This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Getting "svchost.exe application error" and

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok, I think there's something on my computer. I'm completely stupid when it comes to computers so please bear with me.

1. The svchost.exe application error states "The instruction at "0x75606e6a" referenced memory at "0x00000008". The memory could not be "read". Click OK to terminate the program.

I click ok and it just keeps coming back.

2. I have cable internet through a local cable company. I have one modem. The connection (when in the Network connections folder) sometimes disappears, sometimes is disabled, sometimes is unable to be disabled or enabled. Basically for the past couple of days, internet is spotty. I've already called the cable company and it's not a problem with the modem. They said it "may" be software/hardware issue.

3. I also get webpages re-directed randomly. It's not all the time, like I said, more random, but does happen more often when doing google or yahoo web searches.

I have been unable to even open the anti-malware/spyware programs (any…even newly downloaded). I tried downloading the malwarebytes product, but again, I was unable to even open it (after downloading) let alone running it. I do have the Panda Internet Security Virus Protection and am able to run scans on that, but it finds nothing. A couple times it froze in the middle of scans. I have downloaded the ERUNT and the ATF Cleaner as instructed in the "read before posting" posts. I downloaded Hijackthis and this is the log that was generated:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:02:46 AM, on 3/17/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\pavsrv51.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\AVENGINE.EXE
c:\program files\panda software\panda internet security 2007\firewall\PNMSRV.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2M1.EXE
C:\Program Files\Panda Software\Panda Internet Security 2007\APVXDWIN.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Sun\StarOffice 8\program\soffice.exe
C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
C:\Program Files\Sun\StarOffice 8\program\soffice.BIN
C:\Program Files\Panda Software\Panda Internet Security 2007\PavFnSvr.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\AntiSpam\pskmssvc.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Panda Software\Panda Internet Security 2007\PsImSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Software\Panda Internet Security 2007\SRVLOAD.EXE
C:\Program Files\iPod\bin\iPodService.exe
c:\program files\panda software\panda internet security 2007\WebProxy.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: EarthLink BHO Guard - {00000000-0000-0000-0000-000000000002} - C:\Program Files\PeoplePC\Toolbar\ScamGrd.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: EarthLink ScamBlocker V3 - {15F4D456-5BAA-4076-8486-EECB38CD3E57} - C:\Program Files\PeoplePC\Toolbar\ScamGrd.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - c:\program files\peoplepc\toolbar\ppctoolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - c:\program files\peoplepc\toolbar\ppctoolbar.dll
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo RX600] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2M1.EXE" /P24 "EPSON Stylus Photo RX600" /O6 "USB001" /M "Stylus Photo RX600"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Internet Security 2007\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Software\Panda Internet Security 2007\Inicio.exe"
O4 - HKLM\..\Run: [BJCFD] "C:\Program Files\BroadJump\Client Foundation\CFD.exe"
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Monitor] "C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe"
O4 - HKLM\..\Run: [MsgCenterExe] "C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" -osboot
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: StarOffice 8.lnk = C:\Program Files\Sun\StarOffice 8\program\quickstart.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://asp.mathxl.com/wizmodules/testgen/i…GenXInstall.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://zone.msn.com/bingame/dsh2/default/D…h2.1.0.0.68.cab
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
O16 - DPF: {ABB660B6-6694-407B-950A-EDBA5A159722} (DVCDownloadControl) - http://download.games.yahoo.com/games/web_…loadControl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {EEC9DBCC-04AD-4A1B-BEA7-C6DAD9515D5A} (Pearson MyEconLab Player Control) - http://asp.mathxl.com/books/_Players/EconPlayer.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9955B632-8F2A-457F-B043-961A78B0A2E5}: NameServer = 85.255.112.167,85.255.112.72
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.167,85.255.112.72
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.167,85.255.112.72
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.167,85.255.112.72
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Google Update Service (gupdate1c99f8c4876479e) (gupdate1c99f8c4876479e) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LeapFrog Connect Device Service - Unknown owner - C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
O23 - Service: MBackMonitor - Unknown owner - C:\Program Files\McAfee\MBK\MBackMonitor.exe (file missing)
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Software\Panda Internet Security 2007\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Software\Panda Internet Security 2007\pavsrv51.exe
O23 - Service: Panda Antispam Engine (pmshellsrv) - Panda Software International - C:\Program Files\Panda Software\Panda Internet Security 2007\AntiSpam\pskmssvc.exe
O23 - Service: Panda Network Manager (PNMSRV) - Panda Software International - c:\program files\panda software\panda internet security 2007\firewall\PNMSRV.EXE
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software - C:\Program Files\Panda Software\Panda Internet Security 2007\PsImSvc.exe

–
End of file - 13305 bytes





If anyone can help me "fix" my computer, I'd greatly appreciate it!
Hi angeleyeskkhr and welcome to the forums here at WTT.

:welcome:

I'm completely stupid when it comes to computers so please bear with me.

I wouldn't say that. You are savvy enough to get online and seek out one of the best places in the world to get help with this problem. ;)

I can see from your log that you do have a DNS hijacker called Wareout. MalwareBytes' does clean it, but since you cannot run it that won't help right now. I suspect you have more than just that due to the fact you cannot run tools. Let's get a couple of more tools run here to get a better look, hopefully.

Download Rooter.exe to your desktop
  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt (Where %systemdrive% is usually C: or the drive that you have installed Windows). Post that in your next reply.
Please post back with
  • Rooter log

~~~~~~~~~~~~~~~~~~~~~~~~

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
Rooter.exe log:

Microsoft Windows XP Home Edition (5.1.2600) Service Pack 2

C:\ [Fixed] - NTFS - (Total:109913 Mo/Free:3515 Mo)
D:\ [Fixed] - FAT32 - (Total:4548 Mo/Free:1841 Mo)
E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)

Tue 03/17/2009|22:36

———————-\\ Processes..

–Locked– [System Process]
———- System
———- \SystemRoot\System32\smss.exe
———- \??\C:\WINDOWS\system32\csrss.exe
———- \??\C:\WINDOWS\SYSTEM32\winlogon.exe
———- C:\WINDOWS\system32\services.exe
———- C:\WINDOWS\system32\lsass.exe
———- C:\WINDOWS\system32\Ati2evxx.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\Program Files\Panda Security\Panda Internet Security 2009\TPSrv.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\spoolsv.exe
———- C:\PROGRAM FILES\PANDA SECURITY\PANDA INTERNET SECURITY 2009\WebProxy.exe
———- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\Program Files\Google\Update\GoogleUpdate.exe
———- C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
———- C:\Program Files\Panda Security\Panda Internet Security 2009\PsCtrls.exe
———- C:\Program Files\Panda Security\Panda Internet Security 2009\PavFnSvr.exe
———- C:\Program Files\Common Files\Panda Security\PavShld\pavprsrv.exe
———- C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
———- C:\Program Files\Panda Security\Panda Internet Security 2009\PsImSvc.exe
———- C:\Program Files\Panda Security\Panda Internet Security 2009\PskSvc.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\Program Files\Panda Security\Panda Internet Security 2009\pavsrv51.exe
———- C:\Program Files\Panda Security\Panda Internet Security 2009\AVENGINE.EXE
———- C:\WINDOWS\SYSTEM32\Ati2evxx.exe
———- C:\WINDOWS\Explorer.EXE
———- C:\Program Files\Panda Security\Panda Internet Security 2009\ApvxdWin.exe
———- C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
———- C:\WINDOWS\RTHDCPL.EXE
———- C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
———- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2M1.EXE
———- C:\Program Files\BroadJump\Client Foundation\CFD.exe
———- C:\Program Files\Panda Security\Panda Internet Security 2009\SRVLOAD.EXE
———- C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
———- C:\Program Files\QuickTime\QTTask.exe
———- C:\Program Files\iTunes\iTunesHelper.exe
———- C:\Program Files\Panda Security\Panda Internet Security 2009\PavBckPT.exe
———- C:\PROGRA~1\Yahoo!\browser\ycommon.exe
———- C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe
———- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
———- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\Program Files\Messenger\msmsgs.exe
———- C:\WINDOWS\system32\ctfmon.exe
———- C:\Program Files\Sun\StarOffice 8\program\soffice.exe
———- C:\Program Files\Sun\StarOffice 8\program\soffice.BIN
———- C:\Program Files\iPod\bin\iPodService.exe
———- C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
———- C:\Program Files\BitTorrent\bittorrent.exe
———- C:\Program Files\Mozilla Firefox\firefox.exe
———- C:\WINDOWS\system32\cmd.exe
———- C:\Rooter$\RK.exe

———————-\\ Search..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.167,85.255.112.72
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.167,85.255.112.72
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.167,85.255.112.72
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{9955B632-8F2A-457F-B043-961A78B0A2E5}]
NameServer REG_SZ 85.255.112.167,85.255.112.72
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\..\{9955B632-8F2A-457F-B043-961A78B0A2E5}]
NameServer REG_SZ 85.255.112.167,85.255.112.72
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{9955B632-8F2A-457F-B043-961A78B0A2E5}]
NameServer REG_SZ 85.255.112.167,85.255.112.72
==> WAREOUT <==

———————-\\ ROOTKIT !!



1 - "C:\Rooter$\Rooter_1.txt" - Tue 03/17/2009|22:37

———————-\\ Scan completed at 22:37



Now let me do the second one.
OTListIt:

OTListIt logfile created on: 3/17/2009 10:42:34 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.6.0 Folder = C:\Documents and Settings\Krista\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

381.59 Mb Total Physical Memory | 85.45 Mb Available Physical Memory | 22.39% Memory free
918.40 Mb Paging File | 462.95 Mb Available in Paging File | 50.41% Paging File free
Paging file location(s): C:\pagefile.sys 576 1152;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 107.34 Gb Total Space | 59.43 Gb Free Space | 55.37% Space Free | Partition Type: NTFS
Drive D: | 4.44 Gb Total Space | 1.80 Gb Free Space | 40.49% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-4CB685F926
Current User Name: Krista
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Panda Security\Panda Internet Security 2009\TPSrv.exe (Panda Security, S.L.)
PRC - C:\PROGRAM FILES\PANDA SECURITY\PANDA INTERNET SECURITY 2009\WebProxy.exe (Panda Security, S.L.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
PRC - C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe ()
PRC - C:\Program Files\Panda Security\Panda Internet Security 2009\PsCtrls.exe (Panda Security, S.L.)
PRC - C:\Program Files\Panda Security\Panda Internet Security 2009\PavFnSvr.exe (Panda Security, S.L.)
PRC - C:\Program Files\Common Files\Panda Security\PavShld\pavprsrv.exe (Panda Security, S.L.)
PRC - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
PRC - C:\Program Files\Panda Security\Panda Internet Security 2009\PsImSvc.exe (Panda Security S.L.)
PRC - C:\Program Files\Panda Security\Panda Internet Security 2009\PskSvc.exe (Panda Security, S.L.)
PRC - C:\Program Files\Panda Security\Panda Internet Security 2009\pavsrv51.exe (Panda Security, S.L.)
PRC - C:\Program Files\Panda Security\Panda Internet Security 2009\AVENGINE.EXE (Panda Security, S.L.)
PRC - C:\WINDOWS\SYSTEM32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Panda Security\Panda Internet Security 2009\ApvxdWin.exe (Panda Security, S.L.)
PRC - C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
PRC - C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2M1.EXE (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\BroadJump\Client Foundation\CFD.exe ()
PRC - C:\Program Files\Panda Security\Panda Internet Security 2009\SRVLOAD.EXE (Panda Security, S.L.)
PRC - C:\Program Files\Yahoo!\browser\ybrwicon.exe (Yahoo! Inc.)
PRC - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Panda Security\Panda Internet Security 2009\PavBckPT.exe (Panda Security, S.L.)
PRC - C:\Program Files\Yahoo!\browser\ycommon.exe (Yahoo!, Inc.)
PRC - C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe ()
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
PRC - C:\Program Files\Sun\StarOffice 8\program\soffice.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Sun\StarOffice 8\program\soffice.BIN (Sun Microsystems, Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe (Yahoo! Inc.)
PRC - C:\Program Files\BitTorrent\bittorrent.exe (BitTorrent, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\Krista\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) – C:\WINDOWS\system32\ati2sgag.exe ()
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (gupdate1c99f8c4876479e [Auto | Stopped]) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (Gwmsrv [Auto | Running]) – C:\Program Files\Panda Security\Panda Internet Security 2009\Gwmsrv.dll (Panda Security, S.L.)
SRV - (helpsvc [Auto | Stopped]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (LeapFrog Connect Device Service [Auto | Running]) – C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe ()
SRV - (MBackMonitor [On_Demand | Stopped]) – File not found
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Panda Software Controller [Auto | Running]) – C:\Program Files\Panda Security\Panda Internet Security 2009\PsCtrls.exe (Panda Security, S.L.)
SRV - (PAVFNSVR [Auto | Running]) – C:\Program Files\Panda Security\Panda Internet Security 2009\PavFnSvr.exe (Panda Security, S.L.)
SRV - (PavPrSrv [Auto | Running]) – C:\Program Files\Common Files\Panda Security\PavShld\pavprsrv.exe (Panda Security, S.L.)
SRV - (PAVSRV [Auto | Running]) – C:\Program Files\Panda Security\Panda Internet Security 2009\pavsrv51.exe (Panda Security, S.L.)
SRV - (PrismXL [Auto | Running]) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
SRV - (PSHost [Auto | Stopped]) – c:\program files\panda security\panda internet security 2009\firewall\PSHOST.EXE (Panda Software International)
SRV - (PSIMSVC [Auto | Running]) – C:\Program Files\Panda Security\Panda Internet Security 2009\PsImSvc.exe (Panda Security S.L.)
SRV - (PskSvcRetail [Auto | Running]) – C:\Program Files\Panda Security\Panda Internet Security 2009\PskSvc.exe (Panda Security, S.L.)
SRV - (TPSrv [Auto | Running]) – C:\Program Files\Panda Security\Panda Internet Security 2009\TPSrv.exe (Panda Security, S.L.)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (AliIde [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (APPFLT [System | Running]) – C:\WINDOWS\system32\Drivers\APPFLT.SYS (Panda Security, S.L.)
DRV - (asc [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (Cdr4_xp [System | Running]) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Roxio)
DRV - (Cdralw2k [System | Running]) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Roxio)
DRV - (CmdIde [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (ComFiltr [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\COMFiltr.sys ()
DRV - (dac2w2k [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (DSAFLT [System | Running]) – C:\WINDOWS\system32\Drivers\DSAFLT.SYS (Panda Security, S.L.)
DRV - (el575nd5 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\el575nd5.sys (3Com Corporation)
DRV - (FlyUsb [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\FlyUsb.sys (LeapFrog)
DRV - (FNETMON [System | Running]) – C:\WINDOWS\system32\Drivers\fnetmon.SYS (Panda Security, S.L.)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (HSFHWBS2 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (iaStor [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\IASTOR.SYS (Intel Corporation)
DRV - (IDSFLT [System | Running]) – C:\WINDOWS\system32\Drivers\IDSFLT.SYS (Panda Security, S.L.)
DRV - (IntcAzAudAddService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (mr7910 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\mr7910.sys (Mars Semiconductor Corp.)
DRV - (mraid35x [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (NaiAvFilter1 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\naiavf5x.sys (McAfee Inc.)
DRV - (NETFLTDI [System | Running]) – C:\WINDOWS\system32\Drivers\NETFLTDI.SYS (Panda Security, S.L.)
DRV - (NETIMFLT01060034 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\neti1634.sys (Panda Security, S.L.)
DRV - (pavboot [Boot | Running]) – C:\WINDOWS\system32\Drivers\pavboot.sys (Panda Security, S.L.)
DRV - (PAVDRV [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\pavdrv51.sys (Panda Security, S.L.)
DRV - (PavProc [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\PavProc.sys (Panda Security, S.L.)
DRV - (PavTPK.sys [On_Demand | Running]) – File not found
DRV - (pfc [On_Demand | Running]) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (ql1080 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (RTL8023xp [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (rtl8139 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\RTL8139.SYS (Realtek Semiconductor Corporation)
DRV - (samhid [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\samhid.sys ()
DRV - (SASDIFSV [System | Running]) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS ()
DRV - (SASENUM [On_Demand | Stopped]) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS (SuperAdBlocker, Inc.)
DRV - (SASKUTIL [System | Running]) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys ()
DRV - (Secdrv [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (ShldDrv [System | Running]) – C:\WINDOWS\System32\DRIVERS\ShlDrv51.sys (Panda Security, S.L.)
DRV - (sisagp [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (Sparrow [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (StillCam [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (symc810 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (ultra [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (wanatw [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\wanatw4.sys (America Online, Inc.)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (WNMFLT [System | Running]) – C:\WINDOWS\system32\Drivers\WNMFLT.SYS (Panda Security, S.L.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?ei=UTF-8&fr=ytff-msgr&p="
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-msgr"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-msgr"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?ei=UTF-8&fr=ytff-msgr&p="


FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD [2009/03/07 20:23:49 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/03/15 10:43:58 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/07 20:17:08 | 00,000,000 | —D | M]

[2009/01/13 01:42:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\mozilla\Extensions
[2009/01/13 01:42:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/03/17 00:20:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\mozilla\Firefox\Profiles\ajcmlr84.default\extensions
[2009/03/06 01:40:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\mozilla\Firefox\Profiles\ajcmlr84.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/03/15 03:27:35 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/03/05 01:44:11 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/03/05 01:44:05 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/05 01:44:05 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2007/01/04 03:10:51 | 00,214,616 | —- | M] () – C:\Program Files\mozilla firefox\components\FFHook.dll
[2009/01/13 01:42:00 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/01/13 01:42:00 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/01/13 01:42:00 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/01/13 01:42:00 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/01/13 01:42:00 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/01/13 01:42:00 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/01/13 01:42:00 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (ElnkBhoGuard Class) - {00000000-0000-0000-0000-000000000002} - C:\Program Files\PeoplePC\Toolbar\ScamGrd.dll (EarthLink, Inc.)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (ElnkScamBHO Class) - {15F4D456-5BAA-4076-8486-EECB38CD3E57} - C:\Program Files\PeoplePC\Toolbar\ScamGrd.dll (EarthLink, Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (PeoplePal Toolbar) - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - c:\program files\peoplepc\toolbar\ppctoolbar.dll (PeoplePC)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll (Google Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (PeoplePal Toolbar) - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - c:\program files\peoplepc\toolbar\ppctoolbar.dll (PeoplePC)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - c:\program files\peoplepc\toolbar\ppctoolbar.dll (PeoplePC)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Alcmtr] ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Internet Security 2009\APVXDWIN.EXE" /s (Panda Security, S.L.)
O4 - HKLM..\Run: [BJCFD] "C:\Program Files\BroadJump\Client Foundation\CFD.exe" ()
O4 - HKLM..\Run: [EPSON Stylus Photo RX600] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2M1.EXE" /P24 "EPSON Stylus Photo RX600" /O6 "USB001" /M "Stylus Photo RX600" (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [Monitor] "C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe" ()
O4 - HKLM..\Run: [MsgCenterExe] "C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" -osboot (RealNetworks, Inc.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE ()
O4 - HKLM..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe (SoftThinks)
O4 - HKLM..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
O4 - HKLM..\Run: [RTHDCPL] RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SCANINICIO] "C:\Program Files\Panda Security\Panda Internet Security 2009\Inicio.exe" (Panda Security, S.L.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKLM..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [Power2GoExpress] NA File not found
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKLM..\RunOnce: [BorraP2006tmp] cmd /C RD /s/q "C:\DOCUME~1\Krista\LOCALS~1\Temp\P2006tmp" (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Krista\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Documents and Settings\Krista\Start Menu\Programs\Startup\StarOffice 8.lnk = C:\Program Files\Sun\StarOffice 8\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 114 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Ranges: 16 range(s) not assigned to a zone.
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} http://asp.mathxl.com/wizmodules/testgen/i…GenXInstall.cab (TTestGenXInstallObject)
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} http://zone.msn.com/bingame/dsh2/default/D…h2.1.0.0.68.cab (CPlayFirstDinerDash2Control Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab (Pearson Installation Assistant 2)
O16 - DPF: {ABB660B6-6694-407B-950A-EDBA5A159722} http://download.games.yahoo.com/games/web_…loadControl.cab (DVCDownloadControl)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_02)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://zone.msn.com/bingame/popcaploader_v10.cab (PopCapLoader Object)
O16 - DPF: {EEC9DBCC-04AD-4A1B-BEA7-C6DAD9515D5A} http://asp.mathxl.com/books/_Players/EconPlayer.cab (Pearson MyEconLab Player Control)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.167,85.255.112.72
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{9955B632-8F2A-457F-B043-961A78B0A2E5}\\NameServer = 85.255.112.167,85.255.112.72
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\SYSTEM32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avldr: DllName - avldr.dll - C:\WINDOWS\SYSTEM32\avldr.dll (Panda Security, S.L.)
O20 - Winlogon\Notify\WgaLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O32 - Autorun File - C:\autorun.inf () - [ NTFS ]
O32 - Autorun File - D:\Autorun.inf () - [ FAT32 ]
O32 - Autorun File - D:\autorun.inf () - [ FAT32 ]
O33 - MountPoints2\{65b81637-7243-11db-9b69-00167666fd30}\Shell - "" = AutoRun
O33 - MountPoints2\{65b81637-7243-11db-9b69-00167666fd30}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{65b81637-7243-11db-9b69-00167666fd30}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\{e2f6071c-b237-11db-9b7e-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{e2f6071c-b237-11db-9b7e-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e2f6071c-b237-11db-9b7e-00038a000015}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found

========== Files/Folders - Created Within 30 Days ==========

[3 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2009/03/17 22:39:16 | 00,498,176 | —- | C] (OldTimer Tools) – C:\DOCUME~1\Krista\Desktop\OTListIt2.exe
[2009/03/17 22:36:07 | 00,000,000 | —D | C] – C:\Rooter$
[2009/03/17 22:35:57 | 00,267,612 | —- | C] () – C:\DOCUME~1\Krista\Desktop\Rooter.exe
[2009/03/17 15:34:26 | 00,013,880 | —- | C] () – C:\WINDOWS\System32\drivers\COMFiltr.sys
[2009/03/17 15:32:52 | 00,000,000 | —D | C] – C:\Documents and Settings\Krista\Local Settings\Application Data\Panda Security
[2009/03/17 15:22:30 | 00,084,024 | —- | C] (Panda Security, S.L.) – C:\WINDOWS\System32\drivers\pavdrv51.sys
[2009/03/17 15:22:30 | 00,000,261 | —- | C] () – C:\WINDOWS\System32\PavCPL.dat
[2009/03/17 15:22:28 | 00,001,132 | —- | C] () – C:\WINDOWS\System32\drivers\APPFLTR.CFG.bck
[2009/03/17 15:22:28 | 00,001,132 | —- | C] () – C:\WINDOWS\System32\drivers\APPFLTR.CFG
[2009/03/17 15:22:27 | 00,212,016 | —- | C] () – C:\WINDOWS\System32\drivers\APPFCONT.DAT.bck
[2009/03/17 15:22:27 | 00,212,016 | —- | C] () – C:\WINDOWS\System32\drivers\APPFCONT.DAT
[2009/03/17 15:22:23 | 00,193,792 | —- | C] (Panda Security, S.L.) – C:\WINDOWS\System32\drivers\idsflt.sys
[2009/03/17 15:22:23 | 00,052,992 | —- | C] (Panda Security, S.L.) – C:\WINDOWS\System32\drivers\dsaflt.sys
[2009/03/17 15:22:23 | 00,046,720 | —- | C] (Panda Security, S.L.) – C:\WINDOWS\System32\drivers\wnmflt.sys
[2009/03/17 15:22:07 | 00,158,848 | —- | C] (Panda Security, S.L.) – C:\WINDOWS\System32\drivers\NETFLTDI.SYS
[2009/03/17 15:22:07 | 00,073,728 | —- | C] (Panda Security, S.L.) – C:\WINDOWS\System32\drivers\APPFLT.SYS
[2009/03/17 15:22:07 | 00,022,072 | —- | C] (Panda Security, S.L.) – C:\WINDOWS\System32\drivers\fnetmon.sys
[2009/03/17 15:21:47 | 00,054,832 | —- | C] (Panda Software) – C:\WINDOWS\System32\pavcpl.cpl
[2009/03/17 15:21:22 | 00,193,280 | —- | C] (Panda Security, S.L.) – C:\WINDOWS\System32\TpUtil.dll
[2009/03/17 15:21:22 | 00,107,568 | —- | C] (Panda Software) – C:\WINDOWS\System32\SYSTOOLS.DLL
[2009/03/17 15:21:22 | 00,087,296 | —- | C] (Panda Security, S.L.) – C:\WINDOWS\System32\PavLspHook.dll
[2009/03/17 15:21:22 | 00,055,552 | —- | C] (Panda Security, S.L.) – C:\WINDOWS\System32\pavipc.dll
[2009/03/17 15:21:21 | 00,520,448 | —- | C] (Panda Security, S.L.) – C:\WINDOWS\System32\PavSHook.dll
[2009/03/17 15:21:18 | 00,197,888 | —- | C] (Panda Security, S.L.) – C:\WINDOWS\System32\drivers\neti1634.sys
[2009/03/17 15:21:14 | 00,058,672 | —- | C] (Panda Security, S.L.) – C:\WINDOWS\System32\avldr.dll
[2009/03/17 15:21:14 | 00,000,000 | —D | C] – C:\WINDOWS\System32\PAV
[2009/03/17 15:21:12 | 00,000,000 | —D | C] – C:\Program Files\Panda Security
[2009/03/17 15:21:12 | 00,000,000 | —D | C] – C:\Documents and Settings\Krista\Application Data\Panda Security
[2009/03/17 15:21:12 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Panda Security
[2009/03/17 15:19:41 | 00,028,544 | —- | C] (Panda Security, S.L.) – C:\WINDOWS\System32\drivers\pavboot.sys
[2009/03/17 15:18:30 | 00,041,144 | —- | C] (Panda Security, S.L.) – C:\WINDOWS\System32\drivers\ShlDrv51.sys
[2009/03/17 15:18:28 | 00,179,640 | —- | C] (Panda Security, S.L.) – C:\WINDOWS\System32\drivers\PavProc.sys
[2009/03/17 15:18:27 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Panda Security
[2009/03/17 14:59:58 | 00,000,423 | —- | C] () – C:\WINDOWS\AvDetected.ini
[2009/03/17 14:51:01 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Backup
[2009/03/17 14:30:51 | 86,240,656 | —- | C] () – C:\DOCUME~1\Krista\Desktop\IS09promo.exe
[2009/03/16 23:51:30 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/03/16 23:51:19 | 00,000,767 | —- | C] () – C:\Documents and Settings\Krista\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/03/16 23:51:13 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/03/16 23:50:52 | 00,791,393 | —- | C] (Lars Hederer ) – C:\DOCUME~1\Krista\Desktop\erunt_setup.exe
[2009/03/16 23:46:12 | 00,000,696 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/16 23:46:11 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/03/16 23:46:09 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/03/16 23:46:08 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/03/16 23:45:20 | 02,876,720 | —- | C] (Malwarebytes Corporation ) – C:\DOCUME~1\Krista\Desktop\mbam-setup.exe
[2009/03/16 23:16:39 | 00,000,000 | —D | C] – C:\Documents and Settings\Krista\Application Data\Malwarebytes
[2009/03/16 23:00:27 | 40,019,5584 | -HS- | C] () – C:\hiberfil.sys
[2009/03/15 17:06:41 | 00,000,000 | —D | C] – C:\DOCUME~1\Krista\My Documents\Stuff to backup
[2009/03/15 16:52:46 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/03/15 16:51:43 | 02,876,720 | —- | C] (Malwarebytes Corporation ) – C:\DOCUME~1\Krista\Desktop\runme.exe
[2009/03/15 16:39:40 | 00,001,734 | —- | C] () – C:\DOCUME~1\Krista\Desktop\HijackThis.lnk
[2009/03/15 16:39:40 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/03/15 16:39:24 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\DOCUME~1\Krista\Desktop\HJTInstall.exe
[2009/03/15 16:31:55 | 00,000,690 | —- | C] () – C:\DOCUME~1\Krista\Desktop\SpywareBlaster.lnk
[2009/03/15 16:31:53 | 00,000,000 | —D | C] – C:\Program Files\SpywareBlaster
[2009/03/15 16:31:25 | 02,869,536 | —- | C] (Javacool Software LLC ) – C:\DOCUME~1\Krista\Desktop\spywareblastersetup41.exe
[2009/03/11 03:19:13 | 03,711,068 | -H– | C] () – C:\Documents and Settings\Krista\Local Settings\Application Data\IconCache.db
[2009/03/08 20:00:31 | 00,000,396 | RHS- | C] () – C:\autorun.inf
[2009/03/08 20:00:27 | 00,000,000 | —D | C] – C:\Program Files\DecodingHQ
[2009/03/07 23:45:02 | 00,000,191 | —- | C] () – C:\WINDOWS\System32\sam.ini
[2009/03/07 23:39:45 | 00,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\kbdhid.sys
[2009/03/07 23:39:45 | 00,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdhid.sys
[2009/03/07 23:39:10 | 00,000,892 | —- | C] () – C:\DOCUME~1\Krista\Desktop\Philips Retractable PC Controller.lnk
[2009/03/07 23:39:09 | 00,077,824 | —- | C] (Jess Technology Co., Ltd.) – C:\WINDOWS\System32\FDRdriver.dll
[2009/03/07 23:39:09 | 00,007,548 | —- | C] () – C:\WINDOWS\System32\drivers\Samhid.sys
[2009/03/07 23:39:08 | 00,487,424 | —- | C] () – C:\WINDOWS\System32\FDRpage.dll
[2009/03/07 23:39:03 | 00,000,000 | —D | C] – C:\Program Files\PHILIPS
[2009/03/07 23:39:02 | 00,204,800 | —- | C] () – C:\WINDOWS\System32\CreateDir.exe
[2009/03/07 20:26:51 | 00,000,000 | —D | C] – C:\Documents and Settings\Krista\Local Settings\Application Data\Real
[2009/03/07 20:23:51 | 00,000,000 | —D | C] – C:\Program Files\Common Files\xing shared
[2009/03/07 20:23:49 | 00,000,897 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\RealPlayer.lnk
[2009/03/07 20:22:25 | 00,001,773 | —- | C] () – C:\DOCUME~1\ALLUSE~1\Desktop\Google Chrome.lnk
[2009/03/07 20:22:02 | 00,000,882 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
[2009/03/07 00:35:54 | 00,010,875 | —- | C] () – C:\DOCUME~1\Krista\Desktop\MLAPartBKSP09.pdf
[2009/03/01 19:30:30 | 00,018,903 | —- | C] () – C:\DOCUME~1\Krista\Desktop\MLAWorkCitedList.pdf
[2009/02/23 03:01:44 | 00,000,000 | —D | C] – C:\Program Files\ConsoleClassix.com

========== Files - Modified Within 30 Days ==========

[3 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2009/03/17 22:39:31 | 00,498,176 | —- | M] (OldTimer Tools) – C:\DOCUME~1\Krista\Desktop\OTListIt2.exe
[2009/03/17 22:36:01 | 00,267,612 | —- | M] () – C:\DOCUME~1\Krista\Desktop\Rooter.exe
[2009/03/17 16:25:01 | 00,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
[2009/03/17 16:05:04 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/03/17 16:04:59 | 00,013,880 | —- | M] () – C:\WINDOWS\System32\drivers\COMFiltr.sys
[2009/03/17 16:04:30 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/03/17 16:01:40 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/03/17 16:01:38 | 40,019,5584 | -HS- | M] () – C:\hiberfil.sys
[2009/03/17 15:39:49 | 00,477,670 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/17 15:39:49 | 00,406,658 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/03/17 15:39:49 | 00,063,732 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/03/17 15:38:46 | 00,000,423 | —- | M] () – C:\WINDOWS\AvDetected.ini
[2009/03/17 15:22:30 | 00,000,261 | —- | M] () – C:\WINDOWS\System32\PavCPL.dat
[2009/03/17 15:22:28 | 00,212,016 | —- | M] () – C:\WINDOWS\System32\drivers\APPFCONT.DAT.bck
[2009/03/17 15:22:28 | 00,212,016 | —- | M] () – C:\WINDOWS\System32\drivers\APPFCONT.DAT
[2009/03/17 15:22:28 | 00,001,132 | —- | M] () – C:\WINDOWS\System32\drivers\APPFLTR.CFG.bck
[2009/03/17 15:22:28 | 00,001,132 | —- | M] () – C:\WINDOWS\System32\drivers\APPFLTR.CFG
[2009/03/17 15:22:27 | 00,101,052 | —- | M] () – C:\WINDOWS\System32\drivers\etc\DsaFlt.rls.bck
[2009/03/17 15:22:27 | 00,101,052 | —- | M] () – C:\WINDOWS\System32\drivers\etc\DsaFlt.rls
[2009/03/17 14:34:28 | 86,240,656 | —- | M] () – C:\DOCUME~1\Krista\Desktop\IS09promo.exe
[2009/03/16 23:51:19 | 00,000,767 | —- | M] () – C:\Documents and Settings\Krista\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/03/16 23:50:52 | 00,791,393 | —- | M] (Lars Hederer ) – C:\DOCUME~1\Krista\Desktop\erunt_setup.exe
[2009/03/16 23:46:12 | 00,000,696 | —- | M] () – C:\DOCUME~1\ALLUSE~1\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/16 23:45:20 | 02,876,720 | —- | M] (Malwarebytes Corporation ) – C:\DOCUME~1\Krista\Desktop\mbam-setup.exe
[2009/03/16 23:15:37 | 00,000,396 | RHS- | M] () – C:\autorun.inf
[2009/03/15 16:52:13 | 02,876,720 | —- | M] (Malwarebytes Corporation ) – C:\DOCUME~1\Krista\Desktop\runme.exe
[2009/03/15 16:39:40 | 00,001,734 | —- | M] () – C:\DOCUME~1\Krista\Desktop\HijackThis.lnk
[2009/03/15 16:39:25 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\DOCUME~1\Krista\Desktop\HJTInstall.exe
[2009/03/15 16:31:55 | 00,000,690 | —- | M] () – C:\DOCUME~1\Krista\Desktop\SpywareBlaster.lnk
[2009/03/15 16:31:35 | 02,869,536 | —- | M] (Javacool Software LLC ) – C:\DOCUME~1\Krista\Desktop\spywareblastersetup41.exe
[2009/03/15 15:11:47 | 00,002,187 | —- | M] () – C:\DOCUME~1\ALLUSE~1\Desktop\Safari.lnk
[2009/03/15 04:04:34 | 00,000,909 | —- | M] () – C:\WINDOWS\win.ini
[2009/03/15 01:51:28 | 00,231,984 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/11 09:44:01 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/03/11 03:19:16 | 03,711,068 | -H– | M] () – C:\Documents and Settings\Krista\Local Settings\Application Data\IconCache.db
[2009/03/11 02:21:34 | 00,000,191 | —- | M] () – C:\WINDOWS\System32\sam.ini
[2009/03/08 21:22:10 | 00,056,832 | —- | M] () – C:\Documents and Settings\Krista\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/07 23:39:10 | 00,000,892 | —- | M] () – C:\DOCUME~1\Krista\Desktop\Philips Retractable PC Controller.lnk
[2009/03/07 20:27:24 | 00,004,263 | —- | M] () – C:\WINDOWS\cdplayer.ini
[2009/03/07 20:23:49 | 00,000,897 | —- | M] () – C:\DOCUME~1\ALLUSE~1\Desktop\RealPlayer.lnk
[2009/03/07 20:22:25 | 00,001,773 | —- | M] () – C:\DOCUME~1\ALLUSE~1\Desktop\Google Chrome.lnk
[2009/03/07 00:35:55 | 00,010,875 | —- | M] () – C:\DOCUME~1\Krista\Desktop\MLAPartBKSP09.pdf
[2009/03/01 19:30:31 | 00,018,903 | —- | M] () – C:\DOCUME~1\Krista\Desktop\MLAWorkCitedList.pdf
[2009/02/28 19:16:42 | 00,021,840 | —- | M] () – C:\WINDOWS\System32\SIntfNT.dll
[2009/02/28 19:16:41 | 00,017,212 | —- | M] () – C:\WINDOWS\System32\SIntf32.dll
[2009/02/28 19:16:41 | 00,012,067 | —- | M] () – C:\WINDOWS\System32\SIntf16.dll

========== LOP Check ==========

[2009/03/16 23:46:08 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data
[2007/08/02 00:45:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/06/01 22:36:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2007/06/01 22:34:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL Downloads
[2007/06/01 22:36:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL OCP
[2007/12/30 22:37:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2007/12/30 22:41:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/03/17 14:51:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Backup
[2007/11/22 23:31:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BigFishGamesCache
[2009/01/23 19:42:06 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2006/10/22 20:10:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2006/10/20 23:12:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2007/11/10 14:15:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\JollyBear
[2008/12/25 09:31:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Leapfrog
[2009/03/16 23:46:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2007/01/12 22:29:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2006/11/01 19:02:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2006/10/23 17:04:28 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2006/10/20 22:45:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2009/03/17 15:21:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panda Security
[2007/11/11 00:44:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2007/01/18 23:48:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2006/10/20 22:17:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Prism Deploy
[2006/10/20 22:47:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pure Networks
[2007/06/18 01:19:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2006/10/21 15:31:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SonyPicturesGames
[2009/03/16 23:53:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/01/09 20:24:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/03/17 15:13:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/02/12 19:59:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2007/06/07 20:17:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/03/14 01:30:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2007/07/23 11:45:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/11/30 15:25:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\yahoo!
[2009/01/02 22:39:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2009/03/17 15:03:39 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Krista\Application Data
[2008/11/30 15:27:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\Adobe
[2006/10/28 18:19:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\AdobeUM
[2007/03/27 03:37:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\AOL
[2008/08/22 23:29:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\Apple Computer
[2007/08/15 01:57:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\ArcSoft
[2009/03/17 22:38:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\BitTorrent
[2007/07/12 02:22:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\CyberLink
[2007/08/15 01:51:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\EPSON
[2007/08/07 19:40:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\Google
[2009/02/10 01:21:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\gtk-2.0
[2008/02/18 00:14:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\Help
[2006/10/20 22:17:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\Identities
[2007/07/23 11:39:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\Macromedia
[2009/03/16 23:16:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\Malwarebytes
[2009/02/19 09:04:16 | 00,000,000 | –SD | M] – C:\Documents and Settings\Krista\Application Data\Microsoft
[2009/01/13 01:42:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\Mozilla
[2009/03/17 15:21:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\Panda Security
[2007/11/22 23:32:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\PlayFirst
[2009/03/07 20:24:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\Real
[2006/10/20 22:56:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\SampleView
[2008/02/14 17:42:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\ScamBlocker
[2009/03/17 16:05:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\StarOffice8
[2006/10/22 12:26:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\Sun
[2008/03/16 03:28:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\SUPERAntiSpyware.com
[2009/02/14 23:29:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\U3
[2007/08/01 16:05:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\Wal-Mart Digital Photo Manager
[2007/08/07 19:39:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\Yahoo!
[2006/10/20 22:48:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Krista\Application Data\You've Got Pictures Screensaver
[2009/03/11 09:44:01 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004/08/04 14:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/03/17 16:25:01 | 00,000,882 | —- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskMachine.job
[2009/03/17 16:05:04 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 200 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:260575F1
@Alternate Data Stream - 197 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:453190EC
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:44DAF2F1
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4DBBB4EA
< End of report >
Extras.Txt:

OTListIt Extras logfile created on: 3/17/2009 10:42:34 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.6.0 Folder = C:\Documents and Settings\Krista\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

381.59 Mb Total Physical Memory | 85.45 Mb Available Physical Memory | 22.39% Memory free
918.40 Mb Paging File | 462.95 Mb Available in Paging File | 50.41% Paging File free
Paging file location(s): C:\pagefile.sys 576 1152;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 107.34 Gb Total Space | 59.43 Gb Free Space | 55.37% Space Free | Partition Type: NTFS
Drive D: | 4.44 Gb Total Space | 1.80 Gb Free Space | 40.49% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-4CB685F926
Current User Name: Krista
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.js [@ = JSFile] – C:\Program Files\Panda Security\Panda Internet Security 2009\PAVSCRIP.EXE (Panda Security, S.L.)
.jse [@ = JSEFile] – C:\Program Files\Panda Security\Panda Internet Security 2009\PAVSCRIP.EXE (Panda Security, S.L.)
.vbe [@ = VBEFile] – C:\Program Files\Panda Security\Panda Internet Security 2009\PAVSCRIP.EXE (Panda Security, S.L.)
.vbs [@ = VBSFile] – C:\Program Files\Panda Security\Panda Internet Security 2009\PAVSCRIP.EXE (Panda Security, S.L.)
.wsf [@ = WSFFile] – C:\Program Files\Panda Security\Panda Internet Security 2009\PAVSCRIP.EXE (Panda Security, S.L.)
.wsh [@ = WSHFile] – C:\Program Files\Panda Security\Panda Internet Security 2009\PAVSCRIP.EXE (Panda Security, S.L.)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
"DisableMonitoring" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
"DisableMonitoring" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader (AOL LLC)
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL File not found
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL File not found
C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL File not found
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon File not found
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed File not found
C:\Program Files\Common Files\AOL\1161402441\EE\AOLServiceHost.exe:*:Enabled:AOL File not found
C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL File not found
C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:*:Enabled:AOL File not found
C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:*:Enabled:AOL File not found
C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL (Gteko Ltd.)
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger (Yahoo! Inc.)
C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server File not found
C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent (BitTorrent, Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0AFC9710-5DD6-4C6A-BA52-91AE992B2C9D}" = Safari
"{0B721EA9-076B-466C-B09E-5A8FC59A6105}" = Hoyle Word Games 3
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP190_series" = Canon MP190 series MP Drivers
"{15377C3E-9655-400F-B441-E69F0A6BEAFE}" = Recovery Software Suite eMachines
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Solution
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{3119E881-90A3-11D4-9E17-00A0C9CA2831}" = Corel OCR-Trace
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{368FF7BE-2A1E-4ADD-A6EF-328DA820E83F}" = StarOffice 8
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = Browser Address Error Redirector
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go 4.0
"{41FE2866-7D7D-4EDF-9C7A-F1F6A346BA83}" = Wal-Mart Digital Photo Manager
"{44734179-8A79-4DEE-BB08-73037F065543}" = Apple Mobile Device Support
"{53F6009E-756A-4D3D-A0D3-B6D4CBEDA819}" = FloorPlan 3D v8
"{54A55DF7-BCC0-4C98-84AB-01CDA57687C7}" = Hex Workshop v5.1
"{5C52CED3-D45C-4DA9-932F-B91BD44BB461}" = Adabas D 13.01.00
"{5D95AD35-368F-47D5-B63A-A082DDF00111}" = Microsoft Digital Image Starter Edition 2006 Editor
"{65B7ECC2-DA56-4557-B1FA-475488FE7112}" = Panda Internet Security 2009
"{67183F00-3DDC-497B-A090-4E2B79EAF1CD}" = Photo Viewer
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{691F4068-81BF-49E3-B32E-FE3E16400111}" = Microsoft Digital Image Starter Edition 2006 Library
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{7926EFB6-7CB4-4A9D-AB01-095F67F9D519}" = Panda Internet Security 2009
"{80FD852F-5AAC-4129-B931-06AAFFA43138}" = iTunes
"{8AB8D458-939E-403F-0097-9BA1C1F013D5}" = The Sims 2
"{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}" = Napster Burn Engine
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{9EAB794B-ABC6-4261-821F-326B6CA87AFD}" = LeapFrog Tag Plugin
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A70900000002}" = Adobe Reader 7.0.9
"{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}" = REALTEK GbE & FE Ethernet PCI NIC Driver
"{AD13BFB0-FDD2-4AFA-A8AF-9F4A950D56B7}" = ArcSoft Camera Suite 1.3
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BBBCAE4B-B416-4182-A6F2-438180894A81}" = Napster
"{BFD96B89-B769-4CD6-B11E-E79FFD46F067}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CF055C57-A988-42E6-BDAF-E3D94C6973A8}" = LeapFrog Connect
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"0E5906722E3ECA13747F1633D3F55E9F47120424" = Windows Driver Package - LeapFrog (FlyUsb) USB (06/15/2007 1.0.0.6)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AdobeESD" = Adobe Download Manager 2.0 (Remove Only)
"AIM_6" = AIM 6
"AOL YGP Screensaver" = AOL You've Got Pictures Screensaver
"AolCoach2_en" = AOL Coach Version 2.0(Build:20041026.5 en)
"ATI Display Driver" = ATI Display Driver
"BFGC" = Big Fish Games Client
"BFG-Chocolatier" = Chocolatier (remove only)
"BFG-Mystery Case Files - Ravenhearst" = Mystery Case Files: Ravenhearst (remove only)
"BigFix" = BigFix
"BroadJump Client Foundation" = BroadJump Client Foundation
"CDisplay_is1" = CDisplay 1.8
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200014F1" = Soft Data Fax Modem with SmartCP
"DecodingHQ" = DecodingHQ
"Diablo II" = Diablo II
"DiskCleaner" = Disk Cleaner (remove only)
"DivX Content Uploader" = DivX Content Uploader
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"ERUNT_is1" = ERUNT 1.1j
"Google Chrome" = Google Chrome
"Google Desktop" = Google Desktop
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InterActual Player" = InterActual Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Messenger Service" = Messenger Service
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Money2006b" = Microsoft Money 2006
"Mozilla Firefox (3.0.7)" = Mozilla Firefox (3.0.7)
"mr7910_1ffef370f39864f3aaa62219d434ae06b02b70ab" = Windows Driver Package - (mr7910) Image 08/08/2006 1.4.0.0
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MySurvey Messenger" = MySurvey Messenger
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PeoplePC Toolbar" = PeoplePC:PeoplePal Toolbar 6.6
"Philips Retractable PC Controller" = Philips Retractable PC Controller
"PhotoParade.exe" = PhotoParade Player
"PictureItSuiteTrial_v11" = Microsoft Digital Image Starter Edition 2006
"RealPlayer 6.0" = RealPlayer
"SpywareBlaster_is1" = SpywareBlaster 4.1
"The Weather Channel Desktop" = The Weather Channel Desktop
"UPCShell" = LeapFrog Connect
"ViewpointMediaPlayer" = Viewpoint Media Player
"Weather Services" = Weather Services
"WGA" = Windows Genuine Advantage Validation Tool
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinGimp-2.0_is1" = GIMP 2.6.3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WT010646" = Bejeweled 2 Deluxe
"WT010651" = Penguins!
"WT010655" = Tradewinds
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Applications" = AT&T Yahoo! Applications
"Yahoo! Extras" = Yahoo! Browser Services

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent" = BitTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/7/2009 8:53:34 PM | Computer Name = YOUR-4CB685F926 | Source = Application Hang | ID = 1002
Description = Hanging application YahooMessenger.exe, version 9.0.0.2034, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/7/2009 8:53:34 PM | Computer Name = YOUR-4CB685F926 | Source = Application Hang | ID = 1002
Description = Hanging application YahooMessenger.exe, version 9.0.0.2034, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/12/2009 10:08:49 AM | Computer Name = YOUR-4CB685F926 | Source = Application Hang | ID = 1002
Description = Hanging application YahooMessenger.exe, version 9.0.0.2034, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/13/2009 2:29:23 AM | Computer Name = YOUR-4CB685F926 | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.0.3306, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/13/2009 5:20:23 AM | Computer Name = YOUR-4CB685F926 | Source = Application Error | ID = 1000
Description = Faulting application realplay.exe, version 6.0.12.1509, faulting module
unknown, version 0.0.0.0, fault address 0x01f71001.

Error - 2/13/2009 5:20:31 AM | Computer Name = YOUR-4CB685F926 | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.2180, fault address 0x0001295d.

Error - 2/22/2009 4:59:06 AM | Computer Name = YOUR-4CB685F926 | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.0.3306, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/23/2009 4:19:59 AM | Computer Name = YOUR-4CB685F926 | Source = Application Hang | ID = 1002
Description = Hanging application nester.exe, version 1.0.0.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/23/2009 4:20:10 AM | Computer Name = YOUR-4CB685F926 | Source = Application Hang | ID = 1002
Description = Hanging application nester.exe, version 1.0.0.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/23/2009 4:20:11 AM | Computer Name = YOUR-4CB685F926 | Source = Application Hang | ID = 1001
Description = Fault bucket 08963704.

[ System Events ]
Error - 3/17/2009 5:03:50 PM | Computer Name = YOUR-4CB685F926 | Source = Service Control Manager | ID = 7031
Description = The Windows Management Instrumentation service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in
60000 milliseconds: Restart the service.

Error - 3/17/2009 5:03:50 PM | Computer Name = YOUR-4CB685F926 | Source = Service Control Manager | ID = 7034
Description = The Security Center service terminated unexpectedly. It has done
this 1 time(s).

Error - 3/17/2009 5:03:50 PM | Computer Name = YOUR-4CB685F926 | Source = Service Control Manager | ID = 7034
Description = The Automatic Updates service terminated unexpectedly. It has done
this 1 time(s).

Error - 3/17/2009 5:03:50 PM | Computer Name = YOUR-4CB685F926 | Source = Service Control Manager | ID = 7034
Description = The Wireless Zero Configuration service terminated unexpectedly.
It has done this 1 time(s).

Error - 3/17/2009 5:05:13 PM | Computer Name = YOUR-4CB685F926 | Source = Service Control Manager | ID = 7031
Description = The Background Intelligent Transfer Service service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in
60000 milliseconds: Restart the service.

Error - 3/17/2009 5:05:13 PM | Computer Name = YOUR-4CB685F926 | Source = Service Control Manager | ID = 7034
Description = The COM+ Event System service terminated unexpectedly. It has done
this 3 time(s).

Error - 3/17/2009 5:05:13 PM | Computer Name = YOUR-4CB685F926 | Source = Service Control Manager | ID = 7034
Description = The Help and Support service terminated unexpectedly. It has done
this 3 time(s).

Error - 3/17/2009 5:05:13 PM | Computer Name = YOUR-4CB685F926 | Source = Service Control Manager | ID = 7034
Description = The Network Connections service terminated unexpectedly. It has done
this 3 time(s).

Error - 3/17/2009 5:05:13 PM | Computer Name = YOUR-4CB685F926 | Source = Service Control Manager | ID = 7034
Description = The Network Location Awareness (NLA) service terminated unexpectedly.
It has done this 2 time(s).

Error - 3/17/2009 5:05:13 PM | Computer Name = YOUR-4CB685F926 | Source = Service Control Manager | ID = 7034
Description = The Remote Access Connection Manager service terminated unexpectedly.
It has done this 3 time(s).


< End of report >
Please download SmitfraudFix

You should print out these instructions, or copy them to a Notepad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Please reboot your computer in Safe Mode by doing the following :
  • Restart your computer.
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually.
  • Instead of Windows loading as normal, a menu with options should appear.
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
2. Once in Safe Mode
  • Double-click SmitfraudFix.exe
  • Select option #5 - Search and Clean DNS Hijack by typing 5 and press "Enter".
  • You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter".
The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart anyway into normal Windows. A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply along with a new HijackThis log.
The report can also be found at C:\rapport.txt.

Warning : running option #2 on a non infected computer will remove your Desktop background.

Please reboot and provide the following in your next post: rapport.txt

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Run OTListIt2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTLI
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [Alcmtr] ALCMTR.EXE (Realtek Semiconductor Corp.)
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://zone.msn.com/bingame/popcaploader_v10.cab (PopCapLoader Object)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.167,85.255.112.72
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{9955B632-8F2A-457F-B043-961A78B0A2E5}\\NameServer = 85.255.112.167,85.255.112.72
    O33 - MountPoints2\{65b81637-7243-11db-9b69-00167666fd30}\Shell - "" = AutoRun
    O33 - MountPoints2\{65b81637-7243-11db-9b69-00167666fd30}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{65b81637-7243-11db-9b69-00167666fd30}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
    O33 - MountPoints2\{e2f6071c-b237-11db-9b7e-00038a000015}\Shell - "" = AutoRun
    O33 - MountPoints2\{e2f6071c-b237-11db-9b7e-00038a000015}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{e2f6071c-b237-11db-9b7e-00038a000015}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
    
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log

We should also flush your DNS cache:

To flush DNS cache in Microsoft Windows (Win XP, Win ME, Win 2000):-
  • Start > Run > type cmd
  • in command prompt, type ipconfig /flushdns (notice the space between the 'g /' it is needed)
  • Done! You Window DNS cache has just been flush.
Also run and post a new HijackThis log.
OK, I am no longer able to work in "normal" mode (it will start up and go the screen where you can log on as user, but when you go to log on, it freezes). I am unable to open in Safe Mode, but can open in Safe Mode with Networking. I downloaded the smitfraud but when I try to run option 5 it says "mode normal seulement–Normal Mode only Press any key to continue…" When I press enter (or any key) it goes back to the options
Let's try this….

Bring up the Advanced Options Menu by tapping F8 on startup (as you do with going to Safe Mode). But instead of selecting Safe Mode select Last Known Good Configuration, See if that will get you into Normal Mode.

Let's try this….

Bring up the Advanced Options Menu by tapping F8 on startup (as you do with going to Safe Mode). But instead of selecting Safe Mode select Last Known Good Configuration, See if that will get you into Normal Mode.



Yay! :)

Either that worked or I just wasn't giving it long enough beforehand. It took about 5-7 minutes but it did load into Normal Mode. Now lemme download that stuff and see about it.

Am I able to run that first scan in "Safe Mode with Networking" or does it actually have to be in Safe Mode (without the networking)? Because it always hangs up at the black screen where it scrolls through all the drivers and whatnot (or whatever, it's a list of things I'd assume are on the C drive and all that good stuff).

I will get home from work tomorrow around 6 pm-ish and will have *most* of the weekend to work on this. But I'll wait for your answer on the networking question before running the SmitFraud..Just to be on the safe side.
Hi,

Glad that got it back.

Am I able to run that first scan in "Safe Mode with Networking" or does it actually have to be in Safe Mode (without the networking)?

My apologies. My canned speech was incorrect on Smitfraudfix. It's Safe Mode for option 2, but option 5 is to be run in Normal Mode. So run option 5 that way and post the log.

Skip running OTListIt for now and just flush the cache. Run HijackThis after and post that log.
Just wanted to check in and let you know I haven't forgotten. I'm going to try to run the SmitFraud tomorrow morning. I don't have much time tonight.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI