011 11:59:33 PM | Computer Name = ROSCOE | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the LiveUpdate service to
connect.

Error - 3/9/2011 11:59:33 PM | Computer Name = ROSCOE | Source = Service Control Manager | ID = 7000
Description = The LiveUpdate service failed to start due to the following error:
%%1053


< End of report >

Is this correct?
Hello AiDakura,

Upload a file for scanning
I'd like you to check a file for malware.
  • Go to VirusTotal or Jotti's

C:\Documents and Settings\LORI\My Documents\w_E_20101215_07.mp3

  • Copy/Paste the path/ file in the quote box into the white Upload a file box.
  • Click Send/Submit, and the file will upload to VirusTotal/Jotti, where it will be scanned by several anti-virus programmes.
  • After a while, a window will open, with details of what the scans found.
  • Save the complete results in a Notepad/Word document on your desktop.

=================================
Turn off Norton Internet Security

  • Start Norton Internet Security.
  • In the left pane, click Status & Settings.
  • Click Security.
  • Click Turn off.
  • Note: Don't forget to re-enable it after the fix.

=================================

Run OTL Script

We need to run an OTL Fix

  • Double-click OTL.exe to start the program.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word Code
    :OTL
    O1 HOSTS File: ([2011/02/26 21:32:44 | 000,002,134 | RHS- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
    IE - HKU\S-1-5-21-36674038-2814320496-617243875-1007\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No CLSID value found.
    O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Value error. File not found
    O9 - Extra Button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - File not found
    O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
    O15 - HKU\S-1-5-21-36674038-2814320496-617243875-1007\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
    O15 - HKU\S-1-5-21-36674038-2814320496-617243875-1007\..Trusted Domains: turbotax.com ([]https in Trusted sites)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2)
    O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O24 - Desktop Components:0 () - http://rds.yahoo.com/S=96062883/K=stone+mo…e_mountains.jpg
    O24 - Desktop Components:1 () - http://rds.yahoo.com/S=96062883/K=stone+mo…92/14099299.jpg
    O24 - Desktop Components:2 () - http://rds.yahoo.com/S=96062883/K=stone+mo…89/11438933.jpg
    O33 - MountPoints2\{61125a10-b887-11db-9654-000cf1f9b53b}\Shell\AutoRun\command - "" = setupSNK.exe
    O33 - MountPoints2\{c9c2f4e2-a45a-11dc-97cb-000cf1f9b53b}\Shell - "" = AutoRun
    O33 - MountPoints2\{c9c2f4e2-a45a-11dc-97cb-000cf1f9b53b}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\F\Shell - "" = AutoRun
    O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\LaunchU3.exe
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    
    :Files
    C:\Program Files\popcorn Terms.html
    @Alternate Data Stream - 88 bytes -> C:\Documents and Settings\LORI\My Documents\MOV00006.MPG:SummaryInformation
    
    :Commands
    [emptytemp]
    [resethosts]
  • Then click the Run Fix button at the top.
  • Click [external image: Posted Image].
  • OTL may ask to reboot the machine. Please do so if asked.
  • The report should appear in Notepad after the reboot.Copy and Paste that report in your next reply.

=================================

Update and Scan with Malwarebytes' Anti-Malware
  • Launch Malwarebytes' Anti-Malware then select the Update tab. Click on Check for Updates.
  • Select the Scanner tab. Click on Perform Quick scan, then click on Scan.
  • Leave the default options as it is and click on Start Scan.
  • When done, you will be prompted. Click OK, then click on Show Results.
  • Check (tick) all items except items in the C:\System Volume Information folder and click on Remove Selected.
  • After it has removed the items, Notepad will open. Please post this log in your next reply. You can also find the log in the Logs tab. The bottom most log is the latest.

=================================

ESET online scannner

Note: You can use either Internet Explorer or Mozilla FireFox for this scan.

Note: If you are using Windows Vista or Windows 7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  • Hold down Control then click on the following link to open a new window to ESET online scannner
  • Then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Please post the following:
  • The VirusTotal or Jotti results
  • The OTL fix results
  • The Malwarebytes' log
  • The ESET log
  • A fresh OTL log
  • A description of how your computer is now behaving
VirusTotal results:

0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name:
w_E_20101215_07.mp3
Submission date:
2011-03-11 23:34:43 (UTC)
Current status:
finished
Result:
0/ 43 (0.0%) VT Community

not reviewed
Safety score: -
Compact
Print results
Antivirus Version Last Update Result
AhnLab-V3 2011.03.12.00 2011.03.11 -
AntiVir 7.11.4.174 2011.03.11 -
Antiy-AVL 2.0.3.7 2011.03.09 -
Avast 4.8.1351.0 2011.03.11 -
Avast5 5.0.677.0 2011.03.11 -
AVG 10.0.0.1190 2011.03.12 -
BitDefender 7.2 2011.03.12 -
CAT-QuickHeal 11.00 2011.03.11 -
ClamAV 0.96.4.0 2011.03.11 -
Commtouch 5.2.11.5 2011.03.11 -
Comodo 7947 2011.03.11 -
DrWeb 5.0.2.03300 2011.03.12 -
Emsisoft 5.1.0.2 2011.03.11 -
eSafe 7.0.17.0 2011.03.10 -
eTrust-Vet 36.1.8211 2011.03.11 -
F-Prot 4.6.2.117 2011.03.11 -
F-Secure 9.0.16440.0 2011.03.11 -
Fortinet 4.2.254.0 2011.03.11 -
GData 21 2011.03.11 -
Ikarus T3.1.1.97.0 2011.03.11 -
Jiangmin 13.0.900 2011.03.11 -
K7AntiVirus 9.93.4087 2011.03.11 -
Kaspersky 7.0.0.125 2011.03.11 -
McAfee 5.400.0.1158 2011.03.11 -
McAfee-GW-Edition 2010.1C 2011.03.11 -
Microsoft 1.6603 2011.03.11 -
NOD32 5946 2011.03.11 -
Norman 6.07.03 2011.03.11 -
nProtect 2011-02-10.01 2011.02.15 -
Panda 10.0.3.5 2011.03.11 -
PCTools 7.0.3.5 2011.03.11 -
Prevx 3.0 2011.03.12 -
Rising 23.48.04.06 2011.03.11 -
Sophos 4.63.0 2011.03.11 -
SUPERAntiSpyware 4.40.0.1006 2011.03.11 -
Symantec 20101.3.0.103 2011.03.12 -
TheHacker 6.7.0.1.147 2011.03.11 -
TrendMicro 9.200.0.1012 2011.03.11 -
TrendMicro-HouseCall 9.200.0.1012 2011.03.11 -
VBA32 3.12.14.3 2011.03.11 -
VIPRE 8670 2011.03.11 -
ViRobot 2011.3.11.4353 2011.03.11 -
VirusBuster 13.6.246.3 2011.03.11 -
Additional information
Show all
MD5 : b033260f3f592bb4ad0df62178fc62c6
SHA1 : dd1c23452d23d32d49f853d122e59714819ed62e
SHA256: 32f3cd1fe23b358095226d221a5fe3c6e463047f7592293fc5a64633f274dd78
ssdeep: 98304:Ac6NwaiTtE8dRlHryCHpRIg/MRZMYGNq1mOH1qn6P/A+WNH73uFW2l7xXC:ATRWRlLEg/
MRdG01T1nA+WNakA
File size : 6830263 bytes
First seen: 2011-03-11 23:34:43
Last seen : 2011-03-11 23:34:43
TrID:
Sprint Music Store audio (70.0%)
MP3 audio (ID3 v2.x tag) (29.9%)
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned
ExifTool:
file metadata
Album: The Watchtower - December 15, 2010
Artist: Watch Tower Bible and Tract Society of PA
AudioBitrate: 48000
AudioLayer: 3
ChannelMode: Single Channel
Comment-eng: 2010 Watch Tower Bible and Tract Society of Pennsylvania
CopyrightFlag: False
DateTimeOriginal: 2010
Duration: 18:44 (approx)
Emphasis: None
EncodedBy: Fraunhofer IIS MP3 v04.00.03 (high quality)
FileSize: 6.5 MB
FileType: MP3
ID3Size: 82999
IntensityStereo: Off
MIMEType: audio/mpeg
MPEGAudioVersion: 2
MSStereo: Off
OriginalMedia: False
Picture: (Binary data 72408 bytes)
PictureDescription:
PictureMimeType: image/jpeg
PictureType: Other
SampleRate: 24000
Title: Sing to Jehovah! (February 21-27)
Track: 7
Year: 2010
VT Community
This file has never been reviewed by any VT Community member. Be the first one to comment on it!

Yeah, that file is a religious song. Odd that it came up in the scan.

OTL fix log:

All processes killed
========== OTL ==========
Registry value HKEY_USERS\S-1-5-21-36674038-2814320496-617243875-1007\Software\Microsoft\Internet Explorer\URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{d81ca86b-ef63-42af-bee3-4502d9a03c2d}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d81ca86b-ef63-42af-bee3-4502d9a03c2d}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\musicmatch.com\online\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-36674038-2814320496-617243875-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\intuit.com\ttlc\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-36674038-2814320496-617243875-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\turbotax.com\ deleted successfully.
Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
C:\WINDOWS\Downloaded Program Files\gp.inf not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0\ deleted successfully.
File http://rds.yahoo.com/S=96062883/K=stone+mo…e_mountains.jpg not found.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1\ deleted successfully.
File http://rds.yahoo.com/S=96062883/K=stone+mo…92/14099299.jpg not found.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\2\ deleted successfully.
File http://rds.yahoo.com/S=96062883/K=stone+mo…89/11438933.jpg not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{61125a10-b887-11db-9654-000cf1f9b53b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{61125a10-b887-11db-9654-000cf1f9b53b}\ not found.
File setupSNK.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c9c2f4e2-a45a-11dc-97cb-000cf1f9b53b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c9c2f4e2-a45a-11dc-97cb-000cf1f9b53b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c9c2f4e2-a45a-11dc-97cb-000cf1f9b53b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c9c2f4e2-a45a-11dc-97cb-000cf1f9b53b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\ not found.
File F:\LaunchU3.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session manager\\BootExecute:autocheck autochk * deleted successfully.
========== FILES ==========
C:\Program Files\popcorn Terms.html moved successfully.
ADS C:\Documents and Settings\LORI\My Documents\MOV00006.MPG:SummaryInformation deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Abigail
->Temp folder emptied: 24383500 bytes
->Temporary Internet Files folder emptied: 103165375 bytes
->Java cache emptied: 4705698 bytes
->FireFox cache emptied: 72527830 bytes
->Apple Safari cache emptied: 14336 bytes
->Flash cache emptied: 55066 bytes

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 274780 bytes

User: LORI
->Temp folder emptied: 691511559 bytes
->Temporary Internet Files folder emptied: 175988665 bytes
->Java cache emptied: 28439468 bytes
->FireFox cache emptied: 67840517 bytes
->Apple Safari cache emptied: 1648640 bytes
->Flash cache emptied: 4708913 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 118948820 bytes

User: New Folder

User: Owner

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 39097 bytes
%systemroot%\System32 .tmp files removed: 5552657 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 7724715474 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 91226494 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33726 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 8,694.00 mb

C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.22.3 log created on 03112011_184611

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…

Malwarebytes log:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6028

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

3/11/2011 7:31:30 PM
mbam-log-2011-03-11 (19-31-30).txt

Scan type: Quick scan
Objects scanned: 180080
Time elapsed: 8 minute(s), 55 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

ESET log:

ESETSmartInstaller@High as downloader log:
Can not open internetESETSmartInstaller@High as downloader log:
Can not open internet# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6425
# api_version=3.0.2
# EOSSerial=cc51c7697c45504592e1ec137beac766
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2011-03-12 01:08:46
# local_time=2011-03-11 08:08:46 (-0500, Eastern Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=3586 16764889 100 88 0 302283767 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=1216
# found=0
# cleaned=0
# scan_time=488
ESETSmartInstaller@High as downloader log:
all ok
esets_scanner_update returned -1 esets_gle=53251
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6425
# api_version=3.0.2
# EOSSerial=cc51c7697c45504592e1ec137beac766
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2011-03-12 03:41:11
# local_time=2011-03-11 10:41:11 (-0500, Eastern Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=3586 16764889 100 88 0 302284344 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=105504
# found=2
# cleaned=0
# scan_time=9057
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP776\A0124892.mof Win32/RogueAV.A trojan (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP777\A0124904.mof Win32/RogueAV.A trojan (unable to clean) 00000000000000000000000000000000 I

OTL log:

OTL logfile created on: 3/12/2011 5:24:56 PM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\LORI\Desktop\Don't Touch
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 144.00 Mb Available Physical Memory | 28.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 62.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 32.84 Gb Free Space | 44.11% Space Free | Partition Type: NTFS

Computer Name: ROSCOE | User Name: LORI | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/03/10 15:47:07 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\LORI\Desktop\Don't Touch\OTL.exe
PRC - [2011/03/09 21:23:18 | 000,912,344 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/03/04 14:08:20 | 000,099,720 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
PRC - [2009/09/29 09:17:50 | 000,013,088 | —- | M] (Intuit Inc.) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
PRC - [2008/06/17 08:35:43 | 001,251,720 | —- | M] () – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/02/11 16:22:14 | 000,191,848 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE
PRC - [2008/02/11 16:22:14 | 000,169,320 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE
PRC - [2008/02/11 16:22:14 | 000,053,096 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE
PRC - [2008/01/29 16:38:31 | 000,583,048 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
PRC - [2007/10/01 13:50:08 | 000,214,408 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
PRC - [2007/09/13 16:49:48 | 000,202,088 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\CCPROXY.EXE
PRC - [2007/07/12 12:43:50 | 000,226,904 | —- | M] (Macrovision Corporation) – C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe
PRC - [2007/05/23 11:13:38 | 000,139,888 | —- | M] (Symantec Corporation) – C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVAPSVC.EXE
PRC - [2006/12/15 12:36:28 | 000,750,720 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
PRC - [2006/01/19 11:06:18 | 000,102,400 | —- | M] (Musicmatch, Inc.) – C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe
PRC - [2006/01/19 11:06:16 | 000,416,768 | —- | M] (Musicmatch, Inc.) – C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
PRC - [2004/09/02 01:54:52 | 000,180,269 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2003/03/20 19:13:18 | 001,167,872 | —- | M] () – C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.exe
PRC - [2002/07/01 09:50:00 | 000,028,672 | —- | M] (Logitech Inc. ) – C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE
PRC - [2001/11/07 11:45:11 | 000,196,608 | —- | M] (HP) – C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb04.exe


========== Modules (SafeList) ==========

MOD - [2011/03/10 15:47:07 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\LORI\Desktop\Don't Touch\OTL.exe
MOD - [2010/08/23 11:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2008/02/11 16:22:14 | 000,379,240 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\CCL40.DLL
MOD - [2005/09/23 17:38:24 | 000,123,488 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\AntiSpam\asOEHook.dll
MOD - [2002/07/01 09:50:00 | 000,024,576 | —- | M] (Logitech Inc. ) – C:\Program Files\Logitech\MouseWare\system\LGMOUSHK.DLL


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – – (RoxLiveShare9)
SRV - [2010/03/04 14:08:20 | 002,106,760 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE – (LiveUpdate)
SRV - [2010/03/04 14:08:20 | 000,099,720 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe – (Automatic LiveUpdate Scheduler)
SRV - [2009/09/29 09:17:50 | 000,013,088 | —- | M] (Intuit Inc.) [Auto | Running] – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe – (IntuitUpdateService)
SRV - [2008/06/17 08:35:43 | 001,251,720 | —- | M] () [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe – (Symantec Core LC)
SRV - [2008/02/11 16:22:14 | 000,191,848 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe – (ccEvtMgr)
SRV - [2008/02/11 16:22:14 | 000,169,320 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe – (ccSetMgr)
SRV - [2008/01/29 16:38:31 | 000,583,048 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe – (LiveUpdate Notice Service)
SRV - [2007/10/01 13:50:08 | 000,214,408 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe – (SNDSrvc)
SRV - [2007/09/13 16:49:48 | 000,202,088 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\ccProxy.exe – (ccProxy)
SRV - [2007/05/23 11:13:38 | 000,139,888 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe – (navapsvc)
SRV - [2007/03/07 14:47:46 | 000,076,848 | —- | M] () [On_Demand | Stopped] – C:\Program Files\DellSupport\brkrsvc.exe – (DSBrokerService)
SRV - [2007/01/16 10:25:28 | 000,045,696 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Norton Internet Security\comHost.exe – (comHost)
SRV - [2006/12/15 12:36:28 | 000,750,720 | —- | M] (Symantec Corporation) [On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE – (NSCService)
SRV - [2006/02/03 17:29:36 | 000,072,328 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Norton Internet Security\ccPwdSvc.exe – (ccISPwdSvc)
SRV - [2005/12/19 19:41:56 | 000,198,416 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe – (SAVScan)
SRV - [2005/11/03 19:06:21 | 001,160,848 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe – (SPBBCSvc)
SRV - [2003/03/03 13:33:40 | 000,143,360 | —- | M] (Intel® Corporation) [On_Demand | Stopped] – C:\Program Files\Intel\NCS\Sync\NetSvc.exe – (NetSvc)


========== Driver Services (SafeList) ==========

DRV - [2010/09/15 13:07:08 | 000,270,712 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20110307.001\symidsco.sys – (SYMIDSCO)
DRV - [2010/02/16 08:30:28 | 001,324,720 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100506.005\NAVEX15.SYS – (NAVEX15)
DRV - [2010/02/16 08:30:28 | 000,371,248 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Common Files\Symantec Shared\eengine\eeCtrl.sys – (eeCtrl)
DRV - [2010/02/16 08:30:28 | 000,084,912 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100506.005\NAVENG.SYS – (NAVENG)
DRV - [2009/08/27 03:00:00 | 000,102,448 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Common Files\Symantec Shared\eengine\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2009/01/31 19:09:10 | 000,124,464 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.SYS – (SymEvent)
DRV - [2008/04/13 13:45:29 | 000,010,624 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\gameenum.sys – (gameenum)
DRV - [2007/12/08 09:24:14 | 000,016,694 | —- | M] (PalmSource, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\PalmUSBD.sys – (PalmUSBD)
DRV - [2007/10/01 13:49:26 | 000,189,320 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\SYMTDI.SYS – (SYMTDI)
DRV - [2007/10/01 13:49:20 | 000,023,944 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS – (SYMREDRV)
DRV - [2007/10/01 13:49:16 | 000,031,624 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMIDS.SYS – (SYMIDS)
DRV - [2007/10/01 13:49:10 | 000,028,040 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMNDIS.SYS – (SYMNDIS)
DRV - [2007/10/01 13:49:04 | 000,098,184 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMFW.SYS – (SYMFW)
DRV - [2007/10/01 13:48:56 | 000,012,680 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\Drivers\SYMDNS.SYS – (SYMDNS)
DRV - [2007/04/09 19:44:52 | 000,391,256 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys – (SPBBCDrv)
DRV - [2007/02/25 11:10:48 | 000,005,376 | –S- | M] (Gteko Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys – (dsunidrv)
DRV - [2006/10/05 15:07:28 | 000,004,736 | —- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys – (DSproct)
DRV - [2006/06/04 02:47:49 | 000,010,344 | —- | M] (Symantec Corporation) [Kernel | Auto | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\symlcbrd.sys – (symlcbrd)
DRV - [2005/12/19 19:41:58 | 000,054,968 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files\Norton Internet Security\Norton AntiVirus\Savrtpel.sys – (SAVRTPEL)
DRV - [2005/12/19 19:41:56 | 000,337,592 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files\Norton Internet Security\Norton AntiVirus\savrt.sys – (SAVRT)
DRV - [2005/03/30 06:57:25 | 000,008,413 | —- | M] (RealNetworks, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\mcstrm.sys – (MCSTRM)
DRV - [2004/08/04 00:29:49 | 000,019,455 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys – (iAimFP4)
DRV - [2004/08/04 00:29:47 | 000,012,063 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys – (iAimFP3)
DRV - [2004/08/04 00:29:45 | 000,023,615 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys – (iAimTV4)
DRV - [2004/08/04 00:29:43 | 000,033,599 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys – (iAimTV3)
DRV - [2004/08/04 00:29:42 | 000,019,551 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys – (iAimTV1)
DRV - [2004/08/04 00:29:41 | 000,029,311 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys – (iAimTV0)
DRV - [2004/08/04 00:29:37 | 000,012,415 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys – (iAimFP0)
DRV - [2004/08/04 00:29:37 | 000,012,127 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys – (iAimFP1)
DRV - [2004/08/04 00:29:37 | 000,011,775 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys – (iAimFP2)
DRV - [2004/08/04 00:29:36 | 000,161,020 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys – (i81x)
DRV - [2004/08/04 00:29:26 | 000,327,040 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtaa.sys – (ati2mtaa)
DRV - [2003/11/17 15:59:20 | 000,212,224 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWBS2.sys – (HSFHWBS2)
DRV - [2003/11/17 15:58:02 | 000,680,704 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys – (winachsf)
DRV - [2003/11/17 15:56:26 | 001,042,432 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys – (HSF_DP)
DRV - [2003/08/14 10:58:12 | 001,296,384 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\P16X.sys – (P16X) Creative SB Live! Series (WDM)
DRV - [2002/11/08 13:45:06 | 000,017,217 | —- | M] (Dell Computer Corporation) [Kernel | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys – (omci)
DRV - [2002/07/02 11:20:51 | 000,070,382 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\LMouFlt2.sys – (LMouFlt2)
DRV - [2002/07/02 11:20:51 | 000,040,508 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\LHIDUSB.SYS – (LHidUsb)
DRV - [2002/07/02 11:20:51 | 000,023,854 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\LHIDFLT2.SYS – (LHidFlt2)
DRV - [2002/07/02 11:20:51 | 000,006,030 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\LKbdFlt2.sys – (LKbdFlt2)
DRV - [2002/07/02 11:20:50 | 000,050,830 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\L8042Pr2.sys – (l8042pr2)
DRV - [2001/08/17 12:11:06 | 000,066,591 | —- | M] (3Com Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS – (EL90XBC)
DRV - [1999/12/17 01:00:00 | 000,006,752 | —- | M] (Creative Technology Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\SYSTEM32\PFMODNT.SYS – (PfModNT)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell4me.com/myway
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.se1.attbb.net
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = sas.se1.attbb.net:8000

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell4me.com/myway
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.se1.attbb.net
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = sas.se1.attbb.net:8000

IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-36674038-2814320496-617243875-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_adb…//www.yahoo.com
IE - HKU\S-1-5-21-36674038-2814320496-617243875-1007\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKU\S-1-5-21-36674038-2814320496-617243875-1007\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr=b1ie7
IE - HKU\S-1-5-21-36674038-2814320496-617243875-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
IE - HKU\S-1-5-21-36674038-2814320496-617243875-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-36674038-2814320496-617243875-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "http://www.comcast.net"
FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:4.0.2
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: [removed]:0.2.2
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.14.2

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/09 21:23:44 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/09 21:23:43 | 000,000,000 | —D | M]

[2009/02/24 20:54:58 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\LORI\Application Data\Mozilla\Extensions
[2011/03/11 19:13:54 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\LORI\Application Data\Mozilla\Firefox\Profiles\37sv5xp0.default\extensions
[2011/03/11 19:13:43 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\LORI\Application Data\Mozilla\Firefox\Profiles\37sv5xp0.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/09 21:41:20 | 000,000,000 | —D | M] (Flashblock) – C:\Documents and Settings\LORI\Application Data\Mozilla\Firefox\Profiles\37sv5xp0.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2011/03/11 19:13:44 | 000,000,000 | —D | M] (ReloadEvery) – C:\Documents and Settings\LORI\Application Data\Mozilla\Firefox\Profiles\37sv5xp0.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
[2011/03/09 21:41:21 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\LORI\Application Data\Mozilla\Firefox\Profiles\37sv5xp0.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011/03/09 21:41:20 | 000,000,000 | —D | M] (Adblock Plus Pop-up Addon) – C:\Documents and Settings\LORI\Application Data\Mozilla\Firefox\Profiles\37sv5xp0.default\extensions\[removed]
[2009/02/24 20:55:00 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2011/03/11 18:53:15 | 000,000,098 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (CNisExtBho Class) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll (Symantec Corporation)
O2 - BHO: (CNavExtBho Class) - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVSHEXT.DLL (Symantec Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Internet Security 2006) - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton AntiVirus) - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVSHEXT.DLL (Symantec Corporation)
O3 - HKU\S-1-5-21-36674038-2814320496-617243875-1007\..\Toolbar\WebBrowser: (Norton Internet Security 2006) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-36674038-2814320496-617243875-1007\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKU\S-1-5-21-36674038-2814320496-617243875-1007\..\Toolbar\WebBrowser: (Norton AntiVirus) - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVSHEXT.DLL (Symantec Corporation)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [diagent] C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [EM_EXEC] C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE (Logitech Inc. )
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb04.exe (HP)
O4 - HKLM..\Run: [MimBoot] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mimboot.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKU\S-1-5-21-36674038-2814320496-617243875-1007..\Run: [ISUSPM] C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe (Macrovision Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\palmOne\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe (Logitech)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg.exe ()
O4 - Startup: C:\Documents and Settings\LORI\Start Menu\Programs\Startup\palmOne Registration.lnk = C:\Program Files\palmOne\register.exe (palmOne/Leader Technologies)
O4 - Startup: C:\Documents and Settings\LORI\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = _ [binary data]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-36674038-2814320496-617243875-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Google Search - c:\program files\google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Backward Links - c:\program files\google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Similar Pages - c:\program files\google\GoogleToolbar1.dll (Google Inc.)
O8 - Extra context menu item: Translate into English - c:\program files\google\GoogleToolbar1.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc2.cab (Office Update Installation Engine)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} https://webdl.symantec.com/activex/symdlmgr.cab (Symantec Download Manager)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:3 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\LORI\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\LORI\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O29 - HKLM SecurityProviders - (xlibgfl254.dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/09/03 08:59:58 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{a87c8012-baed-11df-9b02-000cf1f9b53b}\Shell - "" = AutoRun
O33 - MountPoints2\{a87c8012-baed-11df-9b02-000cf1f9b53b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a87c8012-baed-11df-9b02-000cf1f9b53b}\Shell\AutoRun\command - "" = G:\LaunchU3.exe
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/03/11 19:53:11 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/03/11 18:46:11 | 000,000,000 | —D | C] – C:\_OTL
[2011/03/10 17:56:40 | 000,000,000 | —D | C] – C:\Documents and Settings\LORI\Desktop\Don't Touch
[2011/03/09 21:26:23 | 000,000,000 | —D | C] – C:\Documents and Settings\LORI\My Documents\Downloads
[2011/03/09 21:08:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/03/09 21:06:14 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/03/09 21:02:13 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2011/03/09 20:58:34 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/03/09 20:49:10 | 080,298,280 | —- | C] (Apple Inc.) – C:\Documents and Settings\LORI\Desktop\iTunesSetup.exe
[2011/03/09 20:30:11 | 000,000,000 | —D | C] – C:\ie-spyad_zo
[2011/03/09 20:25:37 | 000,000,000 | —D | C] – C:\ZonedOut
[2011/03/09 19:40:20 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\LORI\Desktop\HiJackThis.exe
[2011/03/06 08:40:52 | 000,000,000 | —D | C] – C:\Documents and Settings\LORI\Desktop\edgar file
[2011/03/06 07:32:28 | 000,000,000 | —D | C] – C:\Documents and Settings\LORI\Desktop\Jean
[2011/03/06 07:08:59 | 000,000,000 | —D | C] – C:\Documents and Settings\LORI\Desktop\james goldsby
[2011/02/26 22:47:11 | 000,000,000 | —D | C] – C:\Documents and Settings\LORI\My Documents\Abigail
[2011/02/17 18:24:27 | 000,000,000 | —D | C] – C:\Program Files\iPod(2)
[2011/02/17 18:14:44 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/02/15 22:01:45 | 000,249,325 | —- | C] (John El Self) – C:\Documents and Settings\LORI\My Documents\tswin - Copy.exe
[2004/07/09 13:32:18 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\A3d.dll

========== Files - Modified Within 30 Days ==========

[2011/03/12 15:25:41 | 000,000,420 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{0428D3CE-B20B-489A-8274-759974D2F6B6}.job
[2011/03/11 20:04:40 | 000,000,546 | —- | M] () – C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - LORI.job
[2011/03/11 19:43:22 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2011/03/11 19:38:30 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2011/03/11 19:38:29 | 535,875,584 | -HS- | M] () – C:\hiberfil.sys
[2011/03/11 18:53:15 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\ETC\Hosts
[2011/03/11 18:45:05 | 000,042,582 | —- | M] () – C:\Documents and Settings\LORI\Application Data\wklnhst.dat
[2011/03/09 21:08:30 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/03/09 21:02:19 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/03/09 20:51:16 | 080,298,280 | —- | M] (Apple Inc.) – C:\Documents and Settings\LORI\Desktop\iTunesSetup.exe
[2011/03/09 19:40:22 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\LORI\Desktop\HiJackThis.exe
[2011/03/09 03:02:29 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/03/08 16:53:17 | 000,002,483 | —- | M] () – C:\Documents and Settings\LORI\Desktop\Microsoft Word.lnk
[2011/03/06 14:50:08 | 000,000,376 | —- | M] () – C:\WINDOWS\ODBC.INI
[2011/03/06 14:17:31 | 000,000,395 | —- | M] () – C:\WINDOWS\hegames.ini
[2011/03/01 00:47:20 | 000,242,328 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/27 08:00:08 | 006,830,263 | —- | M] () – C:\Documents and Settings\LORI\My Documents\w_E_20101215_07.mp3
[2011/02/27 07:04:54 | 000,002,387 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TurboTax 2009.lnk
[2011/02/26 22:43:36 | 000,000,802 | —- | M] () – C:\Documents and Settings\LORI\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/02/26 21:51:49 | 000,000,751 | —- | M] () – C:\Documents and Settings\LORI\Start Menu\Programs\Startup\palmOne Registration.lnk
[2011/02/18 16:36:58 | 004,184,352 | —- | M] (Apple, Inc.) – C:\WINDOWS\System32\usbaaplrc.dll

========== Files Created - No Company Name ==========

[2011/03/09 21:08:30 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/03/09 21:02:18 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/03/06 17:24:51 | 535,875,584 | -HS- | C] () – C:\hiberfil.sys
[2011/02/28 22:47:48 | 000,151,768 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/02/27 08:00:03 | 006,830,263 | —- | C] () – C:\Documents and Settings\LORI\My Documents\w_E_20101215_07.mp3
[2011/02/19 00:18:48 | 002,035,589 | —- | C] () – C:\Documents and Settings\LORI\My Documents\Copy of TMS 2011-E.pdf
[2010/12/09 21:51:31 | 000,047,932 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/01/31 18:15:24 | 000,000,256 | —- | C] () – C:\WINDOWS\System32\pool.bin
[2007/12/08 08:19:37 | 000,000,000 | —- | C] () – C:\WINDOWS\QuickInstall.INI
[2007/08/09 18:53:19 | 000,000,395 | —- | C] () – C:\WINDOWS\hegames.ini
[2007/02/12 03:14:32 | 000,000,000 | —- | C] () – C:\Documents and Settings\LORI\Application Data\Install.dat
[2007/02/04 12:14:19 | 000,000,087 | —- | C] () – C:\WINDOWS\encore_launcher.ini
[2006/05/20 05:04:22 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/03/17 04:35:19 | 000,000,210 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2006/02/26 15:19:40 | 000,003,052 | —- | C] () – C:\WINDOWS\mozver.dat
[2005/06/09 04:22:37 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005/01/21 05:27:26 | 000,000,000 | —- | C] () – C:\Documents and Settings\LORI\Application Data\dm.ini
[2004/09/29 03:42:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/09/24 15:22:16 | 000,012,435 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2004/08/07 16:30:28 | 000,102,912 | —- | C] () – C:\Documents and Settings\LORI\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/07/20 05:39:16 | 000,042,582 | —- | C] () – C:\Documents and Settings\LORI\Application Data\wklnhst.dat
[2004/07/19 15:22:45 | 000,000,127 | —- | C] () – C:\Documents and Settings\LORI\Local Settings\Application Data\fusioncache.dat
[2004/07/19 07:19:07 | 000,081,920 | R— | C] () – C:\WINDOWS\bwUnin-6.1.4.36-8876480L.exe
[2004/07/19 07:18:09 | 000,096,768 | —- | C] () – C:\WINDOWS\System32\LGUICOM.DLL
[2004/07/09 13:49:57 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/07/09 13:43:09 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2004/07/09 13:37:01 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/07/09 13:34:05 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2004/07/09 13:34:03 | 000,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/07/09 13:32:31 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2004/07/09 13:32:31 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2004/07/09 13:32:18 | 000,047,616 | —- | C] () – C:\WINDOWS\System32\P16X.dll
[2004/07/09 13:32:18 | 000,002,572 | —- | C] () – C:\WINDOWS\MIXDEF.INI
[2004/07/09 13:32:18 | 000,002,158 | —- | C] () – C:\WINDOWS\System32\P16X.ini
[2004/07/09 13:32:18 | 000,000,064 | —- | C] () – C:\WINDOWS\P16x.ini
[2004/07/09 13:32:18 | 000,000,026 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2004/07/09 13:31:51 | 000,000,245 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2004/07/09 13:28:22 | 000,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/07/09 13:20:51 | 000,028,768 | —- | C] () – C:\WINDOWS\System32\javaw.exe
[2004/07/09 13:20:51 | 000,024,670 | —- | C] () – C:\WINDOWS\System32\java.exe
[2004/07/09 13:13:06 | 000,002,048 | –S- | C] () – C:\WINDOWS\BOOTSTAT.DAT
[2004/07/09 13:10:38 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/07/09 13:10:32 | 000,463,628 | —- | C] () – C:\WINDOWS\System32\PERFH009.DAT
[2004/07/09 13:10:32 | 000,080,654 | —- | C] () – C:\WINDOWS\System32\PERFC009.DAT
[2004/07/09 13:10:21 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/07/09 12:50:14 | 000,000,550 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/03/26 16:59:22 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/09/03 09:05:08 | 000,242,328 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2002/09/03 08:59:14 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2002/09/03 08:56:30 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2002/09/03 08:31:46 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.BIN
[2002/09/03 08:31:44 | 000,004,594 | —- | C] () – C:\WINDOWS\System32\OEMBIOS.DAT
[2002/08/29 05:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\MLANG.DAT
[2002/08/29 05:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\PERFI009.DAT
[2002/08/29 05:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\DSSEC.DAT
[2002/08/29 05:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\MIB.BIN
[2002/08/29 05:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\PERFD009.DAT
[2002/08/29 05:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2002/08/29 05:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\NOISE.DAT
[1980/01/01 00:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll

< End of report >


So, the fresh OTL log didn't generate an 'extras' file this time around. It also didn't overwrite the old one. Was it supposed to?
Also, I note that the ESET log found a couple more trojans, it seems.
Otherwise, the problem we were having has been fixed. I can access google and other search engines now. If there are any noticable symptoms from the other trojans, I'd have to say that no one would notice them, as there haven't been popups or unders (more than normal) or randomly opening/closing programs or any other related things, and any general slowness is probably due to the age, poor maintenance and limited hardware of the computer more than anything else.

Please forgive the slowness in response. The first two scans took so long that I had to leave and come back for the third. I hope this won't cause a problem.

So, the fresh OTL log didn't generate an 'extras' file this time around. It also didn't overwrite the old one. Was it supposed to?
Also, I note that the ESET log found a couple more trojans, it seems.
Otherwise, the problem we were having has been fixed. I can access google and other search engines now. If there are any noticable symptoms from the other trojans, I'd have to say that no one would notice them, as there haven't been popups or unders (more than normal) or randomly opening/closing programs or any other related things, and any general slowness is probably due to the age, poor maintenance and limited hardware of the computer more than anything else.

Please forgive the slowness in response. The first two scans took so long that I had to leave and come back for the third. I hope this won't cause a problem.



By default, OTL creates the extras file on the first run only.

The 2 items in the ESET log are contained in System Restore Points. We will create a new, clean System Restore Point and delete the old ones after this next fix.

Yes, these scans can take a long time to complete. Your response time was fine. :thumbup:

================================

I missed one item that we should remove with another OTL script.

Run OTL Script

We need to run an OTL Fix

  • Double-click OTL.exe to start the program.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word Code
    :OTL
    O29 - HKLM SecurityProviders - (xlibgfl254.dll) - File not found
  • Then click the Run Fix button at the top.
  • Click [external image: Posted Image].
  • OTL may ask to reboot the machine. Please do so if asked.
  • The report should appear in Notepad after the reboot.Copy and Paste that report in your next reply.
OTL Fix:

========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders:xlibgfl254.dll deleted successfully.

OTL by OldTimer - Version 3.2.22.3 log created on 03152011_183933


Is that it for this time around?
We just have a little cleaning up to do.

This is my general post for when your logs show no more signs of malware ;)- Please let me know if you still are having problems with your computer and what these problems are

  • CleanUp! with OTL
    • Double click OTL.exe to launch the program.
    • Click on the CleanUp! button.
    • OTL will download a list from the Internet, if your firewall or other defensive programmes alerts you, allow it access.
    • Select Yes when the "Begin cleanup Process?" prompt appears.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • When finished exit out of OTL
    • The tool will delete itself once it finishes, if not delete it by yourself.

    Protection Programs
    Don't forget to re-enable any protection programs we disabled during your fix.

    General Security and Computer Health
    Below are some steps to follow in order to dramatically lower the chances of reinfection. You may have already implemented some of the steps below, however you should follow any steps that you have not already implemented.


  • Clear Infected System Restore Points
    For Windows XP:
    • Click start–>Run and type cleanmgr into the run box and then click "OK".
    • Select the drive where Windows is installed (if you have more than one drive) and click "OK".
    • When the scan completes, check/uncheck desired boxes.
    • Next, please click the More Options tab at the top.
    • Click the "Clean up…" button under the System Restore section at the bottom.
    • Answer Yes to the question "Are you sure you want to delete all but the most recent restore point?", click OK and answer Yes again.
    • The disk clean up utility will remove the selected items. When it completes, please restart the computer to properly record the changes made to the hard disk.

    For Windows Vista and Windows 7:
    • Click start, type Disk Cleanup in the search box
    • Right-Click Disk Cleanup and select "Run as Administrator" and accept the UAC elevation prompt.
    • Select the drive where Windows is installed (if you have more than one drive) and click "OK".
    • When the scan completes, check/uncheck desired boxes.
    • Next, please click the More Options tab at the top.
    • Click the "Clean up…" button under the "System Restore and Shadow Copies" section at the bottom.
    • Click Delete in response to the question "Are you sure you want to delete all but the most recent restore point?", click OK and answer Yes again.
    • The disk clean up utility will remove the selected items. When it completes, please restart the computer to properly record the changes made to the hard disk.

  • Set correct settings for files
    • Click Start > My Computer > Tools menu (at top of page) > Folder Options > View tab.
    • Under Hidden files and folders if necessary select Do not show hidden files and folders.
    • If unchecked please check Hide protected operating system files (Recommended)
    • If necessary check Display content of system folders
    • If necessary Uncheck Hide file extensions for known file types.
    • Click OK

  • Make sure that you keep your antivirus updated
    New viruses come out every minute, so it is essential that you have the latest signatures for your antivirus program to provide you with the best possible protection from malicious software.
    Note: You should only have one antivirus installed at a time. Having more than one antivirus program installed at once is likely to cause conflicts and may well decrease your overall protection as well as impairing the performance of your PC.

  • Security Updates for Windows, Internet Explorer & Microsoft Office
    Whenever a security problem in its software is found, Microsoft will usually create a patch so that after the patch is installed, attackers can't use the vulnerability to install malicious software on your PC. Keeping up with these patches will help to prevent malicious software being installed on your PC. Ensure you are registered for Windows updates via Start > right-click on My Computer > Properties > Automatic Updates tab or visit the Microsoft Update site on a regular basis.
    Note: The update process uses ActiveX, so you will need to use internet explorer for it and allow the ActiveX control to install.

  • Update Non-Microsoft Programs
    Microsoft isn't the only company whose products can contain security vulnerabilities. To check whether other programs running on your PC are in need of an update, you can use the Secunia Software Inspector - I suggest that you run it at least once a month.


Recommended Programs

I would recommend the download and installation of some or all of the following programs (if not already present), and the updating of them on a regular basis.

  • WinPatrol
    As a robust security monitor, WinPatrol will alert you to hijackings, malware attacks and critical changes made to your computer without your permission. WinPatrol takes snapshot of your critical system resources and alerts you to any changes that may occur without your knowledge. For more information, please visit HERE.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites - green to go, yellow for caution and red to stop, helping you avoid the dangerous sites. WOT has an addon available for both Firefox and IE.

  • Malwarebytes' Anti-Malware or SuperAntiSpyware
    These are anti-malware applications that can thoroughly remove even the most advanced malware. They include a number of features, including a built in protection monitor that blocks malicious processes before they even start.
    You can download Malwarebytes' Anti-Malware from HERE. You can find a tutorial HERE.
    You can download SuperAntiSpyware from HERE.

  • Hosts File
    For added protection you may also like to add a host file. A simple explanation of what a Hosts file does is HERE and for more information regarding host files read HERE.

    Be sure to disable the service "DNS Client" FIRST to allow the use of large HOSTS files without slowdowns.
    If this isn't done first, the next reboot may take a VERY LONG TIME.
    This is how to do it. First be sure you are signed in as a user with administrative privileges:

    Stop and Disable the DNS Client Service
    Go to Start, Run and type Services.msc and click OK.
    Under the Extended Tab, Scroll down and find this service.
    DNS Client
    Right-Click on the DNS Client Service. Choose Properties
    Select the General tab. Click on the Stop button.
    Click the Arrow-down tab on the right-hand side at the Start-up Type box.
    From the drop-down menu, click on Manual
    Click the Apply tab, then click OK


  • Use an alternative Internet Browser
    Many of the exploits are directed to users of Internet Explorer. Try using a different browser instead:
    Firefox
    Opera


Finally I am trying to make one point very clear. It is absolutely essential to keep all of your security programs up to date.

Also please read this great article How to prevent Malware by miekiemoes.

I'd be grateful if you could reply to this post so that I know you have read it and, if you've no other questions, the thread can be closed.
Everything seems to be in order. I'll implement some of the stuff you recommended. Unfortunately, trying to get my family to use a diff browser has been like pulling teeth. I really appreciate all your help. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI