This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer is infected with a virus identified by Antivir as exp/byteverify.ba.41. Hijack this log file printed below:

You guys have been terrific in the past. Thanks in advance for your assistance.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:53:34 PM, on 4/18/2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.21256)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTSvcCDA.EXE
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe
C:\WINDOWS\system32\NLSSRV32.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Avira\AntiVir Desktop\avcenter.exe
c:\program files\avira\antivir desktop\avconfig.exe
E:\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:47392
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [JobHisInit] C:\Program Files\RMClient\JobHisInit.exe
O4 - HKLM\..\Run: [MplSetUp] C:\Program Files\RMClient\MplSetUp.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Verizon_McciTrayApp] "C:\Program Files\Verizon\McciTrayApp.exe"
O4 - HKLM\..\Run: [Pvizes] rundll32.exe "C:\WINDOWS\ocoruhakucadic.dll",Startup
O4 - HKLM\..\Run: [35669029] C:\DOCUME~1\ALLUSE~1\APPLIC~1\35669029\35669029.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe
O4 - HKCU\..\Run: [aginauib] C:\DOCUME~1\Owner\LOCALS~1\Temp\eeynrtghp\iaftsvgxsik.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103470 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; GTB5; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://www.shockwave.com/contentPlay/shockwave.jsp?id=jigsawpuzzles&refCode=&brand=ag"
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…mp;n=2010122308
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Mahjong%20Escape%20-%20Ancient%20Japan/Images/stg_drm.ocx
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Mahjong%20Escape%20-%20Ancient%20Japan/Images/armhelper.ocx
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NitroPDFDriverCreatorReadSpool (NitroDriverReadSpool) - Nitro PDF Software - C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe
O23 - Service: NLS Service (nlsX86cc) - Nalpeiron Ltd. - C:\WINDOWS\system32\NLSSRV32.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 9036 bytes
:welcome:

When where done you need to upgrade to SP 3

HJT is not used much anymore , we have moved on to better scanners, lets do this

Please download ATF Cleaner by Atribune to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.




Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please





OTL by OldTimer
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the "Scan All Users" checkbox.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
Thanks Ken for getting back to me. I have dealt with the issue, in a way. The virus disabled any .exe it saw, so downloading any additional malware fighters wouldn't do any good. I was able to create a rescue disc from a Kaspersky app that I downloaded to another computer. It was able to zap all the bad guys, at least to the naked eye. The only side effect is an apparent DNS problem with Internet Explorer, so at the moment I can't download anything, although I suppose I could sneaker whatever is needed from another machine. Should I still scan and post the results? Dan
Yes, I would run ATF Cleaner, Malwarebytes and then run OTL, post the logs from MBAM and OTL

You can try downloading this file to the other computer and transfer it to the infected one and see if it helps running programs

Please download exeHelper to your desktop.

Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).
Programs are running fine, now it's just the one issue with IE. I will run the scans this evening when I get home and post results. Thanks! Dan
Okay, here is the Mbam log and the OLT.txt log. OLT did not open an Extras.text, and I could not find it anywhere on C:\.

Thanks!


Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6408

Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.11

4/20/2011 6:48:49 PM
mbam-log-2011-04-20 (18-48-49).txt

Scan type: Quick scan
Objects scanned: 149684
Time elapsed: 4 minute(s), 11 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 24
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 9
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search;\(default) (Adware.Hotbar) -> Value: (default) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer (PUM.Bad.Proxy) -> Value: ProxyServer -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\aginauib (Trojan.FakeAlertR.Gen) -> Value: aginauib -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\35669029 (Trojan.SCTool.Gen) -> Value: 35669029 -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
c:\documents and settings\all users\application data\35669029 (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\program files\funwebproducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\screensaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\funwebproducts\Shared (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Files Infected:
c:\documents and settings\Owner\application data\avdrn.dat (Malware.Trace) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\History\search3 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.


OTL logfile created on: 4/20/2011 6:53:10 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 636.00 Mb Available Physical Memory | 62.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 73.27 Gb Free Space | 65.55% Space Free | Partition Type: NTFS
Drive E: | 3.77 Gb Total Space | 1.60 Gb Free Space | 42.38% Space Free | Partition Type: FAT32

Computer Name: OWNER-752E2D2FE | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\WINDOWS\system32\NLSSRV32.EXE (Nalpeiron Ltd.)
PRC - C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe (Nitro PDF Software)
PRC - C:\Program Files\verizon\McciTrayApp.exe (Alcatel-Lucent)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\CtHelper.exe (Creative Technology Ltd)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe (Hewlett-Packard Co.)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Microsoft Hardware\Mouse\point32.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Hardware\Keyboard\type32.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Common Files\Motive\McciContextHook_DSR.dll (Alcatel-Lucent)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\ctagent.dll (Creative Technology Ltd)
MOD - C:\Program Files\Microsoft Hardware\Mouse\Msh_zwf.dll (Microsoft Corporation)
MOD - C:\Program Files\Microsoft Hardware\Mouse\point32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (nlsX86cc) – C:\WINDOWS\system32\NLSSRV32.EXE (Nalpeiron Ltd.)
SRV - (NitroDriverReadSpool) – C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe (Nitro PDF Software)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (hzqrp) – C:\WINDOWS\System32\drivers\hzqrp.sys ()
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (COMMONFX.DLL) – C:\WINDOWS\system32\COMMONFX.DLL (Creative Technology Ltd)
DRV - (CT20XUT.DLL) – C:\WINDOWS\system32\CT20XUT.DLL (Creative Technology Ltd.)
DRV - (CTHWIUT.DLL) – C:\WINDOWS\system32\CTHWIUT.DLL (Creative Technology Ltd.)
DRV - (CTEXFIFX.DLL) – C:\WINDOWS\system32\CTEXFIFX.DLL (Creative Technology Ltd.)
DRV - (CTEDSPSY.DLL) – C:\WINDOWS\system32\CTEDSPSY.DLL (Creative Technology Ltd)
DRV - (CTEDSPIO.DLL) – C:\WINDOWS\system32\CTEDSPIO.DLL (Creative Technology Ltd)
DRV - (CTEDSPFX.DLL) – C:\WINDOWS\system32\CTEDSPFX.DLL (Creative Technology Ltd)
DRV - (CTERFXFX.DLL) – C:\WINDOWS\system32\CTERFXFX.DLL (Creative Technology Ltd)
DRV - (CTEAPSFX.DLL) – C:\WINDOWS\system32\CTEAPSFX.DLL (Creative Technology Ltd)
DRV - (CTSBLFX.DLL) – C:\WINDOWS\system32\CTSBLFX.DLL (Creative Technology Ltd)
DRV - (CTAUDFX.DLL) – C:\WINDOWS\system32\CTAUDFX.DLL (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (hap17v2k) – C:\WINDOWS\system32\drivers\haP17v2k.sys (Creative Technology Ltd)
DRV - (hap16v2k) – C:\WINDOWS\system32\drivers\haP16v2k.sys (Creative Technology Ltd)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ctdvda2k) – C:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (MarvinBus) – C:\WINDOWS\system32\drivers\MarvinBus.sys (Pinnacle Systems GmbH)
DRV - (EL2000) – C:\WINDOWS\system32\drivers\EL2K_XP.sys (3Com Corporation)
DRV - (BENDER) – C:\WINDOWS\system32\drivers\bender.sys (Pinnacle Systems GmbH)
DRV - (MaxtorFrontPanel1) – C:\WINDOWS\system32\drivers\mxofwfp.sys (Maxtor Corp.)
DRV - (ctgame) – C:\WINDOWS\system32\drivers\ctgame.sys (Creative Technology Ltd.)
DRV - (PfModNT) – C:\WINDOWS\system32\PFMODNT.SYS (Creative Technology Ltd.)
DRV - (IPFilter) – C:\WINDOWS\system32\drivers\ipfilter.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes

IE - HKU\S-1-5-21-861567501-1682526488-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKU\S-1-5-21-861567501-1682526488-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-861567501-1682526488-1417001333-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.msn.com/
IE - HKU\S-1-5-21-861567501-1682526488-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-21-861567501-1682526488-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.ask.com/?gcht=HC&o;=101706&l;=dis"
FF - prefs.js..extensions.enabledItems: {1C47082E-5EB1-4209-BDCE-00C84857B429}:1.9.1
FF - prefs.js..network.proxy.no_proxies_on: "*.local"

FF - HKLM\software\mozilla\Firefox\Extensions\\{1C47082E-5EB1-4209-BDCE-00C84857B429}: C:\Documents and Settings\Owner\Local Settings\Application Data\{1C47082E-5EB1-4209-BDCE-00C84857B429} [2010/03/01 19:07:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/06 09:17:55 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/19 23:28:27 | 000,000,000 | —D | M]

[2010/06/05 09:00:32 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2011/03/28 08:43:23 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\e5cdqlj5.default\extensions
[2010/08/09 12:36:15 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\e5cdqlj5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/10/13 21:50:31 | 000,002,568 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\e5cdqlj5.default\searchplugins\askcom.xml
[2010/06/05 09:00:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/03/01 19:07:12 | 000,000,000 | —D | M] (XULRunner) – C:\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\APPLICATION DATA\{1C47082E-5EB1-4209-BDCE-00C84857B429}

O1 HOSTS File: ([2004/08/04 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKLM\..\Toolbar: (&Google; Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKU\S-1-5-21-861567501-1682526488-1417001333-1003\..\Toolbar\WebBrowser: (&Google; Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CtHelper.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [CTxfiHlp] C:\WINDOWS\System32\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [IntelliType] C:\Program Files\Microsoft Hardware\Keyboard\type32.exe (Microsoft Corporation)
O4 - HKLM..\Run: [JobHisInit] C:\Program Files\RMClient\JobHisInit.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MplSetUp] C:\Program Files\RMClient\MplSetUp.exe (RICOH CO.,LTD.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] File not found
O4 - HKLM..\Run: [POINTER] File not found
O4 - HKLM..\Run: [Pvizes] File not found
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe (Alcatel-Lucent)
O4 - HKU\S-1-5-21-861567501-1682526488-1417001333-1003..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe (Creative Technology Ltd.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKU\.DEFAULT..\RunOnce: [ShowDeskFix] File not found
O4 - HKU\S-1-5-18..\RunOnce: [ShowDeskFix] File not found
O4 - HKU\S-1-5-19..\RunOnce: [ShowDeskFix] File not found
O4 - HKU\S-1-5-20..\RunOnce: [ShowDeskFix] File not found
O4 - HKU\S-1-5-21-861567501-1682526488-1417001333-1003..\RunOnce: [Shockwave Updater] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-861567501-1682526488-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Mahjong%20Escape%20-%20Ancient%20Japan/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/software/…tiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Mahjong%20Escape%20-%20Ancient%20Japan/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/12/02 13:44:44 | 000,000,035 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{17351d7c-6a8c-11e0-9886-000c6eb8e8d0}\Shell - "" = AutoRun
O33 - MountPoints2\{17351d7c-6a8c-11e0-9886-000c6eb8e8d0}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{17351d7c-6a8c-11e0-9886-000c6eb8e8d0}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{45740cdf-5a9f-11df-970c-000c6eb8e8d0}\Shell - "" = AutoRun
O33 - MountPoints2\{45740cdf-5a9f-11df-970c-000c6eb8e8d0}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{45740cdf-5a9f-11df-970c-000c6eb8e8d0}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{45740ce0-5a9f-11df-970c-000c6eb8e8d0}\Shell\AutoRun\command - "" = GizmoSecure\Windows\GizmoSecure30.exe
O33 - MountPoints2\{ba15aea5-d878-11df-97b7-000c6eb8e8d0}\Shell - "" = AutoRun
O33 - MountPoints2\{ba15aea5-d878-11df-97b7-000c6eb8e8d0}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{ba15aea5-d878-11df-97b7-000c6eb8e8d0}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{d118a906-1002-11df-a700-000c6eb8e8d0}\Shell\AutoRun\command - "" = E:\Seagate\Installer\InstallSeagateManager.exe
O33 - MountPoints2\{d118a906-1002-11df-a700-000c6eb8e8d0}\Shell\Install\command - "" = E:\Seagate\Installer\InstallSeagateManager.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O36 - AppCertDlls: dxdikrnl - (C:\WINDOWS\system32\runoinst.dll) - File not found
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/04/20 18:51:54 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/04/20 18:50:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\Logs 4-20-11
[2011/04/20 18:25:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2011/04/20 18:25:06 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/04/20 18:25:06 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/04/20 18:25:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/04/20 18:25:01 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/04/20 18:25:01 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/04/20 18:24:10 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Owner\Desktop\mbam-setup-1.50.1.1100.exe
[2011/04/20 18:16:14 | 000,050,688 | —- | C] (Atribune.org) – C:\Documents and Settings\Owner\Desktop\ATF-Cleaner.exe
[2011/04/19 23:27:48 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/04/19 15:47:46 | 000,000,000 | —D | C] – C:\d1d9367ad1aa1ed236a9
[2011/04/19 15:47:46 | 000,000,000 | —D | C] – C:\_300171_
[2011/04/19 15:47:40 | 000,000,000 | —D | C] – C:\8b5be84f11cbbcb10ec6c37d
[2011/04/19 08:42:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
[2011/04/18 18:03:29 | 000,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2011/04/18 17:29:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Avira
[2007/04/09 13:32:58 | 000,034,816 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[2007/04/09 13:19:16 | 000,010,240 | —- | C] ( ) – C:\WINDOWS\System32\killapps.exe
[5 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Owner\Desktop\*.tmp files -> C:\Documents and Settings\Owner\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/04/20 18:51:14 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/04/20 18:51:00 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/04/20 18:50:59 | 000,054,016 | —- | M] () – C:\WINDOWS\System32\drivers\xcldybhk.sys
[2011/04/20 18:25:06 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/20 18:22:54 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Owner\Desktop\mbam-setup-1.50.1.1100.exe
[2011/04/20 18:14:34 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Owner\Desktop\ATF-Cleaner.exe
[2011/04/20 18:04:25 | 000,432,356 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/04/20 18:04:25 | 000,067,312 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/04/20 18:00:37 | 004,958,588 | —- | M] () – C:\WINDOWS\{00000002-00000000-0000000B-00001102-00000004-10071102}.CDF
[2011/04/20 18:00:09 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/04/20 18:00:06 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/04/20 18:00:05 | 1072,484,352 | -HS- | M] () – C:\hiberfil.sys
[2011/04/20 17:48:03 | 000,031,056 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-0000000B-00001102-00000004-10071102}.rfx
[2011/04/20 17:48:03 | 000,031,056 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-0000000B-00001102-00000004-10071102}.rfx
[2011/04/20 17:48:03 | 000,030,528 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-0000000B-00001102-00000004-10071102}.rfx
[2011/04/20 17:48:03 | 000,030,528 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-0000000B-00001102-00000004-10071102}.rfx
[2011/04/20 17:48:03 | 000,011,564 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-0000000B-00001102-00000004-10071102}.rfx
[2011/04/20 17:48:03 | 000,001,080 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2011/04/20 17:48:03 | 000,001,080 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2011/04/20 17:47:36 | 004,958,588 | —- | M] () – C:\WINDOWS\{00000002-00000000-0000000B-00001102-00000004-10071102}.BAK
[2011/04/20 17:44:23 | 000,522,577 | —- | M] () – C:\WINDOWS\System32\192.168.1.131
[2011/04/20 12:47:23 | 000,007,164 | —- | M] () – C:\Documents and Settings\Owner\Application Data\PrimoPDFSet.xml
[2011/04/20 12:34:54 | 000,002,483 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Microsoft Word.lnk
[2011/04/20 11:16:13 | 005,602,641 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Le Bananier (Rehearsal Recording).mp3
[2011/04/19 23:28:27 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/04/19 08:38:08 | 000,001,514 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 8.0.lnk
[2011/04/17 22:20:39 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/04/13 12:40:21 | 000,000,488 | —- | M] () – C:\hpfr5550.xml
[2011/04/12 12:37:03 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/04/12 12:30:44 | 000,066,813 | —- | M] () – C:\Documents and Settings\Owner\Desktop\CELEBRATION-COMMITTEE Application.pdf
[2011/03/31 18:50:27 | 001,319,792 | —- | M] () – C:\Documents and Settings\Owner\Desktop\columbia receipt.jpg
[2011/03/31 18:45:39 | 000,710,814 | —- | M] () – C:\Documents and Settings\Owner\Desktop\salem receipt.pdf
[5 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Owner\Desktop\*.tmp files -> C:\Documents and Settings\Owner\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/04/20 18:50:59 | 000,054,016 | —- | C] () – C:\WINDOWS\System32\drivers\xcldybhk.sys
[2011/04/20 18:25:06 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/04/20 11:16:12 | 005,602,641 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Le Bananier (Rehearsal Recording).mp3
[2011/04/12 12:30:44 | 000,066,813 | —- | C] () – C:\Documents and Settings\Owner\Desktop\CELEBRATION-COMMITTEE Application.pdf
[2011/03/31 18:50:27 | 001,319,792 | —- | C] () – C:\Documents and Settings\Owner\Desktop\columbia receipt.jpg
[2011/03/31 18:45:38 | 000,710,814 | —- | C] () – C:\Documents and Settings\Owner\Desktop\salem receipt.pdf
[2010/11/05 08:31:47 | 000,001,957 | —- | C] () – C:\WINDOWS\unins000.dat
[2010/10/29 17:43:02 | 000,004,841 | —- | C] () – C:\WINDOWS\xnview.ini
[2010/06/05 09:00:24 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/03/01 19:07:40 | 000,000,120 | —- | C] () – C:\WINDOWS\Dyedexinod.dat
[2010/03/01 19:07:40 | 000,000,000 | —- | C] () – C:\WINDOWS\Vkilurituc.bin
[2010/03/01 19:02:11 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\drivers\hzqrp.sys
[2010/03/01 18:59:29 | 000,000,024 | —- | C] () – C:\Documents and Settings\NetworkService\Application Data\rbuwzv.dat
[2009/12/12 10:22:52 | 000,000,020 | —- | C] () – C:\WINDOWS\JatJJJg.dat
[2009/12/12 10:22:31 | 000,110,080 | —- | C] () – C:\WINDOWS\System32\LFPNG62N.DLL
[2009/12/12 10:22:31 | 000,078,336 | —- | C] () – C:\WINDOWS\System32\LTIMG62N.DLL
[2009/12/12 10:22:31 | 000,047,616 | —- | C] () – C:\WINDOWS\System32\LFTIF62N.DLL
[2009/12/12 10:22:31 | 000,043,008 | —- | C] () – C:\WINDOWS\System32\LTFIL62N.DLL
[2009/12/12 10:22:31 | 000,024,064 | —- | C] () – C:\WINDOWS\System32\LTTWN62N.DLL
[2009/12/12 10:22:31 | 000,023,552 | —- | C] () – C:\WINDOWS\System32\LFPCX62N.DLL
[2009/12/12 10:22:31 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\LFPCT62N.DLL
[2009/12/12 10:22:31 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\LFGIF62N.DLL
[2009/12/12 10:22:31 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\LFBMP62N.DLL
[2009/12/12 10:22:31 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\LFPSD62N.DLL
[2009/12/12 10:22:31 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\LFWMF62N.DLL
[2009/12/12 10:22:31 | 000,018,944 | —- | C] () – C:\WINDOWS\System32\LFIMG62N.DLL
[2009/12/12 10:22:31 | 000,017,920 | —- | C] () – C:\WINDOWS\System32\LFMAC62N.DLL
[2009/12/12 10:22:30 | 000,175,616 | —- | C] () – C:\WINDOWS\System32\LFFAX62N.DLL
[2009/12/12 10:22:30 | 000,158,720 | —- | C] () – C:\WINDOWS\System32\LFCMP62N.DLL
[2009/12/12 10:22:30 | 000,029,184 | —- | C] () – C:\WINDOWS\System32\LTWND62N.DLL
[2009/12/12 10:22:30 | 000,022,528 | —- | C] () – C:\WINDOWS\System32\LFEPS62N.DLL
[2009/10/01 07:43:46 | 000,054,844 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/09/16 19:27:58 | 000,508,224 | —- | C] () – C:\WINDOWS\System32\ICCProfiles.dll
[2008/11/22 11:15:37 | 000,019,558 | —- | C] () – C:\WINDOWS\hpoins01.dat
[2008/11/22 11:15:37 | 000,016,606 | —- | C] () – C:\WINDOWS\hpomdl01.dat
[2008/11/17 11:51:17 | 000,007,164 | —- | C] () – C:\Documents and Settings\Owner\Application Data\PrimoPDFSet.xml
[2008/11/17 11:48:54 | 000,176,235 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2008/11/11 11:37:53 | 000,000,604 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\T2
[2008/11/11 11:37:53 | 000,000,604 | -H– | C] () – C:\Program Files\STLL Notifier
[2008/11/11 08:39:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\RPCS.ini
[2008/11/11 08:38:12 | 000,041,250 | —- | C] () – C:\WINDOWS\RicDB.ini
[2008/11/11 08:37:57 | 000,002,199 | R— | C] () – C:\WINDOWS\PmData.Dat
[2008/11/11 08:37:57 | 000,000,226 | —- | C] () – C:\WINDOWS\PMJobCli.ini
[2008/11/11 08:37:55 | 000,012,358 | —- | C] () – C:\WINDOWS\PMRicMb.ini
[2008/11/11 08:37:55 | 000,006,702 | —- | C] () – C:\WINDOWS\PMRicPMb.ini
[2008/11/11 08:37:55 | 000,005,390 | —- | C] () – C:\WINDOWS\PMPrtMb.ini
[2008/11/11 08:37:55 | 000,004,303 | —- | C] () – C:\WINDOWS\PMRicFMb.ini
[2008/11/11 08:37:55 | 000,003,005 | —- | C] () – C:\WINDOWS\PMDvPrn.ini
[2008/11/11 08:37:55 | 000,002,102 | —- | C] () – C:\WINDOWS\PMDvDev.ini
[2008/11/11 08:37:55 | 000,002,047 | —- | C] () – C:\WINDOWS\PMDIOMb.ini
[2008/11/11 08:37:55 | 000,002,036 | —- | C] () – C:\WINDOWS\PMHostMb.ini
[2008/11/11 08:37:55 | 000,001,885 | —- | C] () – C:\WINDOWS\PMPSIOMb.ini
[2008/11/11 08:37:55 | 000,001,727 | —- | C] () – C:\WINDOWS\PMRicSMb.ini
[2008/11/11 08:37:55 | 000,001,706 | —- | C] () – C:\WINDOWS\PMRicCMb.ini
[2008/11/11 08:37:55 | 000,001,494 | —- | C] () – C:\WINDOWS\PMMib2Mb.ini
[2008/11/11 08:37:55 | 000,001,143 | —- | C] () – C:\WINDOWS\PMDPIMb.ini
[2008/11/11 08:37:55 | 000,001,110 | —- | C] () – C:\WINDOWS\PMDvFax.ini
[2008/11/11 08:37:55 | 000,001,094 | —- | C] () – C:\WINDOWS\PMAxsMb.ini
[2008/11/11 08:37:55 | 000,000,842 | —- | C] () – C:\WINDOWS\PMDvScan.ini
[2008/11/11 08:37:55 | 000,000,423 | —- | C] () – C:\WINDOWS\PMDvCopy.ini
[2008/11/11 08:37:55 | 000,000,332 | —- | C] () – C:\WINDOWS\PMSnmpMb.ini
[2008/11/11 08:37:54 | 000,000,035 | —- | C] () – C:\WINDOWS\RidocPrn.ini
[2008/11/11 08:37:50 | 000,376,832 | —- | C] () – C:\WINDOWS\System32\rpnv2ui.dll
[2008/11/11 08:37:50 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\rtcpf.dll
[2008/11/11 08:37:50 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\RLPR.dll
[2008/11/11 08:37:49 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\PMObservps.dll
[2008/11/10 20:29:54 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/11/10 14:46:27 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/11/10 14:41:30 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/11/10 09:32:04 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/11/10 09:30:45 | 000,281,336 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/04/28 13:13:33 | 000,000,310 | —- | C] () – C:\WINDOWS\primopdf.ini
[2007/04/12 09:10:28 | 000,105,728 | —- | C] () – C:\WINDOWS\System32\APOMgrH.dll
[2007/04/09 13:55:14 | 000,097,785 | —- | C] () – C:\WINDOWS\System32\instwdm.ini
[2007/04/09 13:55:14 | 000,000,054 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2007/04/09 13:33:50 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CTBurst.dll
[2007/04/09 13:32:32 | 000,037,888 | —- | C] () – C:\WINDOWS\System32\psconv.exe
[2007/04/09 13:24:30 | 000,325,821 | —- | C] () – C:\WINDOWS\System32\ctdlang.dat
[2007/04/09 13:24:30 | 000,046,273 | —- | C] () – C:\WINDOWS\System32\ctdnlstr.dat
[2007/04/09 13:21:44 | 000,048,128 | —- | C] () – C:\WINDOWS\System32\regplib.exe
[2007/04/09 13:21:28 | 000,149,838 | —- | C] () – C:\WINDOWS\System32\ctbas2w.dat
[2007/04/09 13:19:44 | 000,274,587 | —- | C] () – C:\WINDOWS\System32\ctsbas2w.dat
[2007/04/09 13:19:36 | 000,241,084 | —- | C] () – C:\WINDOWS\System32\CTSBASW.DAT
[2007/04/09 13:19:36 | 000,115,166 | —- | C] () – C:\WINDOWS\System32\CTBASICW.DAT
[2007/04/09 13:19:20 | 000,313,207 | —- | C] () – C:\WINDOWS\System32\ctstatic.dat
[2007/04/09 13:19:20 | 000,053,932 | —- | C] () – C:\WINDOWS\System32\ctdaught.dat
[2007/04/09 13:19:18 | 000,005,120 | —- | C] () – C:\WINDOWS\System32\enlocstr.exe
[2006/10/02 10:25:18 | 000,000,307 | —- | C] () – C:\WINDOWS\System32\kill.ini
[2005/06/16 11:17:16 | 000,071,680 | —- | C] () – C:\WINDOWS\System32\ctmmactl.dll
[2005/04/01 17:16:00 | 000,540,672 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2004/08/04 08:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 08:00:00 | 000,432,356 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 08:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 08:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 08:00:00 | 000,067,312 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 08:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 08:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 08:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 08:00:00 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2004/08/04 08:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/01/16 04:00:00 | 000,076,946 | —- | C] () – C:\WINDOWS\unins000.exe
[2003/03/09 22:31:04 | 000,561,152 | —- | C] () – C:\WINDOWS\System32\hpotscl.dll
[2002/04/11 14:47:52 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\msmscoin.dll
[2001/08/18 12:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/18 12:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat

========== LOP Check ==========

[2009/10/19 16:08:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\A-PDF
[2010/05/31 07:42:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/12/23 09:48:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\JollyBear
[2011/02/25 14:22:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nitro PDF
[2011/04/09 22:20:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/03/24 12:55:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/04/06 12:59:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/15 12:50:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/07 14:38:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/03/05 12:45:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVG9
[2009/05/27 08:40:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/03/09 14:40:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Downloaded Installations
[2011/02/25 00:35:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\EurekaLog
[2008/11/13 08:10:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FileMaker
[2011/04/12 14:04:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Nitro PDF
[2008/11/10 15:58:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\OpenOffice.org
[2010/12/23 09:47:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SpinTop
[2010/11/08 09:48:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Tavultesoft
[2009/02/22 12:51:39 | 000,000,342 | —- | M] () – C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 2170 series#1227367500.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 186 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D17E8AFC
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:211ED887

< End of report >
Hello Dan,

Before we proceed any further, lets check these files

You need to enable windows to show all files and folders, instructions Here

Go to VirusTotal and submit these files for analysis, just use the BROWSE feature and then Send File , you will get a report back, post the report into this thread for me to see. If the site says this file has already been checked, have them check it again

C:\WINDOWS\System32\drivers\hzqrp.sys
C:\WINDOWS\System32\drivers\xcldybhk.sys


If the site is busy you can try this one
http://virusscan.jotti.org/en



You have the Ask Toolbar installed, see if you can uninstall it

* It promotes its toolbars on sites targeted at kids.
* It promotes its toolbars through ads that appear to be part of other companies' sites.
* It promotes its toolbars through other companies' spyware.
* It is Installed without any disclosure whatsoever and without any consent from the user whatsoever.
* It solicits installations via "deceptive door openers" that do not accurately describe the offer; failing to affirmatively show a license agreement; linking to a EULA via an off-screen link.
* It makes confusing changes to user's browsers - increasing Ask's revenues while taking users to pages they didn't intend to visit.
Sorry to keep you waiting, I had to run out to a rehearsal.

I'm posting the VT logfile first, followed by the OLT extra.txt file that I found.

Thanks for your patience.

Dan

VT Community Sign in ▼ My account ▼ Sign out Signing out… Languages ▼
VirusTotal's website has changed, we need new translations, do you feel like helping the community?
[removed] in to VT Community
Safety ratings and user comments (disinfection, in-the-wild locations, reverse engineering reports, etc.) on malware and URLs, free and easy.

email
password
Keep me logged in
Sign in
Signing in, please wait…
Login failed, please try again
Forgot your password? Create an account
Edit my profile
View my profile
Inbox

Virustotal is a service that analyzes suspicious files and URLs and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information…

9 VT Community user(s) with a total of 8196 reputation credit(s) say(s) this sample is goodware. 4 VT Community user(s) with a total of 2642 reputation credit(s) say(s) this sample is malware.
File name: xcldybhk.sys
Submission date: 2011-04-21 02:10:33 (UTC)
Current status: queued queued analysing finished


Result: 2/ 41 (4.9%)
VT Community

goodware
Safety score: 75.6%

Compact Print results
Antivirus Version Last Update Result
AhnLab-V3 2011.04.21.00 2011.04.21 -
AntiVir 7.11.6.215 2011.04.20 -
Antiy-AVL 2.0.3.7 2011.04.21 -
Avast 4.8.1351.0 2011.04.20 -
Avast5 5.0.677.0 2011.04.20 -
AVG 10.0.0.1190 2011.04.20 -
BitDefender 7.2 2011.04.21 -
CAT-QuickHeal 11.00 2011.04.20 -
ClamAV 0.97.0.0 2011.04.20 BC.Heuristics.Rootkit.B-11.MV
Commtouch 5.3.2.6 2011.04.21 -
Comodo 8417 2011.04.21 -
DrWeb 5.0.2.03300 2011.04.21 -
eSafe 7.0.17.0 2011.04.20 Win32.TrojanHorse
eTrust-Vet 36.1.8282 2011.04.20 -
F-Prot 4.6.2.117 2011.04.21 -
F-Secure 9.0.16440.0 2011.04.21 -
Fortinet 4.2.257.0 2011.04.21 -
GData 22 2011.04.21 -
Ikarus T3.1.1.103.0 2011.04.21 -
Jiangmin 13.0.900 2011.04.21 -
K7AntiVirus 9.97.4439 2011.04.20 -
Kaspersky 7.0.0.125 2011.04.21 -
McAfee 5.400.0.1158 2011.04.21 -
McAfee-GW-Edition 2010.1D 2011.04.20 -
Microsoft 1.6802 2011.04.20 -
NOD32 6059 2011.04.21 -
Norman 6.07.07 2011.04.20 -
Panda 10.0.3.5 2011.04.20 -
PCTools 7.0.3.5 2011.04.20 -
Prevx 3.0 2011.04.21 -
Rising 23.54.02.06 2011.04.20 -
Sophos 4.64.0 2011.04.21 -
SUPERAntiSpyware 4.40.0.1006 2011.04.21 -
Symantec 20101.3.2.89 2011.04.21 -
TheHacker 6.7.0.1.179 2011.04.21 -
TrendMicro 9.200.0.1012 2011.04.20 -
TrendMicro-HouseCall 9.200.0.1012 2011.04.21 -
VBA32 3.12.16.0 2011.04.20 -
VIPRE 9074 2011.04.21 -
ViRobot 2011.4.20.4420 2011.04.20 -
VirusBuster 13.6.313.2 2011.04.20 -
Additional informationShow all
MD5 : e6d35f3aa51a65eb35c1f2340154a25e
SHA1 : aabbd57e20d2e7041f9e7abce6cfd8a53c366537
SHA256: 3da4f51682e7d42c5569f1fb1adc6295182962e36f748219e1d0c8f2389ba516
ssdeep: 768:Bosx0q2ph6P2Jpz8ftoSUiJP7hYTCMrhwYKUzY4q:j076P2Jpz8ftBUMPaCMrhwY
File size : 54016 bytes
First seen: 2009-09-18 00:44:25
Last seen : 2011-04-21 02:10:33
TrID:
Clipper DOS Executable (33.3%)
Generic Win/DOS Executable (33.0%)
DOS Executable Generic (33.0%)
VXD Driver (0.5%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned

PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0xC505
timedatestamp….: 0x4A9EE5B5 (Wed Sep 02 21:37:57 2009)
machinetype……: 0x14c (I386)

[[ 5 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x480, 0xBD9F, 0xBE00, 5.83, 9474f39576a0e15bdbaa2ea3355f0a4a
.rdata, 0xC280, 0x126, 0x180, 3.78, 375b710d9f213cfced30e9fdb29567e1
.data, 0xC400, 0xC0, 0x100, 0.33, 786971ca2b109729eda604b44d6c72ad
INIT, 0xC500, 0x3C8, 0x400, 5.20, eea49a93a73afb6afc178455582133c6
.reloc, 0xC900, 0x9EC, 0xA00, 6.62, bddd5a40c508bfc84ec87de5f8e6a5d3

[[ 1 import(s) ]]
ntoskrnl.exe: ZwWriteFile, RtlUpcaseUnicodeChar, ZwClose, ZwCreateFile, RtlInitUnicodeString, _wcsicmp, ZwQueryValueKey, ZwOpenKey, ZwDeleteKey, swprintf, ZwEnumerateKey, ExFreePoolWithTag, DbgPrint, ExAllocatePool, RtlPrefixUnicodeString, memcpy, RtlDeleteRegistryValue, ZwSetValueKey, RtlWriteRegistryValue, ZwEnumerateValueKey, ZwSetInformationFile, ZwQueryInformationFile, ZwQueryDirectoryFile, ZwOpenFile, KeTickCount, KeBugCheck, MmGetSystemRoutineAddress, ZwFlushKey, PsTerminateSystemThread, KeSetPriorityThread, KeGetCurrentThread, RtlCheckRegistryKey, KeDelayExecutionThread, ZwReadFile, PsCreateSystemThread, PsGetVersion, KeBugCheckEx



VT Community

13
User:LT1
Reputation:2639 credits
Comment date:2010-09-29 17:53:30 (UTC)
Tags: Malware,
Was this comment helpful? Yes (1) | No (6) | Report abuse Reported as abuseful
User:siri
Reputation:1593 credits
Comment date:2010-10-01 13:42:47 (UTC)
Legit tool: Avenger
Tags: Goodware, avenger, rootkit
Was this comment helpful? Yes (8) | No (2) | Report abuse Reported as abuseful
User:Anonymous
Reputation:1 credits
Comment date:2010-10-04 15:58:28 (UTC)
SIRI IS CORRECT

This is part of Avenger, a low level driver to remove other malware. Delete it if you wish, Avenger always creates a new random driver when it needs to.
Tags: Goodware,
Was this comment helpful? Yes (6) | No (0) | Report abuse Reported as abuseful
User:dr_Bora
Reputation:419 credits
Comment date:2010-10-08 21:30:18 (UTC)
Legit file.
Tags: Goodware, rootkit, avenger
Was this comment helpful? Yes (8) | No (0) | Report abuse Reported as abuseful
User:Anonymous
Reputation:1 credits
Comment date:2010-10-17 08:01:11 (UTC)
Tags: Malware, rootkit, avenger
Was this comment helpful? Yes (1) | No (7) | Report abuse Reported as abuseful
User:LT1
Reputation:2639 credits
Comment date:2010-09-29 17:53:30 (UTC)
Tags: Malware,
Was this comment helpful? Yes (1) | No (6) | Report abuse Reported as abuseful
User:siri
Reputation:1593 credits
Comment date:2010-10-01 13:42:47 (UTC)
Legit tool: Avenger
Tags: Goodware, avenger, rootkit
Was this comment helpful? Yes (8) | No (2) | Report abuse Reported as abuseful
User:Anonymous
Reputation:1 credits
Comment date:2010-10-04 15:58:28 (UTC)
SIRI IS CORRECT

This is part of Avenger, a low level driver to remove other malware. Delete it if you wish, Avenger always creates a new random driver when it needs to.
Tags: Goodware,
Was this comment helpful? Yes (6) | No (0) | Report abuse Reported as abuseful
User:dr_Bora
Reputation:419 credits
Comment date:2010-10-08 21:30:18 (UTC)
Legit file.
Tags: Goodware, rootkit, avenger
Was this comment helpful? Yes (8) | No (0) | Report abuse Reported as abuseful
User:Anonymous
Reputation:1 credits
Comment date:2010-10-17 08:01:11 (UTC)
Tags: Malware, rootkit, avenger
Was this comment helpful? Yes (1) | No (7) | Report abuse Reported as abuseful
Loading…


Prev123Next



Add your comment… Remember that when you write comments as an anonymous user they receive the lowest possible reputation. So if you have not signed in yet don't forget to do so. How to markup your comments?
You can add basic styles to your comments using the following accepted bbcode tags:

text – bold
text – italics
text – underline
text – strikethrough
text
– preformatted text

You can also address comments to particular users using the "@" twitter-like mode. By prepending a "#" symbol to a word you can add custom tags to your comment, tags that can then be searched for.

Goodware Malware Spam attachment/link
P2P download Propagating via IM Network worm
Drive-by-download



Anonymous limit exceeded: anonymous users can only make one comment per file or URL, either sign in or register in order to continue making reviews on this item. Note that anonymous user discrimination is based on IP addresses, hence, it may be possible that another user behind your same proxy or NAT connection already made a review.

Preview commentEdit comment Post comment Posting comment…
Comment successfully posted







ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.
VirusTotal © Hispasec Sistemas - Blog - Twitter - Contact: [removed]- TOS & Privacy Policy



OTL Extras logfile created on: 4/20/2011 6:53:10 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 636.00 Mb Available Physical Memory | 62.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 73.27 Gb Free Space | 65.55% Space Free | Partition Type: NTFS
Drive E: | 3.77 Gb Total Space | 1.60 Gb Free Space | 42.38% Space Free | Partition Type: FAT32

Computer Name: OWNER-752E2D2FE | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_USERS\S-1-5-21-861567501-1682526488-1417001333-1003\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{171E6C1E-B5FC-11DF-B115-005056C00008}" = Google Earth Plug-in
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FD0C5C1-B01B-4B4C-9607-E5D3B3D1318F}" = Microsoft IntelliPoint 4.1
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2A697B53-0DE3-42DA-B41D-C3F804B1C538}" = iTunes
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{369B36BE-3D64-4641-9AEA-808D436FE132}" = Microsoft Picture It! Photo 7.0
"{56F3E1FF-54FE-4384-A153-6CCABA097814}" = Creative MediaSource
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{6ECB39BD-73C2-44DD-B1A0-898207C58D8B}" = HP Photo and Imaging 2.0 - All-in-One Drivers
"{75DE35AB-DA0F-42C3-8EA1-BE0E0902D196}" = Nitro PDF Professional
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7CCEBC24-62DB-4280-A8EC-BFA49F167920}" = Software Update for Web Folders
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{868291A4-229E-4795-B0B0-E60E87AF53CD}" = Sibelius Scorch (ActiveX Only)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{93FB47FB-4FDF-4131-B5FD-7A37883868E7}" = hp psc 2170 series
"{9867A917-5D17-40DE-83BA-BEA5293194B1}" = HP Photo and Imaging 2.0 - All-in-One
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9DE006A5-B384-4EDE-A760-0F217136B9EA}" = Microsoft IntelliType Pro 2.2
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.3
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C138D676-4F0F-4FDE-8BE5-26CFD3566DCD}" = SmartDeviceMonitor for Client
"{C23B8C30-E05E-4CB5-8188-F27CC3B2DD3E}" = Sibelius 5
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D64DCF1C-7A95-49A4-BAFA-C42B5CF6B8B6}" = Works Suite OS Pack
"{DC4C464D-416A-4F42-B212-8B744C1BB4AE}" = FileMaker Pro 8.5
"{E3D4F451-5F04-4082-BE21-1C0C1ADF5014}" = Vz In Home Agent
"{F44DA61E-720D-4E79-871F-F6E628B33242}" = OpenOffice.org 3.0
"{F4B15A3A-E863-4768-8868-472BF3B1392B}" = MLS Property Messenger
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"A-PDF Image to PDF_is1" = A-PDF Image to PDF 3.7
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"DoulosSIL" = DoulosSIL 4.106
"DX-Ball 1.09" = DX-Ball 1.09
"HP PSC 2170 Series" = HP Photo and Imaging 2.0 - hp psc 2170 series
"IPA/SAM Phonetic Fonts_is1" = IPA/SAM Phonetics Fonts
"Jigsaw Puzzles: Fabulous Foods!" = Jigsaw Puzzles: Fabulous Foods!
"Mahjong Escape - Ancient Japan" = Mahjong Escape - Ancient Japan
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.15)" = Mozilla Firefox (3.6.15)
"Pattern Maker for cross stitch" = Pattern Maker for cross stitch
"PrimoPDF4.1.0.9" = PrimoPDF
"Sibelius Sounds Essentials" = Sibelius Sounds Essentials
"Smithsonian's American Art Jigsaws" = Smithsonian's American Art Jigsaws
"Verizon Help and Support" = Verizon Help and Support Tool
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"WinRAR archiver" = WinRAR archiver
"Works2003Setup" = Microsoft Works 2003 Setup Launcher

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-861567501-1682526488-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GoToMeeting" = GoToMeeting 4.1.0.366

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/19/2011 5:11:05 PM | Computer Name = OWNER-752E2D2FE | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041F from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 4/19/2011 6:13:55 PM | Computer Name = OWNER-752E2D2FE | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041F from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 4/19/2011 11:26:15 PM | Computer Name = OWNER-752E2D2FE | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041F from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 4/19/2011 11:35:19 PM | Computer Name = OWNER-752E2D2FE | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041F from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 4/20/2011 12:10:54 AM | Computer Name = OWNER-752E2D2FE | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041F from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 4/20/2011 7:55:14 AM | Computer Name = OWNER-752E2D2FE | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041F from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 4/20/2011 8:25:40 AM | Computer Name = OWNER-752E2D2FE | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041F from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 4/20/2011 12:28:32 PM | Computer Name = OWNER-752E2D2FE | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041F from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 4/20/2011 12:34:59 PM | Computer Name = OWNER-752E2D2FE | Source = Microsoft Office 10 | ID = 2000
Description = Accepted Safe Mode action : Microsoft Word.

Error - 4/20/2011 6:00:34 PM | Computer Name = OWNER-752E2D2FE | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041F from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

[ System Events ]
Error - 4/20/2011 8:25:40 AM | Computer Name = OWNER-752E2D2FE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 4/20/2011 8:25:40 AM | Computer Name = OWNER-752E2D2FE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service iPod Service
with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}

Error - 4/20/2011 12:28:32 PM | Computer Name = OWNER-752E2D2FE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 4/20/2011 12:28:32 PM | Computer Name = OWNER-752E2D2FE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 4/20/2011 12:28:32 PM | Computer Name = OWNER-752E2D2FE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 4/20/2011 12:28:32 PM | Computer Name = OWNER-752E2D2FE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service iPod Service
with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}

Error - 4/20/2011 6:00:34 PM | Computer Name = OWNER-752E2D2FE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 4/20/2011 6:00:34 PM | Computer Name = OWNER-752E2D2FE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 4/20/2011 6:00:34 PM | Computer Name = OWNER-752E2D2FE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 4/20/2011 6:00:34 PM | Computer Name = OWNER-752E2D2FE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service iPod Service
with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}


< End of report >
Sorry to keep you waiting, I had to run out to a rehearsal.

I'm posting the VT logfile first, followed by the OLT extra.txt file that I found.

Thanks for your patience.

Dan

VT Community Sign in ▼ My account ▼ Sign out Signing out… Languages ▼
VirusTotal's website has changed, we need new translations, do you feel like helping the community?
[removed] in to VT Community
Safety ratings and user comments (disinfection, in-the-wild locations, reverse engineering reports, etc.) on malware and URLs, free and easy.

email
password
Keep me logged in
Sign in
Signing in, please wait…
Login failed, please try again
Forgot your password? Create an account
Edit my profile
View my profile
Inbox

Virustotal is a service that analyzes suspicious files and URLs and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information…

9 VT Community user(s) with a total of 8196 reputation credit(s) say(s) this sample is goodware. 4 VT Community user(s) with a total of 2642 reputation credit(s) say(s) this sample is malware.
File name: xcldybhk.sys
Submission date: 2011-04-21 02:10:33 (UTC)
Current status: queued queued analysing finished


Result: 2/ 41 (4.9%)
VT Community

goodware
Safety score: 75.6%

Compact Print results
Antivirus Version Last Update Result
AhnLab-V3 2011.04.21.00 2011.04.21 -
AntiVir 7.11.6.215 2011.04.20 -
Antiy-AVL 2.0.3.7 2011.04.21 -
Avast 4.8.1351.0 2011.04.20 -
Avast5 5.0.677.0 2011.04.20 -
AVG 10.0.0.1190 2011.04.20 -
BitDefender 7.2 2011.04.21 -
CAT-QuickHeal 11.00 2011.04.20 -
ClamAV 0.97.0.0 2011.04.20 BC.Heuristics.Rootkit.B-11.MV
Commtouch 5.3.2.6 2011.04.21 -
Comodo 8417 2011.04.21 -
DrWeb 5.0.2.03300 2011.04.21 -
eSafe 7.0.17.0 2011.04.20 Win32.TrojanHorse
eTrust-Vet 36.1.8282 2011.04.20 -
F-Prot 4.6.2.117 2011.04.21 -
F-Secure 9.0.16440.0 2011.04.21 -
Fortinet 4.2.257.0 2011.04.21 -
GData 22 2011.04.21 -
Ikarus T3.1.1.103.0 2011.04.21 -
Jiangmin 13.0.900 2011.04.21 -
K7AntiVirus 9.97.4439 2011.04.20 -
Kaspersky 7.0.0.125 2011.04.21 -
McAfee 5.400.0.1158 2011.04.21 -
McAfee-GW-Edition 2010.1D 2011.04.20 -
Microsoft 1.6802 2011.04.20 -
NOD32 6059 2011.04.21 -
Norman 6.07.07 2011.04.20 -
Panda 10.0.3.5 2011.04.20 -
PCTools 7.0.3.5 2011.04.20 -
Prevx 3.0 2011.04.21 -
Rising 23.54.02.06 2011.04.20 -
Sophos 4.64.0 2011.04.21 -
SUPERAntiSpyware 4.40.0.1006 2011.04.21 -
Symantec 20101.3.2.89 2011.04.21 -
TheHacker 6.7.0.1.179 2011.04.21 -
TrendMicro 9.200.0.1012 2011.04.20 -
TrendMicro-HouseCall 9.200.0.1012 2011.04.21 -
VBA32 3.12.16.0 2011.04.20 -
VIPRE 9074 2011.04.21 -
ViRobot 2011.4.20.4420 2011.04.20 -
VirusBuster 13.6.313.2 2011.04.20 -
Additional informationShow all
MD5 : e6d35f3aa51a65eb35c1f2340154a25e
SHA1 : aabbd57e20d2e7041f9e7abce6cfd8a53c366537
SHA256: 3da4f51682e7d42c5569f1fb1adc6295182962e36f748219e1d0c8f2389ba516
ssdeep: 768:Bosx0q2ph6P2Jpz8ftoSUiJP7hYTCMrhwYKUzY4q:j076P2Jpz8ftBUMPaCMrhwY
File size : 54016 bytes
First seen: 2009-09-18 00:44:25
Last seen : 2011-04-21 02:10:33
TrID:
Clipper DOS Executable (33.3%)
Generic Win/DOS Executable (33.0%)
DOS Executable Generic (33.0%)
VXD Driver (0.5%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned

PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0xC505
timedatestamp….: 0x4A9EE5B5 (Wed Sep 02 21:37:57 2009)
machinetype……: 0x14c (I386)

[[ 5 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x480, 0xBD9F, 0xBE00, 5.83, 9474f39576a0e15bdbaa2ea3355f0a4a
.rdata, 0xC280, 0x126, 0x180, 3.78, 375b710d9f213cfced30e9fdb29567e1
.data, 0xC400, 0xC0, 0x100, 0.33, 786971ca2b109729eda604b44d6c72ad
INIT, 0xC500, 0x3C8, 0x400, 5.20, eea49a93a73afb6afc178455582133c6
.reloc, 0xC900, 0x9EC, 0xA00, 6.62, bddd5a40c508bfc84ec87de5f8e6a5d3

[[ 1 import(s) ]]
ntoskrnl.exe: ZwWriteFile, RtlUpcaseUnicodeChar, ZwClose, ZwCreateFile, RtlInitUnicodeString, _wcsicmp, ZwQueryValueKey, ZwOpenKey, ZwDeleteKey, swprintf, ZwEnumerateKey, ExFreePoolWithTag, DbgPrint, ExAllocatePool, RtlPrefixUnicodeString, memcpy, RtlDeleteRegistryValue, ZwSetValueKey, RtlWriteRegistryValue, ZwEnumerateValueKey, ZwSetInformationFile, ZwQueryInformationFile, ZwQueryDirectoryFile, ZwOpenFile, KeTickCount, KeBugCheck, MmGetSystemRoutineAddress, ZwFlushKey, PsTerminateSystemThread, KeSetPriorityThread, KeGetCurrentThread, RtlCheckRegistryKey, KeDelayExecutionThread, ZwReadFile, PsCreateSystemThread, PsGetVersion, KeBugCheckEx



VT Community

13
User:LT1
Reputation:2639 credits
Comment date:2010-09-29 17:53:30 (UTC)
Tags: Malware,
Was this comment helpful? Yes (1) | No (6) | Report abuse Reported as abuseful
User:siri
Reputation:1593 credits
Comment date:2010-10-01 13:42:47 (UTC)
Legit tool: Avenger
Tags: Goodware, avenger, rootkit
Was this comment helpful? Yes (8) | No (2) | Report abuse Reported as abuseful
User:Anonymous
Reputation:1 credits
Comment date:2010-10-04 15:58:28 (UTC)
SIRI IS CORRECT

This is part of Avenger, a low level driver to remove other malware. Delete it if you wish, Avenger always creates a new random driver when it needs to.
Tags: Goodware,
Was this comment helpful? Yes (6) | No (0) | Report abuse Reported as abuseful
User:dr_Bora
Reputation:419 credits
Comment date:2010-10-08 21:30:18 (UTC)
Legit file.
Tags: Goodware, rootkit, avenger
Was this comment helpful? Yes (8) | No (0) | Report abuse Reported as abuseful
User:Anonymous
Reputation:1 credits
Comment date:2010-10-17 08:01:11 (UTC)
Tags: Malware, rootkit, avenger
Was this comment helpful? Yes (1) | No (7) | Report abuse Reported as abuseful
User:LT1
Reputation:2639 credits
Comment date:2010-09-29 17:53:30 (UTC)
Tags: Malware,
Was this comment helpful? Yes (1) | No (6) | Report abuse Reported as abuseful
User:siri
Reputation:1593 credits
Comment date:2010-10-01 13:42:47 (UTC)
Legit tool: Avenger
Tags: Goodware, avenger, rootkit
Was this comment helpful? Yes (8) | No (2) | Report abuse Reported as abuseful
User:Anonymous
Reputation:1 credits
Comment date:2010-10-04 15:58:28 (UTC)
SIRI IS CORRECT

This is part of Avenger, a low level driver to remove other malware. Delete it if you wish, Avenger always creates a new random driver when it needs to.
Tags: Goodware,
Was this comment helpful? Yes (6) | No (0) | Report abuse Reported as abuseful
User:dr_Bora
Reputation:419 credits
Comment date:2010-10-08 21:30:18 (UTC)
Legit file.
Tags: Goodware, rootkit, avenger
Was this comment helpful? Yes (8) | No (0) | Report abuse Reported as abuseful
User:Anonymous
Reputation:1 credits
Comment date:2010-10-17 08:01:11 (UTC)
Tags: Malware, rootkit, avenger
Was this comment helpful? Yes (1) | No (7) | Report abuse Reported as abuseful
Loading…


Prev123Next



Add your comment… Remember that when you write comments as an anonymous user they receive the lowest possible reputation. So if you have not signed in yet don't forget to do so. How to markup your comments?
You can add basic styles to your comments using the following accepted bbcode tags:

text – bold
text – italics
text – underline
text – strikethrough
text
– preformatted text

You can also address comments to particular users using the "@" twitter-like mode. By prepending a "#" symbol to a word you can add custom tags to your comment, tags that can then be searched for.

Goodware Malware Spam attachment/link
P2P download Propagating via IM Network worm
Drive-by-download



Anonymous limit exceeded: anonymous users can only make one comment per file or URL, either sign in or register in order to continue making reviews on this item. Note that anonymous user discrimination is based on IP addresses, hence, it may be possible that another user behind your same proxy or NAT connection already made a review.

Preview commentEdit comment Post comment Posting comment…
Comment successfully posted







ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.
VirusTotal © Hispasec Sistemas - Blog - Twitter - Contact: [removed]- TOS & Privacy Policy



OTL Extras logfile created on: 4/20/2011 6:53:10 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 636.00 Mb Available Physical Memory | 62.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 73.27 Gb Free Space | 65.55% Space Free | Partition Type: NTFS
Drive E: | 3.77 Gb Total Space | 1.60 Gb Free Space | 42.38% Space Free | Partition Type: FAT32

Computer Name: OWNER-752E2D2FE | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_USERS\S-1-5-21-861567501-1682526488-1417001333-1003\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{171E6C1E-B5FC-11DF-B115-005056C00008}" = Google Earth Plug-in
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FD0C5C1-B01B-4B4C-9607-E5D3B3D1318F}" = Microsoft IntelliPoint 4.1
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2A697B53-0DE3-42DA-B41D-C3F804B1C538}" = iTunes
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{369B36BE-3D64-4641-9AEA-808D436FE132}" = Microsoft Picture It! Photo 7.0
"{56F3E1FF-54FE-4384-A153-6CCABA097814}" = Creative MediaSource
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D8D64BE-F500-55B6-705D-DFD08AFE0624}" = Acrobat.com
"{6ECB39BD-73C2-44DD-B1A0-898207C58D8B}" = HP Photo and Imaging 2.0 - All-in-One Drivers
"{75DE35AB-DA0F-42C3-8EA1-BE0E0902D196}" = Nitro PDF Professional
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7CCEBC24-62DB-4280-A8EC-BFA49F167920}" = Software Update for Web Folders
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{868291A4-229E-4795-B0B0-E60E87AF53CD}" = Sibelius Scorch (ActiveX Only)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{93FB47FB-4FDF-4131-B5FD-7A37883868E7}" = hp psc 2170 series
"{9867A917-5D17-40DE-83BA-BEA5293194B1}" = HP Photo and Imaging 2.0 - All-in-One
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9DE006A5-B384-4EDE-A760-0F217136B9EA}" = Microsoft IntelliType Pro 2.2
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.3
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C138D676-4F0F-4FDE-8BE5-26CFD3566DCD}" = SmartDeviceMonitor for Client
"{C23B8C30-E05E-4CB5-8188-F27CC3B2DD3E}" = Sibelius 5
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D64DCF1C-7A95-49A4-BAFA-C42B5CF6B8B6}" = Works Suite OS Pack
"{DC4C464D-416A-4F42-B212-8B744C1BB4AE}" = FileMaker Pro 8.5
"{E3D4F451-5F04-4082-BE21-1C0C1ADF5014}" = Vz In Home Agent
"{F44DA61E-720D-4E79-871F-F6E628B33242}" = OpenOffice.org 3.0
"{F4B15A3A-E863-4768-8868-472BF3B1392B}" = MLS Property Messenger
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"A-PDF Image to PDF_is1" = A-PDF Image to PDF 3.7
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"DoulosSIL" = DoulosSIL 4.106
"DX-Ball 1.09" = DX-Ball 1.09
"HP PSC 2170 Series" = HP Photo and Imaging 2.0 - hp psc 2170 series
"IPA/SAM Phonetic Fonts_is1" = IPA/SAM Phonetics Fonts
"Jigsaw Puzzles: Fabulous Foods!" = Jigsaw Puzzles: Fabulous Foods!
"Mahjong Escape - Ancient Japan" = Mahjong Escape - Ancient Japan
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.15)" = Mozilla Firefox (3.6.15)
"Pattern Maker for cross stitch" = Pattern Maker for cross stitch
"PrimoPDF4.1.0.9" = PrimoPDF
"Sibelius Sounds Essentials" = Sibelius Sounds Essentials
"Smithsonian's American Art Jigsaws" = Smithsonian's American Art Jigsaws
"Verizon Help and Support" = Verizon Help and Support Tool
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"WinRAR archiver" = WinRAR archiver
"Works2003Setup" = Microsoft Works 2003 Setup Launcher

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-861567501-1682526488-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GoToMeeting" = GoToMeeting 4.1.0.366

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/19/2011 5:11:05 PM | Computer Name = OWNER-752E2D2FE | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041F from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 4/19/2011 6:13:55 PM | Computer Name = OWNER-752E2D2FE | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041F from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 4/19/2011 11:26:15 PM | Computer Name = OWNER-752E2D2FE | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041F from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 4/19/2011 11:35:19 PM | Computer Name = OWNER-752E2D2FE | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041F from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 4/20/2011 12:10:54 AM | Computer Name = OWNER-752E2D2FE | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041F from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 4/20/2011 7:55:14 AM | Computer Name = OWNER-752E2D2FE | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041F from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 4/20/2011 8:25:40 AM | Computer Name = OWNER-752E2D2FE | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041F from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 4/20/2011 12:28:32 PM | Computer Name = OWNER-752E2D2FE | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041F from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 4/20/2011 12:34:59 PM | Computer Name = OWNER-752E2D2FE | Source = Microsoft Office 10 | ID = 2000
Description = Accepted Safe Mode action : Microsoft Word.

Error - 4/20/2011 6:00:34 PM | Computer Name = OWNER-752E2D2FE | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 8007041F from line 44 of d:\comxp_sp2\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

[ System Events ]
Error - 4/20/2011 8:25:40 AM | Computer Name = OWNER-752E2D2FE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 4/20/2011 8:25:40 AM | Computer Name = OWNER-752E2D2FE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service iPod Service
with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}

Error - 4/20/2011 12:28:32 PM | Computer Name = OWNER-752E2D2FE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 4/20/2011 12:28:32 PM | Computer Name = OWNER-752E2D2FE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 4/20/2011 12:28:32 PM | Computer Name = OWNER-752E2D2FE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 4/20/2011 12:28:32 PM | Computer Name = OWNER-752E2D2FE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service iPod Service
with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}

Error - 4/20/2011 6:00:34 PM | Computer Name = OWNER-752E2D2FE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 4/20/2011 6:00:34 PM | Computer Name = OWNER-752E2D2FE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 4/20/2011 6:00:34 PM | Computer Name = OWNER-752E2D2FE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 4/20/2011 6:00:34 PM | Computer Name = OWNER-752E2D2FE | Source = DCOM | ID = 10005
Description = DCOM got error "%1055" attempting to start the service iPod Service
with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}


< End of report >
Have you tried to remove Ask Toolbar ? We can remove it with OTL if you wish.

With the amount of garbage that Malwarebytes found, lets run this program, it may find more

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
The Ask toolbar was part of Firefox, which we (meaning my wife - it's her machine) don't use. It was installed by the daughter. I uninstalled Firefox. Will there still be traces of the ask toolbar lurking?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI