Jump to content

zia16sun

Honorary Members
  • Posts

    83
  • Joined

  • Last visited

Posts posted by zia16sun

  1. Security Check results are as follows:

     

     Results of screen317's Security Check version 0.99.85 
     Windows 7 Service Pack 1 x64 (UAC is enabled) 
     Internet Explorer 11 
    ``````````````Antivirus/Firewall Check:``````````````
     Windows Firewall Enabled! 
    Microsoft Security Essentials  
     Antivirus up to date! 
    `````````Anti-malware/Other Utilities Check:`````````
     JavaFX 2.1.1   
     Java 7 Update 25 
     Java version out of Date!
     Adobe Flash Player 14.0.0.145 
     Adobe Reader XI 
    ````````Process Check: objlist.exe by Laurent```````` 
     Microsoft Security Essentials MSMpEng.exe
     Microsoft Security Essentials msseces.exe
     Malwarebytes Anti-Malware mbamservice.exe 
     Malwarebytes Anti-Malware mbam.exe 
     Malwarebytes Anti-Malware mbamscheduler.exe  
    `````````````````System Health check`````````````````
     Total Fragmentation on Drive C: 3%
    ````````````````````End of Log``````````````````````
     

  2. Hooray!  K9 is gone!  Thank you!

     

    I did not attempt the first option after reading the instructions and seeing "DO NOT ATTEMPT TO UNINSTALL K9 WITHOUT A PASSWORD. By design, K9 will block all internet access should one attempt to uninstall K9 without using a password. Attempts to modify K9 at the registry level will have the same effect."  That was precisely my problem, as neither of my friends knows what password was used when K9 was installed on the computer, and it, indeed, locked everything down after I tried uninstalling it using Free Revo.

     

    I did follow the Revo Pro Trial instructions instead and it worked like a charm.  I didn't know about the Free version not working nor about the follow-up driver uninstall and with those minor revisions to the uninstall process, it was a breeze. 

     

    So far, everything else seems to be running well and I do not know of any other items needing attention.  I believe it's ready for clean-up unless you deem otherwise. 

  3. Sorry. I had something come up and hadn't been able to get back to this quite yet. I hope to be back on it tonight. I'm already a Revo Uninstaller user and used that to uninstall it before starting this thread and that's what locked everything internet related down so I had to restore it. Hopefully these extra items you've added will make that uninstall work! I'll let you know.

    Thx for your patience and assistance.

  4. Overall, the system seems much better. 

     

    Much to my surprise, it blue screened again today for the first time since we started removing all of the hidden joys.  At that point I realized I misidentified the blue screen error in my thread title and tag, which should've been igdpmd64.sys. I did a little research into that BSOD code and found it was due to the KB2670838 Windows update, which I've since uninstalled and stopped from recurring as is discussed in a multitude of places, including the instruction set I followed found here.  

     

    As for the Blue Coat K9 Web Protection, yes I would like to find a way to remove this if at all possible.  Before we began this endeavor, I found that I could not use Firefox or Chrome due to them both locking up within moments of opening.  My previous attempts to uninstall K9 only locked down IE as well as it "requires" an admin password to uninstall, which my friends do not know and their typical passwords do not work.  I hoped the removal of the other problems on this system would resolve the Firefox/Chrome locking up issue but it has not and I highly suspect K9 to be the culprit.

     

    Any miracles up your sleeve?

  5. Thank you so much for alll of your help and for this excellent security information. I have applied those recomended, and have also applied one of my favorite add ons to both IE and Firefox (http://www.mywot.com/) for the system owner to hopefully prevent another bad episode. All appears to be well, all scans are clear, the system is running well and all I plan to do is run a defrag via www.auslogics.com since I prefer theirs over Microsoft's system defrag, but otherwise I am calling this system "clean". Obviously, if you have anything else, I'm open to suggestions, so feel free. Otherwise, this thread may be closed with my sincere gratitude and ongoing sincere appreciation for everything you do to help us with these bizarre issues. That help is truly invaluable.

  6. No problems running anything, the system is running very well (aside from seriously needing a defrag, of course).

    MBAM log:

    Malwarebytes Anti-Malware 1.65.1.1000

    www.malwarebytes.org

    Database version: v2012.11.17.02

    Windows XP Service Pack 3 x86 NTFS

    Internet Explorer 8.0.6001.18702

    Rose :: ROB [administrator]

    11/17/2012 8:39:01 AM

    mbam-log-2012-11-17 (08-39-01).txt

    Scan type: Quick scan

    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

    Scan options disabled: P2P

    Objects scanned: 263538

    Time elapsed: 5 minute(s), 10 second(s)

    Memory Processes Detected: 0

    (No malicious items detected)

    Memory Modules Detected: 0

    (No malicious items detected)

    Registry Keys Detected: 0

    (No malicious items detected)

    Registry Values Detected: 0

    (No malicious items detected)

    Registry Data Items Detected: 0

    (No malicious items detected)

    Folders Detected: 0

    (No malicious items detected)

    Files Detected: 0

    (No malicious items detected)

    (end)

    Hijack This Log:

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 8:47:00 AM, on 11/17/2012

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v8.00 (8.00.6001.18702)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Intel\WiFi\bin\S24EvMon.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\system32\igfxtray.exe

    C:\WINDOWS\system32\igfxsrvc.exe

    C:\WINDOWS\system32\hkcmd.exe

    C:\WINDOWS\system32\igfxpers.exe

    C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe

    C:\Program Files\Common Files\Java\Java Update\jusched.exe

    C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe

    C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe

    C:\WINDOWS\system32\agrsmsvc.exe

    C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

    C:\Program Files\Intel\WiFi\bin\EvtEng.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Common Files\Intuit\Entitlement Client\v5.3\Server\Intuit.Spc.Map.EntitlementClient.Server.Service.exe

    C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe

    C:\Program Files\Java\jre7\bin\jqs.exe

    C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe

    C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe

    C:\WINDOWS\system32\svchost.exe

    c:\Program Files\Zune\ZuneBusEnum.exe

    C:\WINDOWS\system32\SearchIndexer.exe

    C:\WINDOWS\system32\wbem\unsecapp.exe

    C:\Program Files\QuickTime\QTTask.exe

    C:\Documents and Settings\Rose\My Documents\Downloads\HijackThis.exe

    C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

    C:\WINDOWS\notepad.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mycenturylink.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.coupons.com/

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

    O2 - BHO: WindowShopper - {74F475FA-6C75-43BD-AAB9-ECDA6184F600} - C:\Program Files\Superfish\Window Shopper\SuperfishIEAddon.dll

    O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll

    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

    O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll

    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

    O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe

    O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

    O4 - HKLM\..\Run: [intelZeroConfig] "C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe"

    O4 - HKLM\..\Run: [intelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray

    O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

    O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

    O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000

    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html

    O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105

    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll

    O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll

    O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

    O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

    O9 - Extra button: Window Shopper - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - C:\Program Files\Superfish\Window Shopper\SuperfishIEAddon.dll

    O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1346102124468

    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll

    O18 - Protocol: qbpos - {662E7FAE-5C17-491C-AD9D-98C1F66CC6A0} - C:\WINDOWS\system32\QBPOSProtocol.dll

    O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)

    O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

    O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe

    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe

    O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe

    O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe

    O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

    O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe

    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: Intuit Entitlement Service v5.3 - Intuit, Inc. - C:\Program Files\Common Files\Intuit\Entitlement Client\v5.3\Server\Intuit.Spc.Map.EntitlementClient.Server.Service.exe

    O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe

    O23 - Service: LeapFrog Connect Device Service - LeapFrog Enterprises, Inc. - C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe

    O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe

    O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe

    O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe

    O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe

    O23 - Service: QBPOS Database Manager v8 (QBPOSDBServiceV8) - Intuit Inc. - C:\Program Files\Intuit\QuickBooks Point of Sale 8.0\DatabaseServer\QBPOSDBService.exe

    O23 - Service: QuickBooksDB19 - Intuit, Inc. - C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe

    O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe

    O23 - Service: Intel® PROSet/Wireless WiFi Service (S24EventMonitor) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe

    O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe

    --

    End of file - 12670 bytes

  7. As far as i can tell, everything looks good.

    The script ran without issue, and the log is pasted below for your review.

    I also spent the last couple days confirming everything is running well - updating Windows, etc., and all is running without issue.

    Updates install successfully, nothing else hangs up, it seems to be back to a normal functioning system.

    I also ran another security check to ensure I've update what showed up on the security check (aside from defragging, which I'll do when all is said and done), and as far as I can tell, we're ready to clean up and close this matter. The security check log follows the script combofix log.

    aComboFix 12-11-14.01 - Rose 11/14/2012 14:18:20.1.2 - x86

    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3033.2331 [GMT -7:00]

    Running from: c:\documents and settings\Rose\Desktop\ComboFix.exe

    AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

    .

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

    .

    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    C:\Install.exe

    c:\windows\system32\URTTemp

    c:\windows\system32\URTTemp\regtlib.exe

    .

    .

    ((((((((((((((((((((((((( Files Created from 2012-10-14 to 2012-11-14 )))))))))))))))))))))))))))))))

    .

    .a

    2012-11-14 20:42 . 2008-04-14 12:42 10752 ------w- c:\windows\system32\smtpapi.dll

    2012-11-14 20:40 . 2012-11-14 20:40 -------- d-----w- c:\windows\ServicePackFiles

    2012-11-14 20:39 . 2006-12-29 07:31 19569 ----a-w- c:\windows\000001_.tmp

    2012-11-14 18:34 . 2012-11-14 18:34 -------- d-----w- c:\documents and settings\Rose\Application Data\Windows Search

    .

    .

    .

    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2012-10-22 08:37 . 2008-04-14 12:00 1866368 ----a-w- c:\windows\system32\win32k.sys

    2012-10-11 02:13 . 2012-04-02 17:40 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe

    2012-10-11 02:13 . 2011-07-03 20:55 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

    2012-10-02 18:04 . 2008-04-14 12:00 58368 ----a-w- c:\windows\system32\synceng.dll

    2012-09-30 02:54 . 2012-10-07 21:56 22856 ----a-w- c:\windows\system32\drivers\mbam.sys

    2012-09-05 20:21 . 2012-09-05 20:21 73728 ----a-w- c:\windows\system32\javacpl.cpl

    2012-09-05 20:21 . 2012-09-05 20:21 477168 ----a-w- c:\windows\system32\npdeployJava1.dll

    2012-09-05 20:21 . 2011-06-30 02:40 473072 ----a-w- c:\windows\system32\deployJava1.dll

    2012-08-28 15:14 . 2008-04-14 12:00 916992 ----a-w- c:\windows\system32\wininet.dll

    2012-08-28 15:14 . 2008-04-14 12:00 43520 ------w- c:\windows\system32\licmgr10.dll

    2012-08-28 15:14 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl

    2012-08-28 12:07 . 2008-04-14 12:00 385024 ------w- c:\windows\system32\html.iec

    2012-08-24 13:53 . 2008-04-14 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll

    2012-08-21 13:33 . 2008-04-14 12:00 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe

    2012-08-21 12:58 . 2008-04-14 00:01 2027520 ----a-w- c:\windows\system32\ntkrnlpa.exe

    .

    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Note* empty entries & legit default entries are not shown

    REGEDIT4

    .

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A317CB83-299C-4FC8-9ED7-2D64117D98EE}]

    2011-04-20 17:29 81920 ----a-w- c:\program files\qwesttoolbar\qwesttoolbarDx.dll

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

    "{A317CB83-299C-4FC8-9ED7-2D64117D98EE}"= "c:\program files\qwesttoolbar\qwesttoolbarDx.dll" [2011-04-20 81920]

    .

    [HKEY_CLASSES_ROOT\clsid\{a317cb83-299c-4fc8-9ed7-2d64117d98ee}]

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-07-08 150040]

    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-07-08 170520]

    "Persistence"="c:\windows\system32\igfxpers.exe" [2008-07-08 141848]

    "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-01-12 2219184]

    .

    c:\documents and settings\All Users\Start Menu\Programs\Startup\

    Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat.exe [2011-6-30 295606]

    Adobe Acrobat Synchronizer.lnk - c:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-22 734872]

    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]

    QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2011-6-22 984936]

    .

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

    "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

    @="Driver"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

    @="Service"

    .

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]

    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk

    backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]

    2006-10-23 05:24 620152 ----a-w- c:\program files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]

    2012-07-27 20:51 919008 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]

    2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]

    2012-08-05 02:05 116648 ----atw- c:\documents and settings\Rose\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]

    2011-05-10 08:41 49208 ----a-w- c:\program files\HP\HP Software Update\hpwuschd2.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]

    2008-05-01 01:11 1191936 ----a-w- c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]

    2008-05-01 01:27 1347584 ----a-w- c:\program files\Intel\WiFi\bin\ZCfgSvc.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Intuit SyncManager]

    2011-06-15 05:32 1532760 ----a-w- c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Monitor]

    2011-11-12 19:04 268640 ----a-w- c:\program files\LeapFrog\LeapFrog Connect\Monitor.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

    2008-04-14 11:42 1695232 ------w- c:\program files\Messenger\msmsgs.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MusicManager]

    2012-10-22 22:52 7356928 ----a-w- c:\documents and settings\Rose\Local Settings\Application Data\Programs\Google\MusicManager\MusicManager.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

    2012-07-24 15:48 282624 ----a-w- c:\program files\QuickTime\qttask.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]

    2008-05-28 06:52 16862720 ------r- c:\windows\RTHDCPL.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

    2012-01-18 20:02 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]

    2012-06-01 20:27 296056 ----a-w- c:\program files\Real\RealPlayer\Update\realsched.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WLSS]

    2008-05-09 21:05 951592 ----a-w- c:\program files\Program DJ\Wireless Switch\wlss.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]

    2011-08-05 18:29 159456 ----a-w- c:\program files\Zune\ZuneLauncher.exe

    .

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

    "EnableFirewall"= 0 (0x0)

    .

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

    "c:\\WINDOWS\\system32\\sessmgr.exe"=

    "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=

    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=

    "%windir%\\system32\\sessmgr.exe"=

    .

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

    "5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management

    .

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]

    "AllowInboundEchoRequest"= 1 (0x1)

    "AllowOutboundParameterProblem"= 1 (0x1)

    .

    R0 EMSC;COMPAL Embedded System Control;c:\windows\system32\drivers\EMSC.sys [6/28/2011 10:30 PM 9856]

    R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [12/21/2010 2:04 PM 115008]

    R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [12/21/2010 12:47 PM 94872]

    R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [1/12/2011 3:41 PM 810144]

    R2 Intuit Entitlement Service v5.3;Intuit Entitlement Service v5.3;c:\program files\Common Files\Intuit\Entitlement Client\v5.3\Server\Intuit.Spc.Map.EntitlementClient.Server.Service.exe [7/29/2008 10:26 AM 20480]

    R2 QBPOSDBServiceV8;QBPOS Database Manager v8;c:\program files\Intuit\QuickBooks Point of Sale 8.0\DatabaseServer\QBPOSDBService.exe [8/12/2011 11:07 AM 2734480]

    R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [6/28/2011 5:10 PM 108032]

    R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [6/28/2011 2:45 PM 81296]

    S2 AdobeActiveFileMonitor;Adobe Active File Monitor;c:\program files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe [10/4/2004 3:47 AM 98304]

    S2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;c:\program files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe [10/4/2004 2:40 AM 118784]

    S3 FlyUsb;FLY Fusion;c:\windows\system32\drivers\FlyUsb.sys [2/26/2008 6:33 PM 18560]

    S3 QuickBooksDB19;QuickBooksDB19;c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB19 --> c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB19 [?]

    .

    --- Other Services/Drivers In Memory ---

    .

    *NewlyCreated* - WS2IFSL

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

    HPService REG_MULTI_SZ HPSLPSVC

    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

    .

    Contents of the 'Scheduled Tasks' folder

    .

    2012-11-14 c:\windows\Tasks\Adobe Flash Player Updater.job

    - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 02:13]

    .

    2012-11-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-746137067-2147097355-1003Core.job

    - c:\documents and settings\Rose\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-08-05 02:05]

    .

    2012-11-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-746137067-2147097355-1003UA.job

    - c:\documents and settings\Rose\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-08-05 02:05]

    .

    2012-11-14 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1417001333-746137067-2147097355-1003.job

    - c:\program files\Real\RealUpgrade\realupgrade.exe [2012-05-01 00:21]

    .

    2012-09-30 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1417001333-746137067-2147097355-1003.job

    - c:\program files\Real\RealUpgrade\realupgrade.exe [2012-05-01 00:21]

    .

    2012-11-14 c:\windows\Tasks\User_Feed_Synchronization-{0531BD22-A233-4370-8C7C-BA6C2D0CCA97}.job

    - c:\windows\system32\msfeedssync.exe [2009-03-08 10:31]

    .

    .

    ------- Supplementary Scan -------

    .

    uStart Page = hxxp://www.mycenturylink.com/

    mStart Page = hxxp://search.coupons.com/

    uInternet Settings,ProxyOverride = *.local

    uSearchAssistant = hxxp://www.google.com/ie

    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

    IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

    IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

    IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000

    IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html

    IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105

    IE: {{A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - c:\program files\Superfish\Window Shopper\SuperfishIEAddon.dll

    .

    .

    ------- File Associations -------

    .

    .txt=

    .

    - - - - ORPHANS REMOVED - - - -

    .

    Toolbar-{8660E5B3-6C41-44DE-8503-98D99BBECD41} - c:\program files\Coupons.com CouponBar\tbcore3.dll

    WebBrowser-{8660E5B3-6C41-44DE-8503-98D99BBECD41} - c:\program files\Coupons.com CouponBar\tbcore3.dll

    SafeBoot-WudfPf

    SafeBoot-WudfRd

    .

    .

    .

    **************************************************************************

    .

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

    Rootkit scan 2012-11-14 14:27

    Windows 5.1.2600 Service Pack 3 NTFS

    .

    scanning hidden processes ...

    .

    scanning hidden autostart entries ...

    .

    scanning hidden files ...

    .

    scan completed successfully

    hidden files: 0

    .

    **************************************************************************

    .

    --------------------- LOCKED REGISTRY KEYS ---------------------

    .

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

    @Denied: (A 2) (Everyone)

    @="FlashBroker"

    "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

    "Enabled"=dword:00000001

    .

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

    @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

    @Denied: (A 2) (Everyone)

    @="IFlashBroker5"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

    @="{00020424-0000-0000-C000-000000000046}"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    "Version"="1.0"

    .

    --------------------- DLLs Loaded Under Running Processes ---------------------

    .

    - - - - - - - > 'winlogon.exe'(732)

    c:\windows\system32\netprovcredman.dll

    c:\windows\system32\igfxdev.dll

    .

    - - - - - - - > 'lsass.exe'(788)

    c:\windows\system32\netprovcredman.dll

    .

    Completion time: 2012-11-14 14:30:20

    ComboFix-quarantined-files.txt 2012-11-14 21:30

    .

    Pre-Run: 186,398,609,408 bytes free

    Post-Run: 188,991,463,424 bytes free

    .

    - - End Of File - - 40BDECBB369D8C1E6CA28B9642522D1E

    Security Check log:

    Results of screen317's Security Check version 0.99.54

    Windows XP Service Pack 3 x86

    Internet Explorer 8

    ``````````````Antivirus/Firewall Check:``````````````

    Windows Firewall Enabled!

    ESET NOD32 Antivirus 4.2

    Antivirus up to date!

    `````````Anti-malware/Other Utilities Check:`````````

    Malwarebytes Anti-Malware version 1.65.1.1000

    Java 7 Update 9

    Adobe Flash Player 11.4.402.287

    Adobe Reader X (10.1.4)

    Mozilla Thunderbird (16.0.2)

    ````````Process Check: objlist.exe by Laurent````````

    ESET NOD32 Antivirus egui.exe

    ESET NOD32 Antivirus ekrn.exe

    `````````````````System Health check`````````````````

    Total Fragmentation on Drive C:: 14% Defragment your hard drive soon! (Do NOT defrag if SSD!)

    ````````````````````End of Log``````````````````````

  8. The first time I tried running Combofix, I it started running, but then the .exe moved on the desktop (snapped to the grid or something) and I received an error stating that i wasn't allowed to rename the file to (2) or something like that. I rebooted and ran it again. This time I got further, but I got an error stating that the system doesn't have Recovery Console, so major issues couldn't be fixed. I hit No (thinking it would cancel), and it ran anyway. I didn't stop it.

    For the record, the system has had no running issues, just had the hidden files issue and apparently other fun things like security files being deleted (like the Recovery Console, etc.). It does still seem to process quickly, etc., just have to get the rest of these lurkers out of there and restore security systems, I think.

    I did get a log after that inadvertent combofix run, and it reads as follows:

    ComboFix 12-11-14.01 - Rose 11/14/2012 14:18:20.1.2 - x86

    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3033.2331 [GMT -7:00]

    Running from: c:\documents and settings\Rose\Desktop\ComboFix.exe

    AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

    .

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

    .

    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    C:\Install.exe

    c:\windows\system32\URTTemp

    c:\windows\system32\URTTemp\regtlib.exe

    .

    .

    ((((((((((((((((((((((((( Files Created from 2012-10-14 to 2012-11-14 )))))))))))))))))))))))))))))))

    .

    .

    2012-11-14 20:42 . 2008-04-14 12:42 10752 ------w- c:\windows\system32\smtpapi.dll

    2012-11-14 20:40 . 2012-11-14 20:40 -------- d-----w- c:\windows\ServicePackFiles

    2012-11-14 20:39 . 2006-12-29 07:31 19569 ----a-w- c:\windows\000001_.tmp

    2012-11-14 18:34 . 2012-11-14 18:34 -------- d-----w- c:\documents and settings\Rose\Application Data\Windows Search

    .

    .

    .

    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2012-10-22 08:37 . 2008-04-14 12:00 1866368 ----a-w- c:\windows\system32\win32k.sys

    2012-10-11 02:13 . 2012-04-02 17:40 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe

    2012-10-11 02:13 . 2011-07-03 20:55 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

    2012-10-02 18:04 . 2008-04-14 12:00 58368 ----a-w- c:\windows\system32\synceng.dll

    2012-09-30 02:54 . 2012-10-07 21:56 22856 ----a-w- c:\windows\system32\drivers\mbam.sys

    2012-09-05 20:21 . 2012-09-05 20:21 73728 ----a-w- c:\windows\system32\javacpl.cpl

    2012-09-05 20:21 . 2012-09-05 20:21 477168 ----a-w- c:\windows\system32\npdeployJava1.dll

    2012-09-05 20:21 . 2011-06-30 02:40 473072 ----a-w- c:\windows\system32\deployJava1.dll

    2012-08-28 15:14 . 2008-04-14 12:00 916992 ----a-w- c:\windows\system32\wininet.dll

    2012-08-28 15:14 . 2008-04-14 12:00 43520 ------w- c:\windows\system32\licmgr10.dll

    2012-08-28 15:14 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl

    2012-08-28 12:07 . 2008-04-14 12:00 385024 ------w- c:\windows\system32\html.iec

    2012-08-24 13:53 . 2008-04-14 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll

    2012-08-21 13:33 . 2008-04-14 12:00 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe

    2012-08-21 12:58 . 2008-04-14 00:01 2027520 ----a-w- c:\windows\system32\ntkrnlpa.exe

    .

    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Note* empty entries & legit default entries are not shown

    REGEDIT4

    .

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A317CB83-299C-4FC8-9ED7-2D64117D98EE}]

    2011-04-20 17:29 81920 ----a-w- c:\program files\qwesttoolbar\qwesttoolbarDx.dll

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

    "{A317CB83-299C-4FC8-9ED7-2D64117D98EE}"= "c:\program files\qwesttoolbar\qwesttoolbarDx.dll" [2011-04-20 81920]

    .

    [HKEY_CLASSES_ROOT\clsid\{a317cb83-299c-4fc8-9ed7-2d64117d98ee}]

    .

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-07-08 150040]

    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-07-08 170520]

    "Persistence"="c:\windows\system32\igfxpers.exe" [2008-07-08 141848]

    "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-01-12 2219184]

    .

    c:\documents and settings\All Users\Start Menu\Programs\Startup\

    Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat.exe [2011-6-30 295606]

    Adobe Acrobat Synchronizer.lnk - c:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-22 734872]

    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]

    QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2011-6-22 984936]

    .

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

    "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

    @="Driver"

    .

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

    @="Service"

    .

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]

    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk

    backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]

    2006-10-23 05:24 620152 ----a-w- c:\program files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]

    2012-07-27 20:51 919008 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]

    2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]

    2012-08-05 02:05 116648 ----atw- c:\documents and settings\Rose\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]

    2011-05-10 08:41 49208 ----a-w- c:\program files\HP\HP Software Update\hpwuschd2.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]

    2008-05-01 01:11 1191936 ----a-w- c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]

    2008-05-01 01:27 1347584 ----a-w- c:\program files\Intel\WiFi\bin\ZCfgSvc.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Intuit SyncManager]

    2011-06-15 05:32 1532760 ----a-w- c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Monitor]

    2011-11-12 19:04 268640 ----a-w- c:\program files\LeapFrog\LeapFrog Connect\Monitor.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

    2008-04-14 11:42 1695232 ------w- c:\program files\Messenger\msmsgs.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MusicManager]

    2012-10-22 22:52 7356928 ----a-w- c:\documents and settings\Rose\Local Settings\Application Data\Programs\Google\MusicManager\MusicManager.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

    2012-07-24 15:48 282624 ----a-w- c:\program files\QuickTime\qttask.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]

    2008-05-28 06:52 16862720 ------r- c:\windows\RTHDCPL.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

    2012-01-18 20:02 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]

    2012-06-01 20:27 296056 ----a-w- c:\program files\Real\RealPlayer\Update\realsched.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WLSS]

    2008-05-09 21:05 951592 ----a-w- c:\program files\Program DJ\Wireless Switch\wlss.exe

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]

    2011-08-05 18:29 159456 ----a-w- c:\program files\Zune\ZuneLauncher.exe

    .

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

    "EnableFirewall"= 0 (0x0)

    .

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

    "c:\\WINDOWS\\system32\\sessmgr.exe"=

    "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=

    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=

    "%windir%\\system32\\sessmgr.exe"=

    .

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

    "5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management

    .

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]

    "AllowInboundEchoRequest"= 1 (0x1)

    "AllowOutboundParameterProblem"= 1 (0x1)

    .

    R0 EMSC;COMPAL Embedded System Control;c:\windows\system32\drivers\EMSC.sys [6/28/2011 10:30 PM 9856]

    R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [12/21/2010 2:04 PM 115008]

    R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [12/21/2010 12:47 PM 94872]

    R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [1/12/2011 3:41 PM 810144]

    R2 Intuit Entitlement Service v5.3;Intuit Entitlement Service v5.3;c:\program files\Common Files\Intuit\Entitlement Client\v5.3\Server\Intuit.Spc.Map.EntitlementClient.Server.Service.exe [7/29/2008 10:26 AM 20480]

    R2 QBPOSDBServiceV8;QBPOS Database Manager v8;c:\program files\Intuit\QuickBooks Point of Sale 8.0\DatabaseServer\QBPOSDBService.exe [8/12/2011 11:07 AM 2734480]

    R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [6/28/2011 5:10 PM 108032]

    R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [6/28/2011 2:45 PM 81296]

    S2 AdobeActiveFileMonitor;Adobe Active File Monitor;c:\program files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe [10/4/2004 3:47 AM 98304]

    S2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;c:\program files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe [10/4/2004 2:40 AM 118784]

    S3 FlyUsb;FLY Fusion;c:\windows\system32\drivers\FlyUsb.sys [2/26/2008 6:33 PM 18560]

    S3 QuickBooksDB19;QuickBooksDB19;c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB19 --> c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB19 [?]

    .

    --- Other Services/Drivers In Memory ---

    .

    *NewlyCreated* - WS2IFSL

    .

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

    HPService REG_MULTI_SZ HPSLPSVC

    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

    .

    Contents of the 'Scheduled Tasks' folder

    .

    2012-11-14 c:\windows\Tasks\Adobe Flash Player Updater.job

    - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 02:13]

    .

    2012-11-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-746137067-2147097355-1003Core.job

    - c:\documents and settings\Rose\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-08-05 02:05]

    .

    2012-11-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-746137067-2147097355-1003UA.job

    - c:\documents and settings\Rose\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-08-05 02:05]

    .

    2012-11-14 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1417001333-746137067-2147097355-1003.job

    - c:\program files\Real\RealUpgrade\realupgrade.exe [2012-05-01 00:21]

    .

    2012-09-30 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1417001333-746137067-2147097355-1003.job

    - c:\program files\Real\RealUpgrade\realupgrade.exe [2012-05-01 00:21]

    .

    2012-11-14 c:\windows\Tasks\User_Feed_Synchronization-{0531BD22-A233-4370-8C7C-BA6C2D0CCA97}.job

    - c:\windows\system32\msfeedssync.exe [2009-03-08 10:31]

    .

    .

    ------- Supplementary Scan -------

    .

    uStart Page = hxxp://www.mycenturylink.com/

    mStart Page = hxxp://search.coupons.com/

    uInternet Settings,ProxyOverride = *.local

    uSearchAssistant = hxxp://www.google.com/ie

    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

    IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

    IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

    IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000

    IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html

    IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105

    IE: {{A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - c:\program files\Superfish\Window Shopper\SuperfishIEAddon.dll

    .

    .

    ------- File Associations -------

    .

    .txt=

    .

    - - - - ORPHANS REMOVED - - - -

    .

    Toolbar-{8660E5B3-6C41-44DE-8503-98D99BBECD41} - c:\program files\Coupons.com CouponBar\tbcore3.dll

    WebBrowser-{8660E5B3-6C41-44DE-8503-98D99BBECD41} - c:\program files\Coupons.com CouponBar\tbcore3.dll

    SafeBoot-WudfPf

    SafeBoot-WudfRd

    .

    .

    .

    **************************************************************************

    .

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

    Rootkit scan 2012-11-14 14:27

    Windows 5.1.2600 Service Pack 3 NTFS

    .

    scanning hidden processes ...

    .

    scanning hidden autostart entries ...

    .

    scanning hidden files ...

    .

    scan completed successfully

    hidden files: 0

    .

    **************************************************************************

    .

    --------------------- LOCKED REGISTRY KEYS ---------------------

    .

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

    @Denied: (A 2) (Everyone)

    @="FlashBroker"

    "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

    "Enabled"=dword:00000001

    .

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

    @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

    @Denied: (A 2) (Everyone)

    @="IFlashBroker5"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

    @="{00020424-0000-0000-C000-000000000046}"

    .

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    "Version"="1.0"

    .

    --------------------- DLLs Loaded Under Running Processes ---------------------

    .

    - - - - - - - > 'winlogon.exe'(732)

    c:\windows\system32\netprovcredman.dll

    c:\windows\system32\igfxdev.dll

    .

    - - - - - - - > 'lsass.exe'(788)

    c:\windows\system32\netprovcredman.dll

    .

    Completion time: 2012-11-14 14:30:20

    ComboFix-quarantined-files.txt 2012-11-14 21:30

    .

    Pre-Run: 186,398,609,408 bytes free

    Post-Run: 188,991,463,424 bytes free

    .

    - - End Of File - - 40BDECBB369D8C1E6CA28B9642522D1E

  9. Good morning, Gringo. Thanks for taking this on. I look forward to working with you again.

    First of all, the unhide file brought everything back up, and for that, I'm eternally grateful! I wonder how much of that could've been done (via DOS most likely) while they were at the ranch and ultimately could've saved them so much time and money. Alas.

    Moving forward.

    Security check log:

    Results of screen317's Security Check version 0.99.54

    Windows XP Service Pack 3 x86

    Internet Explorer 8

    ``````````````Antivirus/Firewall Check:``````````````

    Windows Firewall Enabled!

    ESET NOD32 Antivirus 4.2

    Antivirus up to date!

    `````````Anti-malware/Other Utilities Check:`````````

    Malwarebytes Anti-Malware version 1.65.1.1000

    Java 6 Update 35

    Java version out of Date!

    Adobe Flash Player 11.4.402.287

    Adobe Reader X (10.1.4)

    Mozilla Thunderbird 12.0.1 Thunderbird out of Date!

    ````````Process Check: objlist.exe by Laurent````````

    ESET NOD32 Antivirus egui.exe

    ESET NOD32 Antivirus ekrn.exe

    `````````````````System Health check`````````````````

    Total Fragmentation on Drive C:: 15% Defragment your hard drive soon! (Do NOT defrag if SSD!)

    ````````````````````End of Log``````````````````````

    AdwCleaner Log:

    # AdwCleaner v2.007 - Logfile created 11/14/2012 at 08:53:11

    # Updated 06/11/2012 by Xplode

    # Operating system : Microsoft Windows XP Service Pack 3 (32 bits)

    # User : Rose - ROB

    # Boot Mode : Normal

    # Running from : E:\adwcleaner.exe

    # Option [Delete]

    ***** [services] *****

    ***** [Files / Folders] *****

    Folder Deleted : C:\Documents and Settings\All Users\Application Data\Ask

    Folder Deleted : C:\Documents and Settings\All Users\Application Data\Babylon

    Folder Deleted : C:\Documents and Settings\Rose\Application Data\Babylon

    Folder Deleted : C:\Documents and Settings\Rose\Application Data\Toolbar4

    ***** [Registry] *****

    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{96BD48DD-741B-41AE-AC4A-AFF96BA00F7E}

    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}

    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}

    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5911488E-9D1E-40EC-8CBB-06B231CC153F}

    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64182481-4F71-486B-A045-B233BD0DA8FC}

    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E13D095-45C3-4271-9475-F3B48227DD9F}

    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}

    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}

    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}

    Key Deleted : HKCU\Software\TBSB07898

    Key Deleted : HKCU\Software\Zugo

    Key Deleted : HKLM\Software\Babylon

    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}

    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}

    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}

    Key Deleted : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL

    Key Deleted : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE

    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1C950DE5-D31E-42FB-AFB9-91B0161633D8}

    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F}

    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{57CADC46-58FF-4105-B733-5A9F3FC9783C}

    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9F34B17E-FF0D-4FAB-97C4-9713FEE79052}

    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A9A56B8E-2DEB-4ED3-BC92-1FA450BCE1A5}

    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE338F6D-5A7C-4D1D-86E3-C618532079B5}

    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C339D489-FABC-41DD-B39D-276101667C70}

    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}

    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D433A9D0-8267-40CB-8AD5-24F22FA5373F}

    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D565B35E-B787-40FA-95E3-E3562F8FC1A0}

    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D89031C2-10DA-4C90-9A62-FCED012BC46B}

    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}

    Key Deleted : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler

    Key Deleted : HKLM\SOFTWARE\Classes\ComObject.DeskbarEnabler.1

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0FA32667-9A8A-4E9C-902F-CA3323180003}

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778}

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3D8478AA-7B88-48A9-8BCB-B85D594411EC}

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4D8ED2B3-DC62-43EC-ABA3-5B74F046B1BE}

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6B458F62-592F-4B25-8967-E6A350A59328}

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{95B6A271-FEB4-4160-B0FF-44394C21C8DC}

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E67D5BC7-7129-493E-9281-F47BDAFACE4F}

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}

    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FCC9CDD3-EFFF-11D1-A9F0-00A0244AC403}

    Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap

    Key Deleted : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils

    Key Deleted : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils.1

    Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager

    Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager.1

    Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager

    Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager.1

    Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbRequest

    Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbRequest.1

    Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbTask

    Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbTask.1

    Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper

    Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper.1

    Key Deleted : HKLM\SOFTWARE\Classes\TBSB07898.IEToolbar

    Key Deleted : HKLM\SOFTWARE\Classes\TBSB07898.IEToolbar.1

    Key Deleted : HKLM\SOFTWARE\Classes\TBSB07898.TBSB07898

    Key Deleted : HKLM\SOFTWARE\Classes\TBSB07898.TBSB07898.3

    Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier

    Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.ContextMenuNotifier.1

    Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl

    Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.CustomInternetSecurityImpl.1

    Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager

    Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.SearchProviderManager.1

    Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.TBSB07898

    Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.TBSB07898.1

    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4509D3CC-B642-4745-B030-645B79522C6D}

    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148}

    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}

    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{EC4085F2-8DB3-45A6-AD0B-CA289F3C5D7E}

    Key Deleted : HKLM\SOFTWARE\Classes\URLSearchHook.ToolbarURLSearchHook

    Key Deleted : HKLM\SOFTWARE\Classes\URLSearchHook.ToolbarURLSearchHook.1

    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}

    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}

    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]

    ***** [internet Browsers] *****

    -\\ Internet Explorer v8.0.6001.18702

    [OK] Registry is clean.

    -\\ Google Chrome v [unable to get version]

    File : C:\Documents and Settings\Rose\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

    [OK] File is clean.

    *************************

    AdwCleaner[R1].txt - [7703 octets] - [14/11/2012 08:51:56]

    AdwCleaner[s1].txt - [7658 octets] - [14/11/2012 08:53:11]

    ########## EOF - C:\AdwCleaner[s1].txt - [7718 octets] ##########

    RK Log:

    RogueKiller V8.2.3 [11/07/2012] by Tigzy

    mail: tigzyRK<at>gmail<dot>com

    Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/

    Website: http://tigzy.geekstogo.com/roguekiller.php

    Blog: http://tigzyrk.blogspot.com

    Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version

    Started in : Normal mode

    User : Rose [Admin rights]

    Mode : Remove -- Date : 11/14/2012 09:01:38

    ¤¤¤ Bad processes : 0 ¤¤¤

    ¤¤¤ Registry Entries : 7 ¤¤¤

    [RUN][sUSP PATH] HKCU\[...]\Run : MusicManager ("C:\Documents and Settings\Rose\Local Settings\Application Data\Programs\Google\MusicManager\MusicManager.exe") -> DELETED

    [HJPOL] HKLM\[...]\System : DisableTaskMgr (0) -> DELETED

    [HJ SMENU] HKCU\[...]\Advanced : Start_ShowUser (0) -> REPLACED (1)

    [HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> REPLACED (1)

    [HJ DESK] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

    [HJ DESK] HKCU\[...]\ClassicStartMenu : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> REPLACED (0)

    [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver : [LOADED] ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤

    --> C:\WINDOWS\system32\drivers\etc\hosts

    127.0.0.1 localhost

    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: WDC WD2500BEVS-00UST0 +++++

    --- User ---

    [MBR] d9ab72da5714c9c2d66aa6e71f9e55ea

    [bSP] dd3eee80606e623fdbc58b6b5fa71859 : Windows XP MBR Code

    Partition table:

    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 238464 Mo

    User = LL1 ... OK!

    User = LL2 ... OK!

    Finished : << RKreport[2]_D_11142012_02d0901.txt >>

    RKreport[1]_S_11142012_02d0900.txt ; RKreport[2]_D_11142012_02d0901.txt

  10. Greetings, experts.

    I'll apologize in advance for the lack of information that I can provide about this issue. I was brought a laptop post partial repair to see if I could bring it the rest of the way back. This system obtained a trojan that when it reared it's ugly head, literally hid every single thing on this system (all icons, shortcut keys for start menu, etc. did nothing, no my computer, no run command, nada. The system owner was out of town usinmg the wide open wifi at the ranch they were staying at, and reports that she was not surfing or doing anything out of the ordinary when everything went away. Since they were running a store and making sales up at the ranch for an event, they desperately needed their POS system back, and there were no family nerds (i.e. myself, etc) around to help, so they called a local tech for assistance (who charged for mileage and also charged by the half hour for services). After 4 hours, he was able to bring the system partially back up to its current status (yes, he may have ripped these nice ladies off - but there'sno way to know without being there), and his charges were out pricing the value of the system in its entirety, so they limped through the rest of the event, and here we are.

    Malwarebytes scans are clear mbam-log-2012-11-13 (20-23-25).txt, but the Eset Anti-Virus just found the (and allegedly removed) Exploit.Agent.Al.Gen trojan, which was not found on prior scans, so perhaps this is the evil culprit that has been hiding all this time?

    From the relayed report of what this local tech found, this trojan literally hides all system files, and he told them to buy a disc from ESET that will bring back the rest of the hidden files. All start menu folders are empty, etc., but this stuff is reportedly still here somewhere, so if anyone has any theories on how we can 'unhide' things, we'd be very grateful. We really don't want to reinstall the OS and really overwrite things if we can help it.

    DDS log:

    DDS (Ver_2012-11-07.01) - NTFS_x86

    Internet Explorer: 8.0.6001.18702

    Run by Rose at 20:47:04 on 2012-11-13

    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3033.2138 [GMT -7:00]

    .

    AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

    .

    ============== Running Processes ================

    .

    C:\Program Files\Intel\WiFi\bin\S24EvMon.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\system32\igfxtray.exe

    C:\WINDOWS\system32\hkcmd.exe

    C:\WINDOWS\system32\igfxpers.exe

    C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe

    C:\WINDOWS\system32\igfxsrvc.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe

    C:\WINDOWS\system32\agrsmsvc.exe

    C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

    C:\Program Files\Intel\WiFi\bin\EvtEng.exe

    C:\Program Files\Common Files\Intuit\Entitlement Client\v5.3\Server\Intuit.Spc.Map.EntitlementClient.Server.Service.exe

    C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe

    C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe

    C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe

    C:\Program Files\Intuit\QuickBooks Point of Sale 8.0\DatabaseServer\QBPOSDBService.exe

    C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe

    c:\Program Files\Zune\ZuneBusEnum.exe

    C:\Program Files\Intuit\QuickBooks Point of Sale 8.0\DatabaseServer\QBDBMgrN10.exe

    C:\WINDOWS\system32\SearchIndexer.exe

    C:\WINDOWS\system32\wbem\wmiprvse.exe

    C:\WINDOWS\System32\alg.exe

    C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe

    C:\WINDOWS\notepad.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\WINDOWS\system32\wscntfy.exe

    C:\WINDOWS\system32\rundll32.exe

    C:\WINDOWS\system32\wbem\wmiprvse.exe

    C:\WINDOWS\System32\svchost.exe -k netsvcs

    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup

    C:\WINDOWS\system32\svchost.exe -k NetworkService

    C:\WINDOWS\system32\svchost.exe -k LocalService

    C:\WINDOWS\system32\svchost.exe -k LocalService

    C:\WINDOWS\system32\svchost.exe -k hpdevmgmt

    C:\WINDOWS\system32\svchost.exe -k HPService

    C:\WINDOWS\system32\svchost.exe -k imgsvc

    C:\WINDOWS\System32\svchost.exe -k HTTPFilter

    .

    ============== Pseudo HJT Report ===============

    .

    uStart Page = hxxp://www.mycenturylink.com/

    uSearch Bar = hxxp://www.google.com/ie

    uSearch Page = hxxp://www.google.com

    mStart Page = hxxp://search.coupons.com/

    uSearchAssistant = hxxp://www.google.com/ie

    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

    mSearchAssistant = hxxp://www.google.com/ie

    uURLSearchHooks: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll

    BHO: &Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll

    BHO: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll

    BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

    BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll

    BHO: Window Shopper: {74F475FA-6C75-43BD-AAB9-ECDA6184F600} - c:\program files\superfish\window shopper\SuperfishIEAddon.dll

    BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre6\bin\ssv.dll

    BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll

    BHO: CenturyLink: {A317CB83-299C-4FC8-9ED7-2D64117D98EE} - c:\program files\qwesttoolbar\qwesttoolbarDx.dll

    BHO: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll

    BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL

    BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll

    BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    BHO: TBSB07898 Class: {FCBCCB87-9224-4B8D-B117-F56D924BEB18} -

    BHO: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll

    BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll

    TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll

    TB: Coupons.com CouponBar: {8660E5B3-6C41-44DE-8503-98D99BBECD41} -

    TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll

    TB: CenturyLink: {A317CB83-299C-4FC8-9ED7-2D64117D98EE} - c:\program files\qwesttoolbar\qwesttoolbarDx.dll

    TB: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll

    TB: Coupons.com CouponBar: {8660E5B3-6C41-44DE-8503-98D99BBECD41} -

    EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll

    EB: Adobe PDF: {182EC0BE-5110-49C8-A062-BEB1D02A220B} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll

    EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll

    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

    uRun: [MusicManager] "c:\documents and settings\rose\local settings\application data\programs\google\musicmanager\MusicManager.exe"

    mRun: [igfxTray] c:\windows\system32\igfxtray.exe

    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe

    mRun: [Persistence] c:\windows\system32\igfxpers.exe

    mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice

    mRunOnce: [Malwarebytes Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent

    uPolicies-Explorer: NoDriveTypeAutoRun = dword:145

    mPolicies-Explorer: NoDriveTypeAutoRun = dword:145

    IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html

    IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

    IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

    IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html

    IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html

    IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html

    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000

    IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html

    IE: Se&nd to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105

    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll

    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll

    IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll

    IE: {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - {A69A551A-1AAE-4B67-8C2E-52F8B8A19504} - c:\program files\superfish\window shopper\SuperfishIEAddon.dll

    IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll

    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1346102124468

    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab

    DPF: {B479199A-1242-4E3C-AD81-7F0DF801B4AE} - hxxp://download.microsoft.com/download/C/9/C/C9C3D86D-84AC-4AF0-8584-842756A66467/MicrosoftDownloadManager.cab

    DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab

    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab

    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    TCP: NameServer = 192.168.1.1

    TCP: Interfaces\{F0FC53D5-E1F7-45CA-A7D1-4071402A0FC9} : DHCPNameServer = 192.168.1.1

    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL

    Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\intuit\quickbooks 2009\HelpAsyncPluggableProtocol.dll

    Handler: qbpos - {662E7FAE-5C17-491C-AD9D-98C1F66CC6A0} - c:\windows\system32\QBPOSProtocol.dll

    Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} -

    Notify: igfxcui - igfxdev.dll

    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

    SEH: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll

    .

    ============= SERVICES / DRIVERS ===============

    .

    R0 EMSC;COMPAL Embedded System Control;c:\windows\system32\drivers\EMSC.sys [2011-6-28 9856]

    R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2010-12-21 115008]

    R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2010-12-21 94872]

    R2 AdobeActiveFileMonitor;Adobe Active File Monitor;c:\program files\adobe\photoshop elements 3.0\PhotoshopElementsFileAgent.exe [2004-10-4 98304]

    R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2011-1-12 810144]

    R2 Intuit Entitlement Service v5.3;Intuit Entitlement Service v5.3;c:\program files\common files\intuit\entitlement client\v5.3\server\Intuit.Spc.Map.EntitlementClient.Server.Service.exe [2008-7-29 20480]

    R2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;c:\program files\adobe\photoshop elements 3.0\PhotoshopElementsDeviceConnect.exe [2004-10-4 118784]

    R2 QBPOSDBServiceV8;QBPOS Database Manager v8;c:\program files\intuit\quickbooks point of sale 8.0\databaseserver\QBPOSDBService.exe [2011-8-12 2734480]

    R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2011-6-28 108032]

    R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2011-6-28 81296]

    R3 QuickBooksDB19;QuickBooksDB19;c:\progra~1\intuit\quickb~1\qbdbmgrn.exe -hvquickbooksdb19 --> c:\progra~1\intuit\quickb~1\QBDBMgrN.exe -hvQuickBooksDB19 [?]

    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

    S3 FlyUsb;FLY Fusion;c:\windows\system32\drivers\FlyUsb.sys [2008-2-26 18560]

    S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-14 14336]

    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]

    .

    =============== File Associations ===============

    .

    .txt: <filetype is not registered>

    .js: <filetype is not registered>

    .

    =============== Created Last 30 ================

    .

    .

    ==================== Find3M ====================

    .

    2012-10-11 02:13:21 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl

    2012-10-11 02:13:21 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe

    2012-09-30 02:54:26 22856 ----a-w- c:\windows\system32\drivers\mbam.sys

    2012-09-05 20:21:47 73728 ----a-w- c:\windows\system32\javacpl.cpl

    2012-09-05 20:21:47 477168 ----a-w- c:\windows\system32\npdeployJava1.dll

    2012-09-05 20:21:47 473072 ----a-w- c:\windows\system32\deployJava1.dll

    2012-08-28 15:14:53 916992 ----a-w- c:\windows\system32\wininet.dll

    2012-08-28 15:14:53 43520 ------w- c:\windows\system32\licmgr10.dll

    2012-08-28 15:14:52 1469440 ------w- c:\windows\system32\inetcpl.cpl

    2012-08-28 12:07:15 385024 ------w- c:\windows\system32\html.iec

    2012-08-24 13:53:22 177664 ----a-w- c:\windows\system32\wintrust.dll

    2012-08-21 13:33:26 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe

    2012-08-21 12:58:09 2027520 ----a-w- c:\windows\system32\ntkrnlpa.exe

    .

    ============= FINISH: 20:47:26.84 ===============

    Attach log:

    .

    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

    IF REQUESTED, ZIP IT UP & ATTACH IT

    .

    DDS (Ver_2012-11-07.01)

    .

    Microsoft Windows XP Professional

    Boot Device: \Device\HarddiskVolume1

    Install Date: 6/28/2011 2:09:51 PM

    System Uptime: 11/13/2012 7:43:07 PM (1 hours ago)

    .

    Motherboard: | | JHL91

    Processor: Intel Pentium III Xeon processor | U2E1 | 1582/mhz

    .

    ==== Disk Partitions =========================

    .

    C: is FIXED (NTFS) - 233 GiB total, 175.979 GiB free.

    D: is CDROM ()

    .

    ==== Disabled Device Manager Items =============

    .

    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}

    Description: Realtek RTL8102E Family PCI-E Fast Ethernet NIC

    Device ID: PCI\VEN_10EC&DEV_8136&SUBSYS_003014C0&REV_02\4&3905AE0C&0&00E3

    Manufacturer: Realtek Semiconductor Corp.

    Name: Realtek RTL8102E Family PCI-E Fast Ethernet NIC

    PNP Device ID: PCI\VEN_10EC&DEV_8136&SUBSYS_003014C0&REV_02\4&3905AE0C&0&00E3

    Service: RTLE8023xp

    .

    Class GUID: {6BDD1FC6-810F-11D0-BEC7-08002BE2092F}

    Description: Officejet 4500 G510n-z

    Device ID: ROOT\IMAGE\0000

    Manufacturer: HP

    Name: 4500 G510n-z,192.168.0.65

    PNP Device ID: ROOT\IMAGE\0000

    Service: StillCam

    .

    Class GUID: {4D36E971-E325-11CE-BFC1-08002BE10318}

    Description: Officejet 4500 G510n-z

    Device ID: ROOT\MULTIFUNCTION\0000

    Manufacturer: HP

    Name: Officejet 4500 G510n-z

    PNP Device ID: ROOT\MULTIFUNCTION\0000

    Service:

    .

    Class GUID: {4D36E971-E325-11CE-BFC1-08002BE10318}

    Description: Photosmart 7510 series

    Device ID: ROOT\MULTIFUNCTION\0001

    Manufacturer: HP

    Name: Photosmart 7510 series

    PNP Device ID: ROOT\MULTIFUNCTION\0001

    Service:

    .

    Class GUID: {4D36E971-E325-11CE-BFC1-08002BE10318}

    Description: Photosmart Plus B210 series

    Device ID: ROOT\MULTIFUNCTION\0002

    Manufacturer: HP

    Name: Photosmart Plus B210 series

    PNP Device ID: ROOT\MULTIFUNCTION\0002

    Service:

    .

    ==== System Restore Points ===================

    .

    RP138: 8/12/2012 10:06:29 AM - Installed Canon Camera WIA Driver

    RP139: 8/13/2012 10:32:59 AM - System Checkpoint

    RP140: 8/14/2012 10:46:49 AM - System Checkpoint

    RP141: 8/15/2012 3:00:19 AM - Software Distribution Service 3.0

    RP142: 8/16/2012 10:46:02 AM - System Checkpoint

    RP143: 8/17/2012 10:55:30 AM - System Checkpoint

    RP144: 8/18/2012 3:46:26 PM - System Checkpoint

    RP145: 8/26/2012 6:50:14 PM - Installed Adobe® Photoshop® Elements 3.0

    RP146: 8/27/2012 3:03:04 PM - Removed CT-S300 x32 v157.

    RP147: 8/27/2012 3:13:01 PM - Removed Adobe Photoshop Lightroom 2.

    RP148: 8/29/2012 9:36:11 AM - System Checkpoint

    RP149: 9/5/2012 1:30:30 PM - System Checkpoint

    RP150: 9/5/2012 2:21:09 PM - Removed Java 6 Update 22

    RP151: 9/5/2012 2:21:38 PM - Installed Java 6 Update 35

    RP152: 9/15/2012 10:21:32 PM - Software Distribution Service 3.0

    RP153: 9/20/2012 12:54:15 PM - System Checkpoint

    RP154: 9/21/2012 11:22:10 AM - Software Distribution Service 3.0

    RP155: 9/26/2012 3:57:50 PM - System Checkpoint

    RP156: 10/7/2012 6:48:09 PM - System Checkpoint

    RP157: 10/7/2012 6:59:20 PM - Installed Microsoft Download Manager

    RP158: 10/10/2012 6:43:16 PM - Software Distribution Service 3.0

    RP159: 10/10/2012 7:10:20 PM - Software Distribution Service 3.0

    RP160: 11/9/2012 7:15:20 PM - System Checkpoint

    RP161: 11/13/2012 1:12:35 PM - Software Distribution Service 3.0

    .

    ==== Installed Programs ======================

    .

    32 Bit HP CIO Components Installer

    4500_G510nz_Help

    4500G510nz

    4500G510nz_Software_Min

    470_Help

    470_Readme

    Add or Remove Adobe Creative Suite 3 Web Premium

    Adobe Acrobat 8 Professional

    Adobe Connect Add-in

    Adobe Flash Player 11 ActiveX

    Adobe Flash Player 11 Plugin

    Adobe Illustrator CS3

    Adobe Photoshop Elements 3.0

    Adobe Photoshop Lightroom 2.7

    Adobe Reader X (10.1.4)

    Adobe Setup

    Agere Systems HDA Modem

    BPD_HPSU

    BPDSoftware

    BPDSoftware_Ini

    BufferChm

    Canon Camera WIA Driver

    Canon EOS Kiss REBEL 300D WIA Driver

    CenturyLink QuickAssist Desktop Tools

    CK Becky Higgins' Creative Clips

    CK Creative Clips and Fonts for Boys

    CK Creative Clips and Fonts for Girls

    CK Creative Clips and Fonts for Home, Family & Pets

    CK Everyday Celebrations

    CK Font Organizer

    CK Heritage, Vintage and Retro Triple Pack

    Coupon Printer for Windows

    Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition

    Destinations

    DeviceDiscovery

    DocMgr

    DocProc

    EMSC

    ESET NOD32 Antivirus

    Fax

    GPBaseService2

    H470

    Hewlett-Packard ACLM.NET v1.1.0.0

    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)

    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)

    Hotfix for Windows Media Format 11 SDK (KB929399)

    Hotfix for Windows Media Format 11 SDK (KB973442)

    Hotfix for Windows Media Player 11 (KB939683)

    Hotfix for Windows XP (KB2443685)

    Hotfix for Windows XP (KB2570791)

    Hotfix for Windows XP (KB2633952)

    Hotfix for Windows XP (KB2756822)

    Hotfix for Windows XP (KB915800-v4)

    Hotfix for Windows XP (KB932716-v2)

    Hotfix for Windows XP (KB952287)

    Hotfix for Windows XP (KB954550-v5)

    Hotfix for Windows XP (KB954708)

    Hotfix for Windows XP (KB961118)

    HP Customer Participation Program 13.0

    HP Document Manager 2.0

    HP Imaging Device Functions 13.0

    HP Officejet 4500 G510n-z

    HP Officejet H470 Series

    HP Product Detection

    HP Smart Web Printing 4.5

    HP Solution Center 13.0

    HP Update

    HPProductAssistant

    HPSSupply

    Intel PROSet Wireless

    Intel® Graphics Media Accelerator Driver

    Intel® PROSet/Wireless WiFi Software

    Java Auto Updater

    Java 6 Update 35

    JMicron JMB38X Flash Media Controller

    LeapFrog Connect

    LeapFrog Tag Plugin

    Malwarebytes Anti-Malware version 1.65.1.1000

    MarketResearch

    Microsoft .NET Framework 1.1

    Microsoft .NET Framework 2.0 Service Pack 2

    Microsoft .NET Framework 3.0 Service Pack 2

    Microsoft .NET Framework 3.5 SP1

    Microsoft .NET Framework 4 Client Profile

    Microsoft .NET Framework 4 Extended

    Microsoft Application Error Reporting

    Microsoft Base Smart Card Cryptographic Service Provider Package

    Microsoft Choice Guard

    Microsoft Compression Client Pack 1.0 for Windows XP

    Microsoft Download Manager

    Microsoft Kernel-Mode Driver Framework Feature Pack 1.5

    Microsoft Kernel-Mode Driver Framework Feature Pack 1.9

    Microsoft Office 2010 Service Pack 1 (SP1)

    Microsoft Office Access MUI (English) 2010

    Microsoft Office Access Setup Metadata MUI (English) 2010

    Microsoft Office Excel MUI (English) 2010

    Microsoft Office Home and Student 2010

    Microsoft Office OneNote MUI (English) 2010

    Microsoft Office Outlook MUI (English) 2010

    Microsoft Office PowerPoint MUI (English) 2010

    Microsoft Office Proof (English) 2010

    Microsoft Office Proof (French) 2010

    Microsoft Office Proof (Spanish) 2010

    Microsoft Office Proofing (English) 2010

    Microsoft Office Publisher MUI (English) 2010

    Microsoft Office Shared MUI (English) 2010

    Microsoft Office Shared Setup Metadata MUI (English) 2010

    Microsoft Office Single Image 2010

    Microsoft Office Word MUI (English) 2010

    Microsoft Silverlight

    Microsoft Software Update for Web Folders (English) 14

    Microsoft SQL Server 2005 Compact Edition [ENU]

    Microsoft User-Mode Driver Framework Feature Pack 1.9

    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

    Microsoft Visual C++ 2005 Redistributable

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

    Microsoft WinUsb 1.0

    Mozilla Thunderbird 12.0.1 (x86 en-US)

    MSVCRT

    MSXML 4.0 SP2 (KB954430)

    MSXML 4.0 SP2 (KB973688)

    MSXML 4.0 SP2 Parser and SDK

    Music Manager

    MyCenturyLink Toolbar

    Network

    OCR Software by I.R.I.S. 13.0

    OpenOffice.org 3.4

    Pazzles Inspiration Studio

    Personal Ancestral File 5

    ProductContext

    QuickBooks

    QuickBooks Point of Sale 8.0

    QuickBooks Premier: Retail Edition 2009

    QuickTime

    RealNetworks - Microsoft Visual C++ 2008 Runtime

    RealPlayer

    REALTEK GbE & FE Ethernet PCI-E NIC Driver

    Realtek High Definition Audio Driver

    RealUpgrade 1.1

    SAMSUNG Intelli-studio

    Scan

    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)

    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)

    Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)

    Security Update for Microsoft .NET Framework 4 Extended (KB2416472)

    Security Update for Microsoft .NET Framework 4 Extended (KB2487367)

    Security Update for Microsoft .NET Framework 4 Extended (KB2656351)

    Security Update for Microsoft Excel 2010 (KB2597166) 32-Bit Edition

    Security Update for Microsoft InfoPath 2010 (KB2687417) 32-Bit Edition

    Security Update for Microsoft Office 2010 (KB2553091)

    Security Update for Microsoft Office 2010 (KB2553096)

    Security Update for Microsoft Office 2010 (KB2553260) 32-Bit Edition

    Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition

    Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition

    Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition

    Security Update for Microsoft Office 2010 (KB2589322) 32-Bit Edition

    Security Update for Microsoft Office 2010 (KB2589337) 32-Bit Edition

    Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition

    Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition

    Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition

    Security Update for Microsoft Visio Viewer 2010 (KB2598287) 32-Bit Edition

    Security Update for Microsoft Windows (KB2564958)

    Security Update for Microsoft Word 2010 (KB2553488) 32-Bit Edition

    Security Update for Windows Internet Explorer 8 (KB2510531)

    Security Update for Windows Internet Explorer 8 (KB2530548)

    Security Update for Windows Internet Explorer 8 (KB2544521)

    Security Update for Windows Internet Explorer 8 (KB2559049)

    Security Update for Windows Internet Explorer 8 (KB2586448)

    Security Update for Windows Internet Explorer 8 (KB2618444)

    Security Update for Windows Internet Explorer 8 (KB2647516)

    Security Update for Windows Internet Explorer 8 (KB2675157)

    Security Update for Windows Internet Explorer 8 (KB2699988)

    Security Update for Windows Internet Explorer 8 (KB2722913)

    Security Update for Windows Internet Explorer 8 (KB2744842)

    Security Update for Windows Internet Explorer 8 (KB982381)

    Security Update for Windows Media Player (KB2378111)

    Security Update for Windows Media Player (KB952069)

    Security Update for Windows Media Player (KB954155)

    Security Update for Windows Media Player (KB973540)

    Security Update for Windows Media Player (KB975558)

    Security Update for Windows Media Player (KB978695)

    Security Update for Windows Media Player 11 (KB954154)

    Security Update for Windows Search 4 - KB963093

    Security Update for Windows XP (KB2079403)

    Security Update for Windows XP (KB2115168)

    Security Update for Windows XP (KB2121546)

    Security Update for Windows XP (KB2229593)

    Security Update for Windows XP (KB2296011)

    Security Update for Windows XP (KB2347290)

    Security Update for Windows XP (KB2360937)

    Security Update for Windows XP (KB2387149)

    Security Update for Windows XP (KB2393802)

    Security Update for Windows XP (KB2412687)

    Security Update for Windows XP (KB2419632)

    Security Update for Windows XP (KB2423089)

    Security Update for Windows XP (KB2440591)

    Security Update for Windows XP (KB2443105)

    Security Update for Windows XP (KB2476490)

    Security Update for Windows XP (KB2476687)

    Security Update for Windows XP (KB2478960)

    Security Update for Windows XP (KB2478971)

    Security Update for Windows XP (KB2479943)

    Security Update for Windows XP (KB2481109)

    Security Update for Windows XP (KB2483185)

    Security Update for Windows XP (KB2485663)

    Security Update for Windows XP (KB2503665)

    Security Update for Windows XP (KB2506212)

    Security Update for Windows XP (KB2506223)

    Security Update for Windows XP (KB2507618)

    Security Update for Windows XP (KB2507938)

    Security Update for Windows XP (KB2508272)

    Security Update for Windows XP (KB2508429)

    Security Update for Windows XP (KB2509553)

    Security Update for Windows XP (KB2510581)

    Security Update for Windows XP (KB2524375)

    Security Update for Windows XP (KB2530548)

    Security Update for Windows XP (KB2535512)

    Security Update for Windows XP (KB2536276-v2)

    Security Update for Windows XP (KB2536276)

    Security Update for Windows XP (KB2544521)

    Security Update for Windows XP (KB2544893-v2)

    Security Update for Windows XP (KB2544893)

    Security Update for Windows XP (KB2555917)

    Security Update for Windows XP (KB2562937)

    Security Update for Windows XP (KB2566454)

    Security Update for Windows XP (KB2567053)

    Security Update for Windows XP (KB2567680)

    Security Update for Windows XP (KB2570222)

    Security Update for Windows XP (KB2570947)

    Security Update for Windows XP (KB2584146)

    Security Update for Windows XP (KB2585542)

    Security Update for Windows XP (KB2592799)

    Security Update for Windows XP (KB2598479)

    Security Update for Windows XP (KB2603381)

    Security Update for Windows XP (KB2618451)

    Security Update for Windows XP (KB2619339)

    Security Update for Windows XP (KB2620712)

    Security Update for Windows XP (KB2621440)

    Security Update for Windows XP (KB2624667)

    Security Update for Windows XP (KB2631813)

    Security Update for Windows XP (KB2633171)

    Security Update for Windows XP (KB2639417)

    Security Update for Windows XP (KB2641653)

    Security Update for Windows XP (KB2646524)

    Security Update for Windows XP (KB2647518)

    Security Update for Windows XP (KB2653956)

    Security Update for Windows XP (KB2655992)

    Security Update for Windows XP (KB2659262)

    Security Update for Windows XP (KB2660465)

    Security Update for Windows XP (KB2661637)

    Security Update for Windows XP (KB2676562)

    Security Update for Windows XP (KB2685939)

    Security Update for Windows XP (KB2686509)

    Security Update for Windows XP (KB2691442)

    Security Update for Windows XP (KB2695962)

    Security Update for Windows XP (KB2698365)

    Security Update for Windows XP (KB2705219)

    Security Update for Windows XP (KB2707511)

    Security Update for Windows XP (KB2709162)

    Security Update for Windows XP (KB2712808)

    Security Update for Windows XP (KB2718523)

    Security Update for Windows XP (KB2719985)

    Security Update for Windows XP (KB2723135)

    Security Update for Windows XP (KB2724197)

    Security Update for Windows XP (KB2731847)

    Security Update for Windows XP (KB923561)

    Security Update for Windows XP (KB923789)

    Security Update for Windows XP (KB941569)

    Security Update for Windows XP (KB946648)

    Security Update for Windows XP (KB950762)

    Security Update for Windows XP (KB950974)

    Security Update for Windows XP (KB951376-v2)

    Security Update for Windows XP (KB952004)

    Security Update for Windows XP (KB952954)

    Security Update for Windows XP (KB954459)

    Security Update for Windows XP (KB956572)

    Security Update for Windows XP (KB956744)

    Security Update for Windows XP (KB956802)

    Security Update for Windows XP (KB956844)

    Security Update for Windows XP (KB958644)

    Security Update for Windows XP (KB959426)

    Security Update for Windows XP (KB960803)

    Security Update for Windows XP (KB960859)

    Security Update for Windows XP (KB961501)

    Security Update for Windows XP (KB969059)

    Security Update for Windows XP (KB970430)

    Security Update for Windows XP (KB971657)

    Security Update for Windows XP (KB972270)

    Security Update for Windows XP (KB973507)

    Security Update for Windows XP (KB973869)

    Security Update for Windows XP (KB973904)

    Security Update for Windows XP (KB974112)

    Security Update for Windows XP (KB974318)

    Security Update for Windows XP (KB974392)

    Security Update for Windows XP (KB974571)

    Security Update for Windows XP (KB975025)

    Security Update for Windows XP (KB975467)

    Security Update for Windows XP (KB975560)

    Security Update for Windows XP (KB975562)

    Security Update for Windows XP (KB975713)

    Security Update for Windows XP (KB977816)

    Security Update for Windows XP (KB977914)

    Security Update for Windows XP (KB978338)

    Security Update for Windows XP (KB978542)

    Security Update for Windows XP (KB978601)

    Security Update for Windows XP (KB978706)

    Security Update for Windows XP (KB979309)

    Security Update for Windows XP (KB979482)

    Security Update for Windows XP (KB979687)

    Security Update for Windows XP (KB980436)

    Security Update for Windows XP (KB981322)

    Security Update for Windows XP (KB981997)

    Security Update for Windows XP (KB982132)

    Security Update for Windows XP (KB982665)

    Segoe UI

    Shop for HP Supplies

    SmartWebPrinting

    SolutionCenter

    Status

    SupportSoft Assisted Service

    Toolbox

    TrayApp

    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)

    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)

    Update for Microsoft .NET Framework 4 Client Profile (KB2473228)

    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)

    Update for Microsoft .NET Framework 4 Client Profile (KB2600217)

    Update for Microsoft .NET Framework 4 Extended (KB2468871)

    Update for Microsoft .NET Framework 4 Extended (KB2533523)

    Update for Microsoft .NET Framework 4 Extended (KB2600217)

    Update for Microsoft Office 2010 (KB2553065)

    Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition

    Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition

    Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition

    Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition

    Update for Microsoft Office 2010 (KB2566458)

    Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition

    Update for Microsoft Office 2010 (KB2598289) 32-Bit Edition

    Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition

    Update for Microsoft OneNote 2010 (KB2589345) 32-Bit Edition

    Update for Microsoft Outlook 2010 (KB2553248) 32-Bit Edition

    Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition

    Update for Windows Internet Explorer 8 (KB2447568)

    Update for Windows Internet Explorer 8 (KB2598845)

    Update for Windows Internet Explorer 8 (KB2632503)

    Update for Windows XP (KB2345886)

    Update for Windows XP (KB2467659)

    Update for Windows XP (KB2492386)

    Update for Windows XP (KB2541763)

    Update for Windows XP (KB2607712)

    Update for Windows XP (KB2616676)

    Update for Windows XP (KB2641690)

    Update for Windows XP (KB2661254-v2)

    Update for Windows XP (KB2718704)

    Update for Windows XP (KB2736233)

    Update for Windows XP (KB2749655)

    Update for Windows XP (KB898461)

    Update for Windows XP (KB951978)

    Update for Windows XP (KB955759)

    Update for Windows XP (KB968389)

    Update for Windows XP (KB971029)

    Update for Windows XP (KB971737)

    Update for Windows XP (KB973687)

    Update for Windows XP (KB973815)

    Use the entry named LeapFrog Connect to uninstall (LeapFrog Tag Plugin)

    WebFldrs XP

    WebReg

    Window Shopper

    Windows Driver Package - ENE (enecir) HIDClass (04/29/2008 2.5.0.0)

    Windows Driver Package - FTDI CDM Driver Package (02/17/2009 2.04.16)

    Windows Driver Package - LeapFrog (FlyUsb) USB (11/05/2008 1.1.1.0)

    Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net (09/10/2009 02.03.05.012)

    Windows Genuine Advantage Notifications (KB905474)

    Windows Genuine Advantage Validation Tool (KB892130)

    Windows Internet Explorer 8

    Windows Live Communications Platform

    Windows Live Essentials

    Windows Live Photo Gallery

    Windows Live Sign-in Assistant

    Windows Live Sync

    Windows Live Upload Tool

    Windows Live Writer

    Windows Management Framework Core

    Windows Media Format 11 runtime

    Windows Media Player 11

    Windows Mobile Device Updater Component

    Windows Search 4.0

    Wireless Switch

    Yahoo! Toolbar

    Zune

    Zune Language Pack (CHS)

    Zune Language Pack (CHT)

    Zune Language Pack (CSY)

    Zune Language Pack (DAN)

    Zune Language Pack (DEU)

    Zune Language Pack (ELL)

    Zune Language Pack (ESP)

    Zune Language Pack (FIN)

    Zune Language Pack (FRA)

    Zune Language Pack (HUN)

    Zune Language Pack (IND)

    Zune Language Pack (ITA)

    Zune Language Pack (JPN)

    Zune Language Pack (KOR)

    Zune Language Pack (MSL)

    Zune Language Pack (NLD)

    Zune Language Pack (NOR)

    Zune Language Pack (PLK)

    Zune Language Pack (PTB)

    Zune Language Pack (PTG)

    Zune Language Pack (RUS)

    Zune Language Pack (SVE)

    .

    ==== Event Viewer Messages From Past Week ========

    .

    11/13/2012 1:24:07 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)

    11/13/2012 1:18:47 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the SharedAccess service.

    11/13/2012 1:18:17 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the WZCSVC service.

    .

    ==== End Of File ===========================

  11. Results of screen317's Security Check version 0.99.51

    Windows 7 Service Pack 1 x64 (UAC is enabled)

    Internet Explorer 9

    ``````````````Antivirus/Firewall Check:``````````````

    Windows Firewall Enabled!

    Microsoft Security Essentials

    Antivirus up to date!

    `````````Anti-malware/Other Utilities Check:`````````

    Malwarebytes Anti-Malware version 1.65.0.1400

    Java 7 Update 7

    Adobe Flash Player 11.4.402.287

    Adobe Reader X (10.1.4)

    Mozilla Firefox (15.0.1)

    ````````Process Check: objlist.exe by Laurent````````

    Microsoft Security Essentials MSMpEng.exe

    `````````````````System Health check`````````````````

    Total Fragmentation on Drive C: 4%

    ````````````````````End of Log``````````````````````

  12. The log didn't seem to have anything useful (to me).

    ESETSmartInstaller@High as CAB hook log:

    OnlineScanner64.ocx - registred OK

    OnlineScanner.ocx - registred OK

    I also exported the scan results (which were surprising to me considering the tools we've run thus far found no issues):

    C:\Program Files (x86)\Common Files\ZugoInstaller.exe Win32/Toolbar.Zugo application cleaned by deleting - quarantined

    C:\Program Files (x86)\Dell DataSafe Local Backup\hstart.exe a variant of Win32/HiddenStart.A application cleaned by deleting - quarantined

    C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe a variant of Win32/HiddenStart.A application cleaned by deleting - quarantined

    C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\UpdateWorkingDirectory\DSL\hstart.exe a variant of Win32/HiddenStart.A application cleaned by deleting - quarantined

    C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\UpdateWorkingDirectory\DSL\Components\DSUpdate\hstart.exe a variant of Win32/HiddenStart.A application cleaned by deleting - quarantined

    C:\Program Files (x86)\FrostWire 5\frostwire-installer.exe Win32/OpenCandy application cleaned by deleting - quarantined

    C:\TDSSKiller_Quarantine\08.10.2012_07.34.32\mbr0000\tdlfs0000\tsk0000.dta a variant of Win32/Olmarik.AYI trojan cleaned by deleting - quarantined

    C:\TDSSKiller_Quarantine\08.10.2012_07.34.32\mbr0000\tdlfs0000\tsk0001.dta Win64/Olmarik.AK trojan cleaned by deleting - quarantined

    C:\TDSSKiller_Quarantine\08.10.2012_07.34.32\mbr0000\tdlfs0000\tsk0012.dta a variant of Win32/Olmarik.AYI trojan cleaned by deleting - quarantined

    C:\TDSSKiller_Quarantine\08.10.2012_08.56.22\tdlfs0000\tsk0000.dta a variant of Win32/Olmarik.AYI trojan cleaned by deleting - quarantined

    C:\TDSSKiller_Quarantine\08.10.2012_08.56.22\tdlfs0000\tsk0001.dta Win64/Olmarik.AK trojan cleaned by deleting - quarantined

    C:\TDSSKiller_Quarantine\08.10.2012_08.56.22\tdlfs0000\tsk0012.dta a variant of Win32/Olmarik.AYI trojan cleaned by deleting - quarantined

    C:\Users\Gator\.frostwire5\updates\frostwire-5.3.8.windows.exe Win32/OpenCandy application cleaned by deleting - quarantined

    C:\Users\Gator\AppData\Roaming\FrostWire\.AppSpecialShare\frostwire-5.0.8.windows.exe Win32/OpenCandy application cleaned by deleting - quarantined

    C:\Users\Gator\Desktop\avc-free.exe Win32/OpenCandy application cleaned by deleting - quarantined

  13. RogueKiller V8.1.1 [10/03/2012] by Tigzy

    mail: tigzyRK<at>gmail<dot>com

    Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/

    Website: http://tigzy.geekstogo.com/roguekiller.php

    Blog: http://tigzyrk.blogspot.com

    Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version

    Started in : Normal mode

    User : Gator [Admin rights]

    Mode : Scan -- Date : 10/10/2012 18:12:33

    ¤¤¤ Bad processes : 0 ¤¤¤

    ¤¤¤ Registry Entries : 0 ¤¤¤

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver : [NOT LOADED] ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤

    --> C:\Windows\system32\drivers\etc\hosts

    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: ST9500325AS +++++

    --- User ---

    [MBR] 83873ddecb8ada92393ead1bd6461c40

    [bSP] 29c6e6ea19b9e653a532ba7f0f537374 : Windows 7 MBR Code

    Partition table:

    0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo

    1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 15000 Mo

    2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 30926848 | Size: 461838 Mo

    User = LL1 ... OK!

    User = LL2 ... OK!

    Finished : << RKreport[8].txt >>

    RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt ; RKreport[5].txt ;

    RKreport[6].txt ; RKreport[7].txt ; RKreport[8].txt

    ListParts by Farbar Version: 02-10-2012

    Ran by Gator (administrator) on 10-10-2012 at 18:12:01

    Windows 7 (X64)

    Running From: C:\Users\Gator\Downloads

    Language: 0409

    ************************************************************

    ========================= Memory info ======================

    Percentage of memory in use: 33%

    Total physical RAM: 3894.68 MB

    Available physical RAM: 2602.1 MB

    Total Pagefile: 7787.56 MB

    Available Pagefile: 6306.68 MB

    Total Virtual: 8192 MB

    Available Virtual: 8191.9 MB

    ======================= Partitions =========================

    1 Drive c: (OS) (Fixed) (Total:451.01 GB) (Free:384.45 GB) NTFS ==>[Drive with boot components (obtained from BCD)]

    Disk ### Status Size Free Dyn Gpt

    -------- ------------- ------- ------- --- ---

    Disk 0 Online 465 GB 0 B

    Partitions of Disk 0:

    ===============

    Partition ### Type Size Offset

    ------------- ---------------- ------- -------

    Partition 1 OEM 100 MB 1024 KB

    Partition 2 Primary 14 GB 101 MB

    Partition 3 Primary 451 GB 14 GB

    ======================================================================================================

    Disk: 0

    Partition 1

    Type : DE

    Hidden: Yes

    Active: No

    There is no volume associated with this partition.

    ======================================================================================================

    Disk: 0

    Partition 2

    Type : 07

    Hidden: No

    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info

    ---------- --- ----------- ----- ---------- ------- --------- --------

    * Volume 1 Recovery NTFS Partition 14 GB Healthy System (partition with boot components)

    ======================================================================================================

    Disk: 0

    Partition 3

    Type : 07

    Hidden: No

    Active: No

    Volume ### Ltr Label Fs Type Size Status Info

    ---------- --- ----------- ----- ---------- ------- --------- --------

    * Volume 2 C OS NTFS Partition 451 GB Healthy Boot

    ======================================================================================================

    ****** End Of Log ******

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.