This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Flash Player Pro pop up [Closed]

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I posted this topic on the browser, internet and email threads, but perhaps it is more appropriate here. It seems as though I have installed a malware of Adobe's Flash Player, because everytime I select a link with IE 8 I get a pop up that warns me to update Flash Player Pro. I browsed Adobe site and it does appear to be a bogus application. I even get advertisements that play in the back ground but not on any web page open that I can tell.

Anyway here is the HiJackThis Log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:58:14 PM, on 6/10/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Program Files\DellTPad\Apoint.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\All Users\Application Data\OfficeGuardianV2\reminder\SacReminder.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Microsoft Office\Office97\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office97\Office\OSA.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Intel\WiFi\bin\WLKeeper.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
C:\WINDOWS\system32\SearchProtocolHost.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
O2 - BHO: Safe Monitor - {44ed99e2-16a6-4b89-80d6-5b21cf42e78b} - C:\Program Files\SafeMonitor\IE\common.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [DellCleanup] c:\DELL\WINCLEAN.EXE
O4 - HKLM\..\Run: [ChangeTPMAuth] C:\Program Files\Wave Systems Corp\Common\ChangeTPMAuth.exe /T:
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SacReminderHDDV2] C:\Documents and Settings\All Users\Application Data\OfficeGuardianV2\reminder\SacReminder.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office97\Office\FINDFAST.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office2000\Office\OSA9.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office97\Office\OSA.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.scottrade.com
O15 - Trusted Zone: http://ne1-attach.ymail.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1365648701234
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless WiFi Service (S24EventMonitor) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe
O23 - Service: NTRU TSS v1.2.1.12 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\WLKeeper.exe

–
End of file - 7702 bytes
Hi there,
my name is Marius and I will be assisting you with your Malware related problems.

Before we move on, please read the following points carefully.
  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.


That´s a fake - don´t install




Please download Farbar's Recovery Scan Tool to your desktop: FRST 32bit or FRST 64bit (If not sure: Start –> Computer (right click) –> properties)

  • Run FRST.
  • Don´t change one of the checkboxes and hit Scan.
  • Logfiles are created on your desktop.
  • Poste the FRST.txt and (after the first scan only!) the Addition.txt.




Download GMER Rootkit Scanner from here or here. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any "<— ROOKIT" entries unless advised by a trained Security Analyst


If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click Yes.
  • Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop.
If you do not receive notice about possible rootkit activity remain on the Rootkit/Malware tab & make sure the 'Show All' button is unticked.
  • Click the Scan button and let the program do its work. GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop.
Pleae attach the gmer.txt to your reply:
  • Click the[Manage Attachments] button under Additional Options > Attach Files on the post composition page, browse to where you saved the file, and
  • Click Upload.
Here are the first two files as requested:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-06-2013 02
Ran by [removed] (administrator) on 11-06-2013 05:56:04
Running from C:\Documents and Settings\[removed]\My Documents\SoftwareUpdates
Microsoft Windows XP Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(SigmaTel, Inc.) C:\WINDOWS\stsystra.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidFind.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apntex.exe
(CyberLink Corp.) C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastUI.exe
() C:\Program Files\Unlocker\UnlockerAssistant.exe
(SAC) C:\Documents and Settings\All Users\Application Data\OfficeGuardianV2\reminder\SacReminder.exe
(BVRP Software) C:\Program Files\Digital Line Detect\DLG.exe
() C:\Program Files\Microsoft Office\Office97\Office\FINDFAST.EXE
() C:\Program Files\Microsoft Office\Office97\Office\OSA.EXE
(Microsoft Corporation) C:\WINDOWS\System32\SCardSvr.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
() C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\WLKeeper.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe

==================== Registry (Whitelisted) ==================

HKLM\…\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [159744 2007-09-23] (Alps Electric Co., Ltd.)
HKLM\…\Run: [SigmatelSysTrayApp] stsystra.exe [x]
HKLM\…\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup [7401472 2006-01-19] (NVIDIA Corporation)
HKLM\…\Run: [nwiz] nwiz.exe /installquiet [x]
HKLM\…\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start [x]
HKLM\…\Run: [DellCleanup] c:\DELL\WINCLEAN.EXE [212992 2013-04-08] ()
HKLM\…\Run: [ChangeTPMAuth] C:\Program Files\Wave Systems Corp\Common\ChangeTPMAuth.exe /T: [176128 2007-01-31] (Wave Systems Corp.)
HKLM\…\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [49152 2005-12-09] (CyberLink Corp.)
HKLM\…\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit [x]
HKLM\…\Run: [IntelZeroConfig] "C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe" [1372160 2009-11-03] (Intel® Corporation)
HKLM\…\Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray [1202448 2009-11-03] (Intel® Corporation)
HKLM\…\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\…\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [3459712 2011-05-10] (AVAST Software)
HKLM\…\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" [17408 2010-07-04] ()
HKLM\…\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k [x]
Winlogon\Notify\WgaLogon: WgaLogon.dll (Microsoft Corporation)
HKCU\…\Run: [SacReminderHDDV2] C:\Documents and Settings\All Users\Application Data\OfficeGuardianV2\reminder\SacReminder.exe [464752 2012-06-28] (SAC)
MountPoints2: {eb579fdd-a194-11e2-9607-0019b96426d1} - E:\StartClickFreeBackup.exe
HKU\Administrator\…\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe [ 2003-09-10] ()
HKU\Default User\…\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe [ 2003-09-10] ()
Lsa: [Authentication Packages] msv1_0 wvauth
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
ShortcutTarget: Digital Line Detect.lnk -> C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Find Fast.lnk
ShortcutTarget: Microsoft Find Fast.lnk -> C:\Program Files\Microsoft Office\Office97\Office\FINDFAST.EXE ()
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office2000\Office\OSA9.EXE (Microsoft Corporation)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Office Startup.lnk
ShortcutTarget: Office Startup.lnk -> C:\Program Files\Microsoft Office\Office97\Office\OSA.EXE ()
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
ShortcutTarget: Windows Search.lnk -> C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
URLSearchHook: ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
HKLM SearchScopes: DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…ferrer:source?}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={sea…ferrer:source?}
BHO: Safe Monitor - {44ed99e2-16a6-4b89-80d6-5b21cf42e78b} - C:\Program Files\SafeMonitor\IE\common.dll (WebAppTech Coding, LLC)
BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: SweetPacks Browser Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
Toolbar: HKLM - SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
Toolbar: HKLM - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU -No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Toolbar: HKCU -SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
Handler: ipp - No CLSID Value -
Handler: msdaipp - No CLSID Value -
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
Winsock: Catalog9 01 C:\WINDOWS\system32\biolsp.dll [245248] (Microsoft Corporation)
Winsock: Catalog9 02 C:\WINDOWS\system32\biolsp.dll [245248] (Microsoft Corporation)
Winsock: Catalog9 03 C:\WINDOWS\system32\biolsp.dll [245248] (Microsoft Corporation)
Winsock: Catalog9 09 C:\WINDOWS\system32\biolsp.dll [92672] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.10

========================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [42184 2011-05-10] (AVAST Software)
R2 NICCONFIGSVC; C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe [475136 2007-07-20] (Dell Inc.)
R2 S24EventMonitor; C:\Program Files\Intel\WiFi\bin\S24EvMon.exe [909312 2009-11-03] (Intel® Corporation)
S3 SecureStorageService; C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe [487424 2007-01-29] (Wave Systems Corp.)
R2 tcsd_win32.exe; C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [1466368 2007-02-01] ()
R2 Wave UCSPlus; C:\WINDOWS\system32\dllhost.exe [5120 2008-04-14] (Microsoft Corporation)
R2 WLANKEEPER; C:\Program Files\Intel\WiFi\bin\WLKeeper.exe [348160 2009-11-03] (Intel® Corporation)

==================== Drivers (Whitelisted) ====================

R1 Aavmker4; C:\Windows\System32\Drivers\Aavmker4.sys [30808 2011-05-10] (AVAST Software)
R1 APPDRV; C:\Windows\SYSTEM32\DRIVERS\APPDRV.SYS [16128 2005-08-12] (Dell Inc)
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [19544 2011-05-10] (AVAST Software)
R2 aswMon2; C:\Windows\System32\Drivers\aswMon2.sys [102616 2011-05-10] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [25432 2011-05-10] (AVAST Software)
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [441176 2011-05-10] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [307928 2011-05-10] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [49240 2011-05-10] (AVAST Software)
R3 b57w2k; C:\Windows\System32\DRIVERS\b57xp32.sys [142720 2005-10-26] (Broadcom Corporation)
R3 guardian2; C:\Windows\System32\Drivers\oz776.sys [56320 2007-01-30] (O2Micro)
R3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [144384 2008-04-14] (Windows ® Server 2003 DDK provider)
S3 MotioninJoyXFilter; C:\Windows\System32\DRIVERS\MijXfilt.sys [95304 2011-11-10] (MotioninJoy)
R3 NETw5x32; C:\Windows\System32\DRIVERS\NETw5x32.sys [4221952 2009-10-26] (Intel Corporation)
R2 s24trans; C:\Windows\System32\DRIVERS\s24trans.sys [11904 2008-08-13] (Intel Corporation)
R3 STHDA; C:\Windows\System32\drivers\sthda.sys [1156648 2006-03-24] (SigmaTel, Inc.)
S3 xusb21; C:\Windows\System32\DRIVERS\xusb21.sys [61984 2010-08-19] (Microsoft Corporation)
S4 Abiosdsk; No ImagePath
S4 Atdisk; No ImagePath
S1 Changer; No ImagePath
S1 lbrtfdc; No ImagePath
S1 PCIDump; No ImagePath
S3 PDCOMP; No ImagePath
S3 PDFRAME; No ImagePath
S3 PDRELI; No ImagePath
S3 PDRFRAME; No ImagePath
S4 Simbad; No ImagePath
S3 WDICA; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-11 05:55 - 2013-06-11 05:55 - 00000000 ____D C:\FRST
2013-06-10 09:32 - 2013-06-10 09:32 - 00106496 ____A C:\Windows\Minidump\Mini061013-02.dmp
2013-06-10 08:23 - 2013-06-10 09:32 - 00000000 ____D C:\Windows\Minidump
2013-06-10 08:23 - 2013-06-10 08:23 - 00106496 ____A C:\Windows\Minidump\Mini061013-01.dmp
2013-06-09 05:55 - 2013-06-09 05:55 - 00000000 ____D C:\Program Files\Unlocker
2013-06-08 22:52 - 2013-06-08 22:52 - 00000640 ____A C:\Documents and Settings\Terry Felter\Desktop\Frhed.lnk
2013-06-08 07:40 - 2013-06-08 07:40 - 00001691 ____A C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
2013-06-08 07:40 - 2013-06-08 07:40 - 00000000 ____D C:\Program Files\AVAST Software
2013-06-08 07:40 - 2013-06-08 07:40 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\AVAST Software
2013-06-08 07:40 - 2011-05-10 07:10 - 00199304 ____A (AVAST Software) C:\Windows\System32\aswBoot.exe
2013-06-08 07:40 - 2011-05-10 07:10 - 00040112 ____A (AVAST Software) C:\Windows\avastSS.scr
2013-06-08 07:40 - 2011-05-10 07:03 - 00441176 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSnx.sys
2013-06-08 07:40 - 2011-05-10 07:03 - 00307928 ____A (AVAST Software) C:\Windows\System32\Drivers\aswSP.sys
2013-06-08 07:40 - 2011-05-10 07:02 - 00102616 ____A (AVAST Software) C:\Windows\System32\Drivers\aswmon2.sys
2013-06-08 07:40 - 2011-05-10 07:02 - 00096344 ____A (AVAST Software) C:\Windows\System32\Drivers\aswmon.sys
2013-06-08 07:40 - 2011-05-10 07:02 - 00049240 ____A (AVAST Software) C:\Windows\System32\Drivers\aswTdi.sys
2013-06-08 07:40 - 2011-05-10 06:59 - 00030808 ____A (AVAST Software) C:\Windows\System32\Drivers\aavmker4.sys
2013-06-08 07:40 - 2011-05-10 06:59 - 00025432 ____A (AVAST Software) C:\Windows\System32\Drivers\aswRdr.sys
2013-06-08 07:40 - 2011-05-10 06:59 - 00019544 ____A (AVAST Software) C:\Windows\System32\Drivers\aswFsBlk.sys
2013-06-07 10:20 - 2013-06-07 10:20 - 00000000 ____D C:\Documents and Settings\Terry Felter\My Documents\Flash Player Pro
2013-06-07 10:19 - 2013-06-07 10:19 - 00000000 ____D C:\Program Files\SweetIM
2013-06-07 10:19 - 2013-06-07 10:19 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\SweetIM
2013-06-07 10:19 - 2013-06-07 10:19 - 00000000 ____A C:\Windows\System32\TempWmicBatchFile.bat
2013-06-07 10:19 - 2013-06-07 10:19 - 00000000 ____A C:\END
2013-06-07 10:18 - 2013-02-05 02:25 - 00632656 ____A (Microsoft Corporation) C:\Windows\System32\msvcr80.dll
2013-06-07 10:18 - 2013-02-05 02:25 - 00554832 ____A (Microsoft Corporation) C:\Windows\System32\msvcp80.dll
2013-06-07 10:18 - 2013-02-05 02:25 - 00479232 ____A (Microsoft Corporation) C:\Windows\System32\msvcm80.dll
2013-06-07 10:18 - 2013-02-05 02:25 - 00001870 ____A C:\Windows\System32\Microsoft.VC80.CRT.manifest
2013-06-06 21:52 - 2013-06-06 21:52 - 00000000 ____D C:\Documents and Settings\Terry Felter\Application Data\Mozilla
2013-06-06 21:51 - 2013-06-06 21:52 - 00000000 ____D C:\Program Files\SafeMonitor
2013-06-01 14:09 - 2013-06-01 14:10 - 00966048 ____A C:\Documents and Settings\Terry Felter\Desktop\SpikeTrade_comRes.mht
2013-05-16 05:05 - 2013-05-16 05:05 - 17613192 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerInstaller.exe
2013-05-15 23:44 - 2013-06-10 22:01 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-05-15 23:33 - 2013-05-15 23:34 - 00011856 ____A C:\Windows\KB2829530-IE8.log
2013-05-15 23:28 - 2013-05-15 23:28 - 00006928 ____A C:\Windows\KB2820197.log
2013-05-15 23:28 - 2013-05-15 23:28 - 00005871 ____A C:\Windows\KB2847204-IE8.log
2013-05-15 23:28 - 2013-05-15 23:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2820197$
2013-05-15 23:26 - 2013-05-15 23:26 - 00000000 __HDC C:\Windows\$NtUninstallKB2829361$
2013-05-15 08:05 - 2013-05-15 23:26 - 00010709 ____A C:\Windows\KB2829361.log
2013-05-12 21:36 - 2013-05-23 14:57 - 00000300 ____A C:\Windows\REDBOOK2.INI
2013-05-12 19:22 - 2013-05-12 19:22 - 00000000 ____D C:\Documents and Settings\Terry Felter\My Documents\Excel Password Remover Pro
2013-05-12 19:20 - 2011-03-17 14:10 - 00024431 ____A C:\Documents and Settings\Terry Felter\My Documents\PASS_PRO.xlam

==================== One Month Modified Files and Folders ========

2013-06-11 05:55 - 2013-06-11 05:55 - 00000000 ____D C:\FRST
2013-06-11 05:55 - 2013-04-10 00:02 - 00000000 ____D C:\Documents and Settings\Terry Felter\My Documents\SoftwareUpdates
2013-06-11 05:44 - 2008-04-25 16:28 - 01569580 ____A C:\Windows\WindowsUpdate.log
2013-06-11 05:42 - 2008-04-25 16:26 - 00000000 ____D C:\Windows\Registration
2013-06-11 05:42 - 2008-04-25 11:16 - 00001158 ____A C:\Windows\System32\wpa.dbl
2013-06-11 05:41 - 2013-04-10 05:58 - 00000326 ____A C:\Windows\Tasks\GlaryInitialize.job
2013-06-11 05:41 - 2013-04-10 01:43 - 00017730 ____A C:\Windows\System32\nvModes.001
2013-06-11 05:41 - 2013-04-09 19:50 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\Application Data\NTRU Cryptosystems
2013-06-11 05:41 - 2008-04-25 16:32 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-11 05:40 - 2013-04-10 01:43 - 00000000 ____A C:\Windows\System32\NvwsApps.xml
2013-06-11 05:40 - 2013-04-09 20:01 - 00000062 __ASH C:\Documents and Settings\Terry Felter\Local Settings\desktop.ini
2013-06-11 05:40 - 2009-11-03 17:45 - 00000000 ____D C:\dell
2013-06-11 05:40 - 2008-04-25 16:32 - 00000062 __ASH C:\Documents and Settings\NetworkService\Local Settings\desktop.ini
2013-06-11 05:40 - 2008-04-25 16:32 - 00000062 __ASH C:\Documents and Settings\LocalService\Local Settings\desktop.ini
2013-06-10 22:29 - 2008-04-25 16:32 - 00032490 ____A C:\Windows\SchedLgU.Txt
2013-06-10 22:28 - 2013-04-09 20:01 - 00000178 ___SH C:\Documents and Settings\Terry Felter\ntuser.ini
2013-06-10 22:27 - 2013-04-23 18:20 - 00006895 ____A C:\Windows\Terry Felter8.xlb
2013-06-10 22:27 - 2013-04-10 00:08 - 00000000 ____D C:\Documents and Settings\Terry Felter\My Documents\Stock Info
2013-06-10 22:11 - 2013-04-10 00:02 - 00000000 ____D C:\Documents and Settings\Terry Felter\My Documents\My Cheat Tables
2013-06-10 22:02 - 2013-04-09 23:02 - 20414464 ___AH C:\ffastun0.ffx
2013-06-10 22:02 - 2013-04-09 23:02 - 01056768 ___AH C:\ffastun.ffo
2013-06-10 22:02 - 2013-04-09 23:02 - 00005738 ___AH C:\ffastun.ffa
2013-06-10 22:02 - 2013-04-09 23:00 - 01949696 ___AH C:\ffastun.ffl
2013-06-10 22:01 - 2013-05-15 23:44 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-06-10 19:49 - 2013-04-10 05:15 - 01829683 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-753820193-3170401739-325470631-1005-0.dat
2013-06-10 19:49 - 2013-04-10 05:15 - 00282946 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
2013-06-10 19:45 - 2013-04-09 23:36 - 00000000 ____D C:\Documents and Settings\Terry Felter\My Documents\InvestorsBusinessDaily
2013-06-10 19:28 - 2013-04-10 07:35 - 00001998 ____A C:\Documents and Settings\Terry Felter\Desktop\HiJackThis.lnk
2013-06-10 19:17 - 2013-04-10 00:02 - 00000000 ____D C:\Documents and Settings\Terry Felter\My Documents\Snagit
2013-06-10 15:10 - 2013-04-10 06:12 - 00027997 ____A C:\Windows\WinSig.ini
2013-06-10 15:10 - 2013-04-10 06:12 - 00002935 ____A C:\Windows\WinRos.ini
2013-06-10 13:26 - 2013-04-10 07:53 - 00000043 ____A C:\Windows\WALLSTRT.INI
2013-06-10 09:39 - 2013-04-10 09:41 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\performance
2013-06-10 09:39 - 2013-04-10 06:11 - 00000000 ____D C:\Program Files\eSignal
2013-06-10 09:33 - 2013-04-10 01:43 - 00017730 ____A C:\Windows\System32\nvModes.dat
2013-06-10 09:32 - 2013-06-10 09:32 - 00106496 ____A C:\Windows\Minidump\Mini061013-02.dmp
2013-06-10 09:32 - 2013-06-10 08:23 - 00000000 ____D C:\Windows\Minidump
2013-06-10 08:23 - 2013-06-10 08:23 - 00106496 ____A C:\Windows\Minidump\Mini061013-01.dmp
2013-06-09 19:22 - 2013-04-10 05:56 - 00000000 ____D C:\Documents and Settings\Terry Felter\Application Data\Simple Sudoku
2013-06-09 06:48 - 2008-04-25 11:16 - 00001028 ____A C:\Windows\win.ini
2013-06-09 06:48 - 2008-04-25 11:16 - 00000227 ____A C:\Windows\system.ini
2013-06-09 06:48 - 2008-04-25 11:16 - 00000211 _RASH C:\boot.ini
2013-06-09 05:55 - 2013-06-09 05:55 - 00000000 ____D C:\Program Files\Unlocker
2013-06-08 22:52 - 2013-06-08 22:52 - 00000640 ____A C:\Documents and Settings\Terry Felter\Desktop\Frhed.lnk
2013-06-08 22:52 - 2013-04-10 05:59 - 00000000 ____D C:\Program Files\Frhed
2013-06-08 22:47 - 2013-04-09 23:16 - 00000354 ____A C:\REGERRS.TXT
2013-06-08 18:16 - 2013-04-10 21:35 - 00000578 ____A C:\Windows\Tasks\TradeStation Backup - Monthly.job
2013-06-08 18:10 - 2013-04-10 21:17 - 00000000 ____D C:\Program Files\TradeStation Archives
2013-06-08 18:10 - 2013-04-10 20:47 - 36458402 ____A C:\Windows\DYNAZIP.LOG
2013-06-08 14:43 - 2013-04-10 05:56 - 00000000 ____D C:\Program Files\Simple Sudoku
2013-06-08 13:02 - 2013-04-09 23:23 - 00000000 ____D C:\Documents and Settings\Terry Felter\My Documents\Access
2013-06-08 11:39 - 2008-04-25 04:17 - 00000000 ____D C:\Windows\Help
2013-06-08 07:40 - 2013-06-08 07:40 - 00001691 ____A C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
2013-06-08 07:40 - 2013-06-08 07:40 - 00000000 ____D C:\Program Files\AVAST Software
2013-06-08 07:40 - 2013-06-08 07:40 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\AVAST Software
2013-06-08 07:40 - 2008-04-25 16:29 - 00002625 ____A C:\Windows\System32\CONFIG.NT
2013-06-07 12:27 - 2008-04-25 16:26 - 00000000 ____D C:\Windows\System32\FxsTmp
2013-06-07 10:20 - 2013-06-07 10:20 - 00000000 ____D C:\Documents and Settings\Terry Felter\My Documents\Flash Player Pro
2013-06-07 10:19 - 2013-06-07 10:19 - 00000000 ____D C:\Program Files\SweetIM
2013-06-07 10:19 - 2013-06-07 10:19 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\SweetIM
2013-06-07 10:19 - 2013-06-07 10:19 - 00000000 ____A C:\Windows\System32\TempWmicBatchFile.bat
2013-06-07 10:19 - 2013-06-07 10:19 - 00000000 ____A C:\END
2013-06-06 21:52 - 2013-06-06 21:52 - 00000000 ____D C:\Documents and Settings\Terry Felter\Application Data\Mozilla
2013-06-06 21:52 - 2013-06-06 21:51 - 00000000 ____D C:\Program Files\SafeMonitor
2013-06-05 20:51 - 2013-04-10 21:22 - 00000000 ____D C:\Program Files\TradeStation 9.1
2013-06-05 20:39 - 2013-04-10 01:41 - 00686854 ____A C:\Windows\setupapi.log
2013-06-04 21:29 - 2013-04-12 06:10 - 00000961 ____A C:\Windows\MVPBR.INI
2013-06-04 16:22 - 2013-05-06 11:54 - 00000258 ____A C:\Windows\MVPSPADE.INI
2013-06-01 14:10 - 2013-06-01 14:09 - 00966048 ____A C:\Documents and Settings\Terry Felter\Desktop\SpikeTrade_comRes.mht
2013-05-29 21:03 - 2013-04-10 00:02 - 00575488 ____A C:\Documents and Settings\Terry Felter\My Documents\PhoneBook.XLS
2013-05-29 18:06 - 2013-04-09 23:35 - 00000000 ____D C:\Documents and Settings\Terry Felter\My Documents\Engineering
2013-05-28 11:20 - 2013-04-09 23:24 - 00000000 ____D C:\Documents and Settings\Terry Felter\My Documents\Companies
2013-05-23 14:57 - 2013-05-12 21:36 - 00000300 ____A C:\Windows\REDBOOK2.INI
2013-05-20 15:38 - 2013-04-09 23:35 - 00005066 ____A C:\Documents and Settings\Terry Felter\My Documents\Finder.txt
2013-05-16 05:05 - 2013-05-16 05:05 - 17613192 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerInstaller.exe
2013-05-16 05:05 - 2013-04-10 15:33 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-05-16 05:05 - 2013-04-10 15:33 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-05-16 04:54 - 2008-04-25 16:34 - 00000000 ____D C:\Windows\Microsoft.NET
2013-05-15 23:37 - 2008-04-25 04:21 - 00276560 ____A C:\Windows\System32\FNTCACHE.DAT
2013-05-15 23:34 - 2013-05-15 23:33 - 00011856 ____A C:\Windows\KB2829530-IE8.log
2013-05-15 23:34 - 2013-04-10 09:53 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Microsoft Help
2013-05-15 23:34 - 2009-11-03 17:08 - 00060536 ____A C:\Windows\updspapi.log
2013-05-15 23:34 - 2008-04-25 04:22 - 00732521 ____A C:\Windows\iis6.log
2013-05-15 23:34 - 2008-04-25 04:22 - 00642012 ____A C:\Windows\FaxSetup.log
2013-05-15 23:34 - 2008-04-25 04:22 - 00315882 ____A C:\Windows\ocgen.log
2013-05-15 23:34 - 2008-04-25 04:22 - 00295187 ____A C:\Windows\tsoc.log
2013-05-15 23:34 - 2008-04-25 04:22 - 00219653 ____A C:\Windows\comsetup.log
2013-05-15 23:34 - 2008-04-25 04:22 - 00200876 ____A C:\Windows\msmqinst.log
2013-05-15 23:34 - 2008-04-25 04:22 - 00132496 ____A C:\Windows\ntdtcsetup.log
2013-05-15 23:34 - 2008-04-25 04:22 - 00110002 ____A C:\Windows\netfxocm.log
2013-05-15 23:34 - 2008-04-25 04:22 - 00043930 ____A C:\Windows\MedCtrOC.log
2013-05-15 23:34 - 2008-04-25 04:22 - 00034944 ____A C:\Windows\ocmsn.log
2013-05-15 23:34 - 2008-04-25 04:22 - 00031772 ____A C:\Windows\tabletoc.log
2013-05-15 23:34 - 2008-04-25 04:22 - 00031721 ____A C:\Windows\msgsocm.log
2013-05-15 23:34 - 2008-04-25 04:22 - 00001374 ____A C:\Windows\imsins.log
2013-05-15 23:33 - 2008-04-25 04:22 - 00615060 ____A C:\Windows\System32\PerfStringBackup.INI
2013-05-15 23:28 - 2013-05-15 23:28 - 00006928 ____A C:\Windows\KB2820197.log
2013-05-15 23:28 - 2013-05-15 23:28 - 00005871 ____A C:\Windows\KB2847204-IE8.log
2013-05-15 23:28 - 2013-05-15 23:28 - 00000000 __HDC C:\Windows\$NtUninstallKB2820197$
2013-05-15 23:28 - 2013-04-10 05:11 - 00000000 ____D C:\Windows\ie8updates
2013-05-15 23:28 - 2009-11-03 17:26 - 00000000 ___HD C:\Windows\$hf_mig$
2013-05-15 23:28 - 2008-04-25 04:22 - 00001374 ____A C:\Windows\imsins.BAK
2013-05-15 23:26 - 2013-05-15 23:26 - 00000000 __HDC C:\Windows\$NtUninstallKB2829361$
2013-05-15 23:26 - 2013-05-15 08:05 - 00010709 ____A C:\Windows\KB2829361.log
2013-05-15 23:26 - 2013-04-10 05:07 - 72607752 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-05-12 19:22 - 2013-05-12 19:22 - 00000000 ____D C:\Documents and Settings\Terry Felter\My Documents\Excel Password Remover Pro

Files to move or delete:
====================
C:\Documents and Settings\Terry Felter\g2ax_customer_downloadhelper_win32_x86.exe

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== End Of Log ============================

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-06-2013 02
Ran by [removed] at 2013-06-11 05:56:32 Run:
Running from C:\Documents and Settings\[removed]\My Documents\SoftwareUpdates
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

2007 Microsoft Office Suite Service Pack 3 (SP3)
Adobe Flash Player 11 ActiveX (Version: 11.7.700.202)
Adobe Flash Player 11 Plugin (Version: 11.7.700.202)
Adobe Reader XI (11.0.03) (Version: 11.0.03)
avast! Free Antivirus (Version: 6.0.1125.0)
biolsp patch (Version: 01.00.01.0010)
Board Games
Broadcom Gigabit Integrated Controller (Version: 8.22.11)
Broadcom TPM Driver Installer (Version: 8.04.04)
Card Games for Windows
CCleaner (Version: 4.00)
Cheat Engine 6.2
Conexant HDA D110 MDC V.92 Modem
Dell Resource CD (Version: 1.00.0000)
Dell Touchpad (Version: 7.1.102.7)
Digital Line Detect (Version: 1.15)
eSignal (Version: 10.6.2425.1208)
eSignal 10.6 (Version: 10.6.2425.1208)
ETS Upgrade (Version: 02.00.00.012)
Frhed 1.7.1 (Version: 1.7.1)
Glary Utilities 2.54.0.1759 (Version: 2.54.0.1759)
GOM Player (Version: 2.1.40.5106)
GoToMeeting 5.5.0.1132 (Version: 5.5.0.1132)
Heroes of Might and Magic® III
HiJackThis (Version: 1.0.0)
HijackThis 2.0.2 (Version: 2.0.2)
Intel PROSet Wireless
Intel® PROSet/Wireless WiFi Software (Version: 12.04.4000)
Internet Explorer Toolbar 4.8 by SweetPacks (Version: 4.8.0000)
IZArc 4.1.6 (Version: 4.1.6)
Kyocera Product Library (Version: 2.0.0713)
Microsoft .NET Framework 1.1 (Version: 1.1.4322)
Microsoft .NET Framework 1.1 Security Update (KB2742597)
Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729)
Microsoft .NET Framework 3.0 Service Pack 2 (Version: 3.2.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
Microsoft Office 2000 Professional (Version: 9.00.2720)
Microsoft Office 97, Professional Edition
Microsoft Office Access MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Professional 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Software Update for Web Folders (English) 12 (Version: 12.0.6612.1000)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (Version: 10.0.30319)
Modem Helper (Version: 3.02)
MotioninJoy ds3 driver version 0.6.0005 (Version: 0.6.00005)
mProSafe (Version: 7.20.0000)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MSXML 4.0 SP3 Parser (KB2758694) (Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (KB973685) (Version: 4.30.2107.0)
MSXML 6.0 Parser (KB927977) (Version: 6.00.3890.0)
mWlsSafe (Version: 7.20.0000)
NetWaiting (Version: 2.5.23)
NirSoft BlueScreenView
NTRU TCG Software Stack (Version: 2.1.12)
NVIDIA Drivers
O2Micro USB Smart Card Reader (Version: 1.00.0000)
PhotoRazor
PowerDVD 5.7
QuickSet (Version: 8.3.11)
Safe Monitor (Version: 2.6.17)
Simple Sudoku 4.2
SnagIt32 v4.3
TC2000 Version 7 (Version: 7.00.0000)
TextPad 4
TradeStation 9.1 (Version: 9.01.00.12098)
Unlocker 1.9.2 (Version: 1.9.2)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817359) 32-Bit Edition
Update for Windows Internet Explorer 8 (KB2598845) (Version: 1)
Update for Windows XP (KB2345886) (Version: 1)
Update for Windows XP (KB2467659) (Version: 1)
Update for Windows XP (KB2661254-v2) (Version: 2)
Update for Windows XP (KB2736233) (Version: 1)
Update for Windows XP (KB2749655) (Version: 1)
Update for Windows XP (KB898461) (Version: 1)
Update for Windows XP (KB951618-v2) (Version: 2)
Update for Windows XP (KB951978) (Version: 1)
Update for Windows XP (KB955759) (Version: 1)
Update for Windows XP (KB967715) (Version: 1)
Update for Windows XP (KB968389) (Version: 1)
Update for Windows XP (KB971029) (Version: 1)
Update for Windows XP (KB971737) (Version: 1)
Update for Windows XP (KB973687) (Version: 1)
Update for Windows XP (KB973815) (Version: 1)
Update for Windows XP (KB980182) (Version: 1)
upekmsi (Version: 02.00.02.0010)
Wave Infrastructure Installer (Version: 03.05.10.0050)
Wave Support Software (Version: 05.04.00.018)
WebFldrs XP (Version: 9.50.7523)
Windows Driver Package - O2Micro (guardian2) SmartCardReader (02/05/2007 1.1.3.7) (Version: 02/05/2007 1.1.3.7)
Windows Genuine Advantage Notifications (KB905474) (Version: 1.9.0040.0)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Genuine Advantage Validation Tool (KB892130) (Version: 1.7.0069.2)
Windows Internet Explorer 8 (Version: 20090308.140743)
Windows Management Framework Core
Windows Presentation Foundation (Version: 3.0.6920.0)
Windows Rights Management Client Backwards Compatibility SP2 (Version: 5.2.95)
Windows Rights Management Client with Service Pack 2 (Version: 5.2.95)
Windows Search 4.0 (Version: 04.00.6001.503)
WinHex
XML Paper Specification Shared Components Pack 1.0

==================== Restore Points =========================

10-04-2013 01:01:21 System Checkpoint
10-04-2013 01:04:14 Installed Dell Resource CD.
10-04-2013 02:25:36 Installed Broadcom Gigabit Integrated Controller
10-04-2013 02:48:15 Removed mHlpDell
10-04-2013 02:48:18 Removed mWMI
10-04-2013 02:48:27 Removed mIWA
10-04-2013 02:48:30 Removed mPfWiz
10-04-2013 02:48:34 Removed mXML
10-04-2013 02:48:41 Removed mSSO
10-04-2013 02:48:47 Removed mMHouse
10-04-2013 02:48:54 Removed mLogView
10-04-2013 02:49:01 Removed mZConfig
10-04-2013 02:49:05 Removed mDrWiFi
10-04-2013 02:49:25 Removed mCore
10-04-2013 02:49:39 Removed mPfMgr
10-04-2013 02:49:43 Installed Intel® PROSet/Wireless WiFi Software.
10-04-2013 03:27:45 Software Distribution Service 3.0
10-04-2013 03:30:18 Software Distribution Service 3.0
10-04-2013 03:52:59 Software Distribution Service 3.0
10-04-2013 04:05:34 Installed Microsoft Office 2000 Professional
10-04-2013 05:19:10 Installed TC2000 Version 7
10-04-2013 09:52:29 Software Distribution Service 3.0
10-04-2013 11:11:52 Installed eSignal
10-04-2013 14:52:22 Installed Microsoft Office Professional 2007
10-04-2013 22:13:09 Printer Driver Kyocera TASKalfa 500ci KX Installed
11-04-2013 02:18:29 Removed TradeStation 9.1
11-04-2013 02:22:07 Installed TradeStation 9.1
11-04-2013 02:51:31 Before update
11-04-2013 02:52:31 Software Distribution Service 3.0
11-04-2013 02:56:26 Software Distribution Service 3.0
11-04-2013 03:29:51 Installed Windows XP WgaNotify.
12-04-2013 20:32:23 System Checkpoint
13-04-2013 20:02:37 Before update
13-04-2013 20:03:07 Software Distribution Service 3.0
14-04-2013 09:51:45 before update
14-04-2013 09:52:43 Software Distribution Service 3.0
16-04-2013 02:56:48 System Checkpoint
18-04-2013 01:33:21 System Checkpoint
19-04-2013 02:49:05 System Checkpoint
20-04-2013 03:37:45 System Checkpoint
21-04-2013 13:45:14 System Checkpoint
22-04-2013 03:32:59 Installed Windows XP Wdf01009.
22-04-2013 03:36:17 Update to an unsigned driver
23-04-2013 16:10:51 System Checkpoint
25-04-2013 01:08:37 System Checkpoint
26-04-2013 12:31:23 Configured Microsoft Office Professional 2007
27-04-2013 14:11:23 System Checkpoint
28-04-2013 04:17:59 Update to an unsigned driver
29-04-2013 16:38:23 System Checkpoint
01-05-2013 00:39:04 System Checkpoint
03-05-2013 20:57:22 System Checkpoint
04-05-2013 21:46:52 System Checkpoint
05-05-2013 22:47:16 System Checkpoint
07-05-2013 01:27:04 System Checkpoint
08-05-2013 02:04:53 System Checkpoint
09-05-2013 02:58:26 System Checkpoint
10-05-2013 03:34:57 System Checkpoint
11-05-2013 03:36:00 System Checkpoint
12-05-2013 03:54:01 System Checkpoint
13-05-2013 10:49:57 System Checkpoint
14-05-2013 11:10:22 System Checkpoint
15-05-2013 11:35:58 System Checkpoint
16-05-2013 04:24:49 Before update
16-05-2013 04:25:29 Software Distribution Service 3.0
17-05-2013 05:03:37 System Checkpoint
18-05-2013 10:30:55 System Checkpoint
19-05-2013 12:44:43 System Checkpoint
20-05-2013 23:18:55 System Checkpoint
21-05-2013 23:48:52 System Checkpoint
23-05-2013 01:17:25 System Checkpoint
24-05-2013 03:00:46 System Checkpoint
25-05-2013 04:11:02 System Checkpoint
26-05-2013 05:43:34 System Checkpoint
27-05-2013 06:08:08 System Checkpoint
28-05-2013 06:50:10 System Checkpoint
29-05-2013 07:17:52 System Checkpoint
30-05-2013 08:40:41 System Checkpoint
31-05-2013 09:15:40 System Checkpoint
01-06-2013 10:17:29 System Checkpoint
02-06-2013 16:34:56 System Checkpoint
03-06-2013 21:27:12 System Checkpoint
05-06-2013 11:32:50 System Checkpoint
06-06-2013 20:42:24 System Checkpoint
07-06-2013 17:27:23 Printer Driver WebEx Document Loader Installed
08-06-2013 12:40:22 avast! Free Antivirus Setup
09-06-2013 10:32:18 Before update
09-06-2013 10:32:32 Software Distribution Service 3.0
11-06-2013 00:27:57 Installed HiJackThis

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (06/10/2013 01:14:18 PM) (Source: Application Hang) (User: )
Description: Hanging application ORPlat.exe, version 9.33.0.12098, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Error: (06/10/2013 08:15:40 AM) (Source: Application Error) (User: )
Description: Faulting application iexplore.exe, version 8.0.6001.18702, faulting module mshtml.dll, version 8.0.6001.23487, fault address 0x00095ac6.
Processing media-specific event for [iexplore.exe!ws!]

Error: (06/08/2013 10:31:02 AM) (Source: Application Error) (User: )
Description: Faulting application excel.exe, version 8.0.1.5618, faulting module excel.exe, version 8.0.1.5618, fault address 0x00040134.
Processing media-specific event for [excel.exe!ws!]

Error: (06/07/2013 08:49:15 AM) (Source: Application Error) (User: )
Description: Faulting application iexplore.exe, version 8.0.6001.18702, faulting module mshtml.dll, version 8.0.6001.23487, fault address 0x00095ac6.
Processing media-specific event for [iexplore.exe!ws!]

Error: (06/07/2013 07:08:50 AM) (Source: Application Error) (User: )
Description: Faulting application iexplore.exe, version 8.0.6001.18702, faulting module mshtml.dll, version 8.0.6001.23487, fault address 0x00095ac6.
Processing media-specific event for [iexplore.exe!ws!]

Error: (06/06/2013 02:38:36 PM) (Source: Application Hang) (User: )
Description: Hanging application ORPlat.exe, version 9.33.0.12098, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Error: (06/05/2013 08:25:03 PM) (Source: Application Error) (User: )
Description: Faulting application telechart.exe, version 7.0.0.2, faulting module msvbvm50.dll, version 5.2.82.44, fault address 0x0001c8ef.
Processing media-specific event for [telechart.exe!ws!]

Error: (06/05/2013 10:57:50 AM) (Source: Application Error) (User: )
Description: Faulting application scottrader.exe, version 4.3.152.0, faulting module ntdll.dll, version 5.1.2600.6055, fault address 0x00010a19.
Processing media-specific event for [scottrader.exe!ws!]

Error: (06/04/2013 03:35:26 PM) (Source: Application Error) (User: )
Description: Faulting application acrord32.exe, version 11.0.3.37, faulting module acrord32.dll, version 11.0.3.37, fault address 0x000d4680.
Processing media-specific event for [acrord32.exe!ws!]

Error: (06/04/2013 01:32:34 PM) (Source: Application Error) (User: )
Description: Faulting application scottrader.exe, version 4.3.152.0, faulting module scottrader.exe, version 4.3.152.0, fault address 0x004c4748.
Processing media-specific event for [scottrader.exe!ws!]


System errors:
=============
Error: (06/11/2013 05:41:54 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{A4199E55-EBB9-49E5-AF1A-7A5408B2E206}
to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool.

Error: (06/11/2013 05:41:54 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{A4199E55-EBB9-49E5-AF1A-7A5408B2E206}
to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool.

Error: (06/11/2013 05:41:54 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{A4199E55-EBB9-49E5-AF1A-7A5408B2E206}
to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool.

Error: (06/11/2013 05:41:26 AM) (Source: SCardSvr) (User: )
Description: WDM Reader driver initialization cannot open reader device: Access is denied.

Error: (06/11/2013 05:41:02 AM) (Source: 0) (User: )
Description: IOCTL *** UNKNOWN *** failed with status 0xc0000010

Error: (06/10/2013 07:52:33 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{A4199E55-EBB9-49E5-AF1A-7A5408B2E206}
to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool.

Error: (06/10/2013 07:52:33 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{A4199E55-EBB9-49E5-AF1A-7A5408B2E206}
to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool.

Error: (06/10/2013 07:52:33 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{A4199E55-EBB9-49E5-AF1A-7A5408B2E206}
to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool.

Error: (06/10/2013 07:52:08 PM) (Source: SCardSvr) (User: )
Description: WDM Reader driver initialization cannot open reader device: Access is denied.

Error: (06/10/2013 07:51:35 PM) (Source: 0) (User: )
Description: IOCTL *** UNKNOWN *** failed with status 0xc0000010


Microsoft Office Sessions:
=========================

==================== Memory info ===========================

Percentage of memory in use: 32%
Total physical RAM: 3326.05 MB
Available physical RAM: 2236.3 MB
Total Pagefile: 5210.12 MB
Available Pagefile: 4255.13 MB
Total Virtual: 2047.88 MB
Available Virtual: 1928.16 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:149.01 GB) (Free:65.36 GB) NTFS ==>[Drive with boot components (Windows XP)]
Drive d: (Heroes3) (CDROM) (Total:0.63 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 149 GB) (Disk ID: A42D04A3)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=149 GB) - (Type=07 NTFS)

==================== End Of Log ============================
Fix with FRST

  • Open notepad (Start =>All Programs => Accessories => Notepad).
  • Please copy the entire contents of the code box below.
    (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
  • Save it to the same direction as frst.exe (or frst64.exe) as fixlist.txt.

    URLSearchHook: ATTENTION ==> Default URLSearchHook is missing.
    URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
    BHO: Safe Monitor - {44ed99e2-16a6-4b89-80d6-5b21cf42e78b} - C:\Program Files\SafeMonitor\IE\common.dll (WebAppTech Coding, LLC)
    BHO: SweetPacks Browser Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
    Toolbar: HKLM - SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
    Toolbar: HKCU -No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
    Toolbar: HKCU -SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
    
    C:\Program Files\SafeMonitor
    C:\Program Files\SweetIM
    C:\Documents and Settings\All Users\Application Data\SweetIM
    C:\Windows\System32\TempWmicBatchFile.bat
    C:\END
    C:\Documents and Settings\Terry Felter\Application Data\Mozilla
    C:\Documents and Settings\Terry Felter\My Documents\Flash Player Pro
    C:\Documents and Settings\Terry Felter\g2ax_customer_downloadhelper_win32_x86.exe
    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
  • Run frst.exe (on 64bit, run frst64.exe) and press the Fix button just once and wait.
  • The tool will make a log (Fixlog.txt) which you find where you saved FRST. Please post it to your reply.




Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.
Here is the frst.exe fixlog.txt. When running the software I did get a prompt to download a more current version, just FYI. What does this mean: HKCR\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847} => Key not found. Seems like if it found something the key would be in the registry to be removed. Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 11-06-2013 02 Ran by [removed] at 2013-06-11 16:29:47 Run:1 Running from C:\Documents and Settings\[removed]\My Documents\SoftwareUpdates Boot Mode: Normal ============================================== Default URLSearchHook was restored successfully . HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{EEE6C35D-6118-11DC-9C72-001320C79847} => Value deleted successfully. HKCR\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{44ed99e2-16a6-4b89-80d6-5b21cf42e78b} => Key deleted successfully. HKCR\CLSID\{44ed99e2-16a6-4b89-80d6-5b21cf42e78b} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847} => Key deleted successfully. HKCR\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{EEE6C35B-6118-11DC-9C72-001320C79847} => Value deleted successfully. HKCR\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847} => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Value deleted successfully. HKCR\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Key deleted successfully. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847} => Value deleted successfully. HKCR\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847} => Key not found. "C:\Program Files\SafeMonitor" directory move: Could not move C:\Program Files\SafeMonitor\IE\common.dll. => Scheduled to move on reboot. C:\Program Files\SafeMonitor\Firefox\chrome.manifest => Moved successfully. C:\Program Files\SafeMonitor\Firefox\install.rdf => Moved successfully. C:\Program Files\SafeMonitor\Firefox\chrome\content\main.js => Moved successfully. C:\Program Files\SafeMonitor\Firefox\chrome\content\overlay.xul => Moved successfully. C:\Program Files\SafeMonitor\Chrome\common.crx => Moved successfully. Could not move "C:\Program Files\SafeMonitor" directory. => Scheduled to move on reboot. C:\Program Files\SweetIM => Moved successfully. C:\Documents and Settings\All Users\Application Data\SweetIM => Moved successfully. C:\Windows\System32\TempWmicBatchFile.bat => Moved successfully. C:\END => Moved successfully. C:\Documents and Settings\Terry Felter\Application Data\Mozilla => Moved successfully. C:\Documents and Settings\Terry Felter\My Documents\Flash Player Pro => Moved successfully. C:\Documents and Settings\Terry Felter\g2ax_customer_downloadhelper_win32_x86.exe => Moved successfully. =========== Result of Scheduled Files to move =========== C:\Program Files\SafeMonitor\IE\common.dll => Moved successfully. C:\Program Files\SafeMonitor => Moved successfully. ==== End of Fixlog ==== And the Malware log. Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.06.11.07 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Terry Felter :: TERRYFELTER [administrator] 6/11/2013 4:48:45 PM mbam-log-2013-06-11 (16-48-45).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 234104 Time elapsed: 32 minute(s), 41 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKCU\SOFTWARE\CROSSRIDER (Adware.GamePlayLab) -> Quarantined and deleted successfully. Registry Values Detected: 1 HKCU\Software\Crossrider|215AppVerifier (Adware.GamePlayLab) -> Data: c3abcf13d42a0e6c5e17c572f3adca0f -> Quarantined and deleted successfully. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
That does meen that I wanted to do 100% of work and the line I added for removal wasn´t there… ;)

Please go to here to run the online scannner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file….
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.
Well I had to go through the myriad of internet security options to get eset to run. However after hitting the start button I get a page that blocks the ActiveX, so I choose to install the control and I get a Windows Internet Explorer pop up, which is new to me. It says "To display the webpage again, IE needs to resend the informatio you've previously submitted." Then something about if you were making a purchase. Anyway after either hitting Retry OR Cancel and I get an install button—-but nothing happens happens after that. All that is there is a little window with nice light blue color and a small red x in the upper lefthand corner.
That´s weird…let´s use another scanner.

Run an Online scan

Perform an online scan with Panda ActiveScan
  • Click on Scan Your PC Now
  • A "pop up" window will appear, or a new tab will open.
  • Select Full Scan, then Click on Scan Now
  • Wait for the components to be loaded and installed (you may be prompted to confirm the Installation of software by "Panda security S.L. Confirm it by clicking "install"). Don't close this window or go to another page while it is downloading. You can continue using the Internet by opening another window in your browser.
  • If it finds any malware it can disinfect, the Disinfect button will be enabled. Click on Disinfect
  • Please ignore the offer to buy the program. Click on Export To
    [external image: Posted Image]
  • Export the log and save it to your desktop.
  • Please attach the contents of that log to your reply, along with a new HijackThis log.
* Turn off the real time scanner of any existing antivirus program while performing the online scan.
I may not live long enough for this to complete. Over 10 hours, 103K items checked and it hasn't even started with program files. Currently in \FRST directory and scanning TempWmicBatchFile.bat for about 10 minutes alone. I'm leaving work for home and will close the lid and hopefully the scan will pick up where it left off. SLOW
It just didn't work beyond the install window. No other browser installed or used. EDIT: It may have been the office slow speed because I started now at 0415. I'll close the browser for Panda, when I leave for work in about 45 minutes, unless you want me to leave it open

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI