This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer is really slow. No errors but can't figure out what is wr

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I will kindly appreciate it if you take a look at the logs and see if something is amiss. There used to be several errors that popped whenever the computer started, but computer ran just fine if we clicked ok and ignored (I am sorry I cannot recall what the errors were).
We were without internet for about a year since there was no signal for our verizon modem, so we quit using the computer at home. Recently we obtained a new internet service, and have started using this computer again.
After what seemed like a lot "updates" for all sorts of software that we've missed in a year and they installed, this computer got really slow. My husband bought Regzooka and ran it, it took care of the error messages, but it didn't do anything for how slow this pc is.

Thanks in advance for your help. Andre

I have posted here the OTL. txt, Extras.txt, hijackthis.log, and DDS.txt separated by a line of ****. I hope I did this right. Thanks.

**************************************

OTL.txt

OTL logfile created on: 12/5/2011 9:01:55 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Weber\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

509.98 Mb Total Physical Memory | 197.04 Mb Available Physical Memory | 38.64% Memory free
1.22 Gb Paging File | 0.73 Gb Available in Paging File | 59.86% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 108.59 Gb Total Space | 80.29 Gb Free Space | 73.94% Space Free | Partition Type: NTFS
Drive D: | 36.91 Gb Total Space | 0.27 Gb Free Space | 0.74% Space Free | Partition Type: NTFS

Computer Name: EVAN | User Name: Weber | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Weber\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\palmOne\Hotsync.exe (PalmSource, Inc)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_9e2c2e10\mscorlib.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_fcef5848\system.drawing.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_abe31053\system.xml.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_4bef8d5b\system.windows.forms.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_fce5f4a8\system.dll ()
MOD - c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MOD - c:\windows\assembly\gac\hpqcprsc\3.0.0.0__a53cf5803f4c3827\hpqcprsc.dll ()
MOD - c:\windows\assembly\gac\hpqietpz\3.0.0.0__a53cf5803f4c3827\hpqietpz.dll ()
MOD - c:\windows\assembly\gac\interop.hprblog\3.0.0.0__a53cf5803f4c3827\interop.hprblog.dll ()
MOD - c:\windows\assembly\gac\hpqisrtb\4.0.0.0__a53cf5803f4c3827\hpqisrtb.dll ()
MOD - c:\windows\assembly\gac\hpqprrsc\3.0.0.0__a53cf5803f4c3827\hpqprrsc.dll ()
MOD - c:\windows\assembly\gac\hpqimlib\3.0.0.0__a53cf5803f4c3827\hpqimlib.dll ()
MOD - c:\windows\assembly\gac\hpqmdmr\3.0.0.0__a53cf5803f4c3827\hpqmdmr.dll ()
MOD - c:\windows\assembly\gac\lead.wrapper\13.0.0.89__9cf889f53ea9b907\lead.wrapper.dll ()
MOD - c:\windows\assembly\gac\lead.drawing.imaging.imageprocessing\13.0.0.89__9cf889f53ea9b907\lead.drawing.imaging.imageprocessing.dll ()
MOD - c:\windows\assembly\gac\lead.drawing\13.0.0.89__9cf889f53ea9b907\lead.drawing.dll ()
MOD - c:\windows\assembly\gac\lead\13.0.0.89__9cf889f53ea9b907\lead.dll ()
MOD - c:\windows\assembly\gac\lead.windows.forms.drawingcontainer\13.0.0.89__9cf889f53ea9b907\lead.windows.forms.drawingcontainer.dll ()
MOD - c:\windows\assembly\gac\lead.windows.forms\13.0.0.89__9cf889f53ea9b907\lead.windows.forms.dll ()
MOD - c:\windows\assembly\gac\interop.hpqimgr\1.0.0.0__a53cf5803f4c3827\interop.hpqimgr.dll ()
MOD - c:\windows\assembly\gac\hpqtray\3.0.0.0__a53cf5803f4c3827\hpqtray.dll ()
MOD - c:\windows\assembly\gac\hpqimgrc\3.0.0.0__a53cf5803f4c3827\hpqimgrc.dll ()
MOD - c:\windows\assembly\gac\hpqgldlg\3.0.0.0__a53cf5803f4c3827\hpqgldlg.dll ()
MOD - c:\windows\assembly\gac\hpqthumb\3.0.0.0__a53cf5803f4c3827\hpqthumb.dll ()
MOD - c:\windows\assembly\gac\hpqfmrsc\3.0.0.0__a53cf5803f4c3827\hpqfmrsc.dll ()
MOD - c:\windows\assembly\gac\hpqasset\3.0.0.0__a53cf5803f4c3827\hpqasset.dll ()
MOD - c:\windows\assembly\gac\hpqiface\3.0.0.0__a53cf5803f4c3827\hpqiface.dll ()
MOD - c:\windows\assembly\gac\hpqcmctl\3.0.0.0__a53cf5803f4c3827\hpqcmctl.dll ()
MOD - c:\windows\assembly\gac\hpqccrsc\3.0.0.0__a53cf5803f4c3827\hpqccrsc.dll ()
MOD - c:\windows\assembly\gac\hpqutils\3.0.0.0__a53cf5803f4c3827\hpqutils.dll ()
MOD - c:\windows\assembly\gac\hpqgskin\3.0.0.0__a53cf5803f4c3827\hpqgskin.dll ()
MOD - c:\windows\assembly\gac\hpqntrop\3.0.0.0__a53cf5803f4c3827\hpqntrop.dll ()
MOD - c:\windows\assembly\gac\interop.hpqcxm08\3.0.0.0__a53cf5803f4c3827\interop.hpqcxm08.dll ()
MOD - c:\windows\assembly\gac\interop.hpdarc\1.0.0.0__19565c63d39c2842\interop.hpdarc.dll ()
MOD - c:\windows\assembly\gac\hpqptfnd\3.0.0.0__a53cf5803f4c3827\hpqptfnd.dll ()
MOD - c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll ()
MOD - c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll ()
MOD - c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll ()
MOD - c:\windows\assembly\gac\accessibility\1.0.5000.0__b03f5f7f11d50a3a\accessibility.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()


========== Driver Services (SafeList) ==========

DRV - (dfg) – C:\WINDOWS\system32\drivers\dfg.sys (defrag Development Team)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (WFMC_VAD) WFMC Virtual Audio Device (WDM) – C:\WINDOWS\system32\drivers\wfmcvad.sys (WiFi Media Connect)
DRV - (PalmUSBD) – C:\WINDOWS\system32\drivers\PalmUSBD.sys (PalmSource, Inc.)
DRV - (dsunidrv) – C:\WINDOWS\system32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (USBNET_XP) – C:\WINDOWS\system32\drivers\netusbxp.sys (The LinkSys Group, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl;…&channel;=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.com/ig/dell?hl=en&cl;…&channel;=us

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl;…&channel;=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.startup.homepage: "http://mail.google.com/mail/h/92u8q931cbbn/?zy=e&f;=1"
FF - prefs.js..keyword.URL: "http://search.latam.msn.com/results.aspx?mkt=es-XL&FORM;=MICXAB&q;="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@macromedia.com/FlashPlayer9: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@macromedia.com/FlashPlayer9: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2011/11/21 15:54:52 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011/11/20 20:56:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/19 19:34:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/11/19 19:34:41 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{1266764D-FC4F-4FA7-B63B-884D53B1680F}: C:\Documents and Settings\Weber\Application Data\NetAssistant\ [2011/11/19 08:46:05 | 000,000,000 | —D | M]

[2011/10/22 13:06:45 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Weber\Application Data\Mozilla\Extensions
[2011/11/30 18:36:11 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Weber\Application Data\Mozilla\Firefox\Profiles\fqeqwzyz.default\extensions
[2008/09/14 12:59:28 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Weber\Application Data\Mozilla\Firefox\Profiles\fqeqwzyz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2008/09/14 12:59:29 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Weber\Application Data\Mozilla\Firefox\Profiles\fqeqwzyz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}-trash
[2008/02/04 22:38:02 | 000,001,804 | —- | M] () – C:\Documents and Settings\Weber\Application Data\Mozilla\Firefox\Profiles\fqeqwzyz.default\searchplugins\LiveSearch.xml
[2011/11/09 08:46:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/10/22 13:15:44 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
() (No name found) – C:\DOCUMENTS AND SETTINGS\WEBER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\FQEQWZYZ.DEFAULT\EXTENSIONS\{A7C6CF7F-112C-4500-A7EA-39801A327E5F}.XPI
[2011/11/21 15:54:52 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG2012\FIREFOX4
[2011/10/22 13:14:41 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/11/09 08:45:35 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/22 13:14:38 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2007/03/10 11:39:50 | 000,319,488 | —- | M] ( ) – C:\Program Files\mozilla firefox\plugins\npsnapfish.dll
[2011/09/28 18:26:50 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/09 08:45:36 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2004/08/04 04:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\Weber\Start Menu\Programs\Startup\palmOne Registration.lnk = C:\Program Files\palmOne\register.exe (palmOne/Leader Technologies)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O8 - Extra context menu item: &Search; - ?p=ZJfox000 File not found
O8 - Extra context menu item: Translate with &Babylon; - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm File not found
O9 - Extra Button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - Reg Error: Value error. File not found
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo…otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{16FEE1A1-2FE1-428D-8D98-222A4AE21E3E}: DhcpNameServer = [removed] [removed] 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - No CLSID value found.
O24 - Desktop WallPaper: C:\Documents and Settings\Weber\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Weber\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 12:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{4a84ca2c-5ba6-11dc-af57-001676850e07}\Shell - "" = AutoRun
O33 - MountPoints2\{4a84ca2c-5ba6-11dc-af57-001676850e07}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4a84ca2c-5ba6-11dc-af57-001676850e07}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{bddfe99a-1a29-11e1-b090-001676850e07}\Shell\AutoRun\command - "" = H:\PMBP_Win.exe
O33 - MountPoints2\{ce127b10-0b37-11e1-b078-001676850e07}\Shell - "" = AutoRun
O33 - MountPoints2\{ce127b10-0b37-11e1-b078-001676850e07}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{ce127b10-0b37-11e1-b078-001676850e07}\Shell\AutoRun\command - "" = F:\PhotoViewerAP_V6.0.1.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.I420 - lvcodec2.dll File not found
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/05 20:56:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Weber\My Documents\Registry Back up for ccleaner
[2011/12/05 20:52:23 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Weber\Recent
[2011/12/05 20:44:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2011/12/05 20:44:53 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2011/11/27 15:35:26 | 000,000,000 | —D | C] – C:\Program Files\MSECache
[2011/11/20 21:05:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Weber\Application Data\DDMSettings
[2011/11/20 20:55:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\DivX Plus
[2011/11/20 20:54:20 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DivX Shared
[2011/11/20 20:46:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\DivX
[2011/11/19 22:33:25 | 000,000,000 | R–D | C] – C:\Documents and Settings\Weber\Start Menu\Programs\Administrative Tools
[2011/11/19 20:44:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Weber\Desktop\PDF
[2011/11/19 20:15:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Weber\Application Data\InstallShield
[2011/11/19 19:15:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Weber\Application Data\MSNInstaller
[2011/11/19 18:36:43 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Weber\Application Data\GTek
[2011/11/19 18:35:54 | 000,000,000 | —D | C] – C:\Program Files\DellSupport
[2011/11/19 17:38:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Weber\Start Menu\Programs\RegZooka
[2011/11/19 17:37:58 | 000,000,000 | —D | C] – C:\Program Files\RegZooka
[2011/11/19 08:49:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Weber\Application Data\Fighters
[2011/11/19 08:48:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Fighters
[2011/11/19 08:48:07 | 000,000,000 | —D | C] – C:\Program Files\Free Offers from Freeze.com
[2011/11/19 08:46:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Weber\Application Data\NetAssistant
[2011/11/19 08:06:21 | 000,000,000 | —D | C] – C:\Program Files\CyberDefender
[2011/11/10 20:31:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
[2011/11/10 20:31:23 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2011/11/10 20:29:35 | 006,283,632 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Weber\Desktop\Silverlight.exe
[2011/11/07 22:09:38 | 000,017,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2011/11/07 22:07:55 | 000,000,000 | —D | C] – C:\WINDOWS\$SQLUninstallSQL2000-KB960082-v8.00.2055-x86-ENU$
[2011/11/07 21:39:41 | 000,021,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\hidserv.dll
[2011/11/07 21:37:44 | 000,000,000 | —D | C] – C:\WINDOWS\ServicePackFiles
[2011/11/06 18:06:34 | 000,470,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aclayers.dll
[2011/11/06 18:05:42 | 000,743,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2011/11/06 18:01:08 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fontsub.dll
[2011/11/06 18:00:40 | 000,060,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\colbact.dll
[2011/11/06 17:56:22 | 003,555,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\moviemk.exe
[2011/11/06 17:49:18 | 000,655,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstscax.dll
[2011/11/06 16:11:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Weber\My Documents\midec_files
[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/05 20:44:58 | 000,000,682 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/12/05 20:34:55 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/12/05 20:33:42 | 000,000,751 | —- | M] () – C:\Documents and Settings\Weber\Start Menu\Programs\Startup\palmOne Registration.lnk
[2011/12/05 20:33:07 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/05 20:33:04 | 534,827,008 | -HS- | M] () – C:\hiberfil.sys
[2011/12/05 17:42:21 | 111,469,982 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/12/05 17:40:22 | 000,154,665 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011/11/28 07:54:49 | 000,277,352 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/11/27 08:59:20 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/11/23 22:37:47 | 000,130,048 | —- | M] () – C:\Documents and Settings\Weber\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/23 15:04:11 | 000,590,925 | —- | M] () – C:\Documents and Settings\Weber\Desktop\GRACO BES.pdf
[2011/11/23 14:58:32 | 000,372,873 | —- | M] () – C:\Documents and Settings\Weber\Desktop\TomatoPaste.pdf
[2011/11/21 15:54:54 | 000,000,702 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2011/11/20 21:06:27 | 002,647,208 | —- | M] () – C:\Documents and Settings\Weber\Desktop\Phillips 46 TV.divx
[2011/11/20 20:56:59 | 000,001,757 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Converter.lnk
[2011/11/20 20:56:58 | 000,001,504 | —- | M] () – C:\Documents and Settings\Weber\Desktop\DivX Movies.lnk
[2011/11/20 20:56:24 | 000,000,777 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2011/11/20 08:44:58 | 000,766,625 | —- | M] () – C:\Documents and Settings\Weber\Desktop\Steam Flaking.pdf
[2011/11/19 18:59:32 | 000,000,260 | —- | M] () – C:\WINDOWS\_delis32.ini
[2011/11/19 17:54:10 | 000,000,710 | —- | M] () – C:\Documents and Settings\Weber\Desktop\RegZooka.lnk
[2011/11/10 20:30:05 | 006,283,632 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Weber\Desktop\Silverlight.exe
[2011/11/08 10:13:23 | 000,402,426 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/11/08 10:13:22 | 000,062,032 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/11/07 22:04:53 | 000,000,989 | —- | M] () – C:\WINDOWS\System32\mapisvc.inf
[2011/11/07 21:40:16 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
[2011/11/07 21:40:14 | 000,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2011/11/06 17:23:10 | 000,000,742 | —- | M] () – C:\Documents and Settings\Weber\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/11/06 17:23:10 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/11/06 16:11:06 | 000,020,258 | —- | M] () – C:\Documents and Settings\Weber\My Documents\midec.htm
[8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/05 20:44:58 | 000,000,682 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/11/23 15:04:11 | 000,590,925 | —- | C] () – C:\Documents and Settings\Weber\Desktop\GRACO BES.pdf
[2011/11/23 14:58:27 | 000,372,873 | —- | C] () – C:\Documents and Settings\Weber\Desktop\TomatoPaste.pdf
[2011/11/20 21:06:26 | 002,647,208 | —- | C] () – C:\Documents and Settings\Weber\Desktop\Phillips 46 TV.divx
[2011/11/20 20:56:58 | 000,001,504 | —- | C] () – C:\Documents and Settings\Weber\Desktop\DivX Movies.lnk
[2011/11/20 20:56:24 | 000,000,777 | —- | C] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2011/11/20 20:55:28 | 000,001,757 | —- | C] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Converter.lnk
[2011/11/20 08:44:57 | 000,766,625 | —- | C] () – C:\Documents and Settings\Weber\Desktop\Steam Flaking.pdf
[2011/11/19 18:59:31 | 000,000,260 | —- | C] () – C:\WINDOWS\_delis32.ini
[2011/11/19 17:38:18 | 000,000,710 | —- | C] () – C:\Documents and Settings\Weber\Desktop\RegZooka.lnk
[2011/11/07 21:40:16 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
[2011/11/07 21:40:14 | 000,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2011/11/06 16:09:41 | 000,020,258 | —- | C] () – C:\Documents and Settings\Weber\My Documents\midec.htm
[2008/04/22 19:15:44 | 000,000,000 | —- | C] () – C:\WINDOWS\QuickInstall.INI
[2008/03/30 15:18:54 | 000,096,577 | —- | C] () – C:\WINDOWS\hpqins16.dat
[2008/03/07 20:08:38 | 000,000,020 | -H– | C] () – C:\WINDOWS\akebook.ini
[2008/03/07 20:08:38 | 000,000,004 | -H– | C] () – C:\WINDOWS\a3kebook.ini
[2008/03/07 20:08:37 | 000,000,059 | —- | C] () – C:\WINDOWS\ANS2000.INI
[2008/03/07 20:08:19 | 000,000,002 | —- | C] () – C:\WINDOWS\System32\Ciudadania 03-01-0732.dll
[2007/12/30 17:54:29 | 000,053,896 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2007/07/25 11:42:12 | 000,000,851 | —- | C] () – C:\Documents and Settings\Weber\Application Data\yahoo_ab.csv.234102703.xml
[2007/07/25 11:42:09 | 000,000,550 | —- | C] () – C:\Documents and Settings\Weber\Application Data\BCMMappings.xml
[2007/07/09 06:07:11 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2007/05/18 10:52:46 | 000,002,528 | —- | C] () – C:\Documents and Settings\Weber\Application Data\$_hpcst$.hpc
[2007/01/07 21:40:17 | 000,006,144 | —- | C] () – C:\Documents and Settings\Weber\Application Data\dvd.bmk
[2006/08/12 12:26:58 | 000,000,016 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2006/07/05 18:20:46 | 000,130,048 | —- | C] () – C:\Documents and Settings\Weber\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/07/05 18:20:09 | 000,003,350 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/07/05 18:20:09 | 000,000,088 | RHS- | C] () – C:\WINDOWS\System32\D3D51B9D40.sys
[2006/07/05 17:17:58 | 000,107,132 | —- | C] () – C:\WINDOWS\UninstallFirefox.exe
[2006/07/05 17:17:24 | 000,003,712 | —- | C] () – C:\WINDOWS\mozver.dat
[2006/07/05 17:06:52 | 000,000,128 | —- | C] () – C:\Documents and Settings\Weber\Local Settings\Application Data\fusioncache.dat
[2006/06/30 22:00:16 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/06/30 21:48:41 | 000,000,126 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/06/30 21:44:23 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2006/06/30 21:42:23 | 000,712,704 | —- | C] () – C:\WINDOWS\System32\DellSystemRestore.dll
[2006/06/30 21:38:29 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/06/30 21:36:07 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/06/30 21:11:10 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2006/06/30 21:10:48 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2006/06/30 21:10:44 | 000,000,392 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/08/10 12:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 12:07:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/10 12:02:15 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/10 12:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 11:57:52 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/10 11:57:15 | 000,277,352 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/10 11:51:21 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/10 11:51:20 | 000,402,426 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/10 11:51:20 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/10 11:51:20 | 000,062,032 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/10 11:51:20 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/10 11:51:18 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/10 11:51:17 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/10 11:51:16 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/10 11:51:12 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/10 11:51:11 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/10 11:51:05 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/10 11:50:56 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2003/01/07 14:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[1999/01/27 13:39:06 | 000,065,024 | —- | C] () – C:\WINDOWS\System32\indounin.dll
[1997/06/13 07:56:08 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll

========== LOP Check ==========

[2011/10/22 09:25:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2011/10/22 09:05:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avg7
[2007/01/28 14:47:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Babylon
[2011/10/22 09:17:41 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/11/19 08:48:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fighters
[2008/01/18 13:06:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HotSync
[2011/12/05 17:46:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2007/03/01 10:25:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2011/11/19 20:47:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/11/19 20:22:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2011/11/19 11:56:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2011/11/19 20:29:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2011/10/22 19:55:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Weber\Application Data\AVG
[2011/10/22 09:21:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Weber\Application Data\AVG2012
[2007/01/28 14:47:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Weber\Application Data\Babylon
[2011/11/20 21:05:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Weber\Application Data\DDMSettings
[2011/11/19 08:49:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Weber\Application Data\Fighters
[2008/09/20 09:12:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Weber\Application Data\Fisher-Price
[2006/12/17 19:42:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Weber\Application Data\FUJIFILM
[2008/10/11 21:30:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Weber\Application Data\HotSync
[2007/06/16 19:27:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Weber\Application Data\HTML Executable
[2006/07/17 09:51:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Weber\Application Data\Leadertech
[2007/07/26 22:54:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Weber\Application Data\LimeWire
[2011/11/19 19:15:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Weber\Application Data\MSNInstaller
[2011/11/19 08:46:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Weber\Application Data\NetAssistant
[2009/10/13 13:20:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Weber\Application Data\PlayFirst
[2008/05/07 12:32:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Weber\Application Data\Simple Star
[2008/10/11 21:26:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Weber\Application Data\SlipStream
[2007/03/10 11:40:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Weber\Application Data\Snapfish
[2011/12/05 20:52:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Weber\Application Data\uTorrent
[2007/07/06 17:46:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Weber\Application Data\Viewpoint

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/07/31 18:39:56 | 000,001,502 | —- | M] () – C:\ASLog.txt
[2004/08/10 12:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2006/07/05 17:06:27 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2011/11/19 19:12:16 | 000,003,785 | —- | M] () – C:\CD3rdPartyWrapper.log
[2004/08/10 12:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/06/30 21:18:38 | 000,006,020 | RH– | M] () – C:\dell.sdr
[2011/11/19 11:05:03 | 000,000,045 | —- | M] () – C:\error.log
[2011/12/05 20:33:04 | 534,827,008 | -HS- | M] () – C:\hiberfil.sys
[2006/07/06 16:26:02 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/10 12:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2006/06/30 21:39:46 | 000,000,835 | -H– | M] () – C:\IPH.PH
[2008/04/27 20:32:03 | 000,000,084 | —- | M] () – C:\lp.key
[2004/08/10 12:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 04:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 04:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2011/12/05 20:33:03 | 805,306,368 | -HS- | M] () – C:\pagefile.sys
[2007/06/20 07:22:03 | 000,000,000 | —- | M] () – C:\palsound.txt
[2008/08/15 21:45:24 | 000,008,192 | —- | M] () – C:\Shawn.cel
[2009/01/16 22:11:32 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2009/01/20 21:18:10 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2009/01/23 20:00:34 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2009/03/24 20:27:48 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2009/04/02 20:45:51 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2009/04/07 05:25:36 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2009/04/21 20:25:52 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2009/05/05 19:20:47 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2009/09/28 19:40:02 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2009/10/05 14:50:45 | 000,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2009/10/07 04:31:47 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2009/10/13 20:28:58 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2009/10/28 19:08:31 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2009/12/09 10:03:13 | 000,000,268 | -H– | M] () – C:\sqmdata13.sqm
[2009/12/14 19:47:49 | 000,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2009/12/14 20:21:38 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2009/12/16 20:41:43 | 000,000,268 | -H– | M] () – C:\sqmdata16.sqm
[2010/06/01 21:12:31 | 000,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2010/06/27 11:11:59 | 000,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2008/12/16 19:13:25 | 000,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2009/01/16 22:11:32 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/01/20 21:18:10 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/01/23 20:00:34 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/03/24 20:27:48 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/04/02 20:45:51 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/04/07 05:25:36 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/04/21 20:25:52 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/05/05 19:20:47 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/09/28 19:40:02 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/10/05 14:50:45 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/10/07 04:31:47 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/10/13 20:28:58 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/10/28 19:08:30 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/12/09 10:03:13 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/12/14 19:47:49 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/12/14 20:21:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/12/16 20:41:43 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2010/06/01 21:12:31 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2010/06/27 11:11:59 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2008/12/16 19:13:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2006/06/30 21:39:55 | 000,000,087 | —- | M] () – C:\SystemInfo.ini
[2011/10/22 08:07:54 | 000,000,026 | —- | M] () – C:\UpdaterforApp.ini
[2007/02/02 22:10:01 | 000,004,096 | -HS- | M] () – C:\VSNAP.IDX
[2011/11/19 20:31:11 | 000,000,150 | —- | M] () – C:\YServer.txt

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/10 12:03:42 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/10 11:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2004/08/10 11:56:46 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2004/08/10 11:56:46 | 000,872,448 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2004/08/10 12:04:12 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/07/05 17:07:06 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Weber\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/10 12:08:38 | 000,000,079 | —- | M] () – C:\Documents and Settings\Weber\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/11/10 20:30:05 | 006,283,632 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Weber\Desktop\Silverlight.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-12-06 02:27:28

========== Alternate Data Streams ==========

@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4

< End of report >

**********************************************

OTL Extras logfile created on: 12/5/2011 9:01:55 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Weber\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

509.98 Mb Total Physical Memory | 197.04 Mb Available Physical Memory | 38.64% Memory free
1.22 Gb Paging File | 0.73 Gb Available in Paging File | 59.86% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 108.59 Gb Total Space | 80.29 Gb Free Space | 73.94% Space Free | Partition Type: NTFS
Drive D: | 36.91 Gb Total Space | 0.27 Gb Free Space | 0.74% Space Free | Partition Type: NTFS

Computer Name: EVAN | User Name: Weber | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\utorrent\utorrent.exe" = C:\Program Files\utorrent\utorrent.exe:*:Enabled:µTorrent – ()
"C:\Program Files\Extended Systems\OneBridge Desktop Connector\DesktopConnector.exe" = C:\Program Files\Extended Systems\OneBridge Desktop Connector\DesktopConnector.exe:*:Enabled:DesktopConnector
"C:\Program Files\Bentley\Program\MicroStation\ustation.exe" = C:\Program Files\Bentley\Program\MicroStation\ustation.exe:*:Enabled:MicroStation for Windows x86 – (Bentley Systems, Inc.)
"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Philips\Wi-Fi MediaConnect\WFMCDMS.exe" = C:\Program Files\Philips\Wi-Fi MediaConnect\WFMCDMS.exe:*:Enabled:Wi-Fi DMS
"C:\Program Files\AVG\AVG2012\avgnsx.exe" = C:\Program Files\AVG\AVG2012\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgdiagex.exe" = C:\Program Files\AVG\AVG2012\avgdiagex.exe:*:Enabled:AVG Diagnostics 2012 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgemcx.exe" = C:\Program Files\AVG\AVG2012\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{1266764D-FC4F-4FA7-B63B-884D53B1680F}" = NetAssistant
"{14BEB6DF-A499-4A38-8E06-E173BCD5C087}" = ScannerCopy
"{17334AAF-C9E7-483B-9F45-E3FCAF07FFA7}" = Intel® PROSet for Wired Connections
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1AD5F465-8282-4DAD-B957-E09C0B783D18}" = InstantShare
"{1B680FBA-E317-4E93-AF43-3B59798A4BE0}" = Copy
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20FBC0A0-3160-4F14-83ED-3A74BB6B8C31}" = TrayApp
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216029FF}" = Java™ 6 Update 29
"{272EC8BA-5A08-4ea1-A189-684466A06B02}" = cp_dwShrek2Albums1
"{2E8428AD-6CD2-4031-916A-3CF9BBF2DEC9}" = Unload
"{3248F0A8-6813-11D6-A77B-00B0D0150030}" = J2SE Runtime Environment 5.0 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3762DB2D-71BD-421F-9E55-C74DA7DF4D07}" = CueTour
"{4667B940-BB01-428B-986E-A0CC46497BF7}" = ELIcon
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}" = Sonic Activation Module
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.5
"{5E8D588F-307C-4250-B622-26969027319A}" = PanoStandAlone
"{5F1ECD36-0DFA-4C58-830B-0F089083407F}" = AVG 2012
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{644D04A2-C682-4FD5-977D-03B804C4B9C5}" = CreativeProjects
"{646A65DD-23FC-418E-B9F0-E0500FB42CB1}" = PhotoGallery
"{68963635-14A4-48D9-B431-DF3A74D1AAE1}" = Destinations
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{700A6597-3CE6-49C1-AA75-846B24CDA66D}" = BufferChm
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{724517BD-1DE1-4986-BFCA-C1DFD379E3BC}" = cp_dwShrek2Cards1
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7AD25C9F-9957-4D1C-95EF-9BCD09F6D31B}" = HPSystemDiagnostics
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{80F28669-97B7-4CC9-B256-1F1BCFB7FDCF}" = AVG 2012
"{84CDF5A8-1D57-4B69-BAB6-1F11D8923375}" = SkinsHP1
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8BC3B99B-A6BE-4A0B-8535-B1B94BA4B1B1}" = DocProc
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91CA0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Small Business Edition 2003
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
"{A5B9D22C-755A-4AC6-9904-875E80838BB6}" = CP_AtenaShokunin1Config
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{AF363EA8-CB9F-40EC-90E0-A46AD9C78EB0}" = Laugh, Smile & Learn™
"{B911B811-BA3E-46D4-90F8-6F3338359651}" = Director
"{BA68600E-96D9-4E92-80F2-26B9681B5A63}" = Microsoft Office Outlook 2003 with Business Contact Manager Update
"{BCE72AED-3332-4863-9567-C5DCB9052CA2}" = Netflix Movie Viewer
"{C2EEB862-C767-11D5-8626-00C04F0134D4}_0" = Bentley MicroStation (V 08.00.00.21) - 1
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDFCF124-115F-4976-8BF4-08C89187A146}" = WebReg
"{CE0C8CC5-E396-442B-A50E-D1D374A9E820}" = DocumentViewer
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (MICROSOFTSMLBIZ)
"{E7A6ED40-F230-11D4-BBC4-00104B991322}" = VBA (2720)
"{FC22D020-3005-4715-8DF9-F3EDE81DEB3D}" = CreativeProjectsTemplates
"{FF8157AA-F640-45BD-B7C2-BAA1016B267A}" = palmOne
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AVG" = AVG 2012
"CCleaner" = CCleaner
"DivX Setup" = DivX Setup
"HP Photo & Imaging" = HP Image Zone 4.7
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox 8.0 (x86 en-US)" = Mozilla Firefox 8.0 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PROSet" = Intel® PRO Network Adapters and Drivers
"RegZooka" = RegZooka
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"NetAssistant 3.6.5" = NetAssistant for Firefox

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/7/2008 7:58:33 PM | Computer Name = EVAS | Source = Application Hang | ID = 1002
Description = Hanging application ustation.exe, version 8.0.0.21, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/9/2008 11:39:24 PM | Computer Name = EVAS | Source = Application Hang | ID = 1002
Description = Hanging application ustation.exe, version 8.0.0.21, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/13/2008 12:46:33 PM | Computer Name = EVAS | Source = Application Hang | ID = 1002
Description = Hanging application ustation.exe, version 8.0.0.21, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/15/2008 11:27:36 PM | Computer Name = EVAS | Source = Application Hang | ID = 1002
Description = Hanging application AcroRd32.exe, version 8.1.0.137, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/15/2008 11:27:36 PM | Computer Name = EVAS | Source = Application Hang | ID = 1002
Description = Hanging application AcroRd32.exe, version 8.1.0.137, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 9/15/2008 11:27:36 PM | Computer Name = EVAS | Source = Application Hang | ID = 1002
Description = Hanging application AcroRd32.exe, version 8.1.0.137, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 10/11/2008 11:51:55 AM | Computer Name = EVAS | Source = Application Hang | ID = 1002
Description = Hanging application ustation.exe, version 8.0.0.21, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 10/11/2008 11:25:40 PM | Computer Name = EVAS | Source = Application Hang | ID = 1002
Description = Hanging application iesetup.exe, version 7.0.5730.13, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 10/23/2008 8:27:32 PM | Computer Name = EVAS | Source = Windows Live Messenger | ID = 1000
Description =

Error - 11/3/2008 11:54:09 AM | Computer Name = EVAS | Source = Application Hang | ID = 1002
Description = Hanging application wmplayer.exe, version 11.0.5721.5145, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 11/19/2011 10:29:57 PM | Computer Name = EVAN | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 11/19/2011 10:29:57 PM | Computer Name = EVAN | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 11/19/2011 10:29:57 PM | Computer Name = EVAN | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 11/19/2011 10:29:57 PM | Computer Name = EVAN | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 11/19/2011 10:29:58 PM | Computer Name = EVAN | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 11/20/2011 9:59:30 AM | Computer Name = EVAN | Source = DCOM | ID = 10010
Description = The server {4EB61BAC-A3B6-4760-9581-655041EF4D69} did not register
with DCOM within the required timeout.

Error - 11/21/2011 6:51:44 PM | Computer Name = EVAN | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000001'
while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring
the volume.

Error - 11/25/2011 10:46:33 AM | Computer Name = EVAN | Source = DCOM | ID = 10010
Description = The server {4EB61BAC-A3B6-4760-9581-655041EF4D69} did not register
with DCOM within the required timeout.

Error - 11/28/2011 9:56:22 AM | Computer Name = EVAN | Source = DCOM | ID = 10010
Description = The server {4EB61BAC-A3B6-4760-9581-655041EF4D69} did not register
with DCOM within the required timeout.

Error - 12/2/2011 8:06:34 PM | Computer Name = EVAN | Source = Windows Update Agent | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Internet Explorer 8 for Windows XP.


< End of report >

*******************************************

HIJACKTHIS LOG

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:13:47 PM, on 12/5/2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\palmOne\Hotsync.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Weber\My Documents\Downloads\OTL.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Weber\My Documents\Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - Startup: palmOne Registration.lnk = C:\Program Files\palmOne\register.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &Search; - ?p=ZJfox000
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Translate with &Babylon; - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 8014 bytes

**********************************************

DDS.txt

.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 21:15:15.95 on Mon 12/05/2011
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_29
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.126 [GMT -6:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\palmOne\Hotsync.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
svchost.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Weber\My Documents\Downloads\OTL.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Weber\My Documents\Downloads\HiJackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Weber\My Documents\Downloads\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client;=dell-inc&channel;=us
uDefault_Search_URL = hxxp://www.google.com/ie
mDefault_Page_URL = hxxp://www.dell.com
mDefault_Search_URL = hxxp://www.google.com/ie
mSearch Page = hxxp://www.google.com
mStart Page = hxxp://www.dell.com
mSearch Bar = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: DivX Plus Web Player HTML5 : {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7018.1622\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\Wcescomm.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
StartupFolder: c:\docume~1\weber\startm~1\programs\startup\palmon~1.lnk - c:\program files\palmone\register.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palmone\Hotsync.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe
IE: &Search; - ?p=ZJfox000
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Translate with &Babylon; - c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll/Translate.htm
IE: {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE}
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\weber\applic~1\mozilla\firefox\profiles\fqeqwzyz.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.startup.homepage - hxxp://mail.google.com/mail/h/92u8q931cbbn/?zy=e&f;=1
FF - prefs.js: keyword.URL - hxxp://search.latam.msn.com/results.aspx?mkt=es-XL&FORM;=MICXAB&q;=
FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
.
—- FIREFOX POLICIES —-
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-7-11 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-9-13 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-7-11 230608]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-8-8 40016]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-7-11 295248]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-7-11 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-7-11 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-7-11 16720]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-10-23 135664]
S3 dfg;dfg;c:\windows\system32\drivers\dfg.sys [2011-10-21 23552]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-10-23 135664]
S3 USBNET_XP;Instant Wireless XP USB Network Adapter ver.2.6 Driver;c:\windows\system32\drivers\netusbxp.sys [2002-2-20 72576]
S3 WFMC_VAD;WFMC Virtual Audio Device (WDM);c:\windows\system32\drivers\wfmcvad.sys [2011-10-22 19328]
.
=============== Created Last 30 ================
.
2011-12-06 02:44:53 ——– d—–w- c:\program files\CCleaner
2011-11-27 21:35:26 ——– d—–w- c:\program files\MSECache
2011-11-21 03:05:16 ——– d—–w- c:\docume~1\weber\applic~1\DDMSettings
2011-11-21 02:54:20 ——– d—–w- c:\program files\common files\DivX Shared
2011-11-21 02:46:15 ——– d—–w- c:\docume~1\alluse~1\applic~1\DivX
2011-11-20 01:15:11 ——– d—–w- c:\docume~1\weber\applic~1\MSNInstaller
2011-11-20 00:35:54 ——– d—–w- c:\program files\DellSupport
2011-11-19 23:37:58 ——– d—–w- c:\program files\RegZooka
2011-11-19 14:49:46 ——– d—–w- c:\docume~1\weber\applic~1\Fighters
2011-11-19 14:48:30 ——– d—–w- c:\docume~1\alluse~1\applic~1\Fighters
2011-11-19 14:48:07 ——– d—–w- c:\program files\Free Offers from Freeze.com
2011-11-19 14:46:05 ——– d—–w- c:\docume~1\weber\applic~1\NetAssistant
2011-11-19 14:06:21 ——– d—–w- c:\program files\CyberDefender
2011-11-08 04:07:55 ——– d—–w- c:\windows\$SQLUninstallSQL2000-KB960082-v8.00.2055-x86-ENU$
2011-11-08 03:39:41 21504 —-a-w- c:\windows\system32\drivers\hidserv.dll
2011-11-08 03:37:44 ——– d—–w- c:\windows\ServicePackFiles
2011-11-07 00:10:41 215552 ——w- c:\windows\system32\dllcache\wordpad.exe
2011-11-07 00:06:34 470528 ——w- c:\windows\system32\dllcache\aclayers.dll
2011-11-07 00:05:42 743936 ——w- c:\windows\system32\dllcache\helpsvc.exe
2011-11-07 00:01:08 82432 ——w- c:\windows\system32\dllcache\fontsub.dll
2011-11-07 00:00:41 284160 ——w- c:\windows\system32\dllcache\pdh.dll
2011-11-07 00:00:40 60416 ——w- c:\windows\system32\dllcache\colbact.dll
2011-11-07 00:00:39 35328 ——w- c:\windows\system32\dllcache\sc.exe
2011-11-07 00:00:38 401408 ——w- c:\windows\system32\dllcache\rpcss.dll
2011-11-07 00:00:37 110592 ——w- c:\windows\system32\dllcache\services.exe
2011-11-07 00:00:35 473088 ——w- c:\windows\system32\dllcache\fastprox.dll
2011-11-07 00:00:35 227840 ——w- c:\windows\system32\dllcache\wmiprvse.exe
2011-11-07 00:00:31 617984 ——w- c:\windows\system32\dllcache\advapi32.dll
2011-11-07 00:00:30 715264 ——w- c:\windows\system32\dllcache\ntdll.dll
2011-11-06 23:59:02 153088 ——w- c:\windows\system32\dllcache\triedit.dll
2011-11-06 23:56:22 3555328 ——w- c:\windows\system32\dllcache\moviemk.exe
2011-11-06 23:49:18 655872 ——w- c:\windows\system32\dllcache\mstscax.dll
.
==================== Find3M ====================
.
2011-12-06 02:34:55 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-22 19:14:35 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-10-22 19:14:34 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-10-20 23:26:22 94208 —-a-w- c:\windows\system32\dpl100.dll
.
============= FINISH: 21:16:13.60 ===============
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———-

I apologize for the delay in response. As you can see we are very busy.
———-

Please run DDS once more so we can get a fresh look at your system. Save both of the logs created for your next reply.
———-


Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post the logs created by DDS and aswMBR. :)
Hi Jeff, Thanks for taking a look at my computer logs to see if I've got some malware/virus issues. I understand that it may not fix the computer, but I know it will not hurt to have a clean system. Here is the DDS log. I will post the next one in another reply. Thanks. . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 20:49:39.40 on Thu 12/08/2011 Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_29 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.55 [GMT -6:00] . AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ============== Running Processes =============== . C:\PROGRA~1\AVG\AVG2012\avgrsx.exe C:\Program Files\AVG\AVG2012\avgcsrvx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\AVG\AVG2012\avgtray.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\Program Files\DivX\DivX Update\DivXUpdate.exe C:\Program Files\Microsoft ActiveSync\Wcescomm.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\palmOne\Hotsync.exe C:\PROGRA~1\MI3AA1~1\rapimgr.exe svchost.exe C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe C:\Program Files\AVG\AVG2012\avgwdsvc.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\AVG\AVG2012\avgnsx.exe C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\Weber\My Documents\Downloads\OTL.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Weber\My Documents\Downloads\HiJackThis.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Documents and Settings\Weber\My Documents\Downloads\dds.scr . ============== Pseudo HJT Report =============== . uStart Page = hxxp://google.com/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us uDefault_Search_URL = hxxp://www.google.com/ie mDefault_Page_URL = hxxp://www.dell.com mDefault_Search_URL = hxxp://www.google.com/ie mSearch Page = hxxp://www.google.com mStart Page = hxxp://www.dell.com mSearch Bar = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: DivX Plus Web Player HTML5 : {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7018.1622\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\Wcescomm.exe" uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe" mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW StartupFolder: c:\docume~1\weber\startm~1\programs\startup\palmon~1.lnk - c:\program files\palmone\register.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palmone\Hotsync.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe IE: &Search - ?p=ZJfox000 IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: Translate with &Babylon - c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll/Translate.htm IE: {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\docume~1\weber\applic~1\mozilla\firefox\profiles\fqeqwzyz.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.startup.homepage - hxxp://mail.google.com/mail/h/92u8q931cbbn/?zy=e&f=1 FF - prefs.js: keyword.URL - hxxp://search.latam.msn.com/results.aspx?mkt=es-XL&FORM=MICXAB&q= FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll . —- FIREFOX POLICIES —- FF - user.js: yahoo.ytff.general.dontshowhpoffer - true ============= SERVICES / DRIVERS =============== . R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-7-11 23120] R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-9-13 32592] R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-7-11 230608] R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-8-8 40016] R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-7-11 295248] R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248] R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776] R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-7-11 134608] R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-7-11 24272] R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-7-11 16720] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-10-23 135664] S3 dfg;dfg;c:\windows\system32\drivers\dfg.sys [2011-10-21 23552] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-10-23 135664] S3 USBNET_XP;Instant Wireless XP USB Network Adapter ver.2.6 Driver;c:\windows\system32\drivers\netusbxp.sys [2002-2-20 72576] S3 WFMC_VAD;WFMC Virtual Audio Device (WDM);c:\windows\system32\drivers\wfmcvad.sys [2011-10-22 19328] . =============== Created Last 30 ================ . . ==================== Find3M ==================== . 2011-12-06 02:34:55 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-10-22 19:14:35 73728 —-a-w- c:\windows\system32\javacpl.cpl 2011-10-22 19:14:34 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-10-20 23:26:22 94208 —-a-w- c:\windows\system32\dpl100.dll . ============= FINISH: 20:51:27.25 ===============
Here is the next log. Thanks! aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-12-08 20:57:24 —————————– 20:57:24.500 OS Version: Windows 5.1.2600 Service Pack 2 20:57:24.500 Number of processors: 1 586 0x409 20:57:24.500 ComputerName: EVAN UserName: 20:57:25.843 Initialize success 20:58:15.937 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 20:58:15.937 Disk 0 Vendor: Maxtor_6L160P0 BAJ41G10 Size: 152587MB BusType: 3 20:58:17.953 Disk 0 MBR read successfully 20:58:17.953 Disk 0 MBR scan 20:58:17.953 Disk 0 unknown MBR code 20:58:17.953 Disk 0 scanning sectors +312496380 20:58:18.109 Disk 0 scanning C:\WINDOWS\system32\drivers 20:58:46.265 Service scanning 20:58:47.765 Modules scanning 20:58:59.781 Disk 0 trace - called modules: 20:58:59.812 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS 20:58:59.812 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x82fa5ab8] 20:58:59.812 3 CLASSPNP.SYS[f87b805b] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x82fd2d98] 20:58:59.812 Scan finished successfully 20:59:11.250 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Weber\My Documents\Whatthetech files\MBR.dat" 20:59:11.265 The log file has been saved successfully to "C:\Documents and Settings\Weber\My Documents\Whatthetech files\aswMBR.txt"
Hi Andreyta,

While I am looking over your DDS log please do the following

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.

[*]Be sure to disable your security programs



By that do you mean like AVG Anti-virus? Or what kind of security programs. Sorry if it's a dumb question. thanks

No no…there are no dumb questions here. Yes go ahead and disable any antivirus, antimalware and firewall programs while we run these tools. :) We need to make sure that the real-time protection does not interfere.
Here's the MBR log: Thanks! MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Home Edition Windows Information: Service Pack 2 (build 2600) Logical Drives Mask: 0x0000001c Kernel Drivers (total 130): 0x804D7000 \WINDOWS\system32\ntoskrnl.exe 0x806ED000 \WINDOWS\system32\hal.dll 0xF8C77000 \WINDOWS\system32\KDCOM.DLL 0xF8B87000 \WINDOWS\system32\BOOTVID.dll 0xF8728000 ACPI.sys 0xF8C79000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xF8717000 pci.sys 0xF8777000 isapnp.sys 0xF8D3F000 pciide.sys 0xF89F7000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xF8C7B000 intelide.sys 0xF8787000 MountMgr.sys 0xF86F8000 ftdisk.sys 0xF89FF000 PartMgr.sys 0xF8797000 VolSnap.sys 0xF86E0000 atapi.sys 0xF87A7000 disk.sys 0xF87B7000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xF86C0000 fltMgr.sys 0xF86AE000 sr.sys 0xF87C7000 PxHelp20.sys 0xF8697000 KSecDD.sys 0xF860A000 Ntfs.sys 0xF85DD000 NDIS.sys 0xF85C2000 Mup.sys 0xF8A07000 avgrkx86.sys 0xF8B8B000 AVGIDSEH.Sys 0xF8987000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xF849E000 \SystemRoot\system32\DRIVERS\ialmnt5.sys 0xF848A000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xF8AB7000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0xF8467000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xF8ABF000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xF8433000 \SystemRoot\system32\DRIVERS\HSFHWBS2.sys 0xF8410000 \SystemRoot\system32\DRIVERS\ks.sys 0xF8311000 \SystemRoot\system32\DRIVERS\HSF_DP.sys 0xF826A000 \SystemRoot\system32\DRIVERS\HSF_CNXT.sys 0xF8AC7000 \SystemRoot\System32\Drivers\Modem.SYS 0xF8244000 \SystemRoot\system32\DRIVERS\e100b325.sys 0xF8997000 \SystemRoot\system32\DRIVERS\serial.sys 0xF8C3B000 \SystemRoot\system32\DRIVERS\serenum.sys 0xF8230000 \SystemRoot\system32\DRIVERS\parport.sys 0xF89A7000 \SystemRoot\system32\DRIVERS\imapi.sys 0xF8ACF000 \SystemRoot\system32\drivers\Afc.sys 0xF89B7000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xF89C7000 \SystemRoot\system32\DRIVERS\redbook.sys 0xF81F0000 \SystemRoot\system32\drivers\smwdm.sys 0xF81CC000 \SystemRoot\system32\drivers\portcls.sys 0xF89D7000 \SystemRoot\system32\drivers\drmk.sys 0xF8119000 \SystemRoot\system32\drivers\senfilt.sys 0xF8EAB000 \SystemRoot\system32\DRIVERS\audstub.sys 0xF89E7000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xF8C43000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xF80BE000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xF87E7000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xF87F7000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xF8AD7000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xF80AD000 \SystemRoot\system32\DRIVERS\psched.sys 0xF8807000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xF8ADF000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xF8AE7000 \SystemRoot\system32\DRIVERS\raspti.sys 0xF8827000 \SystemRoot\system32\DRIVERS\termdd.sys 0xF8AEF000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xF8AF7000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xF8C9D000 \SystemRoot\system32\DRIVERS\swenum.sys 0xF8054000 \SystemRoot\system32\DRIVERS\update.sys 0xF8C53000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xF8877000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xF8897000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xF8CAB000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xF8581000 \SystemRoot\system32\drivers\MODEMCSA.sys 0xF8CAD000 \SystemRoot\System32\Drivers\i2omgmt.SYS 0xF88B7000 \SystemRoot\system32\DRIVERS\avgmfx86.sys 0xF8CAF000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF8EA9000 \SystemRoot\System32\Drivers\Null.SYS 0xF8CB1000 \SystemRoot\System32\Drivers\Beep.SYS 0xF8B1F000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xF8B27000 \SystemRoot\System32\drivers\vga.sys 0xF8CB3000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF8CB5000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF8B2F000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF8B37000 \SystemRoot\System32\Drivers\Npfs.SYS 0xF8569000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xEFED9000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xEFE81000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xEFE3A000 \SystemRoot\system32\DRIVERS\avgtdix.sys 0xEFE19000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xF88D7000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xEFDC9000 \SystemRoot\system32\DRIVERS\netbt.sys 0xEFDA7000 \SystemRoot\System32\drivers\afd.sys 0xF88E7000 \SystemRoot\system32\DRIVERS\netbios.sys 0xEFD7C000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xEFD0D000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xF88F7000 \SystemRoot\System32\Drivers\Fips.SYS 0xEFCD6000 \SystemRoot\system32\DRIVERS\avgldx86.sys 0xF8C2B000 \SystemRoot\system32\DRIVERS\hidusb.sys 0xF8907000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0xF8B57000 \SystemRoot\system32\DRIVERS\NuidFltr.sys 0xF8917000 \SystemRoot\system32\DRIVERS\WDFLDR.SYS 0xEFC5B000 \SystemRoot\system32\DRIVERS\Wdf01000.sys 0xF8C2F000 \SystemRoot\system32\DRIVERS\mouhid.sys 0xF8C33000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0xF8847000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xEFB7B000 \SystemRoot\System32\Drivers\dump_atapi.sys 0xF8CF5000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xEFBFF000 \SystemRoot\System32\drivers\Dxapi.sys 0xF8AA7000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xF8E8D000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF020000 \SystemRoot\System32\ialmdnt5.dll 0xBF012000 \SystemRoot\System32\ialmrnt5.dll 0xBF040000 \SystemRoot\System32\ialmdev5.DLL 0xBF070000 \SystemRoot\System32\ialmdd5.DLL 0xEFA7F000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xEF756000 \SystemRoot\system32\drivers\wdmaud.sys 0xEF89B000 \SystemRoot\system32\drivers\sysaudio.sys 0xEF454000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xEF833000 \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys 0xF8CD9000 \SystemRoot\system32\DRIVERS\dsunidrv.sys 0xEF903000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys 0xEF21D000 \SystemRoot\system32\DRIVERS\srv.sys 0xEF39C000 \SystemRoot\system32\DRIVERS\secdrv.sys 0xF8A3F000 \SystemRoot\system32\DRIVERS\AVGIDSFilter.Sys 0xEF06D000 \SystemRoot\system32\DRIVERS\AVGIDSDriver.Sys 0xEED84000 \SystemRoot\System32\Drivers\HTTP.sys 0xF8B17000 \??\C:\DOCUME~1\Weber\LOCALS~1\Temp\mbr.sys 0xEF7AB000 \??\C:\DOCUME~1\Weber\LOCALS~1\Temp\aswMBR.sys 0xEDE75000 \SystemRoot\system32\drivers\kmixer.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 43): 0 System Idle Process 4 System 540 C:\WINDOWS\system32\smss.exe 588 C:\PROGRA~1\AVG\AVG2012\avgrsx.exe 620 C:\Program Files\AVG\AVG2012\avgcsrvx.exe 816 csrss.exe 840 C:\WINDOWS\system32\winlogon.exe 888 C:\WINDOWS\system32\services.exe 900 C:\WINDOWS\system32\lsass.exe 1072 C:\WINDOWS\system32\svchost.exe 1140 svchost.exe 1236 C:\WINDOWS\system32\svchost.exe 1320 svchost.exe 1452 svchost.exe 1704 C:\WINDOWS\explorer.exe 1780 C:\WINDOWS\system32\spoolsv.exe 2020 C:\WINDOWS\system32\hkcmd.exe 2028 C:\WINDOWS\system32\igfxpers.exe 116 C:\Program Files\AVG\AVG2012\avgtray.exe 156 C:\Program Files\Analog Devices\Core\smax4pnp.exe 192 C:\Program Files\DivX\DivX Update\DivXUpdate.exe 208 C:\Program Files\Microsoft ActiveSync\wcescomm.exe 236 C:\WINDOWS\system32\ctfmon.exe 280 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe 316 C:\Program Files\palmOne\Hotsync.exe 352 C:\Program Files\Microsoft ActiveSync\rapimgr.exe 448 svchost.exe 468 C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe 572 C:\Program Files\AVG\AVG2012\avgwdsvc.exe 1224 C:\Program Files\Java\jre6\bin\jqs.exe 1268 C:\Program Files\Google\Update\GoogleUpdate.exe 1620 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE 1736 C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe 1932 C:\WINDOWS\system32\HPZipm12.exe 2068 C:\Program Files\AVG\AVG2012\avgnsx.exe 2080 C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe 2120 C:\WINDOWS\system32\svchost.exe 3396 alg.exe 3916 C:\WINDOWS\system32\svchost.exe 804 C:\WINDOWS\system32\wuauclt.exe 3768 C:\WINDOWS\system32\wuauclt.exe 956 C:\WINDOWS\system32\wscntfy.exe 372 C:\Documents and Settings\Weber\My Documents\Downloads\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`02738a00 (NTFS) \\.\D: –> \\.\PhysicalDrive0 at offset 0x0000001b`27f4c800 (NTFS) PhysicalDrive0 Model Number: Maxtor6L160P0, Rev: BAJ41G10 Size Device Name MBR Status ——————————————– 149 GB \\.\PhysicalDrive0 Dell MBR code detected SHA1: 57BDF501CE769EF2720C705B6C71C893DA31574E Done!
Hi Andreyta,

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
———-
here's the combofix log:

ComboFix 11-12-11.02 - Weber 12/11/2011 20:01:46.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.199 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Weber\WINDOWS
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\system32\drivers\dfg.sys
.
Infected copy of c:\windows\system32\kernel32.dll was found and disinfected
Restored copy from - c:\windows\$hf_mig$\KB959426\SP3GDR\kernel32.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Service_dfg
.
.
((((((((((((((((((((((((( Files Created from 2011-11-12 to 2011-12-12 )))))))))))))))))))))))))))))))
.
.
2011-12-06 02:44 . 2011-12-06 02:44 ——– d—–w- c:\program files\CCleaner
2011-11-27 21:35 . 2011-11-27 21:35 ——– d—–w- c:\program files\MSECache
2011-11-21 03:05 . 2011-11-21 03:05 ——– d—–w- c:\documents and settings\Weber\Application Data\DDMSettings
2011-11-21 02:54 . 2011-11-21 02:55 ——– d—–w- c:\program files\Common Files\DivX Shared
2011-11-21 02:46 . 2011-11-21 02:56 ——– d—–w- c:\documents and settings\All Users\Application Data\DivX
2011-11-20 02:15 . 2011-11-20 02:15 ——– d—–w- c:\documents and settings\Weber\Application Data\InstallShield
2011-11-20 01:15 . 2011-11-20 01:15 ——– d—–w- c:\documents and settings\Weber\Application Data\MSNInstaller
2011-11-20 00:36 . 2011-11-20 00:37 ——– d–h–w- c:\documents and settings\Weber\Application Data\GTek
2011-11-20 00:35 . 2011-11-20 00:36 ——– d—–w- c:\program files\DellSupport
2011-11-19 23:37 . 2011-11-20 00:04 ——– d—–w- c:\program files\RegZooka
2011-11-19 14:49 . 2011-11-19 14:49 ——– d—–w- c:\documents and settings\Weber\Application Data\Fighters
2011-11-19 14:48 . 2011-11-19 14:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Fighters
2011-11-19 14:48 . 2011-11-19 14:48 ——– d—–w- c:\program files\Free Offers from Freeze.com
2011-11-19 14:46 . 2011-11-19 14:46 ——– d—–w- c:\documents and settings\Weber\Application Data\NetAssistant
2011-11-19 14:06 . 2011-11-19 14:06 ——– d—–w- c:\program files\CyberDefender
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-06 02:34 . 2011-10-23 12:55 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-22 19:14 . 2007-05-23 14:19 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-10-22 19:14 . 2011-10-22 19:15 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-10-20 23:26 . 2011-10-20 23:26 94208 —-a-w- c:\windows\system32\dpl100.dll
2011-10-07 11:23 . 2011-07-11 06:13 230608 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2011-10-04 11:21 . 2011-07-11 06:14 16720 —-a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-09-13 11:30 . 2011-09-13 11:30 32592 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2011-11-09 14:45 . 2011-10-22 19:06 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 1289000]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-30 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-04-06 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-06 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-04-06 114688]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-10-25 2415456]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-15 1404928]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
.
c:\documents and settings\Weber\Start Menu\Programs\Startup\
palmOne Registration.lnk - c:\program files\palmOne\register.exe [2005-2-22 2301952]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HotSync Manager.lnk - c:\program files\palmOne\Hotsync.exe [2004-6-9 471040]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-4 258048]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-4 53248]
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-5-3 81920]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\utorrent\\utorrent.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bentley\\Program\\MicroStation\\ustation.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [7/11/2011 12:14 AM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/13/2011 5:30 AM 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [7/11/2011 12:13 AM 230608]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [7/11/2011 12:14 AM 295248]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 5:09 AM 192776]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/23/2011 7:13 PM 135664]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [10/12/2011 5:25 AM 4433248]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [7/11/2011 12:14 AM 134608]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [7/11/2011 12:14 AM 24272]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [7/11/2011 12:14 AM 16720]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/23/2011 7:13 PM 135664]
S3 USBNET_XP;Instant Wireless XP USB Network Adapter ver.2.6 Driver;c:\windows\system32\drivers\netusbxp.sys [2/20/2002 1:34 AM 72576]
S3 WFMC_VAD;WFMC Virtual Audio Device (WDM);c:\windows\system32\drivers\wfmcvad.sys [10/22/2011 6:59 PM 19328]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.com/
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.dell.com
mSearch Bar = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Translate with &Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
TCP: DhcpNameServer = [removed] [removed] 192.168.1.1
FF - ProfilePath - c:\documents and settings\Weber\Application Data\Mozilla\Firefox\Profiles\fqeqwzyz.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://mail.google.com/mail/h/92u8q931cbbn/?zy=e&f=1
FF - prefs.js: keyword.URL - hxxp://search.latam.msn.com/results.aspx?mkt=es-XL&FORM=MICXAB&q=
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - ORPHANS REMOVED - - - -
.
Notify-WgaLogon - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-11 20:12
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Enum\USB]
@DACL=(02 0000)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3608)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\progra~1\AVG\AVG2012\avgrsx.exe
c:\program files\AVG\AVG2012\avgcsrvx.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
c:\program files\HP\Digital Imaging\bin\hpqgalry.exe
c:\program files\AVG\AVG2012\avgnsx.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2011-12-11 20:16:38 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-12 02:16
.
Pre-Run: 85,789,450,240 bytes free
Post-Run: 85,660,954,624 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - AC31EFACD30FDD65D9D6C7BAB04AAD56
Hi Andreyta,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    DDS::
    uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
    IE: Translate with &Babylon - c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll/Translate.htm
    IE: {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE}
    IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
    
    Firefox::
    FF - ProfilePath - c:\docume~1\weber\applic~1\mozilla\firefox\profiles\fqeqwzyz.default\
    FF - prefs.js: keyword.URL - hxxp://search.latam.msn.com/results.aspx?mkt=es-XL&FORM=MICXAB&q=
    
    Folder::
    c:\program files\Free Offers from Freeze.com
    c:\program files\CyberDefender
    c:\documents and settings\Weber\Application Data\NetAssistant
    
    Registry::
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3389:TCP"=-
    "26675:TCP"=-
    
    RegLock::
    [HKEY_LOCAL_MACHINE\System\ControlSet001\Enum\USB]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
ComboFix 11-12-11.02 - Weber 12/12/2011 20:10:51.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.298 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Weber\Desktop\CFScript.txt
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Weber\Application Data\NetAssistant
c:\documents and settings\Weber\Application Data\NetAssistant\chrome.manifest
c:\documents and settings\Weber\Application Data\NetAssistant\chrome\content\keywordsearch.js
c:\documents and settings\Weber\Application Data\NetAssistant\chrome\content\netassistant.js
c:\documents and settings\Weber\Application Data\NetAssistant\chrome\content\netassistant.xul
c:\documents and settings\Weber\Application Data\NetAssistant\chrome\content\netError.xhtml
c:\documents and settings\Weber\Application Data\NetAssistant\chrome\content\ns_errors.js
c:\documents and settings\Weber\Application Data\NetAssistant\chrome\content\parseuri.js
c:\documents and settings\Weber\Application Data\NetAssistant\chrome\content\preferences.js
c:\documents and settings\Weber\Application Data\NetAssistant\chrome\content\tabsearch.js
c:\documents and settings\Weber\Application Data\NetAssistant\defaults\preferences\netassistant.js
c:\documents and settings\Weber\Application Data\NetAssistant\install.rdf
c:\program files\CyberDefender
c:\program files\CyberDefender\Registry Cleaner\KillCDRCProcesses.exe
c:\program files\Free Offers from Freeze.com
c:\program files\Free Offers from Freeze.com\6866.url
c:\program files\Free Offers from Freeze.com\6881.url
c:\program files\Free Offers from Freeze.com\6884.url
c:\program files\Free Offers from Freeze.com\control.txt
c:\program files\Free Offers from Freeze.com\dolphinico.ico
c:\program files\Free Offers from Freeze.com\games.ico
c:\program files\Free Offers from Freeze.com\musicoasis.ico
.
.
((((((((((((((((((((((((( Files Created from 2011-11-13 to 2011-12-13 )))))))))))))))))))))))))))))))
.
.
2011-12-06 02:44 . 2011-12-06 02:44 ——– d—–w- c:\program files\CCleaner
2011-11-27 21:35 . 2011-11-27 21:35 ——– d—–w- c:\program files\MSECache
2011-11-21 03:05 . 2011-11-21 03:05 ——– d—–w- c:\documents and settings\Weber\Application Data\DDMSettings
2011-11-21 02:54 . 2011-11-21 02:55 ——– d—–w- c:\program files\Common Files\DivX Shared
2011-11-21 02:46 . 2011-11-21 02:56 ——– d—–w- c:\documents and settings\All Users\Application Data\DivX
2011-11-20 02:15 . 2011-11-20 02:15 ——– d—–w- c:\documents and settings\Weber\Application Data\InstallShield
2011-11-20 01:15 . 2011-11-20 01:15 ——– d—–w- c:\documents and settings\Weber\Application Data\MSNInstaller
2011-11-20 00:36 . 2011-11-20 00:37 ——– d–h–w- c:\documents and settings\Weber\Application Data\GTek
2011-11-20 00:35 . 2011-11-20 00:36 ——– d—–w- c:\program files\DellSupport
2011-11-19 23:37 . 2011-11-20 00:04 ——– d—–w- c:\program files\RegZooka
2011-11-19 14:49 . 2011-11-19 14:49 ——– d—–w- c:\documents and settings\Weber\Application Data\Fighters
2011-11-19 14:48 . 2011-11-19 14:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Fighters
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-06 02:34 . 2011-10-23 12:55 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-22 19:14 . 2007-05-23 14:19 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-10-22 19:14 . 2011-10-22 19:15 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-10-20 23:26 . 2011-10-20 23:26 94208 —-a-w- c:\windows\system32\dpl100.dll
2011-10-07 11:23 . 2011-07-11 06:13 230608 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2011-10-04 11:21 . 2011-07-11 06:14 16720 —-a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-11-09 14:45 . 2011-10-22 19:06 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 1289000]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-30 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-04-06 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-06 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-04-06 114688]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-10-25 2415456]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-15 1404928]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\utorrent\\utorrent.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bentley\\Program\\MicroStation\\ustation.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-10-24 135664]
R3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-10-24 135664]
R3 USBNET_XP;Instant Wireless XP USB Network Adapter ver.2.6 Driver;c:\windows\system32\DRIVERS\netusbxp.sys [2002-02-20 72576]
R3 WFMC_VAD;WFMC Virtual Audio Device (WDM);c:\windows\system32\DRIVERS\wfmcvad.sys [2010-02-08 19328]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2011-07-11 23120]
S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [2011-09-13 32592]
S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [2011-10-07 230608]
S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2011-07-11 295248]
S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [2011-07-11 134608]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [2011-07-11 24272]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\AVGIDSShim.Sys [2011-10-04 16720]
.
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.com/
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://www.dell.com
mSearch Bar = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed] 192.168.1.1
FF - ProfilePath - c:\documents and settings\Weber\Application Data\Mozilla\Firefox\Profiles\fqeqwzyz.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://mail.google.com/mail/h/92u8q931cbbn/?zy=e&f=1
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-12 20:19
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2011-12-12 20:21:21
ComboFix-quarantined-files.txt 2011-12-13 02:21
ComboFix2.txt 2011-12-12 02:16
.
Pre-Run: 85,695,877,120 bytes free
Post-Run: 85,678,465,024 bytes free
.
- - End Of File - - 3DEA6088DD21482F70EF13671697267A
Hi Andreyta,

P2P - I see you have P2P software uTorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections and possibly Identity Theft. It likely contributed to your current situation. This page will give you further information.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.
——————

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.


The log can also be found here:
C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
———-

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/
———-

In your next reply please post the logs created by Malwarebytes and ESET online scanner. :)
Hi Jeff, I open up the control panel, but I do not see that program, Utorrent listed? I don't recall having that program on this computer, but this used to belong to my parents and they gave the computer to us. I'll run the scanners and post later. Thanks!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI