This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Javascript links blocked [Solved]

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A neighbour sought assistance. System is a Dell Inspiron 1012 with windows 7 Starter sp1, 32-bit, 1Gb RAM; IE9; McAfee Security Center.

Problem started as unable to login to Webmail (ISP Bigpond) browser going instead to a directory page for Bigpond. Lengthy session with ISP concluded problem was her browser. I was asked to help.

I found that anytime a link using javascript was clicked, either nothing happened (eg, trying to subit Service Tag to Dell support) or page was not displayed (as with my own webmail account).

I checked procedure to enable javascript for IE9 and it was enabled.

I then thought I might uninstall IE9 and re-install. Went to Microsoft download site and submitted a search for "Internet Explorer 9". This gave an error message that javascript was required to search the site and to enable javascript and try again.

Again I checked that javascript was enabled.

I suspected some malware and tried to run her McAfee security. All I got was a blank square on the screen. Windows Action Centre reported AV turned off (she thinks Bigpond disabled AV during a remote session last week); the "fix it now" failed. So I downloaded Malwarebytes, accepted the full trial and ran a quick scan, 0 objects infected. I then ran a full scan with the same result. While I had the PC running, Windows Defender started a scan and it too completed with no suspicious objects found.

I have preformed the preparatory steps using OTL and seek your help.

here is the output, OTL.TXT:
OTL logfile created on: 7/2/2012 9:59:14 PM - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\elizabeth\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1013.36 Mb Total Physical Memory | 288.30 Mb Available Physical Memory | 28.45% Memory free
1.99 Gb Paging File | 0.65 Gb Available in Paging File | 32.46% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 218.20 Gb Total Space | 183.47 Gb Free Space | 84.08% Space Free | Partition Type: NTFS

Computer Name: ELIZABETH-PC | User Name: elizabeth | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\elizabeth\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - c:\Program Files\McAfee\VirusScan\McVsShld.exe (McAfee, Inc.)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - c:\Program Files\McAfee\MSC\mcupdmgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\Babylon\Babylon-Pro\Babylon.exe (Babylon Ltd.)
PRC - C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.EXE (Microsoft Corporation.)
PRC - C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
PRC - C:\Program Files\Telstra\BigPond Wireless Broadband 2.11.21\TelstraUCM.exe (Telstra)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Sierra Wireless Inc\Common\SwiCardDetect.exe (Sierra Wireless, Inc.)
PRC - C:\Program Files\Babylon\Babylon-Pro\TC\BabylonTC.exe (Ginger Software)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\McAfee\Core\mchost.exe (McAfee, Inc.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel.exe (SRS Labs, Inc.)
PRC - C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
PRC - C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe ()
PRC - C:\Program Files\Dell\Dell WWAN\WMCore\mini_WMCore.exe ()
PRC - C:\Program Files\Battery Meter\BTMeter.exe (Dell)
PRC - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
PRC - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE ()
PRC - C:\Program Files\Dell\Dell Wireless WLAN Card\BCMWLTRY.EXE (Dell Inc.)
PRC - c:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
PRC - C:\Program Files\CapsLKNotify\CapsLKNotify.exe (Compal Electronics, Inc)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Program Files\Dell Support Center\gs_agent\dsc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\WSED\WSED.exe (Dell)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\MenuSkinning\441f70b24b8d34304320c1b8e9f2238d\MenuSkinning.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\VistaBridgeLibrary\1df07192ed74313faa449941475d3aa9\VistaBridgeLibrary.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\DellDock\6639c2f07d223a4b2d9fb996ca415371\DellDock.ni.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\MyDock.Util\7153f49f632b983b217930de1b291113\MyDock.Util.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\761fd1afc17f11bf6d49c3a7d16465ca\System.Web.Services.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\9b2f17fb61b7197f2a04108f5d1a1cc6\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\2ec98ab0193d64e95b7d09d094deed97\Accessibility.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe ()
MOD - C:\Program Files\Dell DataSafe Online\SdbShared.dll ()
MOD - C:\Program Files\Dell DataSafe Online\SdbShared.XmlSerializers.dll ()
MOD - C:\Program Files\Dell DataSafe Online\SdbUI.dll ()
MOD - C:\Program Files\Dell DataSafe Online\BalloonWindow.dll ()
MOD - C:\Program Files\Dell DataSafe Online\CppUtils.dll ()
MOD - C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlrmt.dll ()
MOD - C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll ()
MOD - C:\Windows\System32\EMSC.DLL ()


========== Win32 Services (SafeList) ==========

SRV - (mfevtp) – C:\Windows\System32\mfevtps.exe (McAfee, Inc.)
SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (BBUpdate) – C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\7.1.361.0\BBSvc.EXE (Microsoft Corporation.)
SRV - (SwiCardDetectSvc) – C:\Program Files\Sierra Wireless Inc\Common\SwiCardDetect.exe (Sierra Wireless, Inc.)
SRV - (MSK80Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McProxy) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (0074001341094569mcinstcleanup) McAfee Application Installer Cleanup (0074001341094569) – C:\Windows\Temp\0074001341094569mcinst.exe (McAfee, Inc.)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (WMCoreService) – C:\Program Files\Dell\Dell WWAN\WMCore\mini_WMCore.exe ()
SRV - (wltrysvc) – C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (btwdins) – c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)


========== Driver Services (SafeList) ==========

DRV - (mfeavfk01) – File not found
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (mfehidk) – C:\Windows\System32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – C:\Windows\System32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\Windows\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfewfpk) – C:\Windows\System32\drivers\mfewfpk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\Windows\System32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\Windows\System32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfenlfk) – C:\Windows\System32\drivers\mfenlfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\Windows\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (cfwids) – C:\Windows\System32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (swg3kser00) – C:\Windows\System32\drivers\swg3kser00.sys (Sierra Wireless Incorporated)
DRV - (SWNC8UA3) Sierra Wireless MUX NDIS Driver (UMTSA3) – C:\Windows\System32\drivers\swnc8ua3.sys (Sierra Wireless Inc.)
DRV - (swiwdmbx) – C:\Windows\System32\drivers\swiwdmbx.sys (Sierra Wireless Inc.)
DRV - (massfilter_lte) – C:\Windows\System32\drivers\massfilter_LTE.sys (HandSet Incorporated)
DRV - (ZTEusbnet) – C:\Windows\System32\drivers\ZTEusbnet.sys (ZTE Corporation)
DRV - (ZTEusbser6k) – C:\Windows\System32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) – C:\Windows\System32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\Windows\System32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) – C:\Windows\System32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (BRCMDECO) – C:\Windows\System32\drivers\BRCMHD32.sys (Broadcom Corporation)
DRV - (RSUSBSTOR) – C:\Windows\System32\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV - (WwanUsbServ) – C:\Windows\System32\drivers\WwanUsbMp.sys (Ericsson AB)
DRV - (ecnssndisfltr) – C:\Windows\System32\drivers\wwanussf.sys (Ericsson AB)
DRV - (ecnssndis) – C:\Windows\System32\drivers\wwanuss.sys (Ericsson AB)
DRV - (BCM42RLY) – C:\Windows\System32\drivers\bcm42rly.sys (Broadcom Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (d554gps) – C:\Windows\System32\drivers\d554gps.sys (Ericsson AB)
DRV - (d557mdm) Dell Wireless 5540 HSPA Mini-Card Modem (Win7) – C:\Windows\System32\drivers\d557mdm.sys (MCCI Corporation)
DRV - (d557mgmt) Dell Wireless 5540 HSPA Mini-Card Device Management (Win7) – C:\Windows\System32\drivers\d557mgmt.sys (MCCI Corporation)
DRV - (d557bus) Dell Wireless 5540 HSPA Mini-Card Device (Win7) – C:\Windows\System32\drivers\d557bus.sys (MCCI Corporation)
DRV - (d557mdfl) Dell Wireless 5540 HSPA Mini-Card Modem Filter (Win7) – C:\Windows\System32\drivers\d557mdfl.sys (MCCI Corporation)
DRV - (EMSC) – C:\Windows\System32\drivers\EMSC.sys (Windows ® Win 7 DDK provider)
DRV - (CtClsFlt) – C:\Windows\System32\drivers\CtClsFlt.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {F35B856F-5DB2-408B-8C2C-B518BBDB0FD2}
IE - HKLM\..\SearchScopes\{F35B856F-5DB2-408B-8C2C-B518BBDB0FD2}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.telstra.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
IE - HKCU\..\SearchScopes,DefaultScope = {174AB4B7-92CB-4DD1-AC96-2DBF20BE7DD5}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}…00000a0d5ffffae
IE - HKCU\..\SearchScopes\{174AB4B7-92CB-4DD1-AC96-2DBF20BE7DD5}: "URL" = http://au.search.yahoo.com/search?fr=mcafe…p={SearchTerms}
IE - HKCU\..\SearchScopes\{227A86E8-3027-4999-BC67-ECD393B1EDB7}: "URL" = http://websearch.ask.com/redirect?client=i…87-91332D8385FB
IE - HKCU\..\SearchScopes\{A531D99C-5A22-449b-83DA-872725C6D0ED}: "URL" = http://search.alot.com/web?q={searchTerms}…n=1.1.3000.4(B)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012/02/24 10:11:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2012/07/01 08:18:22 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Search the web (Babylon) (Enabled)
CHR - default_search_provider: search_url = http://search.babylon.com/?q={searchTerms}…00000a0d5ffffae
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\elizabeth\AppData\Local\Google\Chrome\Application\18.0.1025.168\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\elizabeth\AppData\Local\Google\Chrome\Application\18.0.1025.168\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\elizabeth\AppData\Local\Google\Chrome\Application\18.0.1025.168\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Babylon Chrome Plugin (Enabled) = C:\Users\elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.4_0\BabylonChromePI.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: McAfee Virtual Technician (Enabled) = C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\elizabeth\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~1\mcafee\msc\npmcsn~1.dll
CHR - Extension: YouTube = C:\Users\elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
CHR - Extension: Google Search = C:\Users\elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: Babylon Translator = C:\Users\elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.4_0\
CHR - Extension: SiteAdvisor = C:\Users\elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\
CHR - Extension: Gmail = C:\Users\elizabeth\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\

O1 HOSTS File: ([2009/06/11 07:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (Babylon BHO)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120701081505.dll (McAfee, Inc.)
O2 - BHO: (ALOT Appbar Helper) - {85F5CF95-EC8F-49fc-BB3F-38C79455CBA2} - C:\Program Files\alotappbar\bin\BHO\ALOTHelperBHO.dll (Vertro)
O2 - BHO: (Babylon IE plugin) - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (Babylon Ltd.)
O3 - HKLM\..\Toolbar: (ALOT Appbar) - {A531D99C-5A22-449b-83DA-872725C6D0ED} - C:\Program Files\alotappbar\bin\alothelper.dll (Vertro)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe (Babylon Ltd.)
O4 - HKLM..\Run: [BigPondWirelessBroadbandCM] C:\Program Files\Telstra\BigPond Wireless Broadband 2.11.21\TelstraUCM.exe (Telstra)
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
O4 - HKLM..\Run: [BTMeter] C:\Program Files\Battery Meter\BTMeter.exe (Dell)
O4 - HKLM..\Run: [CapsLKNotify] C:\Program Files\CapsLKNotify\CapsLKNotify.exe (Compal Electronics, Inc)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [WSED] C:\Program Files\WSED\WSED.exe (Dell)
O4 - Startup: C:\Users\elizabeth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Translate this web page with Babylon - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.)
O8 - Extra context menu item: Translate with Babylon - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.)
O9 - Extra 'Tools' menuitem : Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{168C7F1E-A766-48C7-96C7-BCDEF71A3BBD}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 07:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{711bf971-1c69-11e1-849a-c44619e6a53c}\Shell - "" = AutoRun
O33 - MountPoints2\{711bf971-1c69-11e1-849a-c44619e6a53c}\Shell\AutoRun\command - "" = D:\WIN\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/07/02 21:54:17 | 000,595,968 | —- | C] (OldTimer Tools) – C:\Users\elizabeth\Desktop\OTL.exe
[2012/07/01 08:15:04 | 000,009,608 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeclnk.sys
[2012/07/01 08:14:52 | 000,151,912 | —- | C] (McAfee, Inc.) – C:\Windows\System32\mfevtps.exe
[2012/07/01 08:14:44 | 000,169,608 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfewfpk.sys
[2012/07/01 08:14:42 | 000,087,656 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mferkdet.sys
[2012/07/01 08:14:41 | 000,464,304 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfehidk.sys
[2012/07/01 08:14:41 | 000,340,920 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfefirek.sys
[2012/07/01 08:14:40 | 000,180,848 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeavfk.sys
[2012/07/01 08:14:40 | 000,121,544 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeapfk.sys
[2012/07/01 08:14:40 | 000,059,456 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfebopk.sys
[2012/07/01 08:14:39 | 000,057,600 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\cfwids.sys
[2012/06/30 11:15:02 | 000,000,000 | —D | C] – C:\Users\elizabeth\AppData\Roaming\Malwarebytes
[2012/06/30 11:14:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/06/30 11:14:52 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/06/30 11:14:51 | 000,022,344 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2012/06/30 11:14:51 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/06/30 11:11:45 | 010,063,000 | —- | C] (Malwarebytes Corporation ) – C:\Users\elizabeth\Desktop\mbam-setup-1.61.0.1400.exe
[2012/06/27 15:25:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2012/06/26 11:21:20 | 000,000,000 | —D | C] – C:\Users\elizabeth\AppData\Local\LogMeIn Rescue Applet
[2012/06/21 14:46:55 | 000,045,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2012/06/21 14:46:53 | 002,422,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll
[2012/06/21 14:46:13 | 000,577,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapi.dll
[2012/06/21 14:46:13 | 000,088,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wudriver.dll
[2012/06/21 14:46:13 | 000,035,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups.dll
[2012/06/21 14:45:20 | 000,171,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2012/06/21 14:45:20 | 000,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2012/06/14 16:13:35 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/06/14 16:13:32 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/06/14 16:13:32 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2012/06/14 16:13:32 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/06/14 16:13:30 | 001,800,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012/06/14 16:13:29 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/06/14 16:13:28 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012/06/14 15:28:03 | 002,343,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2012/06/14 15:27:51 | 000,129,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpcorekmts.dll
[2012/06/14 15:27:49 | 000,058,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpwsx.dll
[2012/06/14 15:27:44 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdrmemptylst.exe
[2009/08/26 17:16:14 | 003,570,557 | —- | C] (Macrovision Corporation) – C:\Users\elizabeth\ZTEDrvSetup.exe
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/07/02 21:58:45 | 000,010,272 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/02 21:58:45 | 000,010,272 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/02 21:45:18 | 000,595,968 | —- | M] (OldTimer Tools) – C:\Users\elizabeth\Desktop\OTL.exe
[2012/07/02 21:21:39 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/07/01 08:02:50 | 000,000,410 | —- | M] () – C:\Windows\tasks\vtscheduletask.job
[2012/07/01 08:01:56 | 000,628,460 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/07/01 08:01:56 | 000,110,612 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/06/30 11:41:37 | 796,938,240 | -HS- | M] () – C:\hiberfil.sys
[2012/06/30 11:14:53 | 000,001,069 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/30 11:12:42 | 010,063,000 | —- | M] (Malwarebytes Corporation ) – C:\Users\elizabeth\Desktop\mbam-setup-1.61.0.1400.exe
[2012/06/27 15:25:59 | 000,001,830 | —- | M] () – C:\Users\Public\Desktop\McAfee Security Center.lnk
[2012/06/27 15:23:56 | 000,000,460 | —- | M] () – C:\Users\elizabeth\Desktop\Registration - Broadband - Telstra BigPond.website
[2012/06/15 10:36:55 | 000,302,112 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/06/03 08:19:33 | 000,045,080 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2012/06/03 08:19:32 | 000,035,864 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wups.dll
[2012/06/03 08:19:23 | 000,577,048 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wuapi.dll
[2012/06/03 08:12:32 | 002,422,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll[2012/06/03 08:12:13 | 000,088,576 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wudriver.dll
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/06/30 11:14:53 | 000,001,069 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/27 15:23:56 | 000,000,460 | —- | C] () – C:\Users\elizabeth\Desktop\Registration - Broadband - Telstra BigPond.website
[2012/04/03 17:57:30 | 000,352,256 | R— | C] () – C:\Windows\System32\zshp1600.exe
[2012/04/03 17:57:29 | 001,777,664 | R— | C] () – C:\Windows\System32\zhp1600r.dll
[2012/04/03 17:57:29 | 000,299,008 | R— | C] () – C:\Windows\System32\zhhp1600.exe
[2012/04/03 17:57:28 | 000,749,568 | R— | C] () – C:\Windows\System32\agi1600.dll
[2011/02/24 10:13:54 | 000,000,030 | —- | C] () – C:\Users\elizabeth\MSO3081.acl

========== LOP Check ==========

[2012/05/05 11:26:35 | 000,000,000 | —D | M] – C:\Users\elizabeth\AppData\Roaming\Babylon
[2012/04/12 14:01:28 | 000,000,000 | —D | M] – C:\Users\elizabeth\AppData\Roaming\PCDr
[2011/12/02 08:33:57 | 000,000,000 | —D | M] – C:\Users\elizabeth\AppData\Roaming\Sierra Wireless
[2012/06/30 10:45:48 | 000,000,000 | —D | M] – C:\Users\elizabeth\AppData\Roaming\Telstra
[2012/03/18 20:54:01 | 000,000,000 | —D | M] – C:\Users\elizabeth\AppData\Roaming\Windows Live Writer
[2011/01/26 06:45:18 | 000,000,000 | —D | M] – C:\Users\elizabeth\AppData\Roaming\WirelessManager
[2011/01/26 06:45:27 | 000,000,000 | —D | M] – C:\Users\elizabeth\AppData\Roaming\WMCore
[2012/06/02 08:09:55 | 000,032,642 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2012/07/01 08:02:50 | 000,000,410 | —- | M] () – C:\Windows\Tasks\vtscheduletask.job

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2009/06/11 07:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/06/11 07:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2010/05/15 17:41:43 | 000,003,946 | RH– | M] () – C:\dell.sdr
[2012/06/30 11:41:37 | 796,938,240 | -HS- | M] () – C:\hiberfil.sys
[2012/06/30 11:42:33 | 1073,741,824 | -HS- | M] () – C:\pagefile.sys
[2012/05/05 11:22:10 | 000,003,018 | —- | M] () – C:\user.js

< %systemroot%\Fonts\*.com >
[2009/07/14 14:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 14:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 14:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 14:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/11 07:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/06/28 01:00:00 | 000,057,344 | R— | M] (Zenographics, Inc.) – C:\Windows\system32\spool\prtprocs\w32x86\1_zIMFPRNT.DLL
[2006/10/27 10:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
[2010/11/20 22:21:36 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll
[2007/06/28 01:00:00 | 000,057,344 | —- | M] (Zenographics, Inc.) – C:\Windows\system32\spool\prtprocs\w32x86\zIMFPRNT.DLL

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 14:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/02/06 10:55:40 | 000,000,221 | -HS- | M] () – C:\Users\elizabeth\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/06/30 11:12:42 | 010,063,000 | —- | M] (Malwarebytes Corporation ) – C:\Users\elizabeth\Desktop\mbam-setup-1.61.0.1400.exe
[2012/07/02 21:45:18 | 000,595,968 | —- | M] (OldTimer Tools) – C:\Users\elizabeth\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-06-30 01:39:06

========== Files - Unicode (All) ==========
[2011/02/24 10:19:07 | 000,000,000 | —D | M](C:\Users\elizabeth\??.1033) – C:\Users\elizabeth\??.1033
[2011/02/24 10:19:07 | 000,000,000 | —D | M](C:\Users\elizabeth\??.1033) – C:\Users\elizabeth\??.1033
(C:\Users\elizabeth\??.1033) – C:\Users\elizabeth\??.1033

< End of report >




and here is the output, EXTRAS.TXT:
OTL Extras logfile created on: 7/2/2012 9:59:14 PM - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\elizabeth\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1013.36 Mb Total Physical Memory | 288.30 Mb Available Physical Memory | 28.45% Memory free
1.99 Gb Paging File | 0.65 Gb Available in Paging File | 32.46% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 218.20 Gb Total Space | 183.47 Gb Free Space | 84.08% Space Free | Partition Type: NTFS

Computer Name: ELIZABETH-PC | User Name: elizabeth | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Telstra\BigPond Wireless Broadband 2.11.21\SwiApiMuxX.exe" = C:\Program Files\Telstra\BigPond Wireless Broadband 2.11.21\SwiApiMuxX.exe:*:Enabled:SwiApiMuxX – (Sierra Wireless, Inc.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{06EB7EC4-E162-44C3-82AE-7B8E151F56C2}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{0766B9ED-2311-44CE-821E-AFA07C4293F0}" = lport=445 | protocol=6 | dir=in | app=system |
"{18F2AA42-4E9E-4ADA-8E4C-484F530CDFD8}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{57DC4386-013F-4512-BC62-AEDEB7E6FD6D}" = lport=139 | protocol=6 | dir=in | app=system |
"{73D7A107-A5D5-43EF-A31B-7D544F87DEA3}" = rport=139 | protocol=6 | dir=out | app=system |
"{87BBAB60-33A9-4EC0-AF29-73B31BBD6F55}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{99E3D142-6906-4813-AC46-45ED6BD03C06}" = rport=137 | protocol=17 | dir=out | app=system |
"{A073C10B-0FEC-40A6-93B0-EBB2ADB9EB15}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{AA6381AA-C956-48B7-BE02-155AC8723F66}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{BED37F09-F1A3-4383-A8B2-6CAE6C0585B8}" = rport=445 | protocol=6 | dir=out | app=system |
"{C6BF3641-E27F-49A3-9203-375AFAE57DC9}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{CF75085E-2E23-4D84-9516-15F514EBEE18}" = lport=138 | protocol=17 | dir=in | app=system |
"{E3AFB458-2D91-4B97-945E-7A31673697CA}" = lport=137 | protocol=17 | dir=in | app=system |
"{F1E600FD-6293-432D-8B3A-56296F763012}" = rport=138 | protocol=17 | dir=out | app=system |
"{F92514B8-8F05-4BD0-B833-5D924F017325}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{FAE65A1D-778E-4B6A-8CA6-078C7E07CF16}" = lport=2869 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1AAF4713-2601-4E22-9EA3-A2F5CAC8A825}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{31A3EF5B-B291-4F57-B05C-5C4D7E273020}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{35B97448-A693-4830-B00B-E7A9589DC7B5}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{3A9BC065-9A77-4300-AF41-B965DA2794E2}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{56B6394F-C456-4C84-BAE0-60626D5E1F66}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{5AC1CB4B-8B30-4301-869E-A59DFC3B2C37}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{7D82F119-5E28-4049-B170-D933E684E9A6}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{8EF81588-21C0-4E63-A50B-210192C8DF6F}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{A457F313-968A-423E-ACE6-2660F16C45FC}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A4B53939-9924-449D-9EE4-D49B0048A9F3}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{AB3E7F0E-88DE-4154-ADFE-FB75AC4D009A}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{BB04FBC2-3BC6-4C58-B977-A2B52A336823}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{CA1E0751-34AE-4864-9720-8E760708BE4C}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{CC3B3198-C4F7-43A0-86D3-A8FC117ED0C3}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{D3AB60AE-ED4D-49BA-B2E8-0DBEB4BE91D3}" = dir=in | app=c:\program files\common files\mcafee\mna\mcnasvc.exe |
"{E5632BB0-A401-40F5-A3E9-C2C7954E2896}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{F1E900D8-07C4-436A-A99D-0A8F230D2206}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{F44289A6-5E9D-42A2-BB2B-CB2F52566BB5}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"TCP Query User{A24862F6-43CD-46CE-8D17-80EDC11913C4}C:\users\elizabeth\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe" = protocol=6 | dir=in | app=c:\users\elizabeth\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe |
"UDP Query User{D6AF349F-5E4E-4317-A832-EDD09A231133}C:\users\elizabeth\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe" = protocol=17 | dir=in | app=c:\users\elizabeth\appdata\local\logmein rescue applet\lmir0001.tmp\lmi_rescue.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{053E51D3-885D-425C-9586-EA5183C4C688}" = Function Keys
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}" = Dell DataSafe Online
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{23EEC842-57ED-4055-A056-9D4185DFB1AA}" = Dell Mobile Broadband Manager
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{29462389-ED3C-4CB4-8172-03B3FD43BD41}" = Mobile Broadband Manager
"{3138EAD3-700B-4A10-B617-B3F8096EE30D}" = Dell Edoc Viewer
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{353FE16B-30FE-469A-BF55-B978F4218003}" = iTunes
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{543A4F31-9590-416A-A621-42CEB4C6A694}" = Battery Meter
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{61916F4F-A6B5-40A7-B29F-C940E270924A}" = Broadcom CrystalHD Decoder
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90578106-70AF-4198-B9DE-1924FA83B03A}" = CapsLKNotify
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = WIDCOMM Bluetooth Software
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.2
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C73A3942-84C8-4597-9F9B-EE227DCBA758}" = Dell Dock
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D6C3C9E7-D334-4918-BD57-5B1EF14C207D}" = Bing Bar
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}" = SRS Premium Sound Control Panel
"{E6CB6126-D120-4FB5-9D1B-E2E19003E66C}" = WSED
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FEF06E73-A519-4510-8CF3-B66041B91D8A}" = EMSC
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"alotAppbar" = ALOT Appbar
"Babylon" = Babylon
"BabylonToolbar" = Babylon toolbar on IE
"Dell Dock" = Dell Dock
"Dell Webcam Central" = Dell Webcam Central
"Dell Wireless WLAN Card Utility" = Dell Wireless WLAN Card Utility
"GoToAssist" = GoToAssist 8.0.0.514
"HDMI" = Intel® Graphics Media Accelerator Driver
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP-Color LaserJet 1600" = Color LaserJet 1600
"InstallShield_{543A4F31-9590-416A-A621-42CEB4C6A694}" = Battery Meter
"InstallShield_{90578106-70AF-4198-B9DE-1924FA83B03A}" = CapsLKNotify
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"McAfee Virtual Technician" = McAfee Virtual Technician
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mobile Broadband Manager" = Telstra Mobile Broadband Manager
"MSC" = McAfee SecurityCenter
"SynTPDeinstKey" = Dell Touchpad
"WinLiveSuite" = Windows Live Essentials
"ZTE USB Driver" = ZTE USB Driver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Ask Toolbar Updater

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 6/1/2012 6:11:02 PM | Computer Name = elizabeth-PC | Source = Swapdrive Backup | ID = 0
Description = Swapdrive Backup: Web Service Error: System.Net.WebException: The
remote name could not be resolved: 'wsvcdell.backup.com' at System.Net.HttpWebRequest.GetRequestStream(TransportContext&
context) at System.Net.HttpWebRequest.GetRequestStream() at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String
methodName, Object[] parameters) at Swapdrive.Shared.com.backup.uswsvcdell.Service.GetInfo(GetInfoRequest
req) at Swapdrive.Shared.ActivationWsvcs.GetInfo()

Error - 6/2/2012 1:34:57 AM | Computer Name = elizabeth-PC | Source = Application Error | ID = 1000
Description = Faulting application name: SwiApiMuxX.exe, version: 11.4.1107.2, time
stamp: 0x4e24c921 Faulting module name: SwiApiMuxX.exe, version: 11.4.1107.2, time
stamp: 0x4e24c921 Exception code: 0xc0000005 Fault offset: 0x0000c109 Faulting process
id: 0x10e4 Faulting application start time: 0x01cd4043655e39ed Faulting application
path: C:\Program Files\Telstra\BigPond Wireless Broadband 2.11.21\SwiApiMuxX.exe
Faulting
module path: C:\Program Files\Telstra\BigPond Wireless Broadband 2.11.21\SwiApiMuxX.exe
Report
Id: af75f908-ac74-11e1-8bdf-c44619e6a53c

Error - 6/2/2012 1:40:04 AM | Computer Name = elizabeth-PC | Source = Swapdrive Backup | ID = 0
Description = Swapdrive Backup: Web Service Error: System.Net.WebException: The
remote name could not be resolved: 'wsvcdell.backup.com' at System.Net.HttpWebRequest.GetRequestStream(TransportContext&
context) at System.Net.HttpWebRequest.GetRequestStream() at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String
methodName, Object[] parameters) at Swapdrive.Shared.com.backup.uswsvcdell.Service.GetInfo(GetInfoRequest
req) at Swapdrive.Shared.ActivationWsvcs.GetInfo()

Error - 6/3/2012 8:26:16 PM | Computer Name = elizabeth-PC | Source = Swapdrive Backup | ID = 0
Description = Swapdrive Backup: Web Service Error: System.Net.WebException: The
remote name could not be resolved: 'wsvcdell.backup.com' at System.Net.HttpWebRequest.GetRequestStream(TransportContext&
context) at System.Net.HttpWebRequest.GetRequestStream() at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String
methodName, Object[] parameters) at Swapdrive.Shared.com.backup.uswsvcdell.Service.GetInfo(GetInfoRequest
req) at Swapdrive.Shared.ActivationWsvcs.GetInfo()

Error - 6/4/2012 10:21:47 PM | Computer Name = elizabeth-PC | Source = Swapdrive Backup | ID = 0
Description = Swapdrive Backup: Web Service Error: System.Net.WebException: The
remote name could not be resolved: 'wsvcdell.backup.com' at System.Net.HttpWebRequest.GetRequestStream(TransportContext&
context) at System.Net.HttpWebRequest.GetRequestStream() at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String
methodName, Object[] parameters) at Swapdrive.Shared.com.backup.uswsvcdell.Service.GetInfo(GetInfoRequest
req) at Swapdrive.Shared.ActivationWsvcs.GetInfo()

Error - 6/5/2012 4:24:10 AM | Computer Name = elizabeth-PC | Source = Swapdrive Backup | ID = 0
Description = Swapdrive Backup: Web Service Error: System.Net.WebException: The
remote name could not be resolved: 'wsvcdell.backup.com' at System.Net.HttpWebRequest.GetRequestStream(TransportContext&
context) at System.Net.HttpWebRequest.GetRequestStream() at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String
methodName, Object[] parameters) at Swapdrive.Shared.com.backup.uswsvcdell.Service.GetInfo(GetInfoRequest
req) at Swapdrive.Shared.ActivationWsvcs.GetInfo()

Error - 6/13/2012 7:01:08 PM | Computer Name = elizabeth-PC | Source = Swapdrive Backup | ID = 0
Description = Swapdrive Backup: Web Service Error: System.Net.WebException: The
remote name could not be resolved: 'wsvcdell.backup.com' at System.Net.HttpWebRequest.GetRequestStream(TransportContext&
context) at System.Net.HttpWebRequest.GetRequestStream() at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String
methodName, Object[] parameters) at Swapdrive.Shared.com.backup.uswsvcdell.Service.GetInfo(GetInfoRequest
req) at Swapdrive.Shared.ActivationWsvcs.GetInfo()

Error - 6/13/2012 7:06:45 PM | Computer Name = elizabeth-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 9.0.8112.16421 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 764 Start
Time: 01cd49b8a43b1cad Termination Time: 1158 Application Path: C:\Program Files\Internet
Explorer\iexplore.exe Report Id:

Error - 6/13/2012 7:47:15 PM | Computer Name = elizabeth-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 9.0.8112.16421 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 140 Start
Time: 01cd49b926396c78 Termination Time: 3286 Application Path: C:\Program Files\Internet
Explorer\iexplore.exe Report Id:

Error - 6/14/2012 12:54:20 AM | Computer Name = elizabeth-PC | Source = Swapdrive Backup | ID = 0
Description = Swapdrive Backup: Web Service Error: System.Net.WebException: The
remote name could not be resolved: 'wsvcdell.backup.com' at System.Net.HttpWebRequest.GetRequestStream(TransportContext&
context) at System.Net.HttpWebRequest.GetRequestStream() at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String
methodName, Object[] parameters) at Swapdrive.Shared.com.backup.uswsvcdell.Service.GetInfo(GetInfoRequest
req) at Swapdrive.Shared.ActivationWsvcs.GetInfo()

[ Broadcom Wireless LAN Events ]
Error - 9/15/2010 5:26:03 PM | Computer Name = elizabeth-PC | Source = WLAN-Tray | ID = 0
Description = 07:26:03, Thu, Sep 16, 10 Error - Unable to switch user context, authentication
information not set correctly

Error - 9/15/2010 8:58:12 PM | Computer Name = elizabeth-PC | Source = WLAN-Tray | ID = 0
Description = 10:58:12, Thu, Sep 16, 10 Error - Unable to switch user context, authentication
information not set correctly

Error - 9/15/2010 8:58:37 PM | Computer Name = elizabeth-PC | Source = WLAN-Tray | ID = 0
Description = 10:58:37, Thu, Sep 16, 10 Error - Unable to get current user admin
status

Error - 9/15/2010 9:11:20 PM | Computer Name = elizabeth-PC | Source = WLAN-Tray | ID = 0
Description = 11:11:20, Thu, Sep 16, 10 Error - Unable to switch user context, authentication
information not set correctly

Error - 9/15/2010 9:11:45 PM | Computer Name = elizabeth-PC | Source = WLAN-Tray | ID = 0
Description = 11:11:45, Thu, Sep 16, 10 Error - Unable to get current user admin
status

Error - 2/23/2011 8:11:13 PM | Computer Name = elizabeth-PC | Source = WLAN-Tray | ID = 0
Description = 11:11:12, Thu, Feb 24, 11 Error - Unable to switch user context, error
87

Error - 2/23/2011 8:24:14 PM | Computer Name = elizabeth-PC | Source = WLAN-Tray | ID = 0
Description = 11:24:14, Thu, Feb 24, 11 Error - Unable to gain access to user store


Error - 4/25/2011 7:03:51 PM | Computer Name = elizabeth-PC | Source = WLAN-Tray | ID = 0
Description = 09:03:51, Tue, Apr 26, 11 Error - Unable to gain access to user store


Error - 4/28/2011 6:11:29 AM | Computer Name = elizabeth-PC | Source = WLAN-Tray | ID = 0
Description = 20:11:29, Thu, Apr 28, 11 Error - Unable to gain access to user store


Error - 5/9/2011 2:46:27 AM | Computer Name = elizabeth-PC | Source = WLAN-Tray | ID = 0
Description = 16:46:27, Mon, May 09, 11 Error - Unable to gain access to user store


[ ODiag Events ]
Error - 2/23/2011 8:14:16 PM | Computer Name = elizabeth-PC | Source = Microsoft Office 12 Diagnostics | ID = 320
Description = An unexpected error occurred. Tag: 2kcx. Error code: N/A

Error - 2/23/2011 8:15:58 PM | Computer Name = elizabeth-PC | Source = Microsoft Office 12 Diagnostics | ID = 320
Description = An unexpected error occurred. Tag: 2kcx. Error code: N/A

[ OSession Events ]
Error - 2/23/2011 8:14:13 PM | Computer Name = elizabeth-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 73
seconds with 60 seconds of active time. This session ended with a crash.

Error - 2/23/2011 8:15:57 PM | Computer Name = elizabeth-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 60
seconds with 0 seconds of active time. This session ended with a crash.

Error - 2/23/2011 8:19:07 PM | Computer Name = elizabeth-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 158
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 5/2/2012 8:26:22 PM | Computer Name = elizabeth-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom

Error - 5/3/2012 7:22:38 AM | Computer Name = elizabeth-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom

Error - 5/4/2012 9:16:37 PM | Computer Name = elizabeth-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom

Error - 5/5/2012 4:24:27 AM | Computer Name = elizabeth-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom

Error - 5/6/2012 8:41:08 PM | Computer Name = elizabeth-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom

Error - 5/6/2012 8:47:51 PM | Computer Name = elizabeth-PC | Source = DCOM | ID = 10010
Description =

Error - 5/7/2012 4:23:11 AM | Computer Name = elizabeth-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom

Error - 5/9/2012 6:57:47 PM | Computer Name = elizabeth-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom

Error - 5/10/2012 12:47:00 AM | Computer Name = elizabeth-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom

Error - 5/10/2012 12:53:07 AM | Computer Name = elizabeth-PC | Source = Service Control Manager | ID = 7022
Description = The McAfee McShield service hung on starting.


< End of report >
Hi kangaroo,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

I'm not seeing anything obvious.

Let's try this:

As we work through your logs. Please remember to run any tools by Right-clicking on the icon and selecting Run As Administrator….

Download ComboFix from here: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Right click on ComboFix.exe, select "Run as Admin…" & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Thanks, Tomk, for for your help. Your post said that ComboFix disables autorun of USB devices. My neighbour's Dell Inspiron Mini does not have a DVD/CD drive and she relies on USB drives for transferring data. When we are finished solving this issue, I'd like to know how to re-enable autorun for USB devices, please. I've used Run as Admnistrator to run ComboFix. The log file is: ComboFix 12-07-06.01 - elizabeth 06/07/2012 21:37:29.1.2 - x86 Microsoft Windows 7 Starter 6.1.7601.1.1252.61.1033.18.1013.264 [GMT 10:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637} FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C} SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\alotappbar c:\program files\alotappbar\alotUninst.exe c:\program files\alotappbar\bin\alotappbar.dll c:\program files\alotappbar\bin\alothelper.dll c:\program files\alotappbar\bin\ALOTSettings.exe c:\program files\alotappbar\bin\alotwidgets.exe c:\program files\alotappbar\bin\BHO\ALOTHelperBHO.dll c:\windows\system32\TBD382.tmp . . ((((((((((((((((((((((((( Files Created from 2012-06-06 to 2012-07-06 ))))))))))))))))))))))))))))))) . . 2012-07-06 12:03 . 2012-07-06 12:03 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-07-06 11:26 . 2012-07-06 11:26 56200 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4E1D78AF-AF27-429F-8FBC-DC52652A4CA9}\offreg.dll 2012-06-30 22:15 . 2012-02-22 03:29 9608 —-a-w- c:\windows\system32\drivers\mfeclnk.sys 2012-06-30 22:14 . 2012-05-25 07:13 151912 —-a-w- c:\windows\system32\mfevtps.exe 2012-06-30 22:14 . 2012-02-22 03:29 169608 —-a-w- c:\windows\system32\drivers\mfewfpk.sys 2012-06-30 22:14 . 2012-02-22 03:29 87656 —-a-w- c:\windows\system32\drivers\mferkdet.sys 2012-06-30 22:14 . 2012-02-22 03:29 464304 —-a-w- c:\windows\system32\drivers\mfehidk.sys 2012-06-30 22:14 . 2012-02-22 03:29 340920 —-a-w- c:\windows\system32\drivers\mfefirek.sys 2012-06-30 22:14 . 2012-02-22 03:29 59456 —-a-w- c:\windows\system32\drivers\mfebopk.sys 2012-06-30 22:14 . 2012-02-22 03:29 180848 —-a-w- c:\windows\system32\drivers\mfeavfk.sys 2012-06-30 22:14 . 2012-02-22 03:29 121544 —-a-w- c:\windows\system32\drivers\mfeapfk.sys 2012-06-30 22:14 . 2012-02-22 03:29 57600 —-a-w- c:\windows\system32\drivers\cfwids.sys 2012-06-30 01:15 . 2012-06-30 01:15 ——– d—–w- c:\users\elizabeth\AppData\Roaming\Malwarebytes 2012-06-30 01:14 . 2012-06-30 01:14 ——– d—–w- c:\programdata\Malwarebytes 2012-06-30 01:14 . 2012-06-30 01:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2012-06-30 01:14 . 2012-04-04 05:56 22344 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-06-30 00:51 . 2012-06-17 17:14 6762896 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4E1D78AF-AF27-429F-8FBC-DC52652A4CA9}\mpengine.dll 2012-06-26 01:21 . 2012-06-26 02:26 ——– d—–w- c:\users\elizabeth\AppData\Local\LogMeIn Rescue Applet 2012-06-21 04:46 . 2012-06-02 22:19 45080 —-a-w- c:\windows\system32\wups2.dll 2012-06-21 04:46 . 2012-06-02 22:19 53784 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-21 04:46 . 2012-06-02 22:19 1933848 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-21 04:46 . 2012-06-02 22:12 2422272 —-a-w- c:\windows\system32\wucltux.dll 2012-06-21 04:46 . 2012-06-02 22:19 35864 —-a-w- c:\windows\system32\wups.dll 2012-06-21 04:46 . 2012-06-02 22:19 577048 —-a-w- c:\windows\system32\wuapi.dll 2012-06-21 04:46 . 2012-06-02 22:12 88576 —-a-w- c:\windows\system32\wudriver.dll 2012-06-21 04:45 . 2012-06-02 05:19 171904 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-21 04:45 . 2012-06-02 05:12 33792 —-a-w- c:\windows\system32\wuapp.exe 2012-06-14 05:33 . 2012-04-07 11:26 2342400 —-a-w- c:\windows\system32\msi.dll 2012-06-14 05:32 . 2012-04-28 03:17 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-06-14 05:28 . 2012-05-15 01:05 2343936 —-a-w- c:\windows\system32\win32k.sys 2012-06-14 05:27 . 2012-04-26 04:45 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-06-14 05:27 . 2012-04-26 04:45 58880 —-a-w- c:\windows\system32\rdpwsx.dll 2012-06-14 05:27 . 2012-04-26 04:41 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-06-14 05:27 . 2012-05-01 04:44 164352 —-a-w- c:\windows\system32\profsvc.dll 2012-06-14 05:26 . 2012-04-24 04:36 1158656 —-a-w- c:\windows\system32\crypt32.dll 2012-06-14 05:25 . 2012-04-24 04:36 140288 —-a-w- c:\windows\system32\cryptsvc.dll 2012-06-14 05:24 . 2012-04-24 04:36 103936 —-a-w- c:\windows\system32\cryptnet.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2012-01-03 05:31 1514152 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-01-03 1514152] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-01-03 1514152] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-02-05 1692968] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-11-17 7866912] "Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-07-17 4562944] "BTMeter"="c:\program files\Battery Meter\BTMeter.exe" [2009-09-17 632176] "WSED"="c:\program files\WSED\WSED.exe" [2009-05-27 247080] "CapsLKNotify"="c:\program files\CapsLKNotify\CapsLKNotify.exe" [2009-06-09 320880] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "Dell DataSafe Online"="c:\program files\Dell DataSafe Online\DataSafeOnline.exe" [2009-11-13 1807600] "dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-06-03 206064] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-14 421160] "BigPondWirelessBroadbandCM"="c:\program files\Telstra\BigPond Wireless Broadband 2.11.21\TelstraUCM.exe" [2011-09-07 6198168] "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-21 1318816] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] "ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2012-01-03 1391272] "Babylon Client"="c:\program files\Babylon\Babylon-Pro\Babylon.exe" [2012-03-13 3196016] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-10-24 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-10-24 173592] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-10-24 150552] . c:\users\elizabeth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-16 1324384] OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-2 795936] SRS Premium Sound.lnk - c:\windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut6_96BE12D997374F89986526ECCB660D4F.exe [2010-5-15 156952] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-16 1324384] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist] 2010-05-15 05:22 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "mixer1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 BBSvc;BingBar Service;c:\program files\Microsoft\BingBar\7.1.361.0\BBSvc.exe [x] R3 d554gps;Dell Wireless HSPA Mini-Card GPS Port;c:\windows\system32\DRIVERS\d554gps.sys [x] R3 d557bus;Dell Wireless 5540 HSPA Mini-Card Device (Win7);c:\windows\system32\DRIVERS\d557bus.sys [x] R3 d557mdfl;Dell Wireless 5540 HSPA Mini-Card Modem Filter (Win7);c:\windows\system32\DRIVERS\d557mdfl.sys [x] R3 d557mdm;Dell Wireless 5540 HSPA Mini-Card Modem (Win7);c:\windows\system32\DRIVERS\d557mdm.sys [x] R3 d557mgmt;Dell Wireless 5540 HSPA Mini-Card Device Management (Win7);c:\windows\system32\DRIVERS\d557mgmt.sys [x] R3 ecnssndis;Service for enabling selective suspend to NDIS device;c:\windows\system32\Drivers\wwanuss.sys [x] R3 ecnssndisfltr;SSNDIS filter service;c:\windows\system32\Drivers\wwanussf.sys [x] R3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [x] R3 massfilter_lte;LTE Device Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter_lte.sys [x] R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [x] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x] R3 swg3kser00;Sierra Wireless QMI USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\swg3kser00.sys [x] R3 swiwdmbx;Sierra Wireless USB Bus Service;c:\windows\system32\DRIVERS\swiwdmbx.sys [x] R3 SWNC8UA3;Sierra Wireless MUX NDIS Driver (UMTSA3);c:\windows\system32\DRIVERS\swnc8ua3.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 WwanUsbServ;Ericsson WWAN Wireless Module Device Driver;c:\windows\system32\DRIVERS\WwanUsbMp.sys [x] R3 ZTEusbnet;ZTE USB-NDIS miniport;c:\windows\system32\DRIVERS\ZTEusbnet.sys [x] S0 EMSC;COMPAL Embedded System Control;c:\windows\system32\DRIVERS\EMSC.SYS [x] S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [x] S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [x] S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [x] S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [x] S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [x] S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [x] S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [x] S2 SwiCardDetectSvc;Sierra Wireless Card Detection Service;c:\program files\Sierra Wireless Inc\Common\SwiCardDetect.exe [x] S2 WMCoreService;Mobile Broadband Core Service;c:\program files\Dell\Dell WWAN\WMCore\mini_WMCore.exe servicemode [x] S3 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\7.1.361.0\SeaPort.exe [x] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x] S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [x] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x] S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [x] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . — Other Services/Drivers In Memory — . *Deregistered* - mfeavfk01 . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc . Contents of the 'Scheduled Tasks' folder . 2012-06-30 c:\windows\Tasks\vtscheduletask.job - c:\program files\McAfee\Supportability\MVT\MvtApp.exe [2011-02-08 03:25] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com.au/ uInternet Settings,ProxyOverride = *.local IE: Translate this web page with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm IE: Translate with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm Trusted Zone: internet Trusted Zone: mcafee.com . - - - - ORPHANS REMOVED - - - - . BHO-{85F5CF95-EC8F-49fc-BB3F-38C79455CBA2} - c:\program files\alotappbar\bin\BHO\ALOTHelperBHO.dll Toolbar-Locked - (no file) Toolbar-{A531D99C-5A22-449b-83DA-872725C6D0ED} - c:\program files\alotappbar\bin\ALOTHelper.dll AddRemove-alotAppbar - c:\program files\alotappbar\alotUninst.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-780604905-3422884488-2714364874-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-780604905-3422884488-2714364874-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-07-06 22:14:43 ComboFix-quarantined-files.txt 2012-07-06 12:14 . Pre-Run: 196,318,593,024 bytes free Post-Run: 197,252,014,080 bytes free . - - End Of File - - C7122FD60EC8019A614AAD1644ECDFBF Looking forward to your response. Kangaroo
kangaroo,

Your post said that ComboFix disables autorun of USB devices. My neighbour's Dell Inspiron Mini does not have a DVD/CD drive and she relies on USB drives for transferring data. When we are finished solving this issue, I'd like to know how to re-enable autorun for USB devices, please.


I should have taken that note out of my instructions as this computer is Windows 7 and that information only applies to XP and older. Starting with Vista, Microsoft corrected the autorun issue. Windows 7 computers do not have this function so it cannot be started or stopped. Your neighbors system will continue to work as it always did.

The log looks good. I'm thinking that this isn't a malware issue and you may be better served in the windows forum. But let's run an online scan first and see if it finds anything.

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
Hi Tomk, I've tried to run the Eset Online scnner twice, The first tiime it stalled at 44% in Step 3 of 4; the second at 46% in Step 3 of 4. Both times it has found 6 infected files (the second time it had been running for 1hr,10mins) and threat found is: Win32/Toolbar Babylon application Win32/Toolbar Babylon application probably a variant of Win32/Toolbar Babylon application Win32/Toolbar Babylon application a variant of Win32/Toolbar Babylon application Win32/Toolbar Babylon application Oops! I just noticed that the target files are still changing and the files scanned is increasing so it hasn't stalled as I thought. I have to take some things to my wife in hospital now so I'll leave it running until I get back this afternoon and update this reply with the scan log then. Thanks for your help Kangaroo
Yeah… it takes hours to run. Babylon toolbar is a "semi" legitimate toolbar. It is often considered as foistware as it is forced on people sometimes when they install other programs. It is also fairly heavy on resources. It's purpose is to provide language translations. I've never used it and it doesn't have a great reputation. Please check with your neighbor and see if it is something they want/need. Otherwise I'd like to remove it.
Thanks, Tomk. I'm back from hospital and Eset hasn't finished; showing 98% Step 3 out of 4, scan time 13hr 48 mins, still only 6 infected files, 56852 files scanned and target is C:\Windows\SoftwareDistribution\Download\e5556aeb…\windows6.1-kb976932-x86.cab. There is still HDD activity indicated by the access light. I'll let it run for now unless you suggest I stop it. I spoke with my neighbour and she is very happy to remove the Babylon Toolbar; hopes it will speed things up a bit. I'll post again when Eset is finished. Kangaroo
Hi Tomk, Finished at last. The scan took 16:43:23, scanned 114586 files, found 6 infected files (threats as listed previously) and cleaned 0 files (as per settings you gave). Here is the log: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330) # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=bfc00636448d4048b8fa622c7aa709d7 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2012-07-06 11:08:00 # local_time=2012-07-07 09:08:00 (+1000, AUS Eastern Standard Time) # country="Australia" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5121 16777213 100 75 522485 6829400 0 0 # compatibility_mode=5893 16776573 100 94 4597 93248259 0 0 # compatibility_mode=8192 67108863 100 0 4084 4084 0 0 # scanned=2634 # found=6 # cleaned=0 # scan_time=2613 C:\Program Files\Babylon\Babylon-Pro\Utils\MyBabylonTB.exe Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarApp.dll a variant of Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarEng.dll Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarsrv.exe probably a variant of Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I esets_scanner_update returned -1 esets_gle=53251 # version=7 # iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330) # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=bfc00636448d4048b8fa622c7aa709d7 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2012-07-07 03:56:54 # local_time=2012-07-08 01:56:54 (+1000, AUS Eastern Standard Time) # country="Australia" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5121 16777213 100 75 525427 6832342 0 0 # compatibility_mode=5893 16776573 100 94 7539 93251201 0 0 # compatibility_mode=8192 67108863 100 0 7026 7026 0 0 # scanned=114586 # found=6 # cleaned=0 # scan_time=60203 C:\Program Files\Babylon\Babylon-Pro\Utils\MyBabylonTB.exe Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarApp.dll a variant of Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarEng.dll Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarsrv.exe probably a variant of Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I Look forward to hearing further from you. Enjoy your weekend. Kangaroo
COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    Folder::
    C:\Program Files\BabylonToolbar
    C:\Program Files\Babylon
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Also, give it a bit of a workout and let me know how things are running now.
Hi Tomk, nice to have you back online; I was getting a bit worried that I couldn't access WTT. Here is the CF log after removing Babylon: ComboFix 12-07-06.01 - elizabeth 08/07/2012 13:25:40.2.2 - x86 Microsoft Windows 7 Starter 6.1.7601.1.1252.61.1033.18.1013.266 [GMT 10:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\elizabeth\Desktop\CFScript.txt AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637} FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C} SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\Babylon c:\program files\Babylon\Babylon-Pro\Babylon.exe c:\program files\Babylon\Babylon-Pro\BabyServices.dll c:\program files\Babylon\Babylon-Pro\BContentServer.dll c:\program files\Babylon\Babylon-Pro\BContentServerExt.dll c:\program files\Babylon\Babylon-Pro\BException.dll c:\program files\Babylon\Babylon-Pro\captlib.dll c:\program files\Babylon\Babylon-Pro\Data\bab027.tt180312_ctrl.dat c:\program files\Babylon\Babylon-Pro\Data\bab094.band.dat c:\program files\Babylon\Babylon-Pro\Data\bab102.NDskIcn.dat c:\program files\Babylon\Babylon-Pro\Data\bab225.rsttrl.dat c:\program files\Babylon\Babylon-Pro\Data\Babylon.dat c:\program files\Babylon\Babylon-Pro\Data\CSConfig.dat c:\program files\Babylon\Babylon-Pro\Data\Features.dat c:\program files\Babylon\Babylon-Pro\Data\LDTs\Afrikaans.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Albanian.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Arabic.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Armenian.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Basque.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Belarus.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Belarusian.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Bulgarian.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Catalan.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Chinese (S).ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Chinese (T).ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Croatian.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Czech.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Danish.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Dutch.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\English.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Esperanto.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Estonian.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Faeroese.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Farsi.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Filipino.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Finnish.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\French.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\German.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Greek.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Hausa.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Hebrew.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Hindi.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Hungarian.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Icelandic.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Indonesian.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Italian.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Japanese.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Korean.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Latin.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Latvian.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Lithuanian.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Macedonian.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Malay.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Mongolian.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Norwegian.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Pashto.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Polish.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Portuguese.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Romanian.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Russian.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Serbian.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Slovak.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Slovenian.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Somali.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Spanish.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Swedish.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Tamazight.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Thai.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Turkish.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Ukrainian.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Urdu.ldt c:\program files\Babylon\Babylon-Pro\Data\LDTs\Vietnamese.ldt c:\program files\Babylon\Babylon-Pro\Data\Metaphone.dat c:\program files\Babylon\Babylon-Pro\Data\Strings.dat c:\program files\Babylon\Babylon-Pro\TC\BabylonTC.exe c:\program files\Babylon\Babylon-Pro\TC\BabylonTC.exe.manifest c:\program files\Babylon\Babylon-Pro\TC\osmax.ocx c:\program files\Babylon\Babylon-Pro\TC\osmax.X.manifest c:\program files\Babylon\Babylon-Pro\TC\resources\{A7EAE3F1-D99E-4845-9F57-FB791C65509B}\images\bg-ginger.png c:\program files\Babylon\Babylon-Pro\TC\resources\{A7EAE3F1-D99E-4845-9F57-FB791C65509B}\images\bg-popup-offline.gif c:\program files\Babylon\Babylon-Pro\TC\resources\{A7EAE3F1-D99E-4845-9F57-FB791C65509B}\index.html c:\program files\Babylon\Babylon-Pro\TC\resources\{A7EAE3F1-D99E-4845-9F57-FB791C65509B}\style.css c:\program files\Babylon\Babylon-Pro\TC\resources\{E9B85A27-7C0D-4b0e-AE5F-3141E7508772}\images\bg-ginger.png c:\program files\Babylon\Babylon-Pro\TC\resources\{E9B85A27-7C0D-4b0e-AE5F-3141E7508772}\images\bg-popup-offline.gif c:\program files\Babylon\Babylon-Pro\TC\resources\{E9B85A27-7C0D-4b0e-AE5F-3141E7508772}\index.html c:\program files\Babylon\Babylon-Pro\TC\resources\{E9B85A27-7C0D-4b0e-AE5F-3141E7508772}\style.css c:\program files\Babylon\Babylon-Pro\TC\resources\babylontc.ico c:\program files\Babylon\Babylon-Pro\TC\secman.dll c:\program files\Babylon\Babylon-Pro\TC\secman.X.manifest c:\program files\Babylon\Babylon-Pro\Updates\Convert.dat c:\program files\Babylon\Babylon-Pro\Updates\Rates.dat c:\program files\Babylon\Babylon-Pro\Utils\Babylon.xpi c:\program files\Babylon\Babylon-Pro\Utils\BabylonChrome.crx c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll c:\program files\Babylon\Babylon-Pro\Utils\BabylonNoTB.xpi c:\program files\Babylon\Babylon-Pro\Utils\BabylonOfficePI.dll c:\program files\Babylon\Babylon-Pro\Utils\BabylonRPI.api c:\program files\Babylon\Babylon-Pro\Utils\MyBabylonTB.exe c:\program files\Babylon\Babylon-Pro\Utils\uninstbb.exe c:\program files\BabylonToolbar c:\program files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarApp.dll c:\program files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarEng.dll c:\program files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarsrv.exe c:\program files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll c:\program files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll c:\program files\BabylonToolbar\BabylonToolbar\1.5.3.17\uninstall.exe . . ((((((((((((((((((((((((( Files Created from 2012-06-08 to 2012-07-08 ))))))))))))))))))))))))))))))) . . 2012-07-08 03:47 . 2012-07-08 03:56 ——– d—–w- c:\users\elizabeth\AppData\Local\temp 2012-07-08 03:47 . 2012-07-08 03:47 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-07-06 23:19 . 2012-07-06 23:19 56200 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{59C514FC-32D4-4883-9FC6-47325DDE7F4C}\offreg.dll 2012-07-06 22:07 . 2012-06-17 17:14 6762896 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{59C514FC-32D4-4883-9FC6-47325DDE7F4C}\mpengine.dll 2012-06-30 22:15 . 2012-02-22 03:29 9608 —-a-w- c:\windows\system32\drivers\mfeclnk.sys 2012-06-30 22:14 . 2012-05-25 07:13 151912 —-a-w- c:\windows\system32\mfevtps.exe 2012-06-30 22:14 . 2012-02-22 03:29 169608 —-a-w- c:\windows\system32\drivers\mfewfpk.sys 2012-06-30 22:14 . 2012-02-22 03:29 87656 —-a-w- c:\windows\system32\drivers\mferkdet.sys 2012-06-30 22:14 . 2012-02-22 03:29 464304 —-a-w- c:\windows\system32\drivers\mfehidk.sys 2012-06-30 22:14 . 2012-02-22 03:29 340920 —-a-w- c:\windows\system32\drivers\mfefirek.sys 2012-06-30 22:14 . 2012-02-22 03:29 59456 —-a-w- c:\windows\system32\drivers\mfebopk.sys 2012-06-30 22:14 . 2012-02-22 03:29 180848 —-a-w- c:\windows\system32\drivers\mfeavfk.sys 2012-06-30 22:14 . 2012-02-22 03:29 121544 —-a-w- c:\windows\system32\drivers\mfeapfk.sys 2012-06-30 22:14 . 2012-02-22 03:29 57600 —-a-w- c:\windows\system32\drivers\cfwids.sys 2012-06-30 01:15 . 2012-06-30 01:15 ——– d—–w- c:\users\elizabeth\AppData\Roaming\Malwarebytes 2012-06-30 01:14 . 2012-06-30 01:14 ——– d—–w- c:\programdata\Malwarebytes 2012-06-30 01:14 . 2012-06-30 01:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2012-06-30 01:14 . 2012-04-04 05:56 22344 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-06-26 01:21 . 2012-06-26 02:26 ——– d—–w- c:\users\elizabeth\AppData\Local\LogMeIn Rescue Applet 2012-06-21 04:46 . 2012-06-02 22:19 45080 —-a-w- c:\windows\system32\wups2.dll 2012-06-21 04:46 . 2012-06-02 22:19 53784 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-21 04:46 . 2012-06-02 22:19 1933848 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-21 04:46 . 2012-06-02 22:12 2422272 —-a-w- c:\windows\system32\wucltux.dll 2012-06-21 04:46 . 2012-06-02 22:19 35864 —-a-w- c:\windows\system32\wups.dll 2012-06-21 04:46 . 2012-06-02 22:19 577048 —-a-w- c:\windows\system32\wuapi.dll 2012-06-21 04:46 . 2012-06-02 22:12 88576 —-a-w- c:\windows\system32\wudriver.dll 2012-06-21 04:45 . 2012-06-02 05:19 171904 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-21 04:45 . 2012-06-02 05:12 33792 —-a-w- c:\windows\system32\wuapp.exe 2012-06-14 05:33 . 2012-04-07 11:26 2342400 —-a-w- c:\windows\system32\msi.dll 2012-06-14 05:32 . 2012-04-28 03:17 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-06-14 05:28 . 2012-05-15 01:05 2343936 —-a-w- c:\windows\system32\win32k.sys 2012-06-14 05:27 . 2012-04-26 04:45 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-06-14 05:27 . 2012-04-26 04:45 58880 —-a-w- c:\windows\system32\rdpwsx.dll 2012-06-14 05:27 . 2012-04-26 04:41 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-06-14 05:27 . 2012-05-01 04:44 164352 —-a-w- c:\windows\system32\profsvc.dll 2012-06-14 05:26 . 2012-04-24 04:36 1158656 —-a-w- c:\windows\system32\crypt32.dll 2012-06-14 05:25 . 2012-04-24 04:36 140288 —-a-w- c:\windows\system32\cryptsvc.dll 2012-06-14 05:24 . 2012-04-24 04:36 103936 —-a-w- c:\windows\system32\cryptnet.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2012-01-03 05:31 1514152 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-01-03 1514152] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-01-03 1514152] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-02-05 1692968] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-11-17 7866912] "Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-07-17 4562944] "BTMeter"="c:\program files\Battery Meter\BTMeter.exe" [2009-09-17 632176] "WSED"="c:\program files\WSED\WSED.exe" [2009-05-27 247080] "CapsLKNotify"="c:\program files\CapsLKNotify\CapsLKNotify.exe" [2009-06-09 320880] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "Dell DataSafe Online"="c:\program files\Dell DataSafe Online\DataSafeOnline.exe" [2009-11-13 1807600] "dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-06-03 206064] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-14 421160] "BigPondWirelessBroadbandCM"="c:\program files\Telstra\BigPond Wireless Broadband 2.11.21\TelstraUCM.exe" [2011-09-07 6198168] "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-21 1318816] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] "ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2012-01-03 1391272] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-10-24 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-10-24 173592] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-10-24 150552] . c:\users\elizabeth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-16 1324384] OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-2 795936] SRS Premium Sound.lnk - c:\windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut6_96BE12D997374F89986526ECCB660D4F.exe [2010-5-15 156952] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-12-16 1324384] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist] 2010-05-15 05:22 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "mixer1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R3 d554gps;Dell Wireless HSPA Mini-Card GPS Port;c:\windows\system32\DRIVERS\d554gps.sys [x] R3 d557bus;Dell Wireless 5540 HSPA Mini-Card Device (Win7);c:\windows\system32\DRIVERS\d557bus.sys [x] R3 d557mdfl;Dell Wireless 5540 HSPA Mini-Card Modem Filter (Win7);c:\windows\system32\DRIVERS\d557mdfl.sys [x] R3 d557mdm;Dell Wireless 5540 HSPA Mini-Card Modem (Win7);c:\windows\system32\DRIVERS\d557mdm.sys [x] R3 d557mgmt;Dell Wireless 5540 HSPA Mini-Card Device Management (Win7);c:\windows\system32\DRIVERS\d557mgmt.sys [x] R3 ecnssndis;Service for enabling selective suspend to NDIS device;c:\windows\system32\Drivers\wwanuss.sys [x] R3 ecnssndisfltr;SSNDIS filter service;c:\windows\system32\Drivers\wwanussf.sys [x] R3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [x] R3 massfilter_lte;LTE Device Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter_lte.sys [x] R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [x] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x] R3 swg3kser00;Sierra Wireless QMI USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\swg3kser00.sys [x] R3 swiwdmbx;Sierra Wireless USB Bus Service;c:\windows\system32\DRIVERS\swiwdmbx.sys [x] R3 SWNC8UA3;Sierra Wireless MUX NDIS Driver (UMTSA3);c:\windows\system32\DRIVERS\swnc8ua3.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 WwanUsbServ;Ericsson WWAN Wireless Module Device Driver;c:\windows\system32\DRIVERS\WwanUsbMp.sys [x] R3 ZTEusbnet;ZTE USB-NDIS miniport;c:\windows\system32\DRIVERS\ZTEusbnet.sys [x] S0 EMSC;COMPAL Embedded System Control;c:\windows\system32\DRIVERS\EMSC.SYS [x] S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [x] S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 BBSvc;BingBar Service;c:\program files\Microsoft\BingBar\7.1.361.0\BBSvc.exe [x] S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [x] S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [x] S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [x] S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [x] S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [x] S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [x] S2 SwiCardDetectSvc;Sierra Wireless Card Detection Service;c:\program files\Sierra Wireless Inc\Common\SwiCardDetect.exe [x] S2 WMCoreService;Mobile Broadband Core Service;c:\program files\Dell\Dell WWAN\WMCore\mini_WMCore.exe servicemode [x] S3 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\7.1.361.0\SeaPort.exe [x] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x] S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [x] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x] S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [x] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL *Deregistered* - mfeavfk01 . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc . Contents of the 'Scheduled Tasks' folder . 2012-07-07 c:\windows\Tasks\vtscheduletask.job - c:\program files\McAfee\Supportability\MVT\MvtApp.exe [2011-02-08 03:25] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com.au/ uInternet Settings,ProxyOverride = *.local IE: Translate this web page with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm IE: Translate with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm Trusted Zone: internet Trusted Zone: mcafee.com . - - - - ORPHANS REMOVED - - - - . HKLM-Run-Babylon Client - c:\program files\Babylon\Babylon-Pro\Babylon.exe AddRemove-Babylon - c:\program files\Babylon\Babylon-Pro\Utils\uninstbb.exe AddRemove-BabylonToolbar - c:\program files\BabylonToolbar\BabylonToolbar\1.5.3.17\uninstall.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-780604905-3422884488-2714364874-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-780604905-3422884488-2714364874-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ——————— DLLs Loaded Under Running Processes ——————— . - - - - - - - > 'Explorer.exe'(4040) c:\program files\WIDCOMM\Bluetooth Software\btncopy.dll . ———————— Other Running Processes ———————— . c:\windows\system32\WLANExt.exe c:\windows\system32\conhost.exe c:\program files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE c:\program files\Dell\Dell Wireless WLAN Card\bcmwltry.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\WIDCOMM\Bluetooth Software\btwdins.exe c:\windows\system32\rundll32.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\Dell\Dell WWAN\WMCore\mini_WMCore.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\program files\Common Files\McAfee\SystemCore\mcshield.exe c:\program files\Common Files\McAfee\SystemCore\mfefire.exe c:\program files\Dell Support Center\bin\sprtsvc.exe c:\windows\system32\taskhost.exe c:\windows\system32\conhost.exe c:\program files\Synaptics\SynTP\SynTPHelper.exe c:\windows\system32\igfxsrvc.exe c:\program files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel.exe c:\program files\WIDCOMM\Bluetooth Software\BtStackServer.exe c:\program files\iPod\bin\iPodService.exe c:\progra~1\mcafee\VIRUSS~1\mcvsshld.exe c:\program files\Common Files\McAfee\Core\mchost.exe . ************************************************************************** . Completion time: 2012-07-08 14:12:54 - machine was rebooted ComboFix-quarantined-files.txt 2012-07-08 04:12 . Pre-Run: 198,114,242,560 bytes free Post-Run: 198,299,398,144 bytes free . - - End Of File - - 57B17E82BDFE688E45CECA9E6F4B010A I've run PCMark7 on the neighbour's Dell Inspiron Mini but haven't got the results with me. The overall score was approx 450. The Dell is very slow. I did some browsing on it and on my own PC to some sites she had specifically complained about. Ancestry.com took 75secs on the Dell, 4Secs on my PC Qantas.com (for flight bookings) took 90 secs on the Dell and 5 secs on my PC Home (Google.com.au) took 20 secs on the Dell and 2 secs on my PC a second go to Qantas.com took 45 secs on the Dell I used ozspeedtest to test upload and download speeds and got 1.42Mb/s d'load and 0.17Mb/s upload on both the Dell and my PC. Internet access was via my Pocket WiFI (wireless) modem so same Interneet speeds was expected. I'll post the PCMark7 results when I get home from the hospital this evening. Thanks for your continuing help. Kangaroo
kangaroo,

I'm just a malware guy. The members of the Tech Team know so much more about computers than I do. Now that it appears that you are malware free, I suggest that you post in the Windows Forum and give the Tech Team a chance to try to help you tweak things a bit. When you post there, please include a link back to this thread so they can see the information you have already provided.

But first, we need to do a little housekeeping:

  • Click START then RUN
  • Now type ComboFix /Uninstall in the runbox and click OK.
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

  • Double click on OTL to run it.
  • Click on CleanUp!
  • When done, you will be prompted to restart your computer. Please restart your computer.

Please re-enable any security that was disabled.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Hi Tomk, Thanks for those three references; I'll use them and recommend them to friends and neighbours. I understand the actions for cleaning up ComboFix and OTL, thanks. One question: when I post in the Windows Forum, how do I link back to this thread? Do I just copy the URL and paste it into the n ew post or is there another way to do it? Thanks for all your help. Kangaroo
When you post there… just copy/past the contents of the following code box and it will leave a link (link will look like this: javascript links blocked ).

[topic=123642] Javascript links blocked [/topic]

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI