This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

google/bing redirect

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

About 50% of the time when doing a google or bing search the links are redirected to random sites. Ive run spybot, malaware, stopzilla and a few other virus removal tools to no avail. I found a suspicious entry in my system 32 host file but am unable to delete it. I was also given the following alert when running hijack this.

" For some reason your system denied write access to the Hosts file. If any hijacked domains are in this file, Hijackthis may NOT be able to fix this. If that happens you need to edit the file yourself"

It then gives directions on how to do that, I followed them and was given an "access denied" alert and was unsuccessful.

Here is a copy of my Host file


# Copyright © 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost
::1 localhost




Here is my hijackthis log

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:59:28 PM, on 6/30/2011
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.17037)
Boot mode: Normal

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\WerCon.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\PdaNet for Android\PdaNetPC.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\owner\Program Files\DNA\btdna.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
C:\Users\owner\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…o&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…o&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…o&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O2 - BHO: HP Print Clips - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [Monitor] "C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: PdaNet Desktop.lnk = C:\Program Files\PdaNet for Android\PdaNetPC.exe
O4 - Startup: setup_9.0.0.722_29.06.2011_17-10.lnk = C:\Users\owner\Desktop\Virus Removal Tool\setup_9.0.0.722_29.06.2011_17-10\startup.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: WebEx Service Host for Support Center (atashost) - WebEx Communications, Inc. - C:\Windows\system32\atashost.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: FlipShare Service - Unknown owner - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
O23 - Service: FlipShare Server (FlipShareServer) - Unknown owner - C:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate1ca194523ff6b60) (gupdate1ca194523ff6b60) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LeapFrog Connect Device Service - LeapFrog Enterprises, Inc. - C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 10341 bytes


Any help would be greatly appreciated, what a frustrating virus :angry:
Hello and Welcome to WhatTheTech Forums

My name is BlackPegasus.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for
    further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to
    get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out
    the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 3 days your thread will be closed.
  • Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to
    ensure that I am giving you the best possible advice.
  • This may cause a delay in response time, but I will do my best to keep it as short as possible.
  • I will reply back shortly with instructions.
Hello wsuozzie,

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")
========================
I noticed that you don't have an Antivirus program installed on your system. As a rule of thumb one should run one firewall, one antivirus program in memory, and one antispyware utility in memory. It's fine to have other security tools available on an as-needed or on-demand basis, but when multiple tools simultaneously perform the same function, you're asking for trouble.
We will Install a Anti-virus program after the computer is clean. Please do not surf the Internet without a Anti-virus program, use the computer for download the tools we will use to clean the computer only .
=======================

Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -


Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.

Reboot Your System
=======================
NEXT

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
=======================
NEXT
Please download aswMBR ( 511KB ) to your desktop.
  • Double click the aswMBR.exe icon to run it
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
=======================
Please include in your next reply:
1. Any problem executing the instructions?
2. OTL log and Extras.Txt
3. aswMBR log
Here is my OTL report

OTL logfile created on: 7/1/2011 8:24:33 AM - Run 1
OTL by OldTimer - Version 3.2.25.0 Folder = C:\Users\owner\Desktop
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.17037)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.94 Gb Total Physical Memory | 1.27 Gb Available Physical Memory | 65.49% Memory free
4.08 Gb Paging File | 3.13 Gb Available in Paging File | 76.69% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 137.36 Gb Total Space | 52.91 Gb Free Space | 38.52% Space Free | Partition Type: NTFS
Drive D: | 11.69 Gb Total Space | 1.86 Gb Free Space | 15.87% Space Free | Partition Type: NTFS

Computer Name: OWNER-PC | User Name: owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
PRC - C:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe ()
PRC - C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe (LeapFrog Enterprises, Inc.)
PRC - C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe (LeapFrog Enterprises, Inc.)
PRC - C:\Program Files\PdaNet for Android\PdaNetPC.exe ()
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Users\owner\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
PRC - C:\Windows\System32\atashost.exe (WebEx Communications, Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
PRC - C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
PRC - C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
PRC - C:\Windows\System32\wercon.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\owner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (RoxLiveShare9) – File not found
SRV - (FlipShare Service) – C:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
SRV - (FlipShareServer) – C:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe ()
SRV - (LeapFrog Connect Device Service) – C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe (LeapFrog Enterprises, Inc.)
SRV - (IntuitUpdateService) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (atashost) – C:\Windows\System32\atashost.exe (WebEx Communications, Inc.)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (aawservice) – C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (Com4Qlb) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)
SRV - (CCALib8) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)


========== Driver Services (SafeList) ==========

DRV - (hitmanpro35) – C:\Windows\System32\drivers\hitmanpro35.sys ()
DRV - (pneteth) – C:\Windows\System32\drivers\pneteth.sys (June Fabrics Technology Inc.)
DRV - (47794382) – C:\Windows\system32\DRIVERS\47794382.sys (Kaspersky Lab)
DRV - (setup_9.0.0.722_29.06.2011_17-10drv) – C:\Windows\System32\drivers\4779438.sys (Kaspersky Lab)
DRV - (47794381) – C:\Windows\System32\drivers\47794381.sys (Kaspersky Lab)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (HdAudAddService) – C:\Windows\System32\drivers\CHDART.sys (Conexant Systems Inc.)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (nvsmu) – C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (WinUSB) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (HBtnKey) – C:\Windows\System32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…o&pf;=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…o&pf;=laptop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…o&pf;=laptop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = F6 1F BD 01 CC 32 9D 44 96 35 78 D0 C5 D1 67 81 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.bing.com"
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.8
FF - prefs.js..extensions.enabledItems: {b7964d47-b174-4a94-ac5a-3ce2e8b53d18}:1.0
FF - prefs.js..keyword.URL: "http://www.google.co.in/search?btnI=I%27m+Feeling+Lucky&q;="

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/22 10:49:00 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/22 10:49:00 | 000,000,000 | —D | M]

[2008/08/27 19:29:49 | 000,000,000 | —D | M] (No name found) – C:\Users\owner\AppData\Roaming\Mozilla\Extensions
[2011/06/30 17:51:15 | 000,000,000 | —D | M] (No name found) – C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\ryo8kylj.default\extensions
[2010/12/10 22:29:28 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\ryo8kylj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/06/26 20:42:36 | 000,000,000 | —D | M] (XUL Cache) – C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\ryo8kylj.default\extensions\{b7964d47-b174-4a94-ac5a-3ce2e8b53d18}
[2011/06/23 13:23:07 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\ryo8kylj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/03/04 21:57:00 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2008/08/27 19:29:46 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2009/11/08 20:06:28 | 000,000,000 | —D | M] (Move Media Player) – C:\USERS\OWNER\APPDATA\ROAMING\MOVE NETWORKS
[2008/09/03 17:11:24 | 000,054,600 | —- | M] (BitTorrent, Inc.) – C:\Program Files\mozilla firefox\plugins\npbittorrent.dll

O1 HOSTS File: ([2006/09/18 14:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (HP Print Clips) - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
O4 - HKLM..\Run: [Monitor] C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe (LeapFrog Enterprises, Inc.)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKCU..\Run: [BitTorrent DNA] C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PdaNet Desktop.lnk = C:\Program Files\PdaNet for Android\PdaNetPC.exe ()
O4 - Startup: C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\setup_9.0.0.722_29.06.2011_17-10.lnk = C:\Users\owner\Desktop\Virus Removal Tool\setup_9.0.0.722_29.06.2011_17-10\startup.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O9 - Extra Button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\owner\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\owner\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/10/25 01:41:43 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2005/09/11 08:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE – [ NTFS ]
O33 - MountPoints2\{0d319f19-df7d-11df-86db-001b24e94d57}\Shell\AutoRun\command - "" = F:\Setup_FlipShare.exe
O33 - MountPoints2\{0d319f19-df7d-11df-86db-001b24e94d57}\Shell\Setup FlipShare\command - "" = F:\Setup_FlipShare.exe
O33 - MountPoints2\{10f4bca0-cccf-11dc-94ba-001b24e94d57}\Shell - "" = AutoRun
O33 - MountPoints2\{10f4bca0-cccf-11dc-94ba-001b24e94d57}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2011/07/01 08:22:43 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Users\owner\Desktop\OTL.exe
[2011/07/01 08:07:09 | 000,000,000 | —D | C] – C:\Users\owner\Desktop\backups
[2011/06/30 15:58:43 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\owner\Desktop\HiJackThis.exe
[2011/06/30 15:38:40 | 000,000,000 | —D | C] – C:\ComboFix
[2011/06/30 12:27:15 | 016,409,960 | —- | C] (Safer Networking Limited ) – C:\Users\owner\Desktop\setup-spybotsd162.exe
[2011/06/30 12:10:37 | 000,000,000 | –SD | C] – C:\32788R22FWJFW
[2011/06/30 08:50:07 | 000,000,000 | —D | C] – C:\ProgramData\Hitman Pro
[2011/06/30 08:40:08 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Roaming\Flip Video
[2011/06/30 08:37:59 | 000,000,000 | —D | C] – C:\Program Files\Flip Video
[2011/06/29 08:46:15 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2011/06/29 08:42:32 | 000,128,016 | —- | C] (Kaspersky Lab) – C:\Windows\System32\drivers\47794381.sys
[2011/06/29 08:42:32 | 000,037,392 | —- | C] (Kaspersky Lab) – C:\Windows\System32\drivers\47794382.sys
[2011/06/29 08:42:31 | 000,311,312 | —- | C] (Kaspersky Lab) – C:\Windows\System32\drivers\4779438.sys
[2011/06/29 08:42:29 | 000,000,000 | —D | C] – C:\Users\owner\Desktop\Virus Removal Tool
[2011/06/27 12:10:50 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/06/27 12:10:33 | 000,000,000 | —D | C] – C:\Qoobox
[2011/06/27 10:57:59 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2011/06/27 08:38:09 | 000,000,000 | —D | C] – C:\ProgramData\STOPzilla!
[2011/06/14 19:24:05 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/06/14 19:22:19 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/06/14 19:22:08 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/06/14 19:14:13 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\owner\Documents\*.tmp files -> C:\Users\owner\Documents\*.tmp -> ]
[1 C:\Users\owner\Desktop\*.tmp files -> C:\Users\owner\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/07/01 08:22:47 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\owner\Desktop\OTL.exe
[2011/07/01 08:18:42 | 000,000,868 | —- | M] () – C:\Windows\tasks\Google Software Updater.job
[2011/07/01 08:16:29 | 000,000,162 | —- | M] () – C:\Users\Public\Documents\hpqp.ini
[2011/07/01 08:16:07 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/07/01 08:15:09 | 000,003,072 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/07/01 08:15:06 | 000,003,072 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/07/01 08:14:39 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/07/01 08:14:34 | 2079,248,384 | -HS- | M] () – C:\hiberfil.sys
[2011/07/01 08:08:20 | 000,002,595 | —- | M] () – C:\Users\owner\Desktop\Microsoft Word.lnk
[2011/06/30 20:41:00 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/30 17:32:30 | 000,007,268 | —- | M] () – C:\Users\owner\AppData\Local\d3d9caps.dat
[2011/06/30 17:00:10 | 000,001,248 | —- | M] () – C:\Windows\System32\drivers\kgpcpy.cfg
[2011/06/30 15:58:51 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\owner\Desktop\HiJackThis.exe
[2011/06/30 15:38:40 | 000,000,338 | —- | M] () – C:\Start_.cmd
[2011/06/30 14:05:20 | 000,074,752 | —- | M] () – C:\Users\owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/30 13:38:14 | 000,000,792 | —- | M] () – C:\Windows\System32\drivers\kgpfr2.cfg
[2011/06/30 12:36:49 | 000,001,095 | —- | M] () – C:\Users\owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/06/30 12:36:49 | 000,001,071 | —- | M] () – C:\Users\owner\Desktop\Spybot - Search & Destroy.lnk
[2011/06/30 12:34:54 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Users\owner\Desktop\setup-spybotsd162.exe
[2011/06/30 09:35:02 | 000,141,239 | —- | M] () – C:\Users\owner\AppData\Roaming\nvModes.001
[2011/06/30 09:30:03 | 000,020,552 | —- | M] () – C:\Windows\System32\drivers\hitmanpro35.sys
[2011/06/30 09:27:07 | 000,000,366 | —- | M] () – C:\Windows\System32\.crusader
[2011/06/30 08:38:45 | 000,000,961 | —- | M] () – C:\Users\Public\Desktop\FlipShare.lnk
[2011/06/30 08:32:12 | 000,618,648 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/06/30 08:32:12 | 000,104,024 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/06/29 08:46:14 | 000,002,650 | —- | M] () – C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\setup_9.0.0.722_29.06.2011_17-10.lnk
[2011/06/27 12:29:49 | 000,326,448 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/06/26 22:49:53 | 000,000,021 | —- | M] () – C:\ProgramData\6650433d
[2011/06/26 20:42:50 | 000,000,097 | —- | M] () – C:\Windows\System32\1283347277
[2011/06/14 19:24:05 | 000,001,664 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/06/13 17:26:03 | 000,000,322 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForowner.job
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\owner\Documents\*.tmp files -> C:\Users\owner\Documents\*.tmp -> ]
[1 C:\Users\owner\Desktop\*.tmp files -> C:\Users\owner\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/06/30 15:38:40 | 000,000,338 | —- | C] () – C:\Start_.cmd
[2011/06/30 12:10:50 | 000,000,792 | —- | C] () – C:\Windows\System32\drivers\kgpfr2.cfg
[2011/06/30 09:32:56 | 000,001,248 | —- | C] () – C:\Windows\System32\drivers\kgpcpy.cfg
[2011/06/30 09:27:07 | 000,000,366 | —- | C] () – C:\Windows\System32\.crusader
[2011/06/30 08:57:43 | 000,020,552 | —- | C] () – C:\Windows\System32\drivers\hitmanpro35.sys
[2011/06/30 08:38:45 | 000,000,973 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FlipShare.lnk
[2011/06/30 08:38:45 | 000,000,961 | —- | C] () – C:\Users\Public\Desktop\FlipShare.lnk
[2011/06/29 08:46:13 | 000,002,650 | —- | C] () – C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\setup_9.0.0.722_29.06.2011_17-10.lnk
[2011/06/27 12:15:27 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/06/27 12:15:27 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/06/27 12:15:27 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/06/26 21:08:49 | 000,000,021 | —- | C] () – C:\ProgramData\6650433d
[2011/06/26 20:42:32 | 000,000,097 | —- | C] () – C:\Windows\System32\1283347277
[2011/06/14 19:24:05 | 000,001,664 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/04/30 21:07:07 | 000,008,252 | -HS- | C] () – C:\Users\owner\AppData\Local\vhf6a7ab7h335d07ur33rbd5x6cjdqx1gr8iu
[2011/04/30 21:07:07 | 000,008,252 | -HS- | C] () – C:\ProgramData\vhf6a7ab7h335d07ur33rbd5x6cjdqx1gr8iu
[2010/12/22 22:57:51 | 000,395,776 | —- | C] () – C:\Windows\System32\libmplayer.dll
[2010/12/22 22:57:51 | 000,262,144 | —- | C] () – C:\Windows\System32\TomsMoComp_ff.dll
[2010/12/22 22:57:51 | 000,112,640 | —- | C] () – C:\Windows\System32\libmpeg2_ff.dll
[2010/12/22 22:57:50 | 002,255,360 | —- | C] () – C:\Windows\System32\libavcodec.dll
[2010/11/23 16:35:08 | 008,892,928 | —- | C] () – C:\ProgramData\atscie.msi
[2010/09/20 18:11:02 | 000,000,412 | —- | C] () – C:\Windows\MAXLINK.INI
[2008/07/05 10:56:49 | 000,002,528 | —- | C] () – C:\Windows\FCIC.INI
[2008/06/26 12:01:06 | 000,000,464 | —- | C] () – C:\Users\owner\AppData\Roaming\wklnhst.dat
[2008/06/24 06:40:57 | 000,074,752 | —- | C] () – C:\Users\owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/06/08 08:09:22 | 000,141,239 | —- | C] () – C:\Users\owner\AppData\Roaming\nvModes.001
[2008/06/07 13:02:01 | 000,141,239 | —- | C] () – C:\Users\owner\AppData\Roaming\nvModes.dat
[2008/05/25 09:23:06 | 000,007,268 | —- | C] () – C:\Users\owner\AppData\Local\d3d9caps.dat
[2008/05/16 11:58:04 | 000,012,632 | —- | C] () – C:\Windows\System32\lsdelete.exe
[2008/05/14 09:35:16 | 001,029,546 | —- | C] () – C:\ProgramData\LuUninstall.LiveUpdate
[2008/05/11 10:30:37 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2008/05/10 20:26:28 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2007/12/06 19:46:25 | 000,001,732 | —- | C] () – C:\Windows\System32\drivers\nvphy.bin
[2007/10/25 01:55:47 | 000,101,605 | —- | C] () – C:\Windows\hpqins13.dat
[2006/11/02 05:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 05:47:37 | 000,326,448 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:33:01 | 000,618,648 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 03:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 03:33:01 | 000,104,024 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 03:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 03:25:21 | 000,061,440 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2006/11/02 03:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 01:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 01:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 00:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2006/11/02 00:22:43 | 000,099,999 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2006/11/02 00:22:43 | 000,018,271 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2006/03/09 15:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll

========== LOP Check ==========

[2008/12/28 13:38:05 | 000,000,000 | —D | M] – C:\Users\owner\AppData\Roaming\BitTorrent
[2010/09/30 20:55:40 | 000,000,000 | —D | M] – C:\Users\owner\AppData\Roaming\Canon
[2011/07/01 08:25:21 | 000,000,000 | —D | M] – C:\Users\owner\AppData\Roaming\DNA
[2010/06/25 09:47:02 | 000,000,000 | —D | M] – C:\Users\owner\AppData\Roaming\Facebook
[2011/06/30 08:40:08 | 000,000,000 | —D | M] – C:\Users\owner\AppData\Roaming\Flip Video
[2009/03/01 12:07:36 | 000,000,000 | —D | M] – C:\Users\owner\AppData\Roaming\GARMIN
[2010/08/01 16:10:13 | 000,000,000 | —D | M] – C:\Users\owner\AppData\Roaming\MusicNet
[2010/09/20 18:10:34 | 000,000,000 | —D | M] – C:\Users\owner\AppData\Roaming\ScanSoft
[2008/06/26 12:01:07 | 000,000,000 | —D | M] – C:\Users\owner\AppData\Roaming\Template
[2008/07/15 11:14:12 | 000,000,000 | —D | M] – C:\Users\owner\AppData\Roaming\WildTangent
[2011/07/01 08:13:34 | 000,032,640 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >
extras log



OTL Extras logfile created on: 7/1/2011 8:24:33 AM - Run 1
OTL by OldTimer - Version 3.2.25.0 Folder = C:\Users\owner\Desktop
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.17037)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.94 Gb Total Physical Memory | 1.27 Gb Available Physical Memory | 65.49% Memory free
4.08 Gb Paging File | 3.13 Gb Available in Paging File | 76.69% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 137.36 Gb Total Space | 52.91 Gb Free Space | 38.52% Space Free | Partition Type: NTFS
Drive D: | 11.69 Gb Total Space | 1.86 Gb Free Space | 15.87% Space Free | Partition Type: NTFS

Computer Name: OWNER-PC | User Name: owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – (EarthLink, Inc.)
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1A153D06-92B7-45AB-83BB-2A5B36590EFE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{5DB96690-9372-4B7D-930F-3BEAABCC450A}" = rport=80 | protocol=6 | dir=out | app=c:\program files\common files\intuit\update service\intuitupdater.exe |
"{760D96A8-F50C-4E67-86EE-D975D2AF766F}" = lport=67 | protocol=17 | dir=in | name=dhcp discovery service |
"{873C4718-6C51-4752-A329-A64D78E7D5E9}" = lport=24727 | protocol=6 | dir=in | name=flipshareserver |
"{87554E76-F422-4FA2-B231-583AE562D97F}" = rport=80 | protocol=6 | dir=out | app=c:\program files\common files\intuit\update service\intuitupdateservice.exe |
"{8B2BB0AF-AE0E-4D54-A09A-5F3DE48FB5DF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{9A2DB3E6-3A00-4A30-8E64-AA1EAF85C70A}" = lport=24726 | protocol=6 | dir=in | name=flipshareserver |
"{C8E51999-8306-48EF-B03D-937B4BC52AC0}" = lport=2869 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{15DB3002-03A4-4537-BDD2-854273BC1B83}" = protocol=17 | dir=in | app=c:\program files\imesh applications\imesh\imesh.exe |
"{1EB347D4-02AB-4EAC-91F7-E1618115A482}" = protocol=6 | dir=in | app=c:\program files\imesh applications\imesh\imesh.exe |
"{22B53B4F-40FA-4CF4-9060-A66D86319ADC}" = protocol=17 | dir=in | app=c:\program files\dna\btdna.exe |
"{3287ED53-5EBD-4AEF-93EF-9E5AB8E319BF}" = protocol=6 | dir=in | app=c:\program files\dna\btdna.exe |
"{3AB9E897-EFD5-46F8-A8FD-92524044A185}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{410F4B76-F130-4695-B8B1-B14553390A90}" = dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{4630CE96-7C84-4111-9852-86D38C21972F}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{5031C68C-54C3-4E23-A3CB-9007F2FC93F8}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{584C99A5-5E55-44F3-94C0-92E250DBD373}" = dir=in | app=c:\windows\system32\keyiso32.exe |
"{5C634452-13D3-47EB-88A4-0BD0A3B8F9A8}" = dir=in | app=c:\program files\leapfrog\leapfrog connect\leapfrogconnect.exe |
"{5CA1D18B-280C-4212-B252-4EACEB848446}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{6DA52B40-B3EB-44DC-A7FD-F76685D124B8}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{7970B03F-C03A-4DC6-B403-082BFE9A039A}" = protocol=6 | dir=in | app=c:\program files\pure networks\network magic\nmsrvc.exe |
"{8760BF42-58E6-44F1-A150-DEF5D4C50B42}" = dir=in | app=c:\windows\system32\keyiso32.exe |
"{87ACB335-E815-49CD-9B08-E80FE0590F7B}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A58FD147-FC5F-4240-AACA-20CF490E93AF}" = protocol=17 | dir=in | app=c:\program files\pure networks\network magic\nmsrvc.exe |
"{A8E5C9F0-4834-430E-BF82-63670D386238}" = protocol=6 | dir=in | app=c:\program files\imesh applications\imesh\imesh.exe |
"{A9336052-F86F-4E0E-8826-A1B48A2ECC8B}" = protocol=17 | dir=in | app=c:\program files\imesh applications\imesh\imesh.exe |
"{AB196BDF-4D50-4B68-BD55-10E9173EF3AB}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{BAF2F0A3-BD92-4F8F-BE0A-268C5AF5A2E8}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{CA6C467C-F80C-4393-A684-1A757088196E}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{CCB39148-7984-4B64-B9C3-C4136001128B}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{D012D9F6-2140-435A-84C2-5468FCAFA85A}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{DFEECBBB-4A49-4F28-B9EF-24D3683EF091}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe |
"{FB8AC562-E60F-4011-B998-AC91AD9AB9A9}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{FC282E7C-6B9D-4D8F-B04B-881AFD0CF752}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{FDED2A38-B727-4CA8-AF3A-50EE24FE07AE}" = dir=in | app=c:\windows\system32\keyiso32.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BDC796-3451-4F81-B91D-E98F7ADA76C2}" = TurboTax 2010 WinPerTaxSupport
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{06E74B9B-631F-4378-BF3A-40D868450C05}" = HPPhotoSmartPhotobookHolidayPack1
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{082F8ABA-84D5-4837-9DFC-F365D91A07D4}" = HP Smart Web Printing
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP210_series" = Canon MP210 series
"{11B83AD3-7A46-4C2E-A568-9505981D4C6F}" = HP Update
"{11BB336F-0E58-4977-B866-F24FA334616B}" = HP Active Support Library
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{172AEB5E-CBB2-4CDD-A4CF-388600825839}" = HPPhotoSmartPhotobookPlayfulPack1
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{209CDA54-D390-46A2-A97C-7BF61734418D}" = WeatherBug Gadget
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{250E9609-E830-43EB-B379-DAB7546A2422}" = muvee autoProducer 6.1
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 18
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program
"{28EDCE9C-3304-4331-8AB3-F3EBE94C35B4}" = HP Help and Support
"{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{341201D4-4F61-4ADB-987E-9CCE4D83A58D}" = Windows Live Toolbar Extension (Windows Live Toolbar)
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 D2
"{3782EC09-4000-475E-8A59-9CABD6F03B4C}" = TurboTax 2010 WinPerFedFormset
"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 3.6
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{4F2FCCCF-29F3-44B9-886F-6D16F8417522}" = TurboTax 2010 wrapper
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.52.02
"{5B35C417-2649-11D6-83D1-0050FC01225C}" = FirstClass® Client
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{68471BF2-F1F7-4C89-BBBA-400B94996596}" = ESU for Microsoft Vista
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7745B7A9-F323-4BB9-9811-01BF57A028DA}" = Map Button (Windows Live Toolbar)
"{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}" = Windows Live Favorites for Windows Live Toolbar
"{7E6066E6-8B5B-4100-B0FA-1D9E9B663CBA}" = iTunes
"{7FCC4EDC-6EE2-4309-ABD7-85F2667A7B90}" = WebEx Support Manager for Internet Explorer
"{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine
"{89E052B2-5CA5-4B7A-AF0C-28CA2836B030}" = HPPhotoSmartPhotobookModernPack1
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{97C658D2-61FB-027F-0D76-E9CDC84AFEC7}" = FlipShare
"{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = AnswerWorks 5.0 English Runtime
"{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel
"{A525E00B-6609-442E-9DCD-64453C233E8D}" = TurboTax 2010 WinPerReleaseEngine
"{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}" = Highlight Viewer (Windows Live Toolbar)
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AC76BA86-7AD7-2448-0000-800000000003}" = Chinese Traditional Fonts Support For Adobe Reader 8
"{AC95121F-1576-45B8-82F7-3911D27882E6}" = HPPhotoSmartPhotobookScrapbookPack1
"{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin
"{b02df929-29a7-4fd2-9a70-81a644b635f7}" = HP Total Care Advisor
"{B1102A25-3AA3-446B-AA0F-A699B07A02FD}" = Garmin USB Drivers
"{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper
"{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{B57A7B53-0662-4AC0-9352-2AE2D8212A9F}" = Garmin Communicator Plugin
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{BA165460-FCF7-4D6C-A7A2-F2321700720F}" = MobileMe Control Panel
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BB77DC4C-B818-4FD4-8D1D-5D3B617B78B4}" = LeapFrog My Pals Plugin
"{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C6359569-E03E-4CDC-98E8-CDD080C6EEB5}" = LeapFrog Connect
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant
"{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}" = WinZip 14.5
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DD3C88A0-C53C-41D0-A21B-6D021981D23E}" = HPPhotoSmartDiscLabelContent1
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{DEE88727-779B-47A9-ACEF-F87CA5F92A65}" = ScanSoft OmniPage SE 4
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E6D3A461-8DDE-45C9-8C34-A33436FCC0B4}" = HP User Guides 0091
"{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp
"{F084395C-40FB-4DB3-981C-B51E74E1E83D}" = Smart Menus (Windows Live Toolbar)
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F636EE9A-F9EC-4606-BCFA-77DD0E210788}" = HPPhotoSmartDiscLabel_Tattoo
"{F7F3B252-E772-48AA-93EB-7964BC326067}" = MSCU for Microsoft Vista
"45A7283175C62FAC673F913C1F532C5361F97841" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0)
"8F14F2ECEDE68D26EA515B48DC25B39103C4FE8D" = Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net (09/10/2009 02.03.05.012)
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"APA PERRLA" = APA PERRLA
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Camera Window DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Camera Window DC_DV 6 for ZoomBrowser EX
"CameraWindowMC" = Canon Camera Window MC 6 for ZoomBrowser EX
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"Canon MP210 series User Registration" = Canon MP210 series User Registration
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"CSCLIB" = Canon Camera Support Core Library
"Cucusoft MPEG/MOV/RM/DivX/AVI to DVD/VCD/SVCD Creator Pro_is1" = Cucusoft MPEG/MOV/RM/DivX/AVI to DVD/VCD/SVCD Creator Pro 7.07
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"EOS Utility" = Canon Utilities EOS Utility
"Google Updater" = Google Updater
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"Mozilla Firefox (3.6.18)" = Mozilla Firefox (3.6.18)
"MP Navigator EX 1.0" = Canon MP Navigator EX 1.0
"MyPalsPlugin" = Use the entry named LeapFrog Connect to uninstall (LeapFrog My Pals Plugin)
"NVIDIA Drivers" = NVIDIA Drivers
"PdaNet_is1" = PdaNet for Android 2.45
"PhotoStitch" = Canon Utilities PhotoStitch
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RemoteCaptureTask" = Canon RemoteCapture Task for ZoomBrowser EX
"SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.4
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TurboTax 2008" = TurboTax 2008
"TurboTax 2009" = TurboTax 2009
"TurboTax 2010" = TurboTax 2010
"UnityWebPlayer" = Unity Web Player
"UPCShell" = LeapFrog Connect
"ViewpointMediaPlayer" = Viewpoint Media Player
"WildTangent hp Master Uninstall" = My HP Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent" = BitTorrent
"BitTorrent DNA" = DNA
"Facebook Plug-In" = Facebook Plug-In
"Move Media Player" = Move Media Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/30/2011 12:23:32 PM | Computer Name = owner-PC | Source = Windows Search Service | ID = 3031
Description =

Error - 6/30/2011 12:27:39 PM | Computer Name = owner-PC | Source = Windows Search Service | ID = 3031
Description =

Error - 6/30/2011 12:32:56 PM | Computer Name = owner-PC | Source = WerSvc | ID = 5007
Description =

Error - 6/30/2011 12:33:43 PM | Computer Name = owner-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 6/30/2011 3:10:53 PM | Computer Name = owner-PC | Source = Application Error | ID = 1000
Description = Faulting application pev.cfxxe, version 0.0.0.0, time stamp 0x4e06cfe8,
faulting module pev.cfxxe, version 0.0.0.0, time stamp 0x4e06cfe8, exception code
0x40000015, fault offset 0x0008d1c0, process id 0xff8, application start time 0x01cc37596db141a0.

Error - 6/30/2011 7:57:52 PM | Computer Name = owner-PC | Source = Application Hang | ID = 1002
Description = The program Ad-Aware.exe version 7.1.0.10 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 15d0 Start Time: 01cc378162a558f0 Termination Time: 61

Error - 6/30/2011 8:34:08 PM | Computer Name = owner-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 6/30/2011 9:34:41 PM | Computer Name = owner-PC | Source = WerSvc | ID = 5007
Description =

Error - 7/1/2011 10:57:11 AM | Computer Name = owner-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 7/1/2011 11:16:28 AM | Computer Name = owner-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

[ System Events ]
Error - 6/30/2011 8:29:39 PM | Computer Name = owner-PC | Source = DCOM | ID = 10016
Description =

Error - 6/30/2011 8:31:37 PM | Computer Name = owner-PC | Source = ACPI | ID = 327686
Description = IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot
12, function 0. Please contact your system vendor for technical assistance.

Error - 6/30/2011 8:31:37 PM | Computer Name = owner-PC | Source = ACPI | ID = 327686
Description = IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot
13, function 0. Please contact your system vendor for technical assistance.

Error - 6/30/2011 8:31:52 PM | Computer Name = owner-PC | Source = Microsoft-Windows-Kernel-WHEA | ID = 6
Description =

Error - 7/1/2011 10:55:07 AM | Computer Name = owner-PC | Source = ACPI | ID = 327686
Description = IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot
12, function 0. Please contact your system vendor for technical assistance.

Error - 7/1/2011 10:55:07 AM | Computer Name = owner-PC | Source = ACPI | ID = 327686
Description = IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot
13, function 0. Please contact your system vendor for technical assistance.

Error - 7/1/2011 10:55:22 AM | Computer Name = owner-PC | Source = Microsoft-Windows-Kernel-WHEA | ID = 6
Description =

Error - 7/1/2011 10:57:06 AM | Computer Name = owner-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 7/1/2011 11:14:33 AM | Computer Name = owner-PC | Source = Microsoft-Windows-Kernel-WHEA | ID = 6
Description =

Error - 7/1/2011 11:16:22 AM | Computer Name = owner-PC | Source = Service Control Manager | ID = 7000
Description =


< End of report >
aswMBR report. The first time I ran this I got an error but the second time it worked just fine. Thanks!! aswMBR version 0.9.7.675 Copyright© 2011 AVAST Software Run date: 2011-07-01 08:39:38 —————————– 08:39:38.478 OS Version: Windows 6.0.6000 08:39:38.478 Number of processors: 2 586 0x6802 08:39:38.478 ComputerName: OWNER-PC UserName: owner 08:40:07.557 Initialize success 08:40:57.216 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 08:40:57.216 Disk 0 Vendor: ST9160821AS 3.BHE Size: 152627MB BusType: 3 08:40:59.369 Disk 0 MBR read successfully 08:40:59.369 Disk 0 MBR scan 08:40:59.384 Disk 0 unknown MBR code 08:41:01.412 Disk 0 scanning sectors +312576705 08:41:01.459 Disk 0 scanning C:\Windows\system32\drivers 08:41:07.356 Service scanning 08:41:09.384 Disk 0 trace - called modules: 08:41:09.446 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys 08:41:09.462 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8489a4b8] 08:41:09.478 3 ntkrnlpa.exe[820b07e2] -> nt!IofCallDriver -> [0x847a88d8] 08:41:09.478 5 acpi.sys[8023232a] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0x8478dbb0] 08:41:09.493 Scan finished successfully 08:42:37.524 Disk 0 MBR has been saved successfully to "C:\Users\owner\Desktop\MBR.dat" 08:42:37.524 The log file has been saved successfully to "C:\Users\owner\Desktop\aswMBR.txt"
Hello wsuozzie,

SPYBOT TEATIMER

* Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
* On the left hand side, click on Tools, then click on the Resident Icon in the list.
* Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
* Click on the "System Startup" icon in the List
* Uncheck the "TeaTimer" box and "OK" any prompts.
* If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
* Exit Spybot S&D when done and reboot your computer.
(When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.
========================

Next

Download and Run ComboFix
  • Please download ComboFix from one of the following links.

    Link 1.

    Link 2.

    **IMPORTANT !!! Save ComboFix.exe to your Desktop**
  • Please disable any Antivirus or Firewall you have active, as shown in this topic. Please close all open application windows.
  • Double click on ComboFix.exe & follow the prompts
  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply
A word of warning: Neither I nor sUBs are responsible for any damage you may cause to your machine by running ComboFix on your own. This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper

===========================
Please include in your next reply:
1. Any problem executing the instructions?
2. Combofix log
4. How is the computer behaving?
ComboFix 11-07-02.02 - owner 07/02/2011 16:33:05.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1982.1353 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\ryo8kylj.default\extensions\{b7964d47-b174-4a94-ac5a-3ce2e8b53d18}
c:\users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\ryo8kylj.default\extensions\{b7964d47-b174-4a94-ac5a-3ce2e8b53d18}\chrome.manifest
c:\users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\ryo8kylj.default\extensions\{b7964d47-b174-4a94-ac5a-3ce2e8b53d18}\chrome\xulcache.jar
c:\users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\ryo8kylj.default\extensions\{b7964d47-b174-4a94-ac5a-3ce2e8b53d18}\defaults\preferences\xulcache.js
c:\users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\ryo8kylj.default\extensions\{b7964d47-b174-4a94-ac5a-3ce2e8b53d18}\install.rdf
c:\windows\system32\KBL.LOG
.
.
((((((((((((((((((((((((( Files Created from 2011-06-02 to 2011-07-02 )))))))))))))))))))))))))))))))
.
.
2011-07-02 23:45 . 2011-07-02 23:45 ——– d—–w- c:\users\owner\AppData\Local\temp
2011-07-02 23:45 . 2011-07-02 23:45 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-06-30 15:57 . 2011-06-30 16:30 20552 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-06-30 15:50 . 2011-06-30 16:27 ——– d—–w- c:\programdata\Hitman Pro
2011-06-30 15:40 . 2011-06-30 15:40 ——– d—–w- c:\users\owner\AppData\Roaming\Flip Video
2011-06-30 15:37 . 2011-06-30 15:38 ——– d—–w- c:\program files\Flip Video
2011-06-29 15:46 . 2011-07-02 23:20 ——– d—–w- c:\programdata\Kaspersky Lab
2011-06-27 17:57 . 2011-06-27 17:57 ——– d—–w- c:\programdata\SUPERAntiSpyware.com
2011-06-27 15:38 . 2011-07-01 00:01 ——– d—–w- c:\programdata\STOPzilla!
2011-06-15 02:22 . 2011-06-15 02:22 ——– d—–w- c:\program files\iPod
2011-06-15 02:22 . 2011-06-15 02:24 ——– d—–w- c:\program files\iTunes
2011-06-15 02:14 . 2011-06-15 02:14 ——– d—–w- c:\program files\Bonjour
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-11 07:04 . 2011-04-29 23:15 7071056 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{01551091-4AD8-4818-AD53-4AAB8C017B44}\mpengine.dll
2011-04-06 23:20 . 2011-04-06 23:20 91424 —-a-w- c:\windows\system32\dnssd.dll
2011-04-06 23:20 . 2011-04-06 23:20 107808 —-a-w- c:\windows\system32\dns-sd.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="c:\users\owner\Program Files\DNA\btdna.exe" [2009-10-06 323392]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-10-03 181544]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-04-13 47392]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"Monitor"="c:\program files\LeapFrog\LeapFrog Connect\Monitor.exe" [2010-11-19 193880]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-06-08 421160]
.
c:\users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
PdaNet Desktop.lnk - c:\program files\PdaNet for Android\PdaNetPC.exe [2011-4-1 473616]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R2 gupdate1ca194523ff6b60;Google Update Service (gupdate1ca194523ff6b60);c:\program files\Google\Update\GoogleUpdate.exe [2009-08-09 133104]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-08-09 133104]
R3 hitmanpro35;Hitman Pro 3.5 Support Driver;c:\windows\system32\drivers\hitmanpro35.sys [2011-06-30 20552]
S2 atashost;WebEx Service Host for Support Center;c:\windows\system32\atashost.exe [2009-03-06 20376]
S2 FlipShareServer;FlipShare Server;c:\program files\Flip Video\FlipShareServer\FlipShareServer.exe [2011-05-06 1085440]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys [2010-09-02 13312]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-24 01:34 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-02 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-09 22:56]
.
2011-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-09 22:59]
.
2011-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-09 22:59]
.
2011-06-14 c:\windows\Tasks\HPCeeScheduleForowner.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2007-10-25 18:58]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Presario&pf=laptop
uInternet Settings,ProxyOverride = *.local
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\ryo8kylj.default\
FF - prefs.js: browser.startup.homepage - www.bing.com
FF - prefs.js: keyword.URL - hxxp://www.google.co.in/search?btnI=I%27m+Feeling+Lucky&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
FF - Ext: Move Media Player: [removed] - c:\users\owner\AppData\Roaming\Move Networks
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-07-02 16:45
Windows 6.0.6000 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-07-02 16:49:19
ComboFix-quarantined-files.txt 2011-07-02 23:49
.
Pre-Run: 56,959,897,600 bytes free
Post-Run: 57,019,744,256 bytes free
.
- - End Of File - - 5AB004328508D2DB12DA0C1C1F7688D5







I had no problems following the instructions. So far there are no problems with the computer and the links seem to be working properly. I will post if anything changes. Thank you!!!
Hello wsuozzie,

That's great the computer is running better. :thumbup: Almost done we still have a few scans and Important updates to do.

Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please

=====================================
NEXT


As a Vista or Windows 7 user you will need to right click your browser icon and select "Run as Administrator" in order to run this scan.
  • Do not use this instance of your browser for anything besides doing this scan
  • When the scan is complete and the results saved, close that instance of your browser
  • Open a new one the usual way and post the results in this topic.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • Re-enable your Antivirus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. or C:\Program Files\ESET\log.txtWe will need this later.
Please post back with the ESET log.

=================================
Please include in your next reply:
1. Any problem executing the instructions?
2. MBAM log
3. ESET log
4. How is the computer behaving?
malaware scan log Malwarebytes' Anti-Malware 1.51.0.1200 www.malwarebytes.org Database version: 7012 Windows 6.0.6000 Internet Explorer 7.0.6000.17037 7/4/2011 8:48:44 AM mbam-log-2011-07-04 (08-48-44).txt Scan type: Quick scan Objects scanned: 165705 Time elapsed: 5 minute(s), 43 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
ESET log ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=7.00.6000.16386 (vista_rtm.061101-2205) # OnlineScanner.ocx=1.0.0.6427 # api_version=3.0.2 # EOSSerial=fe2d22a64f60ea47bcf7f61fc0e3234c # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-07-04 06:36:13 # local_time=2011-07-04 11:36:13 (-0800, Pacific Daylight Time) # country="United States" # lang=9 # osver=6.0.6000 NT # compatibility_mode=5892 16776574 66 100 5484519 146402567 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=196315 # found=1 # cleaned=0 # scan_time=9576 C:\Qoobox\Quarantine\C\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\ryo8kylj.default\extensions\{b7964d47-b174-4a94-ac5a-3ce2e8b53d18}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I Computer is behaving well. Havent had any troubles since a couple of days ago!
Hello wsuozzie,

I see you have P2P software BitTorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall this/these now. You can do so via Control Panel >> Add or Remove Programs.
============================
Please download JavaRa to your desktop and unzip it to its own
folder
  • Run JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista), pick the language of your choice and click Select. Then
    click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista) again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest
    Java Runtime Environment (JRE) version for your computer.
============================
IMPORTANT:

I noticed that you don't have an Antivirus program installed on your system. As a rule of thumb one should run one firewall, one antivirus program in memory, and one antispyware utility in memory. It's fine to have other security tools available on an as-needed or on-demand basis, but when multiple tools simultaneously perform the same function, you're asking for trouble.

I would recommend that you install one of these free Antivirus programs immediately before we begin cleaning your system. Just choose one:
Avira
Avast
Microsoft Security Essentials
============================
MOST IMPORTANT: You Need to Update Windows and IE to get all the Latest Security Patches to protect your computer from the malware that is around on the internet. Please go to
Microsoft Windows and Internet Explorer Updates to get the critical updates.

If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the cirtical updates installed (Free) Microsoft Office Update

============================
Time for some house cleaning
Follow these steps to uninstall Combofix


* Click START Search
* Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the /, it needs to be there.
(Note: There is a space between the ..X and the /U that needs to be there.)

[external image: Posted Image]
============================
Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.


    If you notice any remaining tools or files you can delete them by right clicking and choosing delete.
    I would definitely keep Malwarebytes and run it weekly. SuperAntiSpyware is good to have too, but you don't have to keep it if you don''t want to.
    Any other tools we used can be deleted safely if they remain after these steps.

    ============================

    Now that you appear clean, :thumbup: please follow these simple steps in order to keep your computer clean and secure:

    1.Make your Internet Explorer More Secure
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt.
  • Change the Download unsigned ActiveX controls to Disable.
  • Change the Initialise and script ActiveX controls not marked as safe to Disable.
  • Change the Installation of desktop items to Prompt.
  • Change the Launching programs and files in an IFRAME to Prompt.
  • Change the Navigate sub-frames across different domains to Prompt.
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. Update your Anti-Virus Software - I can not overemphasize the need for you to update your Anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

3. Make sure you keep your Windows OS current by visiting Windows update regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.


4. Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
Without a firewall your computer is succeptible to being hacked and taken over.
I am very serious about this and see it happen almost every day with my clients.
Simply using a Firewall in its default configuration can lower your risk greatly.

5. WOT , Web of Trust, As 'Googling' is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
Green to go
Yellow for caution
Red to stop
WOT has an addon available for both Firefox and IE.


6. SpywareBlaster prevents the installation of ActiveX-based malware, blocks cookies, and restricts the actions of "bad" sites. See tutorial here

7. MVPS HOSTS FILE replaces
  • your current HOSTS file with one that will restrict known ad sites from serving you unsolicited advertisements. It basically prevents your computer from connecting to those sites by redirecting the attempted connections to 127.0.0.1, which is the IP of your local computer. See guide here and for Windows Vista here
  • Download Host.zip and Save it to your Desktop.
  • Right-click hosts.zip and select 'Extract all files' or 'Extract files…'.
  • Follow the prompts and click 'Finish'.
  • This will open the newly created hosts folder on your Desktop.
  • Double-click on the included mvps.bat file, this will rename the existing HOSTS file to HOSTS.MVP, then it will copy the included updated HOSTS file to the correct location on your machine.
  • Once updated you should see another prompt that the task was completed.

Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?

Good luck, happy computing and stay clean! :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI