This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack this log

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I keep getting security errors, and my norton says that it keeps blocking trojans. This is my work computer so worried that I am going to lose all of my information. Any help would be greatly appreciated.




Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:44:35 AM, on 3/28/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
C:\PAYCLOCK\PC50\BTENG32M.EXE
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\PAYCLOCK\BTENG32M.EXE
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\Dell\PanelMgr\SSMMgr.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\PAYCLOCK\PCSCMGR.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\RALINK\Common\RaUI.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\PAYCLOCK\PC50\PCTSCMGR.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\WINDOWS\twain_32\Dell\Dell2335\Scan2Pc.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\QuickBooks Online Backup\OnlineBackup.exe
C:\Program Files\QuickBooks Online Backup\OnlineBackup.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Documents and Settings\NetworkService\Local Settings\Application Data\suj.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\City Clerk\My Documents\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USREL/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.live.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://jookz.toolbaroptions.com/?tmp=toolb…tb04ie&v=12
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://g.msn.com/USREL/1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://jookz.toolbaroptions.com/?tmp=toolb…tb04ie&v=12
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://jookz.toolbaroptions.com/?tmp=toolb…tb04ie&v=12
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\IPSBHO.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Dell PanelMgr] C:\WINDOWS\Dell\PanelMgr\SSMMgr.exe /autorun
O4 - HKLM\..\Run: [2335dn Scan2PC] "C:\WINDOWS\twain_32\Dell\Dell2335\Scan2Pc.exe"
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
O4 - HKLM\..\Run: [PayClockServer] C:\PAYCLOCK\PCSCMGR.EXE
O4 - HKLM\..\Run: [PayClockTerminalService] C:\PAYCLOCK\PC50\PCTSCMGR.EXE
O4 - HKLM\..\Run: [TouchStation] C:\PAYCLOCK\TouchStation\TSMGR.EX_
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Mnosone] rundll32.exe "C:\WINDOWS\oyucopoj.dll",Startup
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [OnlineBackupScheduler] C:\Program Files\QuickBooks Online Backup\OnlineBackup.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [Pzejujupiliyo] rundll32.exe "C:\WINDOWS\cteclops.dll",Startup
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: Conversion to PDF with ScanSnap Organizer.lnk = ?
O4 - Global Startup: Online Backup Scheduler.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
O23 - Service: PayClock Database Service (PayClockServer) - MLB Computer Consulting - C:\PAYCLOCK\BTENG32M.EXE
O23 - Service: PayClock Terminal Service (PayClockTerminalServer) - MLB Computer Consulting - C:\PAYCLOCK\PC50\BTENG32M.EXE
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

–
End of file - 11866 bytes
Hi,

:welcome:

My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
===================================================

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.

Also please describe how your computer behaves at the moment.

===================================================
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

In your next post, please include the following:
  • MBAM log
  • OTL log
  • GMER log
Thank you so much for helping me. To get my computer to even allow me back on the internet, I had to go into safemode and run mbam and install a new antivirus. But here are the results from the steps you told me to do.

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6198

Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

3/28/2011 3:12:19 PM
mbam-log-2011-03-28 (15-12-19).txt

Scan type: Quick scan
Objects scanned: 157349
Time elapsed: 2 minute(s), 11 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

OTL logfile created on: 3/28/2011 3:15:07 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\City Clerk\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 74.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.79 Gb Total Space | 215.07 Gb Free Space | 92.39% Space Free | Partition Type: NTFS

Computer Name: CITYCLERK | User Name: City Clerk | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\City Clerk\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgam.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files\MySpace\IM\MySpaceIM.exe ()
PRC - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\WINDOWS\twain_32\Dell\Dell2335\Scan2Pc.exe ()
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\PAYCLOCK\Pcscmgr.exe (Lathem Time Corp.)
PRC - C:\PAYCLOCK\PC50\Bteng32m.exe (MLB Computer Consulting)
PRC - C:\PAYCLOCK\Bteng32m.exe (MLB Computer Consulting)
PRC - C:\PAYCLOCK\PC50\PCTSCMGR.EXE (Lathem Time Corp.)
PRC - C:\Program Files\QuickBooks Online Backup\OnlineBackup.exe (SwapDrive, Inc.)
PRC - C:\Program Files\RALINK\Common\RaUI.exe (Ralink Technology, Corp.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\City Clerk\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (QBCFMonitorService) – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (QBFCService) – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (PayClockTerminalServer) – C:\PAYCLOCK\PC50\BTENG32M.EXE (MLB Computer Consulting)
SRV - (PayClockServer) – C:\PAYCLOCK\BTENG32M.EXE (MLB Computer Consulting)


========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriverxpx) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilterxpx) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShimxpx) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSErHrxpx) – C:\WINDOWS\System32\Drivers\AVGIDSxx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgRkx86) – C:\WINDOWS\System32\Drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (k57w2k) Broadcom NetLink ™ – C:\WINDOWS\system32\drivers\k57xp32.sys (Broadcom Corporation)
DRV - (SFAUDIO) – C:\WINDOWS\system32\drivers\sfaudio.sys (Sonic Focus, Inc)
DRV - (TOUCHSTA) – C:\WINDOWS\system32\drivers\TouchSta.SYS ()
DRV - (DLADResM) – C:\WINDOWS\system32\drivers\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) – C:\WINDOWS\system32\drivers\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\drivers\DLAUDF_M.SYS (Roxio)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\drivers\DLAUDFAM.SYS (Roxio)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\drivers\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\WINDOWS\system32\drivers\DLABOIOM.SYS (Roxio)
DRV - (DLAPoolM) – C:\WINDOWS\system32\drivers\DLAPoolM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\drivers\DLAIFS_M.SYS (Roxio)
DRV - (DLARTL_M) – C:\WINDOWS\system32\drivers\DLARTL_M.SYS (Roxio)
DRV - (DLACDBHM) – C:\WINDOWS\System32\Drivers\DLACDBHM.SYS (Roxio)
DRV - (RT73) – C:\WINDOWS\system32\drivers\rt73.sys (Ralink Technology, Corp.)
DRV - (TOUCHDSP) – C:\WINDOWS\system32\drivers\TOUCHDSP.sys (Microsoft Corporation)
DRV - (WUSB54GPV4SRV) – C:\WINDOWS\system32\drivers\rt2500usb.sys (Ralink Technology Inc.)
DRV - (BCM42RLY) – C:\WINDOWS\system32\bcm42rly.sys (Broadcom Corporation)
DRV - (BrPar) – C:\WINDOWS\System32\drivers\BrPar.sys (Brother Industries Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = http://www.google.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://g.msn.com/USREL/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://g.msn.com/USREL/1

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Jookz"
FF - prefs.js..browser.search.defaultenginename: "Jookz"
FF - prefs.js..browser.search.order.1: "Jookz"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "msn.com"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.845
FF - prefs.js..extensions.enabledItems: avg@igeared:3.011.025.005

FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2011/03/28 14:21:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2011/03/28 14:13:24 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/28 09:07:56 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/25 08:18:05 | 000,000,000 | —D | M]

[2009/05/18 17:32:32 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\City Clerk\Application Data\Mozilla\Extensions
[2009/05/18 17:32:32 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\City Clerk\Application Data\Mozilla\Firefox\Profiles\mz17j13q.default\extensions
[2009/11/10 21:18:02 | 000,002,160 | —- | M] () – C:\Documents and Settings\City Clerk\Application Data\Mozilla\Firefox\Profiles\mz17j13q.default\searchplugins\MySpace.xml
[2011/03/28 13:19:38 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/03/28 14:21:03 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG9\FIREFOX
[2011/03/28 14:13:24 | 000,000,000 | —D | M] ("urn:mozilla:install-manifest" em:id="avg@igeared" em:name="AVG Security Toolbar" em:version="3.011.025.005" em:displayname="AVG Security Toolbar" em:iconURL="chrome://tavgp/skin/logo.ico" em:creator="AVG Technologies" em:description="AVG Security Toolbar" em:homepageURL="http://www.avg.com" >) – C:\PROGRAM FILES\AVG\AVG9\TOOLBAR\FIREFOX\AVG@IGEARED
[2009/04/16 00:35:21 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF

O1 HOSTS File: ([2011/03/28 12:50:06 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [2335dn Scan2PC] C:\WINDOWS\twain_32\Dell\Dell2335\Scan2Pc.exe ()
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Dell PanelMgr] C:\WINDOWS\Dell\PanelMgr\SSMMgr.exe ()
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [PayClockServer] C:\PAYCLOCK\Pcscmgr.exe (Lathem Time Corp.)
O4 - HKLM..\Run: [PayClockTerminalService] C:\PAYCLOCK\PC50\PCTSCMGR.EXE (Lathem Time Corp.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [TouchStation] File not found
O4 - HKCU..\Run: [OnlineBackupScheduler] C:\Program Files\QuickBooks Online Backup\OnlineBackup.exe (SwapDrive, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Conversion to PDF with ScanSnap Organizer.lnk = C:\Program Files\PFU\ScanSnap\Organizer\PfuSsOrgOcrChk.exe (PFU LIMITED)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Online Backup Scheduler.lnk = C:\WINDOWS\Installer\{A9255718-8A40-45F9-B738-93655FBD4F6F}\_C90BDFE323B95CEE248723.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe (Ralink Technology, Corp.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\City Clerk\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\City Clerk\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/25 17:29:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.imm4 - C:\WINDOWS\System32\vcmimm4.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2011/03/28 15:01:45 | 000,000,000 | —D | C] – C:\Documents and Settings\City Clerk\Local Settings\Application Data\AVG Security Toolbar
[2011/03/28 14:58:05 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/03/28 14:18:39 | 000,012,536 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2011/03/28 14:13:39 | 000,025,168 | —- | C] (AVG Technologies CZ, s.r.o. ) – C:\WINDOWS\System32\drivers\AVGIDSxx.sys
[2011/03/28 14:13:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG 9.0
[2011/03/28 14:13:38 | 000,243,024 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2011/03/28 14:13:38 | 000,052,872 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgrkx86.sys
[2011/03/28 14:13:34 | 000,216,400 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2011/03/28 14:13:32 | 000,029,584 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2011/03/28 14:13:26 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2011/03/28 14:13:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2011/03/28 14:13:02 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2011/03/28 14:13:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg9
[2011/03/28 12:52:12 | 000,000,000 | —D | C] – C:\Documents and Settings\City Clerk\Application Data\Malwarebytes
[2011/03/28 12:52:08 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/03/28 12:52:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/03/28 12:52:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/03/28 12:52:05 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/03/28 12:52:05 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/03/28 12:39:20 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/03/28 12:39:20 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/03/28 12:39:20 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/03/28 12:39:20 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/03/28 12:39:15 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/03/28 12:39:05 | 000,000,000 | —D | C] – C:\Documents and Settings\City Clerk\Local Settings\Application Data\Symantec
[2011/03/28 12:38:23 | 000,000,000 | —D | C] – C:\Qoobox
[2011/03/28 12:38:08 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2011/03/28 12:18:13 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\City Clerk\Desktop\mbam-setup-1.50.1.1100.exe
[2011/03/28 12:17:38 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2011/03/28 12:17:35 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2011/03/28 12:02:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
[2011/03/28 12:02:25 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2011/03/28 12:02:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2011/03/28 09:07:06 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2011/03/28 08:11:52 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/03/25 10:07:27 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/03/25 10:07:21 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/03/22 17:02:57 | 000,000,000 | —D | C] – C:\_AcroTemp
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/28 14:58:32 | 000,002,521 | —- | M] () – C:\Documents and Settings\City Clerk\Desktop\Microsoft Office Outlook 2007.lnk
[2011/03/28 14:55:17 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2011/03/28 14:48:52 | 000,002,363 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Online Backup Scheduler.lnk
[2011/03/28 14:48:34 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/03/28 14:18:41 | 000,243,024 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2011/03/28 14:18:39 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2011/03/28 14:18:39 | 000,012,536 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2011/03/28 14:18:35 | 000,025,168 | —- | M] (AVG Technologies CZ, s.r.o. ) – C:\WINDOWS\System32\drivers\AVGIDSxx.sys
[2011/03/28 14:18:34 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2011/03/28 14:18:33 | 000,052,872 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgrkx86.sys
[2011/03/28 14:13:39 | 000,001,509 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 9.0.lnk
[2011/03/28 14:13:32 | 047,541,798 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/03/28 14:13:32 | 000,113,461 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2011/03/28 14:13:26 | 006,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2011/03/28 14:13:26 | 000,492,629 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2011/03/28 14:13:26 | 000,136,354 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2011/03/28 12:52:08 | 000,000,786 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/28 12:50:06 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/03/28 12:31:49 | 000,017,286 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\1h7o7jc41qixin
[2011/03/28 12:31:48 | 000,017,286 | -HS- | M] () – C:\Documents and Settings\City Clerk\Local Settings\Application Data\1h7o7jc41qixin
[2011/03/28 12:02:28 | 000,000,953 | —- | M] () – C:\Documents and Settings\City Clerk\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/03/28 12:02:28 | 000,000,935 | —- | M] () – C:\Documents and Settings\City Clerk\Desktop\Spybot - Search & Destroy.lnk
[2011/03/28 08:34:48 | 000,017,172 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\3551322423
[2011/03/25 10:55:24 | 000,508,688 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/03/25 10:55:24 | 000,096,420 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/03/25 10:29:10 | 000,000,101 | —- | M] () – C:\WINDOWS\TASAPI.INI
[2011/03/25 09:58:51 | 000,000,120 | —- | M] () – C:\WINDOWS\Tjipulopocitalu.dat
[2011/03/25 09:58:51 | 000,000,000 | —- | M] () – C:\WINDOWS\Ypoho.bin
[2011/03/22 17:19:48 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/02/28 16:59:06 | 000,007,266 | —- | M] () – C:\Documents and Settings\City Clerk\Application Data\Dell2335Options.xml
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/03/28 14:13:39 | 000,001,509 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG 9.0.lnk
[2011/03/28 14:13:32 | 000,113,461 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2011/03/28 14:13:26 | 047,541,798 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/03/28 14:13:26 | 006,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2011/03/28 14:13:26 | 000,492,629 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2011/03/28 14:13:26 | 000,136,354 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2011/03/28 12:52:08 | 000,000,786 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/28 12:43:13 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/03/28 12:39:20 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/03/28 12:39:20 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/03/28 12:39:20 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/03/28 12:39:20 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/03/28 12:39:20 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/03/28 12:02:28 | 000,000,953 | —- | C] () – C:\Documents and Settings\City Clerk\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/03/28 12:02:28 | 000,000,935 | —- | C] () – C:\Documents and Settings\City Clerk\Desktop\Spybot - Search & Destroy.lnk
[2011/03/28 08:34:48 | 000,017,286 | -HS- | C] () – C:\Documents and Settings\City Clerk\Local Settings\Application Data\1h7o7jc41qixin
[2011/03/28 08:34:48 | 000,017,172 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\3551322423
[2011/03/28 08:11:59 | 000,017,286 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\1h7o7jc41qixin
[2011/03/28 08:11:59 | 000,017,270 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\1h7o7jc41qixin
[2011/03/25 09:58:51 | 000,000,120 | —- | C] () – C:\WINDOWS\Tjipulopocitalu.dat
[2011/03/25 09:58:51 | 000,000,000 | —- | C] () – C:\WINDOWS\Ypoho.bin
[2010/08/12 09:13:09 | 000,000,067 | —- | C] () – C:\WINDOWS\iltwain.ini
[2009/09/30 10:15:13 | 000,674,074 | —- | C] () – C:\WINDOWS\unins000.exe
[2009/09/30 10:15:13 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\vcmimm4.dll
[2009/09/30 10:15:13 | 000,000,792 | —- | C] () – C:\WINDOWS\unins000.dat
[2009/09/30 10:06:45 | 000,006,656 | —- | C] () – C:\Documents and Settings\City Clerk\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/01 08:42:51 | 000,020,224 | R— | C] () – C:\WINDOWS\System32\drivers\TouchSta.SYS
[2009/06/01 08:42:51 | 000,007,120 | R— | C] () – C:\WINDOWS\System32\drivers\TUSB2136.BIN
[2009/06/01 08:38:22 | 000,000,101 | —- | C] () – C:\WINDOWS\TASAPI.INI
[2009/05/22 08:27:09 | 000,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2009/05/22 08:27:09 | 000,000,034 | —- | C] () – C:\WINDOWS\System32\BD5240.DAT
[2009/05/22 08:20:45 | 000,000,161 | —- | C] () – C:\WINDOWS\DISPARAM.INI
[2009/05/22 08:13:27 | 000,000,145 | —- | C] () – C:\WINDOWS\BRVIDEO.INI
[2009/05/22 08:13:27 | 000,000,000 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2009/05/22 08:13:26 | 000,000,023 | —- | C] () – C:\WINDOWS\Brownie.ini
[2009/05/22 08:13:16 | 000,014,441 | —- | C] () – C:\WINDOWS\HL-5240.INI
[2009/05/18 17:32:33 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/05/12 14:24:36 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\GTW32N50.dll
[2009/05/11 10:42:19 | 000,000,090 | —- | C] () – C:\WINDOWS\QBChanUtil_Trigger.ini
[2009/04/24 13:29:08 | 000,007,266 | —- | C] () – C:\Documents and Settings\City Clerk\Application Data\Dell2335Options.xml
[2009/04/16 03:21:03 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4957.dll
[2009/04/16 03:20:41 | 000,077,824 | —- | C] () – C:\WINDOWS\setpwr32.exe
[2009/04/16 03:20:10 | 000,001,154 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2009/04/16 01:11:10 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2009/04/16 00:43:28 | 000,000,234 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/04/16 00:37:55 | 000,031,561 | R— | C] () – C:\WINDOWS\maxlink.ini
[2009/04/16 00:35:40 | 000,172,032 | —- | C] () – C:\WINDOWS\System32\SecSNMP.dll
[2009/04/16 00:35:39 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\Dell2335Port_x86.dll
[2009/04/16 00:35:31 | 000,484,592 | —- | C] () – C:\WINDOWS\SSndii.exe
[2008/05/26 22:59:42 | 000,018,904 | —- | C] () – C:\WINDOWS\System32\structuredqueryschematrivial.bin
[2008/05/26 22:59:40 | 000,106,605 | —- | C] () – C:\WINDOWS\System32\structuredqueryschema.bin
[2008/04/25 17:42:40 | 000,064,200 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2008/04/25 17:31:41 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/04/25 17:27:18 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/04/25 17:26:32 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2008/04/25 12:16:24 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/25 12:16:22 | 000,508,688 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2008/04/25 12:16:22 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/25 12:16:22 | 000,096,420 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2008/04/25 12:16:22 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/25 12:16:22 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2008/04/25 12:16:21 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2008/04/25 12:16:20 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2008/04/25 12:16:18 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/25 12:16:18 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/25 12:16:13 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/25 12:16:11 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/04/25 05:22:39 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/04/25 05:21:52 | 000,282,128 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2007/09/27 11:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 11:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 11:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini

========== LOP Check ==========

[2011/03/28 14:13:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2011/03/28 14:13:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2009/05/11 10:42:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2009/04/16 00:37:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/02/23 09:54:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Screentime
[2009/05/12 16:02:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SQL Anywhere 10
[2009/08/19 09:03:16 | 000,000,000 | —D | M] – C:\Documents and Settings\City Clerk\Application Data\Fujitsu
[2009/05/22 08:16:17 | 000,000,000 | —D | M] – C:\Documents and Settings\City Clerk\Application Data\Leadertech
[2011/03/26 16:34:07 | 000,000,000 | —D | M] – C:\Documents and Settings\City Clerk\Application Data\Online Backup
[2009/08/19 09:00:35 | 000,000,000 | —D | M] – C:\Documents and Settings\City Clerk\Application Data\PFU
[2009/05/22 08:56:08 | 000,000,000 | —D | M] – C:\Documents and Settings\City Clerk\Application Data\ScanSoft
[2010/07/09 16:19:11 | 000,000,000 | —D | M] – C:\Documents and Settings\City Clerk\Application Data\WeatherBug
[2009/04/16 00:33:13 | 000,000,000 | —D | M] – C:\Documents and Settings\City Clerk\Application Data\Windows Desktop Search
[2009/04/24 13:34:16 | 000,000,000 | —D | M] – C:\Documents and Settings\City Clerk\Application Data\Windows Search

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/04/25 17:29:32 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/03/28 14:55:17 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2011/03/28 12:51:12 | 000,014,186 | —- | M] () – C:\ComboFix.txt
[2008/04/25 17:29:32 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/04/16 03:22:27 | 000,004,150 | RH– | M] () – C:\dell.sdr
[2008/04/25 17:29:32 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2008/04/25 17:29:32 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2008/04/14 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 08:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/03/28 14:48:32 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/04/20 04:21:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/07/03 06:37:10 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/20 04:21:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/07/03 06:37:12 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/04/25 17:29:00 | 000,000,067 | —- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/10/15 00:43:18 | 000,027,648 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/15 00:44:44 | 000,671,744 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\PrintFilterPipelineSvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2008/12/04 23:55:20 | 000,307,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2009/08/06 08:52:06 | 000,001,738 | -H– | M] () – C:\Documents and Settings\City Clerk\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/04/25 05:21:09 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2008/04/25 05:21:09 | 001,089,536 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2008/04/25 05:21:09 | 000,905,216 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/04/25 17:29:41 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/04/24 13:29:20 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\City Clerk\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008/04/25 17:33:01 | 000,000,079 | —- | M] () – C:\Documents and Settings\City Clerk\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2009/05/20 09:57:49 | 001,878,888 | —- | M] (Adobe Systems Incorporated) – C:\Documents and Settings\City Clerk\Desktop\install_flash_player.exe
[2010/12/26 02:05:34 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\City Clerk\Desktop\mbam-setup-1.50.1.1100.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >
[2008/04/14 08:00:00 | 000,000,791 | —- | M] () – C:\WINDOWS\addins\fxsext.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2009/04/24 13:29:19 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\City Clerk\Favorites\Desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2011/03/28 15:08:50 | 000,065,536 | —- | M] () – C:\Documents and Settings\City Clerk\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >


GMER 1.0.15.15570 - http://www.gmer.net
Rootkit scan 2011-03-28 15:21:36
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST3250310AS rev.4.ADA
Running: gmer.exe; Driver: C:\DOCUME~1\CITYCL~1\LOCALS~1\Temp\pwliipob.sys


—- System - GMER 1.0.15 —-

SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xA82BE670]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xA82BE720]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xA82BE7C0]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xA82BE860]

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwCallbackReturn + 3018 805048B4 4 Bytes CALL CB38F0E4

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\SearchIndexer.exe[800] kernel32.dll!WriteFile 7C810E17 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device A6A0FD20

AttachedDevice fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Roxio)

—- EOF - GMER 1.0.15 —-
OTL Extras logfile created on: 3/28/2011 3:15:07 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\City Clerk\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 74.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.79 Gb Total Space | 215.07 Gb Free Space | 92.39% Space Free | Partition Type: NTFS

Computer Name: CITYCLERK | User Name: City Clerk | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\twain_32\Dell\Dell2335\Scan2Pc.exe" = C:\WINDOWS\twain_32\Dell\Dell2335\Scan2Pc.exe:*:Enabled:Scan2PC.exe – ()
"C:\WINDOWS\twain_32\Dell\Dell2335\Sscan2io.exe" = C:\WINDOWS\twain_32\Dell\Dell2335\Sscan2io.exe:*:Enabled:Sscan2io.exe – ()
"C:\WINDOWS\twain_32\Dell\ScanMgr.exe" = C:\WINDOWS\twain_32\Dell\ScanMgr.exe:*:Enabled:ScanMgr.exe – (Dell)
"C:\Program Files\Intuit\QuickBooks 2009\QBDBMgrN.exe" = C:\Program Files\Intuit\QuickBooks 2009\QBDBMgrN.exe:*:Enabled:QuickBooks 2009 Data Manager – (Intuit, Inc.)
"C:\PAYCLOCK\MAPDB.exe" = C:\PAYCLOCK\MAPDB.exe:*:Enabled:PayClock Database Connection Object Utility – (Lathem Time Corp)
"C:\PAYCLOCK\MapDBWizard.exe" = C:\PAYCLOCK\MapDBWizard.exe:*:Enabled:PayClock Database Connection Wizard Utility – (Lathem Time Corp.)
"C:\PAYCLOCK\Bteng32m.exe" = C:\PAYCLOCK\Bteng32m.exe:*:Enabled:PayClock Database Service – (MLB Computer Consulting)
"C:\PAYCLOCK\Bt32smgr.exe" = C:\PAYCLOCK\Bt32smgr.exe:*:Enabled:PayClock Server Manager – (MLB Comp Consulting)
"C:\PAYCLOCK\RBEdit.exe" = C:\PAYCLOCK\RBEdit.exe:*:Enabled:PayClock Raw Registration Editor – (Lathem Time Corp)
"C:\PAYCLOCK\InstChecker.exe" = C:\PAYCLOCK\InstChecker.exe:*:Enabled:PayClock Install Checker – (Lathem Time)
"C:\PAYCLOCK\Pcihsv.exe" = C:\PAYCLOCK\Pcihsv.exe:*:Enabled:PayClock Interactive Help Viewer – (Lathem Time)
"C:\PAYCLOCK\Pcscmgr.exe" = C:\PAYCLOCK\Pcscmgr.exe:*:Enabled:PayClock Service Connection Manager – (Lathem Time Corp.)
"C:\PAYCLOCK\dbmgr.exe" = C:\PAYCLOCK\dbmgr.exe:*:Enabled:PayClock Database Manager – (Lathem Time Corp)
"C:\PAYCLOCK\RENYRUN.exe" = C:\PAYCLOCK\RENYRUN.exe:*:Enabled:PayClock Base Module – (Lathem Time Corporation)
"C:\PAYCLOCK\TERMMGR.exe" = C:\PAYCLOCK\TERMMGR.exe:*:Enabled:PayClock Terminal Manager – (Lathem Time Corp.)
"C:\PAYCLOCK\Export32.exe" = C:\PAYCLOCK\Export32.exe:*:Enabled:PayClock Export Engine – (Lathem Time)
"C:\PAYCLOCK\LicMgr32.exe" = C:\PAYCLOCK\LicMgr32.exe:*:Enabled:PayClock License Manager – (Lathem Time)
"C:\PAYCLOCK\Reny.exe" = C:\PAYCLOCK\Reny.exe:*:Enabled:PayClock Startup Manager – (Lathem Time)
"C:\PAYCLOCK\RepWrite.exe" = C:\PAYCLOCK\RepWrite.exe:*:Enabled:PayClock Report Manager – (Lathem Time)
"C:\PAYCLOCK\Register32.exe" = C:\PAYCLOCK\Register32.exe:*:Enabled:PayClock Registration Wizard – (Lathem Time)
"C:\PAYCLOCK\EZConfig.exe" = C:\PAYCLOCK\EZConfig.exe:*:Enabled:PayClock EZ Setup Wizard – (Lathem Time)
"C:\PAYCLOCK\ExpressConfig.exe" = C:\PAYCLOCK\ExpressConfig.exe:*:Enabled:PayClock Express Setup Wizard – (Lathem Time)
"C:\PAYCLOCK\QB02Sync.exe" = C:\PAYCLOCK\QB02Sync.exe:*:Enabled:PayClock QuickBooks 2002 Employee Synchronization – (Lathem Time)
"C:\PAYCLOCK\QBExport.exe" = C:\PAYCLOCK\QBExport.exe:*:Enabled:PayClock QuickBooks 2002 Employee Export – (Lathem Time)
"C:\PAYCLOCK\QB03Sync.exe" = C:\PAYCLOCK\QB03Sync.exe:*:Enabled:PayClock QuickBooks 2003 Employee Synchronization – (Lathem Time)
"C:\PAYCLOCK\QBSetup.exe" = C:\PAYCLOCK\QBSetup.exe:*:Enabled:PayClock QuickBooks 2002 Setup Wizard – (Lathem Time)
"C:\PAYCLOCK\QB03Wiz.exe" = C:\PAYCLOCK\QB03Wiz.exe:*:Enabled:PayClock QuickBooks 2003 Setup Wizard – (Lathem Time)
"C:\PAYCLOCK\QB03Exp.exe" = C:\PAYCLOCK\QB03Exp.exe:*:Enabled:PayClock QuickBooks 2003 Employee Export – (Lathem Time)
"C:\PAYCLOCK\EmpReports.exe" = C:\PAYCLOCK\EmpReports.exe:*:Enabled:PayClock Employee Reports Install Utility – (Lathem Time)
"C:\PAYCLOCK\PC50\MAPDB.exe" = C:\PAYCLOCK\PC50\MAPDB.exe:*:Enabled:TouchStation Database Connection Object Utility – (Lathem Time Corp)
"C:\PAYCLOCK\PC50\MapDBWizard.exe" = C:\PAYCLOCK\PC50\MapDBWizard.exe:*:Enabled:PayClock Database Connection Wizard Utility – (Lathem Time Corp.)
"C:\PAYCLOCK\PC50\Bteng32m.exe" = C:\PAYCLOCK\PC50\Bteng32m.exe:*:Enabled:PayClock TouchStation Service – (MLB Computer Consulting)
"C:\PAYCLOCK\PC50\Bt32smgr.exe" = C:\PAYCLOCK\PC50\Bt32smgr.exe:*:Enabled:PayClock Server Manager – (MLB Comp Consulting)
"C:\PAYCLOCK\PC50\RBEdit.exe" = C:\PAYCLOCK\PC50\RBEdit.exe:*:Enabled:PayClock Raw Registration Editor – (Lathem Time Corp)
"C:\PAYCLOCK\PC50\Pcihsv.exe" = C:\PAYCLOCK\PC50\Pcihsv.exe:*:Enabled:PayClock Interactive Help Viewer – (Lathem Time)
"C:\PAYCLOCK\PC50\PCTSCMGR.EXE" = C:\PAYCLOCK\PC50\PCTSCMGR.EXE:*:Enabled:PayClock Terminal Service Connection Manager – (Lathem Time Corp.)
"C:\PAYCLOCK\PC50\FingerConvert.exe" = C:\PAYCLOCK\PC50\FingerConvert.exe:*:Enabled:Finger Conversion Utility – (Lathem Time Corp.)
"C:\Program Files\MySpace\IM\MySpaceIM.exe" = C:\Program Files\MySpace\IM\MySpaceIM.exe:*:Enabled:MySpaceIM – ()
"C:\Program Files\AVG\AVG9\avgam.exe" = C:\Program Files\AVG\AVG9\avgam.exe:*:Enabled:avgam.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgdiagex.exe" = C:\Program Files\AVG\AVG9\avgdiagex.exe:*:Enabled:avgdiagex.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{020D8396-D6D9-4B53-A9A1-83C47E2E27AA}" = Windows Live Call
"{0394CDC8-FABD-4ED8-B104-03393876DFDF}" = Roxio Creator Tools
"{07159635-9DFE-4105-BFC0-2817DB540C68}" = Roxio Activation Module
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0D397393-9B50-4C52-84D5-77E344289F87}" = Roxio Creator Data
"{15095BF3-A3D7-4DDF-B193-3A496881E003}" = Microsoft .NET Framework 3.0
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{299CF645-48C7-4FA1-8BCD-5CE200CF180D}" = Microsoft Search Enhancement Pack
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{2B4C7E1E-E446-4740-ADB5-9842E742EE8A}" = Windows Live Toolbar
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36DDEA9D-9C57-4E45-8029-3BBD2E9E569B}" = PLC-LIMS Report Viewer
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{505DF7A3-88D5-4DD6-9AD5-C98C2ED0CEC4}" = Windows Live Sign-in Assistant
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{5A3F6A80-7913-475E-8B96-477A952CFA43}" = SupportSoft Assisted Service
"{619CDD8A-14B6-43A1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7BB045C3-D5E4-4620-B536-DC11AACD5942}" = Broadcom Management Programs
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83FFCFC7-88C6-41C6-8752-958A45325C82}" = Roxio Creator Audio
"{848E36E7-0784-49C3-81F4-DD946ABAF46A}" = ScanSoft PaperPort 11
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{966669E6-5D3E-4604-A357-76249A928AAA}" = Brother HL-5240
"{97F81AF1-0E47-DC99-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 ATL (x86) WinSXS MSM
"{98CB24AD-52FB-DB5F-FF1F-C8B3B9A1E18E}" = Visual C++ 8.0 CRT (x86) WinSXS MSM
"{9A2F0810-3622-4E86-9072-973FBE1679C5}" = QuickBooks Pro 2009
"{9A2F0810-369F-4E86-9072-973FBE1679C5}" = QuickBooks
"{9EDA3DD1-130D-4EE1-A3D2-5A3D795CC8C9}" = MFCLOC
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser
"{A9255718-8A40-45F9-B738-93655FBD4F6F}" = QuickBooks Online Backup
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AC76BA86-1033-F400-BA7E-000000000004}" = Adobe Acrobat 9 Standard - English, Français, Deutsch
"{AC76BA86-1033-F400-BA7E-000000000004}_920" = Adobe Acrobat 9.2.0 - CPSID_50026
"{AC76BA86-1033-F400-BA7E-000000000004}{AC76BA86-1033-F400-BA7E-000000000004}" = Adobe Acrobat 9 Standard - English, Français, Deutsch
"{B32C4059-6E7A-41EF-AD20-56DF1872B923}" = Business Contact Manager for Outlook 2007
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{C918E3D8-208F-43DB-B346-6299D59336D7}" = CardMinder V3.2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D4F2AFD3-0167-4464-B92F-78AB6DA8A0AA}" = CardMinder V3.2
"{D9D754A1-EAC5-406C-A28B-C49B1E846711}" = Windows Live Essentials
"{DBCDB997-EEEB-4BE9-BAFF-26B4094DBDE6}" = ScanSnap Manager
"{E3CAE4F2-97CE-4985-8732-2206EF495147}" = Dell 2335 Fax
"{E58F3B88-3B3E-4F85-9323-04789D979C15}" = ScanSnap Organizer
"{E91E8912-769D-42F0-8408-0E329443BABC}" = Ralink Wireless LAN
"{E9BE42A2-6815-42BC-82A9-A60401ABD417}" = ScanSnap Organizer
"{E9F44C98-B8B6-480F-AF7B-E42A0A46F4E3}" = Microsoft SQL Server VSS Writer
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
"{F73A5B18-EB75-4B2C-B32D-9457576E2417}" = Windows Live Photo Gallery
"{F9B3DD02-B0B3-42E9-8650-030DFF0D133D}" = Microsoft SQL Server Native Client
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"ag_jack-o-lanterns" = ag_jack-o-lanterns Screen Saver
"alongwintersnap_3129553" = alongwintersnap_3129553 Screen Saver
"AVG9Uninstall" = AVG 9.0
"Business Contact Manager for Outlook 2007" = Business Contact Manager for Outlook 2007
"fallinthecountry_3113669" = fallinthecountry_3113669 Screen Saver
"friendshipangel_3122091" = friendshipangel_3122091 Screen Saver
"HDMI" = Intel® Graphics Media Accelerator Driver
"IMM4 Codec_is1" = IMM4 VCM Codec 1.0.0.10
"kittensinautumn_3145466" = kittensinautumn_3145466 Screen Saver
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Mozilla Firefox (3.5.18)" = Mozilla Firefox (3.5.18)
"MySpaceIM" = MySpaceIM
"PayClock Express Version 5" = PayClock Express Version 5
"playfuldolphin_3122094" = playfuldolphin_3122094 Screen Saver
"PROHYBRIDR" = 2007 Microsoft Office system
"springbutterflies_3042993" = springbutterflies_3042993 Screen Saver
"WinLiveSuite_Wave3" = Windows Live Essentials
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Adobe Acrobat Connect Add-in" = Adobe Acrobat Connect Add-in

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/25/2011 5:58:38 PM | Computer Name = CITYCLERK | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module ntdll.dll, version 5.1.2600.5512, fault address 0x00023825.

Error - 3/28/2011 8:14:45 AM | Computer Name = CITYCLERK | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module icuuc36.dll, version 3.6.0.0, fault address 0x00001f94.

Error - 3/28/2011 8:57:12 AM | Computer Name = CITYCLERK | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.5512, faulting
module ntdll.dll, version 5.1.2600.5512, fault address 0x00023825.

Error - 3/28/2011 12:43:11 PM | Computer Name = CITYCLERK | Source = Application Error | ID = 1000
Description = Faulting application extract.cfxxe, version 0.0.0.0, faulting module
crtdll.dll, version 4.0.1183.1, fault address 0x000115ce.

Error - 3/28/2011 12:44:54 PM | Computer Name = CITYCLERK | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 3/28/2011 12:44:54 PM | Computer Name = CITYCLERK | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 3/28/2011 12:44:54 PM | Computer Name = CITYCLERK | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The server name or address could not be resolved

Error - 3/28/2011 1:17:49 PM | Computer Name = CITYCLERK | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 3/28/2011 2:26:43 PM | Computer Name = CITYCLERK | Source = Application Hang | ID = 1002
Description = Hanging application TeaTimer.exe, version 1.6.4.26, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 3/28/2011 2:49:55 PM | Computer Name = CITYCLERK | Source = Application Hang | ID = 1002
Description = Hanging application TeaTimer.exe, version 1.6.4.26, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 3/28/2011 1:23:33 PM | Computer Name = CITYCLERK | Source = Service Control Manager | ID = 7001
Description = The Symantec Real Time Storage Protection service depends on the Symantec
Real Time Storage Protection (PEL) service which failed to start because of the
following error: %%2

Error - 3/28/2011 2:06:52 PM | Computer Name = CITYCLERK | Source = Service Control Manager | ID = 7000
Description = The DgiVecp service failed to start due to the following error: %%2

Error - 3/28/2011 2:06:52 PM | Computer Name = CITYCLERK | Source = Service Control Manager | ID = 7000
Description = The SSPORT service failed to start due to the following error: %%2

Error - 3/28/2011 2:06:52 PM | Computer Name = CITYCLERK | Source = Service Control Manager | ID = 7000
Description = The DgiVecp service failed to start due to the following error: %%2

Error - 3/28/2011 2:22:19 PM | Computer Name = CITYCLERK | Source = Service Control Manager | ID = 7000
Description = The DgiVecp service failed to start due to the following error: %%2

Error - 3/28/2011 2:22:19 PM | Computer Name = CITYCLERK | Source = Service Control Manager | ID = 7000
Description = The SSPORT service failed to start due to the following error: %%2

Error - 3/28/2011 2:22:19 PM | Computer Name = CITYCLERK | Source = Service Control Manager | ID = 7000
Description = The DgiVecp service failed to start due to the following error: %%2

Error - 3/28/2011 2:49:33 PM | Computer Name = CITYCLERK | Source = Service Control Manager | ID = 7000
Description = The DgiVecp service failed to start due to the following error: %%2

Error - 3/28/2011 2:49:33 PM | Computer Name = CITYCLERK | Source = Service Control Manager | ID = 7000
Description = The SSPORT service failed to start due to the following error: %%2

Error - 3/28/2011 2:49:33 PM | Computer Name = CITYCLERK | Source = Service Control Manager | ID = 7000
Description = The DgiVecp service failed to start due to the following error: %%2


< End of report >
No problem :)

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image] 

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI