This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

XP Antivirus malware & cannot run malwarbytes & hijack this

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The other day I got a pop up that my machine was infected and XP Antivirus was required. I knew this was a virus so I ran a scan with McAffee and it appears to have removed it. Now I cannot access any programs. Everytime I double click on a program I get the open with what program box (examples are malwarebytes, hijack this, Firefox, Command Prompt, etc. I was able to start computer in safe mode and ran Hijack this as an administrator (this is a home computer). Also how do I check to see if my wireless router is infected. For awhile now when we surf the internet we get the google-analytics redircts to other websites and problems of that kind. Here is Hijack this from safemode. Also tried to run OTL or something from a usb thumb drive and computer won't recongnize the USB port.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:03:59 PM, on 3/24/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
C:\WINDOWS\system32\mfevtps.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
O1 - Hosts: .176.57 download.mcafee.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20101218121644.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" -start
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRA~1\QUICKT~1\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Memeo Instant Backup] C:\Program Files\Memeo\AutoBackup\MemeoLauncher2.exe –silent –no_ui
O4 - HKLM\..\Run: [Seagate Dashboard] C:\Program Files\Seagate\Seagate Dashboard\MemeoLauncher.exe –silent –no_ui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Htaxejulat] rundll32.exe "C:\WINDOWS\ohimohagiqinic.dll",Startup
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-745026515-2176700639-2611127406-1008\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup (User 'Mike Unser')
O4 - HKUS\S-1-5-21-745026515-2176700639-2611127406-1008\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter (User 'Mike Unser')
O4 - HKUS\S-1-5-21-745026515-2176700639-2611127406-1008\..\Run: [edjfnkta] C:\Documents and Settings\Mike Unser\Local Settings\Application Data\jrgqfpweq\hphfxthtssd.exe (User 'Mike Unser')
O4 - HKUS\S-1-5-21-745026515-2176700639-2611127406-1008\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Mike Unser')
O4 - HKUS\S-1-5-21-745026515-2176700639-2611127406-1008\..\Run: [A9YA3MI1CF] C:\DOCUME~1\MIKEUN~1\LOCALS~1\Temp\Kjl.exe (User 'Mike Unser')
O4 - HKUS\S-1-5-21-745026515-2176700639-2611127406-1008\..\Run: [Okatunum] rundll32.exe "C:\WINDOWS\WMFTA2.dll",Startup (User 'Mike Unser')
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\PrintMaster Platinum 17\Remind.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} (Device Detection) - http://www.logitech.com/devicedetector/plu…Detection32.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.maricopa.gov/assessor/gis/plugin/mgaxctrl.cab
O16 - DPF: {6632A7E9-FE1F-43D2-A04A-A15951ED63E0} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://www.samsphotoclub.com/upload/FujifilmUploadClient.cab
O16 - DPF: {BAE57CC6-88D1-4AE8-B6FD-306120D5BC52} (SystemRequirement.TechCheck) - http://www.riosalado.edu/techcheck/SystemRequirements.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://bin.mcafee.com/molbin/shared/mcgdmg…,20/mcgdmgr.cab
O16 - DPF: {BEA7310D-06C4-4339-A784-DC3804819809} (Photo Upload Plugin Class) - http://samsclubus.pnimedia.com/upload/acti…veX_Control.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://sa.srpnet.com/dana-cached/setup/JuniperSetupSP1.cab
O16 - DPF: {EFD1E13D-1CB3-4545-B754-CA410FE7734F} (Photo Upload Plugin Class) - http://samsclubus.pnimedia.com/upload/acti…veX_Control.cab
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} (JuniperSetupClientControl Class) - https://sa.srpnet.com/dana-cached/sc/JuniperSetupClient.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: itlnfw32 - itlnfw32.dll (file missing)
O20 - Winlogon Notify: itlntfy - itlnfw32.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: MemeoBackgroundService - Memeo - C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\WINDOWS\system32\mfevtps.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Seagate Dashboard Service (SeagateDashboardService) - Memeo - C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 13976 bytes
Hi mikeinsurprise, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.


First, Open hijackthis, do a system scan only and checkmark these lines, if present


O4 - HKLM\..\Run: [Htaxejulat] rundll32.exe "C:\WINDOWS\ohimohagiqinic.dll",Startup
O4 - HKUS\S-1-5-21-745026515-2176700639-2611127406-1008\..\Run: [edjfnkta] C:\Documents and Settings\Mike Unser\Local Settings\Application Data\jrgqfpweq\hphfxthtssd.exe (User 'Mike Unser')
O4 - HKUS\S-1-5-21-745026515-2176700639-2611127406-1008\..\Run: [A9YA3MI1CF] C:\DOCUME~1\MIKEUN~1\LOCALS~1\Temp\Kjl.exe (User 'Mike Unser')
O4 - HKUS\S-1-5-21-745026515-2176700639-2611127406-1008\..\Run: [Okatunum] rundll32.exe "C:\WINDOWS\WMFTA2.dll",Startup (User 'Mike Unser')
O20 - Winlogon Notify: itlnfw32 - itlnfw32.dll (file missing)
O20 - Winlogon Notify: itlntfy - itlnfw32.dll (file missing)


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.


Reboot the computer. This time log into your usual account.


Next

Let's try downloading a tool in a slightly different manner. Before you download this tool rename it to iexplore.exe

Download OTL to your desktop.
  • Double click on the renamed file to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Deskuop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.


Please post back with
  • both OTL logs
No need for a Hijackthis log this time.

Thanks
Downloaded as iexplore.exe but couldn't run it in normal mode. Got the pop up to choose program to open with. Ran it in safe mode as administrator. Here's the OLT and Extra text files.

OTL logfile created on: 3/25/2011 5:15:19 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Mike Unser\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

766.00 Mb Total Physical Memory | 351.00 Mb Available Physical Memory | 46.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): C:\pagefile.sys 1147 1147 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.73 Gb Total Space | 65.46 Gb Free Space | 58.59% Space Free | Partition Type: NTFS

Computer Name: OFFICE | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Mike Unser\Desktop\iexplore.exe (OldTimer Tools)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
PRC - c:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\WINDOWS\SYSTEM32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Mike Unser\Desktop\iexplore.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\SYSTEM32\wsock32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\SYSTEM32\wshtcpip.dll (Microsoft Corporation)
MOD - C:\WINDOWS\SYSTEM32\hnetcfg.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (itlperf) – File not found
SRV - (AppMgmt) – File not found
SRV - (6to4) – File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (mfevtp) – C:\WINDOWS\SYSTEM32\mfevtps.exe (McAfee, Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (MemeoBackgroundService) – C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe (Memeo)
SRV - (SeagateDashboardService) – C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe (Memeo)
SRV - (McProxy) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\SYSTEM32\HPZipm12.exe (HP)
SRV - (NetSvc) – C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation)


========== Driver Services (SafeList) ==========

DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – C:\WINDOWS\SYSTEM32\DRIVERS\mfefirek.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfeapfk.sys (McAfee, Inc.)
DRV - (mfendiskmp) – C:\WINDOWS\SYSTEM32\DRIVERS\mfendisk.sys (McAfee, Inc.)
DRV - (mfendisk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfendisk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\WINDOWS\SYSTEM32\DRIVERS\mferkdet.sys (McAfee, Inc.)
DRV - (mfetdi2k) – C:\WINDOWS\SYSTEM32\DRIVERS\mfetdi2k.sys (McAfee, Inc.)
DRV - (cfwids) – C:\WINDOWS\SYSTEM32\DRIVERS\cfwids.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfebopk.sys (McAfee, Inc.)
DRV - (FilterService) – C:\WINDOWS\SYSTEM32\DRIVERS\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUVC) Logitech Webcam 250(UVC) – C:\WINDOWS\SYSTEM32\DRIVERS\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\SYSTEM32\DRIVERS\lvrs.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\SYSTEM32\DRIVERS\LVPr2Mon.sys ()
DRV - (lvpopflt) – C:\WINDOWS\SYSTEM32\DRIVERS\lvpopflt.sys (Logitech Inc.)
DRV - (MxlW2k) – C:\WINDOWS\System32\drivers\MxlW2k.sys (MusicMatch, Inc.)
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (NEOFLTR_510_8959) Juniper Networks TDI Filter Driver (NEOFLTR_510_8959) – C:\WINDOWS\SYSTEM32\DRIVERS\NEOFLTR_510_8959.sys (Neoteris)
DRV - (iAimFP4) – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)
DRV - (iAimFP3) – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)
DRV - (iAimTV4) – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)
DRV - (iAimTV3) – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)
DRV - (iAimTV1) – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)
DRV - (iAimTV0) – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)
DRV - (iAimFP0) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)
DRV - (iAimFP1) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)
DRV - (iAimFP2) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)
DRV - (i81x) – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (AFS2K) – C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (cdrbsdrv) – C:\WINDOWS\System32\drivers\CDRBSDRV.SYS (B.H.A Corporation)
DRV - (BCMModem) – C:\WINDOWS\SYSTEM32\DRIVERS\BCMSM.sys (Broadcom Corporation)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (EL90XBC) – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2011/02/28 19:18:08 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{AA1F7949-20DE-494A-9C69-8373D168BCBA}: C:\Documents and Settings\Mike Unser\Local Settings\Application Data\{AA1F7949-20DE-494A-9C69-8373D168BCBA} [2011/03/22 16:23:26 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/06 15:10:27 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/05 15:13:55 | 000,000,000 | —D | M]

[2011/03/22 17:09:12 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/07/12 01:06:19 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/02/05 19:34:35 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010/10/13 22:28:54 | 000,024,376 | —- | M] (McAfee, Inc.) – C:\Program Files\Mozilla Firefox\components\Scriptff.dll
[2009/11/20 14:05:31 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2011/02/05 19:33:54 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/11/20 14:05:32 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll

O1 HOSTS File: ([2010/12/18 12:00:58 | 000,000,808 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: .176.57 download.mcafee.com
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20101218121644.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [Memeo Instant Backup] C:\Program Files\Memeo\AutoBackup\MemeoLauncher2.exe (Memeo Inc.)
O4 - HKLM..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe (MUSICMATCH, Inc.)
O4 - HKLM..\Run: [Seagate Dashboard] C:\Program Files\Seagate\Seagate Dashboard\MemeoLauncher.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [Sonic RecordNow!] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Event Reminder.lnk = C:\Program Files\PrintMaster Platinum 17\Remind.exe (Broderbund Properties LLC)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - File not found
O9 - Extra 'Tools' menuitem : PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Program Files\Neoteris\Secure Application Manager\samnsp.dll (Neoteris)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} http://www.logitech.com/devicedetector/plu…Detection32.cab (Device Detection)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www2.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} Reg Error: Key error. (Reg Error: Key error.)
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} http://www.maricopa.gov/assessor/gis/plugin/mgaxctrl.cab (Autodesk MapGuide ActiveX Control)
O16 - DPF: {6632A7E9-FE1F-43D2-A04A-A15951ED63E0} http://mediaplayer.walmart.com/installer/install.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} http://www.nick.com/common/groove/gx/GrooveAX27.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} http://web1.shutterfly.com/downloads/Uploader.cab (Shutterfly Picture Upload Plugin)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…8045.5157638889 (Reg Error: Key error.)
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} http://www.samsphotoclub.com/upload/FujifilmUploadClient.cab (FujifilmUploader Class)
O16 - DPF: {BAE57CC6-88D1-4AE8-B6FD-306120D5BC52} http://www.riosalado.edu/techcheck/SystemRequirements.cab (SystemRequirement.TechCheck)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://bin.mcafee.com/molbin/shared/mcgdmg…,20/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {BEA7310D-06C4-4339-A784-DC3804819809} http://samsclubus.pnimedia.com/upload/acti…veX_Control.cab (Photo Upload Plugin Class)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://sa.srpnet.com/dana-cached/setup/JuniperSetupSP1.cab (JuniperSetupSP1 Control)
O16 - DPF: {EFD1E13D-1CB3-4545-B754-CA410FE7734F} http://samsclubus.pnimedia.com/upload/acti…veX_Control.cab (Photo Upload Plugin Class)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://sa.srpnet.com/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/04/22 21:30:41 | 000,000,038 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: Ip6FwHlp - File not found

CREATERESTOREPOINT
Error starting restore point: The function was called in safe mode.
Error closing restore point: The sequence number is invalid.

========== Files/Folders - Created Within 30 Days ==========

[2011/03/25 17:13:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Macromedia
[2011/03/25 17:09:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2011/03/25 15:51:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Desktop\backups
[2011/03/24 18:01:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Adobe
[2011/03/24 18:01:35 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Administrator\PrivacIE
[2011/03/23 21:46:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2011/03/23 21:46:13 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/03/23 21:46:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/03/23 21:46:09 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/03/23 21:46:09 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/03/23 21:45:42 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\Desktop\mbam-setup-1.50.1.1100.exe
[2011/03/23 21:45:42 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2011/03/23 21:45:42 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe
[2011/03/23 21:37:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\Juniper Networks
[2011/03/23 21:34:40 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Administrator\IETldCache
[2011/03/22 22:49:58 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Temp
[2011/03/22 22:49:58 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/03/09 15:14:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/03/09 15:12:21 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/03/09 15:12:02 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/03/09 14:58:08 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/03/05 15:14:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/25 17:11:20 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/03/25 17:09:26 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2011/03/25 17:09:21 | 000,001,595 | —- | M] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Center.lnk
[2011/03/25 17:08:52 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2011/03/25 17:08:44 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\logiflt.iad
[2011/03/25 16:38:08 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/25 16:22:00 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011/03/25 16:21:47 | 000,000,324 | -HS- | M] () – C:\WINDOWS\tasks\PYHPB.job
[2011/03/25 16:21:44 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/25 16:21:43 | 000,000,316 | -HS- | M] () – C:\WINDOWS\tasks\BDYLLNDNB.job
[2011/03/25 16:21:42 | 000,000,320 | -HS- | M] () – C:\WINDOWS\tasks\Crhozpaa.job
[2011/03/25 16:21:32 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\lvuvc.hs
[2011/03/23 21:46:13 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/23 21:30:53 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2011/03/23 21:29:26 | 000,359,929 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\dds.scr
[2011/03/23 21:28:55 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe
[2011/03/23 21:11:36 | 000,398,760 | R— | M] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2011/03/23 20:28:18 | 000,000,525 | —- | M] () – C:\hpfr3420.xml
[2011/03/23 19:26:24 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Administrator\Desktop\mbam-setup-1.50.1.1100.exe
[2011/03/23 16:00:00 | 000,000,412 | —- | M] () – C:\WINDOWS\tasks\vtscheduletask.job
[2011/03/23 06:41:12 | 000,016,664 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\e63lt3ed7f6e
[2011/03/23 04:45:11 | 000,000,000 | —- | M] () – C:\WINDOWS\Nhovij.bin
[2011/03/22 20:55:03 | 000,000,120 | —- | M] () – C:\WINDOWS\Lfuyiwitatuxof.dat
[2011/03/22 16:20:50 | 000,108,544 | RHS- | M] () – C:\WINDOWS\System32\webcheckz.dll
[2011/03/18 13:10:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/03/10 03:12:57 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/03/09 15:14:12 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/03/09 14:59:34 | 000,001,854 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2011/03/05 15:14:06 | 000,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]

========== Files Created - No Company Name ==========

[2067/02/24 15:21:18 | 000,079,947 | —- | C] () – C:\WINDOWS\fw20.vxd
[2011/03/23 21:46:13 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/23 21:45:42 | 000,359,929 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\dds.scr
[2011/03/22 17:44:12 | 000,016,664 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\e63lt3ed7f6e
[2011/03/22 16:23:29 | 000,000,120 | —- | C] () – C:\WINDOWS\Lfuyiwitatuxof.dat
[2011/03/22 16:23:29 | 000,000,000 | —- | C] () – C:\WINDOWS\Nhovij.bin
[2011/03/22 16:20:57 | 000,000,324 | -HS- | C] () – C:\WINDOWS\tasks\PYHPB.job
[2011/03/22 16:20:57 | 000,000,316 | -HS- | C] () – C:\WINDOWS\tasks\BDYLLNDNB.job
[2011/03/22 16:20:56 | 000,000,320 | -HS- | C] () – C:\WINDOWS\tasks\Crhozpaa.job
[2011/03/22 16:20:50 | 000,108,544 | RHS- | C] () – C:\WINDOWS\System32\webcheckz.dll
[2011/03/09 15:14:12 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/03/05 15:14:06 | 000,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/03/01 18:40:57 | 000,002,272 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/02/05 17:59:41 | 000,016,432 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2010/11/19 19:51:16 | 000,016,618 | —- | C] () – C:\WINDOWS\hpomdl01.dat
[2010/11/19 19:51:15 | 000,020,454 | —- | C] () – C:\WINDOWS\hpoins01.dat
[2010/08/28 09:26:39 | 000,082,289 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2010/07/18 18:13:11 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/05/14 14:56:06 | 010,830,680 | —- | C] () – C:\WINDOWS\System32\LogiDPP.dll
[2010/05/14 14:56:06 | 000,102,744 | —- | C] () – C:\WINDOWS\System32\LogiDPPApp.exe
[2010/05/14 14:55:58 | 000,290,648 | —- | C] () – C:\WINDOWS\System32\DevManagerCore.dll
[2010/02/27 10:21:52 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2009/10/27 10:04:55 | 000,123,124 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/10/07 01:46:36 | 000,025,752 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009/10/07 01:23:08 | 000,013,584 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2009/09/25 23:20:44 | 000,000,000 | —- | C] () – C:\WINDOWS\popcreg.dat
[2009/09/24 01:23:09 | 000,000,042 | —- | C] () – C:\WINDOWS\popcinfot.dat
[2008/09/23 21:14:25 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2008/09/23 21:14:21 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2008/09/23 21:14:21 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2008/09/23 21:14:19 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2008/09/23 21:14:08 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2008/09/23 21:13:19 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2008/09/23 21:12:56 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2008/06/19 11:20:22 | 000,000,000 | —- | C] () – C:\Program Files\temp01
[2008/05/26 21:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/05/14 16:30:36 | 000,012,288 | —- | C] () – C:\WINDOWS\impborl.dll
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/12/26 21:12:15 | 000,002,189 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/12/12 09:30:29 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\DivXsm.exe
[2006/12/12 09:30:26 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2006/12/12 09:24:42 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2006/02/19 20:46:40 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\uninscpw.exe
[2005/11/11 22:53:06 | 000,000,074 | —- | C] () – C:\WINDOWS\ImportClient.INI
[2004/10/22 01:45:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/15 19:48:55 | 000,022,740 | -H– | C] () – C:\WINDOWS\hpothb07.dat
[2004/08/02 22:28:15 | 000,021,312 | —- | C] () – C:\WINDOWS\choice.exe
[2004/08/02 18:26:46 | 000,000,059 | —- | C] () – C:\WINDOWS\System32\6vo4svc.dll
[2004/08/01 15:14:42 | 001,152,060 | —- | C] () – C:\WINDOWS\kwv2.dat
[2004/07/29 20:16:52 | 000,065,588 | —- | C] () – C:\WINDOWS\System32\zlib.dll
[2004/07/21 20:57:49 | 000,000,574 | —- | C] () – C:\WINDOWS\eReg.dat
[2004/07/15 17:59:51 | 000,000,037 | —- | C] () – C:\WINDOWS\ipixActivex.ini
[2004/04/20 19:14:58 | 000,009,019 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2004/02/28 14:26:30 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/02/28 14:11:09 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2004/02/28 13:18:52 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\instlsp.exe
[2004/02/19 20:37:21 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/02/19 20:32:26 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2004/02/19 20:29:14 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2004/02/19 20:28:22 | 000,000,215 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/02/19 20:18:30 | 000,002,048 | –S- | C] () – C:\WINDOWS\BOOTSTAT.DAT
[2004/02/19 20:16:58 | 000,466,932 | —- | C] () – C:\WINDOWS\System32\PERFH009.DAT
[2004/02/19 20:16:58 | 000,080,148 | —- | C] () – C:\WINDOWS\System32\PERFC009.DAT
[2004/02/19 20:16:47 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/02/19 20:05:16 | 000,000,550 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2003/08/19 12:41:32 | 000,965,096 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2003/08/19 12:40:04 | 000,000,258 | —- | C] () – C:\WINDOWS\System32\BDEMERGE.INI
[2003/08/19 12:38:56 | 000,000,831 | —- | C] () – C:\WINDOWS\ORUN32.INI
[2003/08/13 21:54:00 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/03/09 13:31:04 | 000,561,152 | —- | C] () – C:\WINDOWS\System32\hpotscl.dll
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/09/03 07:59:14 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2002/09/03 07:56:30 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2002/09/03 07:31:46 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2002/09/03 07:31:44 | 000,004,594 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2002/08/29 04:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\MLANG.DAT
[2002/08/29 04:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\PERFI009.DAT
[2002/08/29 04:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\DSSEC.DAT
[2002/08/29 04:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\MIB.BIN
[2002/08/29 04:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\PERFD009.DAT
[2002/08/29 04:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\NOISE.DAT
[1999/03/22 01:00:00 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

========== LOP Check ==========

[2011/03/23 21:37:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Juniper Networks
[2007/12/03 10:28:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund Software
[2010/12/18 08:44:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2009/06/01 05:21:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2008/06/19 12:15:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ludia
[2006/01/20 20:24:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MCA66.tmp
[2011/01/17 18:46:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MemeoCommon
[2009/05/14 14:31:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2009/09/24 01:22:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2007/12/03 10:35:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Riverdeep Interactive Learning Limited
[2007/11/28 17:48:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2010/07/15 13:23:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/09/30 06:41:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/03/14 21:05:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2011/02/05 17:10:36 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{2162CCC0-3A5F-4887-B51F-CE5F195B3620}
[2010/04/21 09:49:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/11 23:06:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/28 11:12:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/03/25 17:11:20 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2011/03/25 16:21:43 | 000,000,316 | -HS- | M] () – C:\WINDOWS\Tasks\BDYLLNDNB.job
[2011/03/25 16:21:42 | 000,000,320 | -HS- | M] () – C:\WINDOWS\Tasks\Crhozpaa.job
[2011/02/20 00:14:10 | 000,000,352 | —- | M] () – C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1290222188.job
[2011/03/25 16:21:47 | 000,000,324 | -HS- | M] () – C:\WINDOWS\Tasks\PYHPB.job
[2011/03/23 16:00:00 | 000,000,412 | —- | M] () – C:\WINDOWS\Tasks\vtscheduletask.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/03/25 17:08:44 | 000,034,240 | —- | M] () – C:\aaw7boot.log
[2004/04/22 21:30:41 | 000,000,038 | —- | M] () – C:\AUTOEXEC.BAT
[2004/11/13 21:13:32 | 000,000,211 | -HS- | M] () – C:\Boot.bak
[2010/06/23 21:14:45 | 000,000,281 | -HS- | M] () – C:\BOOT.INI
[2002/09/03 07:38:46 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/06/29 17:35:51 | 000,013,743 | —- | M] () – C:\ComboFix.txt
[2002/09/03 07:59:58 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2004/02/19 20:07:18 | 000,005,613 | RH– | M] () – C:\DELL.SDR
[2005/03/14 20:51:46 | 000,000,004 | -HS- | M] () – C:\dllimp_regmsft985
[2006/03/21 15:04:20 | 000,000,091 | —- | M] () – C:\dsnsisdll.log
[2011/03/23 20:28:18 | 000,000,525 | —- | M] () – C:\hpfr3420.xml
[2011/03/23 20:28:18 | 001,202,496 | —- | M] () – C:\hpfr3425.log
[2002/09/03 07:59:58 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2004/02/19 20:30:35 | 000,000,855 | -H– | M] () – C:\IPH.PH
[2002/09/03 07:59:58 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/11/13 20:59:22 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/30 22:25:12 | 000,250,048 | —- | M] () – C:\ntldr
[2011/03/25 17:08:45 | 1202,716,672 | -HS- | M] () – C:\pagefile.sys
[2004/05/22 15:02:16 | 000,002,138 | —- | M] () – C:\Rescued document.txt
[2007/08/26 12:20:31 | 000,106,496 | —- | M] () – C:\System.mdw
[2010/06/22 16:46:57 | 000,052,374 | —- | M] () – C:\TDSSKiller.2.3.2.0_22.06.2010_16.46.32_log.txt
[2010/06/28 16:56:39 | 000,051,418 | —- | M] () – C:\TDSSKiller.2.3.2.0_28.06.2010_16.56.23_log.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2002/09/03 07:59:02 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\DESKTOP.INI

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 05:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\filterpipelineprintproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\mdippr.dll
[2008/07/06 03:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2008/05/14 16:30:42 | 000,471,040 | —- | M] (ScreenTime Media) – C:\WINDOWS\Music Works.scr
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/06/19 11:20:22 | 000,000,000 | —- | M] () – C:\Program Files\temp01

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2002/09/03 07:47:18 | 000,094,208 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2002/09/03 07:47:18 | 000,602,112 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2002/09/03 07:47:18 | 000,380,928 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
[2008/09/30 22:34:59 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\DESKTOP.INI
[2006/04/11 20:08:14 | 000,001,566 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Microsoft Update.lnk
[2004/02/28 14:25:52 | 000,001,992 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\New Office Document.lnk
[2010/06/03 11:39:41 | 000,002,439 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Open Office Document.lnk
[2008/09/30 22:34:59 | 000,001,563 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk
[2002/09/03 08:00:00 | 000,000,398 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Catalog.lnk
[2007/05/01 01:00:02 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Deskuop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-11 22:53:40


< MD5 for: EXPLORER.EX_ >
[2002/08/29 04:00:00 | 000,351,603 | —- | M] () MD5=2690171B51B4DBA59C02E89DB7FE6C9B – C:\I386\EXPLORER.EX_

< MD5 for: EXPLORER.EXE >
[2008/04/13 17:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/13 17:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 17:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 04:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 03:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/04 00:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
[2002/08/29 04:00:00 | 001,004,032 | —- | M] (Microsoft Corporation) MD5=A82B28BFC2E4455FE43022A498C0EF0A – C:\WINDOWS\$NtUninstallKB820291$\explorer.exe

< MD5 for: EXPLORER.EXE.000 >
[2004/08/04 00:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe.000

< MD5 for: EXPLORER.SC_ >
[2002/08/29 04:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\I386\EXPLORER.SC_

< MD5 for: EXPLORER.SCF >
[2002/08/29 04:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\EXPLORER.SCF

< MD5 for: IEXPLORE.CHM >
[2002/08/29 04:00:00 | 000,167,956 | —- | M] () MD5=13A43EAD75BC03C50815444AC3018010 – C:\I386\IEXPLORE.CHM
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2004/07/17 11:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2004/07/17 11:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ServicePackFiles\i386\iexplore.chm
[2006/09/01 08:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\ie8\iexplore.chm

< MD5 for: IEXPLORE.CHW >
[2005/11/12 14:20:04 | 000,185,057 | —- | M] () MD5=D2258AFCFB2E7B97C1E3AFA7BEDD0061 – C:\WINDOWS\Help\iexplore.chw

< MD5 for: IEXPLORE.EX_ >
[2002/08/29 04:00:00 | 000,036,925 | —- | M] () MD5=BAC737FDAA9B648A6EBFF76BFAEC7501 – C:\I386\IEXPLORE.EX_

< MD5 for: IEXPLORE.EXE >
[2009/06/29 00:25:31 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD – C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2008/12/18 22:25:25 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=030D78FE84A086ED376EFCBD2D72C522 – C:\WINDOWS\ie7updates\KB963027-IE7\iexplore.exe
[2008/10/14 23:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
[2009/04/24 22:27:50 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2008/12/18 22:25:30 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=15E8A89499741D5CF59A9CF6463A4339 – C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[2008/04/22 01:02:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=197B7E4030CFBD8D2979D375E1787AA2 – C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\iexplore.exe
[2008/08/22 22:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\ie7updates\KB958215-IE7\iexplore.exe
[2010/06/17 08:12:57 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=203E897F843D56496E2CC101DFF6CE34 – C:\WINDOWS\ie7updates\KB2360131-IE7\iexplore.exe
[2008/04/22 00:40:18 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=232B22817B90AE0AFF2D189E3E3735AC – C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe
[2007/12/06 04:01:25 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2703D940A62B731AA220529DD7331A78 – C:\WINDOWS\ie7updates\KB947864-IE7\iexplore.exe
[2008/02/29 01:55:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2D0E5592AB5A46C27DAF7CCAFF4F5B59 – C:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
[2009/08/26 22:18:42 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=332EC7562F3AA7364F2D4231C56DA986 – C:\WINDOWS\$hf_mig$\KB974455-IE7\SP3QFE\iexplore.exe
[2007/08/17 03:21:21 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=3AC2BC667DA0AF2C968E96E1630F5AB5 – C:\WINDOWS\ie7updates\KB942615-IE7\iexplore.exe
[2007/08/17 03:21:21 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=3AC2BC667DA0AF2C968E96E1630F5AB5 – C:\WINDOWS\SoftwareDistribution\Download\0eda838ef8ec599d822155030a70ecac\SP2GDR\iexplore.exe
[2009/06/29 01:35:10 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD – C:\WINDOWS\ie7updates\KB974455-IE7\iexplore.exe
[2009/10/27 23:54:16 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=4F9B04D546C23A295F3F0AE015BE51DB – C:\WINDOWS\ie7updates\KB978207-IE7\iexplore.exe
[2009/12/18 06:05:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=53C291F3B01EECECBD7FD358EA3ACC94 – C:\WINDOWS\ie7updates\KB980182-IE7\iexplore.exe
[2007/08/17 03:12:49 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=5577D0E3AC2F9F035ACD81B44AF5F511 – C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iexplore.exe
[2007/08/17 03:12:49 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=5577D0E3AC2F9F035ACD81B44AF5F511 – C:\WINDOWS\SoftwareDistribution\Download\0eda838ef8ec599d822155030a70ecac\SP2QFE\iexplore.exe
[2008/04/13 17:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2007/10/10 01:16:56 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=632BDE0179847234433CA50945442ACB – C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iexplore.exe
[2008/06/23 02:20:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=64E376A47763DAEABCDA14BD5B6EA286 – C:\WINDOWS\ie7updates\KB956390-IE7\iexplore.exe
[2008/02/22 02:40:22 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=6E0888626E0CAC79F57149814E22DB4D – C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
[2010/10/18 04:07:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=72D1F43C4146D312B0DB6AB98C21340E – C:\WINDOWS\ie8\iexplore.exe
[2009/10/27 23:54:21 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=80675329E0FD54F016C4F8A83C616349 – C:\WINDOWS\$hf_mig$\KB976325-IE7\SP3QFE\iexplore.exe
[2007/12/06 01:34:45 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=809D17D8FA0FDAEE07778CD821CAFFDE – C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
[2008/10/15 00:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
[2009/02/27 21:54:41 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=A251068640DDB69FD7805B57D89D7FF7 – C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2010/06/17 07:45:15 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B0BC6DC9C9277250C5C8F7B7A48A02CC – C:\WINDOWS\$hf_mig$\KB2183461-IE7\SP3QFE\iexplore.exe
[2010/04/16 04:08:29 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B24A4E23A2FEDB6976EB04D334AD82B2 – C:\WINDOWS\$hf_mig$\KB982381-IE7\SP3QFE\iexplore.exe
[2010/02/22 22:20:02 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B5116340B84824DDD0A641E36B126194 – C:\WINDOWS\ie7updates\KB982381-IE7\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
[2009/02/27 21:54:44 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=BCD8E48709BE4A79606F0B6E8E9A6162 – C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[2009/04/24 22:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2010/04/16 04:43:25 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=C4BA5E36FB57F547117305BF1E0FE454 – C:\WINDOWS\ie7updates\KB2183461-IE7\iexplore.exe
[2008/06/23 01:23:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=C52A9EF571E91535EB78DB4B8B95EA07 – C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
[2010/02/22 22:19:59 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=C8DDA4028065D5CE39CBE7A156B72AB9 – C:\WINDOWS\$hf_mig$\KB980182-IE7\SP3QFE\iexplore.exe
[2009/12/18 00:00:27 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=D19E56D5930C37CF211867DF450C372A – C:\WINDOWS\$hf_mig$\KB978207-IE7\SP3QFE\iexplore.exe
[2011/03/25 16:32:25 | 000,580,608 | —- | M] (OldTimer Tools) MD5=D1CFB2FA6A160DB3854E7BCFF19A9D63 – C:\Documents and Settings\Mike Unser\Desktop\iexplore.exe
[2010/10/18 03:36:30 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=DA6E1F0F1932B62DD2F6ED05541C555C – C:\WINDOWS\$hf_mig$\KB2416400-IE7\SP3QFE\iexplore.exe
[2007/08/13 18:43:56 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 – C:\WINDOWS\ie7updates\KB939653-IE7\iexplore.exe
[2010/08/25 04:30:33 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E5412ED9E07C42C20C48D3FF71E6B1E8 – C:\WINDOWS\ie7updates\KB2416400-IE7\iexplore.exe
[2004/08/04 00:56:50 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\$NtServicePackUninstall$\iexplore.exe
[2004/08/04 00:56:50 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\ie7\iexplore.exe
[2008/08/22 22:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
[2007/10/10 03:59:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=E854D02E4231F704D9BE782A424E6D8B – C:\WINDOWS\ie7updates\KB944533-IE7\iexplore.exe
[2010/08/25 04:07:58 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F047BEB9771E45A05F425499A30F9BBA – C:\WINDOWS\$hf_mig$\KB2360131-IE7\SP3QFE\iexplore.exe
[2009/08/26 22:18:44 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F232BA9F39BC0F722672C7E79E68EBEA – C:\WINDOWS\ie7updates\KB976325-IE7\iexplore.exe

< MD5 for: IEXPLORE.EXE.HDMP >
[2011/03/23 20:21:16 | 009,499,103 | —- | M] () MD5=64E74F7FD0375A5796700CBDB8CEA941 – C:\Documents and Settings\Mike Unser\Local Settings\temp\WER65ad.dir00\iexplore.exe.hdmp

< MD5 for: IEXPLORE.EXE.MDMP >
[2011/03/23 20:21:11 | 000,078,402 | —- | M] () MD5=37875D3FF9C6F67FCFE1EDFF7D853391 – C:\Documents and Settings\Mike Unser\Local Settings\temp\WER65ad.dir00\iexplore.exe.mdmp

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2007/08/13 18:43:36 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 – C:\WINDOWS\ie8\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-2D97EBE6.PF >
[2011/03/25 16:31:48 | 000,090,320 | —- | M] () MD5=4284FA8050A8C72B6D05A98428E030DC – C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf

< MD5 for: IEXPLORE.HLP >
[2002/08/29 04:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\I386\IEXPLORE.HLP
[2002/08/29 04:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\IEXPLORE.HLP

< MD5 for: IEXPLORE.LNK >
[2004/09/10 17:42:56 | 000,000,769 | —- | M] () MD5=9CEF863F0EDB1A3F907109785EAC6807 – C:\Documents and Settings\Mike Unser\Application Data\Microsoft\Office\Shortcut Bar\Office\IEXPLORE.lnk

< MD5 for: WINLOGON.EXE >
[2004/08/04 00:56:57 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2002/08/29 04:00:00 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=2246D8D8F4714A2CEDB21AB9B1849ABB – C:\I386\WINLOGON.EXE
[2002/08/29 04:00:00 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=2246D8D8F4714A2CEDB21AB9B1849ABB – C:\WINDOWS\$NtUninstallKB840987$\winlogon.exe
[2008/04/13 17:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/13 17:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 17:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\SYSTEM32\winlogon.exe

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5F1019FF
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34

< End of report >
here's the Extra.txt

OTL Extras logfile created on: 3/25/2011 5:15:19 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Mike Unser\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

766.00 Mb Total Physical Memory | 351.00 Mb Available Physical Memory | 46.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): C:\pagefile.sys 1147 1147 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.73 Gb Total Space | 65.46 Gb Free Space | 58.59% Space Free | Partition Type: NTFS

Computer Name: OFFICE | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management
"80:TCP" = 80:TCP:*:Disabled:Windows Remote Management - Compatibility Mode (HTTP-In)
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EA SPORTS\NASCAR Thunder TM 2004\NASCAR_Thunder_2004.exe" = C:\Program Files\EA SPORTS\NASCAR Thunder TM 2004\NASCAR_Thunder_2004.exe:*:Enabled:NASCAR Thunder TM 2004
"C:\Documents and Settings\Mike Unser\Application Data\Juniper Networks\Juniper Terminal Services Client\dsTermServ.exe" = C:\Documents and Settings\Mike Unser\Application Data\Juniper Networks\Juniper Terminal Services Client\dsTermServ.exe:*:Enabled:Juniper Terminal Services Client – (Juniper Networks)
"C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe" = C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax – (Intuit, Inc.)
"C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe" = C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager – (Intuit, Inc.)
"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server – (Intuit Inc.)
"C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe" = C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe:*:Enabled:McAfee Shared Service Host – (McAfee, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{01DAB7E2-DEC5-4FBD-893E-612FA6758A4D}" = PrintMaster Platinum 17
"{04410044-9149-45C6-A806-F2BF9CFCE762}" = Microsoft Encarta Encyclopedia Standard 2004
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0F756CD9-4A1E-409B-B101-601DDC4C03AA}" = Qualxserve Service Agreement
"{11B569C2-4BF6-4ED0-9D17-A4273943CB24}" = Adobe Photoshop Album 2.0 Starter Edition
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1CE59656-4104-44AA-00BF-D2546C7EA497}" = Tiger Woods PGA TOUR 06
"{1D643CD7-4DD6-11D7-A4E0-000874180BB3}" = Microsoft Money 2004
"{1F51A0CA-2BDD-474E-BB90-C7FA8EA78F52}" = ImageMixer VCD/DVD2 for OLYMPUS
"{25CA5429-86C2-4FA3-B48A-74B0272280A1}" = Hoyle Friday Night Poker
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Dell Media Experience
"{26A24AE4-039D-4CA4-87B4-2F83216023FF}" = Java™ 6 Update 23
"{28B80CEB-9340-4726-84D3-DF70C4349782}" = Cabela's Big Game Hunter 2006 Season
"{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation
"{2A697B53-0DE3-42DA-B41D-C3F804B1C538}" = iTunes
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
"{2FD94FBC-07AE-475C-B522-BFE899B9048E}" = Garmin WebUpdater
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{35D5A740-EAA2-012B-AD08-000000000000}" = TurboTax 2009 waziper
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{45EBDA59-D33B-433A-956E-B2F236468B56}" = MUSICMATCH® Jukebox
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{54F90B55-BEB3-4F0D-8802-228822FA5921}" = WordPerfect Office 11
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{625BD732-ACDF-4552-BF22-98EBB413B6F3}" = McAfee Shredder
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{68D60342-7686-45C9-B8EB-40EF843D0460}" = Dell Networking Guide
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6ECB39BD-73C2-44DD-B1A0-898207C58D8B}" = HP Photo and Imaging 2.0 - All-in-One Drivers
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{81A34902-9D0B-4920-A25C-4CDC5D14B328}" = Jasc Paint Shop Pro 8 Dell Edition
"{86C1A488-24AD-42F0-BCEF-FDB11FC2BEFA}" = NetZero For Riverdeep
"{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8C64E145-54BA-11D6-91B1-00500462BE80}" = Microsoft Money 2004 System Pack
"{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}" = Napster Burn Engine
"{8E666407-AC41-46a2-9692-6C7BFCBFDD37}" = Memeo Instant Backup
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90520409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Visio Viewer 2003 (English)
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{91E30409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{9867A917-5D17-40DE-83BA-BEA5293194B1}" = HP Photo and Imaging 2.0 - All-in-One
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = AnswerWorks 5.0 English Runtime
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A586D09E-1D2C-11D3-9A6B-00105A98B681}" = Microsoft Picture It! Express 2000
"{A71D5E81-B967-43DB-93D7-FD31BFB95748}" = MobileMe Control Panel
"{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X (10.0.1)
"{AF363EA8-CB9F-40EC-90E0-A46AD9C78EB0}" = Laugh, Smile & Learn™
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper
"{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport
"{B376402D-58EA-45EA-BD50-DD924EB67A70}" = HP Memories Disc
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BA820A24-704B-428D-9904-71A10DAC1372}" = OLYMPUS Master
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C27BC2A2-30DD-4014-B22E-63EB0DB572F9}" = Logitech Webcam Software
"{C3A11907-930D-41AC-A135-CC3B12F92011}" = Seagate Dashboard
"{C73F2967-062E-48F2-A462-D335B8950183}" = Safari
"{C900EF06-2E76-49C7-8DB0-41F629B21DC5}" = hp psc 1200 series
"{C98F2FE6-5AF5-11D6-8209-00D0B701C7B5}" = Terayon DOCSIS Modem
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC000127-5E5D-4A1C-90CB-EEAAAC1E3AC0}" = Jasc Paint Shop Photo Album
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7
"{DD763351-DE1C-4EA7-986D-A6EC8AF76434}" = TurboTax 2008 waziper
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp
"{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}" = WexTech AnswerWorks
"{EE8B9C76-1E07-4C26-8587-8184024FA345}" = Hoyle Card Games 2005
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility
"{FC4ED75D-916C-4A8C-BB67-3C6F6E06D62B}" = Banctec Service Agreement
"82A44D22-9452-49FB-00FB-CEC7DCAF7E23" = EA SPORTS online 2006
"Ad-Aware" = Ad-Aware
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3
"BCM V.92 56K Modem" = BCM V.92 56K Modem
"BFG-Hells Kitchen" = Hell's Kitchen
"Casino Collection" = Casino Collection
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"CutePDF Writer Installation" = CutePDF Writer 2.8
"DeductionPro 2004-05" = DeductionPro 2004-05
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"DivX Content Uploader" = DivX Content Uploader
"ESET Online Scanner" = ESET Online Scanner v3
"Foxit Creator" = Foxit Creator
"Foxit Reader" = Foxit Reader
"Google Updater" = Google Updater
"GPL Ghostscript 8.64" = GPL Ghostscript 8.64
"HP PSC 1200 Series" = HP Photo and Imaging 2.0 - hp psc 1200 series
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{BA820A24-704B-428D-9904-71A10DAC1372}" = OLYMPUS Master
"KeePass Password Safe_is1" = KeePass Password Safe 1.17
"lvdrivers_12.10" = Logitech Webcam Software Driver Package
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Virtual Technician" = McAfee Virtual Technician
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.15)" = Mozilla Firefox (3.6.15)
"MSC" = McAfee SecurityCenter
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSN Music Assistant" = MSN Music Assistant
"Music Works" = Music Works Screen Saver
"Neoteris_Secure_Application_Manager" = Secure Application Manager
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Paradise Poker" = Paradise Poker
"PokerStars.net" = PokerStars.net
"PROSet" = Intel® PRO Network Connections Drivers
"Quicken WillMaker Plus 2006" = Quicken WillMaker Plus 2006
"RealPlayer 6.0" = RealPlayer
"Shockwave" = Shockwave
"StreetPlugin" = Learn2 Player (Uninstall Only)
"TaxCut 2004" = TaxCut 2004
"TaxCut Deluxe 2005" = TaxCut Deluxe 2005
"TurboTax 2008" = TurboTax 2008
"TurboTax 2009" = TurboTax 2009
"TurboTax Basic 2003" = TurboTax Basic 2003
"TurboTax Deluxe 2007" = TurboTax Deluxe 2007
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WebPost" = Microsoft Web Publishing Wizard 1.52
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Photos Drag-Drop Uploader 1v7" = Yahoo! Photos Easy Upload Tool 1v7
"Zuma's Revenge!" = Zuma's Revenge!

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/25/2011 7:03:38 PM | Computer Name = OFFICE | Source = Windows Search Service | ID = 3013
Description = The entry SECURITYCENTER.LNK> in the hash map cannot be updated. Context: Application, SystemIndex
Catalog Details: A device attached to the system is not functioning. (0x8007001f)


Error - 3/25/2011 7:03:38 PM | Computer Name = OFFICE | Source = Windows Search Service | ID = 3013
Description = The entry SECURITYCENTER.LNK> in the hash map cannot be updated. Context: Application, SystemIndex
Catalog Details: A device attached to the system is not functioning. (0x8007001f)


Error - 3/25/2011 7:07:43 PM | Computer Name = OFFICE | Source = McLogEvent | ID = 5051
Description = A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
took longer than 90000 ms to complete a request. The process will be terminated.
Thread
id : 2924 (0xb6c) Thread address : 0x7C90E514 Thread message : Build VSCORE.14.2.0.794
/ 5400.1158 Object being scanned = \Device\HarddiskVolume2\Program Files\Java\jre6\bin\deploy.dll

by C:\Program Files\Java\jre6\bin\jqs.exe 4(0)(0) 4(0)(0) 7200(0)(0) 7595(0)(0)

7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0)

Error - 3/25/2011 7:10:06 PM | Computer Name = OFFICE | Source = McLogEvent | ID = 5051
Description = A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
took longer than 90000 ms to complete a request. The process will be terminated.
Thread
id : 3704 (0xe78) Thread address : 0x7C90E514 Thread message : Build VSCORE.14.2.0.794
/ 5400.1158 Object being scanned = \Device\HarddiskVolume2\Program Files\McAfee\SiteAdvisor\SaSSHMod.dll

by C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe 4(0)(0) 4(0)(0) 7200(0)(0)

7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0)

Error - 3/25/2011 7:12:20 PM | Computer Name = OFFICE | Source = McLogEvent | ID = 5051
Description = A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
took longer than 90000 ms to complete a request. The process will be terminated.
Thread
id : 3948 (0xf6c) Thread address : 0x7C90E514 Thread message : Build VSCORE.14.2.0.794
/ 5400.1158 Object being scanned = \Device\HarddiskVolume2\Program Files\Lavasoft\Ad-Aware\lavalicense.dll

by C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe 4(0)(0) 4(0)(0) 7200(0)(0)

7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0)

Error - 3/25/2011 7:14:37 PM | Computer Name = OFFICE | Source = McLogEvent | ID = 5051
Description = A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
took longer than 90000 ms to complete a request. The process will be terminated.
Thread
id : 1336 (0x538) Thread address : 0x7C90E514 Thread message : Build VSCORE.14.2.0.794
/ 5400.1158 Object being scanned = \Device\HarddiskVolume2\Program Files\Lavasoft\Ad-Aware\lavalicense.dll

by C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe 4(0)(0) 4(0)(0) 7200(0)(0)

7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0)

Error - 3/25/2011 7:16:30 PM | Computer Name = OFFICE | Source = McLogEvent | ID = 5051
Description = A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
took longer than 90000 ms to complete a request. The process will be terminated.
Thread
id : 3212 (0xc8c) Thread address : 0x7C90E514 Thread message : Build VSCORE.14.2.0.794
/ 5400.1158 Object being scanned = \Device\HarddiskVolume2\Program Files\Lavasoft\Ad-Aware\lavalicense.dll

by C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe 4(0)(0) 4(0)(0) 7200(0)(0)

7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0)

Error - 3/25/2011 7:18:23 PM | Computer Name = OFFICE | Source = McLogEvent | ID = 5051
Description = A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
took longer than 90000 ms to complete a request. The process will be terminated.
Thread
id : 3120 (0xc30) Thread address : 0x7C90E514 Thread message : Build VSCORE.14.2.0.794
/ 5400.1158 Object being scanned = \Device\HarddiskVolume2\Program Files\Lavasoft\Ad-Aware\lavalicense.dll

by C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe 4(0)(0) 4(0)(0) 7200(0)(0)

7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0)

Error - 3/25/2011 7:37:33 PM | Computer Name = OFFICE | Source = MsiInstaller | ID = 11327
Description = Product: Microsoft Office 2000 Premium – Error 1327. Invalid Drive:
E:\

Error - 3/25/2011 7:38:01 PM | Computer Name = OFFICE | Source = McLogEvent | ID = 5051
Description = A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
took longer than 90000 ms to complete a request. The process will be terminated.
Thread
id : 3844 (0xf04) Thread address : 0x7C90E514 Thread message : Build VSCORE.14.2.0.794
/ 5400.1158 Object being scanned = \Device\HarddiskVolume2\Program Files\McAfee\SiteAdvisor\McIEPlg.dll

by C:\Documents and Settings\Mike Unser\Desktop\iexplore.exe 4(0)(0) 4(0)(0) 7200(0)(0)

7595(0)(0) 7005(0)(0) 7004(0)(0) 5006(0)(0) 5004(0)(0)

[ System Events ]
Error - 3/25/2011 8:09:42 PM | Computer Name = OFFICE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 3/25/2011 8:11:16 PM | Computer Name = OFFICE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 3/25/2011 8:11:24 PM | Computer Name = OFFICE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNaiAnn with
arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

Error - 3/25/2011 8:11:24 PM | Computer Name = OFFICE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNaiAnn with
arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

Error - 3/25/2011 8:11:25 PM | Computer Name = OFFICE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNaiAnn with
arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

Error - 3/25/2011 8:11:25 PM | Computer Name = OFFICE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNaiAnn with
arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

Error - 3/25/2011 8:11:25 PM | Computer Name = OFFICE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNaiAnn with
arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

Error - 3/25/2011 8:11:25 PM | Computer Name = OFFICE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNaiAnn with
arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

Error - 3/25/2011 8:11:25 PM | Computer Name = OFFICE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNaiAnn with
arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}

Error - 3/25/2011 8:11:25 PM | Computer Name = OFFICE | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service McNaiAnn with
arguments "" in order to run the server: {DC7EF8E1-824F-4110-AB43-1604DA9B4F40}


< End of report >
Hi mikeinsurprise,

I see you have a copy of OTL unrenamed on your desktop. We can use this copy for the fix.

When OTL reboots your computer allow it to reboot to normal windows.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
[2011/03/23 06:41:12 | 000,016,664 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\e63lt3ed7f6e
[2011/03/23 04:45:11 | 000,000,000 | —- | M] () – C:\WINDOWS\Nhovij.bin
[2011/03/22 20:55:03 | 000,000,120 | —- | M] () – C:\WINDOWS\Lfuyiwitatuxof.dat
[2011/03/22 16:20:50 | 000,108,544 | RHS- | M] () – C:\WINDOWS\System32\webcheckz.dll

:Files
ipconfig /flushdns /c
C:\WINDOWS\tasks\Crhozpaa.job
C:\WINDOWS\tasks\BDYLLNDNB.job
C:\WINDOWS\tasks\PYHPB.job
C:\WINDOWS\System32\drivers\lvuvc.hs
C:\WINDOWS\System32\drivers\logiflt.iad
C:\Documents and Settings\Mike Unser\Local Settings\Application Data\jrgqfpweq
C:\WINDOWS\ohimohagiqinic.dll
C:\WINDOWS\WMFTA2.dll

:Commands
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.


Next
Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

[external image: Posted Image]
Click the "Scan" button to start scan

[external image: Posted Image]
On completion of the scan click save log, save it to your desktop and post in your next reply

Please post back with
  • OTL fix log
  • aswmbr log
How's the computer?

Thanks
Computer is still not allowing me to do anything in normal mode. I ran the OTL "RUN FIX" in safe mode it rebooted the computer but it did not save the OTL Fix log. I also downloaded aswMBR.exe in normal mode but when I double clicked on it I got the same pop up window "open with what program". I ran aswMBR.exe in safemode / administrator and saved the log. So computer is still aswMBR version 0.9.4 Copyright© 2011 AVAST Software Run date: 2011-03-26 08:22:16 —————————– 08:22:16.578 OS Version: Windows 5.1.2600 Service Pack 3 08:22:16.578 Number of processors: 2 586 0x209 08:22:16.578 ComputerName: OFFICE UserName: 08:22:22.312 Initialize success 08:22:37.703 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdePort1 08:22:37.703 Disk 0 Vendor: Maxtor_6Y120M0 YAR51EW0 Size: 114440MB BusType: 3 08:22:37.718 Device \Device\Ide\IdeDeviceP1T0L0-e -> \??\IDE#DiskMaxtor_6Y120M0__________________________YAR51EW0#3359544c3859454120 2020202020202020202020#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} not found 08:22:37.718 Device \Driver\atapi -> DriverStartIo 8434727f 08:22:39.750 Disk 0 MBR read successfully 08:22:39.750 Disk 0 MBR scan 08:22:39.765 Disk 0 TDL4@MBR code has been found 08:22:39.765 Disk 0 MBR hidden 08:22:39.781 Disk 0 MBR [TDL4] **ROOTKIT** 08:22:39.796 Disk 0 trace - called modules: 08:22:39.796 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x84347439]<< 08:22:39.812 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x84369ab8] 08:22:39.828 3 CLASSPNP.SYS[f7517fd7] -> nt!IofCallDriver -> [0x842fa9d8] 08:22:39.843 \Driver\atapi[0x843777c8] -> IRP_MJ_CREATE -> 0x84347439 08:22:39.859 Scan finished successfully bad, cannot do anything in normal mode.
Hi mikeinsurprise,

It's better if we run these tools from your usual account if possible.

The OTL fix log can be found at C:\_OTL\MovedFiles It will have a file name consisting of numders that reflect the date and time stamp the fix was ran. It will be something similar to 03262011_111009.log . Please copy and paste the contents into your next reply.

Re-Run aswMBR

Click Scan

On completion of the scan

Click the FixButton

[external image: Posted Image]

Save the log as before and post in your next reply.


Reboot and run aswmbr again this time just do a scan and save the log.

Please post back with
  • OTL fix log
  • aswmbr log
Thanks
Hi Oldman960 - Thanks for the help finding the fix log. Attached are the OTL fix lob, the log file from aswMBR "FIX" and the log file from aswMBR after the reboot and scan only. I did all of this under my normal log on. Still have problems when I double click on aswMBR.exe i get the open with what program window, then I have to right click on the aswMBR.exe icon and do a Run As and click on current user and uncheck protect my computer.

OTL FIX LOG


All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
File C:\Documents and Settings\All Users\Application Data\e63lt3ed7f6e not found.
C:\WINDOWS\Nhovij.bin moved successfully.
C:\WINDOWS\Lfuyiwitatuxof.dat moved successfully.
File move failed. C:\WINDOWS\SYSTEM32\webcheckz.dll scheduled to be moved on reboot.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Mike Unser\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Mike Unser\Desktop\cmd.txt deleted successfully.
File move failed. C:\WINDOWS\tasks\Crhozpaa.job scheduled to be moved on reboot.
File move failed. C:\WINDOWS\tasks\BDYLLNDNB.job scheduled to be moved on reboot.
File move failed. C:\WINDOWS\tasks\PYHPB.job scheduled to be moved on reboot.
C:\WINDOWS\System32\drivers\lvuvc.hs moved successfully.
C:\WINDOWS\System32\drivers\logiflt.iad moved successfully.
File\Folder C:\Documents and Settings\Mike Unser\Local Settings\Application Data\jrgqfpweq not found.
File\Folder C:\WINDOWS\ohimohagiqinic.dll not found.
File\Folder C:\WINDOWS\WMFTA2.dll not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 7011364 bytes
->Flash cache emptied: 678 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56543 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 206748 bytes
->Flash cache emptied: 596 bytes

User: Mike Unser
->Temp folder emptied: 517456881 bytes
->Temporary Internet Files folder emptied: 44105155 bytes
->Java cache emptied: 247868 bytes
->FireFox cache emptied: 65940543 bytes
->Apple Safari cache emptied: 14336 bytes
->Flash cache emptied: 2102586 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 137540932 bytes
->Java cache emptied: 18410 bytes
->Flash cache emptied: 43520 bytes

User: Owner

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 58666 bytes
%systemroot%\System32 .tmp files removed: 2675729 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 7804290 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 65988 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 749.00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 03262011_075959


aswMBR after "Fix" log

aswMBR version 0.9.4 Copyright© 2011 AVAST Software
Run date: 2011-03-26 13:41:25
—————————–
13:41:25.203 OS Version: Windows 5.1.2600 Service Pack 3
13:41:25.203 Number of processors: 2 586 0x209
13:41:25.203 ComputerName: OFFICE UserName:
13:41:26.953 Initialize success
13:41:33.015 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdePort1
13:41:33.015 Disk 0 Vendor: Maxtor_6Y120M0 YAR51EW0 Size: 114440MB BusType: 3
13:41:33.015 Device \Device\Ide\IdeDeviceP1T0L0-e -> \??\IDE#DiskMaxtor_6Y120M0__________________________YAR51EW0#3359544c3859454120
2020202020202020202020#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} not found
13:41:33.015 Device \Driver\atapi -> DriverStartIo 8437f27f
13:41:35.015 Disk 0 MBR read successfully
13:41:35.015 Disk 0 MBR scan
13:41:35.015 Disk 0 TDL4@MBR code has been found
13:41:35.015 Disk 0 MBR hidden
13:41:35.015 Disk 0 MBR [TDL4] **ROOTKIT**
13:41:35.015 Disk 0 trace - called modules:
13:41:35.015 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8437f439]<<
13:41:35.015 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8435bab8]
13:41:35.015 3 CLASSPNP.SYS[f7517fd7] -> nt!IofCallDriver -> [0x84368f18]
13:41:35.015 \Driver\atapi[0x843416e0] -> IRP_MJ_CREATE -> 0x8437f439
13:41:35.015 Scan finished successfully
13:41:47.000 Disk 0 fixing MBR
13:41:57.000 Disk 0 MBR restored successfully
13:41:57.000 Infection fixed successfully - please reboot ASAP


aswMBR after reboot log


aswMBR version 0.9.4 Copyright© 2011 AVAST Software
Run date: 2011-03-26 13:50:27
—————————–
13:50:27.203 OS Version: Windows 5.1.2600 Service Pack 3
13:50:27.203 Number of processors: 2 586 0x209
13:50:27.218 ComputerName: OFFICE UserName:
13:50:52.109 Initialize success
13:50:57.109 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e
13:50:57.109 Disk 0 Vendor: Maxtor_6Y120M0 YAR51EW0 Size: 114440MB BusType: 3
13:50:59.125 Disk 0 MBR read successfully
13:50:59.125 Disk 0 MBR scan
13:51:01.125 Disk 0 scanning sectors +234372285
13:51:01.156 Disk 0 scanning C:\WINDOWS\system32\drivers
13:51:48.343 Service scanning
13:51:50.484 Disk 0 trace - called modules:
13:51:50.484 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
13:51:50.484 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x84361ab8]
13:51:50.484 3 CLASSPNP.SYS[f74d7fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-e[0x84396d98]
13:51:50.484 Scan finished successfully
Hi mikeinsurprise,

Ok that took care of that one, let's see if we can get the rest of this sorted out.

Please read through these instructions to familarize yourself with what to expect when this tool runs

If you need to use the right click method to run this tool go ahead. If you need to run it in safe mode you will not be able to disable your security programs so boot back to safe mode and allow the tool to finish.


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the combofix log.
Hi Oldman 960 — I ran ComboFix as you instructed. I had to right click and do a run as. Then when it was going through its "start up" a bunch of open with windows started opening (IE, Firefox, were the two I recongnized and then a bunch of other ones) I canceled all the open with windows and ComboFix ran and rebooted the machine. When the machine rebooted there was an error that a .DLL file was missing. I clicked ok before I wrote what the file name was. Also after the reboot it seems like everything started up ok and I don't have to right click and run as on programs. I also think I may of messed up an closed the combfix window before it finished the log file. The window seemed to be open for about 20 minutes after start up. Here's the combo fix log file. If I really screwed it and need to rerun Combo Fix or anything else please let me know. ComboFix 11-03-26.01 - Mike Unser 03/26/2011 15:40:13.3.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.766.230 [GMT -7:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Firewall *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\Documents and Settings\Mike Unser\Local Settings\Application Data\{AA1F7949-20DE-494A-9C69-8373D168BCBA} C:\Documents and Settings\Mike Unser\Local Settings\Application Data\{AA1F7949-20DE-494A-9C69-8373D168BCBA}\chrome.manifest C:\Documents and Settings\Mike Unser\Local Settings\Application Data\{AA1F7949-20DE-494A-9C69-8373D168BCBA}\chrome\content\_cfg.js C:\Documents and Settings\Mike Unser\Local Settings\Application Data\{AA1F7949-20DE-494A-9C69-8373D168BCBA}\chrome\content\overlay.xul C:\Documents and Settings\Mike Unser\Local Settings\Application Data\{AA1F7949-20DE-494A-9C69-8373D168BCBA}\install.rdf C:\Documents and Settings\Mike Unser\My Documents\DPE.DUS ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . ——-\Legacy_6TO4 ——-\Legacy_ITLPERF ——-\Service_6to4 ——-\Service_itlperf ((((((((((((((((((((((((( Files Created from 2011-02-26 to 2011-03-26 ))))))))))))))))))))))))))))))) 2067-02-24 22:21:18 . 2003-02-05 11:02:00 79947 —-a-w- C:\WINDOWS\fw20.vxd 2011-03-26 14:59:09 . 2011-03-26 14:59:09 ——– d—–w- C:\Documents and Settings\Administrator\Local Settings\Application Data\Temp 2011-03-26 14:59:09 . 2011-03-26 14:59:09 ——– d—–w- C:\Documents and Settings\Administrator\Local Settings\Application Data\Adobe 2011-03-26 14:40:53 . 2011-03-26 14:40:53 ——– d—–w- C:\_OTL 2011-03-25 01:01:35 . 2011-03-25 01:01:35 ——– d-sh–w- C:\Documents and Settings\Administrator\PrivacIE 2011-03-24 04:46:21 . 2011-03-24 04:46:21 ——– d—–w- C:\Documents and Settings\Administrator\Application Data\Malwarebytes 2011-03-24 04:46:13 . 2010-12-21 01:09:00 38224 —-a-w- C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2011-03-24 04:46:09 . 2011-03-24 04:46:14 ——– d—–w- C:\Program Files\Malwarebytes' Anti-Malware 2011-03-24 04:46:09 . 2010-12-21 01:08:40 20952 —-a-w- C:\WINDOWS\system32\drivers\mbam.sys 2011-03-24 04:37:32 . 2011-03-24 04:37:32 ——– d—–w- C:\Documents and Settings\Mike Unser\Application Data\Windows Search 2011-03-24 04:37:32 . 2011-03-24 04:37:32 ——– d—–w- C:\Documents and Settings\Administrator\Application Data\Juniper Networks 2011-03-24 04:34:40 . 2011-03-24 04:34:40 ——– d-sh–w- C:\Documents and Settings\Administrator\IETldCache 2011-03-23 05:49:58 . 2011-03-23 05:49:59 ——– d—–w- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe 2011-03-23 05:49:58 . 2011-03-23 05:49:58 ——– d—–w- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Temp 2011-03-22 23:20:50 . 2011-03-22 23:20:50 108544 –sha-r- C:\WINDOWS\system32\webcheckz.dll 2011-03-09 22:12:21 . 2011-03-09 22:12:21 ——– d—–w- C:\Program Files\iPod 2011-03-09 22:12:02 . 2011-03-09 22:14:08 ——– d—–w- C:\Program Files\iTunes 2011-03-09 21:58:08 . 2011-03-09 21:58:09 ——– d—–w- C:\Program Files\Bonjour 2011-03-08 10:00:54 . 2011-03-08 10:00:54 ——– d-sh–w- C:\Documents and Settings\Default User\IETldCache 2011-03-05 22:14:00 . 2011-03-03 18:16:31 552376 —-a-w- C:\Program Files\Mozilla Firefox\uninstall\helper.exe (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2011-03-24 04:11:36 . 2009-11-24 18:02:18 398760 —-a-r- C:\WINDOWS\system32\cpnprt2.cid 2011-02-09 13:53:52 . 2008-09-24 04:14:04 186880 —-a-w- C:\WINDOWS\system32\encdec.dll 2011-02-09 13:53:52 . 2008-09-24 04:14:01 270848 —-a-w- C:\WINDOWS\system32\sbe.dll 2011-02-08 12:55:21 . 2011-02-06 00:59:41 16432 —-a-w- C:\WINDOWS\system32\lsdelete.exe 2011-02-06 02:33:53 . 2011-02-06 02:34:29 73728 —-a-w- C:\WINDOWS\system32\javacpl.cpl 2011-02-06 02:33:51 . 2011-02-06 02:34:29 472808 —-a-w- C:\WINDOWS\system32\deployJava1.dll 2011-02-06 00:35:43 . 2009-11-22 15:51:45 98392 —-a-w- C:\WINDOWS\system32\drivers\SBREDrv.sys 2011-02-02 07:58:35 . 2008-09-24 04:14:27 2067456 —-a-w- C:\WINDOWS\system32\mstscax.dll 2011-01-27 11:57:06 . 2008-09-24 04:14:27 677888 —-a-w- C:\WINDOWS\system32\mstsc.exe 2011-01-21 14:44:37 . 2008-09-24 04:12:50 439296 —-a-w- C:\WINDOWS\system32\shimgvw.dll 2011-01-07 14:09:02 . 2008-09-24 04:13:24 290048 —-a-w- C:\WINDOWS\system32\atmfd.dll 2010-12-31 13:10:33 . 2008-09-24 04:12:36 1854976 —-a-w- C:\WINDOWS\system32\win32k.sys 2010-10-14 05:28:54 . 2010-12-18 19:16:44 24376 —-a-w- C:\Program Files\mozilla firefox\components\Scriptff.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 18:09:36 460784] "DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 17:55:32 206064]
Hi mikeinsurprise,

Depending on what comfix is logging it can take some time. Anyway the log is incomplete and some very important sections are missing.

Do this first.

I need some information on some unidentified files. We will use Virustotal Please submit these files for analysis

To submit a file to virustotal, please click on this link

Http://www.virustotal.com

copy and paste the following into the upload a file box (one at a time if more than one file is listed)

C:\WINDOWS\system32\webcheckz.dll
C:\WINDOWS\fw20.vxd


scroll down a bit and click "send file", wait for the results and post them in your next reply.

Please note that sometimes the scans take a few minutes. Please ensure that the scan has completed and the results are complete before submitting the next sample. Also please make sure each result is clearly identified as to which sample they belong to.

Please rerun combofix. You should be able to run it in normal windows.

Please post back with
  • VirusTotal results
  • combofix log
Thanks
when I clicked on the link for Virustotal it wouldn't open the webpage. The hyperlink actually has it going to http://http//www.virustotal.com. Should it be http://virustotal.com? If yes, I went to that web page and tried to copy and paste the text in the upload file box and it wouldn't let me. I tried to type it in manually and it wouldn't let. Just gave me an option to browse for a file. I clicked on browse and pasted the files in the window on at a time.

when I submitted C:WINDOWS\System32\webcheckz.dll there was no scan. I looked in that folder and did not have that file, but I had ….C:\WINDOWS\System32\webcheck(2).dll and C:\WINDOWS\System32\webcheck.dll

here's that analysis for webcheck(2).dll

0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name: webcheck(2).dll
Submission date: 2011-03-27 01:46:03 (UTC)
Current status: queued queued analysing finished


Result: 0/ 41 (0.0%)
VT Community

not reviewed
Safety score: -
Compact Print results Antivirus Version Last Update Result
AhnLab-V3 2011.03.27.00 2011.03.26 -
AntiVir 7.11.5.79 2011.03.25 -
Antiy-AVL 2.0.3.7 2011.03.26 -
Avast 4.8.1351.0 2011.03.26 -
Avast5 5.0.677.0 2011.03.26 -
AVG 10.0.0.1190 2011.03.27 -
BitDefender 7.2 2011.03.27 -
CAT-QuickHeal 11.00 2011.03.26 -
ClamAV 0.96.4.0 2011.03.27 -
Commtouch 5.2.11.5 2011.03.24 -
Comodo 8118 2011.03.26 -
DrWeb 5.0.2.03300 2011.03.27 -
eSafe 7.0.17.0 2011.03.24 -
eTrust-Vet 36.1.8236 2011.03.25 -
F-Prot 4.6.2.117 2011.03.26 -
F-Secure 9.0.16440.0 2011.03.23 -
Fortinet 4.2.254.0 2011.03.26 -
GData 21 2011.03.27 -
Ikarus T3.1.1.97.0 2011.03.26 -
Jiangmin 13.0.900 2011.03.26 -
K7AntiVirus 9.94.4219 2011.03.26 -
McAfee 5.400.0.1158 2011.03.27 -
McAfee-GW-Edition 2010.1C 2011.03.26 -
Microsoft 1.6702 2011.03.26 -
NOD32 5988 2011.03.26 -
Norman 6.07.03 2011.03.26 -
nProtect 2011-02-10.01 2011.02.15 -
Panda 10.0.3.5 2011.03.26 -
PCTools 7.0.3.5 2011.03.26 -
Prevx 3.0 2011.03.27 -
Rising 23.50.05.05 2011.03.26 -
Sophos 4.64.0 2011.03.26 -
SUPERAntiSpyware 4.40.0.1006 2011.03.26 -
Symantec 20101.3.0.103 2011.03.27 -
TheHacker 6.7.0.1.159 2011.03.26 -
TrendMicro 9.200.0.1012 2011.03.26 -
TrendMicro-HouseCall 9.200.0.1012 2011.03.27 -
VBA32 3.12.14.3 2011.03.25 -
VIPRE 8831 2011.03.27 -
ViRobot 2011.3.26.4378 2011.03.26 -
VirusBuster 13.6.271.0 2011.03.26 -
Additional informationShow all
MD5 : 111718867ad27976b413c5345ef91e10
SHA1 : a3a943301a1b13b9a3e67bbf5f91633a154bd8e8
SHA256: 5182884b8025f08b8da0a18dad426b670a167eccf8a0203ddf0a9ac3f5d51bb7
ssdeep: 6144:QeMzUBGDNfvaaSZVoK4YCS2ILfRhXdcpAk:L+C/CSVJhq
File size : 233472 bytes
First seen: 2009-12-08 20:17:29
Last seen : 2011-03-27 01:46:03
TrID:
DirectShow filter (80.0%)
Win32 Executable MS Visual C++ (generic) (14.9%)
Win32 Executable Generic (3.3%)
Generic Win/DOS Executable (0.7%)
DOS Executable Generic (0.7%)
sigcheck:
publisher….: Microsoft Corporation
copyright….: © Microsoft Corporation. All rights reserved.
product……: Windows_ Internet Explorer
description..: Web Site Monitor
original name: WEBCHECK.DLL
internal name: WEBCHECK.DLL
file version.: 7.00.6000.16945 (vista_gdr.091027-0049)
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned

PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0x1855
timedatestamp….: 0x4AE94872 (Thu Oct 29 07:46:58 2009)
machinetype……: 0x14c (I386)

[[ 4 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0x28959, 0x28A00, 6.46, 2de8d7765b1364eb4980c6212c0c97d3
.data, 0x2A000, 0xA2C, 0x800, 2.50, 0fac2a26b4dacd7c66872a8bdca9139f
.rsrc, 0x2B000, 0xD610, 0xD800, 4.96, 2cfb43bfe02e821a27df215a28d31523
.reloc, 0x39000, 0x2038, 0x2200, 6.56, 9433fafc24512cab5b6fdb65b1220ed0

[[ 9 import(s) ]]
msvcrt.dll: wcschr, memcpy, _vsnwprintf, _vsnprintf, bsearch, _wcsnicmp, _wcsicmp, wcsncmp, __dllonexit, _unlock, _adjust_fdiv, _amsg_exit, _initterm, free, malloc, _XcptFilter, _onexit, _lock, memset
ntdll.dll: RtlUnwind
IEFRAME.dll: -, -
GDI32.dll: GetDeviceCaps
KERNEL32.dll: UnmapViewOfFile, GetSystemDefaultUILanguage, GetUserDefaultUILanguage, FindResourceW, SearchPathW, CreateFileMappingW, GetModuleHandleW, CreateActCtxW, MapViewOfFile, FindResourceExW, LoadLibraryExW, LoadResource, SystemTimeToFileTime, GetSystemTime, lstrlenW, MultiByteToWideChar, FormatMessageW, LocalFree, LocalAlloc, lstrlenA, InterlockedIncrement, InterlockedDecrement, GetLocalTime, GetProcAddress, LoadLibraryW, FreeLibrary, LocalReAlloc, GetUserDefaultLCID, CopyFileW, GlobalUnlock, GlobalLock, FileTimeToSystemTime, GetLocaleInfoW, GetTickCount, FormatMessageA, GetACP, LocalFileTimeToFileTime, CompareStringA, SetLastError, GetLastError, CloseHandle, CreateFileW, lstrcmpiA, HeapAlloc, GetProcessHeap, HeapFree, WideCharToMultiByte, GetSystemTimeAsFileTime, LoadLibraryA, GetTimeFormatW, GetDateFormatW, GetWindowsDirectoryW, GetModuleFileNameW, GetVersionExW, DisableThreadLibraryCalls, lstrcmpA, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, ReadFile, InterlockedExchange, Sleep, InterlockedCompareExchange, QueryPerformanceCounter, GetCurrentThreadId, GetCurrentProcessId, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, ReleaseActCtx, ActivateActCtx, DeactivateActCtx, RaiseException
USER32.dll: DialogBoxParamW, GetWindowRect, GetDC, LoadStringW, LoadStringA, SendMessageW, PostMessageW, FindWindowW, DestroyWindow, RegisterWindowMessageW, SetTimer, KillTimer, IsDlgButtonChecked, GetWindowLongW, IsWindow, GetWindowTextW, MessageBoxW, MessageBoxIndirectW, EnableWindow, GetDlgItem, SetWindowPos, ReleaseDC, GetClientRect, GetSysColor, GetMenuItemCount, GetMenuItemInfoW, CreatePopupMenu, GetSubMenu, RemoveMenu, PeekMessageW, DispatchMessageW, GetPropW, SetPropW, RemovePropW, GetForegroundWindow, CheckDlgButton, GetParent, CheckRadioButton, EnableMenuItem, SetMenuDefaultItem, LoadIconW, GetDlgItemTextW, GetDlgItemInt, SendDlgItemMessageW, SetDlgItemInt, GetSystemMetrics, DestroyIcon, LoadImageW, LoadCursorW, SetCursor, LoadMenuW, DestroyMenu, SetMenuItemInfoW, RegisterClipboardFormatW, RegisterClassW, DefWindowProcW, EndDialog, SetWindowLongW, SetDlgItemTextW, ShowWindow, MessageBeep, GetDesktopWindow, CreateWindowExW, SetDlgItemTextA
ADVAPI32.dll: RegEnumValueW, RegEnumKeyW, RegQueryInfoKeyW, RegDeleteValueW, RegQueryValueW, RegQueryValueExW, RegSetValueExW, RegEnumKeyExW, RegCreateKeyExW, RegOpenKeyExW, RegCloseKey
SHLWAPI.dll: -, StrSpnA, StrCSpnA, UrlCombineW, -, -, PathStripPathW, PathAppendW, -, SHEnumValueW, -, UrlCompareW, StrTrimW, SHGetValueW, StrChrW, SHRegGetValueW, SHDeleteKeyW, StrCmpIW, PathRemoveBlanksW, StrCmpW, StrDupW, StrRChrW, -, PathFindFileNameW, PathCombineW, PathIsDirectoryW, -, StrCmpNIW, PathFindExtensionW, PathIsURLW, -, -, -, -, SHStrDupW, StrFormatByteSizeW
iertutil.dll: -, -, -, -, -

[[ 2 export(s) ]]
DllCanUnloadNow, DllGetClassObject

ExifTool:
file metadata
CharacterSet: Unicode
CodeSize: 166400
CompanyName: Microsoft Corporation
EntryPoint: 0x1855
FileDescription: Web Site Monitor
FileFlagsMask: 0x003f
FileOS: Windows NT 32-bit
FileSize: 228 kB
FileSubtype: 0
FileType: Win32 DLL
FileVersion: 7.00.6000.16945 (vista_gdr.091027-0049)
FileVersionNumber: 7.0.6000.16945
ImageVersion: 6.0
InitializedDataSize: 67072
InternalName: WEBCHECK.DLL
LanguageCode: English (U.S.)
LegalCopyright: Microsoft Corporation. All rights reserved.
LinkerVersion: 8.0
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 6.0
ObjectFileType: Dynamic link library
OleSelfRegister:
OriginalFilename: WEBCHECK.DLL
PEType: PE32
ProductName: Windows Internet Explorer
ProductVersion: 7.00.6000.16945
ProductVersionNumber: 7.0.6000.16945
Subsystem: Windows GUI
SubsystemVersion: 5.1
TimeStamp: 2009:10:29 08:46:58+01:00
UninitializedDataSize: 0



VT Community

0
This file has never been reviewed by any VT Community member. Be the first one to comment on it!


Also had C:\WINDOWS\System32\webcheck.dll


1 VT Community user(s) with a total of 1764 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name: webcheck.dll
Submission date: 2011-03-27 01:50:48 (UTC)
Current status: queued queued analysing finished


Result: 0/ 43 (0.0%)
VT Community

goodware
Safety score: 100.0%
Compact Print results Antivirus Version Last Update Result
AhnLab-V3 2011.03.26.00 2011.03.25 -
AntiVir 7.11.5.79 2011.03.25 -
Antiy-AVL 2.0.3.7 2011.03.26 -
Avast 4.8.1351.0 2011.03.26 -
Avast5 5.0.677.0 2011.03.26 -
AVG 10.0.0.1190 2011.03.26 -
BitDefender 7.2 2011.03.26 -
CAT-QuickHeal 11.00 2011.03.26 -
ClamAV 0.96.4.0 2011.03.26 -
Commtouch 5.2.11.5 2011.03.24 -
Comodo 8111 2011.03.26 -
DrWeb 5.0.2.03300 2011.03.26 -
Emsisoft 5.1.0.4 2011.03.26 -
eSafe 7.0.17.0 2011.03.24 -
eTrust-Vet None None.. -
F-Prot 4.6.2.117 2011.03.25 -
F-Secure 9.0.16440.0 2011.03.23 -
Fortinet 4.2.254.0 2011.03.26 -
GData 21 2011.03.26 -
Ikarus T3.1.1.97.0 2011.03.26 -
Jiangmin 13.0.900 2011.03.26 -
K7AntiVirus 9.94.4219 2011.03.26 -
Kaspersky 7.0.0.125 2011.03.26 -
McAfee 5.400.0.1158 2011.03.26 -
McAfee-GW-Edition 2010.1C 2011.03.26 -
Microsoft 1.6702 None.. -
NOD32 5987 2011.03.26 -
Norman 6.07.03 2011.03.26 -
nProtect 2011-02-10.01 2011.02.15 -
Panda 10.0.3.5 2011.03.26 -
PCTools 7.0.3.5 2011.03.26 -
Prevx 3.0 2011.03.27 -
Rising 23.50.05.05 2011.03.26 -
Sophos 4.64.0 2011.03.26 -
SUPERAntiSpyware 4.40.0.1006 2011.03.26 -
Symantec 20101.3.0.103 2011.03.26 -
TheHacker 6.7.0.1.156 2011.03.25 -
TrendMicro 9.200.0.1012 2011.03.26 -
TrendMicro-HouseCall 9.200.0.1012 2011.03.26 -
VBA32 3.12.14.3 2011.03.25 -
VIPRE 8824 2011.03.26 -
ViRobot 2011.3.26.4378 2011.03.26 -
VirusBuster 13.6.270.0 2011.03.25 -
Additional informationShow all
MD5 : cc8915db4e33e8fb29ca0d2dbf75306e
SHA1 : 42647487989a1481c061e34b54632a9eaae03cfd
SHA256: 6319c0580ffda989a2726814667c330f6a5c864d34b8c87645dd5a98e7a2c7fb
ssdeep: 3072:+olvPlT3BTdmmZyYdo8JUFCmECzJTX7v1ZsHgjBgM/lX4hxxNmfrmYGKdc0M://gb+6FCm
EmTxZsAjBJtohXNGXdcf
File size : 236544 bytes
First seen: 2009-04-02 13:40:42
Last seen : 2011-03-27 01:50:48
TrID:
DirectShow filter (43.0%)
Windows OCX File (26.3%)
Win64 Executable Generic (18.2%)
Win32 Executable MS Visual C++ (generic) (8.0%)
Win32 Executable Generic (1.8%)
sigcheck:
publisher….: Microsoft Corporation
copyright….: © Microsoft Corporation. All rights reserved.
product……: Windows_ Internet Explorer
description..: Web Site Monitor
original name: WEBCHECK.DLL
internal name: WEBCHECK.DLL
file version.: 8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned

PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0x1899
timedatestamp….: 0x49B3AD53 (Sun Mar 08 11:34:43 2009)
machinetype……: 0x14c (I386)

[[ 4 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0x2931D, 0x29400, 6.37, ef4df5715aff907d114001240631a7a1
.data, 0x2B000, 0xA24, 0xA00, 1.86, fc9ce50f0cd00ddb5bfbe84ba8d55de0
.rsrc, 0x2C000, 0xD630, 0xD800, 4.96, 1077836a6e026e1914605b37078a75ac
.reloc, 0x3A000, 0x2090, 0x2200, 6.59, 62736178c46b33404c890a62133f2c8e

[[ 10 import(s) ]]
msvcrt.dll: _unlock, __dllonexit, _lock, _onexit, bsearch, _vsnwprintf, _adjust_fdiv, _amsg_exit, _initterm, free, malloc, _vsnprintf, wcsncmp, _XcptFilter, _wcsicmp, _wcsnicmp, wcschr, memcpy, memset
ntdll.dll: RtlUnwind
IEFRAME.dll: -, -
GDI32.dll: GetDeviceCaps
KERNEL32.dll: ExpandEnvironmentStringsA, LoadResource, FindResourceExW, MapViewOfFile, CreateFileMappingW, UnmapViewOfFile, GetSystemDefaultUILanguage, GetUserDefaultUILanguage, FindResourceW, SearchPathW, GetModuleHandleW, CreateActCtxW, ReleaseActCtx, LoadLibraryExW, Sleep, SystemTimeToFileTime, GetSystemTime, lstrlenW, MultiByteToWideChar, FormatMessageW, LocalFree, LocalAlloc, lstrlenA, InterlockedIncrement, InterlockedDecrement, GetLocalTime, GetProcAddress, LoadLibraryW, FreeLibrary, LocalReAlloc, GetUserDefaultLCID, CopyFileW, GlobalUnlock, GlobalLock, FileTimeToSystemTime, GetLocaleInfoW, GetTickCount, FormatMessageA, GetACP, LocalFileTimeToFileTime, CompareStringA, SetLastError, GetLastError, CloseHandle, CreateFileW, lstrcmpiA, HeapAlloc, GetProcessHeap, HeapFree, WideCharToMultiByte, GetSystemTimeAsFileTime, LoadLibraryA, ActivateActCtx, GetDateFormatW, GetWindowsDirectoryW, GetModuleFileNameW, GetVersionExW, DisableThreadLibraryCalls, lstrcmpA, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, ReadFile, InterlockedExchange, GetTimeFormatW, InterlockedCompareExchange, QueryPerformanceCounter, GetCurrentThreadId, GetCurrentProcessId, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, DeactivateActCtx, RaiseException, GetPrivateProfileStringW, GetPrivateProfileStringA, lstrcmpW
USER32.dll: IsWindow, LoadStringW, LoadStringA, SendMessageW, PostMessageW, FindWindowW, GetWindowTextW, MessageBoxW, GetClientRect, GetSysColor, GetMenuItemCount, GetMenuItemInfoW, CreatePopupMenu, GetSubMenu, RemoveMenu, PeekMessageW, DispatchMessageW, GetPropW, SetPropW, RemovePropW, GetForegroundWindow, CheckDlgButton, GetParent, CheckRadioButton, EnableMenuItem, SetMenuDefaultItem, LoadIconW, GetDlgItemTextW, GetDlgItemInt, SendDlgItemMessageW, SetDlgItemInt, GetSystemMetrics, DestroyIcon, LoadImageW, LoadCursorW, SetCursor, LoadMenuW, DestroyMenu, RegisterClipboardFormatW, RegisterClassW, DefWindowProcW, EndDialog, SetWindowLongW, SetDlgItemTextW, ShowWindow, MessageBeep, GetDesktopWindow, SetDlgItemTextA, DialogBoxParamW, GetWindowRect, GetDC, ReleaseDC, SetWindowPos, GetDlgItem, EnableWindow, CreateWindowExW, MessageBoxIndirectW, GetWindowLongW, IsDlgButtonChecked, KillTimer, SetTimer, RegisterWindowMessageW, DestroyWindow
ADVAPI32.dll: RegEnumValueW, RegEnumKeyW, RegQueryInfoKeyW, RegDeleteValueW, RegQueryValueExA, RegOpenKeyExA, RegQueryValueW, RegQueryValueExW, RegSetValueExW, RegEnumKeyExW, RegCreateKeyExW, RegOpenKeyExW, RegCloseKey
SHLWAPI.dll: StrSpnA, SHGetValueW, StrChrW, SHRegGetValueW, SHDeleteKeyW, StrCmpIW, -, StrCmpW, StrDupW, StrRChrW, -, PathFindFileNameW, PathCombineW, PathIsDirectoryW, -, StrCmpNIW, PathFindExtensionW, PathIsURLW, -, -, SHStrDupW, StrFormatByteSizeW, PathRemoveBlanksW, StrTrimW, UrlCompareW, -, SHEnumValueW, PathAppendW, PathStripPathW, -, -, UrlCombineW, StrCSpnA
iertutil.dll: -, -, -, -, -
MLANG.dll: -

[[ 2 export(s) ]]
DllCanUnloadNow, DllGetClassObject

ExifTool:
file metadata
CharacterSet: Unicode
CodeSize: 168960
CompanyName: Microsoft Corporation
EntryPoint: 0x1899
FileDescription: Web Site Monitor
FileFlagsMask: 0x003f
FileOS: Windows NT 32-bit
FileSize: 231 kB
FileSubtype: 0
FileType: Win32 DLL
FileVersion: 8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
FileVersionNumber: 8.0.6001.18702
ImageVersion: 6.0
InitializedDataSize: 67072
InternalName: WEBCHECK.DLL
LanguageCode: English (U.S.)
LegalCopyright: Microsoft Corporation. All rights reserved.
LinkerVersion: 8.0
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 6.0
ObjectFileType: Dynamic link library
OleSelfRegister:
OriginalFilename: WEBCHECK.DLL
PEType: PE32
ProductName: Windows Internet Explorer
ProductVersion: 8.00.6001.18702
ProductVersionNumber: 8.0.6001.18702
Subsystem: Windows GUI
SubsystemVersion: 5.1
TimeStamp: 2009:03:08 12:34:43+01:00
UninitializedDataSize: 0



VT Community

1
User:Drexter

Reputation:1764 credits

Comment date:2010-12-21 03:40:57 (UTC)
Goodware
Tags: Goodware,






C:\WINDOWS\fw20.vxd
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name: fw20.vxd
Submission date: 2011-03-27 01:38:27 (UTC)
Current status: finished
Result: 0 /43 (0.0%)
VT Community

not reviewed
Safety score: -
Compact Print results Antivirus Version Last Update Result
AhnLab-V3 2011.03.26.00 2011.03.25 -
AntiVir 7.11.5.79 2011.03.25 -
Antiy-AVL 2.0.3.7 2011.03.26 -
Avast 4.8.1351.0 2011.03.26 -
Avast5 5.0.677.0 2011.03.26 -
AVG 10.0.0.1190 2011.03.26 -
BitDefender 7.2 2011.03.26 -
CAT-QuickHeal 11.00 None.. -
ClamAV 0.96.4.0 2011.03.26 -
Commtouch 5.2.11.5 2011.03.24 -
Comodo 8111 2011.03.26 -
DrWeb 5.0.2.03300 2011.03.26 -
Emsisoft 5.1.0.4 2011.03.26 -
eSafe 7.0.17.0 2011.03.24 -
eTrust-Vet 36.1.8236 2011.03.25 -
F-Prot 4.6.2.117 2011.03.26 -
F-Secure 9.0.16440.0 2011.03.23 -
Fortinet 4.2.254.0 2011.03.26 -
GData 21 2011.03.26 -
Ikarus T3.1.1.97.0 2011.03.26 -
Jiangmin 13.0.900 2011.03.26 -
K7AntiVirus 9.94.4219 2011.03.26 -
Kaspersky 7.0.0.125 2011.03.26 -
McAfee 5.400.0.1158 2011.03.26 -
McAfee-GW-Edition 2010.1C 2011.03.26 -
Microsoft 1.6702 2011.03.26 -
NOD32 5987 2011.03.26 -
Norman 6.07.03 2011.03.26 -
nProtect 2011-02-10.01 2011.02.15 -
Panda 10.0.3.5 2011.03.26 -
PCTools 7.0.3.5 2011.03.26 -
Prevx 3.0 2011.03.27 -
Rising 23.50.05.05 2011.03.26 -
Sophos 4.64.0 2011.03.26 -
SUPERAntiSpyware 4.40.0.1006 2011.03.26 -
Symantec 20101.3.0.103 2011.03.26 -
TheHacker 6.7.0.1.157 2011.03.26 -
TrendMicro 9.200.0.1012 2011.03.26 -
TrendMicro-HouseCall 9.200.0.1012 2011.03.26 -
VBA32 3.12.14.3 2011.03.25 -
VIPRE 8825 2011.03.26 -
ViRobot 2011.3.26.4378 2011.03.26 -
VirusBuster 13.6.270.0 2011.03.25 -
Additional informationShow all
MD5 : fdccfcb07a5ef1b4da039834b07e5fe7
SHA1 : 9a37023866c6100a04996911eff4e01c8994e80a
SHA256: dc3eda14d223857f128ef43fb920571c32285f6721d1c057ae0e0003b1788985
ssdeep: -
File size : 79947 bytes
First seen: 2009-06-12 03:16:04
Last seen : 2011-03-27 01:38:27
Magic: MS-DOS executable, LE executable for MS Windows (VxD)
TrID:
Generic Win/DOS Executable (49.5%)
DOS Executable Generic (49.5%)
VXD Driver (0.7%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned

PEiD: -
ExifTool:
-


VT Community

0
This file has never been reviewed by any VT Community member. Be the first one to comment on it!
VirusTotal Team

Here's the log for Combo Fix

ComboFix 11-03-26.01 - Mike Unser 03/26/2011 19:04:26.4.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.766.145 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
—- Previous Run ——-
.
c:\documents and settings\Mike Unser\Local Settings\Application Data\{AA1F7949-20DE-494A-9C69-8373D168BCBA}\chrome.manifest
c:\documents and settings\Mike Unser\Local Settings\Application Data\{AA1F7949-20DE-494A-9C69-8373D168BCBA}\chrome\content\_cfg.js
c:\documents and settings\Mike Unser\Local Settings\Application Data\{AA1F7949-20DE-494A-9C69-8373D168BCBA}\chrome\content\overlay.xul
c:\documents and settings\Mike Unser\Local Settings\Application Data\{AA1F7949-20DE-494A-9C69-8373D168BCBA}\install.rdf
c:\documents and settings\Mike Unser\My Documents\DPE.DUS
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_6TO4
——-\Legacy_ITLPERF
——-\Service_6to4
——-\Service_itlperf
.
.
((((((((((((((((((((((((( Files Created from 2011-02-27 to 2011-03-27 )))))))))))))))))))))))))))))))
.
.
2067-02-24 22:21 . 2003-02-05 11:02 79947 —-a-w- c:\windows\fw20.vxd
2011-03-26 14:59 . 2011-03-26 14:59 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Temp
2011-03-26 14:59 . 2011-03-26 14:59 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2011-03-26 14:40 . 2011-03-26 14:40 ——– d—–w- C:\_OTL
2011-03-25 01:01 . 2011-03-25 01:01 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2011-03-24 04:46 . 2011-03-24 04:46 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2011-03-24 04:46 . 2010-12-21 01:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-24 04:46 . 2011-03-24 04:46 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-03-24 04:46 . 2010-12-21 01:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-03-24 04:37 . 2011-03-24 04:37 ——– d—–w- c:\documents and settings\Mike Unser\Application Data\Windows Search
2011-03-24 04:37 . 2011-03-24 04:37 ——– d—–w- c:\documents and settings\Administrator\Application Data\Juniper Networks
2011-03-24 04:34 . 2011-03-24 04:34 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2011-03-23 05:49 . 2011-03-23 05:49 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-03-23 05:49 . 2011-03-23 05:49 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2011-03-22 23:20 . 2011-03-22 23:20 108544 –sha-r- c:\windows\system32\webcheckz.dll
2011-03-09 22:12 . 2011-03-09 22:12 ——– d—–w- c:\program files\iPod
2011-03-09 22:12 . 2011-03-09 22:14 ——– d—–w- c:\program files\iTunes
2011-03-09 21:58 . 2011-03-09 21:58 ——– d—–w- c:\program files\Bonjour
2011-03-08 10:00 . 2011-03-08 10:00 ——– d-sh–w- c:\documents and settings\Default User\IETldCache
2011-03-05 22:14 . 2011-03-03 18:16 552376 —-a-w- c:\program files\Mozilla Firefox\uninstall\helper.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-24 04:11 . 2009-11-24 18:02 398760 —-a-r- c:\windows\system32\cpnprt2.cid
2011-02-09 13:53 . 2008-09-24 04:14 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-09 13:53 . 2008-09-24 04:14 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-08 12:55 . 2011-02-06 00:59 16432 —-a-w- c:\windows\system32\lsdelete.exe
2011-02-06 02:33 . 2011-02-06 02:34 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-02-06 02:33 . 2011-02-06 02:34 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-02-06 00:35 . 2009-11-22 15:51 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-02-02 07:58 . 2008-09-24 04:14 2067456 —-a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2008-09-24 04:14 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2008-09-24 04:12 439296 —-a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2008-09-24 04:13 290048 —-a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10 . 2008-09-24 04:12 1854976 —-a-w- c:\windows\system32\win32k.sys
2010-10-14 05:28 . 2010-12-18 19:16 24376 —-a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"edjfnkta"="c:\documents and settings\Mike Unser\Local Settings\Application Data\jrgqfpweq\hphfxthtssd.exe" [BU]
"Okatunum"="c:\windows\WMFTA2.dll" [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2003-08-06 114741]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2003-08-27 204800]
"mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2003-10-06 53248]
"MMTray"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2003-10-06 118784]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"ISUSScheduler"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" [2004-06-16 81920]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-11-11 185896]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-09-22 47904]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-11-23 1193848]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"QuickTime Task"="c:\progra~1\QUICKT~1\qttask.exe" [2010-11-30 421888]
"Memeo Instant Backup"="c:\program files\Memeo\AutoBackup\MemeoLauncher2.exe" [2010-07-08 136416]
"Seagate Dashboard"="c:\program files\Seagate\Seagate Dashboard\MemeoLauncher.exe" [2010-07-06 79112]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-07 421160]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Event Reminder.lnk - c:\program files\PrintMaster Platinum 17\Remind.exe [2006-2-22 344064]
hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-4-6 147456]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Mike Unser\\Application Data\\Juniper Networks\\Juniper Terminal Services Client\\dsTermServ.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Common Files\\Mcafee\\McSvcHost\\McSvHost.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\SYSTEM32\DRIVERS\mfetdi2k.sys [12/18/2010 12:16 PM 84072]
R1 NEOFLTR_510_8959;Juniper Networks TDI Filter Driver (NEOFLTR_510_8959);c:\windows\SYSTEM32\DRIVERS\NEOFLTR_510_8959.sys [8/4/2005 8:21 PM 56038]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [12/3/2010 2:05 AM 1405384]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [12/18/2010 12:16 PM 271480]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [12/18/2010 12:16 PM 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [12/18/2010 12:16 PM 271480]
R2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\Memeo\AutoBackup\MemeoBackgroundService.exe [7/8/2010 11:21 AM 25824]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\Mcafee\SystemCore\mfefire.exe [12/18/2010 12:16 PM 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\SYSTEM32\mfevtps.exe [12/18/2010 12:01 PM 141792]
R2 SeagateDashboardService;Seagate Dashboard Service;c:\program files\Seagate\Seagate Dashboard\SeagateDashboardService.exe [7/6/2010 12:32 PM 14088]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [3/29/2007 6:23 PM 24652]
R3 cfwids;McAfee Inc. cfwids;c:\windows\SYSTEM32\DRIVERS\cfwids.sys [12/18/2010 12:16 PM 55840]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\SYSTEM32\DRIVERS\mfefirek.sys [12/18/2010 12:16 PM 313288]
R3 mfendiskmp;mfendiskmp;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [12/18/2010 12:16 PM 88544]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys –> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/1/2010 7:11 PM 135664]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [12/3/2010 2:05 AM 15232]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [12/18/2010 12:16 PM 88544]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\SYSTEM32\DRIVERS\mferkdet.sys [12/18/2010 12:16 PM 84264]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [9/23/2008 9:12 PM 14336]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
itlsvc REG_MULTI_SZ itlperf
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-27 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-12-03 13:06]
.
2011-03-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-12 19:34]
.
2011-02-20 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1200 series5E771253C1676EBED677BF361FDFC537825E15B8290222188.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-06 07:52]
.
2011-03-27 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-15 06:19]
.
2011-03-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-02 02:10]
.
2011-03-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-02 02:10]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://ww2.cox.com/myconnection/arizona/home.cox
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p;=%s
Trusted Zone: internet
Trusted Zone: intuit.com\ttlc
Trusted Zone: mcafee.com
DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} - hxxp://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab
DPF: {6632A7E9-FE1F-43D2-A04A-A15951ED63E0} - hxxp://mediaplayer.walmart.com/installer/install.cab
DPF: {BAE57CC6-88D1-4AE8-B6FD-306120D5BC52} - hxxp://www.riosalado.edu/techcheck/SystemRequirements.cab
DPF: {BEA7310D-06C4-4339-A784-DC3804819809} - hxxp://samsclubus.pnimedia.com/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
FF - ProfilePath - c:\documents and settings\Mike Unser\Application Data\Mozilla\Firefox\Profiles\0rfs5glm.default\
FF - prefs.js: browser.startup.homepage - hxxp://ww2.cox.com/myconnection/arizona/home.cox
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: McAfee SiteAdvisor: {B7082FAA-CB62-4872-9106-E42DD88EDE45} - c:\program files\McAfee\SiteAdvisor
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-ESET Online Scanner - c:\program files\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe
AddRemove-McAfee Virtual Technician - c:\program files\McAfee\Supportability\MVT\MVTInstaller.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-26 19:26
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-745026515-2176700639-2611127406-1008\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(4952)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
c:\windows\BCMSMMSG.exe
c:\windows\System32\wbem\unsecapp.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\Seagate\Seagate Dashboard\MemeoDashboard.exe
c:\program files\Memeo\AutoBackup\InstantBackup.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
c:\windows\System32\HPZipm12.exe
c:\program files\Common Files\Java\Java Update\jucheck.exe
c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
c:\progra~1\mcafee\VIRUSS~1\mcvsmap.exe
c:\progra~1\mcafee.com\agent\mcupdate.exe
.
**************************************************************************
.
Completion time: 2011-03-26 19:56:14 - machine was rebooted
ComboFix-quarantined-files.txt 2011-03-27 02:55
ComboFix2.txt 2010-06-30 00:35
.
Pre-Run: 69,920,378,880 bytes free
Post-Run: 69,899,223,040 bytes free
.
- - End Of File - - F5175A560AAD02D672EAC105E8A7F874
Hi mikeinsurprise,

The hyperlink actually has it going to http://http//www.virustotal.com. Should it be http://virustotal.com?

Sorry about that, sometimes the forum adds an additional http to my canned. That file is being particular shy.

Let's see if we can get a closer look at that file and we'll take care of the missing dll warning.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Reg
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"edjfnkta"=-
"Okatunum"=-

:Commands
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.


Next

Open OTL if it's not open after the reboot.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/fixes copy and paste the following bold text

    /md5start
    webcheckz.dll
    /md5stop
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt

Please post back with
  • OTL fix log
  • OTL.txt
Everything still reasonably ok?

Thanks
Hi Oldman 960:

Everything is still reasonably ok. Looks like I can access my programs with a double click. When the computer reboots everything that was in the system tray shows up. On a side note, it looks like I have JAVA updates available and also so Windows updates available. I won't update anything until you tell me too. When I'm on my home page (Cox.net) there's that annoying advertisement on the right side that says I'm the 100,000 vistor and just won, click here. I'm sure we still have other things to look at before we start with that.

Here's the OTL Fix log and the OTL.txt

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
File C:\Documents and Settings\All Users\Application Data\e63lt3ed7f6e not found.
C:\WINDOWS\Nhovij.bin moved successfully.
C:\WINDOWS\Lfuyiwitatuxof.dat moved successfully.
File move failed. C:\WINDOWS\SYSTEM32\webcheckz.dll scheduled to be moved on reboot.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Mike Unser\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Mike Unser\Desktop\cmd.txt deleted successfully.
File move failed. C:\WINDOWS\tasks\Crhozpaa.job scheduled to be moved on reboot.
File move failed. C:\WINDOWS\tasks\BDYLLNDNB.job scheduled to be moved on reboot.
File move failed. C:\WINDOWS\tasks\PYHPB.job scheduled to be moved on reboot.
C:\WINDOWS\System32\drivers\lvuvc.hs moved successfully.
C:\WINDOWS\System32\drivers\logiflt.iad moved successfully.
File\Folder C:\Documents and Settings\Mike Unser\Local Settings\Application Data\jrgqfpweq not found.
File\Folder C:\WINDOWS\ohimohagiqinic.dll not found.
File\Folder C:\WINDOWS\WMFTA2.dll not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 7011364 bytes
->Flash cache emptied: 678 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56543 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 206748 bytes
->Flash cache emptied: 596 bytes

User: Mike Unser
->Temp folder emptied: 517456881 bytes
->Temporary Internet Files folder emptied: 44105155 bytes
->Java cache emptied: 247868 bytes
->FireFox cache emptied: 65940543 bytes
->Apple Safari cache emptied: 14336 bytes
->Flash cache emptied: 2102586 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 137540932 bytes
->Java cache emptied: 18410 bytes
->Flash cache emptied: 43520 bytes

User: Owner

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 58666 bytes
%systemroot%\System32 .tmp files removed: 2675729 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 7804290 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 65988 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 749.00 mb


OTL by OldTimer - Version 3.2.22.3 log created on 03262011_075959

Files\Folders moved on Reboot…
C:\WINDOWS\SYSTEM32\webcheckz.dll moved successfully.
File\Folder C:\WINDOWS\tasks\Crhozpaa.job not found!
File\Folder C:\WINDOWS\tasks\BDYLLNDNB.job not found!
File\Folder C:\WINDOWS\tasks\PYHPB.job not found!

Registry entries deleted on Reboot…


This was another txt file in the _Moved files folder:

========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\edjfnkta deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Okatunum deleted successfully.
========== COMMANDS ==========

OTL by OldTimer - Version 3.2.22.3 log created on 03262011_205231


Here's the OTL.txt

OTL logfile created on: 3/26/2011 9:11:04 PM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Mike Unser\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

766.00 Mb Total Physical Memory | 143.00 Mb Available Physical Memory | 19.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 49.00% Paging File free
Paging file location(s): C:\pagefile.sys 1147 1147 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.73 Gb Total Space | 65.13 Gb Free Space | 58.29% Space Free | Partition Type: NTFS

Computer Name: OFFICE | User Name: Mike Unser | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Mike Unser\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\WINDOWS\SYSTEM32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe (Memeo)
PRC - C:\Program Files\Memeo\AutoBackup\InstantBackup.exe ()
PRC - C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe (Memeo)
PRC - C:\Program Files\Seagate\Seagate Dashboard\MemeoDashboard.exe (Memeo)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe (MUSICMATCH, Inc.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe (Hewlett-Packard Co.)
PRC - C:\WINDOWS\SYSTEM32\HPZipm12.exe (HP)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Mike Unser\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (mfevtp) – C:\WINDOWS\SYSTEM32\mfevtps.exe (McAfee, Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (MemeoBackgroundService) – C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe (Memeo)
SRV - (SeagateDashboardService) – C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe (Memeo)
SRV - (McProxy) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\SYSTEM32\HPZipm12.exe (HP)
SRV - (NetSvc) – C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation)


========== Driver Services (SafeList) ==========

DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – C:\WINDOWS\SYSTEM32\DRIVERS\mfefirek.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfeapfk.sys (McAfee, Inc.)
DRV - (mfendiskmp) – C:\WINDOWS\SYSTEM32\DRIVERS\mfendisk.sys (McAfee, Inc.)
DRV - (mfendisk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfendisk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\WINDOWS\SYSTEM32\DRIVERS\mferkdet.sys (McAfee, Inc.)
DRV - (mfetdi2k) – C:\WINDOWS\SYSTEM32\DRIVERS\mfetdi2k.sys (McAfee, Inc.)
DRV - (cfwids) – C:\WINDOWS\SYSTEM32\DRIVERS\cfwids.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfebopk.sys (McAfee, Inc.)
DRV - (FilterService) – C:\WINDOWS\SYSTEM32\DRIVERS\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUVC) Logitech Webcam 250(UVC) – C:\WINDOWS\SYSTEM32\DRIVERS\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\SYSTEM32\DRIVERS\lvrs.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\SYSTEM32\DRIVERS\LVPr2Mon.sys ()
DRV - (lvpopflt) – C:\WINDOWS\SYSTEM32\DRIVERS\lvpopflt.sys (Logitech Inc.)
DRV - (MxlW2k) – C:\WINDOWS\System32\drivers\MxlW2k.sys (MusicMatch, Inc.)
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (NEOFLTR_510_8959) Juniper Networks TDI Filter Driver (NEOFLTR_510_8959) – C:\WINDOWS\SYSTEM32\DRIVERS\NEOFLTR_510_8959.sys (Neoteris)
DRV - (iAimFP4) – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)
DRV - (iAimFP3) – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)
DRV - (iAimTV4) – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)
DRV - (iAimTV3) – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)
DRV - (iAimTV1) – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)
DRV - (iAimTV0) – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)
DRV - (iAimFP0) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)
DRV - (iAimFP1) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)
DRV - (iAimFP2) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)
DRV - (i81x) – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (AFS2K) – C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (cdrbsdrv) – C:\WINDOWS\System32\drivers\CDRBSDRV.SYS (B.H.A Corporation)
DRV - (BCMModem) – C:\WINDOWS\SYSTEM32\DRIVERS\BCMSM.sys (Broadcom Corporation)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (EL90XBC) – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ww2.cox.com/myconnection/arizona/home.cox
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://ww2.cox.com/myconnection/arizona/home.cox"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.1
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {AA1F7949-20DE-494A-9C69-8373D168BCBA}:1.9.1
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2011/02/28 19:18:08 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/06 15:10:27 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/05 15:13:55 | 000,000,000 | —D | M]

[2010/07/04 18:27:19 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Mike Unser\Application Data\Mozilla\Extensions
[2011/03/22 17:09:12 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Mike Unser\Application Data\Mozilla\Firefox\Profiles\0rfs5glm.default\extensions
[2010/07/08 21:15:04 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Mike Unser\Application Data\Mozilla\Firefox\Profiles\0rfs5glm.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/03 12:16:49 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Mike Unser\Application Data\Mozilla\Firefox\Profiles\0rfs5glm.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011/03/22 17:09:12 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/07/12 01:06:19 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/02/05 19:34:35 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\MIKE UNSER\LOCAL SETTINGS\APPLICATION DATA\{AA1F7949-20DE-494A-9C69-8373D168BCBA}
[2011/02/05 19:34:02 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/02/28 19:18:08 | 000,000,000 | —D | M] (McAfee SiteAdvisor) – C:\PROGRAM FILES\MCAFEE\SITEADVISOR
[2010/10/13 22:28:54 | 000,024,376 | —- | M] (McAfee, Inc.) – C:\Program Files\Mozilla Firefox\components\Scriptff.dll
[2009/11/20 14:05:31 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2011/02/05 19:33:54 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/11/20 14:05:32 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll

O1 HOSTS File: ([2011/03/26 19:24:51 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20101218121644.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [Memeo Instant Backup] C:\Program Files\Memeo\AutoBackup\MemeoLauncher2.exe (Memeo Inc.)
O4 - HKLM..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe (MUSICMATCH, Inc.)
O4 - HKLM..\Run: [Seagate Dashboard] C:\Program Files\Seagate\Seagate Dashboard\MemeoLauncher.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Event Reminder.lnk = C:\Program Files\PrintMaster Platinum 17\Remind.exe (Broderbund Properties LLC)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - File not found
O9 - Extra 'Tools' menuitem : PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Program Files\Neoteris\Secure Application Manager\samnsp.dll (Neoteris)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} http://www.logitech.com/devicedetector/plu…Detection32.cab (Device Detection)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www2.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} Reg Error: Key error. (Reg Error: Key error.)
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} http://www.maricopa.gov/assessor/gis/plugin/mgaxctrl.cab (Autodesk MapGuide ActiveX Control)
O16 - DPF: {6632A7E9-FE1F-43D2-A04A-A15951ED63E0} http://mediaplayer.walmart.com/installer/install.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} http://www.nick.com/common/groove/gx/GrooveAX27.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} http://web1.shutterfly.com/downloads/Uploader.cab (Shutterfly Picture Upload Plugin)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…8045.5157638889 (Reg Error: Key error.)
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} http://www.samsphotoclub.com/upload/FujifilmUploadClient.cab (FujifilmUploader Class)
O16 - DPF: {BAE57CC6-88D1-4AE8-B6FD-306120D5BC52} http://www.riosalado.edu/techcheck/SystemRequirements.cab (SystemRequirement.TechCheck)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://bin.mcafee.com/molbin/shared/mcgdmg…,20/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {BEA7310D-06C4-4339-A784-DC3804819809} http://samsclubus.pnimedia.com/upload/acti…veX_Control.cab (Photo Upload Plugin Class)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} https://sa.srpnet.com/dana-cached/setup/JuniperSetupSP1.cab (JuniperSetupSP1 Control)
O16 - DPF: {EFD1E13D-1CB3-4545-B754-CA410FE7734F} http://samsclubus.pnimedia.com/upload/acti…veX_Control.cab (Photo Upload Plugin Class)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://sa.srpnet.com/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Mike Unser\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Mike Unser\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/04/22 21:30:41 | 000,000,038 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/03/26 20:55:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2011/03/26 15:35:54 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/03/26 15:35:54 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/03/26 15:35:54 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/03/26 15:35:54 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/03/26 15:35:03 | 000,000,000 | —D | C] – C:\Qoobox
[2011/03/26 08:13:58 | 000,566,272 | —- | C] (AVAST Software) – C:\Documents and Settings\Mike Unser\Desktop\aswMBR.exe
[2011/03/26 07:40:53 | 000,000,000 | —D | C] – C:\_OTL
[2011/03/25 16:32:19 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Mike Unser\Desktop\iexplore.exe
[2011/03/23 21:46:13 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/03/23 21:46:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/03/23 21:46:09 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/03/23 21:46:09 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/03/23 21:37:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Mike Unser\Application Data\Windows Search
[2011/03/23 21:30:51 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Mike Unser\Desktop\OTL.exe
[2011/03/23 19:26:21 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Mike Unser\Desktop\mbam-setup-1.50.1.1100.exe
[2011/03/22 22:49:58 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Temp
[2011/03/22 22:49:58 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/03/09 15:14:12 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/03/09 15:12:21 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/03/09 15:12:02 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/03/09 14:58:08 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/03/05 15:14:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox
[1 C:\Documents and Settings\Mike Unser\My Documents\*.tmp files -> C:\Documents and Settings\Mike Unser\My Documents\*.tmp -> ]
[1 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/26 21:01:59 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/03/26 20:55:10 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2011/03/26 20:55:01 | 000,001,595 | —- | M] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Center.lnk
[2011/03/26 20:54:49 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011/03/26 20:54:32 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/26 20:54:23 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2011/03/26 20:54:22 | 803,262,464 | -HS- | M] () – C:\hiberfil.sys
[2011/03/26 20:54:20 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\lvuvc.hs
[2011/03/26 20:38:01 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/26 19:24:51 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\ETC\hosts
[2011/03/26 18:46:46 | 000,091,425 | —- | M] () – C:\Documents and Settings\Mike Unser\Desktop\report-fw20vxd.pdf
[2011/03/26 16:28:40 | 000,002,515 | —- | M] () – C:\Documents and Settings\Mike Unser\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2003 (2).lnk
[2011/03/26 13:52:26 | 000,000,512 | —- | M] () – C:\Documents and Settings\Mike Unser\Desktop\MBR.dat
[2011/03/26 08:14:03 | 000,566,272 | —- | M] (AVAST Software) – C:\Documents and Settings\Mike Unser\Desktop\aswMBR.exe
[2011/03/25 16:32:25 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Mike Unser\Desktop\iexplore.exe
[2011/03/23 21:46:13 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/23 21:30:53 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Mike Unser\Desktop\OTL.exe
[2011/03/23 21:29:26 | 000,359,929 | —- | M] () – C:\Documents and Settings\Mike Unser\Desktop\dds.scr
[2011/03/23 21:11:36 | 000,398,760 | R— | M] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2011/03/23 20:28:18 | 000,000,525 | —- | M] () – C:\hpfr3420.xml
[2011/03/23 19:26:24 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Mike Unser\Desktop\mbam-setup-1.50.1.1100.exe
[2011/03/23 16:48:58 | 011,448,320 | —- | M] () – C:\Documents and Settings\Mike Unser\My Documents\My Money.mny
[2011/03/23 16:48:55 | 012,098,822 | R— | M] () – C:\Documents and Settings\Mike Unser\My Documents\My Money Backup 091309.mbf
[2011/03/23 06:41:12 | 000,016,664 | -HS- | M] () – C:\Documents and Settings\Mike Unser\Local Settings\Application Data\e63lt3ed7f6e
[2011/03/18 13:10:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/03/17 20:59:50 | 000,198,656 | —- | M] () – C:\Documents and Settings\Mike Unser\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/16 19:22:59 | 000,002,513 | —- | M] () – C:\Documents and Settings\Mike Unser\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Excel 2003.lnk
[2011/03/10 18:00:39 | 000,000,792 | —- | M] () – C:\Documents and Settings\Mike Unser\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2011/03/10 03:12:57 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/03/09 15:14:12 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/03/09 14:59:34 | 000,001,854 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2011/03/09 14:59:34 | 000,001,854 | —- | M] () – C:\Documents and Settings\Mike Unser\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/03/05 15:14:06 | 000,001,620 | —- | M] () – C:\Documents and Settings\Mike Unser\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/05 15:14:06 | 000,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[1 C:\Documents and Settings\Mike Unser\My Documents\*.tmp files -> C:\Documents and Settings\Mike Unser\My Documents\*.tmp -> ]
[1 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]

========== Files Created - No Company Name ==========

[2067/02/24 15:21:18 | 000,079,947 | —- | C] () – C:\WINDOWS\fw20.vxd
[2011/03/26 18:46:38 | 000,091,425 | —- | C] () – C:\Documents and Settings\Mike Unser\Desktop\report-fw20vxd.pdf
[2011/03/26 15:35:54 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/03/26 15:35:54 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/03/26 15:35:54 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/03/26 15:35:54 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/03/26 15:35:54 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/03/26 08:24:30 | 803,262,464 | -HS- | C] () – C:\hiberfil.sys
[2011/03/26 08:23:09 | 000,000,512 | —- | C] () – C:\Documents and Settings\Mike Unser\Desktop\MBR.dat
[2011/03/26 08:05:20 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\drivers\lvuvc.hs
[2011/03/23 21:46:13 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/23 21:29:25 | 000,359,929 | —- | C] () – C:\Documents and Settings\Mike Unser\Desktop\dds.scr
[2011/03/22 17:44:12 | 000,016,664 | -HS- | C] () – C:\Documents and Settings\Mike Unser\Local Settings\Application Data\e63lt3ed7f6e
[2011/03/09 15:14:12 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/03/09 14:59:34 | 000,001,854 | —- | C] () – C:\Documents and Settings\Mike Unser\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/03/05 15:14:06 | 000,001,620 | —- | C] () – C:\Documents and Settings\Mike Unser\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/05 15:14:06 | 000,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/03/01 18:40:57 | 000,002,272 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/02/05 17:59:41 | 000,016,432 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2010/11/19 19:51:16 | 000,016,618 | —- | C] () – C:\WINDOWS\hpomdl01.dat
[2010/11/19 19:51:15 | 000,020,454 | —- | C] () – C:\WINDOWS\hpoins01.dat
[2010/08/28 09:26:39 | 000,082,289 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2010/07/18 18:13:11 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/05/14 14:56:06 | 010,830,680 | —- | C] () – C:\WINDOWS\System32\LogiDPP.dll
[2010/05/14 14:56:06 | 000,102,744 | —- | C] () – C:\WINDOWS\System32\LogiDPPApp.exe
[2010/05/14 14:55:58 | 000,290,648 | —- | C] () – C:\WINDOWS\System32\DevManagerCore.dll
[2010/02/27 10:21:52 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2009/10/27 10:04:55 | 000,123,124 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/10/07 01:46:36 | 000,025,752 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009/10/07 01:23:08 | 000,013,584 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2009/09/25 23:20:44 | 000,000,000 | —- | C] () – C:\WINDOWS\popcreg.dat
[2009/09/24 01:23:09 | 000,000,042 | —- | C] () – C:\WINDOWS\popcinfot.dat
[2008/09/23 21:13:19 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2008/09/23 21:12:56 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2008/06/19 11:20:22 | 000,000,000 | —- | C] () – C:\Program Files\temp01
[2008/05/26 21:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 21:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/05/14 16:30:36 | 000,012,288 | —- | C] () – C:\WINDOWS\impborl.dll
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/12/26 21:12:15 | 000,002,189 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/12/12 09:30:29 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\DivXsm.exe
[2006/12/12 09:30:26 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2006/12/12 09:24:42 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2006/02/19 20:46:40 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\uninscpw.exe
[2005/11/11 22:53:06 | 000,000,074 | —- | C] () – C:\WINDOWS\ImportClient.INI
[2004/12/12 15:53:58 | 000,000,133 | —- | C] () – C:\Documents and Settings\Mike Unser\Local Settings\Application Data\fusioncache.dat
[2004/10/22 01:45:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/15 19:48:55 | 000,022,740 | -H– | C] () – C:\WINDOWS\hpothb07.dat
[2004/08/02 22:28:15 | 000,021,312 | —- | C] () – C:\WINDOWS\choice.exe
[2004/08/02 18:26:46 | 000,000,059 | —- | C] () – C:\WINDOWS\System32\6vo4svc.dll
[2004/08/01 15:14:42 | 001,152,060 | —- | C] () – C:\WINDOWS\kwv2.dat
[2004/07/29 20:16:52 | 000,065,588 | —- | C] () – C:\WINDOWS\System32\zlib.dll
[2004/07/21 20:57:49 | 000,000,574 | —- | C] () – C:\WINDOWS\eReg.dat
[2004/07/15 17:59:51 | 000,000,037 | —- | C] () – C:\WINDOWS\ipixActivex.ini
[2004/04/20 19:14:58 | 000,009,019 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2004/03/19 16:10:24 | 000,198,656 | —- | C] () – C:\Documents and Settings\Mike Unser\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/02/28 14:26:30 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/02/28 14:11:09 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2004/02/28 13:18:52 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\instlsp.exe
[2004/02/19 20:37:21 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/02/19 20:32:26 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2004/02/19 20:29:14 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2004/02/19 20:28:22 | 000,000,215 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/02/19 20:18:30 | 000,002,048 | –S- | C] () – C:\WINDOWS\BOOTSTAT.DAT
[2004/02/19 20:16:58 | 000,466,932 | —- | C] () – C:\WINDOWS\System32\PERFH009.DAT
[2004/02/19 20:16:58 | 000,080,148 | —- | C] () – C:\WINDOWS\System32\PERFC009.DAT
[2004/02/19 20:16:47 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/02/19 20:05:16 | 000,000,550 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2003/08/19 12:41:32 | 000,965,096 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2003/08/19 12:40:04 | 000,000,258 | —- | C] () – C:\WINDOWS\System32\BDEMERGE.INI
[2003/08/19 12:38:56 | 000,000,831 | —- | C] () – C:\WINDOWS\ORUN32.INI
[2003/08/13 21:54:00 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/03/09 13:31:04 | 000,561,152 | —- | C] () – C:\WINDOWS\System32\hpotscl.dll
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/09/03 07:59:14 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2002/09/03 07:56:30 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2002/09/03 07:31:46 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2002/09/03 07:31:44 | 000,004,594 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2002/08/29 04:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\MLANG.DAT
[2002/08/29 04:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\PERFI009.DAT
[2002/08/29 04:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\DSSEC.DAT
[2002/08/29 04:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\MIB.BIN
[2002/08/29 04:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\PERFD009.DAT
[2002/08/29 04:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\NOISE.DAT
[1999/03/22 01:00:00 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

========== Custom Scans ==========



< MD5 for: WEBCHECKZ.DLL >
[2011/03/22 16:20:50 | 000,108,544 | RHS- | M] (Ijdhualae Vskxgafuqrg) MD5=C82BEA0A0E327664F15E71CEB559DD24 – C:\_OTL\MovedFiles\03262011_075959\C_WINDOWS\SYSTEM32\webcheckz.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5F1019FF
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34

< End of report >

Thanks!
Hi mikeinsurprise,

Hold of on the updates for now.

Seems to be a bit of conflict between what each tool is showing. We will use Virustotal Please submit this file for analysis.

To submit a file to virustotal, please click on this link

Http://www.virustotal.com

copy and paste the following into the upload a file box (it may look like there are 2 file paths but it is one complete path)

C:\_OTL\MovedFiles\03262011_075959\C_WINDOWS\SYSTEM32\webcheckz.dll



scroll down a bit and click "send file", wait for the results and post them in your next reply.

Please note that sometimes the scans take a few minutes. Please ensure that the scan has completed and the results are complete .



We will be using Combofix again but will run it differently.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the all of the text in the code box below into the Notepad, (including the URL). Do Not copy the word CODE

http://forums.whatthetech.com/index.php?showtopic=117747&pid=720631&st=0&#entry720631

Collect::
C:\WINDOWS\SYSTEM32\webcheckz.dll

File::
C:\Documents and Settings\Mike Unser\Local Settings\Application Data\e63lt3ed7f6e
c:\windows\WMFTA2.dll

Folder::
c:\documents and settings\Mike Unser\Local Settings\Application Data\jrgqfpweq

DirLook::
C:\DOCUMENTS AND SETTINGS\MIKE UNSER\LOCAL SETTINGS\APPLICATION DATA\{AA1F7949-20DE-494A-9C69-8373D168BCBA}

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.

Please post back with
  • VirusTotal results
  • combofix log
Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI