This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] help with vundos problems - hijackthis logfile

32 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

my antivirus catches and quarantines the vundo viruses in my comp. but everytime the comp restarts, the same or another vundo just appears again. it always have something to do with "dll" files.
i have notice so many more popups and computer slow downs in the past month because of this.

please help me.
below is my hijackthis logfile.
thank you in advance



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:04:17 PM, on 2/23/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {534C9916-EC47-46DE-B7F6-10F06C309F04} - C:\WINDOWS\system32\khfCstrQ.dll (file missing)
O2 - BHO: (no name) - {57F7EDCC-EB32-4082-A098-318E931773D1} - C:\WINDOWS\system32\ljJDUNHx.dll (file missing)
O2 - BHO: (no name) - {5BA73F0D-7B52-4E5A-9763-DDAD6268CD02} - C:\WINDOWS\system32\urqOGWMd.dll
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\ssqQhfde.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: {77d17a28-aa5a-b389-d2c4-09452be06b7c} - {c7b60eb2-5490-4c2d-983b-a5aa82a71d77} - C:\WINDOWS\system32\vaajnx.dll
O2 - BHO: (no name) - {E43DDAE6-117B-47FF-A1EC-EBE1CA5C0024} - C:\WINDOWS\system32\byXQKDUO.dll (file missing)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Foxy ?? - res://C:\Program Files\Foxy\Foxy.exe/download.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
O16 - DPF: RaptisoftGameLoader - http://www.raptisoft.com/webgames/raptisoftgameloader.cab
O16 - DPF: {09C6CAC0-936E-40A0-BC26-707480103DC3} - http://www.uproar.com/applets/activex/shiz…pside_web18.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1160454364500
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = nyu.edu
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = nyu.edu
O20 - AppInit_DLLs: vaajnx.dll
O20 - Winlogon Notify: cbXNDWnO - cbXNDWnO.dll (file missing)
O20 - Winlogon Notify: ssqQhfde - C:\WINDOWS\system32\ssqQhfde.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 7023 bytes
here is the Rooter report.

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : Intel® Pentium® M processor 1.73GHz )
BIOS : Phoenix NoteBIOS 4.0 Release 6.1
USER : Queenie Leung ( Administrator )
BOOT : Normal boot

Antivirus : Symantec AntiVirus Corporate Edition 10.0.0.359 (Activated)
Firewall : Norton Internet Worm Protection 2006 (Not Activated)

C:\ (Local Disk) - NTFS - Total:55 Go (Free:14 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)

Mon 02/23/2009|17:34

———————-\\ Search..

C:\WINDOWS\system32\dMWGOqru.ini
C:\WINDOWS\system32\dMWGOqru.ini2
C:\WINDOWS\system32\OUDKQXyb.ini
C:\WINDOWS\system32\OUDKQXyb.ini2
C:\WINDOWS\system32\QrtsCfhk.ini
C:\WINDOWS\system32\QrtsCfhk.ini2
C:\WINDOWS\system32\UDJllnnn.ini
C:\WINDOWS\system32\UDJllnnn.ini2
C:\WINDOWS\system32\vuttCcfe.ini
C:\WINDOWS\system32\vuttCcfe.ini2
C:\WINDOWS\system32\xHNUDJjl.ini
C:\WINDOWS\system32\xHNUDJjl.ini2
C:\WINDOWS\system32\urqOGWMd.dll
==> VUNDO <==


1 - "C:\Rooter$\Rooter_1.txt" - Mon 02/23/2009|17:39

———————-\\ Scan completed at 17:39


THANKS!
hello

Please download OTMoveIt3 by OldTimer
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\WINDOWS\system32\dMWGOqru.ini
    C:\WINDOWS\system32\dMWGOqru.ini2
    C:\WINDOWS\system32\OUDKQXyb.ini
    C:\WINDOWS\system32\OUDKQXyb.ini2
    C:\WINDOWS\system32\QrtsCfhk.ini
    C:\WINDOWS\system32\QrtsCfhk.ini2
    C:\WINDOWS\system32\UDJllnnn.ini
    C:\WINDOWS\system32\UDJllnnn.ini2
    C:\WINDOWS\system32\vuttCcfe.ini
    C:\WINDOWS\system32\vuttCcfe.ini2
    C:\WINDOWS\system32\xHNUDJjl.ini
    C:\WINDOWS\system32\xHNUDJjl.ini2
    C:\WINDOWS\system32\urqOGWMd.dll
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    msconfig
    safebootminimal
    safebootnetwork
    %systemroot%\System32\antiwpa.dll
    %systemroot%\SYSTEM32\wpa.dll
    %systemroot%\setup\scripts\biestart.exe
    %systemroot%\system32\serauth1.dll
    %systemroot%\system32\serauth2.dll
    %systemroot%\system32\sysaudio.sys
    %systemroot%\system32\wdmaud.sys
    %systemroot%\system32\aeaudio.sys

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
This is ftom the OT Move IT 3 log. ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== C:\WINDOWS\system32\dMWGOqru.ini moved successfully. C:\WINDOWS\system32\dMWGOqru.ini2 moved successfully. C:\WINDOWS\system32\OUDKQXyb.ini moved successfully. C:\WINDOWS\system32\OUDKQXyb.ini2 moved successfully. C:\WINDOWS\system32\QrtsCfhk.ini moved successfully. C:\WINDOWS\system32\QrtsCfhk.ini2 moved successfully. C:\WINDOWS\system32\UDJllnnn.ini moved successfully. C:\WINDOWS\system32\UDJllnnn.ini2 moved successfully. C:\WINDOWS\system32\vuttCcfe.ini moved successfully. C:\WINDOWS\system32\vuttCcfe.ini2 moved successfully. C:\WINDOWS\system32\xHNUDJjl.ini moved successfully. C:\WINDOWS\system32\xHNUDJjl.ini2 moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\urqOGWMd.dll C:\WINDOWS\system32\urqOGWMd.dll NOT unregistered. C:\WINDOWS\system32\urqOGWMd.dll moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\QUEENI~1\LOCALS~1\Temp\etilqs_2Jtjx5jz8rVVZOlQehy6 scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\QUEENI~1\LOCALS~1\Temp\~DF1D72.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\QUEENI~1\LOCALS~1\Temp\~DFC05F.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\QUEENI~1\LOCALS~1\Temp\~DFE617.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02232009_181226 Files moved on Reboot… File move failed. C:\DOCUME~1\QUEENI~1\LOCALS~1\Temp\etilqs_2Jtjx5jz8rVVZOlQehy6 scheduled to be moved on reboot. File C:\DOCUME~1\QUEENI~1\LOCALS~1\Temp\~DF1D72.tmp not found! C:\DOCUME~1\QUEENI~1\LOCALS~1\Temp\~DFC05F.tmp moved successfully. File C:\DOCUME~1\QUEENI~1\LOCALS~1\Temp\~DFE617.tmp not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File move failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_001_ scheduled to be moved on reboot. File move failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_002_ scheduled to be moved on reboot. File move failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_003_ scheduled to be moved on reboot. File move failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_MAP_ scheduled to be moved on reboot. File move failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\urlclassifier3.sqlite scheduled to be moved on reboot. File move failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\XUL.mfl scheduled to be moved on reboot.
OTLISTIT

OTListIt logfile created on: 2/23/2009 6:27:01 PM - Run
OTListIt2 by OldTimer - Version 2.0.1.1 Folder = C:\Documents and Settings\Queenie Leung\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

502.42 Mb Total Physical Memory | 87.66 Mb Available Physical Memory | 17.45% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 4096 10240;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.68 Gb Total Space | 15.17 Gb Free Space | 27.24% Space Free | Partition Type: NTFS
Drive D: | 58.68 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: QUEENIE
Current User Name: Queenie Leung
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe ()
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\Queenie Leung\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (ccEvtMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (ccPwdSvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccSetMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (CVPND [Auto | Running]) – C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (DefWatch [Auto | Running]) – C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (hpqwmi [On_Demand | Stopped]) – C:\Program Files\HPQ\SHARED\HPQWMI.exe (Hewlett-Packard Development Company, L.P.)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe ()
SRV - (Pml Driver HPZ12 [Auto | Running]) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (SavRoam [On_Demand | Stopped]) – C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (SNDSrvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (SPBBCSvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (Symantec AntiVirus [Auto | Running]) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (UMWdf [Auto | Running]) – C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service [Auto | Running]) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)

========== Driver Services (SafeList) ==========

DRV - (AliIde [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CAMCAUD [On_Demand | Running]) – C:\WINDOWS\system32\drivers\camc6aud.sys (Conexant Systems Inc.)
DRV - (CAMCHALA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\camc6hal.sys (Conexant Systems Inc.)
DRV - (CamDrL [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\Camdrl.sys (Logitech Inc.)
DRV - (CVirtA [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\CVirtA.sys (Cisco Systems, Inc.)
DRV - (CVPNDRVA [Auto | Running]) – C:\WINDOWS\system32\Drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (DNE [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\dne2000.sys (Deterministic Networks, Inc.)
DRV - (eabfiltr [System | Running]) – C:\WINDOWS\system32\drivers\EABFiltr.sys (Hewlett-Packard Company)
DRV - (eabusb [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\eabusb.sys (Hewlett-Packard Company)
DRV - (eeCtrl [System | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilDrvI7 [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI7.sys (Symantec Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HPZid412 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZius12.sys (HP)
DRV - (HSFHWICH [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (HSF_DP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (mchInjDrv [System | Running]) – C:\WINDOWS\system32\Drivers\mchInjDrv.sys ()
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (NAVENG [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090223.002\NAVENG.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090223.002\NAVEX15.SYS (Symantec Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (RTL8023xp [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (SAVRT [On_Demand | Running]) – C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SAVRTPEL [System | Running]) – C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (sea1bus [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1bus.sys (MCCI)
DRV - (sea1mdfl [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1mdfl.sys (MCCI)
DRV - (sea1mdm [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1mdm.sys (MCCI)
DRV - (sea1mgmt [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1mgmt.sys (MCCI)
DRV - (sea1nd5 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1nd5.sys (MCCI)
DRV - (sea1obex [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1obex.sys (MCCI)
DRV - (sea1unic [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1unic.sys (MCCI)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SMCIRDA [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\smcirda.sys (SMC)
DRV - (SPBBCDrv [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SymEvent [On_Demand | Running]) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMREDRV [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMTDI [System | Running]) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SynTP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (tifm21 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (vcddev [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\vcdvnic.sys (VNN B.J.)
DRV - (vsdatant [On_Demand | Stopped]) – C:\WINDOWS\system32\vsdatant.sys (Zone Labs Inc.)
DRV - (w29n51 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\w29n51.sys (Intel® Corporation)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = Reg Error: Invalid data type.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com/puccini/start
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {534C9916-EC47-46DE-B7F6-10F06C309F04} - C:\WINDOWS\system32\khfCstrQ.dll File not found
O2 - BHO: (no name) - {57F7EDCC-EB32-4082-A098-318E931773D1} - C:\WINDOWS\system32\ljJDUNHx.dll File not found
O2 - BHO: (no name) - {5BA73F0D-7B52-4E5A-9763-DDAD6268CD02} - C:\WINDOWS\system32\urqOGWMd.dll File not found
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\ssqQhfde.dll ()
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {88a796be-b4ec-4cfe-9074-198b28ab0973} - C:\WINDOWS\system32\gitdlk.dll ()
O2 - BHO: (no name) - {96D496B3-D54E-42D9-86E5-5456E9F2D262} - C:\WINDOWS\system32\pmnljKbX.dll ()
O2 - BHO: (no name) - {E43DDAE6-117B-47FF-A1EC-EBE1CA5C0024} - C:\WINDOWS\system32\byXQKDUO.dll File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [314c2356] rundll32.exe "C:\WINDOWS\system32\lnebwupq.dll",b ()
O4 - HKLM..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" (Symantec Corporation)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Foxy ?? - res://C:\Program Files\Foxy\Foxy.exe/download.htm
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {09C6CAC0-936E-40A0-BC26-707480103DC3} http://www.uproar.com/applets/activex/shiz…pside_web18.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1160454364500 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: RaptisoftGameLoader http://www.raptisoft.com/webgames/raptisoftgameloader.cab (Reg Error: Key error.)
O18 - Protocol\Handler\ipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (gitdlk.dll) - C:\WINDOWS\system32\gitdlk.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\cbXNDWnO: DllName - cbXNDWnO.dll - File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O20 - Winlogon\Notify\ssqQhfde: DllName - ssqQhfde.dll - C:\WINDOWS\system32\ssqQhfde.dll ()
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\ssqQhfde.dll ()
O29 - HKLM SecurityProviders - ( digeste.dll) - File not found
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\pmnljKbX) - C:\WINDOWS\system32\pmnljKbX.dll ()
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{17f9b040-328d-11dd-b9f7-0015000583e0}\Shell\AutoRun\command - "" = E:\AutoRun.exe – File not found
O33 - MountPoints2\{20f01ae4-3e3e-11db-b602-00c09fc929fb}\Shell - "" = AutoRun
O33 - MountPoints2\{20f01ae4-3e3e-11db-b602-00c09fc929fb}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{20f01ae4-3e3e-11db-b602-00c09fc929fb}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\{30351328-0775-11dc-b775-00c09fc929fb}\Shell - "" = AutoRun
O33 - MountPoints2\{30351328-0775-11dc-b775-00c09fc929fb}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{30351328-0775-11dc-b775-00c09fc929fb}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{30351329-0775-11dc-b775-00c09fc929fb}\Shell\Auto\command - "" = G:\Ghost.pif – File not found
O33 - MountPoints2\{30351329-0775-11dc-b775-00c09fc929fb}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\Shell - "" = AutoRun
O33 - MountPoints2\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\Shell\1\Command - "" = .\RECYCLER\Lcass.exe
O33 - MountPoints2\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\Shell\2\Command - "" = .\RECYCLER\Lcass.exe
O33 - MountPoints2\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{67e1c64f-35b9-11dc-b7cf-0015000583e0}\Shell - "" = AutoRun
O33 - MountPoints2\{67e1c64f-35b9-11dc-b7cf-0015000583e0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{67e1c64f-35b9-11dc-b7cf-0015000583e0}\Shell\AutoRun\command - "" = E:\Launcher.exe – File not found
O33 - MountPoints2\{9f6e0d9c-4970-11dd-ba1a-0015000583e0}\Shell - "" = AutoRun
O33 - MountPoints2\{9f6e0d9c-4970-11dd-ba1a-0015000583e0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{9f6e0d9c-4970-11dd-ba1a-0015000583e0}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O33 - MountPoints2\{d20d7854-2a78-11dc-b7b7-00c09fc929fb}\Shell - "" = AutoRun
O33 - MountPoints2\{d20d7854-2a78-11dc-b7b7-00c09fc929fb}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{d20d7854-2a78-11dc-b7b7-00c09fc929fb}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{f7cf81b8-fe9d-11dd-bb2a-0015000583e0}\Shell - "" = AutoRun
O33 - MountPoints2\{f7cf81b8-fe9d-11dd-bb2a-0015000583e0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f7cf81b8-fe9d-11dd-bb2a-0015000583e0}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[10 C:\Documents and Settings\Queenie Leung\My Documents\*.tmp files]
File not found – C:\WINDOWS\System32\wgsjsume.dll
File not found – C:\WINDOWS\System32\unedukru.dll
File not found – C:\WINDOWS\System32\tnakrraf.dll
File not found – C:\WINDOWS\System32\nxoxwvsj.dll
File not found – C:\WINDOWS\System32\nnpkyh.dll
File not found – C:\WINDOWS\System32\nfjmuvpe.dll
File not found – C:\WINDOWS\System32\maxaolvg.dll
File not found – C:\WINDOWS\System32\kslddono.dll
File not found – C:\WINDOWS\System32\kppkvlgu.dll
File not found – C:\WINDOWS\System32\kgfktdjh.dll
File not found – C:\WINDOWS\System32\gxkggp.dll
File not found – C:\WINDOWS\System32\espjawnf.dll
File not found – C:\WINDOWS\System32\cbsnpz.dll
[2009/02/23 18:30:04 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\ofivoilk.dll
[2009/02/23 18:27:32 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\gitdlk.dll
[2009/02/23 18:27:31 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\bhgvdkdv.dll
[2009/02/23 18:27:02 | 00,002,409 | -HS- | C] () – C:\WINDOWS\System32\XbKjlnmp.ini2
[2009/02/23 18:27:01 | 00,002,409 | -HS- | C] () – C:\WINDOWS\System32\XbKjlnmp.ini
[2009/02/23 18:26:57 | 00,302,592 | —- | C] () – C:\WINDOWS\System32\pmnljKbX.dll
[2009/02/23 18:26:03 | 00,494,080 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Queenie Leung\Desktop\OTListIt2.exe
[2009/02/23 18:12:26 | 00,000,000 | —D | C] – C:\_OTMoveIt
[2009/02/23 18:10:57 | 00,348,160 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Queenie Leung\Desktop\OTMoveIt3.exe
[2009/02/23 17:50:23 | 00,038,447 | —- | C] () – C:\Documents and Settings\Queenie Leung\Desktop\n1331910049_30524037_6342.jpg
[2009/02/23 17:46:46 | 33,911,485 | —- | C] () – C:\Documents and Settings\Queenie Leung\Desktop\CIMG1040.zip
[2009/02/23 17:34:24 | 00,000,000 | —D | C] – C:\Rooter$
[2009/02/23 17:33:36 | 00,268,052 | —- | C] () – C:\Documents and Settings\Queenie Leung\Desktop\Rooter.exe
[2009/02/23 12:37:55 | 01,587,449 | -HS- | C] () – C:\WINDOWS\System32\qpuwbenl.ini
[2009/02/23 12:37:49 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\lnebwupq.dll
[2009/02/23 12:36:14 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\vaajnx.dll
[2009/02/23 12:34:58 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\mjnrhbkw.dll
[2009/02/23 00:50:20 | 00,001,734 | —- | C] () – C:\Documents and Settings\Queenie Leung\Desktop\HijackThis.lnk
[2009/02/23 00:50:19 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/02/22 23:17:33 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\nvnhqo.dll
[2009/02/22 23:17:29 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\jumdlpmd.dll
[2009/02/22 23:14:50 | 01,607,788 | -HS- | C] () – C:\WINDOWS\System32\onrjonwo.ini
[2009/02/22 23:14:48 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\ownojrno.dll
[2009/02/22 20:25:01 | 01,607,788 | -HS- | C] () – C:\WINDOWS\System32\vafgovpp.ini
[2009/02/22 19:35:41 | 01,607,788 | -HS- | C] () – C:\WINDOWS\System32\rqvfuvma.ini
[2009/02/22 19:33:27 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\dhyuej.dll
[2009/02/22 19:33:25 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\klcmlevu.dll
[2009/02/19 23:29:22 | 04,045,312 | —- | C] () – C:\Documents and Settings\Queenie Leung\My Documents\hsmai.ppt
[2009/02/10 13:22:59 | 52,689,7152 | -HS- | C] () – C:\hiberfil.sys
[2009/02/02 23:40:06 | 00,002,560 | —- | C] () – C:\WINDOWS\System32\drivers\mchInjDrv.sys
[2009/02/02 23:28:17 | 00,036,352 | —- | C] () – C:\WINDOWS\System32\fccaAsRH.dll
[2009/02/02 23:26:54 | 00,036,352 | —- | C] () – C:\WINDOWS\System32\ssqQhfde.dll
[2009/02/02 22:53:57 | 01,508,191 | -HS- | C] () – C:\WINDOWS\System32\xwteoaey.ini
[2009/02/02 22:47:22 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/02/02 22:47:16 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\STKIT432.DLL
[2009/02/02 22:47:12 | 00,000,000 | —D | C] – C:\Program Files\Registry Mechanic
[2009/02/02 21:34:39 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/02/02 21:34:39 | 00,000,000 | —D | C] – C:\Qoobox
[2009/01/29 00:13:12 | 01,515,358 | -HS- | C] () – C:\WINDOWS\System32\smmcfbpc.ini
[2009/01/28 00:10:33 | 01,516,535 | -HS- | C] () – C:\WINDOWS\System32\farrkant.ini
[2009/01/26 21:19:30 | 00,000,000 | —D | C] – C:\Documents and Settings\Queenie Leung\My Documents\Spring 09
[2009/01/26 17:14:40 | 01,525,122 | -HS- | C] () – C:\WINDOWS\System32\wsftufxc.ini
[2009/01/25 21:05:33 | 01,434,061 | -HS- | C] () – C:\WINDOWS\System32\tacithut.ini

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[10 C:\Documents and Settings\Queenie Leung\My Documents\*.tmp files]
[2009/02/23 18:33:42 | 00,002,409 | -HS- | M] () – C:\WINDOWS\System32\XbKjlnmp.ini
[2009/02/23 18:33:12 | 00,002,409 | -HS- | M] () – C:\WINDOWS\System32\XbKjlnmp.ini2
[2009/02/23 18:30:21 | 01,587,501 | -HS- | M] () – C:\WINDOWS\System32\kliovifo.ini
[2009/02/23 18:30:06 | 00,072,704 | —- | M] () – C:\WINDOWS\System32\ofivoilk.dll
[2009/02/23 18:27:32 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\gitdlk.dll
[2009/02/23 18:27:32 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\bhgvdkdv.dll
[2009/02/23 18:26:59 | 00,302,592 | —- | M] () – C:\WINDOWS\System32\pmnljKbX.dll
[2009/02/23 18:26:15 | 00,494,080 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Queenie Leung\Desktop\OTListIt2.exe
[2009/02/23 18:21:17 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/23 18:20:25 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/23 18:20:08 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/23 18:19:58 | 00,364,120 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/02/23 18:19:54 | 52,689,7152 | -HS- | M] () – C:\hiberfil.sys
[2009/02/23 18:10:58 | 00,348,160 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Queenie Leung\Desktop\OTMoveIt3.exe
[2009/02/23 17:50:23 | 00,038,447 | —- | M] () – C:\Documents and Settings\Queenie Leung\Desktop\n1331910049_30524037_6342.jpg
[2009/02/23 17:49:23 | 33,911,485 | —- | M] () – C:\Documents and Settings\Queenie Leung\Desktop\CIMG1040.zip
[2009/02/23 17:33:37 | 00,268,052 | —- | M] () – C:\Documents and Settings\Queenie Leung\Desktop\Rooter.exe
[2009/02/23 12:38:10 | 01,587,449 | -HS- | M] () – C:\WINDOWS\System32\qpuwbenl.ini
[2009/02/23 12:37:49 | 00,072,704 | —- | M] () – C:\WINDOWS\System32\lnebwupq.dll
[2009/02/23 12:36:12 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\vaajnx.dll
[2009/02/23 12:36:12 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\mjnrhbkw.dll
[2009/02/23 00:50:20 | 00,001,734 | —- | M] () – C:\Documents and Settings\Queenie Leung\Desktop\HijackThis.lnk
[2009/02/22 23:17:32 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\nvnhqo.dll
[2009/02/22 23:17:32 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\jumdlpmd.dll
[2009/02/22 23:15:03 | 01,607,788 | -HS- | M] () – C:\WINDOWS\System32\onrjonwo.ini
[2009/02/22 23:14:49 | 00,072,704 | —- | M] () – C:\WINDOWS\System32\ownojrno.dll
[2009/02/22 20:25:12 | 01,607,788 | -HS- | M] () – C:\WINDOWS\System32\vafgovpp.ini
[2009/02/22 19:35:45 | 01,607,788 | -HS- | M] () – C:\WINDOWS\System32\rqvfuvma.ini
[2009/02/22 19:33:26 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\klcmlevu.dll
[2009/02/22 19:33:26 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\dhyuej.dll
[2009/02/20 01:52:15 | 04,045,312 | —- | M] () – C:\Documents and Settings\Queenie Leung\My Documents\hsmai.ppt
[2009/02/20 00:26:22 | 00,102,392 | —- | M] () – C:\Documents and Settings\Queenie Leung\Application Data\GDIPFONTCACHEV1.DAT
[2009/02/19 19:00:54 | 00,002,560 | —- | M] () – C:\WINDOWS\System32\drivers\mchInjDrv.sys
[2009/02/10 13:32:21 | 00,000,624 | —- | M] () – C:\WINDOWS\win.ini
[2009/02/10 13:32:21 | 00,000,246 | —- | M] () – C:\WINDOWS\system.ini
[2009/02/10 13:32:21 | 00,000,211 | RHS- | M] () – C:\boot.ini
[2009/02/02 23:35:25 | 00,380,918 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/02/02 23:35:25 | 00,053,166 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/02/02 23:35:23 | 00,439,376 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/02/02 23:28:18 | 00,036,352 | —- | M] () – C:\WINDOWS\System32\fccaAsRH.dll
[2009/02/02 23:26:57 | 00,036,352 | —- | M] () – C:\WINDOWS\System32\ssqQhfde.dll
[2009/02/02 22:54:13 | 01,508,191 | -HS- | M] () – C:\WINDOWS\System32\xwteoaey.ini
[2009/01/29 00:13:17 | 01,515,358 | -HS- | M] () – C:\WINDOWS\System32\smmcfbpc.ini
[2009/01/28 00:10:38 | 01,516,535 | -HS- | M] () – C:\WINDOWS\System32\farrkant.ini
[2009/01/26 17:15:04 | 01,525,122 | -HS- | M] () – C:\WINDOWS\System32\wsftufxc.ini
[2009/01/25 21:05:36 | 01,434,061 | -HS- | M] () – C:\WINDOWS\System32\tacithut.ini

========== LOP Check ==========

[2009/02/19 19:14:52 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/11/12 21:16:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/11/30 13:01:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2008/05/08 10:00:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2005/12/07 23:04:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe Systems
[2007/12/24 14:05:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2008/11/30 12:51:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL Downloads
[2006/12/14 02:39:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL OCP
[2007/08/13 21:01:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2006/10/04 02:36:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2005/12/26 02:55:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameHouse
[2007/07/03 23:19:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2005/09/05 13:47:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2005/09/03 05:44:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\hpqwmi
[2005/04/10 07:51:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2007/12/24 13:25:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogiShrd
[2007/08/04 09:08:55 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/08/19 13:02:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2005/12/26 07:13:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2005/04/10 08:08:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2007/08/08 18:36:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2006/06/29 02:56:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2005/09/05 10:06:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2005/04/10 05:56:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2008/08/30 12:37:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Skype
[2006/01/17 13:23:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2009/02/19 19:13:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/11/30 13:02:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/07/19 22:37:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/02/22 20:11:27 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Queenie Leung\Application Data
[2005/10/11 21:19:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\.bittorrent
[2007/10/28 17:57:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\.purple
[2007/12/24 14:14:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\acccore
[2008/02/04 17:30:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Adobe
[2008/05/08 09:50:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\AdobeUM
[2007/12/13 19:04:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Aim
[2008/11/12 21:36:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Apple Computer
[2005/10/13 04:04:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Azureus
[2008/06/30 22:21:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\com.zipeg
[2005/12/27 01:41:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Google
[2005/09/07 22:11:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Help
[2005/09/05 13:40:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\HP
[2005/04/10 05:56:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Identities
[2005/12/07 22:51:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Image Zone Express
[2005/10/11 23:22:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\iMesh
[2006/01/30 01:45:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\InterVideo
[2006/09/28 21:20:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\JAMS
[2006/01/17 13:27:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Lavasoft
[2005/11/09 22:03:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Leadertech
[2007/08/13 21:24:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\LimeWire
[2005/09/05 15:46:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Macromedia
[2007/11/08 22:28:47 | 00,000,000 | –SD | M] – C:\Documents and Settings\Queenie Leung\Application Data\Microsoft
[2009/01/17 17:51:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Move Networks
[2008/08/28 22:26:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Mozilla
[2007/07/28 22:56:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\MP3Downloads
[2007/07/09 10:45:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\MSNInstaller
[2005/11/09 22:03:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\muvee Technologies
[2005/12/09 03:02:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Opera
[2006/06/29 02:56:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\PlayFirst
[2006/04/21 23:02:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Raptisoft
[2008/03/28 08:29:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Real
[2007/04/15 12:59:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Ringjacker
[2005/12/18 01:52:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Shareaza
[2008/04/13 15:57:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Skype
[2005/11/09 22:03:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Sonic
[2007/07/06 12:20:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Sony Ericsson
[2005/09/04 02:48:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Sun
[2006/01/17 13:19:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Symantec
[2008/05/11 17:29:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Talkback
[2007/07/06 12:21:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Teleca
[2009/02/23 09:18:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\U3
[2007/09/05 17:45:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Viewpoint
[2005/11/23 04:27:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Wildfire
[2007/09/07 00:16:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\WinRAR
[2005/10/17 19:55:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Queenie Leung\Application Data\Zen Puzzle Garden
[2008/11/21 20:34:05 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004/08/04 03:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/02/23 18:20:25 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Custom Scans ==========



========== Net Services ==========

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\NetSvcs

6to4 - -
AppMgmt - C:\WINDOWS\System32\appmgmts.dll - (Microsoft Corporation)
AudioSrv - C:\WINDOWS\System32\audiosrv.dll - (Microsoft Corporation)
Browser - -
CryptSvc - C:\WINDOWS\System32\cryptsvc.dll - (Microsoft Corporation)
DMServer - C:\WINDOWS\System32\dmserver.dll - (Microsoft Corp.)
DHCP - C:\WINDOWS\System32\dhcpcsvc.dll - (Microsoft Corporation)
ERSvc - C:\WINDOWS\System32\ersvc.dll - (Microsoft Corporation)
EventSystem - C:\WINDOWS\system32\es.dll - (Microsoft Corporation)
FastUserSwitchingCompatibility - C:\WINDOWS\System32\shsvcs.dll - (Microsoft Corporation)
HidServ - C:\WINDOWS\System32\hidserv.dll - (Microsoft Corporation)
Ias - -
Iprip - -
Irmon - -
LanmanServer - C:\WINDOWS\System32\srvsvc.dll - (Microsoft Corporation)
LanmanWorkstation - -
Messenger - -
Netman - C:\WINDOWS\System32\netman.dll - (Microsoft Corporation)
Nla - C:\WINDOWS\System32\mswsock.dll - (Microsoft Corporation)
Ntmssvc - C:\WINDOWS\system32\ntmssvc.dll - (Microsoft Corporation)
NWCWorkstation - -
Nwsapagent - -
Rasauto - C:\WINDOWS\System32\rasauto.dll - (Microsoft Corporation)
Rasman - C:\WINDOWS\System32\rasmans.dll - (Microsoft Corporation)
Remoteaccess - C:\WINDOWS\System32\mprdim.dll - (Microsoft Corporation)
Schedule - C:\WINDOWS\system32\schedsvc.dll - (Microsoft Corporation)
Seclogon - C:\WINDOWS\System32\seclogon.dll - (Microsoft Corporation)
SENS - C:\WINDOWS\system32\sens.dll - (Microsoft Corporation)
Sharedaccess - C:\WINDOWS\System32\ipnathlp.dll - (Microsoft Corporation)
SRService - C:\WINDOWS\system32\srsvc.dll - (Microsoft Corporation)
Tapisrv - C:\WINDOWS\System32\tapisrv.dll - (Microsoft Corporation)
Themes - C:\WINDOWS\System32\shsvcs.dll - (Microsoft Corporation)
TrkWks - C:\WINDOWS\system32\trkwks.dll - (Microsoft Corporation)
W32Time - C:\WINDOWS\system32\w32time.dll - (Microsoft Corporation)
WZCSVC - C:\WINDOWS\System32\wzcsvc.dll - (Microsoft Corporation)
Wmi - C:\WINDOWS\System32\advapi32.dll - (Microsoft Corporation)
WmdmPmSp - -
winmgmt - C:\WINDOWS\system32\wbem\WMIsvc.dll - (Microsoft Corporation)
wscsvc - C:\WINDOWS\system32\wscsvc.dll - (Microsoft Corporation)
xmlprov - C:\WINDOWS\System32\xmlprov.dll - (Microsoft Corporation)
BITS - C:\WINDOWS\system32\qmgr.dll - (Microsoft Corporation)
wuauserv - C:\WINDOWS\system32\wuauserv.dll - (Microsoft Corporation)
ShellHWDetection - C:\WINDOWS\System32\shsvcs.dll - (Microsoft Corporation)
helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll - (Microsoft Corporation)
WmdmPmSN - C:\WINDOWS\system32\MsPMSNSv.dll - (Microsoft Corporation)
napagent - C:\WINDOWS\System32\qagentrt.dll - (Microsoft Corporation)
hkmsvc - C:\WINDOWS\System32\kmsvc.dll - (Microsoft Corporation)


========== Disabled MS Config ==========

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\

C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk - %ProgramFiles%\Microsoft Office\Office10\OSA.EXE - (Microsoft Corporation)
C:^Documents and Settings^Queenie Leung^Start Menu^Programs^Startup^Rainlendar.lnk - %SystemDrive%\PROGRA~1\RAINLE~1\RAINLE~1.EXE - File not found

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\

46052968763107085995260575741194 hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Antivirus 2009\av2009.exe -> File not found
Aim6 hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> -> File not found
ares hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Ares\Ares.exe -> File not found
BearShare hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\BearShare\BearShare.exe -> File not found
Cpqset hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\HPQ\Default Settings\cpqset.exe -> ()
eabconfg.cpl hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\HPQ\Quick Launch Buttons\EabServr.exe -> (Hewlett-Packard )
foxy hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Foxy\Foxy.exe -> File not found
Glass2k hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %SystemDrive%\My Downloads\Glass2k.exe -> File not found
HP Software Update hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\HP\HP Software Update\HPWuSchd2.exe -> (Hewlett-Packard Co.)
hpWirelessAssistant hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe -> (Hewlett-Packard Company)
iTunesHelper hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\iTunes\iTunesHelper.exe -> (Apple Inc.)
LSBWatcher hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %SystemDrive%\hp\drivers\hplsbwatcher\lsburnwatcher.exe -> (Hewlett-Packard Company)
QuickTime Task hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\QuickTime\QTTask.exe -> (Apple Inc.)
SunJavaUpdateSched hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Java\jre1.6.0_07\bin\jusched.exe -> (Sun Microsystems, Inc.)
SynTPEnh hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe -> (Synaptics, Inc.)
SynTPLpr hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Synaptics\SynTP\SynTPLpr.exe -> (Synaptics, Inc.)
TkBellExe hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> (RealNetworks, Inc.)
vptray hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Symantec AntiVirus\VPTray.exe -> (Symantec Corporation)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state

"system.ini" - 0
"win.ini" - 0
"bootini" - 0
"services" - 0
"startup" - 2


========== SafeBoot-Minimal Settings ==========

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\

AppMgmt - %SystemRoot%\System32\appmgmts.dll - (Microsoft Corporation)
Base - Driver Group
Boot Bus Extender - Driver Group
Boot file system - Driver Group
CryptSvc - %SystemRoot%\System32\cryptsvc.dll - (Microsoft Corporation)
DcomLaunch - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
dmadmin - %SystemRoot%\System32\dmadmin.exe - (Microsoft Corp., Veritas Software)
dmboot.sys - %SystemRoot%\System32\drivers\dmboot.sys - (Microsoft Corp., Veritas Software)
dmio.sys - %SystemRoot%\System32\drivers\dmio.sys - (Microsoft Corp., Veritas Software)
dmload.sys - %SystemRoot%\System32\drivers\dmload.sys - (Microsoft Corp., Veritas Software.)
dmserver - %SystemRoot%\System32\dmserver.dll - (Microsoft Corp.)
EventLog - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
File system - Driver Group
Filter - Driver Group
HelpSvc - %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll - (Microsoft Corporation)
Netlogon - Service
PCI Configuration - Driver Group
PlugPlay - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
PNP Filter - Driver Group
Primary disk - Driver Group
RpcSs - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
SCSI Class - Driver Group
sermouse.sys - Driver
sr.sys - %SystemRoot%\system32\DRIVERS\sr.sys - (Microsoft Corporation)
SRService - %SystemRoot%\system32\srsvc.dll - (Microsoft Corporation)
System Bus Extender - Driver Group
vds - Service
vga.sys - Driver
vgasave.sys - %SystemRoot%\System32\drivers\vga.sys - (Microsoft Corporation)
WinMgmt - %SystemRoot%\system32\wbem\WMIsvc.dll - (Microsoft Corporation)
{36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
{4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
{4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
{4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
{4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
{4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
{4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
{4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
{4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
{4D36E97D-E325-11CE-BFC1-08002BE10318} - System
{4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
{533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
{71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices


========== SafeBoot-Network Settings ==========

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\

AFD - %SystemRoot%\System32\drivers\afd.sys - (Microsoft Corporation)
AppMgmt - %SystemRoot%\System32\appmgmts.dll - (Microsoft Corporation)
Base - Driver Group
Boot Bus Extender - Driver Group
Boot file system - Driver Group
Browser - Service
CryptSvc - %SystemRoot%\System32\cryptsvc.dll - (Microsoft Corporation)
DcomLaunch - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
Dhcp - %SystemRoot%\System32\dhcpcsvc.dll - (Microsoft Corporation)
dmadmin - %SystemRoot%\System32\dmadmin.exe - (Microsoft Corp., Veritas Software)
dmboot.sys - %SystemRoot%\System32\drivers\dmboot.sys - (Microsoft Corp., Veritas Software)
dmio.sys - %SystemRoot%\System32\drivers\dmio.sys - (Microsoft Corp., Veritas Software)
dmload.sys - %SystemRoot%\System32\drivers\dmload.sys - (Microsoft Corp., Veritas Software.)
dmserver - %SystemRoot%\System32\dmserver.dll - (Microsoft Corp.)
DnsCache - %SystemRoot%\System32\dnsrslvr.dll - (Microsoft Corporation)
EventLog - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
File system - Driver Group
Filter - Driver Group
HelpSvc - %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dll - (Microsoft Corporation)
ip6fw.sys - %SystemRoot%\system32\drivers\ip6fw.sys - (Microsoft Corporation)
ipnat.sys - %SystemRoot%\system32\DRIVERS\ipnat.sys - (Microsoft Corporation)
LanmanServer - %SystemRoot%\System32\srvsvc.dll - (Microsoft Corporation)
LanmanWorkstation - Service
LmHosts - %SystemRoot%\System32\lmhsvc.dll - (Microsoft Corporation)
Messenger - - File not found
NDIS - %SystemRoot%\System32\drivers\ndis.sys - (Microsoft Corporation)
NDIS Wrapper - Driver Group
Ndisuio - %SystemRoot%\system32\DRIVERS\ndisuio.sys - (Microsoft Corporation)
NetBIOS - Service
NetBIOSGroup - Driver Group
NetBT - %SystemRoot%\system32\DRIVERS\netbt.sys - (Microsoft Corporation)
NetDDEGroup - Driver Group
Netlogon - Service
NetMan - %SystemRoot%\System32\netman.dll - (Microsoft Corporation)
Network - Driver Group
NetworkProvider - Driver Group
NtLmSsp - Service
PCI Configuration - Driver Group
PlugPlay - %SystemRoot%\system32\services.exe - (Microsoft Corporation)
PNP Filter - Driver Group
PNP_TDI - Driver Group
Primary disk - Driver Group
rdpcdd.sys - %SystemRoot%\System32\DRIVERS\RDPCDD.sys - (Microsoft Corporation)
rdpdd.sys - %SystemRoot%\System32\rdpdd.dll - (Microsoft Corporation)
rdpwd.sys - %SystemRoot%\System32\drivers\rdpwd.sys - (Microsoft Corporation)
rdsessmgr - %SystemRoot%\system32\sessmgr.exe - (Microsoft Corporation)
RpcSs - %SystemRoot%\system32\rpcss.dll - (Microsoft Corporation)
SCSI Class - Driver Group
sermouse.sys - Driver
SharedAccess - %SystemRoot%\System32\ipnathlp.dll - (Microsoft Corporation)
sr.sys - %SystemRoot%\system32\DRIVERS\sr.sys - (Microsoft Corporation)
SRService - %SystemRoot%\system32\srsvc.dll - (Microsoft Corporation)
Streams Drivers - Driver Group
System Bus Extender - Driver Group
Tcpip - %SystemRoot%\system32\DRIVERS\tcpip.sys - (Microsoft Corporation)
TDI - Driver Group
tdpipe.sys - %SystemRoot%\System32\drivers\tdpipe.sys - (Microsoft Corporation)
tdtcp.sys - %SystemRoot%\System32\drivers\tdtcp.sys - (Microsoft Corporation)
termservice - %SystemRoot%\System32\termsrv.dll - (Microsoft Corporation)
vga.sys - Driver
vgasave.sys - %SystemRoot%\System32\drivers\vga.sys - (Microsoft Corporation)
WinMgmt - %SystemRoot%\system32\wbem\WMIsvc.dll - (Microsoft Corporation)
WZCSVC - %SystemRoot%\System32\wzcsvc.dll - (Microsoft Corporation)
{36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
{4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
{4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
{4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
{4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
{4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
{4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
{4D36E972-E325-11CE-BFC1-08002BE10318} - Net
{4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
{4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
{4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
{4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
{4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
{4D36E97D-E325-11CE-BFC1-08002BE10318} - System
{4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
{71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
{745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

< %systemroot%\System32\antiwpa.dll >

< %systemroot%\SYSTEM32\wpa.dll >

< %systemroot%\setup\scripts\biestart.exe >

< %systemroot%\system32\serauth1.dll >

< %systemroot%\system32\serauth2.dll >

< %systemroot%\system32\sysaudio.sys >

< %systemroot%\system32\wdmaud.sys >

< %systemroot%\system32\aeaudio.sys >

========== Alternate Data Streams ==========

@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Queenie Leung\My Documents\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Queenie Leung\Desktop\Thumbs.db:encryptable
< End of report >
EXTRA OTListIt Extras logfile created on: 2/23/2009 6:27:01 PM - Run
OTListIt2 by OldTimer - Version 2.0.1.1 Folder = C:\Documents and Settings\Queenie Leung\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

502.42 Mb Total Physical Memory | 87.66 Mb Available Physical Memory | 17.45% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 4096 10240;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.68 Gb Total Space | 15.17 Gb Free Space | 27.24% Space Free | Partition Type: NTFS
Drive D: | 58.68 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: QUEENIE
Current User Name: Queenie Leung
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink File not found
C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus File not found
C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client (www.BitComet.com)
C:\Program Files\Ares\Ares.exe:*:Enabled:Ares File not found
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk File not found
C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader (AOL LLC)
C:\Program Files\Common Files\AOL\1159491367\ee\aolsoftware.exe:*:Enabled:AOL Services File not found
C:\Program Files\Common Files\AOL\1159491367\ee\aim6.exe:*:Enabled:AIM File not found
C:\Program Files\Foxy\Foxy.exe:*:Enabled:Foxy File not found
C:\Program Files\Morpheus\Morpheus.exe:*:Enabled:Morpheus File not found
C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire (Lime Wire, LLC)
C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger File not found
C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM (AOL LLC)
C:\Program Files\uTorrent\uTorrent.exe:*:Disabled:µTorrent File not found
C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype File not found
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{06ECCCF4-9295-468E-851C-9529A7C181E8}" = HP User Guides 0001
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic Data Module
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C0BAFCA-BDB8-492B-8845-DC0A4B4C1823}" = HPDeskjet5400Series
"{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}" = HP Wireless Assistant
"{47813E93-F2A0-484A-838E-47EC1B28D190}" = Adobe Stock Photos 1.0
"{5421155F-B033-49DB-9B33-8F80F233D4D5}" = GdiplusUpgrade
"{5624C000-B109-11D4-9DB4-00E0290FCAC5}" = VPN Client
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{5A633ED0-E5D7-4D65-AB8D-53ED43510284}" = Symantec AntiVirus
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{618F637A-5D4D-48F4-9679-D02F45BD4315}" = LS_HSI
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver for Mobile
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{8E50332B-772C-4AEA-BF56-94DE6A1D5F10}" = TIxx21
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD
"{976C2B2A-CE59-4AB3-83FB-BF895E28F2E6}" = Apple Mobile Device Support
"{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}" = HP Help and Support
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic Audio Module
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic Copy Module
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{BD57EA4D-026E-4F08-9B93-080E282B81FE}" = iPod for Windows 2006-06-28
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CEB326EC-8F40-47B2-BA22-BB092565D66F}" = Quick Launch Buttons 5.10 B2
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{DDDE0BE3-0CBE-4BF6-B75A-E3F69C947843}" = iTunes
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{EB57A16E-500D-43d7-85B9-FBE279EBBA6E}" = HP Deskjet 5400 series
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"Ad-Aware SE Plus" = Ad-Aware SE Plus
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Adobe Shockwave Player" = Adobe Shockwave Player
"AIM_6" = AIM 6
"BitComet" = BitComet 0.70
"BitTorrent" = BitTorrent 4.0.4
"CNXT_MODEM_PCI_VEN_8086&DEV_266D&SUBSYS_3080103C" = Soft Data Fax Modem with SmartCP
"Conexant PCI Audio" = Conexant AC-Link Audio
"HijackThis" = HijackThis 2.0.2
"HP Imaging Device Functions" = HP Imaging Device Functions 5.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{8E50332B-772C-4AEA-BF56-94DE6A1D5F10}" = Texas Instruments PCIxx21/x515 drivers.
"InstallShield_{BD57EA4D-026E-4F08-9B93-080E282B81FE}" = iPod for Windows 2006-06-28
"LiveUpdate" = LiveUpdate 2.7 (Symantec Corporation)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Money2005b" = Microsoft Money 2005
"Mozilla Firefox (3.0.6)" = Mozilla Firefox (3.0.6)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Picasa2" = Picasa 2
"RealPlayer 6.0" = RealPlayer
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"XBTB00788.XBTB00788Toolbar" = Calorie-Count.com Toolbar

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/23/2009 2:24:48 PM | Computer Name = QUEENIE | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Trojan.Vundo in File: C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP825\A0218697.dll
by: Auto-Protect scan. Action: Clean failed : Quarantine failed : Delete succeeded
: Access denied. Action Description: The file was deleted successfully.

Error - 2/23/2009 2:25:03 PM | Computer Name = QUEENIE | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Threat: Trojan.Vundo in File: C:\SYSTEM~1\_RESTO~1\RP825\A0218697.dll
by: Auto-Protect scan. Action: Reboot Required. Action Description: The file
was deleted successfully.

Error - 2/23/2009 2:47:33 PM | Computer Name = QUEENIE | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Threat: Trojan.Vundo in File: C:\SYSTEM~1\_RESTO~1\RP825\A0218698.dll
by: Auto-Protect scan. Action: Clean failed : Quarantine failed. Action Description:
The file was deleted successfully.

Error - 2/23/2009 2:47:33 PM | Computer Name = QUEENIE | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Trojan.Vundo in File: C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP825\A0218698.dll
by: Auto-Protect scan. Action: Clean failed : Quarantine failed : Delete succeeded
: Access denied. Action Description: The file was deleted successfully.

Error - 2/23/2009 2:47:38 PM | Computer Name = QUEENIE | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Threat: Trojan.Vundo in File: C:\SYSTEM~1\_RESTO~1\RP825\A0218698.dll
by: Auto-Protect scan. Action: Reboot Required. Action Description: The file
was deleted successfully.

Error - 2/23/2009 7:31:26 PM | Computer Name = QUEENIE | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Threat: Trojan.Vundo in File: C:\WINDOWS\System32\cbsnpz.dll
by: Auto-Protect scan. Action: Clean failed : Quarantine failed. Action Description:
The file was deleted successfully.

Error - 2/23/2009 7:31:31 PM | Computer Name = QUEENIE | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Trojan.Vundo in File: C:\WINDOWS\system32\cbsnpz.dll
by: Auto-Protect scan. Action: Clean failed : Quarantine failed : Delete succeeded
: Access denied. Action Description: The file was deleted successfully.

Error - 2/23/2009 7:31:43 PM | Computer Name = QUEENIE | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Threat: Trojan.Vundo in File: C:\WINDOWS\System32\cbsnpz.dll
by: Auto-Protect scan. Action: Reboot Required. Action Description: The file
was deleted successfully.

Error - 2/23/2009 7:33:06 PM | Computer Name = QUEENIE | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Threat: Trojan.Metajuan in File: C:\WINDOWS\System32\espjawnf.dll
by: Auto-Protect scan. Action: Clean failed : Quarantine failed. Action Description:
The file was deleted successfully.

Error - 2/23/2009 7:33:07 PM | Computer Name = QUEENIE | Source = Symantec AntiVirus | ID = 16711685
Description = Threat Found!Threat: Trojan.Metajuan in File: C:\WINDOWS\system32\espjawnf.dll
by: Auto-Protect scan. Action: Clean failed : Quarantine failed : Delete succeeded
: Access denied. Action Description: The file was deleted successfully.

[ System Events ]
Error - 2/23/2009 12:09:09 AM | Computer Name = QUEENIE | Source = Service Control Manager | ID = 7023
Description = The IPSEC Services service terminated with the following error: %%1747

Error - 2/23/2009 1:09:31 AM | Computer Name = QUEENIE | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.

Error - 2/23/2009 1:31:56 AM | Computer Name = QUEENIE | Source = Service Control Manager | ID = 7000
Description = The HP Pci Information service failed to start due to the following
error: %%3

Error - 2/23/2009 1:31:56 AM | Computer Name = QUEENIE | Source = Service Control Manager | ID = 7023
Description = The IPSEC Services service terminated with the following error: %%1747

Error - 2/23/2009 9:45:17 AM | Computer Name = QUEENIE | Source = PSched | ID = 14103
Description = QoS [Adapter {1E439CBE-6F33-4178-B0BC-D56EBEDCF3C6}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.

Error - 2/23/2009 12:00:35 PM | Computer Name = QUEENIE | Source = PSched | ID = 14103
Description = QoS [Adapter {1E439CBE-6F33-4178-B0BC-D56EBEDCF3C6}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.

Error - 2/23/2009 7:20:20 PM | Computer Name = QUEENIE | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.136 for the Network Card with network
address 0015000583E0 has been denied by the DHCP server 192.168.10.1 (The DHCP Server
sent a DHCPNACK message).

Error - 2/23/2009 7:20:23 PM | Computer Name = QUEENIE | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0015000583E0. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.

Error - 2/23/2009 7:21:10 PM | Computer Name = QUEENIE | Source = Service Control Manager | ID = 7000
Description = The HP Pci Information service failed to start due to the following
error: %%3

Error - 2/23/2009 7:21:10 PM | Computer Name = QUEENIE | Source = Service Control Manager | ID = 7023
Description = The IPSEC Services service terminated with the following error: %%1747


< End of report >



please let me know if this is what you needed =)
hello


Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O2 - BHO: (no name) - {534C9916-EC47-46DE-B7F6-10F06C309F04} - C:\WINDOWS\system32\khfCstrQ.dll File not found
    O2 - BHO: (no name) - {57F7EDCC-EB32-4082-A098-318E931773D1} - C:\WINDOWS\system32\ljJDUNHx.dll File not found
    O2 - BHO: (no name) - {5BA73F0D-7B52-4E5A-9763-DDAD6268CD02} - C:\WINDOWS\system32\urqOGWMd.dll File not found
    O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\ssqQhfde.dll ()
    O2 - BHO: (no name) - {88a796be-b4ec-4cfe-9074-198b28ab0973} - C:\WINDOWS\system32\gitdlk.dll ()
    O2 - BHO: (no name) - {96D496B3-D54E-42D9-86E5-5456E9F2D262} - C:\WINDOWS\system32\pmnljKbX.dll ()
    O2 - BHO: (no name) - {E43DDAE6-117B-47FF-A1EC-EBE1CA5C0024} - C:\WINDOWS\system32\byXQKDUO.dll File not found
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - Reg Error: Key error. File not found
    O4 - HKLM..\Run: [314c2356] rundll32.exe "C:\WINDOWS\system32\lnebwupq.dll",b ()
    O20 - AppInit_DLLs: (gitdlk.dll) - C:\WINDOWS\system32\gitdlk.dll ()
    O20 - Winlogon\Notify\cbXNDWnO: DllName - cbXNDWnO.dll - File not found
    O20 - Winlogon\Notify\ssqQhfde: DllName - ssqQhfde.dll - C:\WINDOWS\system32\ssqQhfde.dll ()
    O28 - HKLM ShellExecuteHooks: {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\ssqQhfde.dll ()
    O29 - HKLM SecurityProviders - ( digeste.dll) - File not found
    O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\pmnljKbX) - C:\WINDOWS\system32\pmnljKbX.dll ()
    O33 - MountPoints2\{17f9b040-328d-11dd-b9f7-0015000583e0}\Shell\AutoRun\command - "" = E:\AutoRun.exe – File not found
    O33 - MountPoints2\{20f01ae4-3e3e-11db-b602-00c09fc929fb}\Shell - "" = AutoRun
    O33 - MountPoints2\{20f01ae4-3e3e-11db-b602-00c09fc929fb}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{20f01ae4-3e3e-11db-b602-00c09fc929fb}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
    O33 - MountPoints2\{30351328-0775-11dc-b775-00c09fc929fb}\Shell - "" = AutoRun
    O33 - MountPoints2\{30351328-0775-11dc-b775-00c09fc929fb}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{30351328-0775-11dc-b775-00c09fc929fb}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
    O33 - MountPoints2\{30351329-0775-11dc-b775-00c09fc929fb}\Shell\Auto\command - "" = G:\Ghost.pif – File not found
    O33 - MountPoints2\{30351329-0775-11dc-b775-00c09fc929fb}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\Shell - "" = AutoRun
    O33 - MountPoints2\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\Shell\1\Command - "" = .\RECYCLER\Lcass.exe
    O33 - MountPoints2\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\Shell\2\Command - "" = .\RECYCLER\Lcass.exe
    O33 - MountPoints2\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{67e1c64f-35b9-11dc-b7cf-0015000583e0}\Shell - "" = AutoRun
    O33 - MountPoints2\{67e1c64f-35b9-11dc-b7cf-0015000583e0}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{67e1c64f-35b9-11dc-b7cf-0015000583e0}\Shell\AutoRun\command - "" = E:\Launcher.exe – File not found
    O33 - MountPoints2\{9f6e0d9c-4970-11dd-ba1a-0015000583e0}\Shell - "" = AutoRun
    O33 - MountPoints2\{9f6e0d9c-4970-11dd-ba1a-0015000583e0}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{9f6e0d9c-4970-11dd-ba1a-0015000583e0}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
    O33 - MountPoints2\{d20d7854-2a78-11dc-b7b7-00c09fc929fb}\Shell - "" = AutoRun
    O33 - MountPoints2\{d20d7854-2a78-11dc-b7b7-00c09fc929fb}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{d20d7854-2a78-11dc-b7b7-00c09fc929fb}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
    O33 - MountPoints2\{f7cf81b8-fe9d-11dd-bb2a-0015000583e0}\Shell - "" = AutoRun
    O33 - MountPoints2\{f7cf81b8-fe9d-11dd-bb2a-0015000583e0}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{f7cf81b8-fe9d-11dd-bb2a-0015000583e0}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
    O33 - MountPoints2\E\Shell - "" = AutoRun
    O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
    O33 - MountPoints2\G\Shell - "" = AutoRun
    O33 - MountPoints2\G\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
    [1 C:\*.tmp files]
    [1 C:\WINDOWS\*.tmp files]
    [10 C:\Documents and Settings\Queenie Leung\My Documents\*.tmp files]
    File not found – C:\WINDOWS\System32\wgsjsume.dll
    File not found – C:\WINDOWS\System32\unedukru.dll
    File not found – C:\WINDOWS\System32\tnakrraf.dll
    File not found – C:\WINDOWS\System32\nxoxwvsj.dll
    File not found – C:\WINDOWS\System32\nnpkyh.dll
    File not found – C:\WINDOWS\System32\nfjmuvpe.dll
    File not found – C:\WINDOWS\System32\maxaolvg.dll
    File not found – C:\WINDOWS\System32\kslddono.dll
    File not found – C:\WINDOWS\System32\kppkvlgu.dll
    File not found – C:\WINDOWS\System32\kgfktdjh.dll
    File not found – C:\WINDOWS\System32\gxkggp.dll
    File not found – C:\WINDOWS\System32\espjawnf.dll
    File not found – C:\WINDOWS\System32\cbsnpz.dll
    [2009/02/23 18:30:04 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\ofivoilk.dll
    [2009/02/23 18:27:32 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\gitdlk.dll
    [2009/02/23 18:27:31 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\bhgvdkdv.dll
    [2009/02/23 18:27:02 | 00,002,409 | -HS- | C] () – C:\WINDOWS\System32\XbKjlnmp.ini2
    [2009/02/23 18:27:01 | 00,002,409 | -HS- | C] () – C:\WINDOWS\System32\XbKjlnmp.ini
    [2009/02/23 18:26:57 | 00,302,592 | —- | C] () – C:\WINDOWS\System32\pmnljKbX.dll
    [2009/02/23 12:37:55 | 01,587,449 | -HS- | C] () – C:\WINDOWS\System32\qpuwbenl.ini
    [2009/02/23 12:37:49 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\lnebwupq.dll
    [2009/02/23 12:36:14 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\vaajnx.dll
    [2009/02/23 12:34:58 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\mjnrhbkw.dll
    [2009/02/22 23:17:33 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\nvnhqo.dll
    [2009/02/22 23:17:29 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\jumdlpmd.dll
    [2009/02/22 23:14:50 | 01,607,788 | -HS- | C] () – C:\WINDOWS\System32\onrjonwo.ini
    [2009/02/22 23:14:48 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\ownojrno.dll
    [2009/02/22 20:25:01 | 01,607,788 | -HS- | C] () – C:\WINDOWS\System32\vafgovpp.ini
    [2009/02/22 19:35:41 | 01,607,788 | -HS- | C] () – C:\WINDOWS\System32\rqvfuvma.ini
    [2009/02/22 19:33:27 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\dhyuej.dll
    [2009/02/22 19:33:25 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\klcmlevu.dll
    [2009/02/02 23:28:17 | 00,036,352 | —- | C] () – C:\WINDOWS\System32\fccaAsRH.dll
    [2009/02/02 23:26:54 | 00,036,352 | —- | C] () – C:\WINDOWS\System32\ssqQhfde.dll
    [2009/02/02 22:53:57 | 01,508,191 | -HS- | C] () – C:\WINDOWS\System32\xwteoaey.ini
    [2009/01/29 00:13:12 | 01,515,358 | -HS- | C] () – C:\WINDOWS\System32\smmcfbpc.ini
    [2009/01/28 00:10:33 | 01,516,535 | -HS- | C] () – C:\WINDOWS\System32\farrkant.ini
    [2009/01/26 17:14:40 | 01,525,122 | -HS- | C] () – C:\WINDOWS\System32\wsftufxc.ini
    [2009/01/25 21:05:33 | 01,434,061 | -HS- | C] () – C:\WINDOWS\System32\tacithut.ini
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )
Here is the new OTL2 log ========== OTLISTIT ========== Process explorer.exe killed successfully! Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{534C9916-EC47-46DE-B7F6-10F06C309F04}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{534C9916-EC47-46DE-B7F6-10F06C309F04}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{57F7EDCC-EB32-4082-A098-318E931773D1}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{57F7EDCC-EB32-4082-A098-318E931773D1}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5BA73F0D-7B52-4E5A-9763-DDAD6268CD02}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5BA73F0D-7B52-4E5A-9763-DDAD6268CD02}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}\ deleted successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\ssqQhfde.dll C:\WINDOWS\system32\ssqQhfde.dll NOT unregistered. File move failed. C:\WINDOWS\system32\ssqQhfde.dll scheduled to be moved on reboot. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{88a796be-b4ec-4cfe-9074-198b28ab0973}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88a796be-b4ec-4cfe-9074-198b28ab0973}\ not found. DllUnregisterServer procedure not found in C:\WINDOWS\system32\gitdlk.dll C:\WINDOWS\system32\gitdlk.dll NOT unregistered. C:\WINDOWS\system32\gitdlk.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{96D496B3-D54E-42D9-86E5-5456E9F2D262}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{96D496B3-D54E-42D9-86E5-5456E9F2D262}\ deleted successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\pmnljKbX.dll C:\WINDOWS\system32\pmnljKbX.dll NOT unregistered. C:\WINDOWS\system32\pmnljKbX.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E43DDAE6-117B-47FF-A1EC-EBE1CA5C0024}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E43DDAE6-117B-47FF-A1EC-EBE1CA5C0024}\ deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB87BFA2-A2E3-451E-8E5A-C89982D87CBF}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\314c2356 deleted successfully. File rundll32.exe "C:\WINDOWS\system32\lnebwupq.dll",b not found. Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:gitdlk.dll scheduled to be deleted on reboot. File C:\WINDOWS\system32\gitdlk.dll not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbXNDWnO\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqQhfde\ deleted successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\ssqQhfde.dll C:\WINDOWS\system32\ssqQhfde.dll NOT unregistered. File move failed. C:\WINDOWS\system32\ssqQhfde.dll scheduled to be moved on reboot. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}\ deleted successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\ssqQhfde.dll C:\WINDOWS\system32\ssqQhfde.dll NOT unregistered. File move failed. C:\WINDOWS\system32\ssqQhfde.dll scheduled to be moved on reboot. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders:digeste.dll deleted successfully. Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages:C:\WINDOWS\system32\pmnljKbX scheduled to be deleted on reboot. File C:\WINDOWS\system32\pmnljKbX.dll not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{17f9b040-328d-11dd-b9f7-0015000583e0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17f9b040-328d-11dd-b9f7-0015000583e0}\ not found. File E:\AutoRun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{20f01ae4-3e3e-11db-b602-00c09fc929fb}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20f01ae4-3e3e-11db-b602-00c09fc929fb}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{20f01ae4-3e3e-11db-b602-00c09fc929fb}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20f01ae4-3e3e-11db-b602-00c09fc929fb}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{20f01ae4-3e3e-11db-b602-00c09fc929fb}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20f01ae4-3e3e-11db-b602-00c09fc929fb}\ not found. File move failed. G:\LaunchU3.exe scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{30351328-0775-11dc-b775-00c09fc929fb}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30351328-0775-11dc-b775-00c09fc929fb}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{30351328-0775-11dc-b775-00c09fc929fb}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30351328-0775-11dc-b775-00c09fc929fb}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{30351328-0775-11dc-b775-00c09fc929fb}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30351328-0775-11dc-b775-00c09fc929fb}\ not found. File F:\LaunchU3.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{30351329-0775-11dc-b775-00c09fc929fb}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30351329-0775-11dc-b775-00c09fc929fb}\ not found. File G:\Ghost.pif not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{30351329-0775-11dc-b775-00c09fc929fb}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30351329-0775-11dc-b775-00c09fc929fb}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{67e1c64f-35b9-11dc-b7cf-0015000583e0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67e1c64f-35b9-11dc-b7cf-0015000583e0}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{67e1c64f-35b9-11dc-b7cf-0015000583e0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67e1c64f-35b9-11dc-b7cf-0015000583e0}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{67e1c64f-35b9-11dc-b7cf-0015000583e0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67e1c64f-35b9-11dc-b7cf-0015000583e0}\ not found. File E:\Launcher.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9f6e0d9c-4970-11dd-ba1a-0015000583e0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9f6e0d9c-4970-11dd-ba1a-0015000583e0}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9f6e0d9c-4970-11dd-ba1a-0015000583e0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9f6e0d9c-4970-11dd-ba1a-0015000583e0}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9f6e0d9c-4970-11dd-ba1a-0015000583e0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9f6e0d9c-4970-11dd-ba1a-0015000583e0}\ not found. File E:\LaunchU3.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d20d7854-2a78-11dc-b7b7-00c09fc929fb}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d20d7854-2a78-11dc-b7b7-00c09fc929fb}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d20d7854-2a78-11dc-b7b7-00c09fc929fb}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d20d7854-2a78-11dc-b7b7-00c09fc929fb}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d20d7854-2a78-11dc-b7b7-00c09fc929fb}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d20d7854-2a78-11dc-b7b7-00c09fc929fb}\ not found. File F:\LaunchU3.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f7cf81b8-fe9d-11dd-bb2a-0015000583e0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f7cf81b8-fe9d-11dd-bb2a-0015000583e0}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f7cf81b8-fe9d-11dd-bb2a-0015000583e0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f7cf81b8-fe9d-11dd-bb2a-0015000583e0}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f7cf81b8-fe9d-11dd-bb2a-0015000583e0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f7cf81b8-fe9d-11dd-bb2a-0015000583e0}\ not found. File E:\LaunchU3.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ deleted successfully. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ not found. File E:\LaunchU3.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\ deleted successfully. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\ not found. File move failed. G:\LaunchU3.exe scheduled to be moved on reboot. File C:\*.tmp not found. File C:\WINDOWS\*.tmp not found. File C:\Documents and Settings\Queenie Leung\My Documents\*.tmp not found. DllUnregisterServer procedure not found in C:\WINDOWS\System32\ofivoilk.dll C:\WINDOWS\System32\ofivoilk.dll NOT unregistered. C:\WINDOWS\System32\ofivoilk.dll moved successfully. File C:\WINDOWS\System32\gitdlk.dll not found. DllUnregisterServer procedure not found in C:\WINDOWS\System32\bhgvdkdv.dll C:\WINDOWS\System32\bhgvdkdv.dll NOT unregistered. C:\WINDOWS\System32\bhgvdkdv.dll moved successfully. C:\WINDOWS\System32\XbKjlnmp.ini2 moved successfully. C:\WINDOWS\System32\XbKjlnmp.ini moved successfully. File C:\WINDOWS\System32\pmnljKbX.dll not found. C:\WINDOWS\System32\qpuwbenl.ini moved successfully. File C:\WINDOWS\System32\lnebwupq.dll not found. DllUnregisterServer procedure not found in C:\WINDOWS\System32\vaajnx.dll C:\WINDOWS\System32\vaajnx.dll NOT unregistered. C:\WINDOWS\System32\vaajnx.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\mjnrhbkw.dll C:\WINDOWS\System32\mjnrhbkw.dll NOT unregistered. C:\WINDOWS\System32\mjnrhbkw.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\nvnhqo.dll C:\WINDOWS\System32\nvnhqo.dll NOT unregistered. C:\WINDOWS\System32\nvnhqo.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\jumdlpmd.dll C:\WINDOWS\System32\jumdlpmd.dll NOT unregistered. C:\WINDOWS\System32\jumdlpmd.dll moved successfully. C:\WINDOWS\System32\onrjonwo.ini moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\ownojrno.dll C:\WINDOWS\System32\ownojrno.dll NOT unregistered. C:\WINDOWS\System32\ownojrno.dll moved successfully. C:\WINDOWS\System32\vafgovpp.ini moved successfully. C:\WINDOWS\System32\rqvfuvma.ini moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\dhyuej.dll C:\WINDOWS\System32\dhyuej.dll NOT unregistered. C:\WINDOWS\System32\dhyuej.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\klcmlevu.dll C:\WINDOWS\System32\klcmlevu.dll NOT unregistered. C:\WINDOWS\System32\klcmlevu.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\fccaAsRH.dll C:\WINDOWS\System32\fccaAsRH.dll NOT unregistered. C:\WINDOWS\System32\fccaAsRH.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\ssqQhfde.dll C:\WINDOWS\System32\ssqQhfde.dll NOT unregistered. File move failed. C:\WINDOWS\System32\ssqQhfde.dll scheduled to be moved on reboot. C:\WINDOWS\System32\xwteoaey.ini moved successfully. C:\WINDOWS\System32\smmcfbpc.ini moved successfully. C:\WINDOWS\System32\farrkant.ini moved successfully. C:\WINDOWS\System32\wsftufxc.ini moved successfully. C:\WINDOWS\System32\tacithut.ini moved successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== File delete failed. C:\Documents and Settings\Queenie Leung\Local Settings\Temp\etilqs_6I9283R2mY5TF7sQ42ok scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTListIt2 by OldTimer - Version 2.0.1.1 log created on 02232009_231156 Files moved on Reboot… DllUnregisterServer procedure not found in C:\WINDOWS\system32\ssqQhfde.dll C:\WINDOWS\system32\ssqQhfde.dll NOT unregistered. File move failed. C:\WINDOWS\system32\ssqQhfde.dll scheduled to be moved on reboot. File G:\LaunchU3.exe not found! File C:\Documents and Settings\Queenie Leung\Local Settings\Temp\etilqs_6I9283R2mY5TF7sQ42ok not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\urlclassifier3.sqlite moved successfully. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\XUL.mfl moved successfully. Registry entries deleted on Reboot… Registry delete failed. :HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:gitdlk.dll scheduled to be deleted on reboot. Registry delete failed. :HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages:C:\WINDOWS\system32\pmnljKbX scheduled to be deleted on reboot.
is this the new log you are talking about - the otl2 log. i apologize - the only one i can find is the same as above. please see below for it again. ========== OTLISTIT ========== Process explorer.exe killed successfully! Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{534C9916-EC47-46DE-B7F6-10F06C309F04}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{534C9916-EC47-46DE-B7F6-10F06C309F04}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{57F7EDCC-EB32-4082-A098-318E931773D1}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{57F7EDCC-EB32-4082-A098-318E931773D1}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5BA73F0D-7B52-4E5A-9763-DDAD6268CD02}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5BA73F0D-7B52-4E5A-9763-DDAD6268CD02}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}\ deleted successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\ssqQhfde.dll C:\WINDOWS\system32\ssqQhfde.dll NOT unregistered. File move failed. C:\WINDOWS\system32\ssqQhfde.dll scheduled to be moved on reboot. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{88a796be-b4ec-4cfe-9074-198b28ab0973}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88a796be-b4ec-4cfe-9074-198b28ab0973}\ not found. DllUnregisterServer procedure not found in C:\WINDOWS\system32\gitdlk.dll C:\WINDOWS\system32\gitdlk.dll NOT unregistered. C:\WINDOWS\system32\gitdlk.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{96D496B3-D54E-42D9-86E5-5456E9F2D262}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{96D496B3-D54E-42D9-86E5-5456E9F2D262}\ deleted successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\pmnljKbX.dll C:\WINDOWS\system32\pmnljKbX.dll NOT unregistered. C:\WINDOWS\system32\pmnljKbX.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E43DDAE6-117B-47FF-A1EC-EBE1CA5C0024}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E43DDAE6-117B-47FF-A1EC-EBE1CA5C0024}\ deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB87BFA2-A2E3-451E-8E5A-C89982D87CBF}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\314c2356 deleted successfully. File rundll32.exe "C:\WINDOWS\system32\lnebwupq.dll",b not found. Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:gitdlk.dll scheduled to be deleted on reboot. File C:\WINDOWS\system32\gitdlk.dll not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbXNDWnO\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqQhfde\ deleted successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\ssqQhfde.dll C:\WINDOWS\system32\ssqQhfde.dll NOT unregistered. File move failed. C:\WINDOWS\system32\ssqQhfde.dll scheduled to be moved on reboot. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}\ deleted successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\ssqQhfde.dll C:\WINDOWS\system32\ssqQhfde.dll NOT unregistered. File move failed. C:\WINDOWS\system32\ssqQhfde.dll scheduled to be moved on reboot. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders:digeste.dll deleted successfully. Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages:C:\WINDOWS\system32\pmnljKbX scheduled to be deleted on reboot. File C:\WINDOWS\system32\pmnljKbX.dll not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{17f9b040-328d-11dd-b9f7-0015000583e0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17f9b040-328d-11dd-b9f7-0015000583e0}\ not found. File E:\AutoRun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{20f01ae4-3e3e-11db-b602-00c09fc929fb}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20f01ae4-3e3e-11db-b602-00c09fc929fb}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{20f01ae4-3e3e-11db-b602-00c09fc929fb}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20f01ae4-3e3e-11db-b602-00c09fc929fb}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{20f01ae4-3e3e-11db-b602-00c09fc929fb}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20f01ae4-3e3e-11db-b602-00c09fc929fb}\ not found. File move failed. G:\LaunchU3.exe scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{30351328-0775-11dc-b775-00c09fc929fb}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30351328-0775-11dc-b775-00c09fc929fb}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{30351328-0775-11dc-b775-00c09fc929fb}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30351328-0775-11dc-b775-00c09fc929fb}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{30351328-0775-11dc-b775-00c09fc929fb}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30351328-0775-11dc-b775-00c09fc929fb}\ not found. File F:\LaunchU3.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{30351329-0775-11dc-b775-00c09fc929fb}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30351329-0775-11dc-b775-00c09fc929fb}\ not found. File G:\Ghost.pif not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{30351329-0775-11dc-b775-00c09fc929fb}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30351329-0775-11dc-b775-00c09fc929fb}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4701ee92-e2c0-11db-b74e-00c09fc929fb}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{67e1c64f-35b9-11dc-b7cf-0015000583e0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67e1c64f-35b9-11dc-b7cf-0015000583e0}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{67e1c64f-35b9-11dc-b7cf-0015000583e0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67e1c64f-35b9-11dc-b7cf-0015000583e0}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{67e1c64f-35b9-11dc-b7cf-0015000583e0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67e1c64f-35b9-11dc-b7cf-0015000583e0}\ not found. File E:\Launcher.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9f6e0d9c-4970-11dd-ba1a-0015000583e0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9f6e0d9c-4970-11dd-ba1a-0015000583e0}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9f6e0d9c-4970-11dd-ba1a-0015000583e0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9f6e0d9c-4970-11dd-ba1a-0015000583e0}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9f6e0d9c-4970-11dd-ba1a-0015000583e0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9f6e0d9c-4970-11dd-ba1a-0015000583e0}\ not found. File E:\LaunchU3.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d20d7854-2a78-11dc-b7b7-00c09fc929fb}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d20d7854-2a78-11dc-b7b7-00c09fc929fb}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d20d7854-2a78-11dc-b7b7-00c09fc929fb}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d20d7854-2a78-11dc-b7b7-00c09fc929fb}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d20d7854-2a78-11dc-b7b7-00c09fc929fb}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d20d7854-2a78-11dc-b7b7-00c09fc929fb}\ not found. File F:\LaunchU3.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f7cf81b8-fe9d-11dd-bb2a-0015000583e0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f7cf81b8-fe9d-11dd-bb2a-0015000583e0}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f7cf81b8-fe9d-11dd-bb2a-0015000583e0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f7cf81b8-fe9d-11dd-bb2a-0015000583e0}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f7cf81b8-fe9d-11dd-bb2a-0015000583e0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f7cf81b8-fe9d-11dd-bb2a-0015000583e0}\ not found. File E:\LaunchU3.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ deleted successfully. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ not found. File E:\LaunchU3.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\ deleted successfully. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\ not found. File move failed. G:\LaunchU3.exe scheduled to be moved on reboot. File C:\*.tmp not found. File C:\WINDOWS\*.tmp not found. File C:\Documents and Settings\Queenie Leung\My Documents\*.tmp not found. DllUnregisterServer procedure not found in C:\WINDOWS\System32\ofivoilk.dll C:\WINDOWS\System32\ofivoilk.dll NOT unregistered. C:\WINDOWS\System32\ofivoilk.dll moved successfully. File C:\WINDOWS\System32\gitdlk.dll not found. DllUnregisterServer procedure not found in C:\WINDOWS\System32\bhgvdkdv.dll C:\WINDOWS\System32\bhgvdkdv.dll NOT unregistered. C:\WINDOWS\System32\bhgvdkdv.dll moved successfully. C:\WINDOWS\System32\XbKjlnmp.ini2 moved successfully. C:\WINDOWS\System32\XbKjlnmp.ini moved successfully. File C:\WINDOWS\System32\pmnljKbX.dll not found. C:\WINDOWS\System32\qpuwbenl.ini moved successfully. File C:\WINDOWS\System32\lnebwupq.dll not found. DllUnregisterServer procedure not found in C:\WINDOWS\System32\vaajnx.dll C:\WINDOWS\System32\vaajnx.dll NOT unregistered. C:\WINDOWS\System32\vaajnx.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\mjnrhbkw.dll C:\WINDOWS\System32\mjnrhbkw.dll NOT unregistered. C:\WINDOWS\System32\mjnrhbkw.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\nvnhqo.dll C:\WINDOWS\System32\nvnhqo.dll NOT unregistered. C:\WINDOWS\System32\nvnhqo.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\jumdlpmd.dll C:\WINDOWS\System32\jumdlpmd.dll NOT unregistered. C:\WINDOWS\System32\jumdlpmd.dll moved successfully. C:\WINDOWS\System32\onrjonwo.ini moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\ownojrno.dll C:\WINDOWS\System32\ownojrno.dll NOT unregistered. C:\WINDOWS\System32\ownojrno.dll moved successfully. C:\WINDOWS\System32\vafgovpp.ini moved successfully. C:\WINDOWS\System32\rqvfuvma.ini moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\dhyuej.dll C:\WINDOWS\System32\dhyuej.dll NOT unregistered. C:\WINDOWS\System32\dhyuej.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\klcmlevu.dll C:\WINDOWS\System32\klcmlevu.dll NOT unregistered. C:\WINDOWS\System32\klcmlevu.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\fccaAsRH.dll C:\WINDOWS\System32\fccaAsRH.dll NOT unregistered. C:\WINDOWS\System32\fccaAsRH.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\ssqQhfde.dll C:\WINDOWS\System32\ssqQhfde.dll NOT unregistered. File move failed. C:\WINDOWS\System32\ssqQhfde.dll scheduled to be moved on reboot. C:\WINDOWS\System32\xwteoaey.ini moved successfully. C:\WINDOWS\System32\smmcfbpc.ini moved successfully. C:\WINDOWS\System32\farrkant.ini moved successfully. C:\WINDOWS\System32\wsftufxc.ini moved successfully. C:\WINDOWS\System32\tacithut.ini moved successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== File delete failed. C:\Documents and Settings\Queenie Leung\Local Settings\Temp\etilqs_6I9283R2mY5TF7sQ42ok scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTListIt2 by OldTimer - Version 2.0.1.1 log created on 02232009_231156 Files moved on Reboot… DllUnregisterServer procedure not found in C:\WINDOWS\system32\ssqQhfde.dll C:\WINDOWS\system32\ssqQhfde.dll NOT unregistered. File move failed. C:\WINDOWS\system32\ssqQhfde.dll scheduled to be moved on reboot. File G:\LaunchU3.exe not found! File C:\Documents and Settings\Queenie Leung\Local Settings\Temp\etilqs_6I9283R2mY5TF7sQ42ok not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\urlclassifier3.sqlite moved successfully. C:\Documents and Settings\Queenie Leung\Local Settings\Application Data\Mozilla\Firefox\Profiles\ba4uipof.default\XUL.mfl moved successfully. Registry entries deleted on Reboot… Registry delete failed. :HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:gitdlk.dll scheduled to be deleted on reboot. Registry delete failed. :HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages:C:\WINDOWS\system32\pmnljKbX scheduled to be deleted on reboot.
no do this

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
OTLISTIT log
OTListIt logfile created on: 2/25/2009 10:08:19 AM - Run 5
OTListIt2 by OldTimer - Version 2.0.1.1 Folder = C:\Documents and Settings\Queenie Leung\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

502.42 Mb Total Physical Memory | 175.71 Mb Available Physical Memory | 34.97% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 4096 10240;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.68 Gb Total Space | 15.11 Gb Free Space | 27.14% Space Free | Partition Type: NTFS
Drive D: | 58.68 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: QUEENIE
Current User Name: Queenie Leung
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe ()
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\Queenie Leung\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (ccEvtMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (ccPwdSvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccSetMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (CVPND [Auto | Running]) – C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (DefWatch [Auto | Running]) – C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (hpqwmi [On_Demand | Stopped]) – C:\Program Files\HPQ\SHARED\HPQWMI.exe (Hewlett-Packard Development Company, L.P.)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe ()
SRV - (Pml Driver HPZ12 [Auto | Running]) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (SavRoam [On_Demand | Stopped]) – C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (SNDSrvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (SPBBCSvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (Symantec AntiVirus [Auto | Running]) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (UMWdf [Auto | Running]) – C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service [Auto | Running]) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)

========== Driver Services (SafeList) ==========

DRV - (AliIde [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CAMCAUD [On_Demand | Running]) – C:\WINDOWS\system32\drivers\camc6aud.sys (Conexant Systems Inc.)
DRV - (CAMCHALA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\camc6hal.sys (Conexant Systems Inc.)
DRV - (CamDrL [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\Camdrl.sys (Logitech Inc.)
DRV - (CVirtA [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\CVirtA.sys (Cisco Systems, Inc.)
DRV - (CVPNDRVA [Auto | Running]) – C:\WINDOWS\system32\Drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (DNE [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\dne2000.sys (Deterministic Networks, Inc.)
DRV - (eabfiltr [System | Running]) – C:\WINDOWS\system32\drivers\EABFiltr.sys (Hewlett-Packard Company)
DRV - (eabusb [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\eabusb.sys (Hewlett-Packard Company)
DRV - (eeCtrl [System | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HPZid412 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HPZius12.sys (HP)
DRV - (HSFHWICH [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (HSF_DP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (mchInjDrv [System | Running]) – C:\WINDOWS\system32\Drivers\mchInjDrv.sys ()
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (NAVENG [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090224.017\NAVENG.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090224.017\NAVEX15.SYS (Symantec Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (RTL8023xp [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (SAVRT [On_Demand | Running]) – C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SAVRTPEL [System | Running]) – C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (sea1bus [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1bus.sys (MCCI)
DRV - (sea1mdfl [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1mdfl.sys (MCCI)
DRV - (sea1mdm [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1mdm.sys (MCCI)
DRV - (sea1mgmt [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1mgmt.sys (MCCI)
DRV - (sea1nd5 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1nd5.sys (MCCI)
DRV - (sea1obex [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1obex.sys (MCCI)
DRV - (sea1unic [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\sea1unic.sys (MCCI)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SMCIRDA [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\smcirda.sys (SMC)
DRV - (SPBBCDrv [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SymEvent [On_Demand | Running]) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMREDRV [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMTDI [System | Running]) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SynTP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (tifm21 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (vcddev [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\vcdvnic.sys (VNN B.J.)
DRV - (vsdatant [On_Demand | Stopped]) – C:\WINDOWS\system32\vsdatant.sys (Zone Labs Inc.)
DRV - (w29n51 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\w29n51.sys (Intel® Corporation)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = Reg Error: Invalid data type.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com/puccini/start
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\ssqQhfde.dll ()
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {7ba61ab9-5ae6-4c31-b09b-a87aa1a914ed} - C:\WINDOWS\system32\voojzv.dll ()
O2 - BHO: (no name) - {8E761807-1AA3-4114-90FA-F95934F7EA18} - C:\WINDOWS\system32\pmnnMdbA.dll ()
O2 - BHO: (no name) - {A4760F21-C14D-43E0-B53D-D1DEC8C0C4B3} - C:\WINDOWS\system32\vtUmNdBs.dll ()
O4 - HKLM..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" (Symantec Corporation)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Foxy ?? - res://C:\Program Files\Foxy\Foxy.exe/download.htm
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {09C6CAC0-936E-40A0-BC26-707480103DC3} http://www.uproar.com/applets/activex/shiz…pside_web18.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1160454364500 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: RaptisoftGameLoader http://www.raptisoft.com/webgames/raptisoftgameloader.cab (Reg Error: Key error.)
O18 - Protocol\Handler\ipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (voojzv.dll) - C:\WINDOWS\system32\voojzv.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O20 - Winlogon\Notify\ssqQhfde: DllName - ssqQhfde.dll - C:\WINDOWS\system32\ssqQhfde.dll ()
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\ssqQhfde.dll ()
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\vtUmNdBs) - C:\WINDOWS\system32\vtUmNdBs.dll ()
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1

========== Files/Folders - Created Within 30 Days ==========

[1 C:\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[10 C:\Documents and Settings\Queenie Leung\My Documents\*.tmp files]
[2009/02/25 10:05:55 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\voojzv.dll
[2009/02/25 10:05:53 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\iqckqhjv.dll
[2009/02/25 10:03:33 | 01,599,703 | -HS- | C] () – C:\WINDOWS\System32\saxlbmiw.ini
[2009/02/25 10:03:25 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\wimblxas.dll
[2009/02/25 10:02:52 | 00,003,643 | -HS- | C] () – C:\WINDOWS\System32\sBdNmUtv.ini2
[2009/02/25 10:02:49 | 00,003,643 | -HS- | C] () – C:\WINDOWS\System32\sBdNmUtv.ini
[2009/02/25 10:02:40 | 00,302,592 | —- | C] () – C:\WINDOWS\System32\vtUmNdBs.dll
[2009/02/24 18:51:39 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\spoyuo.dll
[2009/02/24 18:51:37 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\rmbsvvuv.dll
[2009/02/24 18:49:10 | 01,615,475 | -HS- | C] () – C:\WINDOWS\System32\enhptprd.ini
[2009/02/24 18:49:09 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\drptphne.dll
[2009/02/23 23:11:56 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/02/23 22:40:35 | 01,588,378 | -HS- | C] () – C:\WINDOWS\System32\mxiqqgju.ini
[2009/02/23 22:40:16 | 00,003,587 | -HS- | C] () – C:\WINDOWS\System32\AbdMnnmp.ini
[2009/02/23 22:40:16 | 00,003,526 | -HS- | C] () – C:\WINDOWS\System32\AbdMnnmp.ini2
[2009/02/23 22:40:10 | 00,302,592 | —- | C] () – C:\WINDOWS\System32\pmnnMdbA.dll
[2009/02/23 18:30:09 | 01,587,501 | -HS- | C] () – C:\WINDOWS\System32\kliovifo.ini
[2009/02/23 18:26:03 | 00,494,080 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Queenie Leung\Desktop\OTListIt2.exe
[2009/02/23 18:12:26 | 00,000,000 | —D | C] – C:\_OTMoveIt
[2009/02/23 18:10:57 | 00,348,160 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Queenie Leung\Desktop\OTMoveIt3.exe
[2009/02/23 17:50:23 | 00,038,447 | —- | C] () – C:\Documents and Settings\Queenie Leung\Desktop\n1331910049_30524037_6342.jpg
[2009/02/23 17:34:24 | 00,000,000 | —D | C] – C:\Rooter$
[2009/02/23 17:33:36 | 00,268,052 | —- | C] () – C:\Documents and Settings\Queenie Leung\Desktop\Rooter.exe
[2009/02/23 00:50:20 | 00,001,734 | —- | C] () – C:\Documents and Settings\Queenie Leung\Desktop\HijackThis.lnk
[2009/02/23 00:50:19 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/02/19 23:29:22 | 04,045,312 | —- | C] () – C:\Documents and Settings\Queenie Leung\My Documents\hsmai.ppt
[2009/02/10 13:22:59 | 52,689,7152 | -HS- | C] () – C:\hiberfil.sys
[2009/02/02 23:40:06 | 00,002,560 | —- | C] () – C:\WINDOWS\System32\drivers\mchInjDrv.sys
[2009/02/02 23:26:54 | 00,036,352 | —- | C] () – C:\WINDOWS\System32\ssqQhfde.dll
[2009/02/02 22:47:22 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/02/02 22:47:16 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\STKIT432.DLL
[2009/02/02 22:47:12 | 00,000,000 | —D | C] – C:\Program Files\Registry Mechanic
[2009/02/02 21:34:39 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/02/02 21:34:39 | 00,000,000 | —D | C] – C:\Qoobox
[2009/01/26 21:19:30 | 00,000,000 | —D | C] – C:\Documents and Settings\Queenie Leung\My Documents\Spring 09

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[10 C:\Documents and Settings\Queenie Leung\My Documents\*.tmp files]
[2009/02/25 10:10:12 | 00,003,643 | -HS- | M] () – C:\WINDOWS\System32\sBdNmUtv.ini
[2009/02/25 10:08:58 | 00,003,643 | -HS- | M] () – C:\WINDOWS\System32\sBdNmUtv.ini2
[2009/02/25 10:05:54 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\voojzv.dll
[2009/02/25 10:05:54 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\iqckqhjv.dll
[2009/02/25 10:03:46 | 01,599,703 | -HS- | M] () – C:\WINDOWS\System32\saxlbmiw.ini
[2009/02/25 10:03:26 | 00,072,704 | —- | M] () – C:\WINDOWS\System32\wimblxas.dll
[2009/02/25 10:02:44 | 00,302,592 | —- | M] () – C:\WINDOWS\System32\vtUmNdBs.dll
[2009/02/25 09:57:10 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/25 09:56:09 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/25 09:55:49 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/25 09:55:41 | 52,689,7152 | -HS- | M] () – C:\hiberfil.sys
[2009/02/24 22:41:35 | 00,003,587 | -HS- | M] () – C:\WINDOWS\System32\AbdMnnmp.ini
[2009/02/24 22:40:58 | 00,003,526 | -HS- | M] () – C:\WINDOWS\System32\AbdMnnmp.ini2
[2009/02/24 18:51:38 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\spoyuo.dll
[2009/02/24 18:51:38 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\rmbsvvuv.dll
[2009/02/24 18:49:27 | 01,615,475 | -HS- | M] () – C:\WINDOWS\System32\enhptprd.ini
[2009/02/24 18:49:09 | 00,072,704 | —- | M] () – C:\WINDOWS\System32\drptphne.dll
[2009/02/23 22:40:39 | 01,588,378 | -HS- | M] () – C:\WINDOWS\System32\mxiqqgju.ini
[2009/02/23 22:40:15 | 00,302,592 | —- | M] () – C:\WINDOWS\System32\pmnnMdbA.dll
[2009/02/23 18:30:21 | 01,587,501 | -HS- | M] () – C:\WINDOWS\System32\kliovifo.ini
[2009/02/23 18:26:15 | 00,494,080 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Queenie Leung\Desktop\OTListIt2.exe
[2009/02/23 18:19:58 | 00,364,120 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/02/23 18:10:58 | 00,348,160 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Queenie Leung\Desktop\OTMoveIt3.exe
[2009/02/23 17:50:23 | 00,038,447 | —- | M] () – C:\Documents and Settings\Queenie Leung\Desktop\n1331910049_30524037_6342.jpg
[2009/02/23 17:33:37 | 00,268,052 | —- | M] () – C:\Documents and Settings\Queenie Leung\Desktop\Rooter.exe
[2009/02/23 00:50:20 | 00,001,734 | —- | M] () – C:\Documents and Settings\Queenie Leung\Desktop\HijackThis.lnk
[2009/02/20 01:52:15 | 04,045,312 | —- | M] () – C:\Documents and Settings\Queenie Leung\My Documents\hsmai.ppt
[2009/02/20 00:26:22 | 00,102,392 | —- | M] () – C:\Documents and Settings\Queenie Leung\Application Data\GDIPFONTCACHEV1.DAT
[2009/02/19 19:00:54 | 00,002,560 | —- | M] () – C:\WINDOWS\System32\drivers\mchInjDrv.sys
[2009/02/10 13:32:21 | 00,000,624 | —- | M] () – C:\WINDOWS\win.ini
[2009/02/10 13:32:21 | 00,000,246 | —- | M] () – C:\WINDOWS\system.ini
[2009/02/10 13:32:21 | 00,000,211 | RHS- | M] () – C:\boot.ini
[2009/02/02 23:35:25 | 00,380,918 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/02/02 23:35:25 | 00,053,166 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/02/02 23:35:23 | 00,439,376 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/02/02 23:26:57 | 00,036,352 | —- | M] () – C:\WINDOWS\System32\ssqQhfde.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Queenie Leung\My Documents\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Queenie Leung\Desktop\Thumbs.db:encryptable
< End of report >
hello

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI