Jump to content

Can't run any exe files or "RUN" or regedit in infected acnt


Recommended Posts

Was logged in to an admin account and was infected by Rogue.DefenseCenter (Trojan.FakeAV!gen31) and Worm.Prolaco.M Also discovered that I couldn't run TaskManager or ANY other exe file, nor could I run any command from the "Start/Run", cmd, msconfig etc....

I let MBAM complete and rebooted into the infected account and ran gpedit.msc to change setting to allow me to run Task Manager. Limited apps were running!

However I could log into other accounts, limited and admin prevs and could run those apps denied me in the infected account. Now if logged into the previous infected account, when I try to execute ANY file with exe type, I get the Windows pop up screen asking me which application to use.... even when I type CMD in the "RUN" window this happens. Can't run msconfig nor regedit.

Norton AV ran and caught and removed the Trojan.FakeAV!gen31

At the time of infection, I ran MBAM in the infected account and got the following response. Subsequent running of MBAM showed no other trojan or virus. Also have HijackThis file

MBAM info

Memory Processes Infected:

C:\Documents and Settings\adminron\Application Data\SystemProc\lsass.exe (Worm.Prolaco) -> Unloaded process successfully.

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\rthdbpl (Worm.Prolaco) -> Quarantined and deleted successfully.

Registry Data Items Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:

C:\Documents and Settings\adminron\Application Data\SystemProc (Trojan.Agent) -> Quarantined and deleted successfully.

C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D} (Worm.Prolaco.M) -> Quarantined and deleted successfully.

C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome (Worm.Prolaco.M) -> Quarantined and deleted successfully.

C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content (Worm.Prolaco.M) -> Quarantined and deleted successfully.

Files Infected:

C:\Documents and Settings\adminron\Application Data\SystemProc\lsass.exe (Worm.Prolaco) -> Quarantined and deleted successfully.

C:\RECYCLER\S-1-5-21-3242676782-1459987966-1782763977-1010\Dc68.dll (Rogue.DefenseCenter) -> Quarantined and deleted successfully.

C:\RECYCLER\S-1-5-21-3242676782-1459987966-1782763977-1010\Dc69.EXE (Trojan.Dropper) -> Quarantined and deleted successfully.

C:\RECYCLER\S-1-5-21-3242676782-1459987966-1782763977-1010\Dc52\loadx1[1].exe (Trojan.Dropper) -> Quarantined and deleted successfully.

C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest (Worm.Prolaco.M) -> Quarantined and deleted successfully.

C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf (Worm.Prolaco.M) -> Quarantined and deleted successfully.

C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content\timer.xul (Worm.Prolaco.M) -> Quarantined and deleted successfully.

mbam_log_2010_06_26__11_51_29_.txt

Link to post
Share on other sites

Hello astro3ron and welcome to the forums. ;)

I am jwang01 and I will be assisting you with your issue.

When we get to working on your computer you may want to print out or save my respones in notepad because there may be times were you will not be able to access them here.

Also, please don't attach your logs unless asked, as they can make them hard to read. Just post them as a reply.

Let's see whats going on here.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Custom Scan box paste this in
    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Link to post
Share on other sites

Hello astro3ron and welcome to the forums. ;)

I am jwang01 and I will be assisting you with your issue.

When we get to working on your computer you may want to print out or save my respones in notepad because there may be times were you will not be able to access them here.

Also, please don't attach your logs unless asked, as they can make them hard to read. Just post them as a reply.

Let's see whats going on here.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Custom Scan box paste this in
    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

jwang01,

I'm including the two files requested, otl.txt and extras.txt. I ran otl in an admin account (Fulladmin) that allows me to run exe files and all the other apps I used to run in the bad account, adminron , where I got infected. I also ran otl in the infected account, adminron, and an otl.txt file was generated but no file extras.txt was generated, I suspect due to the .exe issue. However, I generated a diff file on the otl.txt files using Beyond Comapre 2, which I can include as an attachment later if you'd like. Although I suspect you have diff tools as well. Is it easier to upload these as attachments, or just inline copy?

I'll send two parts, Part 1 contains OTL.txt and extras.txt file run out of the good account. Then I'll send the bad otl.txt file in part 2

OTL.txt file run out of the good account, Fulladmin:

OTL.txt

OTL logfile created on: 6/27/2010 11:38:48 AM - Run 1

OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\adminfull\Desktop

Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 7.0.5730.13)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 572.00 Mb Available Physical Memory | 56.00% Memory free

2.00 Gb Paging File | 2.00 Gb Available in Paging File | 85.00% Paging File free

Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 73.84 Gb Total Space | 19.59 Gb Free Space | 26.53% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

Drive E: | 75.17 Gb Total Space | 67.18 Gb Free Space | 89.37% Space Free | Partition Type: NTFS

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: RON3000

Current User Name: adminfull

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: Current user

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\adminfull\Desktop\OTL.com (OldTimer Tools)

PRC - C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)

PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)

PRC - C:\WINDOWS\SYSTEM32\DRIVERS\CDAC11BA.EXE (Macrovision)

PRC - C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)

PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)

PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)

PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)

PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)

PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)

PRC - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)

PRC - C:\Program Files\ISS\BlackICE\blackice.exe (Internet Security Systems, Inc.)

PRC - C:\Program Files\ISS\BlackICE\Vpatch.exe (Internet Security Systems, Inc.)

PRC - C:\Program Files\ISS\BlackICE\RapApp.exe (Internet Security Systems, Inc.)

PRC - C:\Program Files\ISS\BlackICE\blackd.exe (Internet Security Systems, Inc.)

PRC - C:\Program Files\cisco systems\vpn client\cvpnd.exe (Cisco Systems, Inc.)

PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)

PRC - C:\WINDOWS\SYSTEM32\ntvdm.exe (Microsoft Corporation)

PRC - C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)

PRC - C:\Program Files\Iomega\AutoDisk\ADService.exe (Iomega Corporation)

PRC - C:\Program Files\Iomega\System32\AppServices.exe (Iomega Corporation)

PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe (Hewlett-Packard Co.)

PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe (Hewlett-Packard Co.)

PRC - C:\Program Files\Conversions Plus\FormatM.exe (DataViz Inc.)

PRC - C:\Program Files\WinPoET Broadband Connection\WROS.exe (iVasion, a Routerware Company)

========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\adminfull\Desktop\OTL.com (OldTimer Tools)

MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)

MOD - C:\WINDOWS\SYSTEM32\msscript.ocx (Microsoft Corporation)

========== Win32 Services (SafeList) ==========

SRV - (vsmon) -- File not found

SRV - (VPatch) -- File not found

SRV - (RapApp) -- File not found

SRV - (Iomega Activity Disk2) -- File not found

SRV - (BlackICE) -- File not found

SRV - (SpyHunter 4 Service) -- C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)

SRV - (IntuitUpdateService) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)

SRV - (Automatic LiveUpdate Scheduler) -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)

SRV - (LiveUpdate) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)

SRV - (C-DillaCdaC11BA) -- C:\WINDOWS\SYSTEM32\DRIVERS\CDAC11BA.EXE (Macrovision)

SRV - (SavRoam) -- C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)

SRV - (Symantec AntiVirus) -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)

SRV - (DefWatch) -- C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)

SRV - (SNDSrvc) -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)

SRV - (ccSetMgr) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)

SRV - (ccEvtMgr) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)

SRV - (SPBBCSvc) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)

SRV - (CVPND) -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)

SRV - (GhostStartService) -- C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe (Symantec Corporation)

SRV - (NetSvc) -- C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation)

SRV - (Pml Driver HPH11) -- C:\WINDOWS\SYSTEM32\hphipm11.exe (HP)

SRV - (_IOMEGA_ACTIVE_DISK_SERVICE_) -- C:\Program Files\Iomega\AutoDisk\ADService.exe (Iomega Corporation)

SRV - (Iomega App Services) -- C:\Program Files\Iomega\System32\AppServices.exe (Iomega Corporation)

SRV - (Pml Driver HPZ12) -- C:\WINDOWS\SYSTEM32\HPZipm12.exe (HP)

SRV - (MacFormatService) -- C:\Program Files\Conversions Plus\FORMATM.EXE (DataViz Inc.)

SRV - (WinPPPoverEthernet) -- C:\Program Files\WinPoET Broadband Connection\WROS.exe (iVasion, a Routerware Company)

========== Driver Services (SafeList) ==========

DRV - (EraserUtilRebootDrv) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)

DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)

DRV - (NAVEX15) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100626.002\NAVEX15.SYS (Symantec Corporation)

DRV - (NAVENG) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100626.002\NAVENG.SYS (Symantec Corporation)

DRV - (CdaC15BA) -- C:\WINDOWS\SYSTEM32\DRIVERS\CdaC15BA.SYS ()

DRV - (SymEvent) -- C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)

DRV - (SAVRT) -- C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)

DRV - (SAVRTPEL) -- C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)

DRV - (SYMTDI) -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)

DRV - (SYMREDRV) -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)

DRV - (SPBBCDrv) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)

DRV - (BLACK) -- C:\WINDOWS\SYSTEM32\DRIVERS\Blackcat.sys (Internet Security Systems, Inc.)

DRV - (MakoNT) -- C:\WINDOWS\system32\drivers\MakoNT.sys (Internet Security Systems, Inc.)

DRV - (rap) -- C:\WINDOWS\SYSTEM32\DRIVERS\RapDrv.sys (Internet Security Systems, Inc.)

DRV - (CVPNDRVA) -- C:\WINDOWS\SYSTEM32\DRIVERS\CVPNDRVA.sys (Cisco Systems, Inc.)

DRV - (CVirtA) -- C:\WINDOWS\SYSTEM32\DRIVERS\CVirtA.sys (Cisco Systems, Inc.)

DRV - (MxlW2k) -- C:\WINDOWS\SYSTEM32\DRIVERS\MxlW2k.sys (MusicMatch, Inc.)

DRV - (DNE) -- C:\WINDOWS\SYSTEM32\DRIVERS\dne2000.sys (Deterministic Networks, Inc.)

DRV - (AFS2K) -- C:\WINDOWS\SYSTEM32\DRIVERS\AFS2K.SYS (Oak Technology Inc.)

DRV - (MXOPSWD) -- C:\WINDOWS\SYSTEM32\DRIVERS\mxopswd.sys (Maxtor Corp.)

DRV - (amdagp) -- C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)

DRV - (sisagp) -- C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)

DRV - (ppa3) -- C:\WINDOWS\System32\DRIVERS\ppa3.sys (Microsoft Corporation)

DRV - (iAimFP4) -- C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)

DRV - (iAimFP3) -- C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)

DRV - (iAimTV4) -- C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)

DRV - (iAimTV3) -- C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)

DRV - (iAimTV1) -- C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)

DRV - (iAimTV0) -- C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)

DRV - (i81x) -- C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)

DRV - (iAimFP0) -- C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)

DRV - (iAimFP1) -- C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)

DRV - (iAimFP2) -- C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)

DRV - (ati2mtag) -- C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)

DRV - (GhPciScan) -- C:\Program Files\Symantec\Norton Ghost 2003\GhPciScan.sys (Symantec Corporation)

DRV - (Aspi32) -- C:\WINDOWS\SYSTEM32\DRIVERS\ASPI32.SYS (Adaptec)

DRV - (HSFHWBS2) -- C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)

DRV - (winachsf) -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)

DRV - (HSF_DP) -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)

DRV - (nv) -- C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)

DRV - (MXOFX) USB Storage Adapter FX (MXO) -- C:\WINDOWS\SYSTEM32\DRIVERS\MXOFX.SYS (Cypress Semiconductor)

DRV - (MaxtorFrontPanel1) -- C:\WINDOWS\SYSTEM32\DRIVERS\mxofwfp.sys (Maxtor Corp.)

DRV - (RapNet) -- C:\WINDOWS\SYSTEM32\DRIVERS\RapNet.sys (Internet Security Systems, Inc.)

DRV - (RapFile) -- C:\WINDOWS\SYSTEM32\DRIVERS\RapFile.sys (Internet Security Systems, Inc.)

DRV - (Dot4 HPH11) -- C:\WINDOWS\SYSTEM32\DRIVERS\hphid411.sys (HP)

DRV - (Dot4Storage HPH11) Storage Class Driver for IEEE-1284.4 (HPH11) -- C:\WINDOWS\SYSTEM32\DRIVERS\hphs2k11.sys (Hewlett-Packard)

DRV - (Dot4Usb HPH11) -- C:\WINDOWS\SYSTEM32\DRIVERS\hphius11.sys (HP)

DRV - (Dot4Print HPH11) -- C:\WINDOWS\SYSTEM32\DRIVERS\hphipr11.sys (HP)

DRV - (omci) -- C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)

DRV - (PQNTDrv) -- C:\WINDOWS\SYSTEM32\DRIVERS\PQNTDRV.sys (PowerQuest Corporation)

DRV - (iomdisk) -- C:\WINDOWS\System32\DRIVERS\iomdisk.sys (Iomega Corporation)

DRV - (MacOpen) -- C:\WINDOWS\SYSTEM32\DRIVERS\MacOpen.sys (DataViz Inc.)

DRV - (MODEMCSA) -- C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)

DRV - (Sparrow) -- C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)

DRV - (sym_u3) -- C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)

DRV - (sym_hi) -- C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)

DRV - (symc8xx) -- C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)

DRV - (symc810) -- C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)

DRV - (ultra) -- C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)

DRV - (ql12160) -- C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)

DRV - (ql1080) -- C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)

DRV - (ql1280) -- C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)

DRV - (dac2w2k) -- C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)

DRV - (mraid35x) -- C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)

DRV - (asc) -- C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)

DRV - (asc3550) -- C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)

DRV - (AliIde) -- C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)

DRV - (CmdIde) -- C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)

DRV - (EL90XBC) -- C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)

DRV - (EL90X) -- C:\WINDOWS\SYSTEM32\DRIVERS\EL90XND5.SYS (3Com Corporation)

DRV - (WrKPoET2000) -- C:\Program Files\WinPoET Broadband Connection\WrKPoET2000.sys ()

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/01/08 23:56:21 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/09 14:38:53 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/09 14:38:53 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.24\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/05/26 06:36:40 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.24\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2010/04/08 22:18:38 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Netscape 7.01\Extensions\\Components: C:\Program Files\Netscape\Netscape\Components [2010/06/16 19:36:18 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Netscape 7.01\Extensions\\Plugins: C:\Program Files\Netscape\Netscape\Plugins [2010/05/19 20:19:55 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Netscape 7.1\Extensions\\Components: C:\Program Files\Netscape\Netscape\Components [2010/06/16 19:36:18 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Netscape 7.1\Extensions\\Plugins: C:\Program Files\Netscape\Netscape\Plugins [2010/05/19 20:19:55 | 000,000,000 | ---D | M]

[2010/06/26 11:51:12 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/06/26 21:50:14 | 000,000,734 | ---- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No CLSID value found.

O3 - HKLM\..\Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - No CLSID value found.

O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)

O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb07.exe (HP)

O4 - HKLM..\Run: [iSUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)

O4 - HKLM..\Run: [iSUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)

O4 - HKLM..\Run: [MacLicense] C:\Program Files\Conversions Plus\MacLic.exe (DataViz Inc.)

O4 - HKLM..\Run: [sunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunServer.exe (Sunbelt Software)

O4 - HKLM..\Run: [Vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)

O4 - Startup: C:\Documents and Settings\adminfull\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe (Hewlett-Packard Co.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Proventia Desktop Agent.lnk = File not found

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk = C:\Program Files\cisco systems\vpn client\vpngui.exe (Cisco Systems, Inc.)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_16.dll (Sun Microsystems, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\ISS\BlackICE\IBE\ICELSP_8.0.675.0.dll (Internet Security Systems, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\ISS\BlackICE\IBE\ICELSP_8.0.675.0.dll (Internet Security Systems, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\ISS\BlackICE\IBE\ICELSP_8.0.675.0.dll (Internet Security Systems, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\ISS\BlackICE\IBE\ICELSP_8.0.675.0.dll (Internet Security Systems, Inc.)

O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)

O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)

O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} http://downloadcenter.samsung.com/content/...trolLite_EN.cab (DjVuCtl Class)

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab (CKAVWebScan Object)

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/microsoftu...b?1261437161937 (WUWebControl Class)

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu...b?1261437142515 (MUWebControl Class)

O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0...oUploader55.cab (Facebook Photo Uploader 5 Control)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl...indows-i586.cab (Java Plug-in 1.6.0_16)

O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/...8046.9385069444 (Reg Error: Key error.)

O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} http://www.microsoft.com/security/controls.../20/SassCln.CAB (SassCln Object)

O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)

O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} Reg Error: Key error. (Java Plug-in 1.4.0_01)

O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} Reg Error: Key error. (Java Plug-in 1.4.1_02)

O16 - DPF: {CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl...indows-i586.cab (Java Plug-in 1.4.2_18)

O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_16)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_16)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa...ash/swflash.cab (Shockwave Flash Object)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)

O18 - Protocol\Handler\lbxfile {56831180-F115-11d2-B6AA-00104B2B9943} - C:\Program Files\Libronix DLS\System\FileProt.dll (Libronix Corporation)

O18 - Protocol\Handler\lbxres {24508F1B-9E94-40EE-9759-9AF5795ADF52} - C:\Program Files\Libronix DLS\System\ResProt.dll (Libronix Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\SYSTEM32\NavLogon.dll (Symantec Corporation)

O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp

O24 - Desktop BackupWallPaper: C:\WINDOWS\DELL.BMP

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2002/09/03 12:36:02 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.001 -- [ NTFS ]

O32 - AutoRun File - [2004/05/28 19:55:33 | 000,000,177 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\wd_windows_tools\setup.exe -- File not found

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found

NetSvcs: Ias - C:\WINDOWS\SYSTEM32\IAS [2004/02/20 22:20:14 | 000,000,000 | ---D | M]

NetSvcs: Iprip - File not found

NetSvcs: Irmon - File not found

NetSvcs: NWCWorkstation - File not found

NetSvcs: Nwsapagent - File not found

NetSvcs: WmdmPmSp - File not found

NetSvcs: Ip6FwHlp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)

Drivers32: msacm.l3acm - C:\WINDOWS\SYSTEM32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)

Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)

Drivers32: msacm.trspch - C:\WINDOWS\System32\TSSOFT32.ACM (DSP GROUP, INC.)

Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)

Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)

Drivers32: vidc.iv31 - C:\WINDOWS\System32\IR32_32.DLL ()

Drivers32: vidc.iv32 - C:\WINDOWS\System32\IR32_32.DLL ()

Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)

Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

Drivers32: wave1 - C:\WINDOWS\System32\SERWVDRV.DLL (Microsoft Corporation)

CREATERESTOREPOINT

Restore point Set: OTL Restore Point (16620634377289728)

========== Files/Folders - Created Within 30 Days ==========

[2010/06/27 11:33:32 | 000,574,464 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\adminfull\Desktop\OTL.com

[2010/06/26 21:49:17 | 000,000,000 | ---D | C] -- C:\sh4ldr

[2010/06/26 21:47:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\6D1E83602F354C848D53C614FBCA621C.TMP

[2010/06/26 21:45:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard

[2010/06/26 21:38:17 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group

[2010/06/26 18:08:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\adminfull\My Documents\CoffeeCup Software

[2010/06/26 18:08:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\adminfull\Application Data\CoffeeCup Software

[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/06/27 11:33:51 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\adminfull\Desktop\OTL.com

[2010/06/27 11:08:04 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

[2010/06/27 10:29:17 | 000,001,493 | ---- | M] () -- C:\Documents and Settings\adminfull\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Explorer.lnk

[2010/06/27 05:10:56 | 015,487,048 | ---- | M] () -- C:\Dir0627-0500.lis

[2010/06/26 23:09:03 | 004,718,592 | -H-- | M] () -- C:\Documents and Settings\adminfull\NTUSER.DAT

[2010/06/26 21:49:41 | 000,001,981 | ---- | M] () -- C:\Documents and Settings\adminfull\Desktop\SpyHunter.lnk

[2010/06/26 21:37:22 | 000,000,616 | ---- | M] () -- C:\Documents and Settings\adminfull\Application Data\wklnhst.dat

[2010/06/26 19:57:59 | 000,001,230 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL

[2010/06/26 18:10:28 | 000,000,013 | ---- | M] () -- C:\WINDOWS\System32\WinSys32.crc

[2010/06/26 18:08:02 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job

[2010/06/26 16:24:36 | 000,520,570 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI

[2010/06/26 16:24:36 | 000,440,488 | ---- | M] () -- C:\WINDOWS\System32\PERFH009.DAT

[2010/06/26 16:24:36 | 000,070,588 | ---- | M] () -- C:\WINDOWS\System32\PERFC009.DAT

[2010/06/26 16:19:50 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT

[2010/06/26 16:19:41 | 000,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT

[2010/06/26 16:19:34 | 1072,762,880 | -HS- | M] () -- C:\hiberfil.sys

[2010/06/26 16:18:44 | 000,056,836 | ---- | M] () -- C:\WINDOWS\WIN.INI

[2010/06/26 15:57:31 | 000,000,440 | RHS- | M] () -- C:\Documents and Settings\adminfull\ntuser.pol

[2010/06/26 15:51:05 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\adminfull\NTUSER.INI

[2010/06/23 20:07:14 | 000,007,113 | ---- | M] () -- C:\WINDOWS\GWSPRO.INI

[2010/06/14 18:05:53 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini

[2010/06/10 11:09:25 | 000,000,028 | ---- | M] () -- C:\WINDOWS\System32\wininet_dll.iss

[2010/06/10 11:09:24 | 000,000,028 | ---- | M] () -- C:\WINDOWS\System32\urlmon_dll.iss

[2010/06/10 11:09:24 | 000,000,028 | ---- | M] () -- C:\WINDOWS\System32\url_dll.iss

[2010/06/10 11:07:17 | 000,762,120 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2010/06/10 10:53:39 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2010/06/06 19:02:55 | 000,025,600 | ---- | M] () -- C:\WINDOWS\System32\MSCOMM32.oca

[2010/06/06 19:02:54 | 000,000,059 | ---- | M] () -- C:\WINDOWS\VBADDIN.INI

[2010/06/01 19:59:12 | 000,000,151 | ---- | M] () -- C:\WINDOWS\PhotoSnapViewer.INI

[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/27 10:29:16 | 000,001,493 | ---- | C] () -- C:\Documents and Settings\adminfull\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Explorer.lnk

[2010/06/27 05:08:24 | 015,487,048 | ---- | C] () -- C:\Dir0627-0500.lis

[2010/06/27 05:03:35 | 000,000,545 | ---- | C] () -- C:\WINDOWS\TXTPAD.PIF

[2010/06/26 21:49:41 | 000,001,981 | ---- | C] () -- C:\Documents and Settings\adminfull\Desktop\SpyHunter.lnk

[2010/06/26 15:57:31 | 000,000,440 | RHS- | C] () -- C:\Documents and Settings\adminfull\ntuser.pol

[2010/06/26 15:37:00 | 1072,762,880 | -HS- | C] () -- C:\hiberfil.sys

[2010/06/06 19:02:55 | 000,025,600 | ---- | C] () -- C:\WINDOWS\System32\MSCOMM32.oca

[2009/10/12 21:48:24 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CDMP_RtfViewer.INI

[2009/10/12 13:08:52 | 000,000,083 | ---- | C] () -- C:\WINDOWS\CDMP_HtmlViewer.INI

[2009/10/11 20:21:03 | 000,000,032 | ---- | C] () -- C:\WINDOWS\CD_Start.INI

[2009/10/03 20:35:51 | 000,000,037 | ---- | C] () -- C:\WINDOWS\Viewer.ini

[2009/09/01 19:12:38 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll

[2009/08/03 16:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll

[2009/02/28 21:55:46 | 000,000,106 | -HS- | C] () -- C:\WINDOWS\WSYS049.SYS

[2009/02/16 22:10:52 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Isdbg.ini

[2009/01/22 22:28:40 | 000,000,395 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI

[2009/01/15 20:39:05 | 000,000,453 | ---- | C] () -- C:\WINDOWS\I_VIEW32.INI

[2008/11/18 20:44:02 | 000,000,067 | ---- | C] () -- C:\WINDOWS\iltwain.ini

[2008/09/28 21:10:59 | 000,004,018 | ---- | C] () -- C:\WINDOWS\logos20.ini

[2008/03/30 18:14:40 | 000,000,214 | ---- | C] () -- C:\WINDOWS\HP_48BitScanUpdatePatch.ini

[2008/03/16 13:28:18 | 000,299,454 | ---- | C] () -- C:\WINDOWS\ALLSIM.INI

[2008/03/16 13:28:18 | 000,061,268 | ---- | C] () -- C:\WINDOWS\BIUTILSM.INI

[2008/03/16 13:28:18 | 000,057,969 | ---- | C] () -- C:\WINDOWS\SIMSIM.INI

[2008/03/16 13:28:18 | 000,000,580 | ---- | C] () -- C:\WINDOWS\Common.ini

[2008/03/16 13:28:17 | 000,051,712 | ---- | C] () -- C:\WINDOWS\System32\ngprtserv.dll

[2008/03/16 13:28:13 | 000,000,645 | ---- | C] () -- C:\WINDOWS\Setupwizard.ini

[2008/01/08 22:16:20 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini

[2007/03/18 18:57:38 | 000,000,041 | ---- | C] () -- C:\WINDOWS\System32\bdacfb3_s.dll

[2007/03/05 22:52:56 | 000,000,070 | ---- | C] () -- C:\WINDOWS\etrack.ini

[2007/03/05 22:37:18 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI

[2007/02/27 18:07:57 | 000,000,161 | ---- | C] () -- C:\WINDOWS\System32\tdbgpp.dll

[2007/02/24 09:42:42 | 000,005,557 | ---- | C] () -- C:\WINDOWS\POWERUP.INI

[2007/01/21 22:42:33 | 000,202,752 | ---- | C] () -- C:\WINDOWS\CDAC14BA.DLL

[2007/01/21 22:42:31 | 000,011,376 | ---- | C] () -- C:\WINDOWS\System32\drivers\CdaC15BA.SYS

[2007/01/21 22:40:59 | 000,001,383 | ---- | C] () -- C:\WINDOWS\MPCWIN02.INI

[2006/12/21 21:45:11 | 000,000,000 | ---- | C] () -- C:\WINDOWS\autorun.INI

[2006/11/21 21:41:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\BWW.INI

[2006/10/18 22:06:54 | 000,000,776 | ---- | C] () -- C:\WINDOWS\CLARIS.INI

[2006/10/18 22:05:08 | 000,001,169 | ---- | C] () -- C:\WINDOWS\ALCHUPDT.INI

[2006/09/08 19:54:34 | 000,000,052 | ---- | C] () -- C:\WINDOWS\cool.ini

[2006/09/08 19:50:46 | 000,000,011 | ---- | C] () -- C:\WINDOWS\wordpad.ini

[2006/08/28 18:10:58 | 000,000,458 | ---- | C] () -- C:\WINDOWS\SIERRA.INI

[2006/08/01 20:22:52 | 000,001,417 | ---- | C] () -- C:\WINDOWS\QfnOnl.ini

[2006/08/01 20:22:51 | 000,000,792 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI

[2006/08/01 20:22:51 | 000,000,052 | ---- | C] () -- C:\WINDOWS\intuprof.ini

[2006/08/01 20:22:49 | 000,000,362 | ---- | C] () -- C:\WINDOWS\QDQICK.INI

[2006/08/01 20:22:49 | 000,000,038 | ---- | C] () -- C:\WINDOWS\ACCWIZ.INI

[2006/02/14 21:30:10 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI

[2006/01/13 22:08:20 | 000,000,052 | ---- | C] () -- C:\WINDOWS\hpqwrap.INI

[2005/12/28 21:06:50 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini

[2005/11/03 20:44:02 | 000,000,042 | ---- | C] () -- C:\WINDOWS\AlchemyMindworksUpdateList.INI

[2005/11/03 20:43:47 | 000,003,784 | ---- | C] () -- C:\WINDOWS\prspro.ini

[2005/09/03 18:57:12 | 000,000,000 | ---- | C] () -- C:\WINDOWS\VPC32.INI

[2005/06/10 20:59:54 | 000,177,152 | ---- | C] () -- C:\WINDOWS\System32\CSGina.dll

[2005/06/10 20:53:52 | 000,163,840 | ---- | C] () -- C:\WINDOWS\System32\vpnapi.dll

[2005/02/10 23:10:06 | 000,000,076 | ---- | C] () -- C:\WINDOWS\ccard100.ini

[2005/02/10 23:09:14 | 000,000,032 | ---- | C] () -- C:\WINDOWS\GRAPH5.INI

[2005/02/10 23:09:10 | 000,007,128 | ---- | C] () -- C:\WINDOWS\MSACC20.INI

[2004/11/28 21:22:14 | 000,000,229 | ---- | C] () -- C:\WINDOWS\cdplayer.ini

[2004/09/14 21:59:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SafeGuard20.INI

[2004/06/30 15:04:46 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\SDelete.dll

[2004/06/27 20:29:17 | 000,000,022 | ---- | C] () -- C:\WINDOWS\kodakpcd.adminron.ini

[2004/06/27 20:17:07 | 000,000,034 | ---- | C] () -- C:\WINDOWS\hpfsched.ini

[2004/06/27 17:38:12 | 000,000,281 | ---- | C] () -- C:\WINDOWS\MATLAB.INI

[2004/05/28 19:55:33 | 000,037,376 | ---- | C] () -- C:\WINDOWS\System32\f90SQLDVF.dll

[2004/05/20 22:56:53 | 000,000,163 | ---- | C] () -- C:\WINDOWS\ed4w.ini

[2004/05/20 22:06:03 | 000,000,073 | ---- | C] () -- C:\WINDOWS\PTMail.INI

[2004/05/19 19:58:13 | 000,041,984 | ---- | C] () -- C:\WINDOWS\System32\aecrm.dll

[2004/05/19 19:47:09 | 000,000,000 | ---- | C] () -- C:\WINDOWS\MTSTACK.INI

[2004/05/07 22:24:41 | 000,000,009 | ---- | C] () -- C:\WINDOWS\WINHLP32.INI

[2004/05/07 22:24:40 | 000,000,009 | ---- | C] () -- C:\WINDOWS\WINHELP.INI

[2004/05/04 20:32:27 | 000,007,113 | ---- | C] () -- C:\WINDOWS\GWSPRO.INI

[2004/05/01 22:54:35 | 000,000,177 | ---- | C] () -- C:\WINDOWS\Winamp.ini

[2004/05/01 19:23:48 | 000,000,138 | ---- | C] () -- C:\WINDOWS\WinInit.ini.backup

[2004/04/28 21:24:11 | 000,000,120 | ---- | C] () -- C:\WINDOWS\setihome.ini

[2004/04/28 11:19:43 | 000,000,131 | ---- | C] () -- C:\WINDOWS\Readiris.ini

[2004/04/28 11:09:54 | 000,000,158 | ---- | C] () -- C:\WINDOWS\pagesuit.ini

[2004/04/28 11:09:52 | 000,023,040 | ---- | C] () -- C:\WINDOWS\System32\irisco32.dll

[2004/03/07 13:51:00 | 000,024,924 | ---- | C] () -- C:\WINDOWS\System32\openports.dll

[2004/03/02 01:36:06 | 000,000,185 | ---- | C] () -- C:\WINDOWS\mdm.ini

[2004/03/02 00:14:53 | 000,000,225 | ---- | C] () -- C:\WINDOWS\netscape.INI

[2004/02/29 22:56:33 | 000,000,010 | ---- | C] () -- C:\WINDOWS\System32\drivers\tmbi.sys

[2004/02/20 23:02:47 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini

[2004/02/20 22:54:59 | 000,001,315 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2004/02/20 22:50:53 | 000,000,138 | ---- | C] () -- C:\WINDOWS\WinInit.ini

[2004/02/20 22:39:16 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll

[2004/02/20 22:39:02 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini

[2004/02/20 22:23:12 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI

[2003/10/16 14:50:50 | 000,000,791 | ---- | C] () -- C:\WINDOWS\ORUN32.INI

[2003/08/13 21:54:00 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini

[2002/11/22 11:50:06 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\hpodinet.dll

[2002/05/29 06:50:02 | 000,552,960 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll

[2001/11/09 14:27:16 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\glut32.dll

[2000/09/08 18:53:50 | 000,073,839 | ---- | C] () -- C:\WINDOWS\System32\KodakOneTouch.dll

[1999/01/22 11:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL

[1998/06/10 01:00:00 | 000,015,120 | ---- | C] () -- C:\WINDOWS\System32\REPUTIL.DLL

[1998/05/18 01:00:00 | 000,014,017 | ---- | C] () -- C:\WINDOWS\JAUTOEXP.INI

[1998/04/24 01:00:00 | 000,000,218 | ---- | C] () -- C:\WINDOWS\FRONTPG.INI

[1997/07/11 00:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\ODBCSTF.DLL

[1997/07/11 00:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL

[1997/05/11 07:20:50 | 000,062,464 | ---- | C] () -- C:\WINDOWS\System32\hs_regex.dll

[1996/11/14 00:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL

[1979/12/31 23:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >

[2002/09/03 12:36:02 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.001

[2004/05/28 19:55:33 | 000,000,177 | ---- | M] () -- C:\AUTOEXEC.BAT

[2010/01/26 09:39:08 | 000,000,211 | RHS- | M] () -- C:\BOOT.INI

[2002/09/03 12:13:28 | 000,000,512 | -HS- | M] () -- C:\BOOTSECT.DOS

[2007/03/05 22:48:20 | 000,000,003 | ---- | M] () -- C:\chkm01.dll

[2002/09/03 12:36:02 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS

[2004/02/20 22:29:50 | 000,006,078 | RH-- | M] () -- C:\DELL.SDR

[2010/06/27 05:10:56 | 015,487,048 | ---- | M] () -- C:\Dir0627-0500.lis

[2007/12/31 19:48:12 | 000,185,344 | ---- | M] () -- C:\Dir1231-09-10.xls

[2007/12/31 19:33:32 | 000,072,748 | ---- | M] () -- C:\Dir1231-0900.txt

[2007/12/31 19:36:10 | 000,132,608 | ---- | M] () -- C:\Dir1231-0900.xls

[2007/12/31 19:39:18 | 000,031,295 | ---- | M] () -- C:\Dir1231-1000.txt

[2007/12/31 19:49:51 | 000,065,536 | ---- | M] () -- C:\Dir1231-1000.xls

[2009/05/10 07:45:01 | 014,956,258 | ---- | M] () -- C:\dirlisAll.lis

[2009/05/13 21:21:52 | 000,565,118 | ---- | M] () -- C:\dirlisH.lis

[2009/05/10 07:41:06 | 000,177,228 | ---- | M] () -- C:\dirlisSH.lis

[2007/12/28 21:26:00 | 000,000,998 | ---- | M] () -- C:\DirList1-BadExe.lis

[2007/12/22 14:48:05 | 000,042,396 | ---- | M] () -- C:\DirSort-Space-Exes.lis

[2007/12/23 15:46:24 | 000,001,209 | ---- | M] () -- C:\DirSort-Space-Files.lis

[2007/12/29 08:41:50 | 000,155,842 | ---- | M] () -- C:\DirSort2-12-28.lis

[2010/02/09 17:09:33 | 000,010,065 | ---- | M] () -- C:\DlgTest.log

[2006/12/27 20:10:38 | 000,056,357 | ---- | M] () -- C:\EasyShare.dmp

[2004/06/27 20:11:46 | 000,529,963 | ---- | M] () -- C:\EasyShareInstall.log

[2010/06/26 16:19:34 | 1072,762,880 | -HS- | M] () -- C:\hiberfil.sys

[2004/06/27 20:35:03 | 000,000,560 | ---- | M] () -- C:\hpfr5550.xml

[2004/06/27 20:35:03 | 000,000,937 | ---- | M] () -- C:\hph7350.log

[2002/09/03 12:36:02 | 000,000,000 | -H-- | M] () -- C:\IO.SYS

[2006/10/15 17:22:21 | 000,001,214 | -H-- | M] () -- C:\IPH.PH

[2006/12/28 17:26:04 | 000,124,928 | ---- | M] () -- C:\KdgnCert-VA501.DOC

[2002/09/03 12:36:02 | 000,000,000 | -H-- | M] () -- C:\MSDOS.SYS

[2008/01/11 22:34:11 | 011,225,941 | ---- | M] () -- C:\New-CdriveDir.lis

[2006/09/02 19:20:50 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM

[2006/09/02 19:20:50 | 000,250,032 | RHS- | M] () -- C:\NTLDR

[2008/01/09 21:38:24 | 010,999,930 | ---- | M] () -- C:\Old-CdriveDir.lis

[2008/01/09 23:18:49 | 011,000,148 | ---- | M] () -- C:\OldCdrive-Sort.lis

[2010/06/26 16:19:32 | 1610,612,736 | -HS- | M] () -- C:\pagefile.sys

[2007/03/05 22:46:02 | 000,000,003 | ---- | M] () -- C:\qzym01.dll

[2010/06/26 21:50:05 | 000,000,392 | ---- | M] () -- C:\sh4_service.log

[2008/03/20 20:26:36 | 000,000,004 | ---- | M] () -- C:\ss_nb.dat

[2008/03/20 20:26:34 | 000,000,004 | ---- | M] () -- C:\ss_udp.dat

[2008/03/20 20:26:34 | 000,000,004 | ---- | M] () -- C:\ss_udp2.dat

[2004/02/20 22:53:45 | 000,000,087 | ---- | M] () -- C:\SystemInfo.ini

[2007/04/19 19:34:46 | 027,262,976 | ---- | M] () -- C:\VIRTPART.DAT

[2005/09/03 18:43:58 | 000,008,056 | -H-- | M] () -- C:\_NavCClt.Log

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

[2004/08/03 22:51:12 | 000,068,768 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\SYSTEM32\mmsystem.dll

[2002/08/29 04:00:00 | 000,005,120 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\WINDOWS\SYSTEM32\SHELL.DLL

[5 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >

[2002/09/03 12:22:52 | 000,094,208 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV

[2002/09/03 12:22:52 | 000,626,688 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV

[2002/09/03 12:22:52 | 000,397,312 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV

< %systemroot%\system32\user32.dll /md5 >

[2007/03/08 08:36:28 | 000,577,536 | ---- | M] (Microsoft Corporation) MD5=B409909F6E2E8A7067076ED748ABF1E7 -- C:\WINDOWS\SYSTEM32\user32.dll

[5 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2_32.dll /md5 >

[2004/08/04 00:56:48 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=2ED0B7F12A60F90092081C50FA0EC2B2 -- C:\WINDOWS\SYSTEM32\ws2_32.dll

[5 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< End of report >

------------------ Ent otl.txt file ------------------------

extras.txt file:

OTL Extras logfile created on: 6/27/2010 11:38:48 AM - Run 1

OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\adminfull\Desktop

Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 7.0.5730.13)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 572.00 Mb Available Physical Memory | 56.00% Memory free

2.00 Gb Paging File | 2.00 Gb Available in Paging File | 85.00% Paging File free

Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 73.84 Gb Total Space | 19.59 Gb Free Space | 26.53% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

Drive E: | 75.17 Gb Total Space | 67.18 Gb Free Space | 89.37% Space Free | Partition Type: NTFS

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: RON3000

Current User Name: adminfull

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: Current user

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Minimal

========== Extra Registry (SafeList) ==========

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.inf [@ = TextPad.inf] -- C:\Program Files\TextPad\TXTPAD32.EXE (Helios Software Solutions)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

exefile [open] -- "%1" %*

htafile [open] -- "%1" %*

htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)

htmlfile [print] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)

Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)

Directory [Winamp.Play] -- "C:\Program Files\Winamp\Winamp.exe" "%1" (Nullsoft)

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"AntiVirusDisableNotify" = 1

"FirewallDisableNotify" = 0

"UpdatesDisableNotify" = 1

"AntiVirusOverride" = 0

"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004

"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005

"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001

"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 0

"DoNotAllowExceptions" = 0

"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004

"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005

"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001

"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"C:\Program Files\ISS\BlackICE\blackice.exe" = C:\Program Files\ISS\BlackICE\blackice.exe:LocalSubNet:Enabled:BlackICE PC Protection -- (Internet Security Systems, Inc.)

"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealOne Player -- (RealNetworks, Inc.)

"C:\Program Files\TurboTax\Deluxe 2006\32bit\ttax.exe" = C:\Program Files\TurboTax\Deluxe 2006\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax -- (Intuit, Inc.)

"C:\Program Files\TurboTax\Deluxe 2006\32bit\updatemgr.exe" = C:\Program Files\TurboTax\Deluxe 2006\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager -- (Intuit, Inc.)

"C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe" = C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax -- (Intuit, Inc.)

"C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe" = C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager -- (Intuit, Inc.)

"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare -- ()

"C:\Ziphold\Pwr-9258\ipEdit-1.exe" = C:\Ziphold\Pwr-9258\ipEdit-1.exe:*:Enabled:ipEdit IPCam Scan Utility -- (Aviosys Inc.)

"C:\Program Files\FileZilla FTP Client\filezilla.exe" = C:\Program Files\FileZilla FTP Client\filezilla.exe:*:Enabled:FileZilla FTP Client -- (FileZilla Project)

"C:\WINDOWS\SYSTEM32\mmc.exe" = C:\WINDOWS\SYSTEM32\mmc.exe:*:Enabled:Microsoft Management Console -- (Microsoft Corporation)

"D:\Setup.exe" = D:\Setup.exe:*:Enabled:Setup Wizard of WAP54G -- File not found

"C:\Program Files\Symantec AntiVirus\VPC32.exe" = C:\Program Files\Symantec AntiVirus\VPC32.exe:LocalSubNet:Enabled:Symantec AntiVirus -- (Symantec Corporation)

"C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe" = C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server -- (Intuit Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{00040409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Disc 2

"{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}" = Notifier

"{04410044-9149-45C6-A806-F2BF9CFCE762}" = Microsoft Encarta Encyclopedia Standard 2004

"{059AE187-404C-47C5-B846-097DAF59DC44}" = Adobe Stock Photos 1.0

"{073F22CE-9A5B-4A40-A604-C7270AC6BF34}" = ESSSONIC

"{085FE193-B676-11D4-82BC-00A0C993905F}" = Thomas Bros. Street Guide Digital Edition

"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager

"{0AD5AD99-6172-4385-8765-385FBE3A1013}" = Sunbelt CounterSpy

"{0F819909-B465-4F8D-B271-EBB1C7E03696}" = CDMenuPro V5

"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center

"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD

"{15F4085A-BC98-4590-AFFD-03BBBE49524E}" = Garmin Communicator Plugin

"{19991EAD-C273-47EB-87E8-0D274925230B}" = OEB Resource Driver

"{1D643CD7-4DD6-11D7-A4E0-000874180BB3}" = Microsoft Money 2004

"{231F68F4-70E4-41A6-BEDA-7E7934169B54}" = Maxtor OneTouch

"{2554D4F3-CB25-4917-863F-198E897D25C6}" = CDMenuPro V6

"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Dell Media Experience

"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java 6 Update 16

"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime

"{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation

"{29D135E8-59AB-4B92-8E7B-9F29D9CC914D}" = Canvas 7

"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt

"{33BEE6F3-9987-4F98-A069-97A64EC8321A}" = Microsoft Works Suite Add-in for Microsoft Word

"{33CFCF98-F8D6-4549-B469-6F4295676D83}" = Symantec AntiVirus

"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page

"{360EDFB0-EAA2-012B-AD16-000000000000}" = TurboTax 2009 wcaiper

"{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset

"{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine

"{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport

"{3A3521B3-5910-4941-A0F6-65E089DA5E85}" = Grade Machine

"{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper

"{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353}" = OTtBPSDK

"{3CA9D105-113C-11D8-AB3E-000102B0F79A}" = Readiris Pro 9

"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting

"{40F3846A-55FB-41BF-8B57-345DFB29B674}" = Screen Shot Deluxe 5.0

"{43FCA273-9534-40DB-B7C5-D7758875616A}" = Dell Support

"{45EBDA59-D33B-433A-956E-B2F236468B56}" = MUSICMATCH

Link to post
Share on other sites

Hello astro3ron and welcome to the forums. ;)

I am jwang01 and I will be assisting you with your issue.

When we get to working on your computer you may want to print out or save my respones in notepad because there may be times were you will not be able to access them here.

Also, please don't attach your logs unless asked, as they can make them hard to read. Just post them as a reply.

Let's see whats going on here.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Custom Scan box paste this in
    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

jwang01,

Here is part two that contains the otl.txt file run out of the bad account where the virus infection occurred. In a previous post I sent you the otl and extras.txt files run out of the good admin account.

Here's the otl.txt run from the bad account. Recall that otl did not generate an extras.txt file in the bad account.

Otl.txt from bad account:

OTL logfile created on: 6/27/2010 11:57:20 AM - Run 2

OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\adminron\Desktop

Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 7.0.5730.13)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 489.00 Mb Available Physical Memory | 48.00% Memory free

2.00 Gb Paging File | 2.00 Gb Available in Paging File | 86.00% Paging File free

Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 73.84 Gb Total Space | 19.54 Gb Free Space | 26.46% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

Drive E: | 75.17 Gb Total Space | 67.18 Gb Free Space | 89.37% Space Free | Partition Type: NTFS

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: RON3000

Current User Name: adminron

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: Current user

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\adminron\Desktop\OTL.com (OldTimer Tools)

PRC - C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)

PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)

PRC - C:\WINDOWS\SYSTEM32\DRIVERS\CDAC11BA.EXE (Macrovision)

PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)

PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)

PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)

PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)

PRC - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)

PRC - C:\Program Files\ISS\BlackICE\Vpatch.exe (Internet Security Systems, Inc.)

PRC - C:\Program Files\ISS\BlackICE\RapApp.exe (Internet Security Systems, Inc.)

PRC - C:\Program Files\ISS\BlackICE\blackd.exe (Internet Security Systems, Inc.)

PRC - C:\Program Files\cisco systems\vpn client\cvpnd.exe (Cisco Systems, Inc.)

PRC - C:\Program Files\Iomega\AutoDisk\ADService.exe (Iomega Corporation)

PRC - C:\Program Files\Iomega\System32\AppServices.exe (Iomega Corporation)

PRC - C:\Program Files\Conversions Plus\FormatM.exe (DataViz Inc.)

PRC - C:\Program Files\WinPoET Broadband Connection\WROS.exe (iVasion, a Routerware Company)

========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\adminron\Desktop\OTL.com (OldTimer Tools)

MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)

MOD - C:\WINDOWS\SYSTEM32\msscript.ocx (Microsoft Corporation)

========== Win32 Services (SafeList) ==========

SRV - (vsmon) -- File not found

SRV - (Iomega Activity Disk2) -- File not found

SRV - (SpyHunter 4 Service) -- C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)

SRV - (IntuitUpdateService) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)

SRV - (Automatic LiveUpdate Scheduler) -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)

SRV - (LiveUpdate) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)

SRV - (C-DillaCdaC11BA) -- C:\WINDOWS\SYSTEM32\DRIVERS\CDAC11BA.EXE (Macrovision)

SRV - (SavRoam) -- C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)

SRV - (Symantec AntiVirus) -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)

SRV - (DefWatch) -- C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)

SRV - (SNDSrvc) -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)

SRV - (ccSetMgr) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)

SRV - (ccEvtMgr) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)

SRV - (SPBBCSvc) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)

SRV - (VPatch) -- C:\Program Files\ISS\BlackICE\Vpatch.exe (Internet Security Systems, Inc.)

SRV - (RapApp) -- C:\Program Files\ISS\BlackICE\RapApp.exe (Internet Security Systems, Inc.)

SRV - (BlackICE) -- C:\Program Files\ISS\BlackICE\blackd.exe (Internet Security Systems, Inc.)

SRV - (CVPND) -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)

SRV - (GhostStartService) -- C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe (Symantec Corporation)

SRV - (NetSvc) -- C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation)

SRV - (Pml Driver HPH11) -- C:\WINDOWS\SYSTEM32\hphipm11.exe (HP)

SRV - (_IOMEGA_ACTIVE_DISK_SERVICE_) -- C:\Program Files\Iomega\AutoDisk\ADService.exe (Iomega Corporation)

SRV - (Iomega App Services) -- C:\Program Files\Iomega\System32\AppServices.exe (Iomega Corporation)

SRV - (Pml Driver HPZ12) -- C:\WINDOWS\SYSTEM32\HPZipm12.exe (HP)

SRV - (MacFormatService) -- C:\Program Files\Conversions Plus\FORMATM.EXE (DataViz Inc.)

SRV - (WinPPPoverEthernet) -- C:\Program Files\WinPoET Broadband Connection\WROS.exe (iVasion, a Routerware Company)

========== Driver Services (SafeList) ==========

DRV - (EraserUtilRebootDrv) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)

DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)

DRV - (NAVEX15) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100626.002\NAVEX15.SYS (Symantec Corporation)

DRV - (NAVENG) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100626.002\NAVENG.SYS (Symantec Corporation)

DRV - (CdaC15BA) -- C:\WINDOWS\SYSTEM32\DRIVERS\CdaC15BA.SYS ()

DRV - (SymEvent) -- C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)

DRV - (SAVRT) -- C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)

DRV - (SAVRTPEL) -- C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)

DRV - (SYMTDI) -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)

DRV - (SYMREDRV) -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)

DRV - (SPBBCDrv) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)

DRV - (BLACK) -- C:\WINDOWS\SYSTEM32\DRIVERS\Blackcat.sys (Internet Security Systems, Inc.)

DRV - (MakoNT) -- C:\WINDOWS\system32\drivers\MakoNT.sys (Internet Security Systems, Inc.)

DRV - (rap) -- C:\WINDOWS\SYSTEM32\DRIVERS\RapDrv.sys (Internet Security Systems, Inc.)

DRV - (CVPNDRVA) -- C:\WINDOWS\SYSTEM32\DRIVERS\CVPNDRVA.sys (Cisco Systems, Inc.)

DRV - (CVirtA) -- C:\WINDOWS\SYSTEM32\DRIVERS\CVirtA.sys (Cisco Systems, Inc.)

DRV - (MxlW2k) -- C:\WINDOWS\SYSTEM32\DRIVERS\MxlW2k.sys (MusicMatch, Inc.)

DRV - (DNE) -- C:\WINDOWS\SYSTEM32\DRIVERS\dne2000.sys (Deterministic Networks, Inc.)

DRV - (AFS2K) -- C:\WINDOWS\SYSTEM32\DRIVERS\AFS2K.SYS (Oak Technology Inc.)

DRV - (MXOPSWD) -- C:\WINDOWS\SYSTEM32\DRIVERS\mxopswd.sys (Maxtor Corp.)

DRV - (amdagp) -- C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)

DRV - (sisagp) -- C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)

DRV - (ppa3) -- C:\WINDOWS\System32\DRIVERS\ppa3.sys (Microsoft Corporation)

DRV - (iAimFP4) -- C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)

DRV - (iAimFP3) -- C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)

DRV - (iAimTV4) -- C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)

DRV - (iAimTV3) -- C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)

DRV - (iAimTV1) -- C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)

DRV - (iAimTV0) -- C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)

DRV - (i81x) -- C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)

DRV - (iAimFP0) -- C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)

DRV - (iAimFP1) -- C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)

DRV - (iAimFP2) -- C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)

DRV - (ati2mtag) -- C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)

DRV - (GhPciScan) -- C:\Program Files\Symantec\Norton Ghost 2003\GhPciScan.sys (Symantec Corporation)

DRV - (Aspi32) -- C:\WINDOWS\SYSTEM32\DRIVERS\ASPI32.SYS (Adaptec)

DRV - (HSFHWBS2) -- C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)

DRV - (winachsf) -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)

DRV - (HSF_DP) -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)

DRV - (nv) -- C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)

DRV - (MXOFX) USB Storage Adapter FX (MXO) -- C:\WINDOWS\SYSTEM32\DRIVERS\MXOFX.SYS (Cypress Semiconductor)

DRV - (MaxtorFrontPanel1) -- C:\WINDOWS\SYSTEM32\DRIVERS\mxofwfp.sys (Maxtor Corp.)

DRV - (RapNet) -- C:\WINDOWS\SYSTEM32\DRIVERS\RapNet.sys (Internet Security Systems, Inc.)

DRV - (RapFile) -- C:\WINDOWS\SYSTEM32\DRIVERS\RapFile.sys (Internet Security Systems, Inc.)

DRV - (Dot4 HPH11) -- C:\WINDOWS\SYSTEM32\DRIVERS\hphid411.sys (HP)

DRV - (Dot4Storage HPH11) Storage Class Driver for IEEE-1284.4 (HPH11) -- C:\WINDOWS\SYSTEM32\DRIVERS\hphs2k11.sys (Hewlett-Packard)

DRV - (Dot4Usb HPH11) -- C:\WINDOWS\SYSTEM32\DRIVERS\hphius11.sys (HP)

DRV - (Dot4Print HPH11) -- C:\WINDOWS\SYSTEM32\DRIVERS\hphipr11.sys (HP)

DRV - (omci) -- C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)

DRV - (PQNTDrv) -- C:\WINDOWS\SYSTEM32\DRIVERS\PQNTDRV.sys (PowerQuest Corporation)

DRV - (iomdisk) -- C:\WINDOWS\System32\DRIVERS\iomdisk.sys (Iomega Corporation)

DRV - (MacOpen) -- C:\WINDOWS\SYSTEM32\DRIVERS\MacOpen.sys (DataViz Inc.)

DRV - (MODEMCSA) -- C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)

DRV - (Sparrow) -- C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)

DRV - (sym_u3) -- C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)

DRV - (sym_hi) -- C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)

DRV - (symc8xx) -- C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)

DRV - (symc810) -- C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)

DRV - (ultra) -- C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)

DRV - (ql12160) -- C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)

DRV - (ql1080) -- C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)

DRV - (ql1280) -- C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)

DRV - (dac2w2k) -- C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)

DRV - (mraid35x) -- C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)

DRV - (asc) -- C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)

DRV - (asc3550) -- C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)

DRV - (AliIde) -- C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)

DRV - (CmdIde) -- C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)

DRV - (EL90XBC) -- C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)

DRV - (EL90X) -- C:\WINDOWS\SYSTEM32\DRIVERS\EL90XND5.SYS (3Com Corporation)

DRV - (WrKPoET2000) -- C:\Program Files\WinPoET Broadband Connection\WrKPoET2000.sys ()

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.jpl.nasa.gov/index.html

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.jpl.nasa.gov/index.html"

FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0

FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/01/08 23:56:21 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/09 14:38:53 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/09 14:38:53 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.24\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/05/26 06:36:40 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.24\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2010/04/08 22:18:38 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Netscape 7.01\Extensions\\Components: C:\Program Files\Netscape\Netscape\Components [2010/06/16 19:36:18 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Netscape 7.01\Extensions\\Plugins: C:\Program Files\Netscape\Netscape\Plugins [2010/05/19 20:19:55 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Netscape 7.1\Extensions\\Components: C:\Program Files\Netscape\Netscape\Components [2010/06/16 19:36:18 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Netscape 7.1\Extensions\\Plugins: C:\Program Files\Netscape\Netscape\Plugins [2010/05/19 20:19:55 | 000,000,000 | ---D | M]

[2009/02/18 20:40:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminron\Application Data\Mozilla\Extensions

[2010/06/10 21:14:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminron\Application Data\Mozilla\Firefox\Profiles\ho27aq9r.default\extensions

[2010/05/27 07:35:15 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\adminron\Application Data\Mozilla\Firefox\Profiles\ho27aq9r.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}

[2009/12/26 22:21:56 | 000,000,000 | ---D | M] (Web Developer) -- C:\Documents and Settings\adminron\Application Data\Mozilla\Firefox\Profiles\ho27aq9r.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}

[2010/06/26 11:51:12 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/06/26 21:50:14 | 000,000,734 | ---- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No CLSID value found.

O3 - HKLM\..\Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - No CLSID value found.

O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)

O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb07.exe (HP)

O4 - HKLM..\Run: [iSUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)

O4 - HKLM..\Run: [iSUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)

O4 - HKLM..\Run: [MacLicense] C:\Program Files\Conversions Plus\MacLic.exe (DataViz Inc.)

O4 - HKLM..\Run: [sunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunServer.exe (Sunbelt Software)

O4 - HKLM..\Run: [Vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe (Hewlett-Packard Co.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Proventia Desktop Agent.lnk = File not found

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk = C:\Program Files\cisco systems\vpn client\vpngui.exe (Cisco Systems, Inc.)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_16.dll (Sun Microsystems, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\ISS\BlackICE\IBE\ICELSP_8.0.675.0.dll (Internet Security Systems, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\ISS\BlackICE\IBE\ICELSP_8.0.675.0.dll (Internet Security Systems, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\ISS\BlackICE\IBE\ICELSP_8.0.675.0.dll (Internet Security Systems, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\ISS\BlackICE\IBE\ICELSP_8.0.675.0.dll (Internet Security Systems, Inc.)

O15 - HKCU\..Trusted Domains: ascensiontorrance.org ([]http in Trusted sites)

O15 - HKCU\..Trusted Domains: att.net ([]http in Trusted sites)

O15 - HKCU\..Trusted Domains: att.net ([]https in Trusted sites)

O15 - HKCU\..Trusted Domains: intuit.com ([]* in Trusted sites)

O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)

O15 - HKCU\..Trusted Domains: sbcglobal.net ([]https in Trusted sites)

O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)

O15 - HKCU\..Trusted Domains: yahoo.com ([clientapps] http in Trusted sites)

O15 - HKCU\..Trusted Domains: yahoo.com ([clientapps] https in Trusted sites)

O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)

O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)

O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} http://downloadcenter.samsung.com/content/...trolLite_EN.cab (DjVuCtl Class)

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab (CKAVWebScan Object)

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/microsoftu...b?1261437161937 (WUWebControl Class)

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu...b?1261437142515 (MUWebControl Class)

O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0...oUploader55.cab (Facebook Photo Uploader 5 Control)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl...indows-i586.cab (Java Plug-in 1.6.0_16)

O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/...8046.9385069444 (Reg Error: Key error.)

O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} http://www.microsoft.com/security/controls.../20/SassCln.CAB (SassCln Object)

O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)

O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} Reg Error: Key error. (Java Plug-in 1.4.0_01)

O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} Reg Error: Key error. (Java Plug-in 1.4.1_02)

O16 - DPF: {CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl...indows-i586.cab (Java Plug-in 1.4.2_18)

O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_16)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_16)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa...ash/swflash.cab (Shockwave Flash Object)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)

O18 - Protocol\Handler\lbxfile {56831180-F115-11d2-B6AA-00104B2B9943} - C:\Program Files\Libronix DLS\System\FileProt.dll (Libronix Corporation)

O18 - Protocol\Handler\lbxres {24508F1B-9E94-40EE-9759-9AF5795ADF52} - C:\Program Files\Libronix DLS\System\ResProt.dll (Libronix Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\SYSTEM32\NavLogon.dll (Symantec Corporation)

O24 - Desktop WallPaper: C:\Documents and Settings\adminron\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\adminron\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2002/09/03 12:36:02 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.001 -- [ NTFS ]

O32 - AutoRun File - [2004/05/28 19:55:33 | 000,000,177 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O33 - MountPoints2\{eef82764-7bc3-11dd-ba9f-000cf1a44182}\Shell\AutoRun\command - "" = F:\wd_windows_tools\setup.exe -- File not found

O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\CD_Start.exe -- File not found

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

O37 - HKCU\...exe [@ = secfile] -- "C:\DOCUME~1\adminron\LOCALS~1\Temp\AUTMGR32.EXE" /START "%1" %* File not found

NetSvcs: 6to4 - File not found

NetSvcs: Ias - C:\WINDOWS\SYSTEM32\IAS [2004/02/20 22:20:14 | 000,000,000 | ---D | M]

NetSvcs: Iprip - File not found

NetSvcs: Irmon - File not found

NetSvcs: NWCWorkstation - File not found

NetSvcs: Nwsapagent - File not found

NetSvcs: WmdmPmSp - File not found

NetSvcs: Ip6FwHlp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)

Drivers32: msacm.l3acm - C:\WINDOWS\SYSTEM32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)

Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)

Drivers32: msacm.trspch - C:\WINDOWS\System32\TSSOFT32.ACM (DSP GROUP, INC.)

Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)

Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)

Drivers32: vidc.iv31 - C:\WINDOWS\System32\IR32_32.DLL ()

Drivers32: vidc.iv32 - C:\WINDOWS\System32\IR32_32.DLL ()

Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)

Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

Drivers32: wave1 - C:\WINDOWS\System32\SERWVDRV.DLL (Microsoft Corporation)

CREATERESTOREPOINT

Restore point Set: OTL Restore Point (54619756233228288)

========== Files/Folders - Created Within 30 Days ==========

[2010/06/27 11:56:18 | 000,574,464 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\adminron\Desktop\OTL.com

[2010/06/26 21:49:17 | 000,000,000 | ---D | C] -- C:\sh4ldr

[2010/06/26 21:47:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\6D1E83602F354C848D53C614FBCA621C.TMP

[2010/06/26 21:45:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard

[2010/06/26 21:38:17 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group

[2010/06/16 14:46:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\adminron\My Documents\Church-web-6-16-10

[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/06/27 11:55:40 | 000,001,230 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL

[2010/06/27 11:55:35 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job

[2010/06/27 11:33:51 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\adminron\Desktop\OTL.com

[2010/06/27 11:08:04 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

[2010/06/27 05:10:56 | 015,487,048 | ---- | M] () -- C:\Dir0627-0500.lis

[2010/06/26 19:44:20 | 008,650,752 | -H-- | M] () -- C:\Documents and Settings\adminron\NTUSER.DAT

[2010/06/26 19:44:20 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\adminron\NTUSER.INI

[2010/06/26 18:19:58 | 000,042,214 | ---- | M] () -- C:\Documents and Settings\adminron\Application Data\wklnhst.dat

[2010/06/26 18:10:28 | 000,000,013 | ---- | M] () -- C:\WINDOWS\System32\WinSys32.crc

[2010/06/26 16:24:36 | 000,520,570 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI

[2010/06/26 16:24:36 | 000,440,488 | ---- | M] () -- C:\WINDOWS\System32\PERFH009.DAT

[2010/06/26 16:24:36 | 000,070,588 | ---- | M] () -- C:\WINDOWS\System32\PERFC009.DAT

[2010/06/26 16:19:50 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT

[2010/06/26 16:19:41 | 000,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT

[2010/06/26 16:19:34 | 1072,762,880 | -HS- | M] () -- C:\hiberfil.sys

[2010/06/26 16:18:44 | 000,056,836 | ---- | M] () -- C:\WINDOWS\WIN.INI

[2010/06/26 15:52:46 | 000,000,440 | RHS- | M] () -- C:\Documents and Settings\adminron\ntuser.pol

[2010/06/23 20:07:14 | 000,007,113 | ---- | M] () -- C:\WINDOWS\GWSPRO.INI

[2010/06/23 08:52:13 | 000,020,992 | ---- | M] () -- C:\Documents and Settings\adminron\My Documents\Sudoku-Numbers-9c.xls

[2010/06/14 18:06:01 | 000,000,065 | ---- | M] () -- C:\Documents and Settings\adminron\default.pls

[2010/06/14 18:05:53 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini

[2010/06/14 18:04:48 | 000,011,776 | ---- | M] () -- C:\Documents and Settings\adminron\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2010/06/10 11:09:25 | 000,000,028 | ---- | M] () -- C:\WINDOWS\System32\wininet_dll.iss

[2010/06/10 11:09:24 | 000,000,028 | ---- | M] () -- C:\WINDOWS\System32\urlmon_dll.iss

[2010/06/10 11:09:24 | 000,000,028 | ---- | M] () -- C:\WINDOWS\System32\url_dll.iss

[2010/06/10 11:07:17 | 000,762,120 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2010/06/10 10:53:39 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2010/06/06 19:02:55 | 000,025,600 | ---- | M] () -- C:\WINDOWS\System32\MSCOMM32.oca

[2010/06/06 19:02:54 | 000,000,059 | ---- | M] () -- C:\WINDOWS\VBADDIN.INI

[2010/06/04 21:12:39 | 000,000,191 | ---- | M] () -- C:\Documents and Settings\adminron\My Documents\DPE.DUS

[2010/06/04 20:55:30 | 000,113,952 | ---- | M] () -- C:\Documents and Settings\adminron\My Documents\rptReg_Checklist_AllSchool.rtf

[2010/06/01 19:59:12 | 000,000,151 | ---- | M] () -- C:\WINDOWS\PhotoSnapViewer.INI

[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/27 05:08:24 | 015,487,048 | ---- | C] () -- C:\Dir0627-0500.lis

[2010/06/27 05:03:35 | 000,000,545 | ---- | C] () -- C:\WINDOWS\TXTPAD.PIF

[2010/06/26 15:52:45 | 000,000,440 | RHS- | C] () -- C:\Documents and Settings\adminron\ntuser.pol

[2010/06/26 15:37:00 | 1072,762,880 | -HS- | C] () -- C:\hiberfil.sys

[2010/06/06 19:02:55 | 000,025,600 | ---- | C] () -- C:\WINDOWS\System32\MSCOMM32.oca

[2010/06/04 20:55:28 | 000,113,952 | ---- | C] () -- C:\Documents and Settings\adminron\My Documents\rptReg_Checklist_AllSchool.rtf

[2009/10/12 21:48:24 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CDMP_RtfViewer.INI

[2009/10/12 13:08:52 | 000,000,083 | ---- | C] () -- C:\WINDOWS\CDMP_HtmlViewer.INI

[2009/10/11 20:21:03 | 000,000,032 | ---- | C] () -- C:\WINDOWS\CD_Start.INI

[2009/10/03 20:35:51 | 000,000,037 | ---- | C] () -- C:\WINDOWS\Viewer.ini

[2009/09/01 19:12:38 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll

[2009/08/03 16:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll

[2009/02/28 21:55:46 | 000,000,106 | -HS- | C] () -- C:\WINDOWS\WSYS049.SYS

[2009/02/16 22:10:52 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Isdbg.ini

[2009/01/22 22:28:40 | 000,000,395 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI

[2009/01/15 20:39:05 | 000,000,453 | ---- | C] () -- C:\WINDOWS\I_VIEW32.INI

[2008/11/18 20:44:02 | 000,000,067 | ---- | C] () -- C:\WINDOWS\iltwain.ini

[2008/09/28 21:10:59 | 000,004,018 | ---- | C] () -- C:\WINDOWS\logos20.ini

[2008/03/30 18:14:40 | 000,000,214 | ---- | C] () -- C:\WINDOWS\HP_48BitScanUpdatePatch.ini

[2008/03/16 13:28:18 | 000,299,454 | ---- | C] () -- C:\WINDOWS\ALLSIM.INI

[2008/03/16 13:28:18 | 000,061,268 | ---- | C] () -- C:\WINDOWS\BIUTILSM.INI

[2008/03/16 13:28:18 | 000,057,969 | ---- | C] () -- C:\WINDOWS\SIMSIM.INI

[2008/03/16 13:28:18 | 000,000,580 | ---- | C] () -- C:\WINDOWS\Common.ini

[2008/03/16 13:28:17 | 000,051,712 | ---- | C] () -- C:\WINDOWS\System32\ngprtserv.dll

[2008/03/16 13:28:13 | 000,000,645 | ---- | C] () -- C:\WINDOWS\Setupwizard.ini

[2008/01/08 22:16:20 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini

[2007/03/18 18:57:38 | 000,000,041 | ---- | C] () -- C:\WINDOWS\System32\bdacfb3_s.dll

[2007/03/05 22:52:56 | 000,000,070 | ---- | C] () -- C:\WINDOWS\etrack.ini

[2007/03/05 22:37:18 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI

[2007/02/27 18:07:57 | 000,000,161 | ---- | C] () -- C:\WINDOWS\System32\tdbgpp.dll

[2007/02/24 09:42:42 | 000,005,557 | ---- | C] () -- C:\WINDOWS\POWERUP.INI

[2007/01/21 22:42:33 | 000,202,752 | ---- | C] () -- C:\WINDOWS\CDAC14BA.DLL

[2007/01/21 22:42:31 | 000,011,376 | ---- | C] () -- C:\WINDOWS\System32\drivers\CdaC15BA.SYS

[2007/01/21 22:40:59 | 000,001,383 | ---- | C] () -- C:\WINDOWS\MPCWIN02.INI

[2006/12/21 21:45:11 | 000,000,000 | ---- | C] () -- C:\WINDOWS\autorun.INI

[2006/11/21 21:41:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\BWW.INI

[2006/10/18 22:06:54 | 000,000,776 | ---- | C] () -- C:\WINDOWS\CLARIS.INI

[2006/10/18 22:05:08 | 000,001,169 | ---- | C] () -- C:\WINDOWS\ALCHUPDT.INI

[2006/09/08 19:54:34 | 000,000,052 | ---- | C] () -- C:\WINDOWS\cool.ini

[2006/09/08 19:50:46 | 000,000,011 | ---- | C] () -- C:\WINDOWS\wordpad.ini

[2006/08/28 18:10:58 | 000,000,458 | ---- | C] () -- C:\WINDOWS\SIERRA.INI

[2006/08/01 20:22:52 | 000,001,417 | ---- | C] () -- C:\WINDOWS\QfnOnl.ini

[2006/08/01 20:22:51 | 000,000,792 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI

[2006/08/01 20:22:51 | 000,000,052 | ---- | C] () -- C:\WINDOWS\intuprof.ini

[2006/08/01 20:22:49 | 000,000,362 | ---- | C] () -- C:\WINDOWS\QDQICK.INI

[2006/08/01 20:22:49 | 000,000,038 | ---- | C] () -- C:\WINDOWS\ACCWIZ.INI

[2006/02/14 21:30:10 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI

[2006/01/13 22:08:20 | 000,000,052 | ---- | C] () -- C:\WINDOWS\hpqwrap.INI

[2005/12/28 21:06:50 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini

[2005/11/03 20:44:02 | 000,000,042 | ---- | C] () -- C:\WINDOWS\AlchemyMindworksUpdateList.INI

[2005/11/03 20:43:47 | 000,003,784 | ---- | C] () -- C:\WINDOWS\prspro.ini

[2005/09/03 18:57:12 | 000,000,000 | ---- | C] () -- C:\WINDOWS\VPC32.INI

[2005/06/10 20:59:54 | 000,177,152 | ---- | C] () -- C:\WINDOWS\System32\CSGina.dll

[2005/06/10 20:53:52 | 000,163,840 | ---- | C] () -- C:\WINDOWS\System32\vpnapi.dll

[2005/02/10 23:10:06 | 000,000,076 | ---- | C] () -- C:\WINDOWS\ccard100.ini

[2005/02/10 23:09:14 | 000,000,032 | ---- | C] () -- C:\WINDOWS\GRAPH5.INI

[2005/02/10 23:09:10 | 000,007,128 | ---- | C] () -- C:\WINDOWS\MSACC20.INI

[2004/11/28 21:22:14 | 000,000,229 | ---- | C] () -- C:\WINDOWS\cdplayer.ini

[2004/09/14 21:59:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SafeGuard20.INI

[2004/06/30 15:04:46 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\SDelete.dll

[2004/06/27 20:29:17 | 000,000,022 | ---- | C] () -- C:\WINDOWS\kodakpcd.adminron.ini

[2004/06/27 20:17:07 | 000,000,034 | ---- | C] () -- C:\WINDOWS\hpfsched.ini

[2004/06/27 17:38:12 | 000,000,281 | ---- | C] () -- C:\WINDOWS\MATLAB.INI

[2004/05/28 19:55:33 | 000,037,376 | ---- | C] () -- C:\WINDOWS\System32\f90SQLDVF.dll

[2004/05/20 22:56:53 | 000,000,163 | ---- | C] () -- C:\WINDOWS\ed4w.ini

[2004/05/20 22:06:03 | 000,000,073 | ---- | C] () -- C:\WINDOWS\PTMail.INI

[2004/05/19 19:58:13 | 000,041,984 | ---- | C] () -- C:\WINDOWS\System32\aecrm.dll

[2004/05/19 19:47:09 | 000,000,000 | ---- | C] () -- C:\WINDOWS\MTSTACK.INI

[2004/05/07 22:24:41 | 000,000,009 | ---- | C] () -- C:\WINDOWS\WINHLP32.INI

[2004/05/07 22:24:40 | 000,000,009 | ---- | C] () -- C:\WINDOWS\WINHELP.INI

[2004/05/04 20:32:27 | 000,007,113 | ---- | C] () -- C:\WINDOWS\GWSPRO.INI

[2004/05/01 22:54:35 | 000,000,177 | ---- | C] () -- C:\WINDOWS\Winamp.ini

[2004/05/01 19:23:48 | 000,000,138 | ---- | C] () -- C:\WINDOWS\WinInit.ini.backup

[2004/04/28 21:24:11 | 000,000,120 | ---- | C] () -- C:\WINDOWS\setihome.ini

[2004/04/28 11:19:43 | 000,000,131 | ---- | C] () -- C:\WINDOWS\Readiris.ini

[2004/04/28 11:09:54 | 000,000,158 | ---- | C] () -- C:\WINDOWS\pagesuit.ini

[2004/04/28 11:09:52 | 000,023,040 | ---- | C] () -- C:\WINDOWS\System32\irisco32.dll

[2004/03/07 13:51:00 | 000,024,924 | ---- | C] () -- C:\WINDOWS\System32\openports.dll

[2004/03/02 01:36:06 | 000,000,185 | ---- | C] () -- C:\WINDOWS\mdm.ini

[2004/03/02 00:14:53 | 000,000,225 | ---- | C] () -- C:\WINDOWS\netscape.INI

[2004/02/29 22:56:33 | 000,000,010 | ---- | C] () -- C:\WINDOWS\System32\drivers\tmbi.sys

[2004/02/20 23:02:47 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini

[2004/02/20 22:54:59 | 000,001,315 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2004/02/20 22:50:53 | 000,000,138 | ---- | C] () -- C:\WINDOWS\WinInit.ini

[2004/02/20 22:39:16 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll

[2004/02/20 22:39:02 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini

[2004/02/20 22:23:12 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI

[2003/10/16 14:50:50 | 000,000,791 | ---- | C] () -- C:\WINDOWS\ORUN32.INI

[2003/08/13 21:54:00 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini

[2002/11/22 11:50:06 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\hpodinet.dll

[2002/05/29 06:50:02 | 000,552,960 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll

[2001/11/09 14:27:16 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\glut32.dll

[2000/09/08 18:53:50 | 000,073,839 | ---- | C] () -- C:\WINDOWS\System32\KodakOneTouch.dll

[1999/01/22 11:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL

[1998/06/10 01:00:00 | 000,015,120 | ---- | C] () -- C:\WINDOWS\System32\REPUTIL.DLL

[1998/05/18 01:00:00 | 000,014,017 | ---- | C] () -- C:\WINDOWS\JAUTOEXP.INI

[1998/04/24 01:00:00 | 000,000,218 | ---- | C] () -- C:\WINDOWS\FRONTPG.INI

[1997/07/11 00:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\ODBCSTF.DLL

[1997/07/11 00:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL

[1997/05/11 07:20:50 | 000,062,464 | ---- | C] () -- C:\WINDOWS\System32\hs_regex.dll

[1996/11/14 00:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL

[1979/12/31 23:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >

[2002/09/03 12:36:02 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.001

[2004/05/28 19:55:33 | 000,000,177 | ---- | M] () -- C:\AUTOEXEC.BAT

[2010/01/26 09:39:08 | 000,000,211 | RHS- | M] () -- C:\BOOT.INI

[2002/09/03 12:13:28 | 000,000,512 | -HS- | M] () -- C:\BOOTSECT.DOS

[2007/03/05 22:48:20 | 000,000,003 | ---- | M] () -- C:\chkm01.dll

[2002/09/03 12:36:02 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS

[2004/02/20 22:29:50 | 000,006,078 | RH-- | M] () -- C:\DELL.SDR

[2010/06/27 05:10:56 | 015,487,048 | ---- | M] () -- C:\Dir0627-0500.lis

[2007/12/31 19:48:12 | 000,185,344 | ---- | M] () -- C:\Dir1231-09-10.xls

[2007/12/31 19:33:32 | 000,072,748 | ---- | M] () -- C:\Dir1231-0900.txt

[2007/12/31 19:36:10 | 000,132,608 | ---- | M] () -- C:\Dir1231-0900.xls

[2007/12/31 19:39:18 | 000,031,295 | ---- | M] () -- C:\Dir1231-1000.txt

[2007/12/31 19:49:51 | 000,065,536 | ---- | M] () -- C:\Dir1231-1000.xls

[2009/05/10 07:45:01 | 014,956,258 | ---- | M] () -- C:\dirlisAll.lis

[2009/05/13 21:21:52 | 000,565,118 | ---- | M] () -- C:\dirlisH.lis

[2009/05/10 07:41:06 | 000,177,228 | ---- | M] () -- C:\dirlisSH.lis

[2007/12/28 21:26:00 | 000,000,998 | ---- | M] () -- C:\DirList1-BadExe.lis

[2007/12/22 14:48:05 | 000,042,396 | ---- | M] () -- C:\DirSort-Space-Exes.lis

[2007/12/23 15:46:24 | 000,001,209 | ---- | M] () -- C:\DirSort-Space-Files.lis

[2007/12/29 08:41:50 | 000,155,842 | ---- | M] () -- C:\DirSort2-12-28.lis

[2010/02/09 17:09:33 | 000,010,065 | ---- | M] () -- C:\DlgTest.log

[2006/12/27 20:10:38 | 000,056,357 | ---- | M] () -- C:\EasyShare.dmp

[2004/06/27 20:11:46 | 000,529,963 | ---- | M] () -- C:\EasyShareInstall.log

[2010/06/26 16:19:34 | 1072,762,880 | -HS- | M] () -- C:\hiberfil.sys

[2004/06/27 20:35:03 | 000,000,560 | ---- | M] () -- C:\hpfr5550.xml

[2004/06/27 20:35:03 | 000,000,937 | ---- | M] () -- C:\hph7350.log

[2002/09/03 12:36:02 | 000,000,000 | -H-- | M] () -- C:\IO.SYS

[2006/10/15 17:22:21 | 000,001,214 | -H-- | M] () -- C:\IPH.PH

[2006/12/28 17:26:04 | 000,124,928 | ---- | M] () -- C:\KdgnCert-VA501.DOC

[2002/09/03 12:36:02 | 000,000,000 | -H-- | M] () -- C:\MSDOS.SYS

[2008/01/11 22:34:11 | 011,225,941 | ---- | M] () -- C:\New-CdriveDir.lis

[2006/09/02 19:20:50 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM

[2006/09/02 19:20:50 | 000,250,032 | RHS- | M] () -- C:\NTLDR

[2008/01/09 21:38:24 | 010,999,930 | ---- | M] () -- C:\Old-CdriveDir.lis

[2008/01/09 23:18:49 | 011,000,148 | ---- | M] () -- C:\OldCdrive-Sort.lis

[2010/06/26 16:19:32 | 1610,612,736 | -HS- | M] () -- C:\pagefile.sys

[2007/03/05 22:46:02 | 000,000,003 | ---- | M] () -- C:\qzym01.dll

[2010/06/26 21:50:05 | 000,000,392 | ---- | M] () -- C:\sh4_service.log

[2008/03/20 20:26:36 | 000,000,004 | ---- | M] () -- C:\ss_nb.dat

[2008/03/20 20:26:34 | 000,000,004 | ---- | M] () -- C:\ss_udp.dat

[2008/03/20 20:26:34 | 000,000,004 | ---- | M] () -- C:\ss_udp2.dat

[2004/02/20 22:53:45 | 000,000,087 | ---- | M] () -- C:\SystemInfo.ini

[2007/04/19 19:34:46 | 027,262,976 | ---- | M] () -- C:\VIRTPART.DAT

[2005/09/03 18:43:58 | 000,008,056 | -H-- | M] () -- C:\_NavCClt.Log

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

[5 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >

[2002/09/03 12:22:52 | 000,094,208 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV

[2002/09/03 12:22:52 | 000,626,688 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV

[2002/09/03 12:22:52 | 000,397,312 | ---- | M] () -- C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV

< %systemroot%\system32\user32.dll /md5 >

[2007/03/08 08:36:28 | 000,577,536 | ---- | M] (Microsoft Corporation) MD5=B409909F6E2E8A7067076ED748ABF1E7 -- C:\WINDOWS\SYSTEM32\user32.dll

[5 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2_32.dll /md5 >

[2004/08/04 00:56:48 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=2ED0B7F12A60F90092081C50FA0EC2B2 -- C:\WINDOWS\SYSTEM32\ws2_32.dll

[5 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< End of report >

Link to post
Share on other sites

Hello,

You only get the extras.txt with OTL's first run, unless you selct to have it. But thats ok, the first one is enough. ;)

Go ahead and run this in the infected account. After this fix, you should be able to run all EXE files.

Run OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O37 - HKCU\...exe [@ = secfile] -- "C:\DOCUME~1\adminron\LOCALS~1\Temp\AUTMGR32.EXE" /START "%1" %* File not found
    [2010/06/26 18:19:58 | 000,042,214 | ---- | M] () -- C:\Documents and Settings\adminron\Application Data\wklnhst.dat
    [2010/06/10 11:09:25 | 000,000,028 | ---- | M] () -- C:\WINDOWS\System32\wininet_dll.iss
    [2010/06/10 11:09:24 | 000,000,028 | ---- | M] () -- C:\WINDOWS\System32\urlmon_dll.iss
    [2010/06/10 11:09:24 | 000,000,028 | ---- | M] () -- C:\WINDOWS\System32\url_dll.iss
    [2009/02/28 21:55:46 | 000,000,106 | -HS- | C] () -- C:\WINDOWS\WSYS049.SYS
    [2010/06/26 21:49:17 | 000,000,000 | ---D | C] -- C:\sh4ldr
    [2010/06/26 21:47:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\6D1E83602F354C848D53C614FBCA621C.TMP

    :Services

    :Reg

    :Files

    :Commands
    [purity]
    [emptyflash]
    [emptytemp]
    [Reboot]


  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

Next

Download GMER from Here. Note the file's name and save it to your root folder, such as C:\.

  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security program drivers will not conflict with this file.
  • Click on this link to see a list of programs that should be disabled.
  • Double-click on the downloaded file to start the program. (If running Vista, right click on it and select "Run as an Administrator")
  • Allow the driver to load if asked.
  • You may be prompted to scan immediately if it detects rootkit activity.
  • If you are prompted to scan your system click "No", save the log and post back the results.
  • If not prompted, click the "Rootkit/Malware" tab.
  • On the right-side, all items to be scanned should be checked by default except for "Show All". Leave that box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click the Scan button to begin. (Please be patient as it can take some time to complete)
  • When the scan is finished, click Save to save the scan results to your Desktop.
  • Save the file as Results.log and copy/paste the contents in your next reply.
  • Exit the program and re-enable all active protection when done.

Please post the logs of OTL and GMER in your next reply.

Link to post
Share on other sites

Hello,

You only get the extras.txt with OTL's first run, unless you selct to have it. But thats ok, the first one is enough. :)

Go ahead and run this in the infected account. After this fix, you should be able to run all EXE files.

Run OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O37 - HKCU\...exe [@ = secfile] -- "C:\DOCUME~1\adminron\LOCALS~1\Temp\AUTMGR32.EXE" /START "%1" %* File not found
    [2010/06/26 18:19:58 | 000,042,214 | ---- | M] () -- C:\Documents and Settings\adminron\Application Data\wklnhst.dat
    [2010/06/10 11:09:25 | 000,000,028 | ---- | M] () -- C:\WINDOWS\System32\wininet_dll.iss
    [2010/06/10 11:09:24 | 000,000,028 | ---- | M] () -- C:\WINDOWS\System32\urlmon_dll.iss
    [2010/06/10 11:09:24 | 000,000,028 | ---- | M] () -- C:\WINDOWS\System32\url_dll.iss
    [2009/02/28 21:55:46 | 000,000,106 | -HS- | C] () -- C:\WINDOWS\WSYS049.SYS
    [2010/06/26 21:49:17 | 000,000,000 | ---D | C] -- C:\sh4ldr
    [2010/06/26 21:47:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\6D1E83602F354C848D53C614FBCA621C.TMP

    :Services

    :Reg

    :Files

    :Commands
    [purity]
    [emptyflash]
    [emptytemp]
    [Reboot]


  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

Next

Download GMER from Here. Note the file's name and save it to your root folder, such as C:\.

  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security program drivers will not conflict with this file.
  • Click on this link to see a list of programs that should be disabled.
  • Double-click on the downloaded file to start the program. (If running Vista, right click on it and select "Run as an Administrator")
  • Allow the driver to load if asked.
  • You may be prompted to scan immediately if it detects rootkit activity.
  • If you are prompted to scan your system click "No", save the log and post back the results.
  • If not prompted, click the "Rootkit/Malware" tab.
  • On the right-side, all items to be scanned should be checked by default except for "Show All". Leave that box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click the Scan button to begin. (Please be patient as it can take some time to complete)
  • When the scan is finished, click Save to save the scan results to your Desktop.
  • Save the file as Results.log and copy/paste the contents in your next reply.
  • Exit the program and re-enable all active protection when done.

Please post the logs of OTL and GMER in your next reply.

Well, jwang01, that did the trick. Exes are working again. Looks like there was an automgr32.exe running from the registry or did I miss something from the last code paste?

Anyway, after pasting the info from above into otl and running Run Fix, I got the following log file displayed in notepad after the reboot. Then I ran OTL again and got the attached scan file results.

I then ran GMER. It was running fine, but when I came back I found the machine had rebooted. Any reason why?

So I logged back into the adminron account and reran GMER. Prior to running GMER, I closed all running programs, a version of a company firewall and disabled NAV Corp Ed. AV. After I started GMER again, I did a ctrl-alt-del, and it seemed like GMER came to a grinding halt, was going real slow compared to what it was doing earlier. Probably shouldn't have done the C-A-D thing... Anyway, rebooted the maching, did the disable stuff and restarted GMER. It seemed to be running real slow compared to before, (file checks showing at the bottom of the GMER screen). So I decided to stop it and send you these log files and see if I stuffed something up by stopping GMER in the middle. Comments???

Anyway, here's the two log files, 06272010_192259-PostOTLClean.log, captured right after the fix run and OTL-Adminron-PostFix.Txt saved after the OTL scan.

--------------------- 06272010_192259-PostOTLClean.log

All processes killed

========== OTL ==========

Process explorer.exe killed successfully!

Registry key HKEY_CURRENT_USER\Software\Classes\.exe\ deleted successfully.

Registry key HKEY_CURRENT_USER\Software\Classes\secfile\ deleted successfully.

HKEY_LOCAL_MACHINE\Software\Classes\.exe\\|exefile /E : value set successfully!

C:\Documents and Settings\adminron\Application Data\wklnhst.dat moved successfully.

C:\WINDOWS\SYSTEM32\wininet_dll.iss moved successfully.

C:\WINDOWS\SYSTEM32\urlmon_dll.iss moved successfully.

C:\WINDOWS\SYSTEM32\url_dll.iss moved successfully.

C:\WINDOWS\WSYS049.SYS moved successfully.

C:\sh4ldr folder moved successfully.

C:\WINDOWS\6D1E83602F354C848D53C614FBCA621C.TMP folder moved successfully.

========== SERVICES/DRIVERS ==========

========== REGISTRY ==========

========== FILES ==========

========== COMMANDS ==========

[EMPTYFLASH]

User: adminfull

->Flash cache emptied: 8707 bytes

User: Administrator

User: adminron

->Flash cache emptied: 20155 bytes

User: adminron1

->Flash cache emptied: 41 bytes

User: All Users

User: carol

->Flash cache emptied: 5128 bytes

User: Default User

->Flash cache emptied: 41 bytes

User: LocalService

User: mark

->Flash cache emptied: 14633 bytes

User: NetworkService

Total Flash Files Cleaned = 0.00 mb

[EMPTYTEMP]

User: adminfull

->Temp folder emptied: 24586 bytes

->Temporary Internet Files folder emptied: 26525007 bytes

->Java cache emptied: 56132 bytes

->Flash cache emptied: 0 bytes

User: Administrator

->Temp folder emptied: 4259934 bytes

->Temporary Internet Files folder emptied: 151762 bytes

User: adminron

->Temp folder emptied: 3006614 bytes

->Temporary Internet Files folder emptied: 243540 bytes

->Java cache emptied: 28646596 bytes

->FireFox cache emptied: 90422543 bytes

->Flash cache emptied: 0 bytes

User: adminron1

->Temp folder emptied: 946 bytes

->Temporary Internet Files folder emptied: 397414 bytes

->Flash cache emptied: 0 bytes

User: All Users

User: carol

->Temp folder emptied: 443165 bytes

->Temporary Internet Files folder emptied: 31807446 bytes

->Java cache emptied: 388950 bytes

->FireFox cache emptied: 33560354 bytes

->Flash cache emptied: 0 bytes

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 32768 bytes

->Flash cache emptied: 0 bytes

User: LocalService

->Temp folder emptied: 66016 bytes

->Temporary Internet Files folder emptied: 190750 bytes

User: mark

->Temp folder emptied: 166708 bytes

->Temporary Internet Files folder emptied: 79058 bytes

->Java cache emptied: 10423002 bytes

->Flash cache emptied: 0 bytes

User: NetworkService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 19528 bytes

%systemroot%\System32 .tmp files removed: 2832913 bytes

%systemroot%\System32\dllcache .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 152887 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes

RecycleBin emptied: 0 bytes

Total Files Cleaned = 223.00 mb

OTL by OldTimer - Version 3.2.7.0 log created on 06272010_192259

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

------------------- OTL-Adminron-PostFix.Txt --------------

OTL logfile created on: 6/27/2010 7:32:58 PM - Run 3

OTL by OldTimer - Version 3.2.7.0 Folder = C:\Documents and Settings\adminron\Desktop

Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 7.0.5730.13)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 439.00 Mb Available Physical Memory | 43.00% Memory free

2.00 Gb Paging File | 2.00 Gb Available in Paging File | 86.00% Paging File free

Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 73.84 Gb Total Space | 19.73 Gb Free Space | 26.72% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

Drive E: | 75.17 Gb Total Space | 67.18 Gb Free Space | 89.37% Space Free | Partition Type: NTFS

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: RON3000

Current User Name: adminron

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: Current user

Company Name Whitelist: On

Skip Microsoft Files: On

File Age = 90 Days

Output = Minimal

Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\adminron\Desktop\OTL.com (OldTimer Tools)

PRC - C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)

PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)

PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)

PRC - C:\WINDOWS\SYSTEM32\DRIVERS\CDAC11BA.EXE (Macrovision)

PRC - C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)

PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)

PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)

PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)

PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)

PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)

PRC - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)

PRC - C:\Program Files\ISS\BlackICE\blackice.exe (Internet Security Systems, Inc.)

PRC - C:\Program Files\ISS\BlackICE\Vpatch.exe (Internet Security Systems, Inc.)

PRC - C:\Program Files\ISS\BlackICE\RapApp.exe (Internet Security Systems, Inc.)

PRC - C:\Program Files\ISS\BlackICE\blackd.exe (Internet Security Systems, Inc.)

PRC - C:\Program Files\cisco systems\vpn client\cvpnd.exe (Cisco Systems, Inc.)

PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)

PRC - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe (Symantec Corporation)

PRC - C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)

PRC - C:\Program Files\Iomega\AutoDisk\ADService.exe (Iomega Corporation)

PRC - C:\Program Files\Iomega\System32\AppServices.exe (Iomega Corporation)

PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe (Hewlett-Packard Co.)

PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe (Hewlett-Packard Co.)

PRC - C:\Program Files\Conversions Plus\FormatM.exe (DataViz Inc.)

PRC - C:\Program Files\Microsoft Office\Office10\MSOFFICE.EXE (Microsoft Corporation)

PRC - C:\Program Files\WinPoET Broadband Connection\WROS.exe (iVasion, a Routerware Company)

========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\adminron\Desktop\OTL.com (OldTimer Tools)

MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)

MOD - C:\WINDOWS\SYSTEM32\msscript.ocx (Microsoft Corporation)

========== Win32 Services (SafeList) ==========

SRV - (vsmon) -- File not found

SRV - (VPatch) -- File not found

SRV - (RapApp) -- File not found

SRV - (Iomega Activity Disk2) -- File not found

SRV - (BlackICE) -- File not found

SRV - (SpyHunter 4 Service) -- C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)

SRV - (IntuitUpdateService) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)

SRV - (Automatic LiveUpdate Scheduler) -- C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)

SRV - (LiveUpdate) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)

SRV - (C-DillaCdaC11BA) -- C:\WINDOWS\SYSTEM32\DRIVERS\CDAC11BA.EXE (Macrovision)

SRV - (SavRoam) -- C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)

SRV - (Symantec AntiVirus) -- C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)

SRV - (DefWatch) -- C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)

SRV - (SNDSrvc) -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)

SRV - (ccSetMgr) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)

SRV - (ccEvtMgr) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)

SRV - (SPBBCSvc) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)

SRV - (CVPND) -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)

SRV - (GhostStartService) -- C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe (Symantec Corporation)

SRV - (NetSvc) -- C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation)

SRV - (Pml Driver HPH11) -- C:\WINDOWS\SYSTEM32\hphipm11.exe (HP)

SRV - (_IOMEGA_ACTIVE_DISK_SERVICE_) -- C:\Program Files\Iomega\AutoDisk\ADService.exe (Iomega Corporation)

SRV - (Iomega App Services) -- C:\Program Files\Iomega\System32\AppServices.exe (Iomega Corporation)

SRV - (Pml Driver HPZ12) -- C:\WINDOWS\SYSTEM32\HPZipm12.exe (HP)

SRV - (MacFormatService) -- C:\Program Files\Conversions Plus\FORMATM.EXE (DataViz Inc.)

SRV - (WinPPPoverEthernet) -- C:\Program Files\WinPoET Broadband Connection\WROS.exe (iVasion, a Routerware Company)

========== Driver Services (SafeList) ==========

DRV - (EraserUtilRebootDrv) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)

DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)

DRV - (NAVEX15) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100626.002\NAVEX15.SYS (Symantec Corporation)

DRV - (NAVENG) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20100626.002\NAVENG.SYS (Symantec Corporation)

DRV - (CdaC15BA) -- C:\WINDOWS\SYSTEM32\DRIVERS\CdaC15BA.SYS ()

DRV - (SymEvent) -- C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)

DRV - (SAVRT) -- C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)

DRV - (SAVRTPEL) -- C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)

DRV - (SYMTDI) -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)

DRV - (SYMREDRV) -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)

DRV - (SPBBCDrv) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)

DRV - (BLACK) -- C:\WINDOWS\SYSTEM32\DRIVERS\Blackcat.sys (Internet Security Systems, Inc.)

DRV - (MakoNT) -- C:\WINDOWS\system32\drivers\MakoNT.sys (Internet Security Systems, Inc.)

DRV - (rap) -- C:\WINDOWS\SYSTEM32\DRIVERS\RapDrv.sys (Internet Security Systems, Inc.)

DRV - (CVPNDRVA) -- C:\WINDOWS\SYSTEM32\DRIVERS\CVPNDRVA.sys (Cisco Systems, Inc.)

DRV - (CVirtA) -- C:\WINDOWS\SYSTEM32\DRIVERS\CVirtA.sys (Cisco Systems, Inc.)

DRV - (MxlW2k) -- C:\WINDOWS\SYSTEM32\DRIVERS\MxlW2k.sys (MusicMatch, Inc.)

DRV - (DNE) -- C:\WINDOWS\SYSTEM32\DRIVERS\dne2000.sys (Deterministic Networks, Inc.)

DRV - (AFS2K) -- C:\WINDOWS\SYSTEM32\DRIVERS\AFS2K.SYS (Oak Technology Inc.)

DRV - (MXOPSWD) -- C:\WINDOWS\SYSTEM32\DRIVERS\mxopswd.sys (Maxtor Corp.)

DRV - (amdagp) -- C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)

DRV - (sisagp) -- C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)

DRV - (ppa3) -- C:\WINDOWS\System32\DRIVERS\ppa3.sys (Microsoft Corporation)

DRV - (iAimFP4) -- C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)

DRV - (iAimFP3) -- C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)

DRV - (iAimTV4) -- C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)

DRV - (iAimTV3) -- C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)

DRV - (iAimTV1) -- C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)

DRV - (iAimTV0) -- C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)

DRV - (i81x) -- C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)

DRV - (iAimFP0) -- C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)

DRV - (iAimFP1) -- C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)

DRV - (iAimFP2) -- C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)

DRV - (ati2mtag) -- C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)

DRV - (GhPciScan) -- C:\Program Files\Symantec\Norton Ghost 2003\GhPciScan.sys (Symantec Corporation)

DRV - (Aspi32) -- C:\WINDOWS\SYSTEM32\DRIVERS\ASPI32.SYS (Adaptec)

DRV - (HSFHWBS2) -- C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)

DRV - (winachsf) -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)

DRV - (HSF_DP) -- C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)

DRV - (nv) -- C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)

DRV - (MXOFX) USB Storage Adapter FX (MXO) -- C:\WINDOWS\SYSTEM32\DRIVERS\MXOFX.SYS (Cypress Semiconductor)

DRV - (MaxtorFrontPanel1) -- C:\WINDOWS\SYSTEM32\DRIVERS\mxofwfp.sys (Maxtor Corp.)

DRV - (RapNet) -- C:\WINDOWS\SYSTEM32\DRIVERS\RapNet.sys (Internet Security Systems, Inc.)

DRV - (RapFile) -- C:\WINDOWS\SYSTEM32\DRIVERS\RapFile.sys (Internet Security Systems, Inc.)

DRV - (Dot4 HPH11) -- C:\WINDOWS\SYSTEM32\DRIVERS\hphid411.sys (HP)

DRV - (Dot4Storage HPH11) Storage Class Driver for IEEE-1284.4 (HPH11) -- C:\WINDOWS\SYSTEM32\DRIVERS\hphs2k11.sys (Hewlett-Packard)

DRV - (Dot4Usb HPH11) -- C:\WINDOWS\SYSTEM32\DRIVERS\hphius11.sys (HP)

DRV - (Dot4Print HPH11) -- C:\WINDOWS\SYSTEM32\DRIVERS\hphipr11.sys (HP)

DRV - (omci) -- C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)

DRV - (PQNTDrv) -- C:\WINDOWS\SYSTEM32\DRIVERS\PQNTDRV.sys (PowerQuest Corporation)

DRV - (iomdisk) -- C:\WINDOWS\System32\DRIVERS\iomdisk.sys (Iomega Corporation)

DRV - (MacOpen) -- C:\WINDOWS\SYSTEM32\DRIVERS\MacOpen.sys (DataViz Inc.)

DRV - (MODEMCSA) -- C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)

DRV - (Sparrow) -- C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)

DRV - (sym_u3) -- C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)

DRV - (sym_hi) -- C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)

DRV - (symc8xx) -- C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)

DRV - (symc810) -- C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)

DRV - (ultra) -- C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)

DRV - (ql12160) -- C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)

DRV - (ql1080) -- C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)

DRV - (ql1280) -- C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)

DRV - (dac2w2k) -- C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)

DRV - (mraid35x) -- C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)

DRV - (asc) -- C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)

DRV - (asc3550) -- C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)

DRV - (AliIde) -- C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)

DRV - (CmdIde) -- C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)

DRV - (EL90XBC) -- C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)

DRV - (EL90X) -- C:\WINDOWS\SYSTEM32\DRIVERS\EL90XND5.SYS (3Com Corporation)

DRV - (WrKPoET2000) -- C:\Program Files\WinPoET Broadband Connection\WrKPoET2000.sys ()

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.jpl.nasa.gov/index.html

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.jpl.nasa.gov/index.html"

FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0

FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/01/08 23:56:21 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/09 14:38:53 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/09 14:38:53 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.24\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/05/26 06:36:40 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.24\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2010/04/08 22:18:38 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Netscape 7.01\Extensions\\Components: C:\Program Files\Netscape\Netscape\Components [2010/06/16 19:36:18 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Netscape 7.01\Extensions\\Plugins: C:\Program Files\Netscape\Netscape\Plugins [2010/05/19 20:19:55 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Netscape 7.1\Extensions\\Components: C:\Program Files\Netscape\Netscape\Components [2010/06/16 19:36:18 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Netscape 7.1\Extensions\\Plugins: C:\Program Files\Netscape\Netscape\Plugins [2010/05/19 20:19:55 | 000,000,000 | ---D | M]

[2009/02/18 20:40:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminron\Application Data\Mozilla\Extensions

[2010/06/10 21:14:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminron\Application Data\Mozilla\Firefox\Profiles\ho27aq9r.default\extensions

[2010/05/27 07:35:15 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\adminron\Application Data\Mozilla\Firefox\Profiles\ho27aq9r.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}

[2009/12/26 22:21:56 | 000,000,000 | ---D | M] (Web Developer) -- C:\Documents and Settings\adminron\Application Data\Mozilla\Firefox\Profiles\ho27aq9r.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}

[2010/06/26 11:51:12 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/06/26 21:50:14 | 000,000,734 | ---- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No CLSID value found.

O3 - HKLM\..\Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - No CLSID value found.

O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)

O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb07.exe (HP)

O4 - HKLM..\Run: [iSUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)

O4 - HKLM..\Run: [iSUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)

O4 - HKLM..\Run: [MacLicense] C:\Program Files\Conversions Plus\MacLic.exe (DataViz Inc.)

O4 - HKLM..\Run: [sunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunServer.exe (Sunbelt Software)

O4 - HKLM..\Run: [Vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe (Hewlett-Packard Co.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Proventia Desktop Agent.lnk = File not found

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk = C:\Program Files\cisco systems\vpn client\vpngui.exe (Cisco Systems, Inc.)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)

O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_16.dll (Sun Microsystems, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\ISS\BlackICE\IBE\ICELSP_8.0.675.0.dll (Internet Security Systems, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\ISS\BlackICE\IBE\ICELSP_8.0.675.0.dll (Internet Security Systems, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\ISS\BlackICE\IBE\ICELSP_8.0.675.0.dll (Internet Security Systems, Inc.)

O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\ISS\BlackICE\IBE\ICELSP_8.0.675.0.dll (Internet Security Systems, Inc.)

O15 - HKCU\..Trusted Domains: ascensiontorrance.org ([]http in Trusted sites)

O15 - HKCU\..Trusted Domains: att.net ([]http in Trusted sites)

O15 - HKCU\..Trusted Domains: att.net ([]https in Trusted sites)

O15 - HKCU\..Trusted Domains: intuit.com ([]* in Trusted sites)

O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)

O15 - HKCU\..Trusted Domains: sbcglobal.net ([]https in Trusted sites)

O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)

O15 - HKCU\..Trusted Domains: yahoo.com ([clientapps] http in Trusted sites)

O15 - HKCU\..Trusted Domains: yahoo.com ([clientapps] https in Trusted sites)

O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)

O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)

O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} http://downloadcenter.samsung.com/content/...trolLite_EN.cab (DjVuCtl Class)

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab (CKAVWebScan Object)

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/microsoftu...b?1261437161937 (WUWebControl Class)

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu...b?1261437142515 (MUWebControl Class)

O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0...oUploader55.cab (Facebook Photo Uploader 5 Control)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl...indows-i586.cab (Java Plug-in 1.6.0_16)

O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/...8046.9385069444 (Reg Error: Key error.)

O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} http://www.microsoft.com/security/controls.../20/SassCln.CAB (SassCln Object)

O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)

O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} Reg Error: Key error. (Java Plug-in 1.4.0_01)

O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} Reg Error: Key error. (Java Plug-in 1.4.1_02)

O16 - DPF: {CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl...indows-i586.cab (Java Plug-in 1.4.2_18)

O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_16)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_16)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa...ash/swflash.cab (Shockwave Flash Object)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)

O18 - Protocol\Handler\lbxfile {56831180-F115-11d2-B6AA-00104B2B9943} - C:\Program Files\Libronix DLS\System\FileProt.dll (Libronix Corporation)

O18 - Protocol\Handler\lbxres {24508F1B-9E94-40EE-9759-9AF5795ADF52} - C:\Program Files\Libronix DLS\System\ResProt.dll (Libronix Corporation)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\SYSTEM32\NavLogon.dll (Symantec Corporation)

O24 - Desktop WallPaper: C:\Documents and Settings\adminron\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\adminron\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2002/09/03 12:36:02 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.001 -- [ NTFS ]

O32 - AutoRun File - [2004/05/28 19:55:33 | 000,000,177 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O33 - MountPoints2\{eef82764-7bc3-11dd-ba9f-000cf1a44182}\Shell\AutoRun\command - "" = F:\wd_windows_tools\setup.exe -- File not found

O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\CD_Start.exe -- File not found

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2010/06/27 19:22:59 | 000,000,000 | ---D | C] -- C:\_OTL

[2010/06/27 11:56:18 | 000,574,464 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\adminron\Desktop\OTL.com

[2010/06/26 21:45:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard

[2010/06/26 21:38:17 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group

[2010/06/16 14:46:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\adminron\My Documents\Church-web-6-16-10

[2010/05/19 20:14:49 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java

[2010/05/16 14:03:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\adminron\Application Data\Amazon

[2010/05/16 14:02:53 | 000,000,000 | ---D | C] -- C:\Program Files\Amazon

[2010/05/14 10:39:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Real

[2010/04/16 21:05:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\adminron\My Documents\wireless

[2010/04/08 21:50:05 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple

[2010/04/08 21:49:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\adminron\Local Settings\Application Data\Apple

[2010/04/08 21:49:21 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update

[2010/04/08 21:49:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple

========== Files - Modified Within 90 Days ==========

[2010/06/27 19:31:25 | 000,520,570 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI

[2010/06/27 19:31:25 | 000,440,488 | ---- | M] () -- C:\WINDOWS\System32\PERFH009.DAT

[2010/06/27 19:31:25 | 000,070,588 | ---- | M] () -- C:\WINDOWS\System32\PERFC009.DAT

[2010/06/27 19:27:43 | 000,000,028 | ---- | M] () -- C:\WINDOWS\System32\wininet_dll.iss

[2010/06/27 19:27:41 | 000,000,028 | ---- | M] () -- C:\WINDOWS\System32\urlmon_dll.iss

[2010/06/27 19:27:41 | 000,000,028 | ---- | M] () -- C:\WINDOWS\System32\url_dll.iss

[2010/06/27 19:27:38 | 000,001,230 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL

[2010/06/27 19:26:47 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job

[2010/06/27 19:26:42 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT

[2010/06/27 19:26:32 | 000,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT

[2010/06/27 19:26:26 | 1072,762,880 | -HS- | M] () -- C:\hiberfil.sys

[2010/06/27 19:25:36 | 008,650,752 | -H-- | M] () -- C:\Documents and Settings\adminron\NTUSER.DAT

[2010/06/27 19:25:36 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\adminron\NTUSER.INI

[2010/06/27 19:08:01 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

[2010/06/27 19:07:27 | 000,293,376 | ---- | M] () -- C:\nptrjpei.exe

[2010/06/27 13:51:14 | 000,056,840 | ---- | M] () -- C:\WINDOWS\WIN.INI

[2010/06/27 11:33:51 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\adminron\Desktop\OTL.com

[2010/06/27 05:10:56 | 015,487,048 | ---- | M] () -- C:\Dir0627-0500.lis

[2010/06/26 18:10:28 | 000,000,013 | ---- | M] () -- C:\WINDOWS\System32\WinSys32.crc

[2010/06/26 15:52:46 | 000,000,440 | RHS- | M] () -- C:\Documents and Settings\adminron\ntuser.pol

[2010/06/23 20:07:14 | 000,007,113 | ---- | M] () -- C:\WINDOWS\GWSPRO.INI

[2010/06/23 08:52:13 | 000,020,992 | ---- | M] () -- C:\Documents and Settings\adminron\My Documents\Sudoku-Numbers-9c.xls

[2010/06/14 18:06:01 | 000,000,065 | ---- | M] () -- C:\Documents and Settings\adminron\default.pls

[2010/06/14 18:05:53 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini

[2010/06/14 18:04:48 | 000,011,776 | ---- | M] () -- C:\Documents and Settings\adminron\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2010/06/10 11:07:17 | 000,762,120 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2010/06/10 10:53:39 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2010/06/06 19:02:55 | 000,025,600 | ---- | M] () -- C:\WINDOWS\System32\MSCOMM32.oca

[2010/06/06 19:02:54 | 000,000,059 | ---- | M] () -- C:\WINDOWS\VBADDIN.INI

[2010/06/04 21:12:39 | 000,000,191 | ---- | M] () -- C:\Documents and Settings\adminron\My Documents\DPE.DUS

[2010/06/04 20:55:30 | 000,113,952 | ---- | M] () -- C:\Documents and Settings\adminron\My Documents\rptReg_Checklist_AllSchool.rtf

[2010/06/01 19:59:12 | 000,000,151 | ---- | M] () -- C:\WINDOWS\PhotoSnapViewer.INI

[2010/05/25 18:46:05 | 000,000,177 | ---- | M] () -- C:\WINDOWS\Winamp.ini

[2010/05/16 17:15:49 | 000,001,915 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk

[2010/05/16 14:10:32 | 000,000,252 | ---- | M] () -- C:\WINDOWS\SYSTEM.INI

[2010/05/06 16:37:00 | 000,000,041 | ---- | M] () -- C:\WINDOWS\System32\eafdff0_s.ocx

[2010/05/06 16:37:00 | 000,000,041 | ---- | M] () -- C:\WINDOWS\System32\bdacfb3_s.dll

[2010/05/05 06:54:55 | 000,001,169 | ---- | M] () -- C:\WINDOWS\ALCHUPDT.INI

[2010/04/30 19:03:01 | 000,001,315 | ---- | M] () -- C:\WINDOWS\ODBC.INI

[2010/04/30 19:03:00 | 000,012,992 | ---- | M] () -- C:\Documents and Settings\adminron\Application Data\Microsoft Excel.CAL

[2010/04/30 18:59:21 | 000,011,264 | ---- | M] () -- C:\Documents and Settings\adminron\My Documents\TestExport.xls

[2010/04/30 18:56:14 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\adminron\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Outlook.lnk

[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys

[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2010/04/29 11:33:40 | 000,019,968 | ---- | M] () -- C:\Documents and Settings\adminron\My Documents\For-LBT-Alvina.doc

[2010/04/19 15:08:17 | 000,020,992 | ---- | M] () -- C:\Documents and Settings\adminron\My Documents\Virginia Frisch funeral bulletin.doc

[2010/04/11 07:03:16 | 000,039,936 | ---- | M] () -- C:\Documents and Settings\adminron\My Documents\Renegade Tri.xls

========== Files Created - No Company Name ==========

[2010/06/27 19:27:42 | 000,000,028 | ---- | C] () -- C:\WINDOWS\System32\wininet_dll.iss

[2010/06/27 19:27:41 | 000,000,028 | ---- | C] () -- C:\WINDOWS\System32\urlmon_dll.iss

[2010/06/27 19:27:41 | 000,000,028 | ---- | C] () -- C:\WINDOWS\System32\url_dll.iss

[2010/06/27 19:18:10 | 000,293,376 | ---- | C] () -- C:\nptrjpei.exe

[2010/06/27 05:08:24 | 015,487,048 | ---- | C] () -- C:\Dir0627-0500.lis

[2010/06/27 05:03:35 | 000,000,545 | ---- | C] () -- C:\WINDOWS\TXTPAD.PIF

[2010/06/26 15:52:45 | 000,000,440 | RHS- | C] () -- C:\Documents and Settings\adminron\ntuser.pol

[2010/06/26 15:37:00 | 1072,762,880 | -HS- | C] () -- C:\hiberfil.sys

[2010/06/06 19:02:55 | 000,025,600 | ---- | C] () -- C:\WINDOWS\System32\MSCOMM32.oca

[2010/06/04 20:55:28 | 000,113,952 | ---- | C] () -- C:\Documents and Settings\adminron\My Documents\rptReg_Checklist_AllSchool.rtf

[2010/05/16 17:15:49 | 000,001,915 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk

[2010/04/30 18:59:19 | 000,012,992 | ---- | C] () -- C:\Documents and Settings\adminron\Application Data\Microsoft Excel.CAL

[2010/04/30 18:58:46 | 000,011,264 | ---- | C] () -- C:\Documents and Settings\adminron\My Documents\TestExport.xls

[2010/04/30 18:56:14 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\adminron\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Outlook.lnk

[2010/04/29 11:33:40 | 000,019,968 | ---- | C] () -- C:\Documents and Settings\adminron\My Documents\For-LBT-Alvina.doc

[2010/04/19 15:08:16 | 000,020,992 | ---- | C] () -- C:\Documents and Settings\adminron\My Documents\Virginia Frisch funeral bulletin.doc

[2010/04/11 07:03:07 | 000,039,936 | ---- | C] () -- C:\Documents and Settings\adminron\My Documents\Renegade Tri.xls

[2009/10/12 21:48:24 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CDMP_RtfViewer.INI

[2009/10/12 13:08:52 | 000,000,083 | ---- | C] () -- C:\WINDOWS\CDMP_HtmlViewer.INI

[2009/10/11 20:21:03 | 000,000,032 | ---- | C] () -- C:\WINDOWS\CD_Start.INI

[2009/10/03 20:35:51 | 000,000,037 | ---- | C] () -- C:\WINDOWS\Viewer.ini

[2009/09/01 19:12:38 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll

[2009/08/03 16:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll

[2009/02/16 22:10:52 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Isdbg.ini

[2009/01/22 22:28:40 | 000,000,395 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI

[2009/01/15 20:39:05 | 000,000,453 | ---- | C] () -- C:\WINDOWS\I_VIEW32.INI

[2008/11/18 20:44:02 | 000,000,067 | ---- | C] () -- C:\WINDOWS\iltwain.ini

[2008/09/28 21:10:59 | 000,004,018 | ---- | C] () -- C:\WINDOWS\logos20.ini

[2008/03/30 18:14:40 | 000,000,214 | ---- | C] () -- C:\WINDOWS\HP_48BitScanUpdatePatch.ini

[2008/03/16 13:28:18 | 000,299,454 | ---- | C] () -- C:\WINDOWS\ALLSIM.INI

[2008/03/16 13:28:18 | 000,061,268 | ---- | C] () -- C:\WINDOWS\BIUTILSM.INI

[2008/03/16 13:28:18 | 000,057,969 | ---- | C] () -- C:\WINDOWS\SIMSIM.INI

[2008/03/16 13:28:18 | 000,000,580 | ---- | C] () -- C:\WINDOWS\Common.ini

[2008/03/16 13:28:17 | 000,051,712 | ---- | C] () -- C:\WINDOWS\System32\ngprtserv.dll

[2008/03/16 13:28:13 | 000,000,645 | ---- | C] () -- C:\WINDOWS\Setupwizard.ini

[2008/01/08 22:16:20 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini

[2007/03/18 18:57:38 | 000,000,041 | ---- | C] () -- C:\WINDOWS\System32\bdacfb3_s.dll

[2007/03/05 22:52:56 | 000,000,070 | ---- | C] () -- C:\WINDOWS\etrack.ini

[2007/03/05 22:37:18 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI

[2007/02/27 18:07:57 | 000,000,161 | ---- | C] () -- C:\WINDOWS\System32\tdbgpp.dll

[2007/02/24 09:42:42 | 000,005,557 | ---- | C] () -- C:\WINDOWS\POWERUP.INI

[2007/01/21 22:42:33 | 000,202,752 | ---- | C] () -- C:\WINDOWS\CDAC14BA.DLL

[2007/01/21 22:42:31 | 000,011,376 | ---- | C] () -- C:\WINDOWS\System32\drivers\CdaC15BA.SYS

[2007/01/21 22:40:59 | 000,001,383 | ---- | C] () -- C:\WINDOWS\MPCWIN02.INI

[2006/12/21 21:45:11 | 000,000,000 | ---- | C] () -- C:\WINDOWS\autorun.INI

[2006/11/21 21:41:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\BWW.INI

[2006/10/18 22:06:54 | 000,000,776 | ---- | C] () -- C:\WINDOWS\CLARIS.INI

[2006/10/18 22:05:08 | 000,001,169 | ---- | C] () -- C:\WINDOWS\ALCHUPDT.INI

[2006/09/08 19:54:34 | 000,000,052 | ---- | C] () -- C:\WINDOWS\cool.ini

[2006/09/08 19:50:46 | 000,000,011 | ---- | C] () -- C:\WINDOWS\wordpad.ini

[2006/08/28 18:10:58 | 000,000,458 | ---- | C] () -- C:\WINDOWS\SIERRA.INI

[2006/08/01 20:22:52 | 000,001,417 | ---- | C] () -- C:\WINDOWS\QfnOnl.ini

[2006/08/01 20:22:51 | 000,000,792 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI

[2006/08/01 20:22:51 | 000,000,052 | ---- | C] () -- C:\WINDOWS\intuprof.ini

[2006/08/01 20:22:49 | 000,000,362 | ---- | C] () -- C:\WINDOWS\QDQICK.INI

[2006/08/01 20:22:49 | 000,000,038 | ---- | C] () -- C:\WINDOWS\ACCWIZ.INI

[2006/02/14 21:30:10 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI

[2006/01/13 22:08:20 | 000,000,052 | ---- | C] () -- C:\WINDOWS\hpqwrap.INI

[2005/12/28 21:06:50 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini

[2005/11/03 20:44:02 | 000,000,042 | ---- | C] () -- C:\WINDOWS\AlchemyMindworksUpdateList.INI

[2005/11/03 20:43:47 | 000,003,784 | ---- | C] () -- C:\WINDOWS\prspro.ini

[2005/09/03 18:57:12 | 000,000,000 | ---- | C] () -- C:\WINDOWS\VPC32.INI

[2005/06/10 20:59:54 | 000,177,152 | ---- | C] () -- C:\WINDOWS\System32\CSGina.dll

[2005/06/10 20:53:52 | 000,163,840 | ---- | C] () -- C:\WINDOWS\System32\vpnapi.dll

[2005/02/10 23:10:06 | 000,000,076 | ---- | C] () -- C:\WINDOWS\ccard100.ini

[2005/02/10 23:09:14 | 000,000,032 | ---- | C] () -- C:\WINDOWS\GRAPH5.INI

[2005/02/10 23:09:10 | 000,007,128 | ---- | C] () -- C:\WINDOWS\MSACC20.INI

[2004/11/28 21:22:14 | 000,000,229 | ---- | C] () -- C:\WINDOWS\cdplayer.ini

[2004/09/14 21:59:44 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SafeGuard20.INI

[2004/06/30 15:04:46 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\SDelete.dll

[2004/06/27 20:29:17 | 000,000,022 | ---- | C] () -- C:\WINDOWS\kodakpcd.adminron.ini

[2004/06/27 20:17:07 | 000,000,034 | ---- | C] () -- C:\WINDOWS\hpfsched.ini

[2004/06/27 17:38:12 | 000,000,281 | ---- | C] () -- C:\WINDOWS\MATLAB.INI

[2004/05/28 19:55:33 | 000,037,376 | ---- | C] () -- C:\WINDOWS\System32\f90SQLDVF.dll

[2004/05/20 22:56:53 | 000,000,163 | ---- | C] () -- C:\WINDOWS\ed4w.ini

[2004/05/20 22:06:03 | 000,000,073 | ---- | C] () -- C:\WINDOWS\PTMail.INI

[2004/05/19 19:58:13 | 000,041,984 | ---- | C] () -- C:\WINDOWS\System32\aecrm.dll

[2004/05/19 19:47:09 | 000,000,000 | ---- | C] () -- C:\WINDOWS\MTSTACK.INI

[2004/05/07 22:24:41 | 000,000,009 | ---- | C] () -- C:\WINDOWS\WINHLP32.INI

[2004/05/07 22:24:40 | 000,000,009 | ---- | C] () -- C:\WINDOWS\WINHELP.INI

[2004/05/04 20:32:27 | 000,007,113 | ---- | C] () -- C:\WINDOWS\GWSPRO.INI

[2004/05/01 22:54:35 | 000,000,177 | ---- | C] () -- C:\WINDOWS\Winamp.ini

[2004/05/01 19:23:48 | 000,000,138 | ---- | C] () -- C:\WINDOWS\WinInit.ini.backup

[2004/04/28 21:24:11 | 000,000,120 | ---- | C] () -- C:\WINDOWS\setihome.ini

[2004/04/28 11:19:43 | 000,000,131 | ---- | C] () -- C:\WINDOWS\Readiris.ini

[2004/04/28 11:09:54 | 000,000,158 | ---- | C] () -- C:\WINDOWS\pagesuit.ini

[2004/04/28 11:09:52 | 000,023,040 | ---- | C] () -- C:\WINDOWS\System32\irisco32.dll

[2004/03/07 13:51:00 | 000,024,924 | ---- | C] () -- C:\WINDOWS\System32\openports.dll

[2004/03/02 01:36:06 | 000,000,185 | ---- | C] () -- C:\WINDOWS\mdm.ini

[2004/03/02 00:14:53 | 000,000,225 | ---- | C] () -- C:\WINDOWS\netscape.INI

[2004/02/29 22:56:33 | 000,000,010 | ---- | C] () -- C:\WINDOWS\System32\drivers\tmbi.sys

[2004/02/20 23:02:47 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini

[2004/02/20 22:54:59 | 000,001,315 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2004/02/20 22:50:53 | 000,000,138 | ---- | C] () -- C:\WINDOWS\WinInit.ini

[2004/02/20 22:39:16 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll

[2004/02/20 22:39:02 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini

[2004/02/20 22:23:12 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI

[2003/10/16 14:50:50 | 000,000,791 | ---- | C] () -- C:\WINDOWS\ORUN32.INI

[2003/08/13 21:54:00 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini

[2002/11/22 11:50:06 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\hpodinet.dll

[2002/05/29 06:50:02 | 000,552,960 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll

[2001/11/09 14:27:16 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\glut32.dll

[2000/09/08 18:53:50 | 000,073,839 | ---- | C] () -- C:\WINDOWS\System32\KodakOneTouch.dll

[1999/01/22 11:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL

[1998/06/10 01:00:00 | 000,015,120 | ---- | C] () -- C:\WINDOWS\System32\REPUTIL.DLL

[1998/05/18 01:00:00 | 000,014,017 | ---- | C] () -- C:\WINDOWS\JAUTOEXP.INI

[1998/04/24 01:00:00 | 000,000,218 | ---- | C] () -- C:\WINDOWS\FRONTPG.INI

[1997/07/11 00:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\ODBCSTF.DLL

[1997/07/11 00:00:00 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL

[1997/05/11 07:20:50 | 000,062,464 | ---- | C] () -- C:\WINDOWS\System32\hs_regex.dll

[1996/11/14 00:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL

[1979/12/31 23:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll

========== LOP Check ==========

[2008/03/30 18:15:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminron\Application Data\$CUERoot$

[2004/05/04 20:31:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminron\Application Data\Active Disk

[2010/05/16 14:03:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminron\Application Data\Amazon

[2010/02/16 19:55:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminron\Application Data\CoffeeCup Software

[2006/09/16 21:41:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminron\Application Data\Desktop Software

[2010/06/16 15:14:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminron\Application Data\FileZilla

[2009/11/29 13:47:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminron\Application Data\GARMIN

[2006/09/26 21:40:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminron\Application Data\Genie-soft

[2004/02/29 23:48:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminron\Application Data\Leadertech

[2008/10/15 21:37:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminron\Application Data\Libronix DLS

[2008/10/04 16:26:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminron\Application Data\OfficeUpdate12

[2006/01/23 22:34:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminron\Application Data\Opera

[2009/01/22 22:43:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminron\Application Data\ScanSoft

[2005/02/05 18:25:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminron\Application Data\Scooter Software

[2005/02/13 20:51:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminron\Application Data\spweng

[2006/10/18 22:34:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminron\Application Data\Thunderbird

[2009/01/22 22:43:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\adminron\Application Data\Zeon

[2008/11/20 19:27:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FileCenter

[2008/10/15 21:12:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Libronix DLS

[2009/01/22 22:28:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft

[2007/02/19 20:07:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint

[2009/10/11 18:53:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{EC7E3C85-113D-4981-8BAD-E545E4BFEF75}

[2009/06/14 21:00:59 | 000,000,348 | ---- | M] () -- C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 2200 series#1237001639.job

========== Purity Check ==========

< End of report >

Link to post
Share on other sites

Hello,

GMER don't like to run on some computers. You could try unchecking the sections tab and see if that helps. :)

Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1

Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    automgr32.exe


  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.

Note: The log can also be found on your Desktop entitled SystemLook.txt

Next

Download ComboFix from one of these locations:

Link 1

Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

RcAuto1.gif

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

whatnext.png

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Please post the log of SystemLook and ComboFix in your next reply.

Link to post
Share on other sites

Hello,

GMER don't like to run on some computers. You could try unchecking the sections tab and see if that helps. :)

Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1

Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    automgr32.exe


  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.

Note: The log can also be found on your Desktop entitled SystemLook.txt

Next

Download ComboFix from one of these locations:

Link 1

Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

RcAuto1.gif

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

whatnext.png

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Please post the log of SystemLook and ComboFix in your next reply.

What does SystemLook and ComboFix do? I did a regedit search and file search for automgr32.exe and found nothing. Did you mean autmgr32.exe, as that's a system file in windows/system32? There is an entry in HKEY_USERS\S-1-5-21-3242676782-1459987966-1782763977-1006\Software\Microsoft\Windows\ShellNoRoam\MUICache and HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache for C:\DOCUME~1\adminron\LOCALS~1\Temp\AUTMGR32.EXE

Thanks, Ron

autmgr32.exe

Link to post
Share on other sites

Hello,

Ok, go ahead and skip the SystemLook step, but please run ComboFix. ComboFix is another we sometimes use in Malware Removal. :D

OK, ran ComboFix. Couple of questions. Included ComboFix Quarantine file text:

General question on all of these, what triggered these files to be quarantined?

C:\Qoobox\Quarantine\Registry_backups\MSConfigStartUp-updateMgr.reg.dat

C:\Qoobox\Quarantine\Registry_backups\MSConfigStartUp-swg.reg.dat

C:\Qoobox\Quarantine\Registry_backups\MSConfigStartUp-HPHUPD04.reg.dat

C:\Qoobox\Quarantine\Registry_backups\tcpip.reg

C:\Qoobox\Quarantine\catchme.log

C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\bdacfb3_s.dll.vir

C:\Qoobox\Quarantine\C\Documents and Settings\adminron\Start Menu\Lahey ED Developer .lnk.vir Why was this removed?? THis is/was a valid lnk to Lahey Fortran developer. I can still get to it, but curious as to why it was tagged.

C:\Qoobox\Quarantine\C\WINDOWS\WINHELP.INI.vir

C:\Qoobox\Quarantine\C\WINDOWS\XPSP1HFM.LOG.vir

Here's the ComboFix log:

ComboFix 10-06-28.01 - adminron 06/29/2010 11:43:20.1.1 - x86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.424 [GMT -7:00]

Running from: c:\documents and settings\adminron\Desktop\ComboFix.exe

AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

FW: Proventia Desktop *enabled* {73198F12-4C15-41ED-9303-1EF5FEC6BBA4}

FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\documents and settings\adminron\Start Menu\Lahey ED Developer .lnk

c:\windows\system32\bdacfb3_s.dll

c:\windows\winhelp.ini

c:\windows\xpsp1hfm.log

.

((((((((((((((((((((((((( Files Created from 2010-05-28 to 2010-06-29 )))))))))))))))))))))))))))))))

.

2010-06-28 02:22 . 2010-06-28 02:22 -------- d-----w- C:\_OTL

2010-06-28 02:18 . 2010-06-28 02:07 293376 ----a-w- C:\nptrjpei.exe

2010-06-27 19:28 . 2010-06-27 19:28 -------- d-----w- c:\documents and settings\adminfull\Application Data\Scooter Software

2010-06-27 12:03 . 1998-02-15 10:21 545 ----a-w- c:\windows\TXTPAD.PIF

2010-06-27 04:49 . 2010-06-27 04:49 110080 ----a-r- c:\documents and settings\adminfull\Application Data\Microsoft\Installer\{6D1E8360-2F35-4C84-8D53-C614FBCA621C}\IconD7F16134.exe

2010-06-27 04:49 . 2010-06-27 04:49 110080 ----a-r- c:\documents and settings\adminfull\Application Data\Microsoft\Installer\{6D1E8360-2F35-4C84-8D53-C614FBCA621C}\IconF7A21AF7.exe

2010-06-27 04:45 . 2010-06-27 04:45 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard

2010-06-27 04:38 . 2010-06-27 04:38 -------- d-----w- c:\program files\Enigma Software Group

2010-06-27 02:58 . 2010-06-27 02:58 -------- d-----w- c:\documents and settings\adminron1\Local Settings\Application Data\Symantec

2010-06-27 01:08 . 2010-06-27 01:08 -------- d-----w- c:\documents and settings\adminfull\Application Data\CoffeeCup Software

2010-06-26 19:17 . 2010-06-26 19:17 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes

2010-06-26 19:07 . 2010-06-26 19:07 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Symantec

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-06-29 18:37 . 2008-02-01 07:39 -------- d-----w- c:\program files\Symantec AntiVirus

2010-06-29 18:25 . 2006-10-19 05:31 -------- d-----w- c:\program files\Mozilla Thunderbird

2010-06-28 15:09 . 2004-03-01 05:43 -------- d-----w- c:\program files\WinPoET Broadband Connection

2010-06-27 12:03 . 2004-03-01 06:27 -------- d-----w- c:\program files\TextPad

2010-06-27 04:37 . 2009-02-12 04:33 616 ----a-w- c:\documents and settings\adminfull\Application Data\wklnhst.dat

2010-06-27 01:08 . 2009-02-26 05:15 -------- d-----w- c:\program files\CoffeeCup Software

2010-06-16 22:14 . 2009-01-24 21:33 -------- d-----w- c:\documents and settings\adminron\Application Data\FileZilla

2010-06-16 21:39 . 2009-01-24 21:33 -------- d-----w- c:\program files\FileZilla FTP Client

2010-05-26 13:36 . 2010-05-26 13:36 -------- d-----w- c:\documents and settings\adminfull\Application Data\Thunderbird

2010-05-20 08:00 . 2009-04-30 05:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-05-20 03:19 . 2004-02-21 05:22 -------- d-----w- c:\program files\Java

2010-05-20 03:14 . 2010-05-20 03:14 -------- d-----w- c:\program files\Common Files\Java

2010-05-17 00:15 . 2005-11-27 01:22 -------- d-----w- c:\program files\Google

2010-05-16 21:03 . 2010-05-16 21:03 -------- d-----w- c:\documents and settings\adminron\Application Data\Amazon

2010-05-16 21:02 . 2010-05-16 21:02 -------- d-----w- c:\program files\Amazon

2010-05-04 17:20 . 2006-04-28 17:58 832512 ----a-w- c:\windows\system32\wininet.dll

2010-05-04 17:20 . 2006-09-03 02:31 78336 ----a-w- c:\windows\system32\ieencode.dll

2010-05-04 17:20 . 2002-08-29 11:00 17408 ----a-w- c:\windows\system32\corpol.dll

2010-04-29 22:39 . 2009-04-30 05:16 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-04-29 22:39 . 2009-04-30 05:16 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-04-20 05:51 . 2002-08-29 11:00 285696 ----a-w- c:\windows\system32\atmfd.dll

2004-06-10 01:30 . 2004-06-10 01:30 1906 ----a-w- c:\program files\Shortcut to Wtp700.exe.lnk

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb07.exe" [2002-11-22 188416]

"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-20 52896]

"Vptray"="c:\progra~1\Symant~1\VPTray.exe" [2006-09-28 125168]

"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-17 221184]

"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-17 81920]

"MacLicense"="c:\program files\Conversions Plus\MacLic.exe" [2001-09-16 163904]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]

c:\documents and settings\adminfull\Start Menu\Programs\Startup\

Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-4-28 113664]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-4-28 113664]

Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2004-2-20 24576]

hp psc 2000 Series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe [2002-6-11 323646]

Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma.lnk]

path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma.lnk

backup=c:\windows\pss\Adobe Gamma.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]

path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk

backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]

path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk

backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MacName.lnk]

path=c:\documents and settings\All Users\Start Menu\Programs\Startup\MacName.lnk

backup=c:\windows\pss\MacName.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^officejet 6100.lnk]

path=c:\documents and settings\All Users\Start Menu\Programs\Startup\officejet 6100.lnk

backup=c:\windows\pss\officejet 6100.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]

c:\windows\system32\dumprep 0 -k [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

2009-10-03 11:08 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]

2004-08-04 07:56 15360 ----a-w- c:\windows\SYSTEM32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon04]

2002-11-22 18:48 348160 ----a-w- c:\windows\SYSTEM32\hphmon04.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

2010-03-18 04:53 421888 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]

2002-04-11 11:19 69632 ----a-w- c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]

2003-02-13 07:01 155648 ----a-w- c:\program files\Common Files\Sonic\Update Manager\sgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

2009-09-07 17:56 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunServer]

2005-10-28 23:33 290816 ----a-w- c:\program files\Sunbelt Software\CounterSpy\Consumer\SunServer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]

"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=

"c:\\Ziphold\\Pwr-9258\\ipEdit-1.exe"=

"c:\\Program Files\\FileZilla FTP Client\\filezilla.exe"=

"c:\\WINDOWS\\SYSTEM32\\mmc.exe"=

R0 MacOpen;MacOpen;c:\windows\SYSTEM32\DRIVERS\MacOpen.sys [5/19/2009 6:39 PM 176709]

R1 GhPciScan;GhostPciScanner;c:\program files\Symantec\Norton Ghost 2003\GhPciScan.sys [12/17/2003 3:41 PM 5632]

R2 SpyHunter 4 Service;SpyHunter 4 Service;c:\progra~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [5/18/2010 5:06 PM 327064]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/4/2010 9:07 PM 102448]

R3 MakoNT;MakoNT;c:\windows\SYSTEM32\DRIVERS\MakoNT.sys [3/18/2007 11:54 AM 76913]

R3 rap;rap;c:\windows\SYSTEM32\DRIVERS\RapDrv.sys [2/29/2004 11:25 PM 46001]

R4 BLACK;black;c:\windows\SYSTEM32\DRIVERS\Blackcat.sys [3/18/2007 11:54 AM 234155]

S2 gupdate1ca18aa2e626a8;Google Update Service (gupdate1ca18aa2e626a8);c:\program files\Google\Update\GoogleUpdate.exe [8/8/2009 9:29 PM 133104]

S3 RapFile;RapFile;c:\windows\SYSTEM32\DRIVERS\RapFile.sys [2/29/2004 11:25 PM 36644]

S3 RapNet;RapNet;c:\windows\SYSTEM32\DRIVERS\RapNet.sys [2/29/2004 11:25 PM 24344]

S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [9/27/2006 9:33 PM 116464]

S3 WrKPoET2000;WrKPoET2000;c:\program files\WinPoET Broadband Connection\WrKPoET2000.sys [2/29/2004 10:43 PM 52354]

UnknownUnknown BlackICE;BlackICE; [x]

UnknownUnknown VPatch;VPatch; [x]

.

Contents of the 'Scheduled Tasks' folder

2009-06-15 c:\windows\Tasks\FRU Task 2002-06-11 17:56ewlett-Packard2002-06-11 17:56p psc 2200 series0873DBB30DAF953F7DCEA1BDCC4F78BFDB130745237001639.job

- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2002-06-11 17:56]

2010-06-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-09 04:29]

2010-06-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-09 04:29]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.jpl.nasa.gov/index.html

mStart Page = hxxp://www.dell4me.com/myway

mSearch Bar =

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000

LSP: c:\program files\ISS\BlackICE\IBE\ICELSP_8.0.675.0.dll

Trusted Zone: ascensiontorrance.org

Trusted Zone: att.net

Trusted Zone: intuit.com

Trusted Zone: intuit.com\ttlc

Trusted Zone: sbcglobal.net

Trusted Zone: turbotax.com

Trusted Zone: yahoo.com\clientapps

TCP: {69F81847-C4DA-49EF-8498-B8522C761206} = 192.168.1.254

DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab

FF - ProfilePath - c:\documents and settings\adminron\Application Data\Mozilla\Firefox\Profiles\ho27aq9r.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.jpl.nasa.gov/index.html

FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll

FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npaudio.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npavi32.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\NPBeatnk.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npdrmv2.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npdsplay.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\NPJava11.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\NPJava12.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\NPJava13.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\NPJava32.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\NPJPI142_18.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npnul32.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npoji610.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\nppdf32.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\nppl3260.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npqtplugin.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npqtplugin2.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npqtplugin3.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npqtplugin4.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npqtplugin5.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npqtplugin6.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npqtplugin7.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\nprfxins.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\nprjplug.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\nprpjplug.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npswf32.dll

FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npwmsdrm.dll

FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----

c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr

ef", true);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

.

.

------- File Associations -------

.

.scr=AutoCADScript

.txt=TextPad.txt

.

- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-HPHUPD04 - c:\program files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe

MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

MSConfigStartUp-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-06-29 11:56

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Iomega Activity Disk2]

"ImagePath"="\"\""

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]

"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,79,00,73,00,\

.

Completion time: 2010-06-29 12:02:43

ComboFix-quarantined-files.txt 2010-06-29 19:02

Pre-Run: 25,404,293,120 bytes free

Post-Run: 25,415,012,352 bytes free

- - End Of File - - CF9CD930F8B8E4C8410FE75933BD3385

Thanks for your help jwang01.

Ron

Link to post
Share on other sites

Hello,

Ok, go ahead and skip the SystemLook step, but please run ComboFix. ComboFix is another we sometimes use in Malware Removal. :D

Oh left out one comment. While running ComboFix, after stages 1,2,3 completed, I got an error msg pop up stating that PEV.exe encountered a problem, so I clicked ok to shut down. CF then continued on and completed with the log file attached in my previous post.

Ron

Link to post
Share on other sites

Hello,

Most of the things in that Quarantine folder are registry backups. As far a that link goes, it was a false positive. We can restore that. :D

Then get a couple more scans to make sure nothing else is hiding. How is your computer running?

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

DeQuarantine::

C:\Qoobox\Quarantine\C\Documents and Settings\adminron\Start Menu\Lahey ED Developer .lnk.vir

Quit::

Folder::

Registry::

Driver::

Save this as CFScript.txt, in the same location as ComboFix.exe

CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe

Next

Please start up MBAM and update the program. Then run a Quick Scan and post the log it produces in your next reply.

Next

Please run a free online scan with the ESET Online Scanner

Note: You will need to use Internet Explorer for this scan

  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic

Please post the logs of MBAM and ESET in your next reply.

Link to post
Share on other sites

Hello,

Most of the things in that Quarantine folder are registry backups. As far a that link goes, it was a false positive. We can restore that. :D

Then get a couple more scans to make sure nothing else is hiding. How is your computer running?

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

Save this as CFScript.txt, in the same location as ComboFix.exe

CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe

Next

Please start up MBAM and update the program. Then run a Quick Scan and post the log it produces in your next reply.

Next

Please run a free online scan with the ESET Online Scanner

Note: You will need to use Internet Explorer for this scan

  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic

Please post the logs of MBAM and ESET in your next reply.

----------------------

OK, everything is running fine, jwang01. Thanks! After removal of autmgr32, got control of account.

1) Lahey ED Developer .lnk is back in after running CFScript.txt in ComboFix.

2) " start up MBAM and update the program. Then run a Quick Scan and post the log "

Only found one item in registry: HKEY_CURRENT_USER\SOFTWARE\24d1ca9a-a864-4f7b-86fe-495eb56529d8 (Malware.Trace) -> No action taken.

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

Database version: 4259

Windows 5.1.2600 Service Pack 2

Internet Explorer 7.0.5730.13

6/29/2010 9:57:15 PM

mbam-log-2010-06-29 (21-57-15).txt

Scan type: Full scan (C:\|E:\|)

Objects scanned: 364135

Time elapsed: 2 hour(s), 8 minute(s), 34 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 1

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

All following (No malicious items detected)

Memory Processes Infected:

Memory Modules Infected:

Registry Keys Infected:

Registry Data Items Infected:

Folders Infected:

Files Infected:

----

Registry Values Infected:

HKEY_CURRENT_USER\SOFTWARE\24d1ca9a-a864-4f7b-86fe-495eb56529d8 (Malware.Trace) -> No action taken.

3) Eset results: Maybe false positive

C:\Ziphold\Pwr-9258\ipEdit-1.exe probably a variant of Win32/Genetik trojan

C:\Ziphold\Pwr-9258\ipEdit.exe probably a variant of Win32/Genetik trojan

C:\Ziphold\Utils\unlocker1.8.7.exe a variant of Win32/Adware.ADON application

THis is part of a Power switch Management S/W apps used to setup a 9258 Pwr Management Switch.

ipEdit is on the CD used to configure the unit. ipEdit-1.exe is a post mod I made to ipEdit.exe after configuring the Pwr Switch.

ipEdit IPCam Scan Utility vs 1.2.0.6

ipEdit apps comes on CD with Remote Power Management switch

S/W made by AVIOSYS International Inc

Is this a false positive or is AVIOSYS got something going on under the hood that we need to be aware of????

So far everything is running back to normal and I made a full HD backup as well.

Thanks for all your help! One other question. I've run across 3 others who have had some kind of pop up appear on their screen a Bank "Verisign" that if clicked on will disable your keybrd and if cancelled, will disable the keybrd upon next reboot. Seems to disable kybd drivers or the like. What do you know about this? I'd like to be prepared if one of the PCs in the school computer lab gets this. The infected PCs had full admin privs and not limited accounts as they're running XP Home version.

My home systems are all under limited accounts now, except for one account used to update the PCs. It's getting nasty out there. Thanks again. Ron

Link to post
Share on other sites

Hello,

I would have MBAM quarintine and Delete what it found. :D

As far as the ESET scan goes, it's most likely a false positives. As long as you know what they are and trust were they come from.

I personally haven't seen that virus on the forums yet so I don't have any info do give you. Actually, this is the first time Ive heard of it.

I think we can wrap this up. :)

Congratulations!! Your logs look clean!

Now we need to do a little house keeping and remove the tools we have used.

Follow these steps to uninstall Combofix and tools used in the removal of malware

  • Click START then RUN
  • Now type Combofix /uninstall in the runbox and click OK. Note the space between the X and the /Unintstall, it needs to be there.

Run_Combofix%20{47}uninstall.jpg

Next

  • Click on OTL.exe
  • Click the CleanUp button
  • If it tells you to reboot click Yes

It is always a good idea to have ONE Anti-Spyware program that runs in real time along with your Anti-Virus. You can have more the one installed, but all others should be used only as On Access scanners.

Now the next list is some programs I like to recommend to people to help keep your computer safer. Keep in mind that these are all optional.

MalwareBytes Anti Malware

This is an exellent On Access Anti-Malware Scanner.

SuperAntiSpyware

This is an Anti-Spyware program that will help protect your PC.

TFC

This will help delete all temporary files.

Opera

This is an alternative for Internet Explorer. Opera is a more secure browser.

You should also make sure Windows is up to date. You can simply go to Start and go to Windows Update to find out. I would recommend turning on Automatic Updates.

Heres how to do it:

  • Go to Start
  • Click on the Control Panel
  • Click on Security
  • Then click on Windows update
  • Then settings to turn Windows Update On/Off

You should check and make sure that you keep your Anti-Virus up to date. This is also a crucial part of your security. You can do this by clicking on your Anti-Virus and clicking on update. If your AV has an automatic update feature, i would recommend turning it on in the settings menu.

And finally a little action-smiley-036.gifHow did I get infected in the first place? (by Mr. Tony Klein)

Link to post
Share on other sites

Hello,

I would have MBAM quarintine and Delete what it found. :D

As far as the ESET scan goes, it's most likely a false positives. As long as you know what they are and trust were they come from.

I personally haven't seen that virus on the forums yet so I don't have any info do give you. Actually, this is the first time Ive heard of it.

I think we can wrap this up. :)

Congratulations!! Your logs look clean!

Now we need to do a little house keeping and remove the tools we have used.

Follow these steps to uninstall Combofix and tools used in the removal of malware

  • Click START then RUN
  • Now type Combofix /uninstall in the runbox and click OK. Note the space between the X and the /Unintstall, it needs to be there.

Run_Combofix%20{47}uninstall.jpg

Next

  • Click on OTL.exe
  • Click the CleanUp button
  • If it tells you to reboot click Yes

It is always a good idea to have ONE Anti-Spyware program that runs in real time along with your Anti-Virus. You can have more the one installed, but all others should be used only as On Access scanners.

Now the next list is some programs I like to recommend to people to help keep your computer safer. Keep in mind that these are all optional.

MalwareBytes Anti Malware

This is an exellent On Access Anti-Malware Scanner.

SuperAntiSpyware

This is an Anti-Spyware program that will help protect your PC.

TFC

This will help delete all temporary files.

Opera

This is an alternative for Internet Explorer. Opera is a more secure browser.

You should also make sure Windows is up to date. You can simply go to Start and go to Windows Update to find out. I would recommend turning on Automatic Updates.

Heres how to do it:

  • Go to Start
  • Click on the Control Panel
  • Click on Security
  • Then click on Windows update
  • Then settings to turn Windows Update On/Off

You should check and make sure that you keep your Anti-Virus up to date. This is also a crucial part of your security. You can do this by clicking on your Anti-Virus and clicking on update. If your AV has an automatic update feature, i would recommend turning it on in the settings menu.

And finally a little action-smiley-036.gifHow did I get infected in the first place? (by Mr. Tony Klein)

OK, done. Thanks again for the help.

My mistake was to do Internet work with the account as an admin account instead of limited. Also, I'll run the one of my anti-spyware in active mode as well. Otherwise, all other safe guards were taken. My daughter was doing a search on a shopping sale when she encountered this, so I'm not sure what/where she clicked on. One thing to mention to others is that many AV groups are requiring that ALL user accounts be limited accounts and NOT have admin privs. This limits the infection extent. Thanks again for the help!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.