This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus or spyware infection

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi racin9m, A large part of the OTL.txt is missing. Please post it in it's entirety. Please let me know of any symptoms you are having. Thanks
OTL logfile created on: 3/19/2011 3:36:50 PM - Run 4
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Owner\My Documents
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 53.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.97 Gb Total Space | 101.46 Gb Free Space | 69.99% Space Free | Partition Type: NTFS
Drive D: | 4.07 Gb Total Space | 0.71 Gb Free Space | 17.53% Space Free | Partition Type: FAT32
Drive N: | 3.63 Gb Total Space | 3.30 Gb Free Space | 90.97% Space Free | Partition Type: FAT32

Computer Name: CHRISMARK | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\My Documents\iexplore.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\MyFunCards_3v\bar\1.bin\3vmedint.exe (MyFunCards)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe (Eastman Kodak Company)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ArcSoft Inc.)
PRC - C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Philips\Philips Device Manager\bin\DeviceManager.exe (Koninklijke Philips Electronics N.V.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\system32\ps2.EXE (Hewlett-Packard Company)
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()
PRC - C:\Program Files\HP\HP Software Update\hpwuSchd.exe (Hewlett-Packard)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\My Documents\iexplore.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Comcast\Desktop Doctor\bin\sprthook.dll (SupportSoft, Inc.)


========== Win32 Services (SafeList) ==========

SRV - (Symantec Core LC) – File not found
SRV - (HidServ) – File not found
SRV - (HauppaugeTVServer) – File not found
SRV - (getPlusHelper) getPlus® – File not found
SRV - (AppMgmt) – File not found
SRV - (MyFunCards_3vService) – C:\Program Files\MyFunCards_3v\bar\1.bin\3vbarsvc.exe (MyFunCards)
SRV - (Kodak AiO Network Discovery Service) – C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe (Eastman Kodak Company)
SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (vpnagent) – C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.)
SRV - (sprtsvc_ddoctorv2) SupportSoft Sprocket Service (ddoctorv2) – C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (vpnva) – C:\WINDOWS\system32\drivers\vpnva.sys (Cisco Systems, Inc.)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (MPE) – C:\WINDOWS\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (USB28xxBGA) – C:\WINDOWS\system32\drivers\emBDA.sys (eMPIA Technology, Inc.)
DRV - (USB28xxOEM) – C:\WINDOWS\system32\drivers\emOEM.sys (eMPIA Technology, Inc.)
DRV - (hcwAVD2) – C:\WINDOWS\system32\drivers\HCWUSB2AV.sys (Conexant Systems, Inc.)
DRV - (symlcbrd) – C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (SQTECH905C) – C:\WINDOWS\system32\drivers\Capt905c.sys (Service & Quality Technology.)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (AFS2K) – C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (WinDriver6) – C:\WINDOWS\system32\drivers\windrvr6.sys (Jungo)
DRV - (viaagp1) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\R8139n51.sys (Realtek Semiconductor Corporation )
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.startnow.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..extensions.enabledItems: {B728AB94-9BC7-49b7-B76A-422BB31B2FD0}:2.0.0.8
FF - prefs.js..extensions.enabledItems: 3vffxtbr@MyFunCards_3v.com:1.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/11/24 19:12:40 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B728AB94-9BC7-49b7-B76A-422BB31B2FD0}: C:\Program Files\ArcSoft\Media Converter for Philips\Internet Video Downloader\Plugin_FireFox [2010/06/05 09:10:39 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\3vffxtbr@MyFunCards_3v.com: C:\Program Files\MyFunCards_3v\bar\1.bin [2011/03/18 08:10:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/11 18:35:39 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/07 14:12:28 | 000,000,000 | —D | M]

[2010/08/14 06:50:25 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2009/04/05 21:19:58 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\[removed]
[2011/03/18 15:50:10 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\av6uxv5n.default\extensions
[2010/08/14 07:18:11 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\av6uxv5n.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/18 15:50:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/02/04 00:33:04 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010/06/05 09:10:39 | 000,000,000 | —D | M] (Internet Video Downloader) – C:\PROGRAM FILES\ARCSOFT\MEDIA CONVERTER FOR PHILIPS\INTERNET VIDEO DOWNLOADER\PLUGIN_FIREFOX
[2010/11/24 19:12:40 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG9\FIREFOX
[2009/03/15 21:20:02 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/03/18 08:10:41 | 000,000,000 | —D | M] (MyFunCards) – C:\PROGRAM FILES\MYFUNCARDS_3V\BAR\1.BIN
[2006/08/16 10:34:19 | 000,142,848 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npcpbrk7.dll
[2010/11/12 19:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2007/12/17 13:16:14 | 000,065,536 | —- | M] ( ) – C:\Program Files\Mozilla Firefox\plugins\npkimi.dll
[2005/12/05 23:31:00 | 000,114,688 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
[2006/09/26 10:17:26 | 000,319,488 | —- | M] ( ) – C:\Program Files\Mozilla Firefox\plugins\npsnapfish.dll

O1 HOSTS File: ([2011/02/24 00:48:41 | 000,000,334 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Comcast Toolbar) - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\Program Files\ComcastToolbar\comcasttoolbar.dll (Comcast Cable Communications. )
O2 - BHO: (no name) - {71BEEABD-D990-491f-8626-28A7AF43C382} - No CLSID value found.
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Comcast Toolbar) - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\Program Files\ComcastToolbar\comcasttoolbar.dll (Comcast Cable Communications. )
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (FrostWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (no name) - {E5E2F8B2-79A4-495C-8581-90BA2C845CC2} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {E5E2F8B2-79A4-495C-8581-90BA2C845CC2} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Comcast Toolbar) - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\Program Files\ComcastToolbar\comcasttoolbar.dll (Comcast Cable Communications. )
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AlcWzrd] C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Conime] C:\WINDOWS\system32\conime.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ddoctorv2] C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\WINDOWS\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd.exe (Hewlett-Packard)
O4 - HKLM..\Run: [OM2_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe (OLYMPUS IMAGING CORP.)
O4 - HKLM..\Run: [PhilipsDM] C:\Program Files\Philips\Philips Device Manager\Bin\DeviceManager.exe (Koninklijke Philips Electronics N.V.)
O4 - HKLM..\Run: [PS2] C:\WINDOWS\system32\ps2.EXE (Hewlett-Packard Company)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateManager] c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKCU..\Run: [OM2_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe (OLYMPUS IMAGING CORP.)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: SusCom Toolbar - {E5E2F8B2-79A4-495C-8581-90BA2C845CC2} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : SusCom Toolbar - {E5E2F8B2-79A4-495C-8581-90BA2C845CC2} - Reg Error: Key error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: mhyork.org ([portal] https in Local intranet)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo1.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {55963676-2F5E-4BAF-AC28-CF26AA587566} https://portal.mhyork.org/CACHE/stc/5/binaries/vpnweb.cab (Cisco AnyConnect VPN Client Web Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-FFFF-ABCDEFFEDCBA} http://mhykronos01/wfcstatic/plugins/jre-1…dows-i586-p.exe (Java Plug-in)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\OLYMPUS\OLYMPUS Master2\OLYMPUS Master 2.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\OLYMPUS\OLYMPUS Master2\OLYMPUS Master 2.bmp
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/03/28 16:14:56 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/27 14:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2009/03/30 18:32:00 | 000,000,590 | —- | M] () - N:\autorun.inf – [ FAT32 ]
O33 - MountPoints2\M\Shell - "" = AutoRun
O33 - MountPoints2\M\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\M\Shell\AutoRun\command - "" = M:\setup.exe
O33 - MountPoints2\M\Shell\install\command - "" = M:\setup.exe
O33 - MountPoints2\N\Shell - "" = AutoRun
O33 - MountPoints2\N\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\N\Shell\AutoRun\command - "" = N:\setup.exe
O33 - MountPoints2\N\Shell\install\command - "" = N:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/03/19 15:07:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\New Folder
[2011/03/19 14:26:09 | 000,000,000 | —D | C] – C:\_OTL
[2011/03/19 07:01:30 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\My Documents\iexplore.exe
[2011/03/19 00:05:34 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Owner\My Documents\HiJackThis.exe
[2011/03/18 22:55:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\oCmEjEl01805
[2011/03/18 22:54:31 | 000,119,808 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\Iruqya.exe
[2011/03/15 17:57:31 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/03/14 16:36:33 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Owner\Recent
[2011/03/06 21:02:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\magicJack
[2011/03/06 12:39:31 | 000,000,000 | —D | C] – C:\Program Files\GraphPad
[2011/02/20 11:39:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\FrostWire
[2011/02/20 11:39:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\FrostWire

========== Files - Modified Within 30 Days ==========

[2011/03/19 15:01:00 | 000,000,238 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/03/19 14:49:53 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\prvlcl.dat
[2011/03/19 14:32:43 | 072,881,486 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/03/19 14:30:11 | 000,001,038 | —- | M] () – C:\Documents and Settings\Owner\Desktop\magicJack.lnk
[2011/03/19 14:29:02 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/03/19 14:28:46 | 000,000,435 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.ics
[2011/03/19 14:28:46 | 000,000,188 | —- | M] () – C:\WINDOWS\System\hpsysdrv.DAT
[2011/03/19 14:28:15 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/03/19 14:28:12 | 1601,556,480 | -HS- | M] () – C:\hiberfil.sys
[2011/03/19 07:07:19 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\My Documents\iexplore.exe
[2011/03/19 00:05:34 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\My Documents\HiJackThis.exe
[2011/03/18 22:54:15 | 000,119,808 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\Iruqya.exe
[2011/03/14 21:55:31 | 000,511,224 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/03/14 21:55:31 | 000,093,042 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/03/14 13:06:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/03/08 21:49:07 | 000,001,828 | -H– | M] () – C:\Documents and Settings\Owner\My Documents\Default.rdp
[2011/03/06 12:43:51 | 000,000,016 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\obtf504
[2011/03/06 12:43:49 | 000,001,681 | —- | M] () – C:\Documents and Settings\All Users\Desktop\GraphPad Prism 5 Demo.lnk
[2011/02/24 00:48:41 | 000,000,334 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts

========== Files Created - No Company Name ==========

[2011/03/12 07:30:41 | 000,001,044 | —- | C] () – C:\Documents and Settings\Owner\Start Menu\Programs\magicJack.lnk
[2011/03/06 12:39:42 | 000,001,681 | —- | C] () – C:\Documents and Settings\All Users\Desktop\GraphPad Prism 5 Demo.lnk
[2011/01/30 23:07:40 | 000,000,016 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\obtf504
[2010/09/22 19:12:12 | 000,000,016 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\obtf503
[2010/08/29 09:45:14 | 000,180,984 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/05/09 07:55:44 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\prvlcl.dat
[2010/04/03 20:52:49 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2010/01/30 12:02:30 | 000,031,216 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/10/13 17:35:36 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009/04/25 12:51:03 | 000,076,408 | —- | C] () – C:\WINDOWS\TrueInstall.exe
[2008/09/20 09:52:57 | 000,164,352 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2008/09/20 09:52:57 | 000,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2008/09/20 09:52:53 | 000,755,027 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/09/20 09:52:53 | 000,159,839 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/09/20 09:52:52 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/09/20 09:52:50 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2008/09/07 06:48:08 | 000,000,140 | —- | C] () – C:\WINDOWS\RealFlight.INI
[2008/07/10 17:47:20 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2008/02/26 21:03:30 | 000,006,656 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/26 17:26:43 | 000,000,248 | —- | C] () – C:\WINDOWS\HCWBlast.ini
[2008/02/26 17:25:49 | 000,032,829 | —- | C] () – C:\WINDOWS\Irremote.ini
[2008/02/26 17:25:37 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\dmcrypto.dll
[2008/02/26 17:24:52 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\hcwChDB.dll
[2008/02/26 17:24:09 | 000,003,126 | —- | C] () – C:\WINDOWS\HCWPNP.INI
[2008/02/26 17:19:04 | 000,066,048 | R— | C] () – C:\WINDOWS\System32\hcwxds.dll
[2008/02/19 02:33:34 | 000,446,352 | —- | C] () – C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2008/02/14 23:05:02 | 001,228,854 | —- | C] () – C:\Documents and Settings\All Users\Application Data\OrbError.bmp
[2008/02/02 19:19:53 | 000,000,119 | —- | C] () – C:\WINDOWS\ka.ini
[2007/06/01 01:33:06 | 000,000,028 | —- | C] () – C:\WINDOWS\MotionDVSTUDIO.INI
[2006/11/17 23:10:38 | 000,001,310 | —- | C] () – C:\WINDOWS\checkip.dat
[2006/10/18 07:23:14 | 000,033,280 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/08/16 10:34:21 | 000,000,004 | —- | C] () – C:\WINDOWS\uccspecb.sys
[2006/06/11 08:33:33 | 000,000,035 | —- | C] () – C:\WINDOWS\A4W.INI
[2006/05/03 19:12:36 | 000,000,000 | —- | C] () – C:\WINDOWS\webica.ini
[2006/04/30 07:19:18 | 000,000,953 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/04/29 20:38:55 | 000,000,030 | —- | C] () – C:\WINDOWS\trappro.INI
[2006/04/28 22:36:04 | 000,000,373 | —- | C] () – C:\WINDOWS\pdhpro.ini
[2006/03/19 10:33:07 | 000,000,068 | —- | C] () – C:\WINDOWS\TONKA_SR.INI
[2006/02/19 12:34:43 | 000,107,134 | —- | C] () – C:\WINDOWS\UninstallFirefox.exe
[2006/02/10 21:20:48 | 000,002,560 | —- | C] () – C:\WINDOWS\_MSRSTRT.EXE
[2006/02/04 18:01:45 | 000,000,006 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/01/28 11:29:08 | 000,000,205 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2005/09/17 09:28:58 | 000,011,092 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/08/19 17:38:13 | 000,006,865 | —- | C] () – C:\WINDOWS\mozver.dat
[2005/05/08 09:57:52 | 000,000,000 | —- | C] () – C:\WINDOWS\MSDraw.ini
[2005/03/29 06:25:13 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2005/02/18 16:23:36 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\DRMServer.exe
[2005/01/31 09:01:06 | 000,000,085 | —- | C] () – C:\WINDOWS\upst.ini
[2005/01/31 09:01:06 | 000,000,029 | —- | C] () – C:\WINDOWS\atid.ini
[2005/01/30 21:48:15 | 000,000,048 | —- | C] () – C:\WINDOWS\PerWin.ini
[2004/10/24 18:13:00 | 000,000,258 | —- | C] () – C:\WINDOWS\QTW.INI
[2004/08/05 18:07:43 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2004/08/05 17:51:25 | 000,038,867 | —- | C] () – C:\WINDOWS\hpomdl03.dat
[2004/08/05 17:51:25 | 000,029,258 | —- | C] () – C:\WINDOWS\hpoins03.dat
[2004/07/06 20:59:30 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2004/07/06 20:59:30 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2004/07/06 20:59:30 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2004/07/06 20:59:30 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2004/07/06 20:59:30 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2004/07/06 20:59:30 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2004/06/10 17:22:31 | 000,156,160 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2004/06/09 09:23:03 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/06/09 09:23:02 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/06/09 09:22:05 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/06/09 09:21:47 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/06/09 09:02:21 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/06/09 09:02:21 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/06/09 09:02:18 | 000,004,490 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/06/09 09:02:15 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/06/09 09:02:10 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/05/13 21:18:09 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/05/13 01:32:08 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\JAWTAccessBridge.dll
[2004/05/13 01:31:34 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2004/05/13 01:31:34 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2004/05/13 01:29:27 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2004/05/13 01:25:50 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2004/05/13 01:13:00 | 000,090,112 | R— | C] () – C:\WINDOWS\bwUnin-6.2.3.66L.exe
[2004/05/13 01:08:52 | 000,027,755 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2004/05/13 01:08:10 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2004/05/13 00:55:06 | 000,000,483 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/05/13 00:42:02 | 000,000,907 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2004/05/12 23:49:06 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/05/12 23:40:55 | 000,001,040 | —- | C] () – C:\WINDOWS\System32\drivers\alcxinit.dat
[2004/05/12 23:06:32 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/05/12 22:55:34 | 000,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2004/05/12 22:55:34 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2004/05/12 22:55:06 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2004/05/12 22:27:01 | 000,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/05/12 22:24:47 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/05/12 22:17:53 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/05/12 22:05:29 | 000,000,553 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2004/05/12 22:04:30 | 000,511,224 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/05/12 22:04:30 | 000,093,042 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/05/12 15:11:21 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/05/12 15:10:15 | 000,169,896 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/03/31 08:04:00 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/01/05 03:27:36 | 000,565,248 | —- | C] () – C:\WINDOWS\System32\hpotscl.dll
[2003/05/31 20:43:00 | 000,005,632 | —- | C] () – C:\WINDOWS\TrueProcess.exe
[2003/05/30 19:00:02 | 001,287,680 | —- | C] () – C:\WINDOWS\System32\quartz(2).dll
[2002/11/14 22:58:04 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2002/11/14 22:58:04 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2002/11/14 22:58:02 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2002/11/14 22:58:02 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2002/11/14 22:58:02 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2001/09/06 18:42:54 | 000,000,036 | —- | C] () – C:\WINDOWS\A3W.ini
[1999/07/29 04:27:10 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\iyvu9_32.dll
[1999/01/22 14:46:56 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

========== Custom Scans ==========


< C:\Documents and Settings\All Users\Application Data\oCmEjEl01805\*.* /s >
[2011/03/19 14:22:56 | 000,000,098 | —- | M] () – C:\Documents and Settings\All Users\Application Data\oCmEjEl01805\oCmEjEl01805

========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34

< End of report >
Hi racin9m,

How is the computer? Is your background now normal?

You have some very old vulnerable java installed. Please click your start button > Control Panel > Add/remove programs and uninstall

Java 2 Runtime Environment, SE v1.4.2_03
J2SE Runtime Environment 5.0 Update 3
J2SE Runtime Environment 5.0 Update 11
Java™ 6 Update 7
LiveReg (Symantec Corporation)
MyFunCards
Symantec KB-DocID:2003093015493306


Do not uninstall Java™ 6 Update 23


Still in Control panel.
  • Locate the Java icon (it looks like a coffee cup)
  • double click it to open it
  • click the Update tab
  • Click update now

Next

Download the Norton Removal Tool from HERE and save it to your desktop.


Next Double click on Norton_Removal_Tool.exe to run the tool.

Follow the on-screen instructions.
Your computer may be restarted more than once, and you may be asked to repeat some steps after the computer restarts.

Next

Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Files
C:\Documents and Settings\All Users\Application Data\oCmEjEl01805

:Commands
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log .



You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with
  • OTL fix log
  • MBAM log
  • computer status
Thanks
All processes killed ========== SERVICES/DRIVERS ========== ========== FILES ========== C:\Documents and Settings\All Users\Application Data\oCmEjEl01805 folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: admin ->Temp folder emptied: 30953217 bytes ->Temporary Internet Files folder emptied: 1459267 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 15177855 bytes ->Flash cache emptied: 456 bytes User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: All Users User: alyssa ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Application Data User: Chrissy User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Guest ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: KIDS !!!! User: LocalService ->Temp folder emptied: 66016 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Owner ->Temp folder emptied: 135094 bytes ->Temporary Internet Files folder emptied: 59209 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 40025917 bytes ->Apple Safari cache emptied: 0 bytes ->Flash cache emptied: 1075 bytes User: Phone ->Temp folder emptied: 12807 bytes ->Temporary Internet Files folder emptied: 433922 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 664 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 126054 bytes Total Files Cleaned = 84.00 mb OTL by OldTimer - Version 3.2.22.3 log created on 03202011_071848 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6110 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 3/20/2011 7:37:37 AM mbam-log-2011-03-20 (07-37-37).txt Scan type: Quick scan Objects scanned: 235107 Time elapsed: 9 minute(s), 59 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 4 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 4 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{00572d69-36f3-4459-a76e-b681abc2c799} (Adware.MyFunCards) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\A9YA3MI1CF (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\NtWqIVLZEWZU (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\program files\myfuncards_3vei (Adware.MyFunCards) -> Quarantined and deleted successfully. c:\program files\myfuncards_3vei\Installr (Adware.MyFunCards) -> Quarantined and deleted successfully. c:\program files\myfuncards_3vei\Installr\1.bin (Adware.MyFunCards) -> Quarantined and deleted successfully. c:\program files\myfuncards_3vei\Installr\1.bin\chrome (Adware.MyFunCards) -> Quarantined and deleted successfully. Files Infected: c:\documents and settings\Chrissy\my documents\downloads\myfuncards.exe (Adware.MyFunCards) -> Quarantined and deleted successfully. c:\documents and settings\Chrissy\my documents\downloads\myfuncardssetup2.3.67.1.zufox000.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\WINDOWS\Iruqya.exe (Trojan.Downloader) -> Quarantined and deleted successfully. everything seems to be working fine. Thank you.
Hi racin9m,

One more scan to see if there is anything lurking.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • Re-enable your Antivirus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. or C:\Program Files\ESET\log.txtWe will need this later.

After the ESET scan,

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt.

Please post back with
  • ESET log
  • OTL.txt
Thanks
ESET C:\hp\recovery\wizard\fscommand\AppRecoveryLink_ret.exe probably a variant of Win32/Spy.Agent.BMWSIKB trojan C:\hp\recovery\wizard\fscommand\CDLogic_ret.exe probably a variant of Win32/Spy.Agent.BMWSIKB trojan C:\hp\recovery\wizard\fscommand\CreatorLink_ret.exe probably a variant of Win32/Spy.Agent.BMWSIKB trojan C:\hp\recovery\wizard\fscommand\RestoreLink_ret.exe probably a variant of Win32/Spy.Agent.BMWSIKB trojan C:\hp\recovery\wizard\fscommand\RTCDLink_ret.exe probably a variant of Win32/Spy.Agent.BMWSIKB trojan C:\hp\recovery\wizard\fscommand\RunLink_ret.exe probably a variant of Win32/Spy.Agent.BMWSIKB trojan C:\hp\recovery\wizard\fscommand\SysRecoveryLink_ret.exe probably a variant of Win32/Spy.Agent.BMWSIKB trojan C:\hp\recovery\wizard\fscommand\WizardLink_ret.exe probably a variant of Win32/Spy.Agent.BMWSIKB trojan
OTL logfile created on: 3/22/2011 7:27:25 PM - Run 5
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Owner\My Documents
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 52.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.97 Gb Total Space | 101.18 Gb Free Space | 69.79% Space Free | Partition Type: NTFS
Drive D: | 4.07 Gb Total Space | 0.71 Gb Free Space | 17.53% Space Free | Partition Type: FAT32

Computer Name: CHRISMARK | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\My Documents\iexplore.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe (Eastman Kodak Company)
PRC - C:\Program Files\McAfee Security Scan\2.1.121\SSScheduler.exe (McAfee, Inc.)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ArcSoft Inc.)
PRC - C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Philips\Philips Device Manager\bin\DeviceManager.exe (Koninklijke Philips Electronics N.V.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\system32\ps2.EXE (Hewlett-Packard Company)
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()
PRC - C:\Program Files\HP\HP Software Update\hpwuSchd.exe (Hewlett-Packard)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\My Documents\iexplore.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Comcast\Desktop Doctor\bin\sprthook.dll (SupportSoft, Inc.)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (HauppaugeTVServer) – File not found
SRV - (getPlusHelper) getPlus® – File not found
SRV - (AppMgmt) – File not found
SRV - (Kodak AiO Network Discovery Service) – C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe (Eastman Kodak Company)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.1.121\McCHSvc.exe (McAfee, Inc.)
SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (vpnagent) – C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.)
SRV - (sprtsvc_ddoctorv2) SupportSoft Sprocket Service (ddoctorv2) – C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (vpnva) – C:\WINDOWS\system32\drivers\vpnva.sys (Cisco Systems, Inc.)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (MPE) – C:\WINDOWS\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (USB28xxBGA) – C:\WINDOWS\system32\drivers\emBDA.sys (eMPIA Technology, Inc.)
DRV - (USB28xxOEM) – C:\WINDOWS\system32\drivers\emOEM.sys (eMPIA Technology, Inc.)
DRV - (hcwAVD2) – C:\WINDOWS\system32\drivers\HCWUSB2AV.sys (Conexant Systems, Inc.)
DRV - (SQTECH905C) – C:\WINDOWS\system32\drivers\Capt905c.sys (Service & Quality Technology.)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (AFS2K) – C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (WinDriver6) – C:\WINDOWS\system32\drivers\windrvr6.sys (Jungo)
DRV - (viaagp1) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\R8139n51.sys (Realtek Semiconductor Corporation )
DRV - (Ps2) – C:\WINDOWS\system32\drivers\PS2.sys (Hewlett-Packard Company)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.startnow.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..extensions.enabledItems: {B728AB94-9BC7-49b7-B76A-422BB31B2FD0}:2.0.0.8
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/11/24 19:12:40 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B728AB94-9BC7-49b7-B76A-422BB31B2FD0}: C:\Program Files\ArcSoft\Media Converter for Philips\Internet Video Downloader\Plugin_FireFox [2010/06/05 09:10:39 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/11 18:35:39 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/07 14:12:28 | 000,000,000 | —D | M]

[2010/08/14 06:50:25 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2009/04/05 21:19:58 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\[removed]
[2011/03/22 17:57:18 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\av6uxv5n.default\extensions
[2010/08/14 07:18:11 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\av6uxv5n.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/22 17:57:18 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/02/04 00:33:04 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/20 07:04:57 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/06/05 09:10:39 | 000,000,000 | —D | M] (Internet Video Downloader) – C:\PROGRAM FILES\ARCSOFT\MEDIA CONVERTER FOR PHILIPS\INTERNET VIDEO DOWNLOADER\PLUGIN_FIREFOX
[2010/11/24 19:12:40 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG9\FIREFOX
[2009/03/15 21:20:02 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2006/08/16 10:34:19 | 000,142,848 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npcpbrk7.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2007/12/17 13:16:14 | 000,065,536 | —- | M] ( ) – C:\Program Files\Mozilla Firefox\plugins\npkimi.dll
[2005/12/05 23:31:00 | 000,114,688 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
[2006/09/26 10:17:26 | 000,319,488 | —- | M] ( ) – C:\Program Files\Mozilla Firefox\plugins\npsnapfish.dll

O1 HOSTS File: ([2011/02/24 00:48:41 | 000,000,334 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Comcast Toolbar) - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\Program Files\ComcastToolbar\comcasttoolbar.dll (Comcast Cable Communications. )
O2 - BHO: (no name) - {71BEEABD-D990-491f-8626-28A7AF43C382} - No CLSID value found.
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Comcast Toolbar) - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\Program Files\ComcastToolbar\comcasttoolbar.dll (Comcast Cable Communications. )
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {E5E2F8B2-79A4-495C-8581-90BA2C845CC2} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {E5E2F8B2-79A4-495C-8581-90BA2C845CC2} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Comcast Toolbar) - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\Program Files\ComcastToolbar\comcasttoolbar.dll (Comcast Cable Communications. )
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AlcWzrd] C:\WINDOWS\ALCWZRD.EXE (RealTek Semicoductor Corp.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Conime] C:\WINDOWS\system32\conime.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ddoctorv2] C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\WINDOWS\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd.exe (Hewlett-Packard)
O4 - HKLM..\Run: [OM2_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe (OLYMPUS IMAGING CORP.)
O4 - HKLM..\Run: [PhilipsDM] C:\Program Files\Philips\Philips Device Manager\Bin\DeviceManager.exe (Koninklijke Philips Electronics N.V.)
O4 - HKLM..\Run: [PS2] C:\WINDOWS\system32\ps2.EXE (Hewlett-Packard Company)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateManager] c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKCU..\Run: [OM2_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe (OLYMPUS IMAGING CORP.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.1.121\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: SusCom Toolbar - {E5E2F8B2-79A4-495C-8581-90BA2C845CC2} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : SusCom Toolbar - {E5E2F8B2-79A4-495C-8581-90BA2C845CC2} - Reg Error: Key error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: mhyork.org ([portal] https in Trusted sites)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo1.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {55963676-2F5E-4BAF-AC28-CF26AA587566} https://portal.mhyork.org/CACHE/stc/5/binaries/vpnweb.cab (Cisco AnyConnect VPN Client Web Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {CAFEEFAC-0015-0000-FFFF-ABCDEFFEDCBA} http://mhykronos01/wfcstatic/plugins/jre-1…dows-i586-p.exe (Java Plug-in)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\OLYMPUS\OLYMPUS Master2\OLYMPUS Master 2.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\OLYMPUS\OLYMPUS Master2\OLYMPUS Master 2.bmp
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/03/28 16:14:56 | 000,000,050 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/27 14:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O33 - MountPoints2\M\Shell - "" = AutoRun
O33 - MountPoints2\M\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\M\Shell\AutoRun\command - "" = M:\setup.exe
O33 - MountPoints2\M\Shell\install\command - "" = M:\setup.exe
O33 - MountPoints2\N\Shell - "" = AutoRun
O33 - MountPoints2\N\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\N\Shell\AutoRun\command - "" = N:\setup.exe
O33 - MountPoints2\N\Shell\install\command - "" = N:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/03/21 18:51:38 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/03/20 10:45:19 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Owner\Recent
[2011/03/20 07:05:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee Security Scan
[2011/03/20 07:05:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee Security Scan Plus
[2011/03/20 07:05:13 | 000,000,000 | —D | C] – C:\Program Files\McAfee Security Scan
[2011/03/20 07:04:55 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/03/20 07:04:55 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/03/20 07:04:55 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/03/19 15:07:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\New Folder
[2011/03/19 14:26:09 | 000,000,000 | —D | C] – C:\_OTL
[2011/03/19 07:01:30 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\My Documents\iexplore.exe
[2011/03/19 00:05:34 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Owner\My Documents\HiJackThis.exe
[2011/03/15 17:57:31 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/03/06 21:02:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\magicJack
[2011/03/06 12:39:31 | 000,000,000 | —D | C] – C:\Program Files\GraphPad

========== Files - Modified Within 30 Days ==========

[2011/03/22 17:37:50 | 000,000,188 | —- | M] () – C:\WINDOWS\System\hpsysdrv.DAT
[2011/03/22 17:37:47 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/03/22 17:37:04 | 000,000,434 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.ics
[2011/03/22 17:36:38 | 1601,556,480 | -HS- | M] () – C:\hiberfil.sys
[2011/03/22 17:36:38 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/03/22 14:04:49 | 000,000,000 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\prvlcl.dat
[2011/03/22 08:46:24 | 073,046,538 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/03/21 13:06:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/03/20 16:07:23 | 000,001,038 | —- | M] () – C:\Documents and Settings\Owner\Desktop\magicJack.lnk
[2011/03/20 07:56:43 | 000,001,828 | -H– | M] () – C:\Documents and Settings\Owner\My Documents\Default.rdp
[2011/03/20 07:44:28 | 000,000,690 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/03/20 07:05:14 | 000,001,611 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2011/03/19 16:35:04 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\videopadShakeIcon.job
[2011/03/19 07:07:19 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\My Documents\iexplore.exe
[2011/03/19 00:05:34 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\My Documents\HiJackThis.exe
[2011/03/14 21:55:31 | 000,511,224 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/03/14 21:55:31 | 000,093,042 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/03/06 12:43:51 | 000,000,016 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\obtf504
[2011/03/06 12:43:49 | 000,001,681 | —- | M] () – C:\Documents and Settings\All Users\Desktop\GraphPad Prism 5 Demo.lnk
[2011/02/24 00:48:41 | 000,000,334 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts

========== Files Created - No Company Name ==========

[2011/03/20 07:44:28 | 000,000,690 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/03/20 07:05:14 | 000,001,611 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2011/03/12 07:30:41 | 000,001,044 | —- | C] () – C:\Documents and Settings\Owner\Start Menu\Programs\magicJack.lnk
[2011/03/06 12:39:42 | 000,001,681 | —- | C] () – C:\Documents and Settings\All Users\Desktop\GraphPad Prism 5 Demo.lnk
[2011/01/30 23:07:40 | 000,000,016 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\obtf504
[2010/09/22 19:12:12 | 000,000,016 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\obtf503
[2010/08/29 09:45:14 | 000,180,984 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/05/09 07:55:44 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\prvlcl.dat
[2010/04/03 20:52:49 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2010/01/30 12:02:30 | 000,031,216 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/10/13 17:35:36 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009/04/25 12:51:03 | 000,076,408 | —- | C] () – C:\WINDOWS\TrueInstall.exe
[2008/09/20 09:52:57 | 000,164,352 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2008/09/20 09:52:57 | 000,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2008/09/20 09:52:53 | 000,755,027 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/09/20 09:52:53 | 000,159,839 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/09/20 09:52:52 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/09/20 09:52:50 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2008/09/07 06:48:08 | 000,000,140 | —- | C] () – C:\WINDOWS\RealFlight.INI
[2008/07/10 17:47:20 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2008/02/26 21:03:30 | 000,006,656 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/26 17:26:43 | 000,000,248 | —- | C] () – C:\WINDOWS\HCWBlast.ini
[2008/02/26 17:25:49 | 000,032,829 | —- | C] () – C:\WINDOWS\Irremote.ini
[2008/02/26 17:25:37 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\dmcrypto.dll
[2008/02/26 17:24:52 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\hcwChDB.dll
[2008/02/26 17:24:09 | 000,003,126 | —- | C] () – C:\WINDOWS\HCWPNP.INI
[2008/02/26 17:19:04 | 000,066,048 | R— | C] () – C:\WINDOWS\System32\hcwxds.dll
[2008/02/19 02:33:34 | 000,446,352 | —- | C] () – C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2008/02/14 23:05:02 | 001,228,854 | —- | C] () – C:\Documents and Settings\All Users\Application Data\OrbError.bmp
[2008/02/02 19:19:53 | 000,000,119 | —- | C] () – C:\WINDOWS\ka.ini
[2007/06/01 01:33:06 | 000,000,028 | —- | C] () – C:\WINDOWS\MotionDVSTUDIO.INI
[2006/11/17 23:10:38 | 000,001,310 | —- | C] () – C:\WINDOWS\checkip.dat
[2006/10/18 07:23:14 | 000,033,280 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/08/16 10:34:21 | 000,000,004 | —- | C] () – C:\WINDOWS\uccspecb.sys
[2006/06/11 08:33:33 | 000,000,035 | —- | C] () – C:\WINDOWS\A4W.INI
[2006/05/03 19:12:36 | 000,000,000 | —- | C] () – C:\WINDOWS\webica.ini
[2006/04/30 07:19:18 | 000,000,953 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/04/29 20:38:55 | 000,000,030 | —- | C] () – C:\WINDOWS\trappro.INI
[2006/04/28 22:36:04 | 000,000,373 | —- | C] () – C:\WINDOWS\pdhpro.ini
[2006/03/19 10:33:07 | 000,000,068 | —- | C] () – C:\WINDOWS\TONKA_SR.INI
[2006/02/19 12:34:43 | 000,107,134 | —- | C] () – C:\WINDOWS\UninstallFirefox.exe
[2006/02/10 21:20:48 | 000,002,560 | —- | C] () – C:\WINDOWS\_MSRSTRT.EXE
[2006/02/04 18:01:45 | 000,000,006 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/01/28 11:29:08 | 000,000,205 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2005/09/17 09:28:58 | 000,011,092 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/08/19 17:38:13 | 000,006,865 | —- | C] () – C:\WINDOWS\mozver.dat
[2005/05/08 09:57:52 | 000,000,000 | —- | C] () – C:\WINDOWS\MSDraw.ini
[2005/03/29 06:25:13 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2005/02/18 16:23:36 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\DRMServer.exe
[2005/01/31 09:01:06 | 000,000,085 | —- | C] () – C:\WINDOWS\upst.ini
[2005/01/31 09:01:06 | 000,000,029 | —- | C] () – C:\WINDOWS\atid.ini
[2005/01/30 21:48:15 | 000,000,048 | —- | C] () – C:\WINDOWS\PerWin.ini
[2004/10/24 18:13:00 | 000,000,258 | —- | C] () – C:\WINDOWS\QTW.INI
[2004/08/05 18:07:43 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2004/08/05 17:51:25 | 000,038,867 | —- | C] () – C:\WINDOWS\hpomdl03.dat
[2004/08/05 17:51:25 | 000,029,258 | —- | C] () – C:\WINDOWS\hpoins03.dat
[2004/07/06 20:59:30 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2004/07/06 20:59:30 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2004/07/06 20:59:30 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2004/07/06 20:59:30 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2004/07/06 20:59:30 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2004/07/06 20:59:30 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2004/06/10 17:22:31 | 000,156,160 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2004/06/09 09:23:03 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/06/09 09:23:02 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/06/09 09:22:05 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/06/09 09:21:47 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/06/09 09:02:21 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/06/09 09:02:21 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/06/09 09:02:18 | 000,004,490 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/06/09 09:02:15 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/06/09 09:02:10 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/05/13 21:18:09 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/05/13 01:32:08 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\JAWTAccessBridge.dll
[2004/05/13 01:31:34 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2004/05/13 01:31:34 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2004/05/13 01:29:27 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2004/05/13 01:25:50 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2004/05/13 01:13:00 | 000,090,112 | R— | C] () – C:\WINDOWS\bwUnin-6.2.3.66L.exe
[2004/05/13 01:08:52 | 000,027,755 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2004/05/13 01:08:10 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2004/05/13 00:55:06 | 000,000,483 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/05/13 00:42:02 | 000,000,907 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2004/05/12 23:49:06 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/05/12 23:40:55 | 000,001,040 | —- | C] () – C:\WINDOWS\System32\drivers\alcxinit.dat
[2004/05/12 23:06:32 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/05/12 22:55:34 | 000,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2004/05/12 22:55:34 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2004/05/12 22:55:06 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2004/05/12 22:27:01 | 000,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/05/12 22:24:47 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/05/12 22:17:53 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/05/12 22:05:29 | 000,000,553 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2004/05/12 22:04:30 | 000,511,224 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/05/12 22:04:30 | 000,093,042 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/05/12 15:11:21 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/05/12 15:10:15 | 000,169,896 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/03/31 08:04:00 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2004/01/05 03:27:36 | 000,565,248 | —- | C] () – C:\WINDOWS\System32\hpotscl.dll
[2003/05/31 20:43:00 | 000,005,632 | —- | C] () – C:\WINDOWS\TrueProcess.exe
[2003/05/30 19:00:02 | 001,287,680 | —- | C] () – C:\WINDOWS\System32\quartz(2).dll
[2002/11/14 22:58:04 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2002/11/14 22:58:04 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2002/11/14 22:58:02 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2002/11/14 22:58:02 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2002/11/14 22:58:02 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[1999/07/29 04:27:10 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\iyvu9_32.dll
[1999/01/22 14:46:56 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34

< End of report >
Hi racin9m,

Those detections are in your HP recovery folder. They are in some software bundled with HP machines. They are not a problem or a threat so we'll leave them alone.

We'll clean up our tools and send you on your way.

First

Navigate to this folder

C:\Documents and Settings\Owner\My Documents
  • locate iexplore.exe and right click on it
  • click rename
  • on the keyboard type OTL.exe
  • hit enter

From your desktop, please delete, if present
  • any notepads/logs that we created
  • Norton_Removal_Tool.exe

Next

* Create a new restore point

You must be logged on to an administrator account
  • Go to Start - All Programs - Accessories - System Tools - System Restore.
  • Click Create a restore point, and then click Next.
  • In the text box labeled Restore Point Description, type a name for this restore point
  • click create
* Remove old restore points

  • Go to Start - All Programs - Accessories - system tools.
  • Launch the Disk Cleanup tool and let it run.
  • When it finishes a box with tabs will appear, select the more options tab.
  • On this tab you will find a section for System Restore.
  • If you press the Clean Up button for that section, Windows will delete all restore points except for the most recent one.

Next

Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.


I suggest you keep MBAM. Keep it updated and use it regularly.

ESET online scan can be removed via add/remove programs.


Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall.

I suggest either for a resident antispyware program.

Windows Defender
OR
Winpatrol

* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for links and tutorials to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware,IMO)


-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis


- Make sure you have reset Automatic Updates to your chosen optionClick your start button > Control Panel > System


- Keep your antivirus program updated, as well as any other security programs you have.


-More tips and programs can be found HERE


- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879

Please post back if you have any problems.

Take care

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI