Page 1 of 3 123 LastLast
Results 1 to 10 of 22
  1. #1
    Member
    Join Date
    Sep 2010
    Posts
    22
    Points
    0

    Default Spyware/Malware Removal Assistance Request

    Hi forum mods and assistants ~ your creation of this site is very much appreciated. My PC is infected ~ my dumb fault after 2 year of no infections since this machine was built. I am running the latest version of AVF and it seems to have blocked the Trojans but my browser is continually being redirected and I am afraid to enter any passwords, do online banking, etc. I read all of the tutorials. I used the CCleaner and have the latest Windows Updates. I ran HiJack This, which found some suspect files (I already fixed what the Detective told me to and rebooted). My real problem is that it appears the malware is keeping SAS and Malwarebytes from opening/running. I even tried to open SAS portable version from an external flash drive. So, sorry I only have the HiJack This log to submit at first. Any help you can provide would be great. Here is the log:

    --------------------------------------------------------------------------------------------------
    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 12:08:08 PM, on 9/26/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgrsx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\AVG\AVG9\avgwdsvc.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\stsystra.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Program Files\Logitech\iTouch\iTouch.exe
    C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
    C:\PROGRA~1\AVG\AVG9\avgtray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
    C:\Program Files\CMS Products\BounceBack Professional\BBLauncher.exe
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Microsoft LifeCam\MSCamS32.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\IoctlSvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Dell Start Page
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Yahoo!
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = Dell Start Page
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: EWPBrowseObject Class - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
    O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
    O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\Pinnacle\PPE\PPE.EXE
    O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
    O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
    O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
    O4 - Global Startup: BounceBack Launcher.lnk = ?
    O4 - Global Startup: HP Display LiteSaver Startup.lnk = C:\WINDOWS\HPLiteSaver.exe
    O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
    O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
    O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite....x/qtplugin.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/res...scbase5483.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/Driver...sysreqlab2.cab
    O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
    O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/Driver...aSmartScan.cab
    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/...Uploader55.cab
    O16 - DPF: {A8739816-022C-11D6-A85D-00C04F9AEAFB} (Web Camera Server Control) - http://98.189.161.52/wg_webeye.cab
    O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/acti..._v1-0-29-0.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O16 - DPF: {FD3FF62E-61A7-48EE-A4A4-97CE7BD1F99D} (SodaAgt Class) - https://navpn.ingrammicro.com/postauthASD/SodaAgent.CAB
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 93.188.163.75,93.188.166.110
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
    O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Portrait Displays\HP Display Assistant\DTSRVC.exe
    O23 - Service: Intel(R) Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: FlipShare Service - Unknown owner - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
    O23 - Service: Google Update Service (gupdate1c9dbbe8d4f2214) (gupdate1c9dbbe8d4f2214) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HauppaugeTVServer - Hauppauge Computer Works - C:\PROGRA~1\WinTV\HCWTVS~1.EXE
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    --
    End of file - 14090 bytes
    -----------------------------------------------------------------------------------------------

  2. #2
    Member
    Join Date
    Sep 2010
    Posts
    22
    Points
    0

    Default

    Update to my first post: I was able to run Malwarebytes by renaming the mbam file (I am no hot-shot techie; I just did some reading on the Malewarebytes forum).
    Here is the quick scan log:

    Malwarebytes' Anti-Malware 1.46
    Malwarebytes

    Database version: 4052

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    9/26/2010 5:16:39 PM
    mbam-log-2010-09-26 (17-16-39).txt

    Scan type: Quick scan
    Objects scanned: 180396
    Time elapsed: 23 minute(s), 55 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 1

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.

    =========================================================================================

    Here is the full scan log:

    Malwarebytes' Anti-Malware 1.46
    Malwarebytes

    Database version: 4700

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    9/26/2010 7:31:32 PM
    mbam-log-2010-09-26 (19-31-32).txt

    Scan type: Full scan (C:\|)
    Objects scanned: 330540
    Time elapsed: 1 hour(s), 52 minute(s), 25 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 2
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 1

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CURRENT_USER\SOFTWARE\3FWHZQA3LT (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\SMH2B46TDP (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job (Trojan.Downloader) -> Quarantined and deleted successfully.


    * Thank You *

  3. #3
    Member
    Join Date
    Sep 2010
    Posts
    22
    Points
    0

    Default

    OK, I was also able to run SUPER AntiSpyware after renaming it as well. It found a DNS Trojan (whatever that is) .Here is the HJT log done after the Malwarebytes & SUPER AntiSpyware programs were run:

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 9:45:57 PM, on 9/26/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgrsx.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\AVG\AVG9\avgwdsvc.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\stsystra.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
    C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Program Files\Logitech\iTouch\iTouch.exe
    C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
    C:\PROGRA~1\AVG\AVG9\avgtray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\SUPERAntiSpyware\winlog.exe.exe
    C:\Program Files\CMS Products\BounceBack Professional\BBLauncher.exe
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Microsoft LifeCam\MSCamS32.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\IoctlSvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Dell Start Page
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Yahoo!
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = Dell Start Page
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: EWPBrowseObject Class - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
    O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
    O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    O4 - HKLM\..\Run: [PCLEPCI] C:\PROGRA~1\Pinnacle\PPE\PPE.EXE
    O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
    O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
    O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\winlog.exe.exe
    O4 - Global Startup: BounceBack Launcher.lnk = ?
    O4 - Global Startup: HP Display LiteSaver Startup.lnk = C:\WINDOWS\HPLiteSaver.exe
    O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
    O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
    O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
    O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite....x/qtplugin.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/res...scbase5483.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/Driver...sysreqlab2.cab
    O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
    O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/Driver...aSmartScan.cab
    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/...Uploader55.cab
    O16 - DPF: {A8739816-022C-11D6-A85D-00C04F9AEAFB} (Web Camera Server Control) - http://98.189.161.52/wg_webeye.cab
    O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/acti..._v1-0-29-0.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O16 - DPF: {FD3FF62E-61A7-48EE-A4A4-97CE7BD1F99D} (SodaAgt Class) - https://navpn.ingrammicro.com/postauthASD/SodaAgent.CAB
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
    O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Portrait Displays\HP Display Assistant\DTSRVC.exe
    O23 - Service: Intel(R) Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: FlipShare Service - Unknown owner - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
    O23 - Service: Google Update Service (gupdate1c9dbbe8d4f2214) (gupdate1c9dbbe8d4f2214) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HauppaugeTVServer - Hauppauge Computer Works - C:\PROGRA~1\WinTV\HCWTVS~1.EXE
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    --
    End of file - 14022 bytes

  4. #4
    Member Net_Surfer's Avatar
    Join Date
    May 2008
    Location
    Paradise Ca.
    Posts
    1,179
    Points
    89
    Blog Entries
    4

    Default

    Hello Maxxam and Welcome to Help2go Spyware Help Forum.


    My nick is Net_Surfer and I will be helping you with your malware issues, this may or may not solve other issues you may have with your machine.

    Please note that whatever repairs we make, are for fixing "your computer problems only" and by no means should be used on another computer.

    I would also like to inform you that most of us here at help2go support forums offer our expert assistance out of the goodness of our hearts. Please be courteous and appreciative for the assistance provided!


    Please be patient and I'd be grateful if you would note the following:

    The cleaning process is not instant. Combofix, OTL and hijackthis logs can take some time to research, so please be patient with me. I know that you need your computer working as quickly as possible, and I will work hard to help see that happen.

    1. Please Read All Instructions Carefully and perform the steps fully and in the order they are written.
    2. If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
    3. Do not attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
    4. In order to see what's going on with your computer I will ask for you to post various logs from the tools that we will use to resolve your issue. Please also share with me any information about how your computer is reacting and behaving each step of the way as we work through this process.
    5. Please avoid installing/uninstalling or updating any programs and attempting any unsupervised fixes or scans. This can make helping you impossible.
    6. Please continue to review my answers until I tell you that your machine is clean and free of malware. (Absence of symptoms does not mean that everything is clear.
    Just because you can't see a problem doesn't mean it isn't there.

    If you can do these things, everything should go smoothly!

    Firstly we will use ComboFix to install the Microsoft Recovery Console for windows XP - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see >> This Article. <<

    Note: If you already have a copy of ComboFix on your system it is essential that you delete it before downloading this copy.

    Please visit this webpage for instructions for downloading and running ComboFix:
    >> A guide and tutorial on using ComboFix <<

    To work properly, you must install ComboFix on the Desktop..
    • If you are using Firefox, make sure that your download settings are as follows:

      * Tools->Options->Main tab
      * Set to "Always ask me where to Save the files".
    • For Internet Explorer:
      o Choose to save, not open the file
      o When prompted - save the file to your desktop

    Run Combofix as follows:
    • Please, never rename Combofix unless instructed.
    • Please insert your flash drive and all usb-drives before running Combofix


    -----------------------------------------------------------
    1. Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    2. Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      -----------------------------------------------------------
    3. Close any open browsers.
    4. WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    5. Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    6. If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
      -----------------------------------------------------------
    7. Double click on combofix.exe on your desktop & follow the prompts.
    8. **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**
    9. If you receive a message that Combofix has detected the presence of rootkit activity and needs to reboot, kindly write down on paper the list of files present in the message before continuing, and post it in your next reply.
    10. Install the Recovery Console upon request.
      NOTE: If you have Windows XP: Combofix may ask you to install the Recovery Console, please allow it to do so.
    11. As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
    12. Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


    When finished, it will produce a report for you. Please post the "C:\ComboFix.txt" for further review.

    A word of advise if you are a lurker:
    Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix.
    It is intended by its creator to be used under the guidance and supervision of a Malware Removal Expert.


    Using this tool incorrectly could lead to disastrous problems with your operating system such as preventing it from ever starting again.
    Please read >> Combofix's Disclaimer. <<


    __________________________
    Important notes regarding ComboFix:

    ComboFix may reset a number of Internet Explorer's settings, including making it the default browser. This can easily be changed once we're finished.

    ComboFix also prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you, please let me know. This can be undone manually when we're finished. Read HERE for an article written by dvk01 on why we disable autoruns.

    Have no other programs running. Your Task Bar should be clear of any program entries including your Browser.
    Do not run Combofix more than once.
    Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.
    The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.
    Even when ComboFix appears to be doing nothing, look at your Drive light. If it is flashing, Combofix is still at work.


    Upon completing the above steps I will review your logs again and take the steps necessary with you to get your machine back in working order clean and free of malware.

    Please DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean and free of malware!!!

    Kind regards
    Net_Surfer

    Our help here is always free but it does cost money to keep the site running. If you feel we've helped you kindly, Click here: >> Please Donate to the Forum <<


    "Obstacles are what you see when yo take your eyes off your Goals"

    Net_Surfer is a Graduate of BleepingComputer Malware Removal Training ProgramYou too could train to help others!.

  5. #5
    Member
    Join Date
    Sep 2010
    Posts
    22
    Points
    0

    Default

    "Please insert your flash drive and all usb-drives before running Combofix" ~ I want to make sure I get this right. Am I supposed to have a flash drive plugged in or was this meant to say to be sure all external drives are unplugged. Thank you for your help and quick response.

  6. #6
    Member
    Join Date
    Sep 2010
    Posts
    22
    Points
    0

    Default

    ComboFix will not open from my desktop (just like all the other malware/spyware removal programs that I ended up renaming).
    Please let me know what you would like me to do next.

    Thank You for your assistance.

  7. #7
    Member Net_Surfer's Avatar
    Join Date
    May 2008
    Location
    Paradise Ca.
    Posts
    1,179
    Points
    89
    Blog Entries
    4

    Default

    Hello Maxxam

    Combofix cleans your usb components like your flash drives.. that is the why I ask for you tu plug them into your computer so if they are infected combofix will clean them up.

    Ensure that you delete the combofix version that you downloaded and use this instructions instead:

    Before we begin, you should save these instructions in Notepad to your Desktop, or print them, for easy reference and to make sure you don't get lost.
    Make sure to work through the fixes in the exact order in which they are mentioned below and do not miss any steps out. If at any point you have questions, or are unsure of the instructions, do not hesitate to post here and ask for clarification before proceeding with the fixes.

    Please carefully follow the next set of steps:

    If you can not download and run the following tools, then I would like for you to try another approach:

    If you have the use of another computer please either use a Flash Drive or a CD to download the following and transfer them for use on the infected machine.
    Be sure you put them on the desktop of the infected computer.


    * exeHelper by Raktor.

    step1.
    Please download: exeHelper to your desktop.
    Double-click on exeHelper.com to run the fix.
    A black window should pop up, press any key to close once the fix is completed.
    Post the contents of exehelperlog.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan)
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    step2.
    * After running exeHelper ("without rebooting") download and run Rkill and combofix.

    We need to use the RKill Tool by Grinler

    Rkill.com <--- Download site
    • Please Download Rkill.com. Save it to your Desktop.
    • Before we begin, you should disable your anti-malware softwares you have installed so they do not interfere RKill running as some anti-malware softwares detect RKill as malicious. Please refer to this page if you are not sure how.
    • NOTE: If you are unable to connect to the site to download rkill, then you should download it to a clean computer and copy it to the infected one via a USB flash drive or CDROM.
    • Once it is downloaded, double-click on the rkill.com in order to automatically attempt to stop any processes associated with Rogue programs.
    • Please be patient while the program looks for various malware programs and ends them.
    • When it has finished, the black window will automatically close and you can continue with the next step.

    NOTE: If you get a message that rkill is an infection, do not be concerned. This message is just a fake warning given by Antivirus Suite when it terminates programs that may potentially remove it. If you run into these infections warnings that close Rkill, a trick is to leave the warning on the screen and then run Rkill again. By not closing the warning, this typically will allow you to bypass the malware trying to protect itself so that rkill can terminate the rogue program. So, please try running Rkill until the malware is no longer running. You will then be able to proceed with the rest of the steps.

    If you continue having problems running rkill.com, you can download:
    iExplore.exe or eXplorer.exe
    which are renamed copies of rkill.com, and try them instead.

    *If the tool does not run from any of the links, Please tell me about it.

    Step 3.Please try ComboFix tool, if you can not run it use exehelper and Rkill and without rebooting try ComboFix again.....

    Please download ComboFix from BleepingComputer.com

    Alternate link: GeeksToGo.com

    Alternate link: Forospyware.com

    Rename ComboFix.exe to commy.exe before you save it to your Desktop
    • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here
    • Click Start>Run then copy paste the following command into the Run box & click OK "%userprofile%\desktop\commy.exe" /stepdel
    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console


    Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


    • Click on Yes, to continue scanning for malware.
    • When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply.
    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    A word of advise if you are a lurker: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix.
    It is intended by its creator to be used under the guidance and supervision of a Malware Removal Expert.

    Using this tool incorrectly could lead to disastrous problems with your operating system such as preventing it from ever starting again.
    Please read the: Combofix's "Disclaimer".


    Summary of the logs I will need in your next reply:
    • ExeHelper log.
    • Rkill log.
    • The ComboFix log.

    How are things your end Maxxam?
    Last edited by Net_Surfer; 09-27-2010 at 10:21 PM.
    Our help here is always free but it does cost money to keep the site running. If you feel we've helped you kindly, Click here: >> Please Donate to the Forum <<


    "Obstacles are what you see when yo take your eyes off your Goals"

    Net_Surfer is a Graduate of BleepingComputer Malware Removal Training ProgramYou too could train to help others!.

  8. #8
    Member
    Join Date
    Sep 2010
    Posts
    22
    Points
    0

    Default

    Hi Net_Surfer,
    Here is the status: The malware must have put up a good fight as none of the programs would open from my desktop. I saved them all to a flash drive and then 'saved to' desktop each one as a shortcut. Then they all opened and ran. Both exeHelper & RKill had a Windows warning box (box header said "16 Bit MS-DOS Subsystem") before running: "An installable Virtual Device Driver Failed DLL Initialization". I picked 'ignore' and the programs ran. ComboFix did detect rootkit activity and needed to reboot, but there were no messages.

    Here are the logs:

    exeHelper by Raktor
    Build 20100414
    Run at 20:50:29 on 09/27/10
    Now searching...
    Checking for numerical processes...
    Checking for sysguard processes...
    Checking for bad processes...
    Checking for bad files...
    Checking for bad registry entries...
    Resetting filetype association for .exe
    Resetting filetype association for .com
    Resetting userinit and shell values...
    Resetting policies...
    --Finished—


    This log file is located at C:\rkill.log.
    Please post this only if requested to by the person helping you.
    Otherwise you can close this log when you wish.
    Ran as Greg on 09/27/2010 at 20:56:07.


    Services Stopped:


    Processes terminated by Rkill or while it was running:




    Rkill completed on 09/27/2010 at 20:56:13.


    ComboFix 10-09-27.04 - Greg 09/27/2010 21:15:41.1.2 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2550 [GMT -7:00]
    Running from: I:\commy.exe
    AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Greg\Application Data\.#
    c:\documents and settings\Greg\Application Data\Dealio
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\as_sidebar.html
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\blank.gif
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\deal_report.jpg
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\deals-endcap.gif
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\deals-leftcap.gif
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\ebay_login.jpg
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\endcap22-bg.png
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\endcap22-left.png
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\endcap22-right-arrow.png
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\endcap22-right.png
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\err_mainwindow.html
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\err_sidebar.html
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\err_toolbar.html
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\ErrorPageTemplate.css
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\global_scripts.js
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\headerbgthin.jpg
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\help.gif
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\logo.png
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\logo_over.png
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\man_toolbar.html
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\man_toolbar.js
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\pill_bg.gif
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\post-this-deal.gif
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\post-this-deal_over.gif
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\scripts.js
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\scroller.js
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\search-chevron.gif
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\search_bg_blink.gif
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\separator.gif
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\settings.gif
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\settings_over.gif
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\sidebar.html
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\steals_bg.gif
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\tab_icon.png
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\tabdata.js
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\tablib.js
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\tabwelcome_en.html
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\toolbar_background.gif
    c:\documents and settings\Greg\Application Data\Dealio\kb124\res\yahoo_search.gif
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\index.1.80.39
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.10.76
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.109.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.110.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.12.52
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.13.58
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.130.58
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.135.50
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.153.44
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.155.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.156.49
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.16.60
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.161.52
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.178.66
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.184.55
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.188.52
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.189.45
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.196.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.198.56
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.199.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.200.53
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.201.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.202.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.203.71
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.205.62
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.213.71
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.214.49
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.215.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.216.67
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.217.67
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.218.52
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.219.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.220.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.221.57
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.222.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.223.68
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.226.68
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.227.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.228.62
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.229.76
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.23.63
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.239.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.24.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.240.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.241.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.242.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.243.77
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.244.63
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.245.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.247.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.248.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.249.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.250.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.251.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.252.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.253.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.254.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.255.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.256.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.257.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.279.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.28.58
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.282.75
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.283.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.284.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.289.67
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.290.62
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.291.61
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.296.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.297.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.304.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.307.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.308.75
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.31.47
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.310.46
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.311.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.315.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.316.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.317.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.318.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.319.49
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.32.48
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.334.44
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.335.60
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.336.44
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.337.44
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.338.75
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.339.47
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.34.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.340.47
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.341.47
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.349.50
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.35.48
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.350.50
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.351.51
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.352.77
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.353.51
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.354.51
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.357.62
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.358.52
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.359.52
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.360.53
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.361.54
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.362.68
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.363.58
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.364.54
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.365.53
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.367.56
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.368.58
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.369.55
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.370.80
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.371.56
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.372.57
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.373.55
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.375.56
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.376.57
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.377.55
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.378.65
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.384.58
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.386.71
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.387.59
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.388.59
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.389.59
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.390.60
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.391.78
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.392.60
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.393.60
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.394.60
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.396.61
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.397.61
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.398.60
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.399.60
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.403.61
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.404.63
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.405.61
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.406.61
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.407.76
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.408.63
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.409.61
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.412.62
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.413.62
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.414.62
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.415.62
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.416.62
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.417.62
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.418.62
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.419.62
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.420.62
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.421.62
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.423.77
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.424.63
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.425.63
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.426.63
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.427.63
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.428.65
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.429.63
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.430.63
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.432.65
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.433.64
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.434.65
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.435.64
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.436.76
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.437.64
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.438.71
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.439.71
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.440.75
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.442.73
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.443.73
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.444.73
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.445.68
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.446.69
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.450.67
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.451.67
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.452.68
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.453.68
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.454.69
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.456.69
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.457.75
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.458.70
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.459.70
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.460.69
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.462.74
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.463.69
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.464.70
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.465.68
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.468.70
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.469.70
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.470.70
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.471.73
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.472.70
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.478.74
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.479.73
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.480.68
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.481.71
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.482.74
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.49.67
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.50.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.500.71
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.501.74
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.502.71
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.51.69
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.52.72
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.520.76
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.521.76
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.522.76
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.53.51
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.531.76
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.532.75
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.533.77
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.534.75
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.54.47
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.55.45
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.56.69
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.57.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.58.47
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.591.79
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.592.79
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.593.76
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.594.77
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.595.76
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.608.78
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.610.80
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.611.79
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.614.79
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.617.79
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.624.80
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.63.57
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.640.80
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.641.80
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.66.47
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.70.75
    c:\documents and settings\Greg\Application Data\Dealio\kb124\rules\rules.1.71.43
    c:\documents and settings\Greg\Application Data\Dealio\kb124\temp\dealio-13968.log
    c:\documents and settings\Greg\Application Data\Dealio\kb124\temp\dod_cache.xml
    c:\documents and settings\Greg\Application Data\Dealio\kb124\temp\installtype.ini
    C:\LOG3B.tmp
    C:\Thumbs.db
    c:\windows\system32\_000006_.tmp.dll

    Infected copy of c:\windows\system32\drivers\pci.sys was found and disinfected
    Restored copy from - Kitty had a snack
    .
    ((((((((((((((((((((((((( Files Created from 2010-08-28 to 2010-09-28 )))))))))))))))))))))))))))))))
    .

    2010-09-27 14:35 . 2010-09-27 14:35 -------- d-----w- c:\documents and settings\Greg\Application Data\ElevatedDiagnostics
    2010-09-27 04:09 . 2010-09-27 14:16 63488 ----a-w- c:\documents and settings\Greg\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
    2010-09-27 04:09 . 2010-09-27 04:09 52224 ----a-w- c:\documents and settings\Greg\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
    2010-09-27 04:09 . 2010-09-27 14:16 117760 ----a-w- c:\documents and settings\Greg\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
    2010-09-27 04:08 . 2010-09-27 04:08 -------- d-----w- c:\documents and settings\Greg\Application Data\SUPERAntiSpyware.com
    2010-09-26 16:15 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-09-26 16:15 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-09-26 05:39 . 2010-09-26 05:31 1129120 ----a-w- c:\documents and settings\All Users\Application Data\STOPzilla!\vdb\vbcorent.dll
    2010-09-26 05:21 . 2010-09-26 11:44 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
    2010-09-26 05:13 . 2010-09-26 05:13 -------- d-----w- c:\program files\CCleaner
    2010-09-26 04:48 . 2010-09-26 04:48 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
    2010-09-26 02:27 . 2010-09-26 02:27 -------- d-----w- c:\program files\Trend Micro
    2010-09-25 17:38 . 2010-09-25 17:38 14 ----a-w- c:\windows\ASSE.dat
    2010-09-25 17:38 . 2010-09-25 17:38 -------- d-----w- c:\program files\AdWare SpyWare SE
    2010-09-24 22:32 . 2010-09-25 03:09 664 ----a-w- c:\windows\system32\d3d9caps.dat
    2010-09-24 21:31 . 2010-09-24 21:32 -------- d-----w- c:\documents and settings\Greg\Application Data\GetRightToGo
    2010-09-24 21:01 . 2010-09-24 21:01 -------- d-----w- c:\windows\system32\EWS
    2010-09-24 20:47 . 2010-09-24 20:47 -------- d-----w- c:\program files\Easy CD & DVD Cover Creator
    2010-09-12 21:48 . 2010-09-13 03:16 -------- d-----w- c:\windows\BounceBack
    2010-09-09 03:34 . 2010-09-09 14:10 -------- d-----w- c:\windows\BounceBK02

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-09-27 17:11 . 2007-02-11 17:33 -------- d-----w- c:\documents and settings\Greg\Application Data\Canon
    2010-09-27 05:38 . 2009-02-28 04:19 -------- d-----w- c:\documents and settings\Greg\Application Data\Skype
    2010-09-27 04:08 . 2010-09-27 04:08 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
    2010-09-27 04:08 . 2010-09-26 16:18 -------- d-----w- c:\program files\SUPERAntiSpyware
    2010-09-27 04:04 . 2010-03-31 18:56 7168 -csha-w- c:\program files\Thumbs.db
    2010-09-27 03:55 . 2010-09-27 03:46 79488 ----a-w- c:\documents and settings\Greg\Application Data\Sun\Java\jre1.6.0_20\gtapi.dll
    2010-09-27 03:55 . 2010-09-27 03:46 152576 ----a-w- c:\documents and settings\Greg\Application Data\Sun\Java\jre1.6.0_20\lzma.dll
    2010-09-27 03:46 . 2007-01-12 09:15 -------- d-----w- c:\program files\Java
    2010-09-27 03:35 . 2009-02-28 04:19 -------- d-----r- c:\program files\Skype
    2010-09-27 03:35 . 2009-02-28 04:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
    2010-09-26 23:47 . 2010-06-30 20:46 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-09-26 18:47 . 2010-09-26 18:47 388096 ----a-r- c:\documents and settings\Greg\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
    2010-09-26 18:02 . 2010-09-26 18:02 12536 ----a-w- c:\windows\system32\avgrsstx.dll
    2010-09-26 18:02 . 2010-09-26 18:02 243024 -c--a-w- c:\windows\system32\drivers\avgtdix.sys
    2010-09-26 18:01 . 2010-09-26 18:01 216400 -c--a-w- c:\windows\system32\drivers\avgldx86.sys
    2010-09-26 18:01 . 2010-09-26 18:01 29584 -c--a-w- c:\windows\system32\drivers\avgmfx86.sys
    2010-09-26 17:59 . 2009-12-13 17:15 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
    2010-09-26 05:29 . 2010-09-26 05:28 2184 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
    2010-09-26 03:23 . 2007-01-29 06:31 -------- d-----w- c:\program files\Common Files\Adobe
    2010-09-26 03:21 . 2007-01-12 09:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
    2010-09-25 16:57 . 2008-02-03 19:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
    2010-09-21 22:03 . 2007-01-12 09:23 -------- d-----w- c:\program files\QuickTime
    2010-09-21 22:02 . 2007-12-03 05:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
    2010-09-18 23:09 . 2009-02-28 04:27 -------- d-----w- c:\documents and settings\Greg\Application Data\skypePM
    2010-09-17 14:54 . 2007-01-12 09:28 -------- d-----w- c:\program files\Google
    2010-09-04 05:33 . 2010-07-15 23:19 -------- d-----w- c:\program files\iTunes
    2010-08-17 13:17 . 2005-08-16 10:18 58880 ----a-w- c:\windows\system32\spoolsv.exe
    2010-08-10 04:58 . 2010-08-10 04:58 503808 ----a-w- c:\documents and settings\Sabrina\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-7743ed71-n\msvcp71.dll
    2010-08-10 04:58 . 2010-08-10 04:58 499712 ----a-w- c:\documents and settings\Sabrina\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-7743ed71-n\jmc.dll
    2010-08-10 04:58 . 2010-08-10 04:58 348160 ----a-w- c:\documents and settings\Sabrina\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-7743ed71-n\msvcr71.dll
    2010-08-10 04:58 . 2010-08-10 04:58 61440 ----a-w- c:\documents and settings\Sabrina\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-4717df31-n\decora-sse.dll
    2010-08-10 04:58 . 2010-08-10 04:58 12800 ----a-w- c:\documents and settings\Sabrina\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-4717df31-n\decora-d3d.dll
    2010-08-09 17:29 . 2010-08-09 17:29 503808 ----a-w- c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-6ea639f4-n\msvcp71.dll
    2010-08-09 17:29 . 2010-08-09 17:29 499712 ----a-w- c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-6ea639f4-n\jmc.dll
    2010-08-09 17:29 . 2010-08-09 17:29 348160 ----a-w- c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-6ea639f4-n\msvcr71.dll
    2010-08-09 17:29 . 2010-08-09 17:29 12800 ----a-w- c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-2350e948-n\decora-d3d.dll
    2010-08-09 17:29 . 2010-08-09 17:29 61440 ----a-w- c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-2350e948-n\decora-sse.dll
    2010-08-09 17:22 . 2010-08-09 17:22 -------- d-----w- c:\documents and settings\Guest\Application Data\Apple Computer
    2010-08-08 23:17 . 2010-08-08 23:17 503808 ----a-w- c:\documents and settings\Greg\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1c5f1b58-n\msvcp71.dll
    2010-08-08 23:17 . 2010-08-08 23:17 499712 ----a-w- c:\documents and settings\Greg\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1c5f1b58-n\jmc.dll
    2010-08-08 23:17 . 2010-08-08 23:17 348160 ----a-w- c:\documents and settings\Greg\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1c5f1b58-n\msvcr71.dll
    2010-08-08 23:17 . 2010-08-08 23:17 61440 ----a-w- c:\documents and settings\Greg\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1481d573-n\decora-sse.dll
    2010-08-08 23:17 . 2010-08-08 23:17 12800 ----a-w- c:\documents and settings\Greg\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1481d573-n\decora-d3d.dll
    2010-07-22 15:49 . 2005-08-16 10:18 590848 ----a-w- c:\windows\system32\rpcrt4.dll
    2010-07-22 05:57 . 2009-04-16 03:56 5120 ----a-w- c:\windows\system32\xpsp4res.dll
    2010-07-17 12:00 . 2010-05-27 14:34 423656 ----a-w- c:\windows\system32\deployJava1.dll
    2010-07-16 21:10 . 2010-07-16 21:10 75392 ---ha-w- c:\windows\system32\mlfcache.dat
    2010-07-10 05:23 . 2010-07-06 05:00 202192 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
    2010-06-30 12:31 . 2005-08-16 10:18 149504 ----a-w- c:\windows\system32\schannel.dll
    2007-01-28 18:27 . 2007-01-28 18:27 251 -c----w- c:\program files\wt3d.ini
    2007-01-29 07:24 . 2007-01-28 07:37 88 -csh--r- c:\windows\system32\ABDAE0D274.sys
    2007-01-29 07:24 . 2007-01-28 07:37 3920 --sh--w- c:\windows\system32\KGyGaAvL.sys
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-20 39408]
    "DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2010-04-16 818288]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
    "SigmatelSysTrayApp"="stsystra.exe" [2006-07-24 282624]
    "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 151552]
    "OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-03-21 69632]
    "AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2007-02-26 684032]
    "PCLEPCI"="c:\progra~1\Pinnacle\PPE\PPE.EXE" [2004-02-03 49152]
    "zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2004-03-18 892928]
    "EM_EXEC"="c:\progra~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [2002-07-09 28672]
    "LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2009-07-24 118640]
    "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-05-28 570664]
    "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-07-27 221184]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
    "AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-09-26 2065760]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    BounceBack Launcher.lnk - c:\program files\CMS Products\BounceBack Professional\BBLauncher.exe [2007-2-24 90112]
    HP Display LiteSaver Startup.lnk - c:\windows\HPLiteSaver.exe [2004-8-24 65536]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2010-09-26 18:02 12536 ----a-w- c:\windows\system32\avgrsstx.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
    "c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
    "c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
    "c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
    "c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
    "c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
    "c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
    "c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
    "c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=

    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/26/2010 11:01 AM 216400]
    R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/26/2010 11:02 AM 243024]
    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 11:25 AM 12872]
    R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 11:41 AM 67656]
    R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [9/26/2010 11:00 AM 308136]
    R2 portD;CMS PortIO Service;c:\windows\system32\drivers\portd2k.sys [2/24/2007 11:50 PM 7424]
    S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
    S2 gupdate1c9dbbe8d4f2214;Google Update Service (gupdate1c9dbbe8d4f2214);c:\program files\Google\Update\GoogleUpdate.exe [5/23/2009 8:53 AM 133104]
    S3 HauppaugeTVServer;HauppaugeTVServer;c:\progra~1\WinTV\HCWTVS~1.EXE [6/14/2009 1:57 PM 815104]
    S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\drivers\nx6000.sys [2/25/2009 9:05 PM 30560]
    S3 NgFilter;Aventail VPN Filter;c:\windows\system32\DRIVERS\ngfilter.sys --> c:\windows\system32\DRIVERS\ngfilter.sys [?]
    S3 NgLog;Aventail VPN Logging;c:\windows\system32\DRIVERS\nglog.sys --> c:\windows\system32\DRIVERS\nglog.sys [?]
    S3 NgVpn;Aventail VPN Adapter;c:\windows\system32\DRIVERS\ngvpn.sys --> c:\windows\system32\DRIVERS\ngvpn.sys [?]
    S3 NgWfp;Aventail VPN Callout;c:\windows\system32\DRIVERS\ngwfp.sys --> c:\windows\system32\DRIVERS\ngwfp.sys [?]
    .
    Contents of the 'Scheduled Tasks' folder

    2010-09-21 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 18:50]

    2010-09-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-23 15:52]

    2010-09-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-23 15:52]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.yahoo.com/
    uInternet Settings,ProxyOverride = *.local
    IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
    IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
    IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
    IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office10\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
    IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
    IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
    IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
    IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
    IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
    Trusted Zone: ingrammicro.com\navpn
    Trusted Zone: ingrammicro.com\remote
    .
    - - - - ORPHANS REMOVED - - - -

    Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)



    **************************************************************************
    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files:

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(848)
    c:\program files\SUPERAntiSpyware\SASWINLO.DLL
    c:\windows\system32\WININET.dll
    .
    Completion time: 2010-09-27 21:31:34
    ComboFix-quarantined-files.txt 2010-09-28 04:31

    Pre-Run: 18,476,163,072 bytes free
    Post-Run: 19,388,129,280 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    UnsupportedDebug="do not select this" /debug
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /fastdetect /NoExecute=OptIn

    - - End Of File - - 94D9F5D04FC68BEE74A9B04AD2D13EBB

  9. #9
    Member Net_Surfer's Avatar
    Join Date
    May 2008
    Location
    Paradise Ca.
    Posts
    1,179
    Points
    89
    Blog Entries
    4

    Default

    Hello again Maxxam

    Combofix did a good job and got the rootkit...If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

    I believe you can now run the programs normally ?

    Let me know if you still having running the programs normally.


    I recommend you to uninstall "WeatherBug Installer", as WeatherBug has been associated with minor malware.

    The logs also show Viewpoint Manager installed, Viewpoint Manager is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad". This changed from what we know in 2006 read this article:

    http://www.clickz.com/news/article.php/3561546

    I suggest you remove the program now. Click on start > run > and then paste the following into the "open" field: appwiz.cpl and press OK. From within Add or Remove Programs uninstall the following if they exist:
    Viewpoint
    Viewpoint Manager
    Viewpoint Media Player

    Then, go to c: > program files and delete viewpoint folder.
    .



    Lets do the next steps since I noticed that you have SuperAntiSpyware installed on your system run it with this instructions:

    Step 1.

    SUPERANTISPYWARE

    Please download and scan with SUPERAntiSpyware Free
    • Double-click SUPERAntiSypware.exe and use the default settings for installation.
    • An icon will be created on your desktop. Double-click that icon to launch the program.
    • If it will not start, go to Start > All Prgrams > SUPERAntiSpyware and click on Alternate Start.
    • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download them from here. Double-click on the hyperlink for Download Installer and save SASDEFINITIONS.EXE to your desktop. Then double-click on SASDEFINITIONS.EXE to install the definitions.)
    • In the Main Menu, click the Preferences... button.
    • Click the "General and Startup" tab, and under Start-up Options, make sure "Start SUPERAntiSpyware when Windows starts" box is unchecked.
    • Click the "Scanning Control" tab, and under Scanner Options, make sure the following are checked (leave all others unchecked):
      • Close browsers before scanning.
      • Scan for tracking cookies.
      • Terminate memory threats before quarantining.
    • Click the "Close" button to leave the control center screen and exit the program.
    • Do not run a scan just yet.
    Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

    Scan with SUPERAntiSpyware as follows:
    • Launch the program and back on the main screen, under "Scan for Harmful Software" click Scan your computer.
    • On the left, make sure you check C:\Fixed Drive.
    • On the right, under "Complete Scan", choose Perform Complete Scan and click "Next".
    • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
    • Make sure everything has a checkmark next to it and click "Next".
    • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
    • If asked if you want to reboot, click "Yes" and reboot normally.
    • To retrieve the removal information after reboot, launch SUPERAntispyware again.
      • Click Preferences, then click the Statistics/Logs tab.
      • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
      • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
      • Please copy and paste the Scan Log results in your next reply.
    • Click Close to exit the program.


    Step 2.
    • Download: >>> OTL by Old Timer <<< to your desktop.
    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check
    .

    .

    • Now copy the lines below.

      netsvcs
      msconfig
      %SYSTEMDRIVE%\*.exe
      /md5start
      eventlog.dll
      scecli.dll
      netlogon.dll
      cngaudit.dll
      sceclt.dll
      ntelogon.dll
      logevent.dll
      iaStor.sys
      nvstor.sys
      atapi.sys
      IdeChnDr.sys
      viasraid.sys
      AGP440.sys
      vaxscsi.sys
      nvatabus.sys
      viamraid.sys
      nvata.sys
      nvgts.sys
      iastorv.sys
      ViPrt.sys
      eNetHook.dll
      ahcix86.sys
      KR10N.sys
      nvstor32.sys
      ahcix86s.sys
      nvrd32.sys
      symmpi.sys
      adp3132.sys
      /md5stop
      %systemroot%\*. /mp /s
      %systemroot%\system32\*.dll /lockedfiles
      %systemroot%\Tasks\*.job /lockedfiles
      %systemroot%\system32\drivers\*.sys /lockedfiles
      CREATERESTOREPOINT


    • right click in the Custom Scans/Fixes window (under the blue bar) and choose Paste.


      .
    • Click the Run Scan button.


    • Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them with your next reply.


    Summary of the logs I will need in your next reply:
    • The report log of SuperAntiSpyware.
    • the report logs of OTL:

      OTL.Txt and Extras.Txt


    How are things your end Maxxam??


    Upon completing the above steps I will review your logs again and take the steps necessary with you to get your machine back in working order clean and free of malware.

    Again, Please DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean and free of malware!!!

    Kind regards
    Net_Surfer
    Our help here is always free but it does cost money to keep the site running. If you feel we've helped you kindly, Click here: >> Please Donate to the Forum <<


    "Obstacles are what you see when yo take your eyes off your Goals"

    Net_Surfer is a Graduate of BleepingComputer Malware Removal Training ProgramYou too could train to help others!.

  10. #10
    Member
    Join Date
    Sep 2010
    Posts
    22
    Points
    0

    Default

    Hi Net_Surfer ~ Everything done as requested (see logs below).
    I may have made one bad mistake: I have an external hard-drive that I use to make regular backups. It is a SeaGate and I use CMS Bounceback to compare files and update the external hard drive. I do this manually and usually only after I add new pictures. The external hard drive is otherwise left OFF. I have not turned it on or done any backups for probably a week. Which was before my major attack. But now a feel stupid because it probably should have been ON during all the scans - correct? I don't want to turn it on yet ~ if it has some maleware or trojans could it reinfect my PC when doing an update? Let me know the best course of action. Thanks.

    Logs:

    Memory threats detected : 0
    Registry items scanned : 9505
    Registry threats detected : 0
    File items scanned : 133842
    File threats detected : 12

    Adware.Tracking Cookie
    C:\Documents and Settings\Greg\Cookies\greg@richmedia.yahoo[2].txt
    media1.break.com [ C:\Documents and Settings\Greg\Application Data\Macromedia\Flash Player\#SharedObjects\26XZLZXJ ]
    secure-us.imrworldwide.com [ C:\Documents and Settings\Greg\Application Data\Macromedia\Flash Player\#SharedObjects\26XZLZXJ ]

    Malware.Installer-Pkg/Gen
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{26D2C2C3-CF14-4ED7-B1FC-0BE64AFBA3B3}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{3C48F877-A164-45E9-B9DA-26A049FFC207}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{6293BC00-4EB8-4C65-8548-53E2FC3BF937}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{651956B7-1969-42AA-9453-E0B813019D54}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{6B6A7665-DB48-4762-AB5D-BEEB9E1CD7FA}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{C0A0AA4D-C79B-48CA-8843-2B02B626C9E6}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{C2D8F0E2-6978-4409-8351-BA8785DA11EE}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{D1A6F3FD-7B40-443F-8767-BADB25A0D222}.EXE
    C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{E0814F95-5380-4892-B8C8-7FA4B349EF46}.EXE


    OTL logfile created on: 9/28/2010 4:35:04 PM - Run 1
    OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Greg\Desktop
    Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 80.00% Memory free
    4.00 Gb Paging File | 4.00 Gb Available in Paging File | 90.00% Paging File free
    Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 228.13 Gb Total Space | 17.87 Gb Free Space | 7.83% Space Free | Partition Type: NTFS
    D: Drive not present or media not loaded
    E: Drive not present or media not loaded
    F: Drive not present or media not loaded
    G: Drive not present or media not loaded
    H: Drive not present or media not loaded
    I: Drive not present or media not loaded

    Computer Name: GLICK-DEN-PC
    Current User Name: Greg
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Company Name Whitelist: Off
    Skip Microsoft Files: Off
    File Age = 30 Days
    Output = Minimal

    ========== Processes (SafeList) ==========

    PRC - C:\Documents and Settings\Greg\Desktop\OTL.exe (OldTimer Tools)
    PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
    PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
    PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
    PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
    PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
    PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
    PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
    PRC - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
    PRC - C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe (The Weather Channel Interactive, Inc.)
    PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    PRC - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
    PRC - C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe (Roxio)
    PRC - C:\Program Files\CMS Products\BounceBack Professional\BBLauncher.exe ()
    PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
    PRC - C:\Program Files\Portrait Displays\HP Display Assistant\DTSRVC.exe ()
    PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
    PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
    PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
    PRC - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\ELService.exe (Intel Corporation)
    PRC - C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe (ScanSoft, Inc.)
    PRC - C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
    PRC - C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE (Logitech Inc. )


    ========== Modules (SafeList) ==========

    MOD - C:\Documents and Settings\Greg\Desktop\OTL.exe (OldTimer Tools)
    MOD - C:\WINDOWS\system32\msacm32.dll (Microsoft Corporation)
    MOD - C:\WINDOWS\AppPatch\acgenral.dll (Microsoft Corporation)
    MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
    MOD - C:\Program Files\ScanSoft\OmniPageSE4.0\OpHookSE4.dll (ScanSoft, Inc.)
    MOD - C:\Program Files\Logitech\iTouch\itchhk.dll (Logitech Inc.)
    MOD - C:\Program Files\Logitech\MouseWare\system\LGMOUSHK.DLL (Logitech Inc. )


    ========== Win32 Services (SafeList) ==========

    SRV - (avg9wd) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
    SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
    SRV - (FlipShare Service) -- C:\Program Files\Flip Video\FlipShare\FlipShareService.exe ()
    SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
    SRV - (MSCamSvc) -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
    SRV - (Symantec Core LC) -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
    SRV - (HauppaugeTVServer) -- C:\Program Files\WinTV\HCWTVServer.exe (Hauppauge Computer Works)
    SRV - (CCALib8) -- C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
    SRV - (DTSRVC) -- C:\Program Files\Portrait Displays\HP Display Assistant\DTSRVC.exe ()
    SRV - (IAANTMON) Intel(R) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
    SRV - (ELService) Intel(R) -- C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\ELService.exe (Intel Corporation)


    ========== Driver Services (SafeList) ==========

    DRV - (wanatw) WAN Miniport (ATW) -- C:\WINDOWS\System32\DRIVERS\wanatw4.sys File not found
    DRV - (SABProcEnum) -- C:\Program Files\Internet Explorer\SABProcEnum.sys File not found
    DRV - (NgWfp) -- C:\WINDOWS\System32\DRIVERS\ngwfp.sys File not found
    DRV - (NgVpn) -- C:\WINDOWS\System32\DRIVERS\ngvpn.sys File not found
    DRV - (NgLog) -- C:\WINDOWS\System32\DRIVERS\nglog.sys File not found
    DRV - (NgFilter) -- C:\WINDOWS\System32\DRIVERS\ngfilter.sys File not found
    DRV - (Lbd) -- C:\WINDOWS\System32\DRIVERS\Lbd.sys File not found
    DRV - (catchme) -- C:\DOCUME~1\Greg\LOCALS~1\Temp\catchme.sys File not found
    DRV - (AvgTdiX) -- C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
    DRV - (AvgLdx86) -- C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
    DRV - (AvgMfx86) -- C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
    DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    DRV - (MSHUSBVideo) -- C:\WINDOWS\system32\drivers\nx6000.sys (Microsoft Corporation)
    DRV - (hcwPP2) -- C:\WINDOWS\system32\drivers\hcwPP2.sys (Hauppauge Computer Works, Inc.)
    DRV - (61883) -- C:\WINDOWS\system32\drivers\61883.sys (Microsoft Corporation)
    DRV - (Avc) -- C:\WINDOWS\system32\drivers\avc.sys (Microsoft Corporation)
    DRV - (MSDV) -- C:\WINDOWS\system32\drivers\msdv.sys (Microsoft Corporation)
    DRV - (IrBus) -- C:\WINDOWS\system32\drivers\irbus.sys (Microsoft Corporation)
    DRV - (usbaudio) USB Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
    DRV - (amdagp) -- C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
    DRV - (sisagp) -- C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
    DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows (R) Server 2003 DDK provider)
    DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
    DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
    DRV - (UsbDiag) -- C:\WINDOWS\system32\drivers\lgusbdiag.sys (LG Electronics Inc.)
    DRV - (USBModem) -- C:\WINDOWS\system32\drivers\lgusbmodem.sys (LG Electronics Inc.)
    DRV - (usbbus) -- C:\WINDOWS\system32\drivers\lgusbbus.sys (LG Electronics Inc.)
    DRV - (cdudf_xp) -- C:\WINDOWS\System32\drivers\cdudf_xp.sys (Roxio)
    DRV - (UdfReadr_xp) -- C:\WINDOWS\System32\drivers\udfreadr_xp.sys (Roxio)
    DRV - (pwd_2k) -- C:\WINDOWS\System32\drivers\pwd_2K.sys (Roxio)
    DRV - (mmc_2K) -- C:\WINDOWS\System32\drivers\Mmc_2k.sys (Roxio)
    DRV - (dvd_2K) -- C:\WINDOWS\System32\drivers\Dvd_2k.sys (Roxio)
    DRV - (StMp3Rec) -- C:\WINDOWS\system32\drivers\StMp3Rec.sys (Generic)
    DRV - (pfc) -- C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
    DRV - (symlcbrd) -- C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
    DRV - (pdiddcci) -- C:\WINDOWS\system32\drivers\pdiddcci.sys (Portrait Displays, Inc.)
    DRV - (PdiPorts) -- C:\WINDOWS\system32\drivers\PdiPorts.sys (Portrait Displays, Inc.)
    DRV - (Cdralw2k) -- C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
    DRV - (Cdr4_xp) -- C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
    DRV - (STHDA) -- C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
    DRV - (e1express) Intel(R) -- C:\WINDOWS\system32\drivers\e1e5132.sys (Intel Corporation)
    DRV - (iaStor) -- C:\WINDOWS\system32\drivers\iaStor.sys (Intel Corporation)
    DRV - (NAL) -- C:\WINDOWS\system32\drivers\iqvw32.sys (Intel Corporation )
    DRV - (ELacpi) -- C:\WINDOWS\system32\drivers\ELacpi.sys (Intel Corporation)
    DRV - (ELmon) -- C:\WINDOWS\system32\drivers\Elmon.sys (Intel Corporation)
    DRV - (ELkbd) -- C:\WINDOWS\system32\drivers\Elkbd.sys (Intel Corporation)
    DRV - (ELmou) -- C:\WINDOWS\system32\drivers\Elmou.sys (Intel Corporation)
    DRV - (ELhid) -- C:\WINDOWS\system32\drivers\Elhid.sys (Intel Corporation)
    DRV - (DSproct) -- C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys (GTek Technologies Ltd.)
    DRV - (portD) -- C:\WINDOWS\system32\drivers\portd2k.sys (CMS Peripherals, Inc.)
    DRV - (MarvinBus) -- C:\WINDOWS\system32\drivers\MarvinBus.sys (Pinnacle Systems GmbH)
    DRV - (ASAPIW2k) -- C:\WINDOWS\system32\drivers\asapiW2k.sys (Pinnacle Systems GmbH)
    DRV - (itchfltr) -- C:\WINDOWS\system32\drivers\itchfltr.sys (Logitech, Inc.)
    DRV - (LHidUsb) -- C:\WINDOWS\system32\drivers\LHidUsb.sys (Logitech, Inc.)
    DRV - (LCcfltr) -- C:\WINDOWS\system32\drivers\LCcfltr.sys (Logitech, Inc.)
    DRV - (PCLEPCI) -- C:\WINDOWS\system32\drivers\PCLEPCI.sys (Pinnacle Systems GmbH)
    DRV - (LMouFlt2) -- C:\WINDOWS\system32\drivers\LMouFlt2.sys (Logitech, Inc.)
    DRV - (LHidFlt2) -- C:\WINDOWS\system32\drivers\LHidFlt2.sys (Logitech, Inc.)
    DRV - (LKbdFlt2) -- C:\WINDOWS\system32\drivers\LKbdFlt2.sys (Logitech, Inc.)
    DRV - (Sparrow) -- C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
    DRV - (sym_u3) -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
    DRV - (sym_hi) -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
    DRV - (symc8xx) -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
    DRV - (symc810) -- C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
    DRV - (ultra) -- C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
    DRV - (ql12160) -- C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
    DRV - (ql1080) -- C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
    DRV - (ql1280) -- C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
    DRV - (dac2w2k) -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
    DRV - (mraid35x) -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
    DRV - (asc) -- C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
    DRV - (asc3550) -- C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
    DRV - (AliIde) -- C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
    DRV - (CmdIde) -- C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = Dell Start Page
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = Dell Start Page

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = Yahoo!
    IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local



    O1 HOSTS File: ([2010/09/27 21:30:03 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
    O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
    O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
    O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
    O2 - BHO: (EWPBrowseObject Class) - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll ()
    O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll (Google Inc.)
    O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc)
    O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
    O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
    O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
    O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
    O4 - HKLM..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe (Roxio)
    O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
    O4 - HKLM..\Run: [EM_EXEC] C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE (Logitech Inc. )
    O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
    O4 - HKLM..\Run: [ISUSPM Startup] c:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
    O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
    O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
    O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe (ScanSoft, Inc.)
    O4 - HKLM..\Run: [PCLEPCI] C:\Program Files\Pinnacle\PPE\PPE.exe (Pinnacle Systems GmbH)
    O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
    O4 - HKLM..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
    O4 - HKCU..\Run: [DW6] C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe (The Weather Channel Interactive, Inc.)
    O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BounceBack Launcher.lnk = C:\Program Files\CMS Products\BounceBack Professional\BBLauncher.exe ()
    O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Display LiteSaver Startup.lnk = C:\WINDOWS\HPLiteSaver.exe (Hewlett-Packard Development Company, L.P.)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O8 - Extra context menu item: &ieSpell Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
    O8 - Extra context menu item: &Yahoo! Search - C:\Program Files\Yahoo!\Common [2009/02/24 23:23:13 | 000,000,000 | ---D | M]
    O8 - Extra context menu item: Check &Spelling - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
    O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
    O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
    O8 - Extra context menu item: Lookup on Merriam Webster - C:\Program Files\ieSpell\Merriam Webster.HTM ()
    O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files\ieSpell\wikipedia.HTM ()
    O8 - Extra context menu item: Yahoo! &Dictionary - C:\Program Files\Yahoo!\Common [2009/02/24 23:23:13 | 000,000,000 | ---D | M]
    O8 - Extra context menu item: Yahoo! &Maps - C:\Program Files\Yahoo!\Common [2009/02/24 23:23:13 | 000,000,000 | ---D | M]
    O8 - Extra context menu item: Yahoo! &SMS - C:\Program Files\Yahoo!\Common [2009/02/24 23:23:13 | 000,000,000 | ---D | M]
    O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
    O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
    O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
    O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
    O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
    O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O15 - HKCU\..Trusted Domains: ingrammicro.com ([navpn] https in Trusted sites)
    O15 - HKCU\..Trusted Domains: ingrammicro.com ([remote] https in Trusted sites)
    O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
    O15 - HKCU\..Trusted Ranges: Range1 ([https] in Local intranet)
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite....x/qtplugin.cab (QuickTime Object)
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/res...scbase5483.cab (Windows Live Safety Center Base Module)
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/S.../bin/cabsa.cab (Symantec RuFSI Utility Class)
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.nvidia.com/content/Driver...sysreqlab2.cab (System Requirements Lab Class)
    O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} https://webdl.symantec.com/activex/symdlmgr.cab (Symantec Download Manager)
    O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/Driver...aSmartScan.cab (NVIDIA Smart Scan)
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/...Uploader55.cab (Facebook Photo Uploader 5 Control)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {A8739816-022C-11D6-A85D-00C04F9AEAFB} http://98.189.161.52/wg_webeye.cab (Web Camera Server Control)
    O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadblocker.com/activex/sabspx.cab (SABScanProcesses Class)
    O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} http://tools.ebayimg.com/eps/wl/acti..._v1-0-29-0.cab (EPUImageControl Class)
    O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeup...tent/opuc4.cab (Office Update Installation Engine)
    O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jin...ndows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_20)
    O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_21)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O16 - DPF: {FD3FF62E-61A7-48EE-A4A4-97CE7BD1F99D} https://navpn.ingrammicro.com/postauthASD/SodaAgent.CAB (SodaAgt Class)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
    O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
    O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
    O24 - Desktop WallPaper: C:\Documents and Settings\Greg\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
    O24 - Desktop BackupWallPaper: C:\Documents and Settings\Greg\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
    O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2005/08/16 03:43:04 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    NetSvcs: 6to4 - File not found
    NetSvcs: Ias - File not found
    NetSvcs: Iprip - File not found
    NetSvcs: Irmon - File not found
    NetSvcs: NWCWorkstation - File not found
    NetSvcs: Nwsapagent - File not found
    NetSvcs: WmdmPmSp - File not found


    CREATERESTOREPOINT
    Restore point Set: OTL Restore Point (58560350072602624)

    ========== Files/Folders - Created Within 30 Days ==========

    [2010/09/28 16:33:22 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Greg\Desktop\OTL.exe
    [2010/09/28 16:28:13 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
    [2010/09/28 13:15:56 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
    [2010/09/28 08:24:24 | 000,000,000 | -HSD | C] -- C:\RECYCLER
    [2010/09/28 07:43:15 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
    [2010/09/27 21:48:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Greg\Application Data\AVG9
    [2010/09/27 21:06:15 | 000,000,000 | RHSD | C] -- C:\cmdcons
    [2010/09/27 20:59:49 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
    [2010/09/27 20:59:49 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
    [2010/09/27 20:59:49 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
    [2010/09/27 20:59:49 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
    [2010/09/27 20:59:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
    [2010/09/27 20:59:35 | 000,000,000 | ---D | C] -- C:\commy
    [2010/09/27 20:59:09 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2010/09/27 07:41:09 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Greg\Recent
    [2010/09/27 07:35:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Greg\Application Data\ElevatedDiagnostics
    [2010/09/27 07:33:31 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\windowspowershell
    [2010/09/26 21:08:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Greg\Application Data\SUPERAntiSpyware.com
    [2010/09/26 21:08:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
    [2010/09/26 20:47:02 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
    [2010/09/26 20:47:02 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
    [2010/09/26 20:47:02 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
    [2010/09/26 11:02:05 | 000,012,536 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
    [2010/09/26 11:02:03 | 000,243,024 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
    [2010/09/26 11:01:58 | 000,216,400 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
    [2010/09/26 11:01:56 | 000,029,584 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
    [2010/09/26 11:01:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\Avg
    [2010/09/26 09:15:01 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2010/09/26 09:15:00 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [2010/09/26 09:13:38 | 006,153,352 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Greg\My Documents\mbam-setup-1.46.exe
    [2010/09/25 22:21:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
    [2010/09/25 22:13:15 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
    [2010/09/25 19:27:56 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
    [2010/09/25 10:38:20 | 000,000,000 | ---D | C] -- C:\Program Files\AdWare SpyWare SE
    [2010/09/24 14:31:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Greg\Application Data\GetRightToGo
    [2010/09/24 14:01:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\EWS
    [2010/09/24 13:47:47 | 000,000,000 | ---D | C] -- C:\Program Files\Easy CD & DVD Cover Creator
    [2010/09/12 14:48:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\BounceBack
    [2010/09/08 20:34:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\BounceBK02
    [2010/09/08 11:17:46 | 000,094,208 | ---- | C] (Apple Inc.) -- C:\WINDOWS\System32\QuickTimeVR.qtx
    [2010/09/08 11:17:46 | 000,069,632 | ---- | C] (Apple Inc.) -- C:\WINDOWS\System32\QuickTime.qts
    [16 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2010/09/28 16:33:22 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Greg\Desktop\OTL.exe
    [2010/09/28 16:16:30 | 000,021,504 | ---- | M] () -- C:\Documents and Settings\Greg\Desktop\Logs.doc
    [2010/09/28 16:13:04 | 000,000,065 | ---- | M] () -- C:\WINDOWS\iTouch.ini
    [2010/09/28 16:12:49 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
    [2010/09/28 16:12:23 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
    [2010/09/28 16:12:07 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
    [2010/09/28 16:12:05 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2010/09/28 16:10:57 | 006,291,456 | ---- | M] () -- C:\Documents and Settings\Greg\ntuser.dat
    [2010/09/28 16:10:57 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Greg\ntuser.ini
    [2010/09/28 13:15:58 | 000,001,678 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2010/09/28 12:51:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
    [2010/09/28 07:54:07 | 065,401,937 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
    [2010/09/27 21:30:07 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
    [2010/09/27 21:30:03 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
    [2010/09/27 21:06:20 | 000,000,325 | RHS- | M] () -- C:\boot.ini
    [2010/09/26 21:45:37 | 000,002,445 | ---- | M] () -- C:\Documents and Settings\Greg\Desktop\HiJackThis.lnk
    [2010/09/26 17:22:59 | 000,000,740 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/09/26 11:02:06 | 000,012,536 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
    [2010/09/26 11:02:05 | 000,243,024 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
    [2010/09/26 11:01:59 | 000,216,400 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
    [2010/09/26 11:01:58 | 000,029,584 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
    [2010/09/26 11:01:56 | 000,113,461 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
    [2010/09/26 09:13:38 | 006,153,352 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Greg\My Documents\mbam-setup-1.46.exe
    [2010/09/25 22:29:37 | 000,002,184 | ---- | M] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
    [2010/09/25 22:13:16 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\Greg\Desktop\CCleaner.lnk
    [2010/09/25 10:38:51 | 000,000,014 | ---- | M] () -- C:\WINDOWS\ASSE.dat
    [2010/09/25 10:38:23 | 000,000,826 | ---- | M] () -- C:\Documents and Settings\Greg\Desktop\AdWare SpyWare SE.lnk
    [2010/09/24 22:45:16 | 000,165,888 | ---- | M] () -- C:\Documents and Settings\Greg\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2010/09/24 22:45:16 | 000,000,719 | ---- | M] () -- C:\WINDOWS\win.ini
    [2010/09/24 22:45:16 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
    [2010/09/24 20:09:59 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
    [2010/09/21 14:55:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [2010/09/20 15:54:05 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Greg\default.pls
    [2010/09/20 15:42:10 | 000,083,344 | ---- | M] () -- C:\Documents and Settings\Greg\My Documents\Sea Doo.lbl
    [2010/09/17 07:54:59 | 000,001,915 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
    [2010/09/12 14:07:36 | 000,039,424 | ---- | M] () -- C:\Documents and Settings\Greg\Desktop\Updated 7-9-2010 Asset Spreadsheet.Glick.XLS
    [2010/09/08 11:17:46 | 000,094,208 | ---- | M] (Apple Inc.) -- C:\WINDOWS\System32\QuickTimeVR.qtx
    [2010/09/08 11:17:46 | 000,069,632 | ---- | M] (Apple Inc.) -- C:\WINDOWS\System32\QuickTime.qts
    [2010/09/05 17:54:00 | 000,019,968 | ---- | M] () -- C:\Documents and Settings\Greg\Desktop\Posture Excercise.doc
    [16 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2010/09/28 16:16:30 | 000,021,504 | ---- | C] () -- C:\Documents and Settings\Greg\Desktop\Logs.doc
    [2010/09/28 13:15:58 | 000,001,678 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2010/09/27 21:06:19 | 000,000,209 | ---- | C] () -- C:\Boot.bak
    [2010/09/27 21:06:17 | 000,260,272 | RHS- | C] () -- C:\cmldr
    [2010/09/27 20:59:49 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
    [2010/09/27 20:59:49 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
    [2010/09/27 20:59:49 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
    [2010/09/27 20:59:49 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
    [2010/09/27 20:59:49 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
    [2010/09/26 11:47:58 | 000,002,445 | ---- | C] () -- C:\Documents and Settings\Greg\Desktop\HiJackThis.lnk
    [2010/09/26 11:01:56 | 000,113,461 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
    [2010/09/26 11:01:50 | 065,401,937 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
    [2010/09/26 09:15:04 | 000,000,740 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
    [2010/09/25 22:28:42 | 000,002,184 | ---- | C] () -- C:\WINDOWS\System32\drivers\kgpcpy.cfg
    [2010/09/25 22:13:16 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\Greg\Desktop\CCleaner.lnk
    [2010/09/25 10:38:51 | 000,000,014 | ---- | C] () -- C:\WINDOWS\ASSE.dat
    [2010/09/25 10:38:23 | 000,000,826 | ---- | C] () -- C:\Documents and Settings\Greg\Desktop\AdWare SpyWare SE.lnk
    [2010/09/24 15:32:59 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
    [2010/09/20 15:42:10 | 000,083,344 | ---- | C] () -- C:\Documents and Settings\Greg\My Documents\Sea Doo.lbl
    [2010/09/17 07:54:59 | 000,001,915 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
    [2010/09/13 12:57:29 | 000,988,160 | ---- | C] () -- C:\Documents and Settings\Greg\Desktop\Psalm23.pps
    [2010/09/05 17:54:00 | 000,019,968 | ---- | C] () -- C:\Documents and Settings\Greg\Desktop\Posture Excercise.doc
    [2010/07/05 22:00:46 | 000,202,192 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
    [2010/05/26 19:08:30 | 000,007,680 | -HS- | C] () -- C:\Documents and Settings\Greg\Application Data\Thumbs.db
    [2010/03/31 11:56:13 | 000,008,704 | -HS- | C] () -- C:\Program Files\Thumbs.db
    [2010/03/06 14:21:35 | 000,000,004 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\DirectCDUserNameD.txt
    [2009/06/14 13:56:49 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\hcwChDB.dll
    [2009/06/14 13:56:36 | 000,006,170 | ---- | C] () -- C:\WINDOWS\HCWPNP.INI
    [2009/06/14 13:31:34 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\hcwXDS.dll.hcw
    [2008/02/18 23:33:34 | 000,446,352 | ---- | C] () -- C:\WINDOWS\System32\OpenQuicktimeLib.dll
    [2008/01/27 22:37:28 | 000,096,768 | ---- | C] () -- C:\WINDOWS\System32\LGUICOM.DLL
    [2008/01/09 00:15:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\dmcrypto.dll
    [2007/12/05 02:41:00 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
    [2007/12/05 02:41:00 | 001,474,560 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
    [2007/12/05 02:41:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
    [2007/12/05 02:41:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
    [2007/12/05 02:41:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
    [2007/10/20 20:07:20 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
    [2007/05/18 16:35:31 | 000,000,104 | ---- | C] () -- C:\WINDOWS\eficolor.ini
    [2007/05/18 16:29:48 | 000,000,517 | ---- | C] () -- C:\WINDOWS\quark.ini
    [2007/03/31 09:34:44 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
    [2007/03/22 21:29:45 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Vstudio.INI
    [2007/03/22 21:24:42 | 000,001,224 | ---- | C] () -- C:\WINDOWS\Ulead32.ini
    [2007/03/22 21:24:42 | 000,000,085 | ---- | C] () -- C:\WINDOWS\Dswplug.ini
    [2007/03/22 21:24:42 | 000,000,061 | ---- | C] () -- C:\WINDOWS\Msdevctl.ini
    [2007/02/25 13:20:23 | 000,003,072 | ---- | C] () -- C:\Documents and Settings\Greg\Application Data\dvd.bmk
    [2007/02/18 11:08:59 | 000,000,438 | ---- | C] () -- C:\Documents and Settings\Greg\Application Data\wklnhst.dat
    [2007/02/10 14:36:43 | 000,000,419 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
    [2007/02/01 20:21:02 | 000,000,017 | ---- | C] () -- C:\WINDOWS\MovingPicture.ini
    [2007/01/29 00:45:21 | 000,165,888 | ---- | C] () -- C:\Documents and Settings\Greg\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2007/01/28 11:27:31 | 000,000,251 | ---- | C] () -- C:\Program Files\wt3d.ini
    [2007/01/28 00:37:32 | 000,003,920 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
    [2007/01/28 00:37:32 | 000,000,088 | RHS- | C] () -- C:\WINDOWS\System32\ABDAE0D274.sys
    [2007/01/28 00:20:57 | 000,000,065 | ---- | C] () -- C:\WINDOWS\iTouch.ini
    [2007/01/27 15:38:31 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
    [2007/01/27 15:06:36 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Greg\Local Settings\Application Data\fusioncache.dat
    [2007/01/12 02:37:42 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
    [2007/01/12 02:31:27 | 000,000,483 | ---- | C] () -- C:\WINDOWS\ODBC.INI
    [2007/01/12 02:24:22 | 000,000,126 | ---- | C] () -- C:\WINDOWS\wininit.ini
    [2007/01/12 01:59:11 | 000,000,393 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
    [2006/07/21 14:50:34 | 000,066,048 | ---- | C] () -- C:\WINDOWS\System32\hcwXDS.dll
    [2005/08/16 03:37:24 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
    [2005/08/05 13:01:54 | 000,235,008 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
    [2004/03/18 09:44:29 | 001,663,068 | ---- | C] () -- C:\WINDOWS\System32\libmmd.dll
    [2002/12/18 11:11:14 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll
    [2002/03/21 16:39:02 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\UNACEV2.DLL
    [1995/10/21 10:37:52 | 000,035,328 | ---- | C] () -- C:\WINDOWS\INETWH32.DLL

    ========== LOP Check ==========

    [2008/09/16 21:21:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Aventail
    [2010/09/26 10:59:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
    [2007/02/10 14:27:10 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
    [2010/03/26 22:07:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Flip Video
    [2007/02/01 18:58:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle
    [2007/02/10 14:36:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
    [2007/02/01 19:07:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
    [2010/09/26 04:44:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
    [2010/09/25 20:21:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
    [2007/02/22 23:35:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
    [2007/11/22 21:06:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\YAHOO
    [2010/07/15 16:20:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
    [2007/01/29 00:38:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg\Application Data\ACD Systems
    [2010/01/15 08:59:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg\Application Data\Acoustica
    [2008/09/16 20:49:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg\Application Data\Aventail
    [2010/09/27 21:48:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg\Application Data\AVG9
    [2010/09/27 10:11:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg\Application Data\Canon
    [2007/01/27 16:27:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg\Application Data\DisplayTune
    [2010/09/27 07:35:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg\Application Data\ElevatedDiagnostics
    [2010/01/30 15:31:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg\Application Data\FileMaker
    [2010/01/31 11:49:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg\Application Data\FileMaker Pro Advanced
    [2010/09/24 14:32:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg\Application Data\GetRightToGo
    [2009/05/14 21:27:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg\Application Data\ieSpell
    [2007/02/24 00:17:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg\Application Data\Leadertech
    [2007/02/18 20:32:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg\Application Data\OfficeUpdate12
    [2007/02/10 14:36:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg\Application Data\ScanSoft
    [2009/12/26 00:12:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg\Application Data\Smilebox
    [2007/02/18 11:10:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Greg\Application Data\Template

    ========== Purity Check ==========



    ========== Custom Scans ==========


    < %SYSTEMDRIVE%\*.exe >


    < MD5 for: AGP440.SYS >
    [2004/08/10 04:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\i386\sp2.cab:AGP440.sys
    [2004/08/10 04:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
    [2008/08/31 07:42:16 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
    [2008/08/31 07:42:16 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
    [2008/04/13 11:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
    [2008/04/13 11:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
    [2008/04/13 11:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
    [2004/08/03 22:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\i386\AGP440.SYS
    [2004/08/03 22:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys

    < MD5 for: ATAPI.SYS >
    [2004/08/10 04:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\i386\sp2.cab:atapi.sys
    [2004/08/10 04:00:00 | 016,971,599 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
    [2008/08/31 07:42:16 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
    [2008/08/31 07:42:16 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
    [2008/04/13 11:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
    [2008/04/13 11:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
    [2008/04/13 11:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
    [2004/08/03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\i386\atapi.sys
    [2004/08/03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

    < MD5 for: EVENTLOG.DLL >
    [2008/04/13 17:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ERDNT\cache\eventlog.dll
    [2008/04/13 17:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
    [2008/04/13 17:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
    [2004/08/10 04:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\i386\eventlog.dll
    [2004/08/10 04:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

    < MD5 for: IASTOR.SYS >
    [2006/10/10 12:03:48 | 000,246,784 | ---- | M] (Intel Corporation) MD5=019CF5F31C67030841233C545A0E217A -- C:\drivers\storage\R130118\iastor.sys
    [2006/07/06 05:59:42 | 000,246,784 | ---- | M] (Intel Corporation) MD5=019CF5F31C67030841233C545A0E217A -- C:\i386\iaStor.sys
    [2006/07/06 05:59:42 | 000,246,784 | ---- | M] (Intel Corporation) MD5=019CF5F31C67030841233C545A0E217A -- C:\Program Files\Intel\Intel Matrix Storage Manager\Driver\iaStor.sys
    [2006/07/06 05:59:42 | 000,246,784 | ---- | M] (Intel Corporation) MD5=019CF5F31C67030841233C545A0E217A -- C:\WINDOWS\system32\drivers\iaStor.sys
    [2006/10/10 12:03:48 | 000,246,784 | ---- | M] (Intel Corporation) MD5=019CF5F31C67030841233C545A0E217A -- C:\WINDOWS\system32\ReinstallBackups\0014\DriverFiles\iaStor.sys
    [2006/07/06 06:01:32 | 000,484,864 | ---- | M] (Intel Corporation) MD5=6A3C354BFC163B81F6EF2FC421280DB5 -- C:\Program Files\Intel\Intel Matrix Storage Manager\Driver64\IaStor.sys

    < MD5 for: NETLOGON.DLL >
    [2008/04/13 17:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
    [2008/04/13 17:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
    [2008/04/13 17:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
    [2004/08/10 04:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\i386\netlogon.dll
    [2004/08/10 04:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

    < MD5 for: SCECLI.DLL >
    [2004/08/10 04:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\i386\scecli.dll
    [2004/08/10 04:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
    [2008/04/13 17:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ERDNT\cache\scecli.dll
    [2008/04/13 17:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
    [2008/04/13 17:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll

    < %systemroot%\*. /mp /s >

    < %systemroot%\system32\*.dll /lockedfiles >
    [2008/04/13 17:11:51 | 001,267,200 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\comsvcs.dll
    [2009/03/08 04:31:44 | 000,348,160 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtmsft.dll
    [2009/03/08 04:31:38 | 000,216,064 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\system32\dxtrans.dll
    [16 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

    < %systemroot%\Tasks\*.job /lockedfiles >

    < %systemroot%\system32\drivers\*.sys /lockedfiles >
    < End of report >



    OTL Extras logfile created on: 9/28/2010 4:50:40 PM - Run 1
    OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Greg\Desktop
    Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 78.00% Memory free
    4.00 Gb Paging File | 4.00 Gb Available in Paging File | 88.00% Paging File free
    Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 228.13 Gb Total Space | 17.84 Gb Free Space | 7.82% Space Free | Partition Type: NTFS
    D: Drive not present or media not loaded
    E: Drive not present or media not loaded
    F: Drive not present or media not loaded
    G: Drive not present or media not loaded
    H: Drive not present or media not loaded
    I: Drive not present or media not loaded

    Computer Name: GLICK-DEN-PC
    Current User Name: Greg
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Company Name Whitelist: Off
    Skip Microsoft Files: Off
    File Age = 30 Days
    Output = Minimal

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    exefile [open] -- "%1" %*
    htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
    htmlfile [print] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirstRunDisabled" = 1
    "UpdatesDisableNotify" = 0
    "AntiVirusOverride" = 0
    "FirewallOverride" = 0
    "AntiVirusDisableNotify" = 0
    "FirewallDisableNotify" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
    "DisableMonitoring" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
    "DisableMonitoring" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
    "Start" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
    "Start" = 2

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
    "139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
    "445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
    "137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
    "138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1
    "DoNotAllowExceptions" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
    "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
    "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
    "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
    "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
    "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
    "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL -- File not found
    "C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL -- File not found
    "C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL -- File not found

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
    "C:\Program Files\Microsoft LifeCam\LifeCam.exe" = C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe -- (Microsoft Corporation)
    "C:\Program Files\Microsoft LifeCam\LifeEnC2.exe" = C:\Program Files\Microsoft LifeCam\LifeEnC2.exe:*:Enabled:LifeEnC2.exe -- (Microsoft Corporation)
    "C:\Program Files\Microsoft LifeCam\LifeExp.exe" = C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe -- (Microsoft Corporation)
    "C:\Program Files\Microsoft LifeCam\LifeTray.exe" = C:\Program Files\Microsoft LifeCam\LifeTray.exe:*:Enabled:LifeTray.exe -- (Microsoft Corporation)
    "C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe" = C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe:*:Enabled:Nero ProductSetup -- (Nero AG)
    "C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth -- (Google)
    "C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth -- (Google)
    "C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)
    "C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.)


    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{036AA4D4-6D32-11D4-9875-00105ACE7734}" = Logitech iTouch Software
    "{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}" = Symantec KB-DocID:2003093015493306
    "{0A0873E1-D9BA-4994-B85D-A0A331EF1F0C}" = Intel(R) PRO Network Connections
    "{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
    "{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
    "{1190BD2E-97B1-475A-8510-B7ACEAF9B2C5}" = ArcSoft Photo Greeting Card
    "{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP600" = Canon MP600
    "{16E217EA-C3E0-402D-8D4F-6189DB74497A}" = Studio 9.4 Patch
    "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
    "{2227E1FA-01F5-483C-AB0E-2A308E900B3D}" = InterVideo FilterSDK for Hauppauge
    "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
    "{26A24AE4-039D-4CA4-87B4-2F83216019FF}" = Java(TM) 6 Update 21
    "{26A24AE4-039D-4CA4-87B4-2F83216020F0}" = Java(TM) 6 Update 20
    "{27113CA3-36B8-48AB-A419-79CF1FC0ECED}" = Ulead VideoStudio 5.0
    "{29D851C2-048C-4B5E-8D1F-25D473342BB5}" = ScanSoft OmniPage SE 4.0
    "{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
    "{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
    "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
    "{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
    "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
    "{36C97B5B-5593-45B8-B50E-DAD87036BD9D}" = Microsoft LifeCam
    "{3E5A81BA-4702-490A-B729-0BFF6E7CBF96}" = Pinnacle PCI Performance Enhancer
    "{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
    "{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
    "{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
    "{54D44AD1-A083-48B9-BD6F-AFD517B7C775}" = Aventail Webifiers
    "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
    "{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = Logitech MouseWare 9.71
    "{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
    "{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}" = Sonic Activation Module
    "{5C474A83-A45F-470C-9AC8-2BD1C251BF9A}" = Skype™ 4.2
    "{609F7AC8-C510-11D4-A788-009027ABA5D0}" = Easy CD Creator 5 DVD Edition
    "{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
    "{62CB2326-9C09-42D8-AED9-077E8ED11033}" = Nero 7 Ultra Edition
    "{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
    "{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}" = Digital Content Portal
    "{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
    "{72552C46-944B-4E16-BBC8-0D85F31C1800}" = Aventail Access Manager
    "{743D18E2-1B67-4AA9-9E74-B392505A3565}" = Aventail OPSWAT End Point Control
    "{76643356-611A-4A07-8BEC-79E85546916F}" = HP Display LiteSaver
    "{7B08D306-7266-4647-A926-2F78817ED1E0}" = Microsoft Corporation
    "{7EAB1D85-7BA3-47C1-BBF7-A0EBC241DB94}" = Intel® Viiv™ Software
    "{7F3D9322-E392-411F-81EB-3F844B56248B}" = Lyra Personal Audio Player (RD1021/1071/1075)
    "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
    "{84288B51-B162-47FB-A74E-25C6D67E44BB}" = HP Display Assistant
    "{85309D89-7BE9-4094-BB17-24999C6118FC}" = ArcSoft PhotoStudio 5.5
    "{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
    "{8ACE0437-ABC8-42EE-A165-D5ADD81A1BD3}" = Pixie registration fix
    "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
    "{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
    "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel(R) Matrix Storage Manager
    "{95632566-071E-4A02-92C1-4BD907065736}" = BounceBack Professional
    "{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
    "{9B0B46B3-10DF-4ADA-9501-0129D784563D}" = Aventail Web Proxy Agent
    "{9E491AB7-4589-48CA-9CBB-874CB2788391}" = Studio 9
    "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.4
    "{B0DF58A2-40DF-4465-AA56-38623EC9938C}" = Documentation & Support Launcher
    "{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
    "{B1C0D829-FE30-059E-E93F-CDC7A48235C0}" = FlipShare
    "{B3BC9DB1-0B0A-48B0-B86B-EA77CAA7F800}" = Microsoft Corporation
    "{B67624DE-75CE-4FAD-9F29-5C115773CE61}" = Studio 9 Content CD/DVD
    "{B6884A07-0305-47AE-9969-8F26FADC17DE}" = Games, Music, & Photos Launcher
    "{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
    "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
    "{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
    "{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
    "{C53BECC0-C579-44F8-A995-E97FACB04DFC}" = FileMaker Pro 11 Advanced
    "{C53BECC0-C579-44F8-A995-E97FACB04DFC}_FileMaker" = FileMaker Pro 11 Advanced
    "{C978F5A7-5E75-4DBD-BFD7-A0488E8EFF9E}" = FileMaker Pro 8.5 Advanced
    "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
    "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{CEE2252C-4035-4B27-8EC6-0B085DD3A413}" = Dell Support 3.2.1
    "{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
    "{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
    "{E759DA2E-DCB9-4B35-980C-2A990E33A212}" = FileMaker Pro 10 Advanced
    "{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
    "{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
    "{FB26A501-6BA6-459B-89AA-9736730752FB}" = VoiceOver Kit
    "12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
    "3ivx MPEG-4 5.0.3" = 3ivx MPEG-4 5.0.3 (remove only)
    "Adobe AIR" = Adobe AIR
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "AdWare SpyWare SE_is1" = AdWare SpyWare SE
    "AVG9Uninstall" = AVG Free 9.0
    "B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
    "CAL" = Canon Camera Access Library
    "CameraWindowDC" = Canon Utilities CameraWindow DC
    "CameraWindowDVC5" = Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
    "CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
    "CameraWindowLauncher" = Canon Utilities CameraWindow
    "Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
    "Canon MP600 User Registration" = Canon MP600 User Registration
    "CanonMyPrinter" = Canon My Printer
    "CCleaner" = CCleaner
    "CSCLIB" = Canon Camera Support Core Library
    "DECCHECK" = Microsoft Windows XP Video Decoder Checkup Utility
    "Dell Game Console" = Dell Game Console
    "Easy CD and DVD Cover Creator" = Easy CD and DVD Cover Creator 4.13
    "Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
    "Easy-WebPrint" = Easy-WebPrint
    "EL" = Intel(R) Quick Resume Technology Drivers
    "EmeraldQFE2" = Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
    "EOS Utility" = Canon Utilities EOS Utility
    "Hauppauge WinTV" = Hauppauge WinTV
    "Hauppauge WinTV Radio" = Hauppauge WinTV Radio
    "Hauppauge WinTV Scheduler" = Hauppauge WinTV Scheduler
    "Hauppauge WinTV TV Services" = Hauppauge WinTV TV Services
    "HijackThis" = HijackThis 2.0.2
    "Hollywood FX 5.5 Additional Effects" = Hollywood FX 5.5 Additional Effects
    "Hollywood FX for Studio" = Pinnacle Hollywood FX for Studio
    "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
    "ie7" = Windows Internet Explorer 7
    "ie8" = Windows Internet Explorer 8
    "ieSpell" = ieSpell
    "InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
    "InstallShield_{76643356-611A-4A07-8BEC-79E85546916F}" = HP Display LiteSaver
    "Logitech Resource Center" = Logitech Resource Center
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
    "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
    "MP Navigator 3.0" = Canon MP Navigator 3.0
    "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
    "MyCamera" = Canon Utilities MyCamera
    "MyCameraDC" = Canon Utilities MyCamera DC
    "nanoPEG-Editor 2.6.0 for WinTV_is1" = nanoPEG-Editor 2.6.0 for WinTV
    "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
    "NVIDIA Drivers" = NVIDIA Drivers
    "Photo Viewer" = Photo Viewer 2.4
    "PhotoStitch" = Canon Utilities PhotoStitch
    "proDAD-Heroglyph-1.0" = proDAD Heroglyph 1.0
    "RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
    "RemoteCaptureDC" = Canon Utilities RemoteCapture DC
    "RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
    "SearchAssist" = SearchAssist
    "StreetPlugin" = Learn2 Player (Uninstall Only)
    "SystemRequirementsLab" = System Requirements Lab
    "The Weather Channel Desktop 6" = The Weather Channel Desktop 6
    "WildTangent CDA" = WildTangent Web Driver
    "Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
    "Windows Media Format Runtime" = Windows Media Format 11 runtime
    "Windows Media Player" = Windows Media Player 11
    "Windows XP Service Pack" = Windows XP Service Pack 3
    "WMFDist11" = Windows Media Format 11 runtime
    "wmp11" = Windows Media Player 11
    "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
    "XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
    "Yahoo! Companion" = Yahoo! Toolbar
    "Yahoo! Customizations" = Yahoo! Browser Services
    "Yahoo! Internet Mail" = Yahoo! Internet Mail
    "Yahoo! Messenger" = Yahoo! Messenger
    "YInstHelper" = Yahoo! Install Manager
    "ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
    "ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility

    ========== HKEY_CURRENT_USER Uninstall List ==========

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{72552C46-944B-4E16-BBC8-0D85F31C1800}" = Aventail Access Manager
    "Smilebox" = Smilebox

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 9/2/2010 11:44:17 PM | Computer Name = GLICK-DEN-PC | Source = Application Error | ID = 1000
    Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
    module unknown, version 0.0.0.0, fault address 0x62905938.

    Error - 9/13/2010 2:27:43 PM | Computer Name = GLICK-DEN-PC | Source = Application Error | ID = 1000
    Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
    module unknown, version 0.0.0.0, fault address 0x2025ff90.

    Error - 9/20/2010 1:18:23 AM | Computer Name = GLICK-DEN-PC | Source = Application Error | ID = 1000
    Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
    module unknown, version 0.0.0.0, fault address 0x010c0008.

    Error - 9/20/2010 6:47:39 PM | Computer Name = GLICK-DEN-PC | Source = Application Hang | ID = 1002
    Description = Hanging application wmplayer.exe, version 11.0.5721.5145, hang module
    hungapp, version 0.0.0.0, hang address 0x00000000.

    Error - 9/20/2010 6:47:42 PM | Computer Name = GLICK-DEN-PC | Source = Application Hang | ID = 1001
    Description = Fault bucket 337816799.

    Error - 9/20/2010 6:50:39 PM | Computer Name = GLICK-DEN-PC | Source = Application Hang | ID = 1002
    Description = Hanging application wmplayer.exe, version 11.0.5721.5145, hang module
    hungapp, version 0.0.0.0, hang address 0x00000000.

    Error - 9/20/2010 6:50:41 PM | Computer Name = GLICK-DEN-PC | Source = Application Hang | ID = 1001
    Description = Fault bucket 337816799.

    Error - 9/24/2010 7:34:07 PM | Computer Name = GLICK-DEN-PC | Source = Application Error | ID = 1000
    Description = Faulting application kdz.exe, version 0.2.1.0, faulting module ntdll.dll,
    version 5.1.2600.5755, fault address 0x00010cd0.

    Error - 9/24/2010 11:30:08 PM | Computer Name = GLICK-DEN-PC | Source = Application Error | ID = 1000
    Description = Faulting application kdz.exe, version 0.2.1.0, faulting module ntdll.dll,
    version 5.1.2600.5755, fault address 0x00010cd0.

    Error - 9/26/2010 1:19:34 AM | Computer Name = GLICK-DEN-PC | Source = crypt32 | ID = 131080
    Description = Failed auto update retrieval of third-party root list sequence number
    from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
    with error: A connection with the server could not be established

    [ System Events ]
    Error - 9/28/2010 4:23:27 PM | Computer Name = GLICK-DEN-PC | Source = Service Control Manager | ID = 7001
    Description = The DHCP Client service depends on the NetBios over Tcpip service
    which failed to start because of the following error: %%31

    Error - 9/28/2010 4:23:27 PM | Computer Name = GLICK-DEN-PC | Source = Service Control Manager | ID = 7001
    Description = The DNS Client service depends on the TCP/IP Protocol Driver service
    which failed to start because of the following error: %%31

    Error - 9/28/2010 4:23:27 PM | Computer Name = GLICK-DEN-PC | Source = Service Control Manager | ID = 7001
    Description = The TCP/IP NetBIOS Helper service depends on the AFD service which
    failed to start because of the following error: %%31

    Error - 9/28/2010 4:23:27 PM | Computer Name = GLICK-DEN-PC | Source = Service Control Manager | ID = 7001
    Description = The Apple Mobile Device service depends on the TCP/IP Protocol Driver
    service which failed to start because of the following error: %%31

    Error - 9/28/2010 4:23:27 PM | Computer Name = GLICK-DEN-PC | Source = Service Control Manager | ID = 7001
    Description = The Bonjour Service service depends on the TCP/IP Protocol Driver
    service which failed to start because of the following error: %%31

    Error - 9/28/2010 4:23:27 PM | Computer Name = GLICK-DEN-PC | Source = Service Control Manager | ID = 7001
    Description = The IPSEC Services service depends on the IPSEC driver service which
    failed to start because of the following error: %%31

    Error - 9/28/2010 4:23:27 PM | Computer Name = GLICK-DEN-PC | Source = Service Control Manager | ID = 7026
    Description = The following boot-start or system-start driver(s) failed to load:
    AFD AvgLdx86 AvgMfx86 AvgTdiX cdudf_xp eeCtrl Fips intelppm IPSec Lbd MRxSmb NetBIOS NetBT RasAcd
    Rdbss
    SASDIFSV
    SASKUTIL
    Tcpip

    Error - 9/28/2010 7:10:57 PM | Computer Name = GLICK-DEN-PC | Source = DCOM | ID = 10005
    Description = DCOM got error "%1084" attempting to start the service EventSystem
    with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

    Error - 9/28/2010 7:12:23 PM | Computer Name = GLICK-DEN-PC | Source = Service Control Manager | ID = 7023
    Description = The HID Input Service service terminated with the following error:
    %%126

    Error - 9/28/2010 7:12:32 PM | Computer Name = GLICK-DEN-PC | Source = Service Control Manager | ID = 7026
    Description = The following boot-start or system-start driver(s) failed to load:
    Lbd


    < End of report >

Page 1 of 3 123 LastLast