This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] antivirus 1 help

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer seems to be infected with Antivirus 1 saying my computer is infected with some wierd kernel memory conflict.

HJT Log included:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:34:32 PM, on 3/7/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\1XConfig.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\WINDOWS\system32\BacsTray.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Okidata\OKI LPR Utility\okilpr.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHCLDCS.EXE
C:\WINDOWS\system32\RegSrvc.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Java\jre1.5.0_10\bin\javaw.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: 217.20.175.74 www.review.2009softwarereviews.com
O1 - Hosts: 217.20.175.74 review.2009softwarereviews.com
O1 - Hosts: 217.20.175.74 a1.review.zdnet.com
O1 - Hosts: 217.20.175.74 www.d1.reviews.cnet.com
O1 - Hosts: 217.20.175.74 www.reviews.toptenreviews.com
O1 - Hosts: 217.20.175.74 reviews.toptenreviews.com
O1 - Hosts: 217.20.175.74 www.reviews.download.com
O1 - Hosts: 217.20.175.74 reviews.download.com
O1 - Hosts: 217.20.175.74 www.reviews.pcadvisor.c.uk
O1 - Hosts: 217.20.175.74 reviews.pcadvisor.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.pcmag.com
O1 - Hosts: 217.20.175.74 reviews.pcmag.com
O1 - Hosts: 217.20.175.74 www.reviews.pcpro.co.uk
O1 - Hosts: 217.20.175.74 reviews.pcpro.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.reevoo.com
O1 - Hosts: 217.20.175.74 reviews.reevoo.com
O1 - Hosts: 217.20.175.74 www.reviews.riverstreams.co.uk
O1 - Hosts: 217.20.175.74 reviews.riverstreams.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.techradar.com
O1 - Hosts: 217.20.175.74 reviews.techradar.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [bacstray] BacsTray.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [Drives swap] C:\Documents and Settings\All Users\Application Data\AV1\AV1i.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: OKI LPR Utility.lnk = C:\Program Files\Okidata\OKI LPR Utility\okilpr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .avi: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1232512532077
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: OKI OPHC DCS Loader - Oki Data Corporation - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHCLDCS.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe

–
End of file - 6985 bytes
Hello and welcome to Posted Image

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

I am checking over your HJT log now, I will post back shortly with instructions.
Hi ganjadank,

Please do the following

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

In your next reply I need
  • MBAM log
  • OTListIt log
Hey CatByte, thanks for your reply and help. The OTLIST scan only gave me the OTLISTLT.txt, I couldn't find the EXTRAS.txt

Here's the requested txt files.

OTListIt logfile created on: 3/8/2009 10:45:46 AM - Run 3
OTListIt2 by OldTimer - Version 2.0.3.5 Folder = C:\Documents and Settings\Dragon\Desktop\New Folder (2)
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.43 Gb Available Physical Memory | 71.52% Memory free
2.60 Gb Paging File | 2.08 Gb Available in Paging File | 79.90% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.70 Gb Total Space | 3.62 Gb Free Space | 10.74% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ADMIN
Current User Name: Dragon
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\system32\Ati2evxx.exe ()
PRC - C:\WINDOWS\system32\S24EvMon.exe (Intel Corporation )
PRC - C:\WINDOWS\system32\ZCfgSvc.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\1XConfig.exe (Intel)
PRC - C:\WINDOWS\system32\Ati2evxx.exe ()
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\BCMSMMSG.exe (Broadcom Corporation)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
PRC - C:\Program Files\Dell\Media Experience\PCMService.exe (CyberLink Corp.)
PRC - C:\Program Files\Common Files\Dell\EUSW\Support.exe (Dell)
PRC - C:\WINDOWS\system32\BacsTray.exe (Broadcom Corporation)
PRC - C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Program Files\Apoint\Apntex.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe ( )
PRC - C:\Program Files\Okidata\OKI LPR Utility\okilpr.exe (Oki Data Corporation)
PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHCLDCS.EXE (Oki Data Corporation)
PRC - C:\WINDOWS\system32\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Java\jre1.5.0_10\bin\javaw.exe (Sun Microsystems, Inc.)
PRC - C:\Documents and Settings\Dragon\Desktop\New Folder (2)\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\Ati2evxx.exe ()
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (OKI OPHC DCS Loader [Auto | Running]) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHCLDCS.EXE (Oki Data Corporation)
SRV - (RegSrvc [Auto | Running]) – C:\WINDOWS\system32\RegSrvc.exe (Intel Corporation)
SRV - (S24EventMonitor [Auto | Running]) – C:\WINDOWS\system32\S24EvMon.exe (Intel Corporation )
SRV - (IntuitUpdateService [Auto | Running]) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)

========== Driver Services (SafeList) ==========

DRV - (AliIde [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (ApfiltrService [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (asc [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (bcm4sbxp [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (BCMModem [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\BCMSM.sys (Broadcom Corporation)
DRV - (CmdIde [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (E100B [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (MDC8021X [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (mraid35x [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (omci [System | Running]) – C:\WINDOWS\system32\DRIVERS\omci.sys (Dell Inc)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (ql1080 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (s24trans [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\s24trans.sys (Intel Corporation)
DRV - (SCDEmu [System | Running]) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (Sparrow [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (STAC97 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\stac97.sys (SigmaTel, Inc.)
DRV - (symc810 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (ultra [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (w22n51 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\w22n51.sys (Intel® Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - prefs.js..browser.startup.homepage: "www.yahoo.com"
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.07103010
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components -> %ProgramFiles%\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2009/03/06 14:35:56 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins -> %ProgramFiles%\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2009/03/06 14:35:55 00,000,000 | —D | M]
FF - C:\Documents and Settings\Dragon\Application Data\mozilla\Extensions [2008/06/30 10:32:22 00,000,000 | —D | M]
FF - C:\Documents and Settings\Dragon\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2008/06/30 10:32:22 00,000,000 | —D | M]
FF - C:\Documents and Settings\Dragon\Application Data\mozilla\Firefox\Profiles\b3z0307w.default\extensions [2009/03/07 11:49:04 00,000,000 | —D | M]
FF - C:\Documents and Settings\Dragon\Application Data\mozilla\Firefox\Profiles\b3z0307w.default\extensions\[removed] [2008/08/27 22:56:13 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions [2008/06/30 10:31:54 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009/03/06 14:35:55 00,000,000 | —D | M]

O1 HOSTS File: (1551 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 217.20.175.74 www.review.2009softwarereviews.com
O1 - Hosts: 217.20.175.74 review.2009softwarereviews.com
O1 - Hosts: 217.20.175.74 a1.review.zdnet.com
O1 - Hosts: 217.20.175.74 www.d1.reviews.cnet.com
O1 - Hosts: 217.20.175.74 www.reviews.toptenreviews.com
O1 - Hosts: 217.20.175.74 reviews.toptenreviews.com
O1 - Hosts: 217.20.175.74 www.reviews.download.com
O1 - Hosts: 217.20.175.74 reviews.download.com
O1 - Hosts: 217.20.175.74 www.reviews.pcadvisor.c.uk
O1 - Hosts: 217.20.175.74 reviews.pcadvisor.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.pcmag.com
O1 - Hosts: 217.20.175.74 reviews.pcmag.com
O1 - Hosts: 217.20.175.74 www.reviews.pcpro.co.uk
O1 - Hosts: 217.20.175.74 reviews.pcpro.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.reevoo.com
O1 - Hosts: 217.20.175.74 reviews.reevoo.com
O1 - Hosts: 217.20.175.74 www.reviews.riverstreams.co.uk
O1 - Hosts: 217.20.175.74 reviews.riverstreams.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.techradar.com
O1 - Hosts: 217.20.175.74 reviews.techradar.com
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Ask Toolbar BHO) - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (Ask.com)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (Ask.com)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [ATIModeChange] Ati2mdxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [bacstray] BacsTray.exe (Broadcom Corporation)
O4 - HKLM..\Run: [BCMSMMSG] BCMSMMSG.exe (Broadcom Corporation)
O4 - HKLM..\Run: [Drives swap] C:\Documents and Settings\All Users\Application Data\AV1\AV1i.exe File not found
O4 - HKLM..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe (Dell)
O4 - HKLM..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe (Intel® Corporation)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent (Malwarebytes Corporation)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\OKI LPR Utility.lnk = C:\Program Files\Okidata\OKI LPR Utility\okilpr.exe (Oki Data Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\npjpi150_10.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O12 - Plugin for: .avi - C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll (Apple Computer, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: turbotax.com ([]https in Trusted sites)
O16 - DPF: {32505657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/A…01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1232512532077 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\ipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll ()
O20 - Winlogon\Notify\Sebring: DllName - C:\WINDOWS\system32\LgNotify.dll - C:\WINDOWS\system32\LgNotify.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[2009/03/08 10:41:04 | 00,000,000 | —D | C] – C:\Documents and Settings\Dragon\Desktop\New Folder (2)
[2009/03/08 00:29:45 | 00,001,734 | —- | C] () – C:\Documents and Settings\Dragon\Desktop\HijackThis.lnk
[2009/03/08 00:29:44 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/03/08 00:21:36 | 00,000,000 | —D | C] – C:\Documents and Settings\Dragon\Application Data\Malwarebytes
[2009/03/08 00:21:34 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/03/08 00:21:34 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/08 00:21:32 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/03/08 00:21:31 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/03/08 00:21:30 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/02/21 19:23:41 | 00,000,000 | —D | C] – C:\Documents and Settings\Dragon\Local Settings\Application Data\Intuit
[2009/02/21 19:19:51 | 00,000,000 | —D | C] – C:\Program Files\Common Files\AnswerWorks 5.0
[2009/02/21 19:08:38 | 00,000,682 | —- | C] () – C:\Documents and Settings\All Users\Desktop\PowerISO.lnk
[2009/02/21 19:08:37 | 00,000,000 | —D | C] – C:\Program Files\PowerISO
[2009/02/21 19:08:16 | 01,150,620 | —- | C] () – C:\Documents and Settings\Dragon\Desktop\PowerISO43.exe
[2009/02/21 19:05:11 | 32,556,8512 | —- | C] () – C:\Documents and Settings\Dragon\Desktop\Turbo Tax Deluxe 2008.iso
[2009/02/21 19:03:17 | 00,061,064 | —- | C] () – C:\Documents and Settings\Dragon\Desktop\winxpvirtualcdcontrolpanel_21.exe
[2009/02/13 23:02:17 | 00,060,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\USBAUDIO.sys
[2009/02/13 23:02:17 | 00,060,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbaudio.sys
[2009/02/13 23:02:11 | 00,032,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\usbccgp.sys
[2009/02/13 23:02:11 | 00,032,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbccgp.sys
[2009/02/09 10:51:31 | 00,258,668 | —- | C] () – C:\Documents and Settings\Dragon\Desktop\sams.pdf
[2009/02/06 12:23:34 | 00,000,000 | —D | C] – C:\Documents and Settings\Dragon\Desktop\Naruto_434_[FH]
[2009/02/06 12:07:09 | 05,076,125 | —- | C] () – C:\Documents and Settings\Dragon\Desktop\Naruto_434_[FH].zip

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/03/08 00:29:45 | 00,001,734 | —- | M] () – C:\Documents and Settings\Dragon\Desktop\HijackThis.lnk
[2009/03/08 00:21:34 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/06 15:53:29 | 00,047,616 | —- | M] () – C:\Documents and Settings\Dragon\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/06 09:02:19 | 00,002,000 | —- | M] () – C:\Documents and Settings\Dragon\Desktop\E-TRADE MarketTrader.lnk
[2009/02/21 19:28:13 | 00,017,476 | —- | M] () – C:\WINDOWS\System32\OPC52NV2.cah
[2009/02/21 19:23:31 | 00,041,496 | —- | M] () – C:\Documents and Settings\Dragon\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/02/21 19:14:51 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/21 19:14:48 | 00,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2009/02/21 19:14:46 | 21,467,42272 | -HS- | M] () – C:\hiberfil.sys
[2009/02/21 19:13:45 | 00,478,424 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/02/21 19:13:45 | 00,408,238 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2009/02/21 19:13:45 | 00,064,602 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2009/02/21 19:08:38 | 00,000,682 | —- | M] () – C:\Documents and Settings\All Users\Desktop\PowerISO.lnk
[2009/02/21 19:08:26 | 01,150,620 | —- | M] () – C:\Documents and Settings\Dragon\Desktop\PowerISO43.exe
[2009/02/21 19:03:18 | 00,061,064 | —- | M] () – C:\Documents and Settings\Dragon\Desktop\winxpvirtualcdcontrolpanel_21.exe
[2009/02/11 11:19:42 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/02/11 11:19:34 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/02/09 10:51:32 | 00,258,668 | —- | M] () – C:\Documents and Settings\Dragon\Desktop\sams.pdf
[2009/02/06 12:08:46 | 05,076,125 | —- | M] () – C:\Documents and Settings\Dragon\Desktop\Naruto_434_[FH].zip

========== LOP Check ==========

[2009/03/08 00:29:19 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/09/02 23:34:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/07/01 22:05:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2008/07/08 04:21:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2008/10/14 15:56:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Blizzard
[2004/10/20 17:13:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2004/10/20 17:20:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Dell
[2006/06/17 17:26:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameTap
[2009/02/21 19:18:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2006/06/17 17:43:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\JollyBear
[2009/03/08 00:21:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2007/07/01 22:11:08 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2004/10/20 17:17:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2004/10/20 16:44:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2007/07/01 21:53:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2006/06/17 16:34:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2004/10/20 17:17:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/06/30 07:24:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2007/07/01 22:01:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\yahoo!
[2009/03/08 00:21:36 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Dragon\Application Data
[2008/09/02 23:33:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Dragon\Application Data\Adobe
[2008/12/26 22:41:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Dragon\Application Data\AdobeUM
[2008/09/28 10:23:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Dragon\Application Data\Azureus
[2008/09/18 11:21:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Dragon\Application Data\CyberLink
[2004/10/20 16:44:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Dragon\Application Data\Identities
[2008/07/05 13:05:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Dragon\Application Data\InstallShield
[2008/07/05 13:07:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Dragon\Application Data\Intuit
[2004/10/20 17:21:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Dragon\Application Data\Jasc Software Inc
[2006/07/19 00:18:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Dragon\Application Data\Macromedia
[2009/03/08 00:21:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Dragon\Application Data\Malwarebytes
[2008/07/01 06:04:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Dragon\Application Data\Media Player Classic
[2008/10/24 17:09:34 | 00,000,000 | –SD | M] – C:\Documents and Settings\Dragon\Application Data\Microsoft
[2008/08/27 23:07:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Dragon\Application Data\Move Networks
[2008/06/30 10:32:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Dragon\Application Data\Mozilla
[2004/10/20 17:16:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Dragon\Application Data\Sonic
[2004/10/20 17:10:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Dragon\Application Data\Sun
[2004/10/20 17:21:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Dragon\Application Data\Symantec
[2008/08/09 18:47:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Dragon\Application Data\Ventrilo
[2007/07/01 22:01:42 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Dragon\Application Data\yahoo!
[2004/08/04 03:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\DESKTOP.INI
[2004/10/28 10:53:02 | 00,000,258 | —- | M] () – C:\WINDOWS\Tasks\ISP signup reminder 1.job
[2009/02/21 19:14:51 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

< End of report >
Malwarebytes' Anti-Malware 1.34 Database version: 1827 Windows 5.1.2600 Service Pack 3 3/8/2009 11:29:21 AM mbam-log-2009-03-08 (11-29-21).txt Scan type: Quick Scan Objects scanned: 68634 Time elapsed: 4 minute(s), 35 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi ganjadank,

Please do the following:


Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following text written inside the code box (do not include the word "CODE" )
    :OTLI
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
    O4 - HKLM..\Run: [Drives swap] C:\Documents and Settings\All Users\Application Data\AV1\AV1i.exe File not found
    [1 C:\WINDOWS\System32\*.tmp files]
    [1 C:\WINDOWS\*.tmp files]
    :Services
    
    :Reg
    
    :Files
    C:\Documents and Settings\All Users\Application Data\AV1
    
    :Commands
    [resethosts]
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )

Next:


Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
  • Download and install the latest Java Runtime Environment (JRE) version for your computer: Version 6 - update 12

Next:


Go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

In your next reply I need

  • OTListIt log
  • Kaspersky report
  • Fresh HJT log
When I tried to Run Fix with OTListIt, my computer froze. I'm not sure what happened.

Reports:

OTListIt logfile created on: 3/8/2009 7:24:54 PM - Run 5
OTListIt2 by OldTimer - Version 2.0.3.5 Folder = C:\Documents and Settings\Dragon\Desktop\New Folder (2)
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.62 Gb Available Physical Memory | 81.17% Memory free
2.60 Gb Paging File | 2.38 Gb Available in Paging File | 91.50% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.70 Gb Total Space | 3.61 Gb Free Space | 10.72% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ADMIN
Current User Name: Dragon
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\system32\Ati2evxx.exe ()
PRC - C:\WINDOWS\system32\S24EvMon.exe (Intel Corporation )
PRC - C:\WINDOWS\system32\ZCfgSvc.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\1XConfig.exe (Intel)
PRC - C:\WINDOWS\system32\Ati2evxx.exe ()
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\BCMSMMSG.exe (Broadcom Corporation)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
PRC - C:\Program Files\Dell\Media Experience\PCMService.exe (CyberLink Corp.)
PRC - C:\Program Files\Common Files\Dell\EUSW\Support.exe (Dell)
PRC - C:\WINDOWS\system32\BacsTray.exe (Broadcom Corporation)
PRC - C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe ( )
PRC - C:\Program Files\Okidata\OKI LPR Utility\okilpr.exe (Oki Data Corporation)
PRC - C:\Program Files\Apoint\Apntex.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHCLDCS.EXE (Oki Data Corporation)
PRC - C:\WINDOWS\system32\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Dragon\Desktop\New Folder (2)\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\Ati2evxx.exe ()
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IntuitUpdateService [Auto | Running]) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (OKI OPHC DCS Loader [Auto | Running]) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHCLDCS.EXE (Oki Data Corporation)
SRV - (RegSrvc [Auto | Running]) – C:\WINDOWS\system32\RegSrvc.exe (Intel Corporation)
SRV - (S24EventMonitor [Auto | Running]) – C:\WINDOWS\system32\S24EvMon.exe (Intel Corporation )

========== Driver Services (SafeList) ==========

DRV - (AliIde [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (ApfiltrService [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (asc [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (bcm4sbxp [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (BCMModem [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\BCMSM.sys (Broadcom Corporation)
DRV - (CmdIde [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (E100B [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (MDC8021X [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (mraid35x [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (omci [System | Running]) – C:\WINDOWS\system32\DRIVERS\omci.sys (Dell Inc)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (ql1080 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (s24trans [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\s24trans.sys (Intel Corporation)
DRV - (SCDEmu [System | Running]) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (Sparrow [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (STAC97 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\stac97.sys (SigmaTel, Inc.)
DRV - (symc810 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (ultra [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (w22n51 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\w22n51.sys (Intel® Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - prefs.js..browser.startup.homepage: "www.yahoo.com"
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.07103010
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components -> %ProgramFiles%\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2009/03/06 14:35:56 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins -> %ProgramFiles%\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2009/03/06 14:35:55 00,000,000 | —D | M]
FF - C:\Documents and Settings\Dragon\Application Data\mozilla\Extensions [2008/06/30 10:32:22 00,000,000 | —D | M]
FF - C:\Documents and Settings\Dragon\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2008/06/30 10:32:22 00,000,000 | —D | M]
FF - C:\Documents and Settings\Dragon\Application Data\mozilla\Firefox\Profiles\b3z0307w.default\extensions [2009/03/08 13:19:37 00,000,000 | —D | M]
FF - C:\Documents and Settings\Dragon\Application Data\mozilla\Firefox\Profiles\b3z0307w.default\extensions\[removed] [2008/08/27 22:56:13 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions [2008/06/30 10:31:54 00,000,000 | —D | M]
FF - C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009/03/06 14:35:55 00,000,000 | —D | M]

O1 HOSTS File: (1551 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 217.20.175.74 www.review.2009softwarereviews.com
O1 - Hosts: 217.20.175.74 review.2009softwarereviews.com
O1 - Hosts: 217.20.175.74 a1.review.zdnet.com
O1 - Hosts: 217.20.175.74 www.d1.reviews.cnet.com
O1 - Hosts: 217.20.175.74 www.reviews.toptenreviews.com
O1 - Hosts: 217.20.175.74 reviews.toptenreviews.com
O1 - Hosts: 217.20.175.74 www.reviews.download.com
O1 - Hosts: 217.20.175.74 reviews.download.com
O1 - Hosts: 217.20.175.74 www.reviews.pcadvisor.c.uk
O1 - Hosts: 217.20.175.74 reviews.pcadvisor.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.pcmag.com
O1 - Hosts: 217.20.175.74 reviews.pcmag.com
O1 - Hosts: 217.20.175.74 www.reviews.pcpro.co.uk
O1 - Hosts: 217.20.175.74 reviews.pcpro.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.reevoo.com
O1 - Hosts: 217.20.175.74 reviews.reevoo.com
O1 - Hosts: 217.20.175.74 www.reviews.riverstreams.co.uk
O1 - Hosts: 217.20.175.74 reviews.riverstreams.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.techradar.com
O1 - Hosts: 217.20.175.74 reviews.techradar.com
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Ask Toolbar BHO) - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (Ask.com)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (Ask.com)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [ATIModeChange] Ati2mdxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [bacstray] BacsTray.exe (Broadcom Corporation)
O4 - HKLM..\Run: [BCMSMMSG] BCMSMMSG.exe (Broadcom Corporation)
O4 - HKLM..\Run: [Drives swap] C:\Documents and Settings\All Users\Application Data\AV1\AV1i.exe File not found
O4 - HKLM..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe (Dell)
O4 - HKLM..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe (Intel® Corporation)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\OKI LPR Utility.lnk = C:\Program Files\Okidata\OKI LPR Utility\okilpr.exe (Oki Data Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\npjpi150_10.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O12 - Plugin for: .avi - C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll (Apple Computer, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: turbotax.com ([]https in Trusted sites)
O16 - DPF: {32505657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/A…01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1232512532077 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\ipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp Reg Error: Value error. - Reg Error: Key error. File not found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll ()
O20 - Winlogon\Notify\Sebring: DllName - C:\WINDOWS\system32\LgNotify.dll - C:\WINDOWS\system32\LgNotify.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[2009/03/08 19:16:22 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/03/08 10:41:04 | 00,000,000 | —D | C] – C:\Documents and Settings\Dragon\Desktop\New Folder (2)
[2009/03/08 00:29:45 | 00,001,734 | —- | C] () – C:\Documents and Settings\Dragon\Desktop\HijackThis.lnk
[2009/03/08 00:29:44 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/03/08 00:21:36 | 00,000,000 | —D | C] – C:\Documents and Settings\Dragon\Application Data\Malwarebytes
[2009/03/08 00:21:34 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/03/08 00:21:34 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/08 00:21:32 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/03/08 00:21:31 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/03/08 00:21:30 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/02/21 19:23:41 | 00,000,000 | —D | C] – C:\Documents and Settings\Dragon\Local Settings\Application Data\Intuit
[2009/02/21 19:19:51 | 00,000,000 | —D | C] – C:\Program Files\Common Files\AnswerWorks 5.0
[2009/02/21 19:08:38 | 00,000,682 | —- | C] () – C:\Documents and Settings\All Users\Desktop\PowerISO.lnk
[2009/02/21 19:08:37 | 00,000,000 | —D | C] – C:\Program Files\PowerISO
[2009/02/21 19:08:16 | 01,150,620 | —- | C] () – C:\Documents and Settings\Dragon\Desktop\PowerISO43.exe
[2009/02/21 19:05:11 | 32,556,8512 | —- | C] () – C:\Documents and Settings\Dragon\Desktop\Turbo Tax Deluxe 2008.iso
[2009/02/21 19:03:17 | 00,061,064 | —- | C] () – C:\Documents and Settings\Dragon\Desktop\winxpvirtualcdcontrolpanel_21.exe
[2009/02/13 23:02:17 | 00,060,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\USBAUDIO.sys
[2009/02/13 23:02:17 | 00,060,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbaudio.sys
[2009/02/13 23:02:11 | 00,032,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\usbccgp.sys
[2009/02/13 23:02:11 | 00,032,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbccgp.sys
[2009/02/09 10:51:31 | 00,258,668 | —- | C] () – C:\Documents and Settings\Dragon\Desktop\sams.pdf

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/03/08 19:23:52 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/03/08 19:23:49 | 00,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2009/03/08 19:23:46 | 21,467,42272 | -HS- | M] () – C:\hiberfil.sys
[2009/03/08 19:23:46 | 00,194,568 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/08 00:29:45 | 00,001,734 | —- | M] () – C:\Documents and Settings\Dragon\Desktop\HijackThis.lnk
[2009/03/08 00:21:34 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/06 15:53:29 | 00,047,616 | —- | M] () – C:\Documents and Settings\Dragon\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/06 09:02:19 | 00,002,000 | —- | M] () – C:\Documents and Settings\Dragon\Desktop\E-TRADE MarketTrader.lnk
[2009/02/21 19:28:13 | 00,017,476 | —- | M] () – C:\WINDOWS\System32\OPC52NV2.cah
[2009/02/21 19:23:31 | 00,041,496 | —- | M] () – C:\Documents and Settings\Dragon\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/02/21 19:13:45 | 00,478,424 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/02/21 19:13:45 | 00,408,238 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2009/02/21 19:13:45 | 00,064,602 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2009/02/21 19:08:38 | 00,000,682 | —- | M] () – C:\Documents and Settings\All Users\Desktop\PowerISO.lnk
[2009/02/21 19:08:26 | 01,150,620 | —- | M] () – C:\Documents and Settings\Dragon\Desktop\PowerISO43.exe
[2009/02/21 19:03:18 | 00,061,064 | —- | M] () – C:\Documents and Settings\Dragon\Desktop\winxpvirtualcdcontrolpanel_21.exe
[2009/02/11 11:19:42 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/02/11 11:19:34 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/02/09 10:51:32 | 00,258,668 | —- | M] () – C:\Documents and Settings\Dragon\Desktop\sams.pdf
< End of report >
——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Sunday, March 8, 2009 Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Monday, March 09, 2009 02:43:30 Records in database: 1881491 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Files scanned: 55566 Threat name: 4 Infected objects: 28 Suspicious objects: 0 Duration of the scan: 00:56:48 File name / Threat name / Threats count C:\I386\f3PSSavr.scr Infected: not-a-virus:WebToolbar.Win32.MyWebSearch 1 C:\I386\ibm00001.dll Infected: Trojan-PSW.Win32.Sinowal.gj 1 C:\I386\ibm00002.dll Infected: Trojan-PSW.Win32.Sinowal.er 1 C:\WINDOWS\agt.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\asdydtx.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\dhmof.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\ejmsioe.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\hjm.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\j.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\jq.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\jyf.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\k.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\lh.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\lljpas.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\mrv.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\n.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\njf.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\nrmwd.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\o.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\pmc.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\r.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\s.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\svtt.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\tfjbruo.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\uiaa.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\vsf.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\xj.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 C:\WINDOWS\yyy.exe Infected: Trojan-Downloader.Win32.Agent.bqr 1 The selected area was scanned.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:54:07 PM, on 3/8/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\1XConfig.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\WINDOWS\system32\BacsTray.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Okidata\OKI LPR Utility\okilpr.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHCLDCS.EXE
C:\WINDOWS\system32\RegSrvc.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: 217.20.175.74 www.review.2009softwarereviews.com
O1 - Hosts: 217.20.175.74 review.2009softwarereviews.com
O1 - Hosts: 217.20.175.74 a1.review.zdnet.com
O1 - Hosts: 217.20.175.74 www.d1.reviews.cnet.com
O1 - Hosts: 217.20.175.74 www.reviews.toptenreviews.com
O1 - Hosts: 217.20.175.74 reviews.toptenreviews.com
O1 - Hosts: 217.20.175.74 www.reviews.download.com
O1 - Hosts: 217.20.175.74 reviews.download.com
O1 - Hosts: 217.20.175.74 www.reviews.pcadvisor.c.uk
O1 - Hosts: 217.20.175.74 reviews.pcadvisor.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.pcmag.com
O1 - Hosts: 217.20.175.74 reviews.pcmag.com
O1 - Hosts: 217.20.175.74 www.reviews.pcpro.co.uk
O1 - Hosts: 217.20.175.74 reviews.pcpro.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.reevoo.com
O1 - Hosts: 217.20.175.74 reviews.reevoo.com
O1 - Hosts: 217.20.175.74 www.reviews.riverstreams.co.uk
O1 - Hosts: 217.20.175.74 reviews.riverstreams.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.techradar.com
O1 - Hosts: 217.20.175.74 reviews.techradar.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [bacstray] BacsTray.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [Drives swap] C:\Documents and Settings\All Users\Application Data\AV1\AV1i.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: OKI LPR Utility.lnk = C:\Program Files\Okidata\OKI LPR Utility\okilpr.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .avi: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1232512532077
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: OKI OPHC DCS Loader - Oki Data Corporation - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHCLDCS.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe

–
End of file - 6611 bytes
Hi,

Looks like OTListIt just ran a normal scan - not a fix….

look for the Custom Scans/Fixes box - It's at the bottom = copy and past all the text that is contained INSIDE of the code box into that Custon Scans/Fixes box….(don't copy the word code though) Make sure you highlight all of it. starting with the COLON in front of OTLI and ending with the last bracket around the word [reboot]

:OTLI
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Drives swap] C:\Documents and Settings\All Users\Application Data\AV1\AV1i.exe File not found
[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
:Services

:Reg

:Files
C:\Documents and Settings\All Users\Application Data\AV1

:Commands
[resethosts]
[purity]
[emptytemp]
[start explorer]
[Reboot]


Then make sure you press the RUN FIX button at the top.


Run the fix again - see what happens

post the new log as well as a fresh HJT log

(run hjt after otlistIt)
Hi ganjadank,

Please do the following:


Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it.
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\I386\f3PSSavr.scr 
    C:\I386\ibm00001.dll 
    C:\I386\ibm00002.dll 
    C:\WINDOWS\agt.exe
    C:\WINDOWS\asdydtx.exe 
    C:\WINDOWS\dhmof.exe 
    C:\WINDOWS\ejmsioe.exe 
    C:\WINDOWS\hjm.exe 
    C:\WINDOWS\j.exe 
    C:\WINDOWS\jq.exe 
    C:\WINDOWS\jyf.exe 
    C:\WINDOWS\k.exe 
    C:\WINDOWS\lh.exe 
    C:\WINDOWS\lljpas.exe 
    C:\WINDOWS\mrv.exe 
    C:\WINDOWS\n.exe 
    C:\WINDOWS\njf.exe 
    C:\WINDOWS\nrmwd.exe 
    C:\WINDOWS\o.exe 
    C:\WINDOWS\pmc.exe 
    C:\WINDOWS\r.exe 
    C:\WINDOWS\s.exe 
    C:\WINDOWS\svtt.exe 
    C:\WINDOWS\tfjbruo.exe 
    C:\WINDOWS\uiaa.exe 
    C:\WINDOWS\vsf.exe 
    C:\WINDOWS\xj.exe 
    C:\WINDOWS\yyy.exe 
    
    :Commands
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


NEXT

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
Double click on ComboFix.exe & follow the prompts.

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.



Please make sure you include the Combo Fix log and the OTMoveIt3 log in your next reply as well as describe how your computer is running now.

Hi,

Looks like OTListIt just ran a normal scan - not a fix….

look for the Custom Scans/Fixes box - It's at the bottom = copy and past all the text that is contained INSIDE of the code box into that Custon Scans/Fixes box….(don't copy the word code though) Make sure you highlight all of it. starting with the COLON in front of OTLI and ending with the last bracket around the word [reboot]

:OTLI
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Drives swap] C:\Documents and Settings\All Users\Application Data\AV1\AV1i.exe File not found
[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
:Services

:Reg

:Files
C:\Documents and Settings\All Users\Application Data\AV1

:Commands
[resethosts]
[purity]
[emptytemp]
[start explorer]
[Reboot]


Then make sure you press the RUN FIX button at the top.


Run the fix again - see what happens

post the new log as well as a fresh HJT log

(run hjt after otlistIt)


OTListIt is "not responding" and I've left it on for over an hour. My computer is probably at fault here. Should I continue on to the next step?
My computer seems to be running faster now thank you. Both logs: ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== C:\I386\f3PSSavr.scr moved successfully. DllUnregisterServer procedure not found in C:\I386\ibm00001.dll C:\I386\ibm00001.dll NOT unregistered. C:\I386\ibm00001.dll moved successfully. DllUnregisterServer procedure not found in C:\I386\ibm00002.dll C:\I386\ibm00002.dll NOT unregistered. C:\I386\ibm00002.dll moved successfully. C:\WINDOWS\agt.exe moved successfully. C:\WINDOWS\asdydtx.exe moved successfully. C:\WINDOWS\dhmof.exe moved successfully. C:\WINDOWS\ejmsioe.exe moved successfully. C:\WINDOWS\hjm.exe moved successfully. C:\WINDOWS\j.exe moved successfully. C:\WINDOWS\jq.exe moved successfully. C:\WINDOWS\jyf.exe moved successfully. C:\WINDOWS\k.exe moved successfully. C:\WINDOWS\lh.exe moved successfully. C:\WINDOWS\lljpas.exe moved successfully. C:\WINDOWS\mrv.exe moved successfully. C:\WINDOWS\n.exe moved successfully. C:\WINDOWS\njf.exe moved successfully. C:\WINDOWS\nrmwd.exe moved successfully. C:\WINDOWS\o.exe moved successfully. C:\WINDOWS\pmc.exe moved successfully. C:\WINDOWS\r.exe moved successfully. C:\WINDOWS\s.exe moved successfully. C:\WINDOWS\svtt.exe moved successfully. C:\WINDOWS\tfjbruo.exe moved successfully. C:\WINDOWS\uiaa.exe moved successfully. C:\WINDOWS\vsf.exe moved successfully. C:\WINDOWS\xj.exe moved successfully. C:\WINDOWS\yyy.exe moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\Dragon\LOCALS~1\Temp\etilqs_MIw8VhFC9kzxlHvfz4ff scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Dragon\LOCALS~1\Temp\Perflib_Perfdata_7fc.dat scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_480.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\Dragon\Local Settings\Application Data\Mozilla\Firefox\Profiles\b3z0307w.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Dragon\Local Settings\Application Data\Mozilla\Firefox\Profiles\b3z0307w.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Dragon\Local Settings\Application Data\Mozilla\Firefox\Profiles\b3z0307w.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Dragon\Local Settings\Application Data\Mozilla\Firefox\Profiles\b3z0307w.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Dragon\Local Settings\Application Data\Mozilla\Firefox\Profiles\b3z0307w.default\urlclassifier3.sqlite scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03092009_165941 Files moved on Reboot… File C:\DOCUME~1\Dragon\LOCALS~1\Temp\etilqs_MIw8VhFC9kzxlHvfz4ff not found! File C:\DOCUME~1\Dragon\LOCALS~1\Temp\Perflib_Perfdata_7fc.dat not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT scheduled to be moved on reboot. File C:\WINDOWS\temp\Perflib_Perfdata_480.dat not found! C:\Documents and Settings\Dragon\Local Settings\Application Data\Mozilla\Firefox\Profiles\b3z0307w.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\Dragon\Local Settings\Application Data\Mozilla\Firefox\Profiles\b3z0307w.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\Dragon\Local Settings\Application Data\Mozilla\Firefox\Profiles\b3z0307w.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\Dragon\Local Settings\Application Data\Mozilla\Firefox\Profiles\b3z0307w.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\Dragon\Local Settings\Application Data\Mozilla\Firefox\Profiles\b3z0307w.default\urlclassifier3.sqlite moved successfully.
ComboFix 09-03-06.02 - Dragon 2009-03-09 17:08:06.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1721 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\drivers\fad.sys

—– BITS: Possible infected sites —–

hxxp://download.esd.intuit.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_GB


((((((((((((((((((((((((( Files Created from 2009-02-10 to 2009-03-10 )))))))))))))))))))))))))))))))
.

2009-03-09 16:59 . 2009-03-09 16:59 d——– C:\_OTMoveIt
2009-03-08 19:29 . 2009-03-08 19:29 410,984 –a—— c:\windows\SYSTEM32\deploytk.dll
2009-03-08 19:29 . 2009-03-08 19:29 73,728 –a—— c:\windows\SYSTEM32\javacpl.cpl
2009-03-08 19:16 . 2009-03-08 19:16 d——– C:\_OTListIt
2009-03-08 00:29 . 2009-03-08 00:29 d——– c:\program files\Trend Micro
2009-03-08 00:21 . 2009-03-08 00:21 d——– c:\program files\Malwarebytes' Anti-Malware
2009-03-08 00:21 . 2009-03-08 00:21 d——– c:\documents and settings\Dragon\Application Data\Malwarebytes
2009-03-08 00:21 . 2009-03-08 00:21 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-08 00:21 . 2009-02-11 11:19 38,496 –a—— c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2009-03-08 00:21 . 2009-02-11 11:19 15,504 –a—— c:\windows\SYSTEM32\DRIVERS\mbam.sys
2009-02-21 19:19 . 2009-02-21 19:19 d——– c:\program files\Common Files\AnswerWorks 5.0
2009-02-21 19:08 . 2009-02-21 19:08 d——– c:\program files\PowerISO
2009-02-13 23:02 . 2008-04-13 14:45 60,032 –a—— c:\windows\SYSTEM32\DRIVERS\USBAUDIO.sys
2009-02-13 23:02 . 2008-04-13 14:45 60,032 –a—— c:\windows\SYSTEM32\DLLCACHE\usbaudio.sys
2009-02-13 23:02 . 2008-04-13 14:45 32,128 –a—— c:\windows\SYSTEM32\DRIVERS\usbccgp.sys
2009-02-13 23:02 . 2008-04-13 14:45 32,128 –a—— c:\windows\SYSTEM32\DLLCACHE\usbccgp.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-09 02:29 ——— d—–w c:\program files\Java
2009-03-03 06:41 ——— d—–w c:\program files\World of Warcraft
2009-02-22 02:18 ——— d—–w c:\program files\Common Files\Intuit
2009-02-22 02:18 ——— d—–w c:\documents and settings\All Users\Application Data\Intuit
2009-02-22 02:16 ——— d—–w c:\program files\TurboTax
2006-06-18 00:35 24,146,141 —-a-w c:\program files\bigcityadventuresf_AOL.exe
2006-06-17 23:57 9,905,987 —-a-w c:\program files\Bejeweled2_AOL.exe
2006-06-17 23:51 15,967,272 —-a-w c:\program files\yahoo_monopolyherenow1-1_tm5-3.exe
2006-06-17 23:32 28,330,096 —-a-w c:\program files\yahoo_jewelquest2_tm5-3.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-02-02 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-08 148888]
"PRONoMgr.exe"="c:\program files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe" [2003-12-19 86016]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-07-16 335872]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2004-10-20 77824]
"DwlClient"="c:\program files\Common Files\Dell\EUSW\Support.exe" [2004-05-27 323584]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2008-11-02 167936]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 c:\windows\SYSTEM32\Ati2mdxx.exe]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 c:\windows\BCMSMMSG.exe]
"bacstray"="BacsTray.exe" [2003-05-14 c:\windows\SYSTEM32\BacsTray.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-13 c:\windows\SYSTEM32\narrator.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
OKI LPR Utility.lnk - c:\program files\Okidata\OKI LPR Utility\okilpr.exe [2008-11-03 151552]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2004-01-13 13:17 110592 c:\windows\SYSTEM32\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=

R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [2008-10-10 13088]
R2 OKI OPHC DCS Loader;OKI OPHC DCS Loader;c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\OPHCLDCS.EXE [2005-05-10 24576]
.
Contents of the 'Scheduled Tasks' folder

2004-10-28 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\OOBEBALN.EXE [2008-04-13 17:12]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Drives swap - c:\documents and settings\All Users\Application Data\AV1\AV1i.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway
Trusted Zone: turbotax.com
FF - ProfilePath - c:\documents and settings\Dragon\Application Data\Mozilla\Firefox\Profiles\b3z0307w.default\
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAskSBr.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-09 17:10:37
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DwlClient = c:\program files\Common Files\Dell\EUSW\Support.exe?l?e?s?\?D?e?l?l?\?E?U?S?W?\?S?u?p?p?o?r?t?.?e?x?e???????P???????????????X:??????????X???????x????????:??x???????????????????x???? ??x???x???8???X??????|????????x???????`???????4???????x???????????x??????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(712)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\LgNotify.dll
.
———————— Other Running Processes ————————
.
c:\windows\SYSTEM32\ati2evxx.exe
c:\windows\SYSTEM32\S24EvMon.exe
c:\windows\SYSTEM32\ZCfgSvc.exe
c:\windows\SYSTEM32\1XConfig.exe
c:\windows\SYSTEM32\ati2evxx.exe
c:\program files\Dell\Support\Alert\bin\NotifyAlert.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Apoint\ApntEx.exe
c:\windows\SYSTEM32\RegSrvc.exe
c:\windows\SYSTEM32\WBEM\wmiapsrv.exe
c:\windows\SYSTEM32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-03-09 17:13:07 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-10 00:12:48

Pre-Run: 8,288,813,056 bytes free
Post-Run: 8,228,364,288 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

146 — E O F — 2008-07-13 20:01:15

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI