This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google search redirect

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
When I click on a link from a google search results list it will often be re-directed to some other site. Sometimes the sites appear benign, but other times I get a warning from McAfee saying that I shouldn't go there. Thanks for your help.

Here is the log file from Hijackthis:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:36:56 AM, on 10/19/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\mfevtps.exe
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Norton Ghost\Agent\VProTray.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\Ahead\Ahead\data\Xtras\mssysmgr.exe
C:\Program Files\Free Download Manager\fdm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Garmin\gStart.exe
C:\Program Files\Common Files\Intuit\DataProtect\IntuitDataProtect.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Intuit\QuickBooks 2008\QBW32.EXE
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110629120626.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Norton Ghost 14.0] "C:\Program Files\Norton Ghost\Agent\VProTray.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\Ahead\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [gStart] C:\Program Files\Garmin\gStart.exe
O4 - HKCU\..\Run: [Jvenusasiyu] rundll32.exe "C:\WINDOWS\nenp6g.dll",Startup
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Intuit Data Protect.lnk = C:\Program Files\Common Files\Intuit\DataProtect\IntuitDataProtect.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: QuickBooks_Standard_21.lnk = C:\Program Files\Intuit\QuickBooks 2008\QBW32.EXE
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1315287898734
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file:///C:/Program%20Files/Autodesk/MDT6/AcDcToday.ocx
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file:///C:/Program%20Files/Autodesk/MDT6/InstBanr.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file:///C:/Program%20Files/Autodesk/MDT6/InstFred.ocx
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file:///C:/Program%20Files/Autodesk/MDT6/AcPreview.ocx
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: intu-help-qb4 - {ACE22922-D07C-4860-B51B-8CF472FEC2CB} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\GEST\GSvr.exe
O23 - Service: Google Update Service (gupdate1c9c88d466b165f) (gupdate1c9c88d466b165f) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\WINDOWS\system32\mfevtps.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: NVIDIA Performance Driver Service - Unknown owner - C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: QBIDPService (QBVSS) - Intuit Inc. - C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: Sprint RcAppSvc (SprintRcAppSvc) - SmithMicro Inc. - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe
O23 - Service: Symantec RemoteAssist - Unknown owner - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe (file missing)
O23 - Service: SymSnapService - Symantec - C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe

–
End of file - 16269 bytes
Hello dmkeng and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I am looking at your log now and will reply with instructions shortly

Satchfan
Hello again Dmkeng

I see that you asked for help recently but didn’t reply when a Malware Team member offered to help.

We are all doing this on a voluntary basis and also have day jobs and families, so please be gracious enough to reply even if it is only to say that you no longer require help. Thanks :)

===========================================

There is evidence of a Trojan on your computer so we need some more scans which will look deeper.

Run HijackThis

Open HijackThis and click Do a system scan only.

Place a check mark next to:

O4 - HKCU\..\Run: [Jvenusasiyu] rundll32.exe "C:\WINDOWS\nenp6g.dll",Startup

Close all windows except for HijackThis and click Fix checked.

===========================================

Download the GMER Rootkit Scanner

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done, click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===========================================

Run Malwarebytes’ Anti-Malware

I noticed that you had MBAM on your system when you previously ran OTL: if you no longer have it, you can download it from here:
  • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
  • once it is updated, click on “Scanner” tab, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Logs to include in next post:

Gmer.txt
Mbam.txt


Thanks

Satchfan
Hi Satchfan, First of all thank you very much for your generous help and support. You are correct that I posted this same problem a few weeks ago. I apologize for not responding then. I had a family emergency and was out of town and away from my computer for a few weeks. I have followed your instructions, removed the nenp6g.dll, run the requested scans and attached them to this reply. Please tell me what my next steps are. Thanks again. David
Hi Dmkeng

I apologize for not responding then. I had a family emergency and was out of town and away from my computer for a few weeks

Thanks for explaining. I hope all is well now.


We need to run something that’ll take a deeper look.

Download and run ComboFix

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, as they may otherwise interfere with our tools. See here for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    [external image: Posted Image]


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Please do not attach this or any other logs, just copy and paste them in the reply.

Thanks

Satchfan
ComboFix 11-10-23.02 - David Kramer 10/23/2011 13:53:28.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2532 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\tmp505.tmp
c:\documents and settings\All Users\Application Data\tmp514.tmp
c:\documents and settings\All Users\Application Data\tmp551.tmp
c:\documents and settings\All Users\Application Data\tmp8F.tmp
c:\documents and settings\All Users\Application Data\tmp97.tmp
c:\documents and settings\All Users\Application Data\tmp9C.tmp
c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
c:\documents and settings\David Kramer\Application Data\.#
c:\documents and settings\David Kramer\Application Data\3406.594
c:\documents and settings\David Kramer\Error.log
c:\documents and settings\David Kramer\g2mdlhlpx.exe
c:\documents and settings\David Kramer\Local Settings\Application Data\{3134FF42-48F7-4DC4-A483-1ADBBC3C1EF2}
c:\documents and settings\David Kramer\Local Settings\Application Data\{3134FF42-48F7-4DC4-A483-1ADBBC3C1EF2}\chrome.manifest
c:\documents and settings\David Kramer\Local Settings\Application Data\{3134FF42-48F7-4DC4-A483-1ADBBC3C1EF2}\chrome\content\_cfg.js
c:\documents and settings\David Kramer\Local Settings\Application Data\{3134FF42-48F7-4DC4-A483-1ADBBC3C1EF2}\chrome\content\overlay.xul
c:\documents and settings\David Kramer\Local Settings\Application Data\{3134FF42-48F7-4DC4-A483-1ADBBC3C1EF2}\install.rdf
c:\documents and settings\David Kramer\Local Settings\Temporary Internet Files\viewChanges.html
c:\documents and settings\David Kramer\WINDOWS
c:\documents and settings\David\Application Data\3406.594
c:\documents and settings\David\Local Settings\Application Data\{074E8F8B-5C9D-489B-A98C-3F650071A39D}
c:\documents and settings\David\Local Settings\Application Data\{074E8F8B-5C9D-489B-A98C-3F650071A39D}\chrome.manifest
c:\documents and settings\David\Local Settings\Application Data\{074E8F8B-5C9D-489B-A98C-3F650071A39D}\chrome\content\_cfg.js
c:\documents and settings\David\Local Settings\Application Data\{074E8F8B-5C9D-489B-A98C-3F650071A39D}\chrome\content\overlay.xul
c:\documents and settings\David\Local Settings\Application Data\{074E8F8B-5C9D-489B-A98C-3F650071A39D}\install.rdf
c:\program files\messenger\msmsgsin.exe
c:\program files\msn\msncorefiles\custdial.dll
c:\program files\msn\msncorefiles\logonmgr.dll
c:\windows\dasetup.log
c:\windows\help\tours\htmltour\unlock_playing.htm
c:\windows\system32\prsgrc.dll
c:\windows\system32\qxcyfuj.dll
c:\windows\system32\zlibwapi.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-09-23 to 2011-10-23 )))))))))))))))))))))))))))))))
.
.
2011-10-03 20:54 . 2011-10-03 21:01 ——– d—–w- c:\documents and settings\David Kramer\Application Data\TeamViewer
2011-10-03 20:54 . 2011-10-03 20:57 ——– d—–w- c:\program files\TeamViewer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-14 23:59 . 2011-05-22 06:12 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-26 18:41 . 2008-07-30 02:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 18:41 . 2001-08-23 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 18:41 . 2001-08-23 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-17 04:03 . 2011-09-17 04:03 388096 —-a-r- c:\documents and settings\David Kramer\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-09-09 09:12 . 2001-08-23 12:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-06 13:20 . 2001-08-23 12:00 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-09-06 06:05 . 2011-09-06 05:27 2377696 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\VisualStudio\10.0\1033\ResourceCache.dll
2011-09-06 05:27 . 2011-09-06 05:27 18368 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\VSA\9.0\1033\ResourceCache.dll
2011-09-01 00:00 . 2011-08-26 18:14 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-08-26 17:47 . 2011-08-26 17:47 388096 —-a-r- c:\documents and settings\David\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-08-22 23:48 . 2001-08-23 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48 . 2001-08-23 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48 . 2001-08-23 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56 . 2008-10-04 23:57 385024 ——w- c:\windows\system32\html.iec
2011-08-17 13:49 . 2001-08-23 12:00 138496 —-a-w- c:\windows\system32\drivers\afd.sys
2010-09-14 17:14 . 2009-01-15 15:56 28488 —-a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
2010-09-14 17:14 . 2009-01-15 15:56 185240 —-a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
2010-09-14 17:14 . 2009-01-15 15:56 46408 —-a-w- c:\program files\mozilla firefox\plugins\atmccli.dll
2009-01-15 15:56 . 2009-01-15 15:56 98704 ——w- c:\program files\mozilla firefox\plugins\ieatgpc.dll
2011-09-30 20:46 . 2011-05-07 22:13 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2008-06-30 21:44 . 2008-12-04 18:46 324976 ——w- c:\program files\mozilla firefox\components\coFFPlgn.dll
2011-04-14 21:01 . 2011-06-29 19:06 24376 —-a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-18 68856]
"PhotoShow Deluxe Media Manager"="c:\progra~1\Ahead\Ahead\data\Xtras\mssysmgr.exe" [2004-05-12 196608]
"Free Download Manager"="c:\program files\Free Download Manager\fdm.exe" [2008-05-21 2474031]
"gStart"="c:\program files\Garmin\gStart.exe" [2008-08-13 1891416]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 16857600]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"36X Raid Configurer"="c:\windows\system32\xRaidSetup.exe" [2007-08-29 1966080]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-05 13590528]
"nwiz"="nwiz.exe" [2008-11-05 1657376]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 4.0\apdproxy.exe" [2005-09-09 57344]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 40960]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2005-11-12 995328]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-11-05 86016]
"Norton Ghost 14.0"="c:\program files\Norton Ghost\Agent\VProTray.exe" [2009-08-04 2250088]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-06-04 564496]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-08-10 421888]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2011-06-14 1527128]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-06-28 1195408]
.
c:\documents and settings\David Kramer\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-10-5 113664]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Intuit Data Protect.lnk - c:\program files\Common Files\Intuit\DataProtect\IntuitDataProtect.exe [2011-3-1 5828952]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-11-4 805392]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2011-7-6 1156968]
QuickBooks_Standard_21.lnk - c:\program files\Intuit\QuickBooks 2008\QBW32.EXE [2011-7-6 1178984]
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2006-3-26 257752]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-9-11 525664]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-03-13 233472]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 10:42 72208 ——w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^David Kramer^Start Menu^Programs^Startup^iaxComm.lnk]
path=c:\documents and settings\David Kramer\Start Menu\Programs\Startup\iaxComm.lnk
backup=c:\windows\pss\iaxComm.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 10:43 69632 ——r- c:\windows\Alcmtr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-09-21 23:36 305440 ——w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RDVCHG]
2009-09-25 16:04 316672 —-a-w- c:\program files\Sprint\Sprint SmartView\RDVCHG.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-03-09 17:02 26100520 —-a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sprint SmartView]
2009-09-25 16:04 75008 —-a-w- c:\program files\Sprint\Sprint SmartView\SprintSV.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\GIGABYTE\\GEST\\run.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2008\\QBDBMgrN.exe"=
"c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"=
.
R0 firedrv;TI OHCI-1394 (intek);c:\windows\system32\drivers\firedrv.sys [1/29/2010 2:04 PM 106312]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [6/29/2011 12:06 PM 84200]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [12/22/2010 12:31 AM 21992]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [6/29/2011 12:06 PM 271480]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [6/29/2011 12:06 PM 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [6/29/2011 12:06 PM 271480]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [6/29/2011 12:06 PM 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [6/29/2011 11:39 AM 148520]
R2 NVIDIA Performance Driver Service;NVIDIA Performance Driver Service;c:\program files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe [10/28/2008 8:44 AM 3575808]
R2 QBVSS;QBIDPService;c:\program files\Common Files\Intuit\DataProtect\QBIDPService.exe [6/30/2011 1:25 PM 1248256]
R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [8/23/2001 5:00 AM 5120]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [6/29/2011 12:06 PM 56064]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [6/29/2011 12:06 PM 314088]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [6/29/2011 12:06 PM 88736]
R3 SymSnapService;SymSnapService;c:\program files\Norton Ghost\Shared\Drivers\SymSnapService.exe [12/20/2007 6:13 PM 1562096]
R3 usbsnoop;USB Snoopy Filter Driver;c:\windows\system32\drivers\UsbSnoop.sys [1/26/2009 5:44 PM 182200]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S2 gupdate1c9c88d466b165f;Google Update Service (gupdate1c9c88d466b165f);c:\program files\Google\Update\GoogleUpdate.exe [4/28/2009 10:42 PM 133104]
S3 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\GEST\GSvr.exe [12/22/2008 1:01 PM 55816]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [4/28/2009 10:42 PM 133104]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 5:49 AM 227232]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [6/29/2011 12:06 PM 88736]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [6/29/2011 12:06 PM 84488]
S3 NCBULK;MPLAB HS USB client driver;c:\windows\system32\drivers\RealICEBulk.SYS [4/5/2007 12:08 PM 12160]
S3 silabenm;Silicon Labs CP210x USB to UART Bridge Serial Port Enumerator Driver;c:\windows\system32\drivers\silabenm.sys [1/27/2011 8:18 PM 47176]
S3 silabser;Silicon Labs CP210x USB to UART Bridge Driver;c:\windows\system32\drivers\silabser.sys [1/27/2011 8:18 PM 58496]
S3 sy04bus;SANYO USB Composite Device SY04 driver (WDM);c:\windows\system32\drivers\sy04bus.sys [4/30/2010 8:36 AM 83328]
S3 sy04mdfl;SANYO USB Modem SY04 Filter;c:\windows\system32\drivers\sy04mdfl.sys [4/30/2010 8:36 AM 14848]
S3 sy04mdm;SANYO USB Modem SY04 Drivers;c:\windows\system32\drivers\sy04mdm.sys [4/30/2010 8:36 AM 109824]
S3 sy04serd;SANYO USB Modem SY04 Diagnostic Serial Port (WDM);c:\windows\system32\drivers\sy04serd.sys [4/30/2010 8:36 AM 89856]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [7/22/2009 8:08 PM 47128]
S4 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [3/30/2009 3:09 AM 239336]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [3/30/2009 3:23 AM 366936]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-23 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-05 04:49]
.
2011-10-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-29 05:42]
.
2011-10-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-29 05:42]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local;
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download all with Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
LSP: bmnet.dll
TCP: DhcpNameServer = 192.168.0.1 192.168.0.2
FF - ProfilePath - c:\documents and settings\David Kramer\Application Data\Mozilla\Firefox\Profiles\my4cn7gd.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 58808
FF - prefs.js: network.proxy.type - 0
.
.
——- File Associations ——-
.
.scr=AutoCADScriptFile
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-Ttudiduba - c:\windows\abigizoyowohow.dll
MSConfigStartUp-tvncontrol - c:\program files\TightVNC\tvnserver.exe
AddRemove-Diff Doc_is1 - c:\program files\Softinterface
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-23 15:37
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1428)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
- - - - - - - > 'lsass.exe'(1484)
c:\windows\system32\bmnet.dll
.
- - - - - - - > 'explorer.exe'(11816)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\windows\system32\nview.dll
c:\progra~1\mcafee\SITEAD~1\saHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\program files\Norton Ghost\Agent\VProSvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
c:\windows\System32\msdtc.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\rundll32.exe
c:\windows\system32\RUNDLL32.EXE
c:\progra~1\mcafee\VIRUSS~1\mcvsshld.exe
c:\program files\Windows Desktop Search\WindowsSearchIndexer.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\windows\system32\wscntfy.exe
c:\progra~1\mcafee\VIRUSS~1\mcvsmap.exe
.
**************************************************************************
.
Completion time: 2011-10-23 15:41:10 - machine was rebooted
ComboFix-quarantined-files.txt 2011-10-23 22:41
.
Pre-Run: 13,231,120,384 bytes free
Post-Run: 19,109,847,040 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 527C586AD1823E530299AAEB79F62823
Hi dmkeng

That looks better but I’d like another look with OTL.

Run OTL

download OTL and save it to your desktop.
  • double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted
  • when the window appears, underneath Output at the top change it to Minimal Output
  • check the boxes beside LOP Check and Purity Check
  • click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long
  • when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
Note: These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them with your next reply. You may need two posts to fit them both in.

Can you tell me how your computer is running

Satchfan
Yes, it does seem much better. My google search redirects are gone. Thanks so much for your help.

When OTL completed it opened OTL.txt, but there doesn't appear to be any file called Extras.txt anywhere on my hard drive.

Here is OTL.txt:

OTL logfile created on: 10/24/2011 8:49:02 AM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\David Kramer\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.32 Gb Available Physical Memory | 71.34% Memory free
5.09 Gb Paging File | 4.07 Gb Available in Paging File | 79.90% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 58.59 Gb Total Space | 18.34 Gb Free Space | 31.30% Space Free | Partition Type: NTFS
Drive E: | 220.86 Gb Total Space | 140.78 Gb Free Space | 63.74% Space Free | Partition Type: NTFS
Drive K: | 465.76 Gb Total Space | 203.62 Gb Free Space | 43.72% Space Free | Partition Type: NTFS

Computer Name: DMKENG | User Name: David Kramer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\David Kramer\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit Inc.)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
PRC - C:\Program Files\Intuit\QuickBooks 2008\QBW32.EXE (Intuit Inc.)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe (Intuit Inc.)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files\Norton Ghost\Agent\VProSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Norton Ghost\Agent\VProTray.exe (Symantec Corporation)
PRC - C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe (Symantec)
PRC - C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe ()
PRC - C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
PRC - C:\Program Files\Garmin\gStart.exe (GARMIN Corp.)
PRC - C:\Program Files\Common Files\Logishrd\LComMgr\Communications_Helper.exe ()
PRC - C:\Program Files\Free Download Manager\fdm.exe (FreeDownloadManager.ORG)
PRC - C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\Logishrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe (Logitech, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe (Microsoft Corporation)
PRC - C:\Program Files\Brother\ControlCenter2\brctrcen.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe ()
PRC - C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Ahead\Ahead\data\Xtras\mssysmgr.exe ()


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\ceadaf3b3d017c7a1ef10a06f8009f6f\System.ServiceModel.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\abef85f2fb8ba830eda73e2d12e8d41e\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Services\6303e256d2ac0843c3e4c24172c90544\System.Web.Services.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\bce0720436dc6cb76006377f295ea365\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\71a2ae9ad561a62181cbd9fb11e9de7a\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\c10bea3c4bb7ef654651141bf9419090\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\054488924fcc579cce9fa0209dafe28b\PresentationFramework.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationCore\b2f0318713eca304eaa9d86fc17edb96\PresentationCore.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsBase\1adc4ae51a5ac63e896a1402749ca495\WindowsBase.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll ()
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files\Common Files\Intuit\DataProtect\IntuitDataProtect.XmlSerializers.dll ()
MOD - C:\Program Files\Intuit\QuickBooks 2008\QBMAPILibrary.dll ()
MOD - C:\Program Files\Intuit\QuickBooks 2008\QBCompressor.DLL ()
MOD - C:\Program Files\Intuit\QuickBooks 2008\mbpopup.dll ()
MOD - C:\Program Files\Intuit\QuickBooks 2008\boost_regex-vc90-mt-p-1_33.dll ()
MOD - C:\Program Files\Intuit\QuickBooks 2008\boost_serialization-vc90-mt-p-1_33.dll ()
MOD - C:\Program Files\Intuit\QuickBooks 2008\BackupLib.dll ()
MOD - C:\WINDOWS\system32\nview.dll ()
MOD - C:\WINDOWS\system32\nvshell.dll ()
MOD - C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe ()
MOD - C:\WINDOWS\system32\pdf995mon.dll ()
MOD - C:\Program Files\Common Files\Logishrd\LComMgr\Communications_Helper.exe ()
MOD - C:\Program Files\Common Files\Logishrd\LVCOMSER\LVCSPS.dll ()
MOD - C:\Program Files\Free Download Manager\FUM\fumcore.dll ()
MOD - C:\WINDOWS\system32\Primomonnt.dll ()
MOD - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe ()
MOD - C:\Program Files\Intuit\QuickBooks 2008\zlib1.dll ()
MOD - C:\Program Files\Ahead\Ahead\data\Xtras\mssysmgr.exe ()
MOD - C:\WINDOWS\system32\BrMuSNMP.dll ()


========== Win32 Services (SafeList) ==========

SRV - (Symantec RemoteAssist) – File not found
SRV - (QBCFMonitorService) – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (QBVSS) – C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe (Intuit Inc.)
SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (mfevtp) – C:\WINDOWS\system32\mfevtps.exe (McAfee, Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (MSK80Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McProxy) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (SprintRcAppSvc) – C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe (SmithMicro Inc.)
SRV - (Norton Ghost) – C:\Program Files\Norton Ghost\Agent\VProSvc.exe (Symantec Corporation)
SRV - (QBFCService) – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (SymSnapService) – C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe (Symantec)
SRV - (NVIDIA Performance Driver Service) – C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe ()
SRV - (SolidWorks Licensing Service) – C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe (SolidWorks)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (LVCOMSer) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (LBTServ) – C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (GEST Service) – C:\Program Files\GIGABYTE\GEST\GSvr.exe ()
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (AdobeActiveFileMonitor4.0) – C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe ()


========== Driver Services (SafeList) ==========

DRV - (mfefirek) – C:\WINDOWS\system32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfendiskmp) – C:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mfendisk) – C:\WINDOWS\system32\drivers\mfendisk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\WINDOWS\system32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfetdi2k) – C:\WINDOWS\system32\drivers\mfetdi2k.sys (McAfee, Inc.)
DRV - (cfwids) – C:\WINDOWS\system32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (silabser) – C:\WINDOWS\system32\drivers\silabser.sys (Silicon Laboratories)
DRV - (silabenm) – C:\WINDOWS\system32\drivers\silabenm.sys (Silicon Laboratories)
DRV - (cpuz135) – C:\WINDOWS\system32\drivers\cpuz135_x32.sys (CPUID)
DRV - (truecrypt) – C:\WINDOWS\system32\drivers\truecrypt.sys (TrueCrypt Foundation)
DRV - (gdrv) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (mfesmfk) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (PCTINDIS5) – C:\WINDOWS\system32\PCTINDIS5.sys (Smith Micro Inc.)
DRV - (swmsflt) – C:\WINDOWS\System32\drivers\swmsflt.sys ()
DRV - (tcpipBM) – C:\WINDOWS\System32\drivers\tcpipBM.sys (Bytemobile, Inc.)
DRV - (NWADI) – C:\WINDOWS\system32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (PCASp50) – C:\WINDOWS\system32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (sy04mdm) – C:\WINDOWS\system32\drivers\sy04mdm.sys (MCCI)
DRV - (sy04serd) SANYO USB Modem SY04 Diagnostic Serial Port (WDM) – C:\WINDOWS\system32\drivers\sy04serd.sys (MCCI)
DRV - (sy04bus) SANYO USB Composite Device SY04 driver (WDM) – C:\WINDOWS\system32\drivers\sy04bus.sys (MCCI)
DRV - (sy04mdfl) – C:\WINDOWS\system32\drivers\sy04mdfl.sys (MCCI Corporation)
DRV - (symsnap) – C:\WINDOWS\system32\DRIVERS\symsnap.sys (StorageCraft)
DRV - (firedrv) TI OHCI-1394 (intek) – C:\WINDOWS\system32\DRIVERS\firedrv.sys (intek (Darmstadt))
DRV - (RsFx0103) – C:\WINDOWS\system32\drivers\RsFx0103.sys (Microsoft Corporation)
DRV - (usbsnoop) – C:\WINDOWS\system32\drivers\UsbSnoop.sys ()
DRV - (v2imount) – C:\WINDOWS\system32\drivers\v2imount.sys (Symantec Corporation)
DRV - (Sentinel) – C:\WINDOWS\System32\Drivers\SENTINEL.SYS (SafeNet, Inc.)
DRV - (SNTNLUSB) – C:\WINDOWS\system32\drivers\SNTNLUSB.SYS (SafeNet, Inc.)
DRV - (FilterService) – C:\WINDOWS\system32\drivers\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUVC) Logitech QuickCam S5500(UVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (LMouFilt) – C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (WimFltr) – C:\WINDOWS\system32\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (VProEventMonitor) – C:\WINDOWS\system32\drivers\vproeventmonitor.sys (Symantec Corporation)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (ET5Drv) – C:\WINDOWS\system32\drivers\ET5Drv.sys (Windows ® 2000 DDK provider)
DRV - (JRAID) – C:\WINDOWS\system32\DRIVERS\jraid.sys (JMicron Technology Corp.)
DRV - (NCBULK) – C:\WINDOWS\system32\drivers\RealICEBulk.SYS (PLX Technology, Inc. (visit www.PlxTech.com))
DRV - (MaVctrl) – C:\WINDOWS\system32\drivers\MaVc2K.sys (Mobile Action Technology Inc.)
DRV - (speedfan) – C:\WINDOWS\system32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (FTSER2K) – C:\WINDOWS\system32\drivers\ftser2k.sys (FTDI Ltd.)
DRV - (FTDIBUS) – C:\WINDOWS\system32\drivers\ftdibus.sys (FTDI Ltd.)
DRV - (giveio) – C:\WINDOWS\system32\giveio.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Secure Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.3.2
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=mcafee&p;="
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 58808
FF - prefs.js..network.proxy.type: 0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\David Kramer\Application Data\Move Networks\plugins\npqmp071701000002.dll (Move Networks)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\David Kramer\Application Data\Move Networks\plugins\npqmp071701000002.dll (Move Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2011/09/26 18:22:04 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/30 13:46:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/13 15:10:37 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Documents and Settings\David Kramer\Application Data\Move Networks [2009/11/28 16:27:55 | 000,000,000 | —D | M]

[2008/10/04 19:17:20 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\David Kramer\Application Data\Mozilla\Extensions
[2011/05/07 14:41:50 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\David Kramer\Application Data\Mozilla\Firefox\Profiles\my4cn7gd.default\extensions
[2010/04/27 12:52:17 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\David Kramer\Application Data\Mozilla\Firefox\Profiles\my4cn7gd.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/10/19 16:44:54 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\David Kramer\Application Data\Mozilla\Firefox\Profiles\my4cn7gd.default_backup\extensions
[2011/05/07 14:41:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/03/26 13:12:07 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/04/27 09:27:23 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/10 17:08:07 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/01 07:26:27 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/09/26 18:22:04 | 000,000,000 | —D | M] (McAfee SiteAdvisor) – C:\PROGRAM FILES\MCAFEE\SITEADVISOR
[2011/09/30 13:46:00 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2008/06/30 14:44:08 | 000,324,976 | —- | M] (Symantec Corporation) – C:\Program Files\mozilla firefox\components\coFFPlgn.dll
[2011/04/14 14:01:38 | 000,024,376 | —- | M] (McAfee, Inc.) – C:\Program Files\mozilla firefox\components\Scriptff.dll
[2010/09/14 10:14:03 | 000,028,488 | —- | M] (WebEx Communications, Inc) – C:\Program Files\mozilla firefox\plugins\atgpcdec.dll
[2010/09/14 10:14:04 | 000,185,240 | —- | M] (WebEx Communications, Inc) – C:\Program Files\mozilla firefox\plugins\atgpcext.dll
[2010/09/14 10:14:08 | 000,046,408 | —- | M] () – C:\Program Files\mozilla firefox\plugins\atmccli.dll
[2009/01/15 08:56:32 | 000,098,704 | —- | M] (WebEx Communications, Inc) – C:\Program Files\mozilla firefox\plugins\ieatgpc.dll
[2010/09/14 10:14:03 | 000,061,848 | —- | M] (WebEx Communications, Inc) – C:\Program Files\mozilla firefox\plugins\npatgpc.dll
[2010/09/15 04:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/05/07 15:13:47 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/03/28 21:59:16 | 000,002,024 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml

O1 HOSTS File: ([2011/10/23 15:36:51 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (dsWebAllowBHO Class) - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll (Microsoft Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110629120626.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4 - HKLM..\Run: [36X Raid Configurer] C:\WINDOWS\System32\xRaidSetup.exe (Gigabyte Technology Corp.)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [Norton Ghost 14.0] C:\Program Files\Norton Ghost\Agent\VProTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKCU..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe (FreeDownloadManager.ORG)
O4 - HKCU..\Run: [gStart] C:\Program Files\Garmin\gStart.exe (GARMIN Corp.)
O4 - HKCU..\Run: [PhotoShow Deluxe Media Manager] C:\Program Files\Ahead\Ahead\data\Xtras\mssysmgr.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Intuit Data Protect.lnk = C:\Program Files\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk = C:\Program Files\Intuit\QuickBooks 2008\QBW32.EXE (Intuit Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
O4 - Startup: C:\Documents and Settings\David Kramer\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1315287898734 (MUWebControl Class)
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} file:///C:/Program%20Files/Autodesk/MDT6/AcDcToday.ocx (AcDcToday Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} file:///C:/Program%20Files/Autodesk/MDT6/InstBanr.ocx (NOXLATE-BANR)
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} file:///C:/Program%20Files/Autodesk/MDT6/InstFred.ocx (InstaFred)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} file:///C:/Program%20Files/Autodesk/MDT6/AcPreview.ocx (AcPreview Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 192.168.0.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F70C2795-BF90-4D1A-B07C-F1F10C5AF82C}: DhcpNameServer = 192.168.0.1 192.168.0.2
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\intu-help-qb4 {ACE22922-D07C-4860-B51B-8CF472FEC2CB} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logitech\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\David Kramer\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\David Kramer\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/10/19 18:47:41 | 000,000,047 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…com [@ = ComFile] – Reg Error: Key error. File not found
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2011/10/24 08:46:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2011/10/24 08:37:48 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\David Kramer\Desktop\OTL.exe
[2011/10/23 13:52:15 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/10/23 13:49:45 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/10/23 13:49:45 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/10/23 13:49:45 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/10/23 13:49:45 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/10/23 13:49:39 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/10/23 13:49:38 | 000,000,000 | —D | C] – C:\ComboFix
[2011/10/23 13:49:35 | 000,000,000 | —D | C] – C:\Qoobox
[2011/10/23 13:44:06 | 004,269,652 | R— | C] (Swearware) – C:\Documents and Settings\David Kramer\Desktop\ComboFix.exe
[2011/10/03 13:57:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\TeamViewer 6
[2011/10/03 13:54:39 | 000,000,000 | —D | C] – C:\Documents and Settings\David Kramer\Application Data\TeamViewer
[2011/10/03 13:54:35 | 000,000,000 | —D | C] – C:\Program Files\TeamViewer
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\David Kramer\Desktop\*.tmp files -> C:\Documents and Settings\David Kramer\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/10/24 08:50:00 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011/10/24 08:46:35 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/10/24 08:46:08 | 008,585,078 | —- | M] () – C:\WINDOWS\System32\nvwsapps.xml
[2011/10/24 08:46:03 | 000,001,595 | —- | M] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Center.lnk
[2011/10/24 08:45:39 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/24 08:45:30 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/10/24 08:39:03 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/24 08:37:52 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\David Kramer\Desktop\OTL.exe
[2011/10/23 15:48:46 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/10/23 15:36:51 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/10/23 13:52:17 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2011/10/23 13:44:19 | 004,269,652 | R— | M] (Swearware) – C:\Documents and Settings\David Kramer\Desktop\ComboFix.exe
[2011/10/22 22:36:23 | 000,004,096 | -HS- | M] () – C:\VSNAP.IDX
[2011/10/22 18:56:56 | 000,006,774 | —- | M] () – C:\Documents and Settings\David Kramer\Application Data\PrimoPDFSet.xml
[2011/10/22 17:52:03 | 000,002,461 | —- | M] () – C:\Documents and Settings\David Kramer\Desktop\HiJackThis.lnk
[2011/10/22 17:10:58 | 000,002,243 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SolidWorks 2007 SP0.0.lnk
[2011/10/22 17:01:26 | 000,850,944 | —- | M] () – C:\Documents and Settings\David Kramer\Desktop\hinged clamp idea..SLDPRT
[2011/10/21 18:19:57 | 000,000,426 | —- | M] () – C:\WINDOWS\BRWMARK.INI
[2011/10/21 15:22:58 | 000,106,105 | —- | M] () – C:\Documents and Settings\David Kramer\Desktop\fax-19081636.pdf
[2011/10/17 22:48:05 | 001,252,949 | —- | M] () – C:\Documents and Settings\David Kramer\Desktop\X1-X2SystemInstructions2010914.pdf
[2011/10/17 19:20:04 | 000,000,114 | —- | M] () – C:\WINDOWS\System32\prsgrc.tgz
[2011/10/17 19:20:04 | 000,000,087 | —- | M] () – C:\WINDOWS\System32\ssprs.tgz
[2011/10/17 19:20:03 | 000,000,218 | —- | M] () – C:\WINDOWS\System32\qxcyfuj.tgz
[2011/10/17 11:53:17 | 000,001,200 | —- | M] () – C:\WINDOWS\Brpfx04a.ini
[2011/10/14 16:59:20 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/10/14 11:20:08 | 000,000,600 | —- | M] () – C:\Documents and Settings\David Kramer\Local Settings\Application Data\PUTTY.RND
[2011/10/13 10:03:22 | 000,374,464 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/10/12 23:29:23 | 000,560,446 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/10/12 23:29:23 | 000,109,954 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/10/12 23:26:09 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/10/12 23:03:17 | 000,000,146 | —- | M] () – C:\WINDOWS\Capture.INI
[2011/10/10 16:28:13 | 000,001,663 | —- | M] () – C:\Documents and Settings\All Users\Desktop\FileZilla Client.lnk
[2011/10/03 13:57:18 | 000,000,815 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TeamViewer 6.lnk
[2011/10/03 01:35:11 | 005,971,456 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2011/09/26 11:41:20 | 000,611,328 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\uiautomationcore.dll
[2011/09/26 11:41:20 | 000,220,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\oleacc.dll
[2011/09/26 11:41:14 | 000,020,480 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\oleaccrc.dll
[2011/09/26 11:41:14 | 000,020,480 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\oleaccrc.dll
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\David Kramer\Desktop\*.tmp files -> C:\Documents and Settings\David Kramer\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/10/23 13:52:17 | 000,000,211 | —- | C] () – C:\Boot.bak
[2011/10/23 13:52:16 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/10/23 13:49:45 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/10/23 13:49:45 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/10/23 13:49:45 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/10/23 13:49:45 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/10/23 13:49:45 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/10/22 17:01:26 | 000,850,944 | —- | C] () – C:\Documents and Settings\David Kramer\Desktop\hinged clamp idea..SLDPRT
[2011/10/21 15:22:58 | 000,106,105 | —- | C] () – C:\Documents and Settings\David Kramer\Desktop\fax-19081636.pdf
[2011/10/17 22:48:05 | 001,252,949 | —- | C] () – C:\Documents and Settings\David Kramer\Desktop\X1-X2SystemInstructions2010914.pdf
[2011/10/03 13:57:18 | 000,000,815 | —- | C] () – C:\Documents and Settings\All Users\Desktop\TeamViewer 6.lnk
[2011/09/06 21:50:18 | 001,692,624 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-507921405-1336601894-725345543-1003-0.dat
[2011/09/05 23:23:01 | 000,284,614 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/08/15 13:44:58 | 000,000,120 | —- | C] () – C:\WINDOWS\Njabipulukeli.dat
[2011/08/15 13:44:58 | 000,000,000 | —- | C] () – C:\WINDOWS\Spaxinu.bin
[2011/06/22 21:35:25 | 000,000,016 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2011/04/24 20:26:31 | 002,524,480 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/04/24 18:46:45 | 000,000,090 | —- | C] () – C:\WINDOWS\QBChanUtil_Trigger.ini
[2011/03/16 18:52:55 | 000,000,817 | —- | C] () – C:\WINDOWS\WDD_COMPARE_DIR_CFX1.INI
[2011/03/16 18:48:48 | 000,000,907 | —- | C] () – C:\WINDOWS\MD_MicroDiffs.INI
[2011/03/16 18:48:48 | 000,000,907 | —- | C] () – C:\WINDOWS\MD_MacroDiffs.INI
[2011/03/16 18:48:47 | 000,000,817 | —- | C] () – C:\WINDOWS\CFX.INI
[2011/03/16 18:38:56 | 000,000,054 | —- | C] () – C:\WINDOWS\SW_Win2000X9.DLL
[2011/03/16 18:37:56 | 000,000,051 | —- | C] () – C:\WINDOWS\SW_Win2141X16.DLL
[2011/03/16 18:37:56 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\XLSCX.INI
[2011/03/16 18:37:56 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\WordCX.INI
[2011/03/16 18:37:46 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\RegisterExe.exe
[2011/03/16 18:37:45 | 000,225,280 | —- | C] () – C:\WINDOWS\System32\DrakeCom.dll
[2011/03/16 18:37:45 | 000,221,184 | —- | C] () – C:\WINDOWS\System32\SII_PDF.dll
[2011/03/16 18:37:45 | 000,131,072 | —- | C] () – C:\WINDOWS\System32\CSVSpecialProcessing.dll
[2011/03/16 18:37:45 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\DVM.dll
[2011/01/31 09:53:06 | 000,000,002 | —- | C] () – C:\Program Files\mshexc.bmp
[2010/07/31 01:06:16 | 000,038,429 | —- | C] () – C:\Documents and Settings\David Kramer\Application Data\Microsoft Excel.ADR
[2010/06/24 17:18:02 | 000,000,033 | —- | C] () – C:\WINDOWS\render.ini
[2010/04/28 12:59:03 | 000,000,165 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2010/03/26 13:29:27 | 000,068,960 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2010/03/26 13:13:26 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/02/21 15:10:27 | 008,892,928 | —- | C] () – C:\Documents and Settings\All Users\Application Data\atscie.msi
[2010/02/10 12:16:26 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\MPMapTrace.dll
[2010/02/10 11:41:16 | 000,364,544 | —- | C] () – C:\WINDOWS\System32\mpPathan.dll
[2009/11/16 23:26:54 | 000,002,744 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LUUnInstall.LiveUpdate
[2009/09/25 09:04:42 | 000,026,888 | —- | C] () – C:\WINDOWS\System32\drivers\swmsflt.sys
[2009/09/02 16:04:07 | 000,215,144 | R— | C] () – C:\WINDOWS\patchw32.dll
[2009/09/02 16:02:50 | 000,215,144 | R— | C] () – C:\WINDOWS\pw32a.dll
[2009/08/29 16:20:06 | 000,006,144 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/06/24 17:50:37 | 000,002,195 | —- | C] () – C:\WINDOWS\coolmp3.ini
[2009/06/24 17:45:38 | 000,000,052 | —- | C] () – C:\WINDOWS\cool.ini
[2009/06/24 17:43:24 | 000,000,772 | —- | C] () – C:\WINDOWS\wordpad.ini
[2009/04/01 23:04:42 | 000,038,434 | —- | C] () – C:\Documents and Settings\David Kramer\Application Data\Comma Separated Values (Windows).ADR
[2009/03/28 15:58:45 | 000,000,146 | —- | C] () – C:\WINDOWS\Capture.INI
[2009/02/25 21:33:15 | 000,006,774 | —- | C] () – C:\Documents and Settings\David Kramer\Application Data\PrimoPDFSet.xml
[2009/02/25 21:31:34 | 000,176,235 | —- | C] () – C:\WINDOWS\System32\Primomonnt.dll
[2009/01/26 17:44:06 | 000,182,200 | —- | C] () – C:\WINDOWS\System32\drivers\UsbSnoop.sys
[2008/12/09 21:39:38 | 000,001,025 | —- | C] () – C:\WINDOWS\System32\sysprs7.dll
[2008/12/09 21:39:38 | 000,000,476 | —- | C] () – C:\WINDOWS\System32\lsprst7.dll
[2008/12/09 19:22:54 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\serauth2.dll
[2008/12/09 19:22:54 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\serauth1.dll
[2008/12/09 19:22:54 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\nsprs.dll
[2008/11/12 18:19:30 | 000,028,672 | —- | C] () – C:\WINDOWS\etUnInst.exe
[2008/11/03 11:46:03 | 000,000,600 | —- | C] () – C:\Documents and Settings\David Kramer\Local Settings\Application Data\PUTTY.RND
[2008/10/19 21:42:30 | 000,000,028 | —- | C] () – C:\WINDOWS\pdf995.ini
[2008/10/19 21:41:37 | 000,051,716 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2008/10/19 21:41:37 | 000,000,060 | —- | C] () – C:\WINDOWS\wpd99.drv
[2008/10/19 17:32:51 | 000,040,960 | —- | C] () – C:\Documents and Settings\David Kramer\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/10/19 17:32:50 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/10/18 15:10:03 | 000,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2008/10/18 15:09:48 | 000,001,200 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2008/10/18 15:09:48 | 000,000,153 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2008/10/18 15:09:48 | 000,000,065 | —- | C] () – C:\WINDOWS\System32\BD8860DN.DAT
[2008/10/18 15:09:39 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\BRTCPCON.DLL
[2008/10/18 15:09:39 | 000,000,114 | —- | C] () – C:\WINDOWS\System32\BRLMW03A.INI
[2008/10/18 15:09:25 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\BrMuSNMP.dll
[2008/10/18 15:09:25 | 000,000,089 | —- | C] () – C:\WINDOWS\brdfxspd.dat
[2008/10/18 15:07:15 | 000,027,019 | —- | C] () – C:\WINDOWS\maxlink.ini
[2008/10/05 17:53:38 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2008/10/05 17:52:24 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\pxhpinst.exe
[2008/10/05 17:39:34 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/10/05 17:22:53 | 000,000,000 | —- | C] () – C:\WINDOWS\eDrawingOfficeAutomator.INI
[2008/10/04 19:17:21 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2008/10/04 18:11:17 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\ChCfg.exe
[2008/10/04 16:16:44 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/10/04 16:13:31 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/10/04 09:03:46 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/10/04 09:02:33 | 000,374,464 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/07/31 08:21:46 | 000,000,092 | —- | C] () – C:\WINDOWS\System32\ftdiun2k.ini
[2008/05/20 11:57:16 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2008/04/28 10:13:33 | 000,000,310 | —- | C] () – C:\WINDOWS\primopdf.ini
[2008/02/04 18:23:10 | 000,693,792 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2007/09/21 17:38:00 | 001,724,416 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2007/09/21 17:38:00 | 001,657,376 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2007/09/21 17:38:00 | 001,507,328 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2007/09/21 17:38:00 | 001,346,080 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2007/09/21 17:38:00 | 001,101,824 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2007/09/21 17:38:00 | 001,018,772 | —- | C] () – C:\WINDOWS\System32\nvucode.bin
[2007/09/21 17:38:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2007/09/21 17:38:00 | 000,449,056 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2007/09/21 17:38:00 | 000,436,768 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2007/09/21 17:38:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2007/08/03 11:07:14 | 000,000,835 | —- | C] () – C:\WINDOWS\System32\IdentixLicense.INI
[2006/06/13 16:35:32 | 000,053,760 | —- | C] () – C:\WINDOWS\System32\zlib.dll
[2004/08/02 14:20:40 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2002/03/04 10:16:34 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\Jpeg32.dll
[2001/08/23 05:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 05:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 05:00:00 | 000,560,446 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 05:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 05:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 05:00:00 | 000,109,954 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 05:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 05:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 05:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 05:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2001/08/23 05:00:00 | 000,001,024 | —- | C] () – C:\WINDOWS\System32\grcauth2.dll
[2001/08/23 05:00:00 | 000,001,024 | —- | C] () – C:\WINDOWS\System32\grcauth1.dll
[2001/08/23 05:00:00 | 000,001,024 | —- | C] () – C:\WINDOWS\System32\clauth2.dll
[2001/08/23 05:00:00 | 000,001,024 | —- | C] () – C:\WINDOWS\System32\clauth1.dll
[2001/08/23 05:00:00 | 000,001,024 | —- | C] () – C:\WINDOWS\System32\a4onhwd.dll
[2001/08/23 05:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2001/08/23 05:00:00 | 000,000,073 | —- | C] () – C:\WINDOWS\System32\ssprs.dll
[2001/08/23 05:00:00 | 000,000,016 | -H– | C] () – C:\WINDOWS\System32\zdznltv.dll
[2001/08/23 05:00:00 | 000,000,016 | -H– | C] () – C:\WINDOWS\System32\yi0kbf3.dll
[2001/08/23 05:00:00 | 000,000,016 | -H– | C] () – C:\WINDOWS\System32\y3sayt5.dll
[2001/08/23 05:00:00 | 000,000,016 | -H– | C] () – C:\WINDOWS\System32\x3txr8h.dll
[2001/08/23 05:00:00 | 000,000,016 | -H– | C] () – C:\WINDOWS\System32\w92h6z0.dll
[2001/08/23 05:00:00 | 000,000,016 | -H– | C] () – C:\WINDOWS\System32\vgeilxn.dll
[2001/08/23 05:00:00 | 000,000,016 | -H– | C] () – C:\WINDOWS\System32\vf6kvkm.dll
[2001/08/23 05:00:00 | 000,000,016 | -H– | C] () – C:\WINDOWS\System32\v2ataay.dll
[2001/08/23 05:00:00 | 000,000,016 | -H– | C] () – C:\WINDOWS\System32\s0lz06y.dll
[2001/08/23 05:00:00 | 000,000,016 | -H– | C] () – C:\WINDOWS\System32\qakvuoc.dll
[2001/08/23 05:00:00 | 000,000,016 | -H– | C] () – C:\WINDOWS\System32\okybcyf.dll
[2001/08/23 05:00:00 | 000,000,016 | -H– | C] () – C:\WINDOWS\System32\o7sdcuc.dll
[2001/08/23 05:00:00 | 000,000,016 | -H– | C] () – C:\WINDOWS\System32\nlp4m8m.dll
[2001/08/23 05:00:00 | 000,000,016 | -H– | C] () – C:\WINDOWS\System32\lzq4l06.dll
[2001/08/23 05:00:00 | 000,000,016 | -H– | C] () – C:\WINDOWS\System32\iblqw4n.dll
[2001/08/23 05:00:00 | 000,000,016 | -H– | C] () – C:\WINDOWS\System32\h2uir87.dll
[2001/08/23 05:00:00 | 000,000,016 | -H– | C] () – C:\WINDOWS\System32\gm1tf45.dll
[2001/08/23 05:00:00 | 000,000,016 | -H– | C] () – C:\WINDOWS\System32\gh4tbev.dll
[2001/08/23 05:00:00 | 000,000,016 | -H– | C] () – C:\WINDOWS\System32\fi7er8m.dll
[2001/08/23 05:00:00 | 000,000,016 | -H– | C] () – C:\WINDOWS\System32\elynvfk.dll
[2001/08/23 05:00:00 | 000,000,016 | -H– | C] () – C:\WINDOWS\System32\e9xhvnx.dll
[2001/08/23 05:00:00 | 000,000,016 | -H– | C] () – C:\WINDOWS\System32\a6g5e5i.dll
[2001/04/23 02:07:28 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\mtstack.exe
[2000/10/20 14:25:36 | 000,079,360 | —- | C] () – C:\WINDOWS\System32\acdbres.dll
[1996/04/03 12:33:26 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys

========== LOP Check ==========

[2011/06/23 21:31:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Big Fish Games
[2008/10/18 16:16:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\COMMON FILES
[2008/12/18 12:06:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DassaultSystemes
[2008/10/23 10:12:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
[2011/06/01 22:47:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Garmin
[2008/10/22 12:48:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\j2 Messenger 4.4 Output
[2008/10/21 22:18:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\j2 Messenger 4.4 Setup
[2011/04/24 18:46:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nuance
[2011/04/14 13:06:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pdf995
[2011/09/05 22:33:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PreEmptive Solutions
[2008/10/18 15:06:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2010/04/30 08:35:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sprint
[2011/04/24 19:05:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SQL Anywhere 11
[2011/06/23 21:30:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/08/15 10:15:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TrueCrypt
[2008/11/25 16:26:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2008/10/18 14:29:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009/09/23 14:11:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2008/11/12 18:22:21 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\Autodesk
[2008/10/04 19:29:37 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2008/12/18 12:06:15 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\DassaultSystemes
[2011/06/30 21:54:04 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\Dropbox
[2008/10/05 17:23:31 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\DWGeditor
[2011/10/22 19:23:45 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\FileZilla
[2011/10/24 08:52:02 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\Free Download Manager
[2011/06/01 22:47:21 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\Garmin
[2008/12/09 19:22:57 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\IAR Embedded Workbench
[2008/10/21 22:19:36 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\j2 Global
[2008/11/10 14:44:02 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\j2 Messenger
[2008/10/04 19:25:02 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\Leadertech
[2011/07/10 14:17:47 | 000,000,000 | RH-D | M] – C:\Documents and Settings\David Kramer\Application Data\Microchip
[2008/10/05 19:32:41 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\OfficeUpdate12
[2009/05/27 21:28:06 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\Opera
[2008/10/19 21:42:30 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\pdf995
[2009/04/29 10:20:48 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\PentaLogix
[2009/02/12 14:23:39 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\ScanSoft
[2009/09/02 21:46:16 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\SIP Communicator
[2011/09/23 11:12:04 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\sldIM
[2008/10/18 15:10:00 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\Snapfish
[2010/04/30 08:38:31 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\Sprint
[2011/10/03 14:01:19 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\TeamViewer
[2010/07/16 11:43:47 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\TightVNC
[2010/08/15 10:27:24 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\TrueCrypt
[2011/05/02 11:03:19 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\webex
[2009/02/06 23:39:34 | 000,000,000 | —D | M] – C:\Documents and Settings\David Kramer\Application Data\Z-Firm LLC

========== Purity Check ==========



========== Files - Unicode (All) ==========
[2011/01/21 19:09:56 | 000,000,000 | —D | M](C:\Do?) – C:\DoՐ
[2011/01/21 19:09:56 | 000,000,000 | —D | C](C:\Do?) – C:\DoՐ
[2010/09/24 10:12:11 | 000,000,000 | —D | M](C:\Documen??) – C:\Documen׵
[2010/09/24 10:12:11 | 000,000,000 | —D | C](C:\Documen??) – C:\Documen׵
[2010/08/19 23:58:53 | 000,000,000 | —D | M](C:\Documenl?) – C:\Documenl׵
[2010/08/19 23:58:53 | 000,000,000 | —D | C](C:\Documenl?) – C:\Documenl׵
[2010/03/26 09:35:00 | 000,000,000 | —D | M](C:\Documen?) – C:\Documen؈
[2010/03/26 09:35:00 | 000,000,000 | —D | C](C:\Documen?) – C:\Documen؈
[2009/11/30 22:57:53 | 000,000,000 | —D | M](C:\Documen?) – C:\Documenռ
[2009/11/30 22:57:53 | 000,000,000 | —D | C](C:\Documen?) – C:\Documenռ
[2008/12/01 22:41:59 | 000,000,000 | —D | M](C:\Documen?) – C:\DocumenҚ
[2008/12/01 22:41:58 | 000,000,000 | —D | C](C:\Documen?) – C:\DocumenҚ

========== Alternate Data Streams ==========

@Alternate Data Stream - 175 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:07BB519E
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A3E39C6A

< End of report >
That also seems to be OK

Let’s run one more scan to be sure before we tidy up.

Run ESET Online Scan

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan 1. Click the Eset online Scanner button.
2. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

• Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
• Double click on the Eset installer icon on your desktop.

3. Check Yes, I accept the Terms of Use
4. Click the Start button.
5. Accept any security warnings from your browser.
6. Check Scan archives
7. Push the Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push List of found threats
10. Push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Note - when ESET doesn't find any threats, no report will be created.
11. Push the back button.
12. Push Finish
If a log has been produced post it in your next reply.

Satchfan
Well, it looks like my machine wasn't completely clean after all. Btw, I have had problems recently with Java. I keep getting notices that an update is available but the install fails. Also, it looks like a few utilities I have been using are nasty. I googled each one before downloading and didn't find anything that said they were malware. What are the next steps? Again, thanks for all you help. ESET Scan Results: C:\Documents and Settings\David\Application Data\Sun\Java\Deployment\cache\6.0\29\3970fbdd-40f6f87e multiple threats deleted - quarantined C:\Documents and Settings\David\Application Data\Sun\Java\Deployment\cache\6.0\7\3fbc9f87-64815ba2 multiple threats deleted - quarantined C:\Documents and Settings\David Kramer\Application Data\Sun\Java\Deployment\cache\6.0\10\33df908a-7ac120ff probably a variant of Java/TrojanDownloader.OpenStream.NCC trojan cleaned by deleting - quarantined C:\Documents and Settings\David Kramer\Application Data\Sun\Java\Deployment\cache\6.0\47\fd7bfaf-6582e6c6 multiple threats deleted - quarantined E:\Downloads\Flv to Avi Converter\cnet_Pazera_Free_FLV_to_AVI_Converter_zip.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined E:\Downloads\PlayFLV\PlayFLV.exe Win32/TrojanDownloader.Adload.NIQ trojan deleted - quarantined
The scan has got the last few stragglers and that is why we run it at the end, when we think the computer is clean.


Your Java is well out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version

Please download JavaRa to your desktop and unzip it to its own folder
  • Double-click on JavaRa.exe to start the program
  • From the drop-down menu, choose English or the appropriate language…and click on Select.
  • Click Remove Older Versions to remove the older versions of Java installed on your computer
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

====================================================

Run CKScanner

Download CKScanner by askey127 from here & save it to your Desktop.
  • Doubleclick CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply

Satchfan
Hi Satchfan, There was an error in the link you provided for JavaRa, but I was able to download it from RaProducts. It removed Java and I re-installed per your instructions. Here are the contents from ckfiles.txt: CKScanner - Additional Security Risks - These are not necessarily bad c:\program files\ahead\ahead\data\app\simplestar\data\shared\music\jazz\noonisthecrackofdawn_image.swf c:\program files\ahead\ahead\data\app\simplestar\data\shared\music\jazz\noon_is_the_crack_of_dawn.swf scanner sequence 3.LB.11.VANABT —– EOF —– Thanks again for all your help. David
Hi dmkeng

Good that the Java is now OK. :)

Your computer appears to be clean.

Now that you’re free from malware, as long as your computer seems to be running well, please follow these simple steps to tidy up you computer and decrease the likelihood of getting infected again:

Uninstall Combofix

Follow these steps to uninstall Combofix
  • click START then RUN
  • now type Combofix /uninstall in the runbox and click OK.
Note the space between the X and the /, it needs to be there.
🖼Click to load external image (Posted Image)
  • please follow the prompts to uninstall Combofix.
  • once it's finished uninstalling itself you will receive a message saying Combofix was uninstalled successfully.
===================================================

Uninstall OTL
  • Double-click OTL.exe
  • Click the CleanUp! button.
  • Select Yes when the Begin cleanup Process? prompt appears.
  • If you are prompted to reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it by yourself.
NOTE: If you receive a warning from your firewall or other security programs regarding OTL attempting to contact the internet, please allow it to do so.

===================================================

Recommended programs

SpywareBlaster. SpywareBlaster protects against bad ActiveX, it immunizes your PC against them. It blocks over 11,000 bad sites and uses no resources of your computer.

===================================================

Update and run Malwarebytes. This really is an excellent program that you should update and run on a regular basis, probably weekly.

===================================================

It’s important to keep programs up to date so that malware doesn't exploit any old security flaws.

FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated.

===================================================

MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

===================================================

I also recommend that you read the following:

How to prevent malware by miekiemoes

Safe computing

Satchfan
My computer appears clean - Yay!!! When I ran combofix /uninstall Windows could not find combofix on my computer. Should I be worried about that? And yes, I put the space between x and /. I did all the other stuff you suggested as well. Plus, I paid for a 2 year subscription to the SpywareBlaster auto updates. Thank you for all your help. How can I donate to your organization?
There is no problem regarding ComboFix. If you can;t see it on your desktop, (which is wgere it was), then it has gone.

I'm glad we could help and thank you for your offer of a donation. You can donate by clicking on this link.

Best wishes

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI