This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HP computer running slow

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i got a hp pc it has a prity good specs but it runs rely slow like if you have 2 things runing it slows right down to the point were its unusebel and takes for ever to just do internet things or any thing i have done every thing PLease Help!!!!
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete, download or install anything or run additional scans unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———-

Please download DDS from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post both of the logs created by DDS and the log created by aswMBR.exe. :)
. DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 Run by [removed] at 19:43:40 on 2011-09-16 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2942.1679 [GMT -7:00] . SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\rundll32.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\SUPERAntiSpyware\SASCORE.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Microsoft\BingBar\SeaPort.EXE C:\Program Files\Bonjour\mDNSResponder.exe c:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Motive\McciCMService.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\hp\support\hpsysdrv.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\WINDOWS\System32\rundll32.exe C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\ehome\ehtray.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe C:\Windows\system32\Macromed\Flash\FlashUtil10v_ActiveX.exe C:\Program Files\Internet Explorer\iexplore.exe c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\system32\rundll32.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uSearch Bar = Preserve mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Pavilion&pf=desktop uInternet Settings,ProxyOverride = *.local BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll" BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll" uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_01\bin\jusched.exe" mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL Trusted Zone: $talisma_url$ DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.1.254 TCP: Interfaces\{EE8227C0-2ACF-47E5-9DFF-89E83026540A} : DhcpNameServer = 192.168.1.254 Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL . ============= SERVICES / DRIVERS =============== . R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2010-2-17 12880] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67664] R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCORE.EXE [2010-6-29 116608] R2 BBUpdate;BBUpdate;c:\program files\microsoft\bingbar\SeaPort.EXE [2011-6-15 249648] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2009-12-29 21504] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-5 135664] S3 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-7-7 195336] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-2-5 135664] S3 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\symantec\defini~1\symcdata\idsdefs\20070108.003\IDSvix86.sys [2007-8-4 212280] S3 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-8-4 1174664] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2011-09-16 23:04:00 ——– d—–w- c:\program files\iPod 2011-09-16 22:48:52 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll 2011-09-16 22:48:52 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll 2011-09-16 22:48:52 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll 2011-09-16 22:48:52 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll 2011-09-16 22:48:52 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll 2011-09-16 22:48:52 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll 2011-09-16 22:48:52 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin.dll 2011-09-16 20:22:13 7152464 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{4d72e50f-5766-44a5-8aea-387c0391d878}\mpengine.dll 2011-09-16 20:09:18 ——– d—–w- c:\program files\iPhoneBrowser 2011-09-15 20:59:32 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat 2011-08-28 23:05:15 4186376 —-a-w- c:\programdata\microsoft\bingbar\bbsvc\7.0.822.0oemBingBarSetup-Partner.EXE 2011-08-24 21:47:15 2048 —-a-w- c:\windows\system32\tzres.dll . ==================== Find3M ==================== . 2011-08-13 05:28:44 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-07-22 02:54:43 1797632 —-a-w- c:\windows\system32\jscript9.dll 2011-07-22 02:48:26 1126912 —-a-w- c:\windows\system32\wininet.dll 2011-07-22 02:44:36 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2011-07-12 18:20:54 83816 —-a-w- c:\windows\system32\dns-sd.exe 2011-07-12 18:20:54 73064 —-a-w- c:\windows\system32\dnssd.dll 2011-07-12 18:20:54 50536 —-a-w- c:\windows\system32\jdns_sd.dll 2011-07-12 18:20:54 178536 —-a-w- c:\windows\system32\dnssdX.dll 2011-07-06 15:31:47 214016 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-07-06 01:37:00 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx 2011-07-06 01:37:00 69632 —-a-w- c:\windows\system32\QuickTime.qts 2011-06-20 08:54:36 3602832 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-06-20 08:54:36 3550096 —-a-w- c:\windows\system32\ntoskrnl.exe . ============= FINISH: 19:44:39.97 =============== aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-09-16 19:47:35 —————————– 19:47:35.982 OS Version: Windows 6.0.6002 Service Pack 2 19:47:35.982 Number of processors: 2 586 0x4303 19:47:35.982 ComputerName: YESENIAGUT-PC UserName: yeseniagut 19:47:38.478 Initialize success 19:48:26.407 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000004f 19:48:26.407 Disk 0 Vendor: WDC_WD40 12.0 Size: 381554MB BusType: 6 19:48:28.435 Disk 0 MBR read successfully 19:48:28.435 Disk 0 MBR scan 19:48:28.435 Disk 0 unknown MBR code 19:48:28.450 Disk 0 scanning sectors +781416720 19:48:28.544 Disk 0 scanning C:\Windows\system32\drivers 19:48:36.375 Service scanning 19:48:37.623 Modules scanning 19:48:41.492 Disk 0 trace - called modules: 19:48:41.507 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll storport.sys nvstor32.sys 19:48:41.523 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8602d780] 19:48:41.523 3 CLASSPNP.SYS[8a5a48b3] -> nt!IofCallDriver -> [0x85641748] 19:48:41.539 5 acpi.sys[82a086bc] -> nt!IofCallDriver -> \Device\0000004f[0x85641b88] 19:48:41.554 Scan finished successfully 19:49:00.227 Disk 0 MBR has been saved successfully to "C:\Users\yeseniagut\Desktop\MBR.dat" 19:49:00.227 The log file has been saved successfully to "C:\Users\yeseniagut\Desktop\aswMBR.txt"
. DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 Run by [removed] at 19:43:40 on 2011-09-16 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2942.1679 [GMT -7:00] . SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\rundll32.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\SUPERAntiSpyware\SASCORE.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Microsoft\BingBar\SeaPort.EXE C:\Program Files\Bonjour\mDNSResponder.exe c:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Motive\McciCMService.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\hp\support\hpsysdrv.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\WINDOWS\System32\rundll32.exe C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\ehome\ehtray.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe C:\Windows\system32\Macromed\Flash\FlashUtil10v_ActiveX.exe C:\Program Files\Internet Explorer\iexplore.exe c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\system32\rundll32.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uSearch Bar = Preserve mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Pavilion&pf=desktop uInternet Settings,ProxyOverride = *.local BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll" BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll" uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_01\bin\jusched.exe" mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL Trusted Zone: $talisma_url$ DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.1.254 TCP: Interfaces\{EE8227C0-2ACF-47E5-9DFF-89E83026540A} : DhcpNameServer = 192.168.1.254 Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL . ============= SERVICES / DRIVERS =============== . R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2010-2-17 12880] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67664] R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCORE.EXE [2010-6-29 116608] R2 BBUpdate;BBUpdate;c:\program files\microsoft\bingbar\SeaPort.EXE [2011-6-15 249648] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2009-12-29 21504] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-5 135664] S3 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-7-7 195336] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-2-5 135664] S3 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\symantec\defini~1\symcdata\idsdefs\20070108.003\IDSvix86.sys [2007-8-4 212280] S3 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-8-4 1174664] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2011-09-16 23:04:00 ——– d—–w- c:\program files\iPod 2011-09-16 22:48:52 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll 2011-09-16 22:48:52 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll 2011-09-16 22:48:52 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll 2011-09-16 22:48:52 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll 2011-09-16 22:48:52 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll 2011-09-16 22:48:52 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll 2011-09-16 22:48:52 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin.dll 2011-09-16 20:22:13 7152464 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{4d72e50f-5766-44a5-8aea-387c0391d878}\mpengine.dll 2011-09-16 20:09:18 ——– d—–w- c:\program files\iPhoneBrowser 2011-09-15 20:59:32 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat 2011-08-28 23:05:15 4186376 —-a-w- c:\programdata\microsoft\bingbar\bbsvc\7.0.822.0oemBingBarSetup-Partner.EXE 2011-08-24 21:47:15 2048 —-a-w- c:\windows\system32\tzres.dll . ==================== Find3M ==================== . 2011-08-13 05:28:44 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-07-22 02:54:43 1797632 —-a-w- c:\windows\system32\jscript9.dll 2011-07-22 02:48:26 1126912 —-a-w- c:\windows\system32\wininet.dll 2011-07-22 02:44:36 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2011-07-12 18:20:54 83816 —-a-w- c:\windows\system32\dns-sd.exe 2011-07-12 18:20:54 73064 —-a-w- c:\windows\system32\dnssd.dll 2011-07-12 18:20:54 50536 —-a-w- c:\windows\system32\jdns_sd.dll 2011-07-12 18:20:54 178536 —-a-w- c:\windows\system32\dnssdX.dll 2011-07-06 15:31:47 214016 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-07-06 01:37:00 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx 2011-07-06 01:37:00 69632 —-a-w- c:\windows\system32\QuickTime.qts 2011-06-20 08:54:36 3602832 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-06-20 08:54:36 3550096 —-a-w- c:\windows\system32\ntoskrnl.exe . ============= FINISH: 19:44:39.97 =============== aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-09-16 19:47:35 —————————– 19:47:35.982 OS Version: Windows 6.0.6002 Service Pack 2 19:47:35.982 Number of processors: 2 586 0x4303 19:47:35.982 ComputerName: YESENIAGUT-PC UserName: yeseniagut 19:47:38.478 Initialize success 19:48:26.407 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000004f 19:48:26.407 Disk 0 Vendor: WDC_WD40 12.0 Size: 381554MB BusType: 6 19:48:28.435 Disk 0 MBR read successfully 19:48:28.435 Disk 0 MBR scan 19:48:28.435 Disk 0 unknown MBR code 19:48:28.450 Disk 0 scanning sectors +781416720 19:48:28.544 Disk 0 scanning C:\Windows\system32\drivers 19:48:36.375 Service scanning 19:48:37.623 Modules scanning 19:48:41.492 Disk 0 trace - called modules: 19:48:41.507 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll storport.sys nvstor32.sys 19:48:41.523 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8602d780] 19:48:41.523 3 CLASSPNP.SYS[8a5a48b3] -> nt!IofCallDriver -> [0x85641748] 19:48:41.539 5 acpi.sys[82a086bc] -> nt!IofCallDriver -> \Device\0000004f[0x85641b88] 19:48:41.554 Scan finished successfully 19:49:00.227 Disk 0 MBR has been saved successfully to "C:\Users\yeseniagut\Desktop\MBR.dat" 19:49:00.227 The log file has been saved successfully to "C:\Users\yeseniagut\Desktop\aswMBR.txt"

Attachments:

Hi yesi,

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Right-click and Run as Administrator GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
.
Hi yesi,

Thanks for the new log. You are doing just fine, but if you wouldn't mind please copy/paste the logs into your replies instead of attaching them. It helps me to review the logs more easily. :)
———-

  • Download OTL to your desktop.
  • Right-click and Run as Administrator on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
This one?


GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-09-17 23:35:05
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\0000004f WDC_WD40 rev.12.0
Running: gmer.exe; Driver: C:\Users\YESENI~1\AppData\Local\Temp\pxlyipob.sys


—- System - GMER 1.0.15 —-

SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS ZwTerminateProcess [0x8F4C9640]

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!KeSetEvent + 621 824C1DA4 4 Bytes [40, 96, 4C, 8F]
.text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x8E60D340, 0x3DA8C7, 0xE8000020]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Internet Explorer\iexplore.exe[1020] kernel32.dll!CreateThread 768ACB2E 5 Bytes JMP 6E5571CB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1020] USER32.dll!SetWindowsHookExW 769487AD 5 Bytes JMP 6E59204C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1020] USER32.dll!CallNextHookEx 76948E3B 5 Bytes JMP 6E5B7A4F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1020] USER32.dll!UnhookWindowsHookEx 769498DB 5 Bytes JMP 6E5DEA08 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1020] USER32.dll!EnableWindow 7694CD8B 5 Bytes JMP 6E5998BC C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1020] USER32.dll!DefWindowProcA 7694DB88 7 Bytes JMP 6E5593F5 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1020] USER32.dll!CreateWindowExA 7694DC2A 2 Bytes JMP 6E563223 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1020] USER32.dll!CreateWindowExA + 3 7694DC2D 2 Bytes [C1, F7]
.text C:\Program Files\Internet Explorer\iexplore.exe[1020] USER32.dll!CreateWindowExW 76951305 5 Bytes JMP 6E5BFE2F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1020] USER32.dll!DefWindowProcW 769603B4 7 Bytes JMP 6E5B7AB2 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1020] USER32.dll!DialogBoxParamW 769710B0 5 Bytes JMP 6E4F15E3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1020] USER32.dll!DialogBoxIndirectParamW 76972EF5 5 Bytes JMP 6E6E5E8E C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1020] USER32.dll!DialogBoxParamA 76988152 5 Bytes JMP 6E6E5E29 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1020] USER32.dll!DialogBoxIndirectParamA 7698847D 5 Bytes JMP 6E6E5EF3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1020] USER32.dll!MessageBoxIndirectA 7699D4D9 5 Bytes JMP 6E6E5DB0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1020] USER32.dll!MessageBoxIndirectW 7699D5D3 5 Bytes JMP 6E6E5D37 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1020] USER32.dll!MessageBoxExA 7699D639 5 Bytes JMP 6E6E5CD3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1020] USER32.dll!MessageBoxExW 7699D65D 5 Bytes JMP 6E6E5C6F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1020] ole32.dll!OleLoadFromStream 76731E80 5 Bytes JMP 6E6E6676 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1184] kernel32.dll!CreateThread 768ACB2E 5 Bytes JMP 6E5571CB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1184] USER32.dll!SetWindowsHookExW 769487AD 5 Bytes JMP 6E59204C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1184] USER32.dll!CallNextHookEx 76948E3B 5 Bytes JMP 6E5B7A4F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1184] USER32.dll!UnhookWindowsHookEx 769498DB 5 Bytes JMP 6E5DEA08 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1184] USER32.dll!EnableWindow 7694CD8B 5 Bytes JMP 6E5998BC C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1184] USER32.dll!DefWindowProcA 7694DB88 7 Bytes JMP 6E5593F5 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1184] USER32.dll!CreateWindowExA 7694DC2A 2 Bytes JMP 6E563223 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1184] USER32.dll!CreateWindowExA + 3 7694DC2D 2 Bytes [C1, F7]
.text C:\Program Files\Internet Explorer\iexplore.exe[1184] USER32.dll!CreateWindowExW 76951305 5 Bytes JMP 6E5BFE2F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1184] USER32.dll!DefWindowProcW 769603B4 7 Bytes JMP 6E5B7AB2 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1184] USER32.dll!DialogBoxParamW 769710B0 5 Bytes JMP 6E4F15E3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1184] USER32.dll!DialogBoxIndirectParamW 76972EF5 5 Bytes JMP 6E6E5E8E C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1184] USER32.dll!DialogBoxParamA 76988152 5 Bytes JMP 6E6E5E29 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1184] USER32.dll!DialogBoxIndirectParamA 7698847D 5 Bytes JMP 6E6E5EF3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1184] USER32.dll!MessageBoxIndirectA 7699D4D9 5 Bytes JMP 6E6E5DB0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1184] USER32.dll!MessageBoxIndirectW 7699D5D3 5 Bytes JMP 6E6E5D37 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1184] USER32.dll!MessageBoxExA 7699D639 5 Bytes JMP 6E6E5CD3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1184] USER32.dll!MessageBoxExW 7699D65D 5 Bytes JMP 6E6E5C6F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1184] ole32.dll!OleLoadFromStream 76731E80 5 Bytes JMP 6E6E6676 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2288] kernel32.dll!CreateThread 768ACB2E 5 Bytes JMP 6E5571CB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2288] USER32.dll!SetWindowsHookExW 769487AD 5 Bytes JMP 6E59204C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2288] USER32.dll!CallNextHookEx 76948E3B 5 Bytes JMP 6E5B7A4F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2288] USER32.dll!UnhookWindowsHookEx 769498DB 5 Bytes JMP 6E5DEA08 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2288] USER32.dll!EnableWindow 7694CD8B 5 Bytes JMP 6E5998BC C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2288] USER32.dll!DefWindowProcA 7694DB88 7 Bytes JMP 6E5593F5 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2288] USER32.dll!CreateWindowExA 7694DC2A 2 Bytes JMP 6E563223 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2288] USER32.dll!CreateWindowExA + 3 7694DC2D 2 Bytes [C1, F7]
.text C:\Program Files\Internet Explorer\iexplore.exe[2288] USER32.dll!CreateWindowExW 76951305 5 Bytes JMP 6E5BFE2F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2288] USER32.dll!DefWindowProcW 769603B4 7 Bytes JMP 6E5B7AB2 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2288] USER32.dll!DialogBoxParamW 769710B0 5 Bytes JMP 6E4F15E3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2288] USER32.dll!DialogBoxIndirectParamW 76972EF5 5 Bytes JMP 6E6E5E8E C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2288] USER32.dll!DialogBoxParamA 76988152 5 Bytes JMP 6E6E5E29 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2288] USER32.dll!DialogBoxIndirectParamA 7698847D 5 Bytes JMP 6E6E5EF3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2288] USER32.dll!MessageBoxIndirectA 7699D4D9 5 Bytes JMP 6E6E5DB0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2288] USER32.dll!MessageBoxIndirectW 7699D5D3 5 Bytes JMP 6E6E5D37 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2288] USER32.dll!MessageBoxExA 7699D639 5 Bytes JMP 6E6E5CD3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2288] USER32.dll!MessageBoxExW 7699D65D 5 Bytes JMP 6E6E5C6F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2288] ole32.dll!OleLoadFromStream 76731E80 5 Bytes JMP 6E6E6676 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3768] USER32.dll!EnableWindow 7694CD8B 5 Bytes JMP 6E5998BC C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3768] USER32.dll!DialogBoxParamW 769710B0 5 Bytes JMP 6E4F15E3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3768] USER32.dll!DialogBoxIndirectParamW 76972EF5 5 Bytes JMP 6E6E5E8E C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3768] USER32.dll!DialogBoxParamA 76988152 5 Bytes JMP 6E6E5E29 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3768] USER32.dll!DialogBoxIndirectParamA 7698847D 5 Bytes JMP 6E6E5EF3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3768] USER32.dll!MessageBoxIndirectA 7699D4D9 5 Bytes JMP 6E6E5DB0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3768] USER32.dll!MessageBoxIndirectW 7699D5D3 5 Bytes JMP 6E6E5D37 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3768] USER32.dll!MessageBoxExA 7699D639 5 Bytes JMP 6E6E5CD3 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3768] USER32.dll!MessageBoxExW 7699D65D 5 Bytes JMP 6E6E5C6F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
Hi yesi,

This one?

Yes that is what I meant…to cut/paste the logs into your replies. Were you able to run OTL yet? If so go ahead and post the logs that were created. :)
OTL logfile created on: 9/19/2011 11:44:16 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\yeseniagut\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.87 Gb Total Physical Memory | 1.81 Gb Available Physical Memory | 63.15% Memory free
5.97 Gb Paging File | 4.88 Gb Available in Paging File | 81.79% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 363.75 Gb Total Space | 295.66 Gb Free Space | 81.28% Space Free | Partition Type: NTFS
Drive D: | 8.85 Gb Total Space | 1.14 Gb Free Space | 12.82% Space Free | Partition Type: NTFS

Computer Name: YESENIAGUT-PC | User Name: yeseniagut | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\yeseniagut\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe (Sun Microsystems, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dll ()
MOD - C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL ()
MOD - C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll ()
MOD - C:\ProgramData\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()


========== Win32 Services (SafeList) ==========

SRV - (ISPwdSvc) – File not found
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (BBUpdate) – C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (Symantec Corporation)


========== Driver Services (SafeList) ==========

DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (nvlddmkm) – C:\WINDOWS\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (HSXHWBS2) – C:\WINDOWS\System32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\System32\drivers\HSX_DP.sys (Conexant Systems, Inc.)
DRV - (XAudio) – C:\WINDOWS\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (nvstor32) – C:\Windows\system32\drivers\nvstor32.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (IDSvix86) – C:\ProgramData\Symantec\Definitions\SymcData\idsdefs\20070108.003\IDSvix86.sys (Symantec Corporation)
DRV - (Ps2) – C:\WINDOWS\System32\drivers\PS2.sys (Hewlett-Packard Company)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\yeseniagut\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HBLite\bin\11.0.363.0\firefox\extensions

[2011/05/14 16:13:09 | 000,002,047 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\fcmdSrch.xml

O1 HOSTS File: ([2011/05/18 11:03:14 | 000,000,027 | —- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: $talisma_url$ ([]https in Trusted sites)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EE8227C0-2ACF-47E5-9DFF-89E83026540A}: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Users\yeseniagut\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\yeseniagut\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/08/04 21:58:18 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/09/16 16:04:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/09/16 16:04:00 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/09/16 15:48:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/09/16 15:48:40 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2011/09/16 15:41:05 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/09/16 13:11:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iPhoneBrowser
[2011/09/16 13:09:18 | 000,000,000 | —D | C] – C:\Program Files\iPhoneBrowser
[2011/08/24 14:47:15 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[1 C:\Users\yeseniagut\Documents\*.tmp files -> C:\Users\yeseniagut\Documents\*.tmp -> ]
[1 C:\Users\yeseniagut\Desktop\*.tmp files -> C:\Users\yeseniagut\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/09/19 23:33:11 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/09/19 23:03:00 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/09/19 22:49:26 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/09/19 22:49:26 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/09/19 20:49:25 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/09/17 23:12:07 | 000,294,216 | —- | M] () – C:\Users\yeseniagut\Desktop\gmer.zip
[2011/09/16 19:49:00 | 000,000,512 | —- | M] () – C:\Users\yeseniagut\Desktop\MBR.dat
[2011/09/16 16:08:56 | 000,001,854 | —- | M] () – C:\Users\Public\Desktop\Safari.lnk
[2011/09/16 16:08:56 | 000,001,854 | —- | M] () – C:\Users\yeseniagut\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/09/16 16:04:32 | 000,001,664 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/09/16 15:48:47 | 000,001,726 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/09/16 15:42:26 | 000,000,629 | —- | M] () – C:\Windows\System32\mapisvc.inf
[2011/09/15 14:19:47 | 000,604,264 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/09/15 14:19:47 | 000,103,964 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/09/14 16:11:34 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[1 C:\Users\yeseniagut\Documents\*.tmp files -> C:\Users\yeseniagut\Documents\*.tmp -> ]
[1 C:\Users\yeseniagut\Desktop\*.tmp files -> C:\Users\yeseniagut\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/09/17 23:11:15 | 000,294,216 | —- | C] () – C:\Users\yeseniagut\Desktop\gmer.zip
[2011/09/16 19:49:00 | 000,000,512 | —- | C] () – C:\Users\yeseniagut\Desktop\MBR.dat
[2011/09/16 16:04:32 | 000,001,664 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/09/16 15:48:47 | 000,001,726 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/03/13 17:22:39 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2011/03/13 17:22:39 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/03/13 17:22:39 | 000,089,088 | —- | C] () – C:\Windows\MBR.exe
[2011/03/13 17:22:39 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/03/13 17:22:39 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2010/02/04 23:41:19 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010/02/03 22:23:10 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2010/02/03 22:23:10 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/12/13 22:11:08 | 000,000,322 | —- | C] () – C:\Users\yeseniagut\AppData\Roaming\wklnhst.dat
[2009/12/12 16:01:30 | 000,010,240 | —- | C] () – C:\Users\yeseniagut\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/03 16:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 16:07:42 | 000,230,768 | —- | C] () – C:\Windows\System32\OGAEXEC.exe
[2007/08/04 21:48:19 | 000,107,026 | —- | C] () – C:\Windows\hpqins13.dat
[2007/08/04 21:33:11 | 000,061,440 | —- | C] () – C:\Windows\System32\OsdRemove.exe
[2007/08/04 21:24:41 | 000,102,400 | —- | C] () – C:\Windows\System32\pywintypes25.dll
[2007/08/04 21:24:40 | 000,327,680 | —- | C] () – C:\Windows\System32\pythoncom25.dll
[2007/05/14 05:28:10 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/12/13 23:01:36 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/12/13 23:01:36 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
[2006/11/02 05:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 05:47:37 | 000,348,112 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:33:01 | 000,604,264 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 03:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 03:33:01 | 000,103,964 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 03:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 03:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 01:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 01:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 00:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat

========== LOP Check ==========

[2011/01/06 21:59:53 | 000,000,000 | —D | M] – C:\Users\yeseniagut\AppData\Roaming\Amazon
[2011/02/01 00:49:11 | 000,000,000 | —D | M] – C:\Users\yeseniagut\AppData\Roaming\AVG
[2011/01/04 22:41:09 | 000,000,000 | —D | M] – C:\Users\yeseniagut\AppData\Roaming\AVG10
[2011/06/30 12:57:47 | 000,000,000 | —D | M] – C:\Users\yeseniagut\AppData\Roaming\Catalina Marketing Corp
[2010/03/24 22:12:25 | 000,000,000 | —D | M] – C:\Users\yeseniagut\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/06/01 22:55:42 | 000,000,000 | —D | M] – C:\Users\yeseniagut\AppData\Roaming\HBLite
[2011/01/03 15:44:19 | 000,000,000 | —D | M] – C:\Users\yeseniagut\AppData\Roaming\Jaran Nilsen
[2011/05/14 12:07:28 | 000,000,000 | —D | M] – C:\Users\yeseniagut\AppData\Roaming\OpenCandy
[2010/07/21 22:06:30 | 000,000,000 | —D | M] – C:\Users\yeseniagut\AppData\Roaming\PlayFirst
[2011/09/14 16:12:26 | 000,000,000 | —D | M] – C:\Users\yeseniagut\AppData\Roaming\Sammsoft
[2009/12/29 16:59:00 | 000,000,000 | —D | M] – C:\Users\yeseniagut\AppData\Roaming\Snapfish
[2009/12/15 21:12:56 | 000,000,000 | —D | M] – C:\Users\yeseniagut\AppData\Roaming\TeamViewer
[2009/12/13 22:11:09 | 000,000,000 | —D | M] – C:\Users\yeseniagut\AppData\Roaming\Template
[2010/06/26 22:41:16 | 000,000,000 | —D | M] – C:\Users\yeseniagut\AppData\Roaming\WildTangent
[2009/12/24 10:53:41 | 000,000,000 | —D | M] – C:\Users\yeseniagut\AppData\Roaming\WinBatch
[2011/09/19 19:07:22 | 000,032,560 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:63238B95
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:0B4227B4

< End of report >
OTL Extras logfile created on: 9/19/2011 11:44:16 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\yeseniagut\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.87 Gb Total Physical Memory | 1.81 Gb Available Physical Memory | 63.15% Memory free
5.97 Gb Paging File | 4.88 Gb Available in Paging File | 81.79% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 363.75 Gb Total Space | 295.66 Gb Free Space | 81.28% Space Free | Partition Type: NTFS
Drive D: | 8.85 Gb Total Space | 1.14 Gb Free Space | 12.82% Space Free | Partition Type: NTFS

Computer Name: YESENIAGUT-PC | User Name: yeseniagut | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – (EarthLink, Inc.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1C683374-66E5-4160-A4EB-A44911E26E4B}" = rport=138 | protocol=17 | dir=out | app=system |
"{1CC9E474-4A6E-4D78-BB76-0E1375328A9E}" = lport=137 | protocol=17 | dir=in | app=system |
"{40BA9D15-8D86-4B60-BB6B-7553A086073C}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{4C51CCAF-F82E-4AAD-BC2C-4D704521345D}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{5006F684-CABA-4020-8EEE-1A2FCFE61157}" = lport=139 | protocol=6 | dir=in | app=system |
"{65107C07-2253-4A1D-9325-373B8276B693}" = rport=137 | protocol=17 | dir=out | app=system |
"{7F1A5497-7DB8-4D45-83B6-47F1FF9A3577}" = lport=138 | protocol=17 | dir=in | app=system |
"{A60C6A84-F165-47DC-9492-74B11D7A9391}" = lport=445 | protocol=6 | dir=in | app=system |
"{AC1BF9CB-AE7F-47A3-882F-34EC93C9A13F}" = rport=445 | protocol=6 | dir=out | app=system |
"{DFE3FF8A-5C22-4865-990C-0A8F2AA4902C}" = rport=139 | protocol=6 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01C1F1F1-B79F-4C73-8F92-CAEFB54AF2AD}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{02AF93B0-FAA8-4059-9029-4DBD95F301EB}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{16B679DB-D1AD-46BC-A48B-FF0F26331937}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{19EC5448-B7E3-41C5-AE11-A65A67A14276}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{1F34ED51-7E79-46B6-BD86-F46ADA6096F4}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{2BE3A958-5D93-4F6B-B5AA-E93F6FFC4BB9}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{2EF2797C-C2F9-49D0-BD8A-9B622F9A7225}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{45E4AE03-B090-4624-A9B5-26F93628D41B}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{4AE50274-27D8-4966-87D5-6311AA99B027}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{7D5ADCEE-1E27-4789-AC1C-EDB3D509285E}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{7F877AC6-5F57-4F33-ABD4-410F2763855C}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{90823AD4-A2F1-486D-8EA7-9E2C01DE83B2}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{AD0E426E-AB2A-4962-AE9B-768675D72A51}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{B7C18973-9DD2-4B16-917D-D94BD39BEDAE}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{BA8C0E53-1F52-47C1-8971-885FFD426EE4}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{C9A02434-3456-43E1-9787-153C55F598B6}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{CBF53917-2CFE-4BF8-8EAA-BD1A70250085}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{E5CCA13D-C068-4DBF-B606-2F36AF4D5460}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{E7BCF2CF-8A5A-459D-A68B-F732A469DAB3}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{F50A491F-B3A8-4A42-BF20-C4B949CB3A5B}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{029B5901-1F27-4347-9923-E8ACC8F54E15}" = Snapfish Picture Mover
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{0A2C5854-557E-48C8-835A-3B9F074BDCAA}" = Python 2.5
"{0A47BAFF-D4FF-4BD3-96CA-02A22EA62722}" = HP Active Support Library
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{0DDA7620-4F8B-43B3-8828-CA5EE292FA3B}" = HP Total Care Advisor
"{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}" = Roxio Creator EasyArchive
"{16D0F2D2-242C-4885-BEF1-4B1655C141AE}" = Bing Bar
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{209CDA54-D390-46A2-A97C-7BF61734418D}" = WeatherBug Gadget
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216019FF}" = Java™ 6 Update 26
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Roxio Activation Module
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{40F7AED3-0C7D-4582-99F6-484A515C73F2}" = HP Easy Setup - Frontend
"{4571CC76-42C4-7D67-E024-0AEB166E1C6F}" = Acrobat.com
"{495B6040-801F-474C-ADB8-309F132CF5F9}" = iPhoneBrowser
"{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}" = HP Picasso Media Center Add-In
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{69995C7A-062A-4A90-A4DF-8C22895DF522}" = iTunes
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support
"{6D3DB611-D5E8-4E4B-8952-0D3F549F9CC6}" = HP Active Support Library 32 bit components
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{735619D4-B42A-437A-958C-199BFCAEDB38}" = Safari
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{779DECD7-E072-4B56-9B6B-BEB5973EEEB5}" = MobileMe Control Panel
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{824D3839-DAA1-4315-A822-7AE3E620E528}" = VideoToolkit01
"{8389382B-53BA-4A87-8854-91E3D80A5AC7}" = HP Photosmart Essential2.01
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{865A8951-8D9A-46CB-84A2-3D67BA38B923}" = EASEUS Deleted File Recovery 2.1.1
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{938B1CD7-7C60-491E-AA90-1F1888168240}" = Roxio MyDVD Basic v9
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5E289E-76BF-4251-9F3F-9B763F681AE0}" = HP Customer Experience Enhancements
"{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B6ADA0E4-9451-43EB-B86E-878AD9E68D4F}" = LightScribe [removed]
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator Basic v9
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F72E2DDC-3DB8-4190-A21D-63883D955FE7}" = PSSWCORE
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.10
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1" = Soft Data Fax Modem with SmartCP
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Coupon Printer for Windows5.0.0.1" = Coupon Printer for Windows
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Photosmart Essential" = HP Photosmart Essential 2.01
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NTFS Undelete_is1" = NTFS Undelete v0.93
"NVIDIA Drivers" = NVIDIA Drivers
"OsdMaestro" = HP On-Screen Cap/Num/Scroll Lock Indicator
"Recover My Files_is1" = Recover My Files
"Rhapsody" = Rhapsody
"VirtualLab 5 Client_is1" = VirtualLab Client 5.5.17
"WildTangent hp Master Uninstall" = My HP Games
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Mail" = att.net Internet Mail
"Yahoo! Search Defender" = Yahoo! Search Protection

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"UnityWebPlayer" = Unity Web Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/29/2011 11:53:13 PM | Computer Name = yeseniagut-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 6/29/2011 11:53:14 PM | Computer Name = yeseniagut-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 6/29/2011 11:53:14 PM | Computer Name = yeseniagut-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 6/29/2011 11:53:19 PM | Computer Name = yeseniagut-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 6/29/2011 11:53:19 PM | Computer Name = yeseniagut-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 6/30/2011 4:07:57 PM | Computer Name = yeseniagut-PC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 9.0.8112.16421, time stamp
0x4d76255d, faulting module msvcrt.dll, version 7.0.6002.18005, time stamp 0x49e0379e,
exception code 0x40000015, fault offset 0x00052fcb, process id 0x730, application
start time 0x01cc3760bd0feb65.

Error - 6/30/2011 5:21:33 PM | Computer Name = yeseniagut-PC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 9.0.8112.16421, time stamp
0x4d76255d, faulting module ntdll.dll, version 6.0.6002.18327, time stamp 0x4cb73436,
exception code 0xc0000005, fault offset 0x0003969e, process id 0xf98, application
start time 0x01cc37523cbc34e5.

Error - 7/3/2011 4:37:10 AM | Computer Name = yeseniagut-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 7/3/2011 4:37:10 AM | Computer Name = yeseniagut-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1014

Error - 7/3/2011 4:37:10 AM | Computer Name = yeseniagut-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1014

[ OSession Events ]
Error - 4/7/2010 11:27:39 PM | Computer Name = yeseniagut-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 0
seconds with 0 seconds of active time. This session ended with a crash.

Error - 4/7/2010 11:27:57 PM | Computer Name = yeseniagut-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 0
seconds with 0 seconds of active time. This session ended with a crash.

Error - 11/14/2010 6:51:16 PM | Computer Name = yeseniagut-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 12482
seconds with 1800 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 9/18/2011 4:59:56 PM | Computer Name = yeseniagut-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 9/18/2011 4:59:56 PM | Computer Name = yeseniagut-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 9/18/2011 10:41:01 PM | Computer Name = yeseniagut-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 9/18/2011 10:41:01 PM | Computer Name = yeseniagut-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 9/19/2011 5:58:03 PM | Computer Name = yeseniagut-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 9/19/2011 5:58:03 PM | Computer Name = yeseniagut-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 9/19/2011 9:09:31 PM | Computer Name = yeseniagut-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 9/19/2011 9:09:31 PM | Computer Name = yeseniagut-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 9/19/2011 11:51:07 PM | Computer Name = yeseniagut-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 9/19/2011 11:51:07 PM | Computer Name = yeseniagut-PC | Source = Service Control Manager | ID = 7026
Description =


< End of report >
Hi yesi,

I notice from your logs that you have run ComboFix previously? Do you have the log that was created? It can be found at C:\ComboFix.txt. If you can find it please post that into your next reply. :)
———-


Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HBLite\bin\11.0.363.0\firefox\extensions
    [2011/05/14 16:13:09 | 000,002,047 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\fcmdSrch.xml
    O15 - HKCU\..Trusted Domains: $talisma_url$ ([]https in Trusted sites)
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • There will be a log created after the fix that I will need and then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
———-

In your next reply please post the logs created by ComboFix if you can find it and both of the log created by OTL. :)
ComboFix 11-05-17.03 - yeseniagut 05/18/2011 10:54:38.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2942.1916 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\facemoods.com
c:\program files\facemoods.com\facemoods\1.4.17.8\bh\facemoods.dll
c:\program files\facemoods.com\facemoods\1.4.17.8\dealply.crx
c:\program files\facemoods.com\facemoods\1.4.17.8\facemoods.crx
c:\program files\facemoods.com\facemoods\1.4.17.8\facemoods.png
c:\program files\facemoods.com\facemoods\1.4.17.8\facemoodsApp.dll
c:\program files\facemoods.com\facemoods\1.4.17.8\facemoodsEng.dll
c:\program files\facemoods.com\facemoods\1.4.17.8\facemoodssrv.exe
c:\program files\facemoods.com\facemoods\1.4.17.8\facemoodsTlbr.dll
c:\program files\facemoods.com\facemoods\1.4.17.8\uninstall.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-04-18 to 2011-05-18 )))))))))))))))))))))))))))))))
.
.
2011-05-18 18:03 . 2011-05-18 18:03 ——– d—–w- c:\users\yeseniagut\AppData\Local\temp
2011-05-18 18:03 . 2011-05-18 18:03 ——– d—–w- c:\users\Public\AppData\Local\temp
2011-05-18 18:03 . 2011-05-18 18:03 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-05-18 16:45 . 2011-05-18 16:45 28752 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B012A46F-19CC-4E47-AD65-8799FF173D7E}\MpKsl9823cd48.sys
2011-05-18 03:13 . 2011-04-11 07:04 7071056 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B012A46F-19CC-4E47-AD65-8799FF173D7E}\mpengine.dll
2011-05-14 19:08 . 2011-05-14 19:08 ——– d—–w- c:\users\yeseniagut\AppData\Roaming\Sammsoft
2011-05-14 19:08 . 2011-05-14 19:08 ——– d—–w- c:\program files\ARO 2011
2011-05-14 19:07 . 2011-05-15 07:22 ——– d—–w- c:\users\yeseniagut\AppData\Local\OpenCandy
2011-05-14 19:07 . 2011-05-14 19:07 ——– d—–w- c:\users\yeseniagut\AppData\Roaming\OpenCandy
2011-05-11 04:29 . 2011-04-07 12:01 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-04-28 00:00 . 2011-03-03 15:40 28672 —-a-w- c:\windows\system32\Apphlpdm.dll
2011-04-28 00:00 . 2011-03-03 13:35 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-04-27 23:59 . 2011-03-12 21:55 876032 —-a-w- c:\windows\system32\XpsPrint.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-11 07:04 . 2011-03-14 01:54 7071056 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-03-14 01:54 . 2011-04-05 17:51 439632 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3876857B-48F8-4A57-A77F-DB3AA1466880}\gapaengine.dll
2011-03-14 01:54 . 2011-03-28 00:31 439632 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2011-03-10 17:03 . 2011-04-14 21:21 1162240 —-a-w- c:\windows\system32\mfc42u.dll
2011-03-10 17:03 . 2011-04-14 21:21 1136640 —-a-w- c:\windows\system32\mfc42.dll
2011-03-03 15:42 . 2011-04-14 21:21 739328 —-a-w- c:\windows\system32\inetcomm.dll
2011-03-03 15:40 . 2011-04-28 00:00 173056 —-a-w- c:\windows\apppatch\AcXtrnal.dll
2011-03-03 15:40 . 2011-04-28 00:00 542720 —-a-w- c:\windows\apppatch\AcLayers.dll
2011-03-03 15:40 . 2011-04-28 00:00 458752 —-a-w- c:\windows\apppatch\AcSpecfc.dll
2011-03-03 15:40 . 2011-04-28 00:00 2159616 —-a-w- c:\windows\apppatch\AcGenral.dll
2011-03-03 13:25 . 2011-04-14 21:21 2041856 —-a-w- c:\windows\system32\win32k.sys
2011-03-02 15:44 . 2011-04-14 21:21 86528 —-a-w- c:\windows\system32\dnsrslvr.dll
2011-02-22 14:13 . 2011-03-23 00:48 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-02-22 13:33 . 2011-03-23 00:48 1068544 —-a-w- c:\windows\system32\DWrite.dll
2011-02-22 13:33 . 2011-03-23 00:48 797696 —-a-w- c:\windows\system32\FntCache.dll
2011-02-22 13:24 . 2011-04-14 21:21 213504 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-02-22 13:24 . 2011-04-14 21:21 79360 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-02-22 13:23 . 2011-04-14 21:21 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-22 13:23 . 2011-04-14 21:21 69632 —-a-w- c:\windows\system32\drivers\bowser.sys
2011-02-19 00:36 . 2011-02-19 00:36 41984 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2011-02-19 00:36 . 2011-02-19 00:36 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll
2011-02-18 14:03 . 2011-04-14 21:21 305152 —-a-w- c:\windows\system32\drivers\srv.sys
2011-02-18 14:03 . 2011-04-14 21:21 146432 —-a-w- c:\windows\system32\drivers\srv2.sys
2011-02-18 14:03 . 2011-04-14 21:21 102400 —-a-w- c:\windows\system32\drivers\srvnet.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-02-03 39408]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-02-18 2423752]
"AROReminder"="c:\program files\ARO 2011\ARO.exe" [2011-01-25 2312048]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-05-24 71176]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-22 13539872]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-22 92704]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_01\bin\jusched.exe" [2007-04-07 132760]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-30 421888]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-12-15 47904]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-07 421160]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-05-11 10:06 40048 —-a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EKIJ5000StatusMonitor]
2009-07-31 22:00 1626112 —-a-w- c:\windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-03-07 23:33 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-30 01:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2008-01-15 19:26 4874240 —-a-w- c:\windows\RtHDVCpl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 135664]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-02-15 183560]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 135664]
R3 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\idsdefs\20070108.003\IDSvix86.sys [2006-12-27 212280]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 MpKsl9823cd48;MpKsl9823cd48;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B012A46F-19CC-4E47-AD65-8799FF173D7E}\MpKsl9823cd48.sys [2011-05-18 28752]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-25 43392]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-25 54144]
S3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSL9823CD48
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 21:17]
.
2011-05-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 21:17]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Pavilion&pf=desktop
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
Trusted Zone: $talisma_url$
DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A} - hxxp://www.shockwave.com/content/ghostfrenzy/sis/axhost.cab
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{64182481-4F71-486b-A045-B233BD0DA8FC} - c:\program files\facemoods.com\facemoods\1.4.17.8\bh\facemoods.dll
Toolbar-{DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - c:\program files\facemoods.com\facemoods\1.4.17.8\facemoodsTlbr.dll
HKLM-Run-facemoods - c:\program files\facemoods.com\facemoods\1.4.17.8\facemoodssrv.exe
AddRemove-facemoods - c:\program files\facemoods.com\facemoods\1.4.17.8\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-18 11:03
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-05-18 11:04:54
ComboFix-quarantined-files.txt 2011-05-18 18:04
ComboFix2.txt 2011-03-14 01:02
.
Pre-Run: 284,083,351,552 bytes free
Post-Run: 284,113,956,864 bytes free
.
- - End Of File - - C942875411E63310B22A825C5D31E13E
All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== File HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HBLite\bin\11.0.363.0\firefox\extensions not found. C:\Program Files\Mozilla Firefox\searchplugins\fcmdSrch.xml moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\$talisma_url$\ deleted successfully. ========== COMMANDS ========== C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->Flash cache emptied: 41620 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: kids ->Temp folder emptied: 128297642 bytes ->Temporary Internet Files folder emptied: 342179167 bytes ->Java cache emptied: 28505 bytes ->Flash cache emptied: 172704 bytes User: Public ->Temp folder emptied: 0 bytes User: yeseniagut ->Temp folder emptied: 117945727 bytes ->Temporary Internet Files folder emptied: 1259622280 bytes ->Java cache emptied: 2878729 bytes ->Apple Safari cache emptied: 0 bytes ->Flash cache emptied: 2877612 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 72706695 bytes RecycleBin emptied: 609184 bytes Total Files Cleaned = 1,838.00 mb OTL by OldTimer - Version 3.2.29.1 log created on 09202011_174103 Files\Folders moved on Reboot… C:\Users\yeseniagut\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully. File\Folder C:\Users\yeseniagut\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{4A82C859-34DE-4C81-8F45-65F15EC413CB}.tmp not found! File\Folder C:\Users\yeseniagut\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{898B79BB-5084-4343-A88E-3B60F0045E5E}.tmp not found! C:\Users\yeseniagut\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VCOMMRYL\like[1].htm moved successfully. C:\Users\yeseniagut\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JF3EV3CU\search[1].htm moved successfully. C:\Users\yeseniagut\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CWCM86TV\iframe[1].htm moved successfully. Registry entries deleted on Reboot… ;)
Hi yesi, Thank you for the old ComboFix log and the OTL fix log. :) Were you able to get a new OTL scan yet? When you do please post that into your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI