Hello Elster,
Thank you for getting back to me. I followed your instructions but ran into a few problems. I ran OTS as instructed and the log is below.
OTS Log:
��[\0R\0e\0g\0i\0s\0t\0r\0y\0 \0-\0 \0S\0a\0f\0e\0 \0L\0i\0s\0t\0]\0
\0
\0R\0e\0g\0i\0s\0t\0r\0y\0 \0v\0a\0l\0u\0e\0 \0H\0K\0E\0Y\0_\0L\0O\0C\0A\0L\0_\0M\0A\0C\0H\0I\0N\0E\0\\0S\0Y\0S\0T\0E\0M\0\\0C\0u\0r\0r\0e\0n\0t\0C\0o\0n\0t\0r\0o\0l\0S\0e\0t\0\\0C\0o\0n\0t\0r\0o\0l\0\\0S\0e\0c\0u\0r\0i\0t\0y\0P\0r\0o\0v\0i\0d\0e\0r\0s\0\\0\\0S\0e\0c\0u\0r\0i\0t\0y\0P\0r\0o\0v\0i\0d\0e\0r\0s\0:\0m\0s\0a\0n\0s\0s\0p\0c\0.\0d\0l\0l\0 \0d\0e\0l\0e\0t\0e\0d\0 \0s\0u\0c\0c\0e\0s\0s\0f\0u\0l\0l\0y\0.\0
\0
\0[\0F\0i\0l\0e\0s\0/\0F\0o\0l\0d\0e\0r\0s\0 \0-\0 \0C\0r\0e\0a\0t\0e\0d\0 \0W\0i\0t\0h\0i\0n\0 \03\00\0 \0D\0a\0y\0s\0]\0
\0
\0C\0:\0\\0D\0o\0c\0u\0m\0e\0n\0t\0s\0 \0a\0n\0d\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0K\0a\0t\0h\0e\0r\0i\0n\0e\0\\0L\0o\0c\0a\0l\0 \0S\0e\0t\0t\0i\0n\0g\0s\0\\0A\0p\0p\0l\0i\0c\0a\0t\0i\0o\0n\0 \0D\0a\0t\0a\0\\0o\0j\0b\0m\0m\0w\0 \0f\0o\0l\0d\0e\0r\0 \0m\0o\0v\0e\0d\0 \0s\0u\0c\0c\0e\0s\0s\0f\0u\0l\0l\0y\0.\0
\0
\0[\0F\0i\0l\0e\0s\0 \0-\0 \0N\0o\0 \0C\0o\0m\0p\0a\0n\0y\0 \0N\0a\0m\0e\0]\0
\0
\0C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0j\0s\0t\0.\0d\0l\0l\0 \0m\0o\0v\0e\0d\0 \0s\0u\0c\0c\0e\0s\0s\0f\0u\0l\0l\0y\0.\0
\0
\0C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0c\0o\0m\0p\0J\0N\0I\0.\0d\0l\0l\0 \0m\0o\0v\0e\0d\0 \0s\0u\0c\0c\0e\0s\0s\0f\0u\0l\0l\0y\0.\0
\0
\0C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0P\0M\0L\0J\0N\0I\0.\0d\0l\0l\0 \0m\0o\0v\0e\0d\0 \0s\0u\0c\0c\0e\0s\0s\0f\0u\0l\0l\0y\0.\0
\0
\0C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0g\0r\0c\0a\0u\0t\0h\02\0.\0d\0l\0l\0 \0m\0o\0v\0e\0d\0 \0s\0u\0c\0c\0e\0s\0s\0f\0u\0l\0l\0y\0.\0
\0
\0C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0g\0r\0c\0a\0u\0t\0h\01\0.\0d\0l\0l\0 \0m\0o\0v\0e\0d\0 \0s\0u\0c\0c\0e\0s\0s\0f\0u\0l\0l\0y\0.\0
\0
\0C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0p\0r\0s\0g\0r\0c\0.\0d\0l\0l\0 \0m\0o\0v\0e\0d\0 \0s\0u\0c\0c\0e\0s\0s\0f\0u\0l\0l\0y\0.\0
\0
\0C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0s\0y\0s\0p\0r\0s\07\0.\0d\0l\0l\0 \0m\0o\0v\0e\0d\0 \0s\0u\0c\0c\0e\0s\0s\0f\0u\0l\0l\0y\0.\0
\0
\0C\0:\0\\0W\0I\0N\0D\0O\0W\0S\0\\0S\0y\0s\0t\0e\0m\03\02\0\\0l\0s\0p\0r\0s\0t\07\0.\0d\0l\0l\0 \0m\0o\0v\0e\0d\0 \0s\0u\0c\0c\0e\0s\0s\0f\0u\0l\0l\0y\0.\0
\0
\0<\0 \0E\0n\0d\0 \0o\0f\0 \0f\0i\0x\0 \0l\0o\0g\0 \0>\0
\0
\0O\0T\0S\0 \0b\0y\0 \0O\0l\0d\0T\0i\0m\0e\0r\0 \0-\0 \0V\0e\0r\0s\0i\0o\0n\0 \03\0.\01\0.\01\09\0.\01\0 \0f\0i\0x\0 \0l\0o\0g\0f\0i\0l\0e\0 \0c\0r\0e\0a\0t\0e\0d\0 \0o\0n\0 \00\01\02\02\02\00\01\00\0_\01\06\02\00\03\05\0
\0
Combo fix log:
ComboFix 10-01-16.04 - Katherine 01/22/2010 16:35:32.1.1 - x86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.674 [GMT -5:00]
Running from: f:\computer fix\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\EventSystem.log
c:\windows\kb913800.exe
.
((((((((((((((((((((((((( Files Created from 2009-12-22 to 2010-01-22 )))))))))))))))))))))))))))))))
.
2010-01-18 23:48 . 2010-01-18 23:48 -------- d-----w- c:\program files\ERUNT
2010-01-18 05:11 . 2010-01-18 05:11 -------- d-----w- c:\documents and settings\Administrator\Application Data\Windows Search
2010-01-18 04:34 . 2010-01-18 04:34 -------- d-----w- c:\documents and settings\Administrator\Application Data\Yahoo!
2010-01-18 04:29 . 2010-01-18 04:29 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-01-18 04:29 . 2010-01-18 04:29 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-01-18 04:02 . 2010-01-18 04:02 -------- d-----w- c:\documents and settings\Katherine\Application Data\Yahoo!
2010-01-16 15:21 . 2009-11-21 15:51 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
2010-01-08 00:31 . 2010-01-08 00:31 -------- d-----w- c:\program files\Common Files\Skype
2010-01-07 21:33 . 2010-01-07 21:33 -------- d-----w- c:\program files\iPod
2010-01-07 21:32 . 2010-01-07 21:34 -------- d-----w- c:\program files\iTunes
2010-01-07 21:32 . 2010-01-07 21:34 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-01-07 21:27 . 2010-01-07 21:28 -------- d-----w- c:\program files\QuickTime
2010-01-07 21:19 . 2010-01-07 21:19 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2010-01-07 21:18 . 2010-01-07 21:18 -------- d-----w- c:\program files\Safari
2010-01-07 21:16 . 2010-01-07 21:16 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-20 16:52 . 2009-04-04 14:05 -------- d-----w- c:\documents and settings\Katherine\Application Data\Skype
2010-01-20 16:50 . 2009-04-04 14:07 -------- d-----w- c:\documents and settings\Katherine\Application Data\skypePM
2010-01-19 00:26 . 2008-11-19 02:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-01-18 23:52 . 2010-01-18 23:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-18 23:35 . 2006-06-08 14:23 -------- d-----w- c:\program files\SmartDraw 7
2010-01-18 05:37 . 2006-06-05 19:20 -------- d-----w- c:\program files\Trend Micro
2010-01-18 04:34 . 2006-04-25 04:29 -------- d-----w- c:\program files\Yahoo!
2010-01-18 04:24 . 2009-10-27 17:02 -------- d--h--w- c:\program files\Zero G Registry
2010-01-18 04:24 . 2009-10-27 16:55 -------- d-----w- c:\program files\Hewlett-Packard
2010-01-18 04:22 . 2009-10-27 16:47 -------- d-----w- c:\program files\HP
2010-01-18 04:05 . 2006-02-22 22:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-16 22:54 . 2008-07-14 21:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-08 00:32 . 2009-04-04 14:04 -------- d-----r- c:\program files\Skype
2010-01-08 00:31 . 2009-04-04 14:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2010-01-07 22:39 . 2006-04-06 20:27 91976 ----a-w- c:\documents and settings\Katherine\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-07 22:29 . 2008-07-14 21:32 -------- d-----w- c:\program files\Microsoft Works
2010-01-07 21:51 . 2006-10-29 01:04 -------- d-----w- c:\documents and settings\Katherine\Application Data\Apple Computer
2010-01-07 21:33 . 2009-05-11 01:18 -------- d-----w- c:\program files\Common Files\Apple
2010-01-07 21:07 . 2010-01-18 23:52 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2010-01-18 23:52 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-16 22:19 . 2006-06-08 14:40 -------- d-----w- c:\documents and settings\Katherine\Application Data\SmartDraw
2009-12-09 16:21 . 2009-12-07 15:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Fiesta Download Manager
2009-12-07 19:29 . 2008-09-02 20:29 186 ----a-w- c:\documents and settings\All Users\Application Data\SafeNet Sentinel\Sentinel RMS Development Kit\System\prsgrc.dll
2009-12-07 16:52 . 2009-12-07 16:52 -------- d-----w- c:\documents and settings\Katherine\Application Data\gtk-2.0
2009-12-07 15:47 . 2009-12-07 15:47 -------- d-----w- c:\program files\Fiesta Download Manager
2009-11-21 15:51 . 2005-08-16 10:18 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-10-29 07:45 . 2005-08-16 10:18 916480 ----a-w- c:\windows\system32\wininet.dll
2006-09-20 15:52 . 2006-09-20 15:52 265358 ----a-w- c:\program files\PPGRE.ISU
2008-06-05 01:13 . 2006-10-17 03:50 104 --sh--r- c:\windows\system32\AE1C104679.sys
2008-06-05 01:13 . 2006-10-17 03:50 6580 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-26 1008896]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-26 1008896]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-26 1008896]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-29 68856]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dell Wireless Manager UI"="c:\windows\system32\WLTRAY" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-24 729178]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-15 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-15 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-15 114688]
"SigmatelSysTrayApp"="stsystra.exe" [2005-09-10 393216]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-02-11 168448]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 1121280]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-14 2043160]
"FixCamera"="c:\windows\FixCamera.exe" [2007-02-10 20480]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2007-03-10 270336]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-19 827392]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-2-11 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-4 258048]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-4 53248]
SafeConnect.lnk - c:\program files\SafeConnect\scClient.exe [2007-11-13 271640]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-28 13:46 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\SPSSInc\\SPSS16\\spss.exe"=
"c:\\Program Files\\SPSSInc\\SPSS16\\spss.com"=
"c:\\Program Files\\SPSSInc\\SPSS16\\SPSSWinWrapIDE.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\javaw.exe"=
"c:\\Program Files\\Hewlett-Packard\\Toolbox\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8097:TCP"= 8097:TCP:EarthLink UHP Modem Support
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [7/18/2008 6:19 PM 335240]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/18/2008 6:19 PM 297752]
S2 gupdate1c9f9cb51d16708;Google Update Service (gupdate1c9f9cb51d16708);c:\program files\Google\Update\GoogleUpdate.exe [6/30/2009 4:39 PM 133104]
S2 SCManager;SafeConnect Manager;c:\program files\SafeConnect\scManager.sys servicestart --> c:\program files\SafeConnect\scManager.sys servicestart [?]
S3 BW2NDIS5;BW2NDIS5;c:\windows\system32\Drivers\BW2NDIS5.sys --> c:\windows\system32\Drivers\BW2NDIS5.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2010-01-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2010-01-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-30 21:39]
2010-01-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-30 21:39]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &MP3Bar - c:\program files\Fiesta Download Manager\mp3bar.dll/MENUSEARCH.HTM
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{F6BD6330-76F8-44d9-B775-87614E2D8374} - (no file)
WebBrowser-{F6BD6330-76F8-44D9-B775-87614E2D8374} - (no file)
AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-22 16:44
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2010-01-22 16:49:14
ComboFix-quarantined-files.txt 2010-01-22 21:48
Pre-Run: 43,744,280,576 bytes free
Post-Run: 43,765,747,712 bytes free
- - End Of File - - 3A27B425BA7F620DDAA29AAE9610EB91
Problems I ran into with Combo Fix: I was unable to disable AVG or Spybot. I received a warning about AVG but continued running Combo Fix. Microsoft Recovery Console was unable to be installed because I still can not access the internet. Finally, I received several pop ups from Spybot about changes. I denied the changes since I wasn't sure what to do. I apologize if this has complicated the matter or made your job more difficult. Also as a note I did all of this is in Safe Mode. Please let me know if I need to re-run any of these due to the problems I ran into.
Thanks for all of your help.
Cheers,
Katherine