This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan on my Computer [Solved]

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

When running "MalwareBytes Anti-Malware," it detects the following trojan on my computer:


Registry Keys Detected: 1
HKCU\Software\Microsoft\Windows\CurrentVersion\Run (Trojan.Agent)



And while "MalwareBytes Anti-Malware" says it "Quarantined and deleted successfully."

The same trojan keeps appearing on repeated "MalwareBytes Anti-Malware" scans.



So I'm here. I ran HijackThis. Thanks in advance. Here is my HijackThis log:







Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:40:52 PM, on 6/15/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17110)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Secunia\PSI\PSIA.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb06.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Secunia\PSI\psi_tray.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?fr=mcafee&p=%s%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1:9421;
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
N3 - Netscape 7: # Mozilla User Preferences

/* Do not edit this file.
*
* If you make changes to this file while the browser is running,
* the changes will be overwritten when the browser exits.
*
* To make a manual change to preferences, you can visit the URL about:config
* For more information, see http://www.mozilla.org/unix/customizing.html#prefs
*/

user_pref("BillyJC00l.aim.general.im.enterCR", false);
user_pref("BillyJC00l.aim.general.im.smilies", true);
user_pref("BillyJC00l.aim.general.im.tabKey", false);
user_pref("BillyJC00l.aim.general.im.timeStamp", false);
user_pref("BillyJC00l.aim.general.snsautosignon", false);
user_pref("BillyJC00l.aim.general.today", true);
user_pref("BillyJC00l.aim.mail.presence", true);
user_pref("aim.session.screenname", "BillyJC00l");
user_pref("browser.activation.checkedNNFlag", true);
user_pref("browser.bookmarks.added_static_root", true);
user_pref("browser.cache.disk.parent_directory", "C:\\DOCUMENTS AND SETTINGS\\IKE\\APPLICATION DATA\\Mozilla\\Prof
N3 - Netscape 7: # Mozilla User Preferences

/* Do not edit this file.
*
* If you make changes to this file while the browser is running,
* the changes will be overwritten when the browser exits.
*
* To make a manual change to preferences, you can visit the URL about:config
* For more information, see http://www.mozilla.org/unix/customizing.html#prefs
*/

user_pref("BillyJC00l.aim.general.im.enterCR", false);
user_pref("BillyJC00l.aim.general.im.smilies", true);
user_pref("BillyJC00l.aim.general.im.tabKey", false);
user_pref("BillyJC00l.aim.general.im.timeStamp", false);
user_pref("BillyJC00l.aim.general.snsautosignon", false);
user_pref("BillyJC00l.aim.general.today", true);
user_pref("BillyJC00l.aim.mail.presence", true);
user_pref("aim.session.screenname", "BillyJC00l");
user_pref("browser.activation.checkedNNFlag", true);
user_pref("browser.bookmarks.added_static_root", true);
user_pref("browser.cache.disk.parent_directory", "C:\\DOCUMENTS AND SETTINGS\\IKE\\APPLICATION DATA\\Mozilla\\Prof
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O2 - BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Anonymizer 2005 Toolbar - {DB264E15-F83B-4603-BFC1-4EA7E3204686} - C:\Program Files\Anonymizer\Anon2005\AnonIEBar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [WrtMon.exe] C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
O4 - HKLM\..\Run: [ScanSoft OmniPage SE 4.0-reminder] "C:\Program Files\ScanSoft\OmniPageSE4.0\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\OmniPageSE4.0\Ereg\ereg.ini"
O4 - HKLM\..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [QuickTime Task] "C:\application files\multimedia\video\quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Secunia PSI Tray.lnk = C:\Program Files\Secunia\PSI\psi_tray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler Options - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01010200-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Installer) - http://supportcenter.rr.com/sdccommon/download/tgctlins.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/distribution/al…x-w32-2.0.3.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1135806761620
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1135807830562
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files\Secunia\PSI\PSIA.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WD Drive Manager Service (WDBtnMgrSvc.exe) - WDC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe

–
End of file - 12603 bytes
Hi ike001, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    consrv.dll
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Download aswMBR.exe to your desktop.

Double click the aswMBR.exe to run it. If asked to download Avast's database please do so.

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.

Please post back with
  • both OTL log
  • aswMBR og
  • mbr.zip (attached)
Hello oldman960,

Thank you for your help!


Here is my OTL.txt file:

OTL logfile created on: 6/17/2012 2:21:40 PM - Run 1
OTL by OldTimer - Version 3.2.49.0 Folder = C:\Documents and Settings\Ike\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.94 Gb Total Physical Memory | 1.49 Gb Available Physical Memory | 76.91% Memory free
2.07 Gb Paging File | 1.72 Gb Available in Paging File | 83.19% Paging File free
Paging file location(s): C:\pagefile.sys 288 576 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 93.16 Gb Total Space | 31.44 Gb Free Space | 33.75% Space Free | Partition Type: NTFS
Drive D: | 149.05 Gb Total Space | 41.31 Gb Free Space | 27.72% Space Free | Partition Type: NTFS

Computer Name: BUD | User Name: Ike | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Ike\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\Secunia\PSI\psia.exe (Secunia)
PRC - C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe (WDC)
PRC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe (WDC)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe ()
PRC - C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe (ScanSoft, Inc.)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe ()
PRC - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)
PRC - C:\WINDOWS\system32\VTTimer.exe (S3 Graphics, Inc.)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (McAfee SiteAdvisor Service) – c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (Secunia PSI Agent) – C:\Program Files\Secunia\PSI\psia.exe (Secunia)
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (vsmon) – C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (WDBtnMgrSvc.exe) – C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe (WDC)
SRV - (W3SVC) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (IISADMIN) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (ColdFusion MX 7 Application Server) – C:\CFusionMX7\runtime\bin\jrunsvc.exe (Macromedia Inc.)
SRV - (APC UPS Service) – C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)
SRV - (ColdFusion MX 7 Search Server) – C:\CFusionMX7\verity\k2\_nti40\bin\k2admin.exe (Verity, Inc.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (MySql) – C:/mysql/bin/mysqld-nt.exe ()
SRV - (ColdFusion MX 7 ODBC Server) – C:\CFusionMX7\db\slserver54\bin\swstrtr.exe ()
SRV - (ColdFusion MX 7 ODBC Agent) – C:\CFusionMX7\db\slserver54\bin\swagent.exe ()
SRV - (MSSQLServer) – C:\MSSQL7\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLServerAgent) – C:\MSSQL7\Binn\sqlagent.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (srescan) – system32\ZoneLabs\srescan.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (AVGIDSHX) – C:\WINDOWS\system32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\avgidsfilterx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o. )
DRV - (KeyScrambler) – C:\WINDOWS\system32\drivers\keyscrambler.sys (QFX Software Corporation)
DRV - (PSI) – C:\WINDOWS\system32\drivers\psi_mf.sys (Secunia)
DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (ggsemc) – C:\WINDOWS\system32\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV - (ggflt) – C:\WINDOWS\system32\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV - (WDC_SAM) – C:\WINDOWS\system32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (a016obex) – C:\WINDOWS\system32\drivers\a016obex.sys (MCCI Corporation)
DRV - (a016mdm) – C:\WINDOWS\system32\drivers\a016mdm.sys (MCCI Corporation)
DRV - (a016mgmt) Sony Ericsson Device A016 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\a016mgmt.sys (MCCI Corporation)
DRV - (a016mdfl) – C:\WINDOWS\system32\drivers\a016mdfl.sys (MCCI Corporation)
DRV - (a016bus) Sony Ericsson Device A016 driver (WDM) – C:\WINDOWS\system32\drivers\a016bus.sys (MCCI Corporation)
DRV - (s115mgmt) Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s115mgmt.sys (MCCI Corporation)
DRV - (s115obex) – C:\WINDOWS\system32\drivers\s115obex.sys (MCCI Corporation)
DRV - (s115mdm) – C:\WINDOWS\system32\drivers\s115mdm.sys (MCCI Corporation)
DRV - (s115mdfl) – C:\WINDOWS\system32\drivers\s115mdfl.sys (MCCI Corporation)
DRV - (s115bus) Sony Ericsson Device 115 driver (WDM) – C:\WINDOWS\system32\drivers\s115bus.sys (MCCI Corporation)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ALCXSENS) – C:\WINDOWS\system32\drivers\ALCXSENS.SYS (Sensaura)
DRV - (RTL8023) – C:\WINDOWS\system32\drivers\Rtlnic51.sys (Realtek Semiconductor Corporation )
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\rtl8139.sys (Realtek Semiconductor Corporation)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (USBCM) – C:\WINDOWS\system32\drivers\Sacm2A.sys ( )
DRV - (viaagp1) – C:\WINDOWS\system32\drivers\VIAAGP1.SYS (VIA Technologies, Inc.)
DRV - (crlscsi) – C:\WINDOWS\System32\drivers\crlscsi.sys (Corel Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {DECA3892-BA8F-44b8-A993-A466AD694AE4}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…age={startPage}
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo.com/search?fr=mcafee&p;={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.startup.homepage: "D:\\Data Files\\Work Files\\WebsiteFiles\\HomePage\\Home.htm"
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20090920.2
FF - prefs.js..extensions.enabledItems:
FF - prefs.js..extensions.enabledItems:
FF - prefs.js..extensions.enabledItems:
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3
FF - prefs.js..extensions.enabledItems:
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=mcafee&p;="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nosltd.com/getPlus+®,version=1.6.2.102: C:\Program Files\NOS\bin\np_gp.dll (NOS Microsystems Ltd.)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2536: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2594: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1698: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012/02/05 00:39:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG2012\Firefox\ [2012/06/08 03:20:57 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012/06/11 12:49:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files\AVG\AVG2012\Firefox\DoNotTrack\ [2012/06/08 03:20:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/06/05 22:59:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/06/08 12:56:22 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Netscape 7.1\Extensions\\Components: c:\Application Files\Internet\NewsReaders\Netscape\Components [2009/03/30 20:41:58 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Netscape 7.1\Extensions\\Plugins: c:\Application Files\Internet\NewsReaders\Netscape\Plugins [2012/06/16 00:41:13 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Netscape 7.1\Extensions\\Components: c:\Application Files\Internet\NewsReaders\Netscape\Components [2009/03/30 20:41:58 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Netscape 7.1\Extensions\\Plugins: c:\Application Files\Internet\NewsReaders\Netscape\Plugins [2012/06/16 00:41:13 | 000,000,000 | —D | M]

[2009/11/21 15:24:03 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Ike\Application Data\Mozilla\Extensions
[2009/11/21 15:24:03 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Ike\Application Data\Mozilla\Extensions\[removed]
[2011/03/07 10:33:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Ike\Application Data\Mozilla\Firefox\Profiles\xaac7lao.default\extensions
[2009/07/23 21:07:16 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Ike\Application Data\Mozilla\Firefox\Profiles\xaac7lao.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/11/13 20:05:07 | 000,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\Ike\Application Data\Mozilla\Firefox\Profiles\xaac7lao.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2012/06/16 00:41:14 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/04/15 18:43:04 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/06/10 15:06:06 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2012/06/08 12:56:24 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA}
[2012/06/16 00:41:15 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/06/08 12:56:06 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012/02/05 00:39:43 | 000,000,000 | —D | M] (McAfee SiteAdvisor) – C:\PROGRAM FILES\MCAFEE\SITEADVISOR
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2008/06/17 20:43:04 | 000,086,016 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2010/11/26 09:55:52 | 000,002,024 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml

O1 HOSTS File: ([2011/07/15 19:25:11 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (KeyScramblerBHO Class) - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll File not found
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Anonymizer 2005 Toolbar) - {DB264E15-F83B-4603-BFC1-4EA7E3204686} - C:\Program Files\Anonymizer\Anon2005\AnonIEBar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Anonymizer 2005 Toolbar) - {DB264E15-F83B-4603-BFC1-4EA7E3204686} - C:\Program Files\Anonymizer\Anon2005\AnonIEBar.dll ()
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb06.exe (HP)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [ScanSoft OmniPage SE 4.0-reminder] C:\Program Files\ScanSoft\OmniPageSE4.0\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)
O4 - HKLM..\Run: [VTTrayp] C:\WINDOWS\System32\VTTrayp.exe (S3 Graphics Co., Ltd.)
O4 - HKLM..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe (WDC)
O4 - HKLM..\Run: [WrtMon.exe] C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe ()
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk = C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
O4 - Startup: C:\Documents and Settings\Ike\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : &KeyScrambler; Options - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O16 - DPF: {01010200-5E80-11D8-9E86-0007E96C65AE} http://supportcenter.rr.com/sdccommon/download/tgctlins.cab (SupportSoft Installer)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} http://www.alternatiff.com/distribution/al…x-w32-2.0.3.cab (AlternaTIFF ActiveX)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/5/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab (Yahoo! Audio Conferencing)
O16 - DPF: {3253344D-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/mpg4sax.cab (Reg Error: Key error.)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1135806761620 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1135807830562 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} http://chat.yahoo.com/cab/yacsui.cab (Yahoo! Audio UI1)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} http://acs.pandasoftware.com/activescan/as5free/asinst.cab (ActiveScan Installer Class)
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} Reg Error: Key error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files\Qualcomm\Eudora\EuShlExt.dll (Qualcomm Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/12/28 11:41:55 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/06/17 13:25:18 | 004,731,392 | —- | C] (AVAST Software) – C:\Documents and Settings\Ike\Desktop\aswMBR.exe
[2012/06/17 13:23:44 | 000,595,968 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Ike\Desktop\OTL.exe
[2012/06/16 00:41:13 | 000,157,448 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/06/16 00:41:13 | 000,149,256 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/06/16 00:41:13 | 000,149,256 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/06/15 22:39:25 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2012/06/15 22:39:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Ike\Start Menu\Programs\HiJackThis
[2012/06/15 20:40:11 | 000,607,260 | R— | C] (Swearware) – C:\Documents and Settings\Ike\Desktop\dds.scr
[2012/06/12 11:06:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Ike\Application Data\QFX Software
[2012/06/12 11:06:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\QFX Software
[2012/06/12 11:02:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\KeyScrambler
[2012/06/12 11:02:26 | 000,173,880 | —- | C] (QFX Software Corporation) – C:\WINDOWS\System32\drivers\keyscrambler.sys
[2012/06/12 11:02:26 | 000,000,000 | —D | C] – C:\Program Files\KeyScrambler
[2012/06/12 10:51:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Ike\Application Data\FK_Monitor
[2012/06/12 10:51:28 | 000,000,000 | —D | C] – C:\Program Files\FK_Monitor
[2012/06/11 12:49:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG
[2012/06/08 12:56:22 | 000,476,936 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\npdeployJava1.dll
[2012/06/08 03:22:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Ike\Application Data\AVG2012
[2012/06/08 03:21:49 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2012/06/08 03:20:49 | 000,000,000 | -H-D | C] – C:\$AVG
[2012/06/08 03:20:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2012/06/08 03:20:49 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\AVG
[2012/06/08 03:19:53 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2012/06/08 03:15:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2012/06/08 02:48:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2012/06/03 04:17:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/06/03 04:17:54 | 000,022,344 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012/06/03 04:17:54 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/06/03 03:38:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Ike\Local Settings\Application Data\Secunia PSI
[2012/06/03 03:38:04 | 000,000,000 | —D | C] – C:\Program Files\Secunia

========== Files - Modified Within 30 Days ==========

[2012/06/17 14:14:05 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/06/17 14:13:20 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2012/06/17 14:12:56 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/06/17 14:12:55 | 2078,855,168 | -HS- | M] () – C:\hiberfil.sys
[2012/06/17 13:25:17 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\Ike\Desktop\aswMBR.exe
[2012/06/17 13:23:44 | 000,595,968 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Ike\Desktop\OTL.exe
[2012/06/17 11:03:25 | 100,539,838 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/06/17 00:28:50 | 000,002,709 | —- | M] () – C:\WINDOWS\SOLFIRE4.INI
[2012/06/15 22:40:14 | 000,002,445 | —- | M] () – C:\Documents and Settings\Ike\Desktop\HiJackThis.lnk
[2012/06/15 22:19:55 | 001,402,880 | —- | M] () – C:\Documents and Settings\Ike\Desktop\HiJackThis.msi
[2012/06/15 20:40:11 | 000,607,260 | R— | M] (Swearware) – C:\Documents and Settings\Ike\Desktop\dds.scr
[2012/06/13 21:25:38 | 000,002,497 | —- | M] () – C:\Documents and Settings\Ike\Desktop\Microsoft Office Word 2003.lnk
[2012/06/13 12:59:54 | 000,298,704 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/06/13 12:52:48 | 000,492,562 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/06/13 12:52:48 | 000,085,594 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/06/13 12:38:37 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/06/11 20:30:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/06/11 12:49:14 | 000,000,702 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2012/06/10 08:13:14 | 000,034,764 | —- | M] () – C:\Documents and Settings\Ike\Local Settings\Application Data\dt.dat
[2012/06/08 03:05:55 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2012/06/08 02:07:53 | 000,000,281 | -HS- | M] () – C:\boot.ini
[2012/06/03 04:17:58 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/03 03:38:15 | 000,000,753 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/05/31 03:22:09 | 000,599,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\crypt32.dll
[2012/05/21 21:35:26 | 000,419,488 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/05/21 21:35:26 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl

========== Files Created - No Company Name ==========

[2012/06/17 11:03:25 | 100,539,838 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/06/15 22:39:25 | 000,002,445 | —- | C] () – C:\Documents and Settings\Ike\Desktop\HiJackThis.lnk
[2012/06/15 22:19:55 | 001,402,880 | —- | C] () – C:\Documents and Settings\Ike\Desktop\HiJackThis.msi
[2012/06/12 11:57:21 | 2078,855,168 | -HS- | C] () – C:\hiberfil.sys
[2012/06/10 08:13:14 | 000,034,764 | —- | C] () – C:\Documents and Settings\Ike\Local Settings\Application Data\dt.dat
[2012/06/08 03:21:37 | 000,000,702 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2012/06/03 04:17:58 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/03 03:38:15 | 000,000,753 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/06/03 03:38:15 | 000,000,716 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Secunia PSI.lnk
[2010/12/17 02:52:39 | 000,009,322 | —- | C] () – C:\Documents and Settings\Ike\Application Data\Comma Separated Values (Windows).EML

========== LOP Check ==========

[2009/05/16 12:58:05 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\ACD Systems
[2012/06/08 02:02:19 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2012/06/08 03:07:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2012/06/08 03:25:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2008/12/23 15:06:08 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2012/06/08 03:21:49 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2008/01/16 07:25:10 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2008/07/09 05:39:54 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2008/11/30 14:29:02 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Memeo
[2008/12/01 04:02:28 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\MemeoCommon
[2012/06/16 23:43:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2012/06/12 11:06:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QFX Software
[2007/10/24 11:47:28 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2008/12/23 02:32:35 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2009/08/01 10:12:17 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/01/13 23:16:37 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/03/30 20:46:34 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2009/05/16 13:04:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\ACD Systems
[2010/06/08 23:07:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\AnvSoft
[2012/06/08 03:22:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\AVG2012
[2007/10/24 12:11:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Canon
[2012/06/17 11:23:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\CoreFTP
[2012/06/12 12:16:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\FK_Monitor
[2008/01/05 04:36:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\FrostWire
[2005/12/30 10:27:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\funkitron
[2009/05/20 22:21:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\GrabPro
[2008/01/16 07:28:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Grisoft
[2006/01/01 22:37:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Image Zone Express
[2005/12/29 17:27:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Leadertech
[2011/03/13 21:10:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\MailWasher
[2009/11/26 15:19:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Newsbin
[2007/10/24 16:00:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\NewSoft
[2011/07/17 03:35:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Opera
[2010/05/01 11:34:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Orbit
[2012/06/12 11:06:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\QFX Software
[2005/12/28 18:41:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Qualcomm
[2007/10/24 11:47:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\ScanSoft
[2008/12/23 15:50:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Sony
[2008/12/23 02:22:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Sony Setup
[2008/12/16 14:04:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Teleca
[2007/01/13 23:16:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Viewpoint
[2008/12/01 04:01:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\WD
[2010/06/08 22:31:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Xilisoft Corporation
[2012/06/17 14:13:20 | 000,000,236 | —- | M] () – C:\WINDOWS\Tasks\OGALogon.job

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2009/01/13 08:02:58 | 000,011,395 | —- | M] () – C:\2009-1-13 - hijackthis.log
[2007/06/11 07:11:43 | 000,374,032 | —- | M] () – C:\ACF3758.zip
[2005/12/28 11:41:55 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/12/20 12:08:44 | 000,000,211 | —- | M] () – C:\Boot.bak
[2012/06/08 02:07:53 | 000,000,281 | -HS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2005/12/28 11:41:55 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2004/04/04 19:55:35 | 000,003,872 | —- | M] () – C:\cvv1.gif
[2009/07/23 21:39:42 | 007,024,337 | —- | M] () – C:\Daves.flv
[2011/08/16 10:35:09 | 000,123,886 | —- | M] () – C:\Diamond Head Theatre.jpg
[2007/06/04 22:46:03 | 001,524,871 | —- | M] () – C:\easybio_setup.exe
[2007/03/16 05:55:53 | 000,000,269 | —- | M] () – C:\executive.log
[2012/06/17 14:12:55 | 2078,855,168 | -HS- | M] () – C:\hiberfil.sys
[2009/04/01 22:34:34 | 000,011,590 | —- | M] () – C:\hijackthis.log
[2009/07/23 21:41:00 | 013,712,566 | —- | M] () – C:\Holly.flv
[2005/12/28 11:41:55 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/01/13 18:27:22 | 000,002,986 | —- | M] () – C:\Kas - C Drive - Eudora Directory.html
[2009/01/17 05:12:12 | 000,003,043 | —- | M] () – C:\Kas - C Drive.html
[2009/01/13 19:12:52 | 000,002,888 | —- | M] () – C:\Kas - K Drive - Backup Directory Look Again.html
[2009/01/13 18:37:34 | 000,002,897 | —- | M] () – C:\Kas - K Drive - Backup Directory.html
[2009/01/13 19:01:52 | 000,002,893 | —- | M] () – C:\Kas - K Drive - Old-E-Drive Directory.html
[2009/01/13 18:11:22 | 000,002,955 | —- | M] () – C:\Kas L Drive.html
[2009/01/13 06:45:57 | 000,029,102 | —- | M] () – C:\Kas.gif
[2009/01/12 06:32:54 | 000,016,016 | —- | M] () – C:\Kasp.gif
[2007/07/17 05:23:30 | 000,157,988 | —- | M] () – C:\LylaCaptcha_v1Beta.zip
[2009/04/01 23:13:14 | 000,003,566 | —- | M] () – C:\mbam-log-2009-04-01 (23-11-56).txt
[2009/01/12 05:20:40 | 000,020,872 | —- | M] () – C:\Modify - ComboFix.txt
[2005/12/28 11:41:55 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2005/12/28 13:04:06 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/03 09:19:34 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/06/17 14:12:53 | 301,989,888 | -HS- | M] () – C:\pagefile.sys
[2009/01/12 06:11:24 | 000,000,833 | —- | M] () – C:\Post This - mbam-log-2009-01-12 (06-06-59).txt
[2009/05/24 22:15:37 | 000,000,022 | -H– | M] () – C:\qpmd8378.bin
[2008/03/09 09:53:02 | 000,000,320 | —- | M] () – C:\t12g.1
[2007/07/05 21:48:51 | 000,000,094 | —- | M] () – C:\t15s.1
[2008/08/06 13:41:06 | 000,001,923 | —- | M] () – C:\t1o0.1
[2008/08/07 17:38:11 | 000,001,925 | —- | M] () – C:\t1o8.1
[2008/07/20 23:04:55 | 000,001,229 | —- | M] () – C:\t1r8.3
[2006/04/18 21:24:43 | 000,000,313 | —- | M] () – C:\t1rs.1
[2008/03/01 00:51:42 | 000,001,659 | —- | M] () – C:\t6o.5
[2008/02/28 06:59:03 | 000,000,400 | —- | M] () – C:\t7k.3
[2008/04/18 03:04:37 | 000,000,317 | —- | M] () – C:\tc4.3
[2007/08/09 12:12:02 | 000,000,866 | —- | M] () – C:\tck.1
[2007/08/13 12:12:55 | 000,000,389 | —- | M] () – C:\tdg.3
[2007/10/10 15:53:19 | 000,000,323 | —- | M] () – C:\tu4.3
[2012/06/12 10:50:15 | 000,098,447 | —- | M] () – C:\winzip.log

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2005/12/28 11:41:33 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 02:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2005/05/05 08:48:54 | 000,067,072 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp3xu.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 00:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2005/12/28 01:29:31 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2005/12/28 01:29:31 | 000,626,688 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2005/12/28 01:29:31 | 000,434,176 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Desktop\*.exe >
[2012/06/17 13:25:17 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\Ike\Desktop\aswMBR.exe
[2008/01/16 07:39:16 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Ike\Desktop\ATF-Cleaner.exe
[2012/06/17 13:23:44 | 000,595,968 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Ike\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-06-13 22:53:53

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.CPL >
[1996/06/24 06:51:20 | 000,005,536 | —- | M] () MD5=8AD05DB07CD116CD4223A8B606945A77 – C:\Application Files\Multimedia\Graphics\ImageEditors\Corel\Draw70\programs\DATA\explorer.cpl

< MD5 for: EXPLORER.EXE >
[2008/04/13 14:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\erdnt\cache\explorer.exe
[2008/04/13 14:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 14:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 01:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 00:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/03 21:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe

< MD5 for: EXPLORER.EXE.000 >
[2004/08/03 21:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe.000

< MD5 for: EXPLORER.EXE-082F38A9.PF >
[2012/06/17 14:14:09 | 000,067,016 | —- | M] () MD5=2DC79D736DFABF65D2D7447FEA0BFEA9 – C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf

< MD5 for: EXPLORER.GIF >
[2008/02/14 13:22:08 | 000,001,054 | —- | M] () MD5=678B9EABF7493254CDB7F86E98AFAFD7 – C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\Sync Studio\Images\Explorer.gif

< MD5 for: EXPLORER.SCF >
[2003/03/31 02:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.CHM >
[2004/07/17 08:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2004/07/17 08:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ServicePackFiles\i386\iexplore.chm
[2006/09/01 07:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\Help\iexplore.chm

< MD5 for: IEXPLORE.EXE >
[2009/06/28 21:25:31 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD – C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2008/12/18 19:25:25 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=030D78FE84A086ED376EFCBD2D72C522 – C:\WINDOWS\ie7updates\KB963027-IE7\iexplore.exe
[2008/10/14 20:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
[2010/12/20 01:25:27 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=091D358EFC9D22901BD879EF37F0DAC4 – C:\WINDOWS\ie7updates\KB2497640-IE7\iexplore.exe
[2009/04/24 19:27:50 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2012/04/21 20:40:38 | 000,634,488 | —- | M] (Microsoft Corporation) MD5=0A39EEAD063CCDFF36AC9F0B8F800956 – C:\Program Files\Internet Explorer\iexplore.exe
[2012/04/21 20:40:38 | 000,634,488 | —- | M] (Microsoft Corporation) MD5=0A39EEAD063CCDFF36AC9F0B8F800956 – C:\WINDOWS\SoftwareDistribution\Download\44db2dc6f65744579e39a12db0457613\sp3gdr\iexplore.exe
[2012/04/21 20:40:38 | 000,634,488 | —- | M] (Microsoft Corporation) MD5=0A39EEAD063CCDFF36AC9F0B8F800956 – C:\WINDOWS\system32\dllcache\iexplore.exe
[2007/04/24 04:26:26 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=10BDB55982586A432A3951EB19A26009 – C:\WINDOWS\ie7updates\KB937143-IE7\iexplore.exe
[2008/12/18 19:25:30 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=15E8A89499741D5CF59A9CF6463A4339 – C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[2008/04/21 22:02:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=197B7E4030CFBD8D2979D375E1787AA2 – C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\iexplore.exe
[2011/12/16 01:00:16 | 000,634,680 | —- | M] (Microsoft Corporation) MD5=1C206B8FEEC6882B7F7F479E95D2BDD9 – C:\WINDOWS\ie7updates\KB2675157-IE7\iexplore.exe
[2011/10/31 00:32:32 | 000,634,504 | —- | M] (Microsoft Corporation) MD5=1C5DA2D9EA2A59D0D5C116FA3A5A21AA – C:\WINDOWS\$hf_mig$\KB2618444-IE7\SP3QFE\iexplore.exe
[2008/08/22 19:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\ie7updates\KB958215-IE7\iexplore.exe
[2010/06/17 05:12:57 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=203E897F843D56496E2CC101DFF6CE34 – C:\WINDOWS\ie7updates\KB2360131-IE7\iexplore.exe
[2008/04/21 21:40:18 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=232B22817B90AE0AFF2D189E3E3735AC – C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe
[2007/12/06 01:01:25 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2703D940A62B731AA220529DD7331A78 – C:\WINDOWS\ie7updates\KB947864-IE7\iexplore.exe
[2007/06/26 22:27:30 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=275CEE268B9E5D82474C43D5D249D111 – C:\WINDOWS\ie7updates\KB939653-IE7\iexplore.exe
[2008/02/28 22:55:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2D0E5592AB5A46C27DAF7CCAFF4F5B59 – C:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
[2011/10/31 00:46:00 | 000,634,504 | —- | M] (Microsoft Corporation) MD5=2E34CF22B5862AB02786F0819B9FD819 – C:\WINDOWS\ie7updates\KB2647516-IE7\iexplore.exe
[2009/08/26 19:18:42 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=332EC7562F3AA7364F2D4231C56DA986 – C:\WINDOWS\$hf_mig$\KB974455-IE7\SP3QFE\iexplore.exe
[2007/08/17 00:21:21 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=3AC2BC667DA0AF2C968E96E1630F5AB5 – C:\WINDOWS\ie7updates\KB942615-IE7\iexplore.exe
[2009/06/28 22:35:10 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD – C:\WINDOWS\ie7updates\KB974455-IE7\iexplore.exe
[2011/04/21 00:34:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=3E23DBEBE1020D52C63235E4189FAC03 – C:\WINDOWS\$hf_mig$\KB2530548-IE7\SP3QFE\iexplore.exe
[2009/10/27 20:54:16 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=4F9B04D546C23A295F3F0AE015BE51DB – C:\WINDOWS\ie7updates\KB978207-IE7\iexplore.exe
[2012/02/29 01:01:00 | 000,634,680 | —- | M] (Microsoft Corporation) MD5=50BA6A230D743A4D33BFFA2FA1113055 – C:\WINDOWS\ie7updates\KB2699988-IE7\iexplore.exe
[2006/10/17 12:04:40 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=5334D4461AA92A7B008755FE6D13C5F2 – C:\WINDOWS\ie7updates\KB928090-IE7\iexplore.exe
[2009/12/18 03:05:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=53C291F3B01EECECBD7FD358EA3ACC94 – C:\WINDOWS\ie7updates\KB980182-IE7\iexplore.exe
[2007/08/17 00:12:49 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=5577D0E3AC2F9F035ACD81B44AF5F511 – C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iexplore.exe
[2008/04/13 14:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2007/10/09 22:16:56 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=632BDE0179847234433CA50945442ACB – C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iexplore.exe
[2008/06/22 23:20:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=64E376A47763DAEABCDA14BD5B6EA286 – C:\WINDOWS\ie7updates\KB956390-IE7\iexplore.exe
[2007/02/20 22:00:58 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=683DDE71BCF03B501B912D20CB93B549 – C:\WINDOWS\ie7updates\KB933566-IE7\iexplore.exe
[2011/08/17 01:01:37 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=6A1D755C68C10863C598C78A597FA7C3 – C:\WINDOWS\ie7updates\KB2618444-IE7\iexplore.exe
[2008/02/21 23:40:22 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=6E0888626E0CAC79F57149814E22DB4D – C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
[2010/10/18 01:07:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=72D1F43C4146D312B0DB6AB98C21340E – C:\WINDOWS\ie7updates\KB2482017-IE7\iexplore.exe
[2009/10/27 20:54:21 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=80675329E0FD54F016C4F8A83C616349 – C:\WINDOWS\$hf_mig$\KB976325-IE7\SP3QFE\iexplore.exe
[2007/12/05 22:34:45 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=809D17D8FA0FDAEE07778CD821CAFFDE – C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
[2007/01/08 18:08:42 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=93A6A4F5293AE19E3B37021AABCF0902 – C:\WINDOWS\ie7updates\KB931768-IE7\iexplore.exe
[2011/06/20 01:29:11 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=993F33696EF219C306BF9BBA34D85073 – C:\WINDOWS\ie7updates\KB2586448-IE7\iexplore.exe
[2007/04/24 04:20:41 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=9B3516C1F30DA17ADD3818573047D63C – C:\WINDOWS\$hf_mig$\KB933566-IE7\SP2QFE\iexplore.exe
[2008/10/14 21:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
[2009/02/27 18:54:41 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=A251068640DDB69FD7805B57D89D7FF7 – C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2010/06/17 04:45:15 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B0BC6DC9C9277250C5C8F7B7A48A02CC – C:\WINDOWS\$hf_mig$\KB2183461-IE7\SP3QFE\iexplore.exe
[2010/04/16 01:08:29 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B24A4E23A2FEDB6976EB04D334AD82B2 – C:\WINDOWS\$hf_mig$\KB982381-IE7\SP3QFE\iexplore.exe
[2010/02/22 19:20:02 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B5116340B84824DDD0A641E36B126194 – C:\WINDOWS\ie7updates\KB982381-IE7\iexplore.exe
[2011/04/21 00:58:25 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B6E13F9C120C776A89D783E26D6C15C5 – C:\WINDOWS\erdnt\cache\iexplore.exe
[2011/04/21 00:58:25 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B6E13F9C120C776A89D783E26D6C15C5 – C:\WINDOWS\ie7updates\KB2559049-IE7\iexplore.exe
[2010/12/20 00:49:55 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B74CBEBA34E3CAA2CCACC87FEE8A16C0 – C:\WINDOWS\$hf_mig$\KB2482017-IE7\SP3QFE\iexplore.exe
[2009/02/27 18:54:44 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=BCD8E48709BE4A79606F0B6E8E9A6162 – C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[2007/06/26 23:16:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=BD8502DFD53FC24FB8D6929DC46B8C2C – C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iexplore.exe
[2009/04/24 19:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2010/04/16 01:43:25 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=C4BA5E36FB57F547117305BF1E0FE454 – C:\WINDOWS\ie7updates\KB2183461-IE7\iexplore.exe
[2008/06/22 22:23:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=C52A9EF571E91535EB78DB4B8B95EA07 – C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
[2010/02/22 19:19:59 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=C8DDA4028065D5CE39CBE7A156B72AB9 – C:\WINDOWS\$hf_mig$\KB980182-IE7\SP3QFE\iexplore.exe
[2011/08/17 00:34:43 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=CB0AFAF9E5C5FE70EC7087E71275DD33 – C:\WINDOWS\$hf_mig$\KB2586448-IE7\SP3QFE\iexplore.exe
[2012/04/21 20:32:36 | 000,634,488 | —- | M] (Microsoft Corporation) MD5=CE2379FC341C65CAD88FF8264A791AB5 – C:\WINDOWS\$hf_mig$\KB2699988-IE7\SP3QFE\iexplore.exe
[2012/04/21 20:32:36 | 000,634,488 | —- | M] (Microsoft Corporation) MD5=CE2379FC341C65CAD88FF8264A791AB5 – C:\WINDOWS\SoftwareDistribution\Download\44db2dc6f65744579e39a12db0457613\sp3qfe\iexplore.exe
[2009/12/17 21:00:27 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=D19E56D5930C37CF211867DF450C372A – C:\WINDOWS\$hf_mig$\KB978207-IE7\SP3QFE\iexplore.exe
[2007/02/27 20:51:34 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=D321092F8529CDAE843D6E24E3CAC6CB – C:\WINDOWS\$hf_mig$\KB931768-IE7\SP2QFE\iexplore.exe
[2010/10/18 00:36:30 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=DA6E1F0F1932B62DD2F6ED05541C555C – C:\WINDOWS\$hf_mig$\KB2416400-IE7\SP3QFE\iexplore.exe
[2011/12/16 00:35:06 | 000,634,680 | —- | M] (Microsoft Corporation) MD5=DB9D9A73FACB0B11992201D670D73E16 – C:\WINDOWS\$hf_mig$\KB2647516-IE7\SP3QFE\iexplore.exe
[2011/06/20 00:38:09 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=DE0F15DD275A36C3E67DC1E36F958F3A – C:\WINDOWS\$hf_mig$\KB2559049-IE7\SP3QFE\iexplore.exe
[2012/02/29 00:34:48 | 000,634,680 | —- | M] (Microsoft Corporation) MD5=DF642AABFDACE36E3B4329091A07DE87 – C:\WINDOWS\$hf_mig$\KB2675157-IE7\SP3QFE\iexplore.exe
[2011/02/14 01:36:55 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E3CC8CCF21BFDC954255BB17083FB9F0 – C:\WINDOWS\$hf_mig$\KB2497640-IE7\SP3QFE\iexplore.exe
[2011/02/14 02:17:08 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E4A798DFDE7FE6E79F23548F0EF0F844 – C:\WINDOWS\ie7updates\KB2530548-IE7\iexplore.exe
[2010/08/25 01:30:33 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E5412ED9E07C42C20C48D3FF71E6B1E8 – C:\WINDOWS\ie7updates\KB2416400-IE7\iexplore.exe
[2004/08/03 21:56:50 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\$NtServicePackUninstall$\iexplore.exe
[2004/08/03 21:56:50 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\ie7\iexplore.exe
[2008/08/22 19:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
[2007/10/10 00:59:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=E854D02E4231F704D9BE782A424E6D8B – C:\WINDOWS\ie7updates\KB944533-IE7\iexplore.exe
[2010/08/25 01:07:58 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F047BEB9771E45A05F425499A30F9BBA – C:\WINDOWS\$hf_mig$\KB2360131-IE7\SP3QFE\iexplore.exe
[2009/08/26 19:18:44 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F232BA9F39BC0F722672C7E79E68EBEA – C:\WINDOWS\ie7updates\KB976325-IE7\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2006/10/17 12:04:26 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=E83C9C1F9DD9D47BB44871BFC7E69DDD – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-27122324.PF >
[2012/06/17 14:14:26 | 000,074,610 | —- | M] () MD5=E4EA8E1782684C9A90E9B96BE402FF0F – C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf

< MD5 for: IEXPLORE.GIF >
[1999/09/27 08:00:50 | 000,001,272 | -H– | M] () MD5=E33A77046E2004ED5A299F90DEE7080C – C:\Application Files\Development\Website\ColdFusionStudio\Help\HTML_Reference\images\iexplore.gif

< MD5 for: IEXPLORE.HLP >
[2003/03/31 02:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: WINLOGON.EXE >
[2004/08/03 21:56:57 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 14:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\erdnt\cache\winlogon.exe
[2008/04/13 14:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 14:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< End of report >










Here is my Extras.Txt file:

OTL Extras logfile created on: 6/17/2012 2:21:40 PM - Run 1
OTL by OldTimer - Version 3.2.49.0 Folder = C:\Documents and Settings\Ike\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.94 Gb Total Physical Memory | 1.49 Gb Available Physical Memory | 76.91% Memory free
2.07 Gb Paging File | 1.72 Gb Available in Paging File | 83.19% Paging File free
Paging file location(s): C:\pagefile.sys 288 576 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 93.16 Gb Total Space | 31.44 Gb Free Space | 33.75% Space Free | Partition Type: NTFS
Drive D: | 149.05 Gb Total Space | 41.31 Gb Free Space | 27.72% Space Free | Partition Type: NTFS

Computer Name: BUD | User Name: Ike | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = Opera.HTML] – Reg Error: Key error. File not found
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
https [open] – "C:\Application Files\Internet\Browsers\Opera\Opera.exe" "%1" (Opera Software)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] – "C:\APPLIC~1\MULTIM~1\Graphics\IMAGEV~1\ACDSYS~1\ACDSee\ACDSee.exe" "%1" (ACD Systems, Ltd.)
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Enqueue] – "C:\Application Files\Multimedia\Audio\Mp3Players\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Application Files\Multimedia\Audio\Mp3Players\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\SmartFTP Client 2.0\SmartFTP.exe" = C:\Program Files\SmartFTP Client 2.0\SmartFTP.exe:*:Enabled:SmartFTP Client 2.0 – (SmartFTP GmbH)
"C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager\MediaManager.exe" = C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager\MediaManager.exe:*:Enabled:Sony Ericsson Media Manager 1.2 – (Sony Creative Software Inc.)
"C:\Application Files\Internet\NewsReaders\NewsBin\nbpro.exe" = C:\Application Files\Internet\NewsReaders\NewsBin\nbpro.exe:*:Enabled:NewsBin Pro – (CMCEI)
"C:\Application Files\Internet\Browsers\Opera\opera.exe" = C:\Application Files\Internet\Browsers\Opera\opera.exe:*:Enabled:Opera Internet Browser – (Opera Software)
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe" = C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:vsmon – (Check Point Software Technologies LTD)
"C:\Documents and Settings\Ike\Local Settings\Application Data\Akamai\netsession_win.exe" = C:\Documents and Settings\Ike\Local Settings\Application Data\Akamai\netsession_win.exe:*:Disabled:Akamai NetSession Client – (Akamai Technologies, Inc)
"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgnsx.exe" = C:\Program Files\AVG\AVG2012\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgdiagex.exe" = C:\Program Files\AVG\AVG2012\avgdiagex.exe:*:Enabled:AVG Diagnostics 2012 – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ4802" = CanoScan LiDE 600F
"{15EE79F4-4ED1-4267-9B0F-351009325D7D}" = HP Software Update
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216032FF}" = Java™ 6 Update 33
"{29042B1C-0713-4575-B7CA-5C8E7B0899D4}" = MyODBC 3.51.8
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{2CD2C0DB-81C3-416B-9FA6-589B9235359B}" = OpenOffice.org 2.4
"{2FFE93F0-BB72-4E52-8761-354D1AAA9387}" = Sony Ericsson PC Suite 4.006.00
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java™ 6 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{33D6CC28-9F75-4d1b-A11D-98895B3A3729}" = HP Photosmart 330,380,420,470,7800,8000,8200 Series
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}" = Google Earth
"{4073AAEC-B01B-4000-BC9B-1447E3A7BD87}" = AVG 2012
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{5A0C892E-FD1C-4203-941E-0956AED20A6A}" = APC PowerChute Personal Edition
"{619B8475-0F48-41B7-A370-5147F7092989}" = Virtual Earth 3D (Beta)
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6E7D29CB-E3D9-4ef2-B4DC-ECF1C0C45ECC}" = PS470
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{755EC5E3-FD51-46bd-A57F-7A2D56FBF061}" = PSTAPlugin
"{769A295C-DCF4-41d6-AFBA-7D9394B23AFE}" = PSPrinters08
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{85309D89-7BE9-4094-BB17-24999C6118FC}" = ArcSoft PhotoStudio 5.5
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8BBF6DFD-0AD9-43A7-9FBD-BF065E3866AF}" = URGE
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{94FB906A-CF42-4128-A509-D353026A607E}" = REALTEK Gigabit and Fast Ethernet NIC Driver
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9EB1504E-FD95-4BCD-8E93-B4039F59C469}" = Sony Ericsson Media Manager 1.2
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A3455242-DAE0-4523-8242-FD82706ABF4B}" = CameraDrivers
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A70500000002}" = Adobe Reader 7.0.5
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{BCF75973-29C2-4245-80E3-B3C2B7E7548B}" = AVG 2012
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C169D3BB-9A27-43F5-9979-09A0D65FE95C}" = SmartFTP Client 2.0
"{C1E693A4-B1D5-4DCD-B68D-2087835B7184}" = ScanSoft OmniPage SE 4.0
"{C6A09671-93A6-4548-9FAE-3BF21EB9C921}" = AVG 2012
"{CAAB0192-5704-469F-A0BE-2D842D70E93B}_is1" = Sothink FLV Player
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2D6B9EB-C6DC-4DAA-B4DE-BB7D9735E7DA}" = Presto! PageManager 7.15.14
"{DE076BC1-42A1-4C8C-BFCD-C1BC48531762}" = Anonymizer 2005
"{E1F4FB82-3EA6-46B6-A18A-9B3A62DA393E}" = hp deskjet 6122
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{E934E2A2-BE3B-4C1A-A3D9-753FFB2B38B4}" = WD Drive Manager (x86)
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{ECDBCAF5-BC83-4E03-86EB-552E7D53A94F}_is1" = AML Power Video Converter 1.2
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{F86B6D9F-FA9A-4164-A66A-EAFF7C067272}_is1" = Sothink Video Encoder for Adobe Flash
"{F87BD397-DE42-4679-A91B-30E9E531711B}" = Eudora
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FE64AE29-0883-4C70-8388-DC026019C900}" = HP Image Zone Express
"7-Zip" = 7-Zip 4.57
"AC3Filter" = AC3Filter (remove only)
"ACDSee Trial Version" = ACDSee Trial Version
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Any Video Converter_is1" = Any Video Converter 3.0.5
"AVG" = AVG 2012
"BearShare" = BearShare
"BearShare Acceleration Patch_is1" = BearShare Acceleration Patch 4.5
"Canon CanoScan LiDE 600F User Registration" = Canon CanoScan LiDE 600F User Registration
"CanoScan Toolbox 5.0" = Canon CanoScan Toolbox 5.0
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200014F1" = SoftV92 Data Fax Modem with SmartCP
"CodInstl" = Intel A/V Codecs V2.0
"CoreFTP" = Core FTP LE
"Corel Applications" = Corel Applications
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Desktop Weather by The Weather Channel" = Desktop Weather by The Weather Channel
"DivX Pro Codec Adware" = DivX Pro Codec Adware
"ERUNT_is1" = ERUNT 1.1j
"Eusing Free Registry Cleaner" = Eusing Free Registry Cleaner
"FastStone Image Viewer" = FastStone Image Viewer 2.8
"ffdshow_is1" = ffdshow [rev 1723] [2007-12-24]
"FLV Player" = FLV Player 2.0 (build 25)
"hp deskjet 6122 series_Driver" = hp deskjet 6122 series
"HP Imaging Device Functions" = HP Imaging Device Functions 5.3
"hp print screen utility" = hp print screen utility
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"IrfanView" = IrfanView (remove only)
"KeyScrambler" = KeyScrambler
"MailWasher_is1" = MailWasher
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"MasterSplitter" = MasterSplitter Program
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft SQL Server 7.0" = Microsoft SQL Server 7.0
"Move Networks Player_is1" = Move Networks Player for Internet Explorer
"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MySQL Servers and Clients 4.0.20d" = MySQL Servers and Clients 4.0.20d
"MySQL-Front_is1" = MySQL-Front 3.1
"Netscape (7.1)" = Netscape (7.1)
"NetTracker 7.5 Lite" = NetTracker 7.5 Lite
"NewsBin5" = NewsBin Pro
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Numerology Calculator_is1" = Numerology Calculator
"oggcodecs" = oggcodecs 0.71.0946
"Opera" = Opera
"Panda ActiveScan" = Panda ActiveScan
"PartyPoker" = PartyPoker
"Poker Superstars Deluxe" = Poker Superstars Deluxe (remove only)
"PokerStars.net" = PokerStars.net
"QuickPar" = QuickPar 0.9
"RealPlayer 6.0" = RealPlayer
"Rhythm & Bio" = Rhythm & Bio
"Riva FLV Encoder 2.0_is1" = Riva FLV Encoder 2.0
"Secunia PSI" = Secunia PSI (2.0.0.4003)
"SmartFTP Client 2.0 Setup Files" = SmartFTP Client 2.0 Setup Files (remove only)
"SUPER ©" = SUPER © Version 2009.bld.36 (June 10, 2009)
"TopStyle Lite (Version 2)" = TopStyle Lite (Version 2)
"Tweak UI 2.10" = Tweak UI
"Uninstall Macromedia ColdFusion MX 7" = Macromedia ColdFusion MX 7
"VIA/S3G UniChrome Family Win2K/XP Display" = VIA/S3G Display Driver
"ViewpointMediaPlayer" = Viewpoint Media Player (Remove Only)
"VLC media player" = VLC media player 1.0.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WebSTAR DPC2100 Uninstall" = Scientific-Atlanta WebSTAR 2000 series Cable Modem
"WIC" = Windows Imaging Component
"Winamp" = Winamp (Remove Only)
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"WMA To MP3 Converter" = WMA To MP3 Converter
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xenu_is1" = Xenu's Link Sleuth
"ZoneAlarm" = ZoneAlarm

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"ColdFusion Studio 4.5" = ColdFusion Studio 4.5
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 6/4/2012 5:22:23 PM | Computer Name = BUD | Source = Application Error | ID = 1000
Description = Faulting application opera.exe, version 8.51.7712.0, faulting module
ntdll.dll, version 5.1.2600.6055, fault address 0x00010a1b.

Error - 6/5/2012 5:45:36 AM | Computer Name = BUD | Source = Application Error | ID = 1000
Description = Faulting application dllhost.exe, version 5.1.2600.5512, faulting
module msvcrt.dll, version 7.0.2600.5512, fault address 0x00037fd4.

Error - 6/5/2012 5:51:09 AM | Computer Name = BUD | Source = Application Error | ID = 1000
Description = Faulting application dllhost.exe, version 5.1.2600.5512, faulting
module ntdll.dll, version 5.1.2600.6055, fault address 0x00019af2.

Error - 6/5/2012 5:55:48 AM | Computer Name = BUD | Source = Application Error | ID = 1000
Description = Faulting application dllhost.exe, version 5.1.2600.5512, faulting
module ntdll.dll, version 5.1.2600.6055, fault address 0x00019af2.

Error - 6/5/2012 5:55:58 AM | Computer Name = BUD | Source = Application Error | ID = 1000
Description = Faulting application dllhost.exe, version 5.1.2600.5512, faulting
module ntdll.dll, version 5.1.2600.6055, fault address 0x00019af2.

Error - 6/5/2012 11:11:30 AM | Computer Name = BUD | Source = Application Error | ID = 1000
Description = Faulting application dllhost.exe, version 5.1.2600.5512, faulting
module ntdll.dll, version 5.1.2600.6055, fault address 0x00019af2.

Error - 6/6/2012 6:55:11 PM | Computer Name = BUD | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

Error - 6/7/2012 8:24:05 AM | Computer Name = BUD | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

Error - 6/8/2012 9:26:33 AM | Computer Name = BUD | Source = MsiInstaller | ID = 11722
Description = SA_Error1709: StandardAction(0xC00706AD): Product: AVG 2012 – Error
1722. SA_Error1722: StandardAction(0xC00706BA): There is a problem with this Windows
Installer package. A program run as part of the setup did not finish as expected.
Contact your support personnel or package vendor. Action RegisterTuneUp, location:
C:\Program Files\AVG\AVG2012\PCTuneup\MicroScanner.exe, command: -REGSERVER

Error - 6/8/2012 6:55:34 PM | Computer Name = BUD | Source = MsiInstaller | ID = 11704
Description = Product: Java™ 6 Update 31 – Error 1704.An installation for AVG
2012 is currently suspended. You must undo the changes made by that installation
to continue. Do you want to undo those changes?

[ System Events ]
Error - 6/17/2012 8:02:10 PM | Computer Name = BUD | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service upnphost with
arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}

Error - 6/17/2012 8:03:52 PM | Computer Name = BUD | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service upnphost with
arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}

Error - 6/17/2012 8:04:00 PM | Computer Name = BUD | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service upnphost with
arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}

Error - 6/17/2012 8:06:54 PM | Computer Name = BUD | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service upnphost with
arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}

Error - 6/17/2012 8:08:51 PM | Computer Name = BUD | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service upnphost with
arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}

Error - 6/17/2012 8:13:23 PM | Computer Name = BUD | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service IISADMIN with
arguments "" in order to run the server: {A9E69610-B80D-11D0-B9B9-00A0C922E750}

Error - 6/17/2012 8:13:49 PM | Computer Name = BUD | Source = Service Control Manager | ID = 7001
Description = The World Wide Web Publishing service depends on the IIS Admin service
which failed to start because of the following error: %%1058

Error - 6/17/2012 8:17:01 PM | Computer Name = BUD | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {601D72B9-326F-46CD-815E-12D5D15761BA}.
The
error: "%2" Happened while starting this command: "c:\PROGRA~1\mcafee\SITEAD~1\saui.exe"
-Embedding

Error - 6/17/2012 8:24:22 PM | Computer Name = BUD | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service IISADMIN with
arguments "" in order to run the server: {A9E69610-B80D-11D0-B9B9-00A0C922E750}

Error - 6/17/2012 8:24:31 PM | Computer Name = BUD | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service IISADMIN with
arguments "" in order to run the server: {A9E69610-B80D-11D0-B9B9-00A0C922E750}


< End of report >








Here is my aswMBR.txt file:

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-06-17 14:57:34
—————————–
14:57:34.593 OS Version: Windows 5.1.2600 Service Pack 3
14:57:34.593 Number of processors: 1 586 0x1C00
14:57:34.593 ComputerName: BUD UserName:
14:57:35.296 Initialize success
14:58:56.140 AVAST engine defs: 12061700
15:02:28.203 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-13
15:02:28.203 Disk 0 Vendor: ST3100011A 3.02 Size: 95396MB BusType: 3
15:02:28.203 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T1L0-1b
15:02:28.218 Disk 1 Vendor: ST3160023A 8.01 Size: 152627MB BusType: 3
15:02:28.234 Disk 0 MBR read successfully
15:02:28.234 Disk 0 MBR scan
15:02:28.265 Disk 0 Windows XP default MBR code
15:02:28.296 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 95393 MB offset 63
15:02:28.312 Disk 0 scanning sectors +195366465
15:02:28.406 Disk 0 scanning C:\WINDOWS\system32\drivers
15:02:41.468 Service scanning
15:03:06.968 Service vsdatant C:\WINDOWS\System32\vsdatant.sys **LOCKED** 32
15:03:10.625 Modules scanning
15:03:20.296 Disk 0 trace - called modules:
15:03:20.343 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys viaide.sys PCIIDEX.SYS
15:03:20.343 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8aa5aab8]
15:03:20.343 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\00000062[0x8aa93bd0]
15:03:20.359 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-13[0x8a9f2940]
15:03:20.640 AVAST engine scan C:\WINDOWS
15:03:45.000 AVAST engine scan C:\WINDOWS\system32
15:06:45.203 AVAST engine scan C:\WINDOWS\system32\drivers
15:07:03.203 AVAST engine scan C:\Documents and Settings\Ike
15:23:58.312 AVAST engine scan C:\Documents and Settings\All Users
15:27:46.203 Scan finished successfully
15:40:32.140 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Ike\Desktop\MBR.dat"
15:40:32.156 The log file has been saved successfully to "C:\Documents and Settings\Ike\Desktop\aswMBR.txt"




Attached is the Zip file (finally got it to work).

Thank you,

Ike

Attachments:

Hi ike001,

Not much showing in these logs.

BearShare

You have BearShare, a P2P/file sharing program installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx

http://www.internetworldstats.com/articles…cles/art053.htm

I would recommend that you uninstall LimeWire, however that choice is up to you. If you choose to remove this program, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.


You have some very old vulnerable java installed. Click start > Control Panel > Add/Remove Programs and uninstall


Java™ 6 Update 4
Java™ 6 Update 5
Java™ 6 Update 7

Do not uninstall Java™ 6 Update 33



Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;

:Files
ipconfig /flushdns /c

:Commands
[purity]
[emptytemp]
[createrestorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL fix log.



Next

You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with
  • OTL fix log
  • MBAM log
Hello oldman960,

I uninstalled the Java 6 updates 4, 5, and 7.

I could not uninstall Limewire because it's not in the Add/Remove Programs List.
I actually think I unistalled Limewire awhile ago. (I haven't used that thing for years.)
I looked in "Program Files" and other places, I could not find the Limewire directory with the uninstall file.


I looked for Limewire files on my C drive and I found these stray files:

LimeWireWin4.14.12.exe C:\Documents and Settings\Ike\Application Data\FrostWire\.NetworkShare
limewire.jar
limewire.manifest
LimeWireWinInstaller.exe.part
LimeWireWinInstaller.exe.info


There are also Limewire directories that has subdirectories of executeable files and other stuff:

.limewire C:\Documents and Settings\Ike\
.NetworkShare C:\Documents and Settings\Ike\Application Data\FrostWire\



I just put them in my Recycle Bin. You give me the go ahead, I will delete them.


But when it comes down to it, you "nailed it" when you identified Bearshare as the culprit.

When using the custom option when uninstalling Bearshare, it asked me if I wanted to uninstall a whole
bunch of files; one of the the files was the "HKCU\Software\Microsoft\Windows\CurrentVersion\"

I haven't used that Bearshare thing since June 2006.


Anyhow, thanks for your help oldman960! I really appreciate it!

Ike



Here is the OTL fix log:

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Ike\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Ike\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 176347 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 65748 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 803458 bytes
->Temporary Internet Files folder emptied: 839355 bytes

User: Ike
->Temp folder emptied: 715260141 bytes
->Temporary Internet Files folder emptied: 77392084 bytes
->Java cache emptied: 60793 bytes
->FireFox cache emptied: 0 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 29823 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 4486714 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 47173274 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 807.00 mb

Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.49.0 log created on 06182012_145956

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…




Here is the MBAM log:

Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Database version: v2012.06.19.01

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 7.0.5730.11
Ike :: BUD [administrator]

6/18/2012 3:20:52 PM
mbam-log-2012-06-18 (15-20-52).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 218785
Time elapsed: 8 minute(s), 7 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
Hi ike001,

Sorry about the confusion with LimeWire. i missed changing it in the P2P canned that I use. BearShare is what I meant. There is also a related program you may as well also uninstall, BearShare Acceleration Patch 4.5

Yes go ahead and empty the recycle bin. Any other problems?
Hello oldman960, Yes, I uninstalled the "BearShare Acceleration Patch 4.5" when uninstalling Bearshare. I will empty the recycle bin. Great deduction in spotting the Bearshare! Great job! Thanks a lot for your help! Ike
Hi ike001

You're welcome. Let's clean up.

From your desktop, please delete, if present
  • any notepads/logs that we created
  • mbr.zip
  • mbr.dat
  • aswMBR.exe

Next

* Create a new restore point

You must be logged on to an administrator account
  • Go to Start - All Programs - Accessories - System Tools - System Restore.
  • Click Create a restore point, and then click Next.
  • In the text box labeled Restore Point Description, type a name for this restore point
  • click create
* Remove old restore points

  • Go to Start - All Programs - Accessories - system tools.
  • Launch the Disk Cleanup tool and let it run.
  • When it finishes a box with tabs will appear, select the more options tab.
  • On this tab you will find a section for System Restore.
  • If you press the Clean Up button for that section, Windows will delete all restore points except for the most recent one.


Next

pen OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.

I suggest you keep MBAM. Keep it updated and use it regularly.


Updates and upgrades

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum If you choose Foxit, decline the Foxit Toolbar offered during the install.

In either case you should uninstall Adobe Reader 7.0.5 first. Be sure to move any PDF documents to another folder first though.


Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. You have most of those. Just add a resident antispyware.

I suggest either for a resident antispyware program.

Windows Defender
OR
Winpatrol

You may find a differnt one more to your liking in the link further down.


You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.


-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis


- Make sure you have reset Automatic Updates to your chosen optionClick your start button > Control Panel > System > Automatic Updates tab


- Keep your antivirus program updated, as well as any other security programs you have.

-More tips and programs can be found HERE

Please post back if you have any problems.

Take care
Hello oldman960, Wow - thanks for all the info! I was wondering about the cleanup. I'm following your advice - so thanks a lot! I really appreciate all of your help! Take care! Ike

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI