This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] computer gone haywire

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hi my computer is acting strange lately. i cannot see part of the page on the right hand side i have also lost the top and btm toolbar on the right i have tried changing the resolution but thats not helping.my computer is gone very slow aswell hope someone can help .thanks martin
ok downloaded and ran hjt here is the log, thanks martin

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:02:22, on 08/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark 2400 Series\lxcrmon.exe
C:\Program Files\Lexmark 2400 Series\ezprint.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\lxcrcoms.exe
C:\Program Files\Huawei technologies\Huawei UMTS Data Card\3 DataModem HSDPA.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\User\Desktop\HiJackThis(2).exe

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe"
O4 - HKLM\..\Run: [PAC207_Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Microgaming\Poker\ladbrokesMPP\MPPoker.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://register3.valueactive.com/mpp_236/w…OCX/FlashAX.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{403DD3AC-331F-4FE1-9D7F-204612FB6517}: NameServer = 172.31.140.69 172.30.140.69
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exe

–
End of file - 6105 bytes
ok downloaded and ran hjt here is the log, thanks martin

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:02:22, on 08/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark 2400 Series\lxcrmon.exe
C:\Program Files\Lexmark 2400 Series\ezprint.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\lxcrcoms.exe
C:\Program Files\Huawei technologies\Huawei UMTS Data Card\3 DataModem HSDPA.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\User\Desktop\HiJackThis(2).exe

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe"
O4 - HKLM\..\Run: [PAC207_Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Microgaming\Poker\ladbrokesMPP\MPPoker.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://register3.valueactive.com/mpp_236/w…OCX/FlashAX.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{403DD3AC-331F-4FE1-9D7F-204612FB6517}: NameServer = 172.31.140.69 172.30.140.69
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exe

–
End of file - 6105 bytes
Hi tailight,

Please do the following:


  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
right otlistit.txt

OTListIt logfile created on: 08/03/2009 14:06:12 - Run 1
OTListIt2 by OldTimer - Version 2.0.3.5 Folder = C:\Documents and Settings\User\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00001809 | Country: Ireland | Language: ENI | Date Format: dd/MM/yyyy

367.48 Mb Total Physical Memory | 141.46 Mb Available Physical Memory | 38.49% Memory free
888.61 Mb Paging File | 577.00 Mb Available in Paging File | 64.93% Paging File free
Paging file location(s): C:\pagefile.sys 552 1104;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 57.25 Gb Free Space | 76.83% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 9.07 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MYCOMPUTER
Current User Name: User
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Grisoft\AVG7\avgamsvr.exe (GRISOFT, s.r.o.)
PRC - C:\Program Files\Grisoft\AVG7\avgupsvc.exe (GRISOFT, s.r.o.)
PRC - C:\Program Files\Grisoft\AVG7\avgemc.exe (GRISOFT, s.r.o.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Grisoft\AVG7\avgcc.exe (GRISOFT, s.r.o.)
PRC - C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
PRC - C:\Program Files\Lexmark 2400 Series\lxcrmon.exe ()
PRC - C:\Program Files\Lexmark 2400 Series\ezprint.exe (Lexmark International Inc.)
PRC - C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\WINDOWS\system32\lxcrcoms.exe ( )
PRC - C:\Program Files\Huawei technologies\Huawei UMTS Data Card\3 DataModem HSDPA.exe (Huawei Technologies)
PRC - C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\User\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Avg7Alrt [Auto | Running]) – C:\Program Files\Grisoft\AVG7\avgamsvr.exe (GRISOFT, s.r.o.)
SRV - (Avg7UpdSvc [Auto | Running]) – C:\Program Files\Grisoft\AVG7\avgupsvc.exe (GRISOFT, s.r.o.)
SRV - (AVGEMS [Auto | Running]) – C:\Program Files\Grisoft\AVG7\avgemc.exe (GRISOFT, s.r.o.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (lxcr_device [On_Demand | Running]) – C:\WINDOWS\system32\lxcrcoms.exe ( )
SRV - (usnjsvc [On_Demand | Running]) – C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WLSetupSvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (Afc [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Afc.sys (Arcsoft, Inc.)
DRV - (Avg7Core [System | Running]) – C:\WINDOWS\System32\Drivers\avg7core.sys (GRISOFT, s.r.o.)
DRV - (Avg7RsW [System | Running]) – C:\WINDOWS\System32\Drivers\avg7rsw.sys (GRISOFT, s.r.o.)
DRV - (Avg7RsXP [System | Running]) – C:\WINDOWS\System32\Drivers\avg7rsxp.sys (GRISOFT, s.r.o.)
DRV - (AvgClean [System | Running]) – C:\WINDOWS\System32\Drivers\avgclean.sys (GRISOFT, s.r.o.)
DRV - (AvgTdi [Auto | Running]) – C:\WINDOWS\System32\Drivers\avgtdi.sys (GRISOFT, s.r.o.)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (hwdatacard [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (S3SavageNB [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (VIAudio [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ac97via.sys (VIA Technologies, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar;=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar;=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…&ar;=msnhome
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - prefs.js..browser.search.defaultenginename: "Live Search"
FF - presf.js..browser.search.defaulturl: "http://search.live.com/results.aspx?FORM=IEFM1&q;="
FF - prefs.js..browser.search.selectedEngine: "Live Search"
FF - prefs.js..browser.startup.homepage: "http://en-GB.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official"
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.5
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.4\extensions\\Components -> %ProgramFiles%\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2009/03/07 20:04:25 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.4\extensions\\Plugins -> %ProgramFiles%\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2009/03/07 20:04:31 00,000,000 | —D | M]
FF - C:\Documents and Settings\User\Application Data\mozilla\Extensions [2008/11/24 16:21:39 00,000,000 | —D | M]
FF - C:\Documents and Settings\User\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2008/11/24 16:21:39 00,000,000 | —D | M]
FF - C:\Documents and Settings\User\Application Data\mozilla\Extensions\[removed] [2008/11/08 21:41:45 00,000,000 | —D | M]
FF - C:\Documents and Settings\User\Application Data\mozilla\Firefox\Profiles\3mood97l.default\extensions [2009/03/07 21:26:14 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions [2008/11/24 16:21:41 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2008/12/30 17:25:43 00,000,000 | —D | M]

O1 HOSTS File: (302687 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 10432 more lines…
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP (GRISOFT, s.r.o.)
O4 - HKLM..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe" (Lexmark International Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16 ()
O4 - HKLM..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe" ()
O4 - HKLM..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [PAC207_Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
O4 - HKCU..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe" File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Windows; Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Microgaming\Poker\ladbrokesMPP\MPPoker.exe (Microgaming)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 50 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} https://register3.valueactive.com/mpp_236/w…OCX/FlashAX.cab (FlashXControl Object)
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O32 - Autorun File - E:\AutoRun.exe (Huawei Technologies Co., Ltd.) - [ CDFS ]
O32 - Autorun File - E:\AUTORUN.INF () - [ CDFS ]
O33 - MountPoints2\{205312ae-f5e3-11dc-a69e-c72a53b6f7bd}\Shell - "" = AutoRun
O33 - MountPoints2\{205312ae-f5e3-11dc-a69e-c72a53b6f7bd}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{205312ae-f5e3-11dc-a69e-c72a53b6f7bd}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{352c9650-961f-11dd-a763-f916fdf80de4}\Shell - "" = AutoRun
O33 - MountPoints2\{352c9650-961f-11dd-a763-f916fdf80de4}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{352c9650-961f-11dd-a763-f916fdf80de4}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{352c9654-961f-11dd-a763-f916fdf80de4}\Shell - "" = AutoRun
O33 - MountPoints2\{352c9654-961f-11dd-a763-f916fdf80de4}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{352c9654-961f-11dd-a763-f916fdf80de4}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{4db28683-3d5d-11dd-a6fe-e7db945bceb2}\Shell - "" = AutoRun
O33 - MountPoints2\{4db28683-3d5d-11dd-a6fe-e7db945bceb2}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4db28683-3d5d-11dd-a6fe-e7db945bceb2}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{515d0a9e-fb24-11dc-a6a7-c4da5c5eeab2}\Shell - "" = AutoRun
O33 - MountPoints2\{515d0a9e-fb24-11dc-a6a7-c4da5c5eeab2}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{515d0a9e-fb24-11dc-a6a7-c4da5c5eeab2}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{7005e90c-3bcf-11dd-a6f8-828484e1afb2}\Shell - "" = AutoRun
O33 - MountPoints2\{7005e90c-3bcf-11dd-a6f8-828484e1afb2}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{7005e90c-3bcf-11dd-a6f8-828484e1afb2}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{7b26f759-ed38-11dc-a698-8cab1c9000b2}\Shell - "" = AutoRun
O33 - MountPoints2\{7b26f759-ed38-11dc-a698-8cab1c9000b2}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{7b26f759-ed38-11dc-a698-8cab1c9000b2}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{90695da1-b0fd-11dd-a793-b0d97b5e18ea}\Shell\AutoRun\command - "" = F:\
O33 - MountPoints2\{90695da1-b0fd-11dd-a793-b0d97b5e18ea}\Shell\open\Command - "" = .\autorun.exe explore
O33 - MountPoints2\{93dd0f07-f52d-11dc-a69a-bec853ebb7e1}\Shell\AutoRun\command - "" = G:\
O33 - MountPoints2\{93dd0f07-f52d-11dc-a69a-bec853ebb7e1}\Shell\open\Command - "" = .\autorun.exe explore
O33 - MountPoints2\{944966e9-0b56-11de-a7ba-ec79c3caa0b1}\Shell - "" = AutoRun
O33 - MountPoints2\{944966e9-0b56-11de-a7ba-ec79c3caa0b1}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{944966e9-0b56-11de-a7ba-ec79c3caa0b1}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{cbbb9ec6-9a49-11dd-a76e-fc87ff0040b2}\Shell - "" = AutoRun
O33 - MountPoints2\{cbbb9ec6-9a49-11dd-a76e-fc87ff0040b2}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{cbbb9ec6-9a49-11dd-a76e-fc87ff0040b2}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{db483f0e-3c41-11dd-a6fc-9dfcb2db4fae}\Shell - "" = AutoRun
O33 - MountPoints2\{db483f0e-3c41-11dd-a6fc-9dfcb2db4fae}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{db483f0e-3c41-11dd-a6fc-9dfcb2db4fae}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{f0375f1f-ba43-11dd-a79d-99adb2a1aa63}\Shell - "" = AutoRun
O33 - MountPoints2\{f0375f1f-ba43-11dd-a79d-99adb2a1aa63}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{f0375f1f-ba43-11dd-a79d-99adb2a1aa63}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{f0375f20-ba43-11dd-a79d-99adb2a1aa63}\Shell - "" = AutoRun
O33 - MountPoints2\{f0375f20-ba43-11dd-a79d-99adb2a1aa63}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{f0375f20-ba43-11dd-a79d-99adb2a1aa63}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)

========== Files/Folders - Created Within 30 Days ==========

[2 C:\WINDOWS\System32\*.tmp files]
[2009/03/08 14:05:54 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/03/08 14:01:26 | 00,497,664 | —- | C] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTListIt2.exe
[2009/03/08 11:25:46 | 00,401,720 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\User\Desktop\HiJackThis(2).exe
[2009/03/08 02:55:57 | 00,000,611 | —- | C] () – C:\Documents and Settings\User\Desktop\NTREGOPT.lnk
[2009/03/08 02:55:57 | 00,000,592 | —- | C] () – C:\Documents and Settings\User\Desktop\ERUNT.lnk
[2009/03/08 02:54:08 | 00,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\User\Desktop\erunt_setup.exe
[2009/03/07 20:38:28 | 00,001,750 | —- | C] () – C:\Documents and Settings\All Users\Desktop\3 DataModem HSDPA.lnk
[2009/03/07 20:37:54 | 00,088,960 | —- | C] (Huawei Technologies Co., Ltd.) – C:\WINDOWS\System32\drivers\ewusbmdm.sys
[2009/03/07 20:37:54 | 00,024,448 | —- | C] (Huawei Tech. Co., Ltd.) – C:\WINDOWS\System32\drivers\ewdcsc.sys
[2009/03/07 20:28:51 | 00,000,000 | —D | C] – C:\Program Files\OO Software
[2009/03/07 20:22:40 | 38,540,4928 | -HS- | C] () – C:\hiberfil.sys
[2009/03/07 16:40:57 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/03/07 16:40:52 | 00,000,000 | —D | C] – C:\Program Files\Free Easy Burner
[2009/03/07 16:40:30 | 00,000,000 | —D | C] – C:\WINDOWS\System32\QuickTime
[2009/03/07 16:40:30 | 00,000,000 | —D | C] – C:\Program Files\QuickTime
[2009/03/07 16:35:48 | 00,000,000 | —D | C] – C:\Microgaming
[2009/03/07 16:35:37 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware

========== Files - Modified Within 30 Days ==========

[2 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009/03/08 14:02:24 | 00,497,664 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTListIt2.exe
[2009/03/08 12:44:43 | 00,000,552 | —- | M] () – C:\Documents and Settings\User\My Documents\My Sharing Folders.lnk
[2009/03/08 11:29:00 | 00,401,720 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\User\Desktop\HiJackThis(2).exe
[2009/03/08 11:17:02 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/03/08 11:16:57 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/03/08 11:16:51 | 38,540,4928 | -HS- | M] () – C:\hiberfil.sys
[2009/03/08 03:21:19 | 00,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/03/08 03:19:11 | 01,575,772 | -H– | M] () – C:\Documents and Settings\User\Local Settings\Application Data\IconCache.db
[2009/03/08 02:56:01 | 00,000,767 | —- | M] () – C:\Documents and Settings\User\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/03/08 02:55:57 | 00,000,611 | —- | M] () – C:\Documents and Settings\User\Desktop\NTREGOPT.lnk
[2009/03/08 02:55:57 | 00,000,592 | —- | M] () – C:\Documents and Settings\User\Desktop\ERUNT.lnk
[2009/03/08 02:54:36 | 00,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\User\Desktop\erunt_setup.exe
[2009/03/07 20:38:28 | 00,001,750 | —- | M] () – C:\Documents and Settings\All Users\Desktop\3 DataModem HSDPA.lnk
[2009/03/07 20:05:58 | 00,000,588 | —- | M] () – C:\WINDOWS\win.ini
[2009/03/07 16:43:44 | 00,109,400 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/07 15:56:15 | 00,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/03/05 23:28:50 | 00,302,687 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts

========== LOP Check ==========

[2009/03/07 16:39:53 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/04/22 17:13:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\2BrightSparks
[2008/11/27 11:25:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/03/18 20:49:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe(2)
[2009/03/07 16:40:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/08/20 20:39:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ashampoo
[2008/03/09 08:00:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg7
[2008/03/08 16:41:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2008/11/08 21:29:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2008/11/12 22:22:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/03/08 03:01:03 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2009/03/07 19:58:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NOS
[2008/03/26 11:12:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2008/11/08 21:39:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/03/08 15:59:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2009/01/07 12:29:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Vodafone(2)
[2008/03/22 14:35:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WLInstaller
[2008/12/26 11:46:58 | 00,000,000 | RH-D | M] – C:\Documents and Settings\User\Application Data
[2008/03/22 16:43:44 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Adobe
[2008/03/18 20:49:22 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\AdobeUM
[2008/03/24 17:15:14 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Apple Computer
[2008/11/08 21:39:52 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\ArcSoft
[2008/11/08 21:33:36 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Ashampoo
[2009/03/08 11:18:21 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\AVG7
[2008/04/26 18:48:36 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\dvdcss
[2008/03/18 20:48:58 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\FaxCtr
[2008/05/27 20:02:55 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Google
[2008/06/17 09:11:18 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Help
[2008/03/08 14:51:31 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Identities
[2008/03/09 03:33:19 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Macromedia
[2008/11/12 22:22:43 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Malwarebytes
[2008/12/09 17:50:03 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Microgaming
[2009/01/08 15:49:27 | 00,000,000 | –SD | M] – C:\Documents and Settings\User\Application Data\Microsoft
[2008/11/08 21:28:22 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Mozilla
[2008/12/26 12:03:56 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\MSN6
[2008/04/22 16:53:22 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Opera
[2009/03/07 20:04:22 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Real
[2008/06/04 19:54:38 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Sonic
[2008/03/10 21:46:17 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Template
[2008/10/30 23:04:14 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\TomTom
[2008/11/28 11:21:57 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\vlc
[2008/12/26 11:46:58 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Vodafone
[2003/03/31 12:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/03/08 11:17:02 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

< End of report >

extras.txt


OTListIt Extras logfile created on: 08/03/2009 14:06:12 - Run 1
OTListIt2 by OldTimer - Version 2.0.3.5 Folder = C:\Documents and Settings\User\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00001809 | Country: Ireland | Language: ENI | Date Format: dd/MM/yyyy

367.48 Mb Total Physical Memory | 141.46 Mb Available Physical Memory | 38.49% Memory free
888.61 Mb Paging File | 577.00 Mb Available in Paging File | 64.93% Paging File free
Paging file location(s): C:\pagefile.sys 552 1104;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 57.25 Gb Free Space | 76.83% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 9.07 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MYCOMPUTER
Current User Name: User
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
C:\Program Files\Huawei technologies\Huawei UMTS Data Card\3 DataModem HSDPA.exe:*:Enabled:3 DDataModem HSDPA (Huawei Technologies)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{184E7118-0295-43C4-B72C-1D54AA75AAF7}" = Windows Live Mail
"{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}" = Windows Live Photo Gallery
"{341201D4-4F61-4ADB-987E-9CCE4D83A58D}" = Windows Live Toolbar Extension (Windows Live Toolbar)
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{53480280-DE8B-445F-9676-FAE6293E06E5}" = O&O; SafeErase
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}" = Windows Live Favorites for Windows Live Toolbar
"{90110409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional
"{9176251A-4CC1-4DDB-B343-B487195EB397}" = Windows Live Writer
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}" = Highlight Viewer (Windows Live Toolbar)
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{D5A145FC-D00C-4F1A-9119-EB4D9D659750}" = Windows Live Toolbar
"{F084395C-40FB-4DB3-981C-B51E74E1E83D}" = Smart Menus (Windows Live Toolbar)
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"3 DataModem HSDPA" = 3 DataModem HSDPA
"AVG7Uninstall" = AVG 7.5
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"ERUNT_is1" = ERUNT 1.1j
"Free Easy Burner_is1" = Free Easy Burner V 3.8
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"Ladbrokes Poker" = Ladbrokes Poker
"Lexmark 2400 Series" = Lexmark 2400 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"manutd_fanzone_oldtrafford" = manutd_fanzone_oldtrafford Screen Saver
"Mozilla Firefox (3.0.4)" = Mozilla Firefox (3.0.4)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"QuickTime" = QuickTime
"WIC" = Windows Imaging Component
"Windows Live Toolbar" = Windows Live Toolbar
"Windows XP Service Pack" = Windows XP Service Pack 3

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 07/03/2009 12:27:38 | Computer Name = MYCOMPUTER | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Office XP Professional – Error 1706. Setup cannot
find the required files. Check your connection to the network, or CD-ROM drive.
For other potential solutions to this problem, see C:\Program Files\Microsoft Office\Office10\1033\SETUP.HLP.

Error - 07/03/2009 12:27:40 | Computer Name = MYCOMPUTER | Source = MsiInstaller | ID = 1024
Description = Product: Microsoft Office XP Professional - Update '{DA256408-A2E7-41A5-8AD6-62ACB86A0FD7}'
could not be installed. Error code 1603. Windows Installer can create logs to help
troubleshoot issues with installing software packages. Use the following link for
instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127

Error - 07/03/2009 12:44:12 | Computer Name = MYCOMPUTER | Source = VSS | ID = 8193
Description = Volume Shadow Copy Service error: Unexpected error calling routine
CoCreateInstance. hr = 0x8007007e.

Error - 07/03/2009 16:00:43 | Computer Name = MYCOMPUTER | Source = MsiInstaller | ID = 11905
Description = Product: Macromedia Flash Player 8 – Error 1905.Module C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx
failed to unregister. HRESULT -2147220472. Contact your support personnel.

Error - 07/03/2009 16:09:12 | Computer Name = MYCOMPUTER | Source = VSS | ID = 8193
Description = Volume Shadow Copy Service error: Unexpected error calling routine
CoCreateInstance. hr = 0x8007007e.

Error - 07/03/2009 16:22:49 | Computer Name = MYCOMPUTER | Source = VSS | ID = 8193
Description = Volume Shadow Copy Service error: Unexpected error calling routine
CoCreateInstance. hr = 0x8007007e.

Error - 07/03/2009 17:12:04 | Computer Name = MYCOMPUTER | Source = VSS | ID = 8193
Description = Volume Shadow Copy Service error: Unexpected error calling routine
CoCreateInstance. hr = 0x8007007e.

Error - 07/03/2009 22:34:57 | Computer Name = MYCOMPUTER | Source = VSS | ID = 8193
Description = Volume Shadow Copy Service error: Unexpected error calling routine
CoCreateInstance. hr = 0x8007007e.

Error - 07/03/2009 23:00:45 | Computer Name = MYCOMPUTER | Source = MsiInstaller | ID = 11316
Description = Product: Windows Live Sign-in Assistant – Error 1316. A network error
occurred while attempting to read from the file: C:\WINDOWS\TEMP\IXP000.TMP\Install_{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}.msi

Error - 08/03/2009 07:17:05 | Computer Name = MYCOMPUTER | Source = VSS | ID = 8193
Description = Volume Shadow Copy Service error: Unexpected error calling routine
CoCreateInstance. hr = 0x8007007e.

[ System Events ]
Error - 07/03/2009 16:19:20 | Computer Name = MYCOMPUTER | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 07/03/2009 16:22:50 | Computer Name = MYCOMPUTER | Source = Service Control Manager | ID = 7023
Description = The COM+ Event System service terminated with the following error:
%%126

Error - 07/03/2009 16:22:50 | Computer Name = MYCOMPUTER | Source = Service Control Manager | ID = 7001
Description = The System Event Notification service depends on the COM+ Event System
service which failed to start because of the following error: %%126

Error - 07/03/2009 17:12:11 | Computer Name = MYCOMPUTER | Source = Service Control Manager | ID = 7023
Description = The COM+ Event System service terminated with the following error:
%%126

Error - 07/03/2009 17:12:11 | Computer Name = MYCOMPUTER | Source = Service Control Manager | ID = 7001
Description = The System Event Notification service depends on the COM+ Event System
service which failed to start because of the following error: %%126

Error - 07/03/2009 22:35:13 | Computer Name = MYCOMPUTER | Source = Service Control Manager | ID = 7023
Description = The COM+ Event System service terminated with the following error:
%%126

Error - 07/03/2009 22:35:13 | Computer Name = MYCOMPUTER | Source = Service Control Manager | ID = 7001
Description = The System Event Notification service depends on the COM+ Event System
service which failed to start because of the following error: %%126

Error - 08/03/2009 07:17:17 | Computer Name = MYCOMPUTER | Source = Service Control Manager | ID = 7023
Description = The COM+ Event System service terminated with the following error:
%%126

Error - 08/03/2009 07:17:17 | Computer Name = MYCOMPUTER | Source = Service Control Manager | ID = 7001
Description = The System Event Notification service depends on the COM+ Event System
service which failed to start because of the following error: %%126

Error - 08/03/2009 07:27:17 | Computer Name = MYCOMPUTER | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000043'
while processing the file 'hijackthis.exe' on the volume 'HarddiskVolume1'. It
has stopped monitoring the volume.


< End of report >
Hi tailight,

please do the following


Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - Reg Error: Key error. File not found
    O33 - MountPoints2\{205312ae-f5e3-11dc-a69e-c72a53b6f7bd}\Shell - "" = AutoRun
    O33 - MountPoints2\{205312ae-f5e3-11dc-a69e-c72a53b6f7bd}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{205312ae-f5e3-11dc-a69e-c72a53b6f7bd}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)
    O33 - MountPoints2\{352c9650-961f-11dd-a763-f916fdf80de4}\Shell - "" = AutoRun
    O33 - MountPoints2\{352c9650-961f-11dd-a763-f916fdf80de4}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{352c9650-961f-11dd-a763-f916fdf80de4}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)
    O33 - MountPoints2\{352c9654-961f-11dd-a763-f916fdf80de4}\Shell - "" = AutoRun
    O33 - MountPoints2\{352c9654-961f-11dd-a763-f916fdf80de4}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{352c9654-961f-11dd-a763-f916fdf80de4}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)
    O33 - MountPoints2\{4db28683-3d5d-11dd-a6fe-e7db945bceb2}\Shell - "" = AutoRun
    O33 - MountPoints2\{4db28683-3d5d-11dd-a6fe-e7db945bceb2}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{4db28683-3d5d-11dd-a6fe-e7db945bceb2}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)
    O33 - MountPoints2\{515d0a9e-fb24-11dc-a6a7-c4da5c5eeab2}\Shell - "" = AutoRun
    O33 - MountPoints2\{515d0a9e-fb24-11dc-a6a7-c4da5c5eeab2}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{515d0a9e-fb24-11dc-a6a7-c4da5c5eeab2}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)
    O33 - MountPoints2\{7005e90c-3bcf-11dd-a6f8-828484e1afb2}\Shell - "" = AutoRun
    O33 - MountPoints2\{7005e90c-3bcf-11dd-a6f8-828484e1afb2}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{7005e90c-3bcf-11dd-a6f8-828484e1afb2}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)
    O33 - MountPoints2\{7b26f759-ed38-11dc-a698-8cab1c9000b2}\Shell - "" = AutoRun
    O33 - MountPoints2\{7b26f759-ed38-11dc-a698-8cab1c9000b2}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{7b26f759-ed38-11dc-a698-8cab1c9000b2}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)
    O33 - MountPoints2\{90695da1-b0fd-11dd-a793-b0d97b5e18ea}\Shell\AutoRun\command - "" = F:\
    O33 - MountPoints2\{90695da1-b0fd-11dd-a793-b0d97b5e18ea}\Shell\open\Command - "" = .\autorun.exe explore
    O33 - MountPoints2\{93dd0f07-f52d-11dc-a69a-bec853ebb7e1}\Shell\AutoRun\command - "" = G:\
    O33 - MountPoints2\{93dd0f07-f52d-11dc-a69a-bec853ebb7e1}\Shell\open\Command - "" = .\autorun.exe explore
    O33 - MountPoints2\{944966e9-0b56-11de-a7ba-ec79c3caa0b1}\Shell - "" = AutoRun
    O33 - MountPoints2\{944966e9-0b56-11de-a7ba-ec79c3caa0b1}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{944966e9-0b56-11de-a7ba-ec79c3caa0b1}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)
    O33 - MountPoints2\{cbbb9ec6-9a49-11dd-a76e-fc87ff0040b2}\Shell - "" = AutoRun
    O33 - MountPoints2\{cbbb9ec6-9a49-11dd-a76e-fc87ff0040b2}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{cbbb9ec6-9a49-11dd-a76e-fc87ff0040b2}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)
    O33 - MountPoints2\{db483f0e-3c41-11dd-a6fc-9dfcb2db4fae}\Shell - "" = AutoRun
    O33 - MountPoints2\{db483f0e-3c41-11dd-a6fc-9dfcb2db4fae}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{db483f0e-3c41-11dd-a6fc-9dfcb2db4fae}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)
    O33 - MountPoints2\{f0375f1f-ba43-11dd-a79d-99adb2a1aa63}\Shell - "" = AutoRun
    O33 - MountPoints2\{f0375f1f-ba43-11dd-a79d-99adb2a1aa63}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{f0375f1f-ba43-11dd-a79d-99adb2a1aa63}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)
    O33 - MountPoints2\{f0375f20-ba43-11dd-a79d-99adb2a1aa63}\Shell - "" = AutoRun
    O33 - MountPoints2\{f0375f20-ba43-11dd-a79d-99adb2a1aa63}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{f0375f20-ba43-11dd-a79d-99adb2a1aa63}\Shell\AutoRun\command - "" = E:\AutoRun.exe – [2007/03/03 18:19:40 | 00,077,824 | R— | M] (Huawei Technologies Co., Ltd.)
    [2 C:\WINDOWS\System32\*.tmp files]
    [4 C:\WINDOWS\*.tmp files]
    :Services
    :Reg
    :Files
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )

NEXT


Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


NEXT

Go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

In your next reply I need
  • OTListIt log
  • MBAM log
  • Kaspersky report
  • fresh HJT log
copied the fix into the otlist and ran fix .when it rebooted this log appeared . Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret <[2 C:\WINDOWS\System32\*.tmp files]> in the current context! Error: Unable to interpret <[4 C:\WINDOWS\*.tmp files]> in the current context! ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== File delete failed. C:\Documents and Settings\User\Local Settings\Temp\etilqs_u5L5wshZzouvnuDrMt3G scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\User\Local Settings\Temp\~DF2599.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\User\Local Settings\Temp\~DF25C3.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\User\Local Settings\Temp\~DFBD7F.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\User\Local Settings\Temp\~DFBD84.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. File delete failed. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTListIt2 by OldTimer - Version 2.0.3.5 log created on 03082009_150125 Files moved on Reboot… File C:\Documents and Settings\User\Local Settings\Temp\etilqs_u5L5wshZzouvnuDrMt3G not found! File C:\Documents and Settings\User\Local Settings\Temp\~DF2599.tmp not found! File C:\Documents and Settings\User\Local Settings\Temp\~DF25C3.tmp not found! File C:\Documents and Settings\User\Local Settings\Temp\~DFBD7F.tmp not found! File C:\Documents and Settings\User\Local Settings\Temp\~DFBD84.tmp not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\urlclassifier3.sqlite moved successfully. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\XUL.mfl moved successfully. Registry entries deleted on Reboot…
while I check this out can you just confirm that it was only the text INSIDE the code box that you copied…not the word CODE thanks
hi catbyte i the ran fix again making sure it was only the text inside the box this is the log that appeared on reboot ========== OTLISTIT ========== Process explorer.exe killed successfully! Process TeaTimer.exe killed successfully! Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{1017A80C-6F09-4548-A84D-EDD6AC9525F0} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1017A80C-6F09-4548-A84D-EDD6AC9525F0}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{205312ae-f5e3-11dc-a69e-c72a53b6f7bd}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{205312ae-f5e3-11dc-a69e-c72a53b6f7bd}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{205312ae-f5e3-11dc-a69e-c72a53b6f7bd}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{205312ae-f5e3-11dc-a69e-c72a53b6f7bd}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{205312ae-f5e3-11dc-a69e-c72a53b6f7bd}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{205312ae-f5e3-11dc-a69e-c72a53b6f7bd}\ not found. File move failed. E:\AutoRun.exe scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{352c9650-961f-11dd-a763-f916fdf80de4}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{352c9650-961f-11dd-a763-f916fdf80de4}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{352c9650-961f-11dd-a763-f916fdf80de4}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{352c9650-961f-11dd-a763-f916fdf80de4}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{352c9650-961f-11dd-a763-f916fdf80de4}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{352c9650-961f-11dd-a763-f916fdf80de4}\ not found. File move failed. E:\AutoRun.exe scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{352c9654-961f-11dd-a763-f916fdf80de4}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{352c9654-961f-11dd-a763-f916fdf80de4}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{352c9654-961f-11dd-a763-f916fdf80de4}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{352c9654-961f-11dd-a763-f916fdf80de4}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{352c9654-961f-11dd-a763-f916fdf80de4}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{352c9654-961f-11dd-a763-f916fdf80de4}\ not found. File move failed. E:\AutoRun.exe scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4db28683-3d5d-11dd-a6fe-e7db945bceb2}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4db28683-3d5d-11dd-a6fe-e7db945bceb2}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4db28683-3d5d-11dd-a6fe-e7db945bceb2}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4db28683-3d5d-11dd-a6fe-e7db945bceb2}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4db28683-3d5d-11dd-a6fe-e7db945bceb2}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4db28683-3d5d-11dd-a6fe-e7db945bceb2}\ not found. File move failed. E:\AutoRun.exe scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{515d0a9e-fb24-11dc-a6a7-c4da5c5eeab2}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{515d0a9e-fb24-11dc-a6a7-c4da5c5eeab2}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{515d0a9e-fb24-11dc-a6a7-c4da5c5eeab2}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{515d0a9e-fb24-11dc-a6a7-c4da5c5eeab2}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{515d0a9e-fb24-11dc-a6a7-c4da5c5eeab2}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{515d0a9e-fb24-11dc-a6a7-c4da5c5eeab2}\ not found. File move failed. E:\AutoRun.exe scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7005e90c-3bcf-11dd-a6f8-828484e1afb2}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7005e90c-3bcf-11dd-a6f8-828484e1afb2}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7005e90c-3bcf-11dd-a6f8-828484e1afb2}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7005e90c-3bcf-11dd-a6f8-828484e1afb2}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7005e90c-3bcf-11dd-a6f8-828484e1afb2}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7005e90c-3bcf-11dd-a6f8-828484e1afb2}\ not found. File move failed. E:\AutoRun.exe scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7b26f759-ed38-11dc-a698-8cab1c9000b2}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7b26f759-ed38-11dc-a698-8cab1c9000b2}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7b26f759-ed38-11dc-a698-8cab1c9000b2}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7b26f759-ed38-11dc-a698-8cab1c9000b2}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7b26f759-ed38-11dc-a698-8cab1c9000b2}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7b26f759-ed38-11dc-a698-8cab1c9000b2}\ not found. File move failed. E:\AutoRun.exe scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{90695da1-b0fd-11dd-a793-b0d97b5e18ea}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90695da1-b0fd-11dd-a793-b0d97b5e18ea}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{90695da1-b0fd-11dd-a793-b0d97b5e18ea}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90695da1-b0fd-11dd-a793-b0d97b5e18ea}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{93dd0f07-f52d-11dc-a69a-bec853ebb7e1}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93dd0f07-f52d-11dc-a69a-bec853ebb7e1}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{93dd0f07-f52d-11dc-a69a-bec853ebb7e1}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{93dd0f07-f52d-11dc-a69a-bec853ebb7e1}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{944966e9-0b56-11de-a7ba-ec79c3caa0b1}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{944966e9-0b56-11de-a7ba-ec79c3caa0b1}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{944966e9-0b56-11de-a7ba-ec79c3caa0b1}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{944966e9-0b56-11de-a7ba-ec79c3caa0b1}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{944966e9-0b56-11de-a7ba-ec79c3caa0b1}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{944966e9-0b56-11de-a7ba-ec79c3caa0b1}\ not found. File move failed. E:\AutoRun.exe scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cbbb9ec6-9a49-11dd-a76e-fc87ff0040b2}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cbbb9ec6-9a49-11dd-a76e-fc87ff0040b2}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cbbb9ec6-9a49-11dd-a76e-fc87ff0040b2}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cbbb9ec6-9a49-11dd-a76e-fc87ff0040b2}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cbbb9ec6-9a49-11dd-a76e-fc87ff0040b2}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cbbb9ec6-9a49-11dd-a76e-fc87ff0040b2}\ not found. File move failed. E:\AutoRun.exe scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{db483f0e-3c41-11dd-a6fc-9dfcb2db4fae}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{db483f0e-3c41-11dd-a6fc-9dfcb2db4fae}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{db483f0e-3c41-11dd-a6fc-9dfcb2db4fae}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{db483f0e-3c41-11dd-a6fc-9dfcb2db4fae}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{db483f0e-3c41-11dd-a6fc-9dfcb2db4fae}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{db483f0e-3c41-11dd-a6fc-9dfcb2db4fae}\ not found. File move failed. E:\AutoRun.exe scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f0375f1f-ba43-11dd-a79d-99adb2a1aa63}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f0375f1f-ba43-11dd-a79d-99adb2a1aa63}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f0375f1f-ba43-11dd-a79d-99adb2a1aa63}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f0375f1f-ba43-11dd-a79d-99adb2a1aa63}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f0375f1f-ba43-11dd-a79d-99adb2a1aa63}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f0375f1f-ba43-11dd-a79d-99adb2a1aa63}\ not found. File move failed. E:\AutoRun.exe scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f0375f20-ba43-11dd-a79d-99adb2a1aa63}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f0375f20-ba43-11dd-a79d-99adb2a1aa63}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f0375f20-ba43-11dd-a79d-99adb2a1aa63}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f0375f20-ba43-11dd-a79d-99adb2a1aa63}\ not found. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f0375f20-ba43-11dd-a79d-99adb2a1aa63}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f0375f20-ba43-11dd-a79d-99adb2a1aa63}\ not found. File move failed. E:\AutoRun.exe scheduled to be moved on reboot. File C:\WINDOWS\System32\*.tmp not found. File C:\WINDOWS\*.tmp not found. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== File delete failed. C:\Documents and Settings\User\Local Settings\Temp\etilqs_mQkkNFqaA4KrYHRUuGYp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. File delete failed. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTListIt2 by OldTimer - Version 2.0.3.5 log created on 03082009_160355 Files moved on Reboot… File move failed. E:\AutoRun.exe scheduled to be moved on reboot. File C:\Documents and Settings\User\Local Settings\Temp\etilqs_mQkkNFqaA4KrYHRUuGYp not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\urlclassifier3.sqlite moved successfully. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\3mood97l.default\XUL.mfl moved successfully. Registry entries deleted on Reboot…
Very good..that's what I wanted to see :thumbup: Now if you could continue with the MalwareBytes and the Kaspersky scans from my previous post Thanks
hi there catbyte finally got the scans done. had a bit of bother with ownloading and updating kasperskey online scanner had to download twice and at that it took forever.at the end of all that there was nothing to report on the scan.any how here is mbam and hjt logs, thanks martin.

Malwarebytes' Anti-Malware 1.34
Database version: 1827
Windows 5.1.2600 Service Pack 3

08/03/2009 18:20:54
mbam-log-2009-03-08 (18-20-54).txt

Scan type: Full Scan (A:\|C:\|D:\|E:\|)
Objects scanned: 93630
Time elapsed: 38 minute(s), 36 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:34:38, on 09/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark 2400 Series\lxcrmon.exe
C:\Program Files\Lexmark 2400 Series\ezprint.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\lxcrcoms.exe
C:\Program Files\Huawei technologies\Huawei UMTS Data Card\3 DataModem HSDPA.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\User\Desktop\HiJackThis(2).exe

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe"
O4 - HKLM\..\Run: [PAC207_Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Microgaming\Poker\ladbrokesMPP\MPPoker.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://register3.valueactive.com/mpp_236/w…OCX/FlashAX.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{403DD3AC-331F-4FE1-9D7F-204612FB6517}: NameServer = 172.31.140.69 172.30.140.69
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exe

–
End of file - 6694 bytes
Hi Tailight,

Good news, your logs are clean :thumbup:

We just have a little clean up to do now,

First:


  • Open HiJackThis
  • Click on Do a system scan only
  • Check the box next to ONLY the entry listed below (if still present):


O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.

NEXT


Download ToolsCleaner2 to your desktop and run it ( by de A.Rothstein & Dj Quiou )
  • Click the Pt. Restauration button and press OK to the prompts.
  • Click the Corbeille button and press OK to the prompt.
  • Click the Fichiers temp button and press OK to the prompt.
  • Click the Recherche button and let it run ( it may look like it freezes but let it continue )
  • Once it is done click the Suppression button and let it remove anything it finds.
  • Close the program

Tools Cleaner will create a new system restore point, so now we have to flush out all previous Restore Points:

Click Start > Run > copy and paste the following into the run box:


cleanmgr


At the top, click on More Options tab. Click the Clean up button in the System Restore box.
Click on the Yes button.
When finished, click on Cancel button to exit.



Below I have included a number of recommendations for how to protect your computer against malware infections.


  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.
  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.
  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.
  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
  • For Firefox I highly recommend these add-ons to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
    • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.
  • Please read the guide by Rorschach112 on how to prevent malware and about safe computing here


Thank you for your patience, and performing all of the procedures requested.
hi catbyte thanks a million for all your help sorry i took so long to reply but i was busy for the last few days.my computer certainly seems to respond quicker now and thankfully i dont have any nasty viruses so again thanks for your help and i have implemented all your recomedations for safer computing.screen res is still a bit off but hey i got a clean comp.
Hi tailight, you're quite welcome, If your screen res is an issue post a new topic in the appropriate tech forum and I'm sure one of our tech gurus will be able to help you out (they are amazing)…link to this topic so they will know you are clear of malware… I'm not sure which forum would be best…maybe hardware?…have a read through those forums, you made find a similar topic to what you are experiencing. good luck and stay safe :wavey: CB

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI