This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] plz help, pop ups (www.url.adtrgt.com) and fake anti s

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Can someone please help me out, i keep getting pop ups from www.url.adtrgt.com which is being blocked from my trend micro internet sucurity but pops up every minute or so when i am trying to open new pages with internet explorer… also i get fake anti virus sites appearing for no reason and runs a scan on my computer wich i can not stop. i have tryed blocking these websites but new ones just appear. i use windows xp here is my hijackthis log. i have tryed so many different things to fix this and nothing seems to work… thanks

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:55:13 PM, on 4/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O1 - Hosts: 82.98.235.133 browser-security.microsoft.com
O1 - Hosts: 82.98.235.133 best-click-scanner.info
O1 - Hosts: 82.98.235.133 antivirus-xp-pro-2009.com
O1 - Hosts: 82.98.235.133 microsoft.infosecuritycenter.com
O1 - Hosts: 82.98.235.133 microsoft.softwaresecurityhelp.com
O1 - Hosts: 82.98.235.133 onlinenotifyq.net
O1 - Hosts: 82.98.235.133 antivirusxp-pro-2009.com
O1 - Hosts: 82.98.235.133 microsoft.browser-security-center.com
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA3105] command.com /c del "C:\WINDOWS\system32\ssqOGwXR.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8736] cmd.exe /c del "C:\WINDOWS\system32\ssqOGwXR.dll_old"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB1981] command.com /c del "C:\WINDOWS\system32\ssqOGwXR.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1989] cmd.exe /c del "C:\WINDOWS\system32\ssqOGwXR.dll_old"
O4 - HKUS\S-1-5-19\..\RunOnce: [NeroHomeFirstStart] "C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [NeroHomeFirstStart] "C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe" (User 'NETWORK SERVICE')
O4 - Startup: RollerCoaster Tycoon 3 Registration.lnk = C:\Documents and Settings\Main\Local Settings\Temp\{AF7A94F2-F7B1-4646-B835-8EBDC369D400}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.google.com
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinner.com/games/v47/scrab…rabblecubes.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - http://www.bebo.com/files/BeboUploader.5.1.4.cab
O16 - DPF: {2C153C75-8476-434B-B3C3-57B63A3D1939} (Brickout Control) - http://www.worldwinner.com/games/v48/brickout/brickout.cab
O16 - DPF: {42FDC231-A411-45F8-B8B6-3B5026111DA8} (SolitaireRush Control) - http://www.worldwinner.com/games/v47/solit…litairerush.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {555F1BBC-6EC2-474F-84AF-633EF097FF54} (WWHearts Control) - http://www.worldwinner.com/games/v52/wwhearts/wwhearts.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinner.com/games/v63/bjattack/bja.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
O16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} (Blockwerx Control) - http://www.worldwinner.com/games/v49/blockwerx/blockwerx.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} (Cubis Control) - http://www.worldwinner.com/games/v57/cubis/cubis.cab
O16 - DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} (WwLuxor Control) - http://www.worldwinner.com/games/v49/luxor/luxor.cab
O16 - DPF: {C5326A4D-E9AA-40AD-A09A-E74304D86B47} (DinerDash Control) - http://www.worldwinner.com/games/v50/dinerdash/dinerdash.cab
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} (FamilyFeud Control) - http://www.worldwinner.com/games/v47/famil…/familyfeud.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHos…ronGameHost.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe

–
End of file - 10021 bytes
Hello and :welcome:

Please do the following:

Please first disable teatimer and windows defender as they may interfere with our fix (right click icon in system tray>exit)


  • Open HiJackThis
  • Click on Do a system scan only
  • Check the boxes next to ONLY the entries listed below (if still present):


O1 - Hosts: 82.98.235.133 browser-security.microsoft.com
O1 - Hosts: 82.98.235.133 best-click-scanner.info
O1 - Hosts: 82.98.235.133 antivirus-xp-pro-2009.com
O1 - Hosts: 82.98.235.133 microsoft.infosecuritycenter.com
O1 - Hosts: 82.98.235.133 microsoft.softwaresecurityhelp.com
O1 - Hosts: 82.98.235.133 onlinenotifyq.net
O1 - Hosts: 82.98.235.133 antivirusxp-pro-2009.com
O1 - Hosts: 82.98.235.133 microsoft.browser-security-center.com


  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.


Next


  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt.
    Note:These logs can be located in the OTListIt2. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
thankyou for helping me catbyte, i have done as you have said and here are the 2 logs as you asked

here is the Extras.Txt

OTListIt Extras logfile created on: 5/04/2009 6:13:53 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.11.0 Folder = C:\Documents and Settings\Main\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1.99 Gb Total Physical Memory | 1.29 Gb Available Physical Memory | 64.76% Memory free
3.84 Gb Paging File | 3.30 Gb Available in Paging File | 85.91% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 109.87 Gb Free Space | 47.18% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DOLPHIN
Current User Name: Main
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call (Microsoft Corporation)
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire (Lime Wire, LLC)
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent (BitTorrent, Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call (Microsoft Corporation)
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{184E7118-0295-43C4-B72C-1D54AA75AAF7}" = Windows Live Mail
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{1EB8D94B-4AC2-4483-9616-0FD7EDE14B18}" = 101 Kids Games Volume 1
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23970E31-948B-466E-8376-1224D32FDF0C}" = Convert
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 13
"{2CD2C0DB-81C3-416B-9FA6-589B9235359B}" = OpenOffice.org 2.4
"{318AB667-3230-41B5-A617-CB3BF748D371}" = iTunes
"{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java™ 6 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C52E7DA-C431-4239-B66B-1BF703D5B194}" = Windows Live Photo Gallery
"{40C03514-89C3-41BA-0090-3B440256DB87}" = The Sims 2
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}" = Junk Mail filter update
"{4E868D3D-6EEB-4273-926C-2287236B5B79}" = 3DVIA player 4.1
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{611BD998-34B9-4DDA-00AE-0CB4632E86FA}" = SimCity 4
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}" = Trend Micro Internet Security
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD [removed]
"{76CD2979-09C0-493A-84B3-8FD97EF4BCEA}" = Windows Live Family Safety
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E72B982-D54F-486F-B35A-C24B6F171033}" = Nero 7 Essentials
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{907B4640-266B-4A21-92FB-CD1A86CD0F63}" = RollerCoaster Tycoon 3 Platinum
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{993960EE-CA4D-443F-8F88-E24260DD5FD2}" = LG PC Suite
"{9FB2CE8C-E86C-4368-B3C9-F472898F926E}" = Desert Storm
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}" = Windows Live Sync
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A621B45A-D138-4A95-BE10-7CABA05EF94E}" = Trend Micro Internet Security
"{AC76BA86-7AD7-1033-7B44-A70800000002}" = Adobe Reader 7.0.8
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BEA2FF8E-50A3-4C6D-955E-5632C881753F}" = NetComm NB6 Series ADSL2+ Router USB Driver
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{C3B58B0A-53CE-4A88-8C42-76E18341CA91}" = Eureka's 1000 Games
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F958CA02-BB40-4007-894B-258729456EE4}" = QuickTime
"3DGroove" = 3D Groove Playback Engine
"ABC's & 123's" = ABC's & 123's
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"Cars - Radiator Springs Adventures" = Cars - Radiator Springs Adventures
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Shrink_is1" = DVD Shrink 3.2
"DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5_is1" = DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5.1.1.0
"FUN ON ALPHABET FARM" = FUN ON ALPHABET FARM
"FUN WITH NUMBERS & PUZZLES" = FUN WITH NUMBERS & PUZZLES
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"Hoyle Casino 2009" = Hoyle Casino 2009
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ImgBurn" = ImgBurn
"Kid's Paint & Puzzles" = Kid's Paint & Puzzles
"Lexmark 510 Series" = Lexmark 510 Series
"LimeWire" = LimeWire 4.18.5
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Monopoly by Parker Brothers" = Monopoly by Parker Brothers
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"OJOsoft Total Video Converter_is1" = OJOsoft Total Video Converter
"Password Safe" = Password Safe
"Pregnancy Count_is1" = Pregnancy Count 4.0
"RollerCoaster Tycoon Setup" = Roll
"The Game Of Life" = The Game Of Life
"UltimateBet" = UltimateBet
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 25/02/2009 12:07:28 PM | Computer Name = DOLPHIN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 25/02/2009 7:24:01 PM | Computer Name = DOLPHIN | Source = Application Hang | ID = 1002
Description = Hanging application Play&Learn.exe, version 5.0.1.26, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 25/02/2009 7:24:14 PM | Computer Name = DOLPHIN | Source = Application Hang | ID = 1002
Description = Hanging application Play&Learn.exe, version 5.0.1.26, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 25/02/2009 7:24:14 PM | Computer Name = DOLPHIN | Source = Application Hang | ID = 1002
Description = Hanging application Play&Learn.exe, version 5.0.1.26, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/03/2009 4:49:01 AM | Computer Name = DOLPHIN | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module mshtml.dll, version 7.0.6000.16809, fault address 0x000ba952.

Error - 1/03/2009 4:49:07 AM | Computer Name = DOLPHIN | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.

Error - 1/03/2009 4:49:41 AM | Computer Name = DOLPHIN | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16791, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/03/2009 5:47:03 PM | Computer Name = DOLPHIN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

[ System Events ]
Error - 3/04/2009 8:30:04 PM | Computer Name = DOLPHIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 3/04/2009 8:30:04 PM | Computer Name = DOLPHIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 3/04/2009 9:04:10 PM | Computer Name = DOLPHIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 3/04/2009 9:04:10 PM | Computer Name = DOLPHIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 3/04/2009 10:52:20 PM | Computer Name = DOLPHIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 4/04/2009 11:20:00 AM | Computer Name = DOLPHIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 4/04/2009 11:20:00 AM | Computer Name = DOLPHIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 4/04/2009 12:20:00 PM | Computer Name = DOLPHIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 4/04/2009 12:20:00 PM | Computer Name = DOLPHIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 4/04/2009 9:11:00 PM | Computer Name = DOLPHIN | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{7C4A95AF-EA25-4AE6-B74E-4C4D26FC8876}
because another computer on the network has the same name. The server could not
start.


< End of report >



AND here is the OTList.Txt

OTListIt logfile created on: 5/04/2009 6:13:53 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.11.0 Folder = C:\Documents and Settings\Main\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1.99 Gb Total Physical Memory | 1.29 Gb Available Physical Memory | 64.76% Memory free
3.84 Gb Paging File | 3.30 Gb Available in Paging File | 85.91% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 109.87 Gb Free Space | 47.18% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DOLPHIN
Current User Name: Main
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\system32\LEXPPS.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Trend Micro Inc.)
PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
PRC - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Main\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (fsssvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (InCDsrv [Auto | Running]) – C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LexBceS [Auto | Running]) – C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (NMIndexingService [On_Demand | Stopped]) – C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (Nero AG)
SRV - (SfCtlCom [Auto | Running]) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
SRV - (TMBMServer [Auto | Running]) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
SRV - (TmPfw [On_Demand | Running]) – C:\Program Files\Trend Micro\Internet Security\TmPfw.exe (Trend Micro Inc.)
SRV - (tmproxy [On_Demand | Running]) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (E100B [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (fssfltr [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (gdrv [On_Demand | Stopped]) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\igxpmp32.sys (Intel Corporation)
DRV - (InCDfs [Disabled | Running]) – C:\WINDOWS\system32\drivers\InCDFs.sys (Nero AG)
DRV - (InCDPass [System | Running]) – C:\WINDOWS\system32\drivers\InCDPass.sys (Nero AG)
DRV - (incdrm [System | Running]) – C:\WINDOWS\system32\drivers\InCDRm.sys (Nero AG)
DRV - (IntcAzAudAddService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (pcouffin [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\pcouffin.sys (VSO Software)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (RTLE8023xp [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (Secdrv [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (tmactmon [Auto | Running]) – C:\WINDOWS\system32\drivers\tmactmon.sys (Trend Micro Inc.)
DRV - (tmcfw [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\TM_CFW.sys (Trend Micro Inc.)
DRV - (tmcomm [Auto | Running]) – C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (tmevtmgr [Auto | Running]) – C:\WINDOWS\system32\drivers\tmevtmgr.sys (Trend Micro Inc.)
DRV - (tmpreflt [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\tmpreflt.sys (Trend Micro Inc.)
DRV - (tmtdi [System | Running]) – C:\WINDOWS\system32\DRIVERS\tmtdi.sys (Trend Micro Inc.)
DRV - (tmxpflt [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\tmxpflt.sys (Trend Micro Inc.)
DRV - (usbbus [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\lgusbbus.sys (LG Electronics Inc.)
DRV - (UsbDiag [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys (LG Electronics Inc.)
DRV - (USB_RNDIS [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\usb8023.sys (Microsoft Corporation)
DRV - (vsapint [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\vsapint.sys (Trend Micro Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com.au
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com.au
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,AutoSearch = http://ie.search.msn.com/{SUB_RFC1766}/src…autosearch.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.google.com.au"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.6

FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/02/11 17:01:11 | 00,000,000 | —D | M]

[2008/12/17 16:04:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\mozilla\Extensions
[2008/12/17 16:04:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2008/12/17 16:04:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\mozilla\Firefox\Profiles\1mqicrfg.default\extensions
[2009/03/08 12:22:37 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/02/11 17:01:20 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}

O1 HOSTS File: (728 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (no name) - {209ba86b-cd8c-4393-951e-b172ffbca90c} - Reg Error: Key error. File not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Key error. File not found
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {EAC84402-1B6F-46C2-AB0F-D4B9AA17E552} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {F6D66EE9-88BE-415C-8DD4-B8C7FDCF484A} - C:\WINDOWS\system32\fccdCsst.dll ()
O3 - HKLM\..\Toolbar: (&Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" (Trend Micro Inc.)
O4 - HKLM..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide (Microsoft Corporation)
O4 - HKCU..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\Main\Start Menu\Programs\Startup\RollerCoaster Tycoon 3 Registration.lnk = C:\Documents and Settings\Main\Local Settings\Temp\{AF7A94F2-F7B1-4646-B835-8EBDC369D400}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe (UltimateBet)
O9 - Extra 'Tools' menuitem : UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe (UltimateBet)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} http://www.worldwinner.com/games/v47/scrab…rabblecubes.cab (ScrabbleCubes Control)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} http://www.bebo.com/files/BeboUploader.5.1.4.cab (Bebo Uploader Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://active.macromedia.com/director/cabs/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2C153C75-8476-434B-B3C3-57B63A3D1939} http://www.worldwinner.com/games/v48/brickout/brickout.cab (Brickout Control)
O16 - DPF: {42FDC231-A411-45F8-B8B6-3B5026111DA8} http://www.worldwinner.com/games/v47/solit…litairerush.cab (SolitaireRush Control)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {555F1BBC-6EC2-474F-84AF-633EF097FF54} http://www.worldwinner.com/games/v52/wwhearts/wwhearts.cab (WWHearts Control)
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} http://www.worldwinner.com/games/v63/bjattack/bja.cab (BJA Control)
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab (Bejeweled Control)
O16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} http://www.worldwinner.com/games/v49/blockwerx/blockwerx.cab (Blockwerx Control)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} http://www.nick.com/common/groove/gx/GrooveAX27.cab (Groove Control)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} http://www.worldwinner.com/games/v57/cubis/cubis.cab (Cubis Control)
O16 - DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} http://www.worldwinner.com/games/v49/luxor/luxor.cab (WwLuxor Control)
O16 - DPF: {C5326A4D-E9AA-40AD-A09A-E74304D86B47} http://www.worldwinner.com/games/v50/dinerdash/dinerdash.cab (DinerDash Control)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} http://www.worldwinner.com/games/v47/famil…/familyfeud.cab (FamilyFeud Control)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://games.myspace.com/Gameshell/GameHos…ronGameHost.cab (Oberon Flash Game Host)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe (Virtools WebPlayer Class)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {196d8e11-fd4e-4caa-86d2-58f64970f4ad} - Reg Error: Key error. File not found
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\fccdCsst) - C:\WINDOWS\system32\fccdCsst.dll ()
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (MACHINE BootExecut) - File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\*.tmp files]
[2009/04/05 18:12:00 | 00,499,200 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Main\Desktop\OTListIt2.exe
[2009/04/05 16:21:59 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\wulbicyu.dll
[2009/04/05 16:21:57 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\gehqvkdg.dll
[2009/04/05 04:24:55 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\wnhthpjx.dll
[2009/04/05 04:21:55 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\isalhhpy.dll
[2009/04/04 22:57:06 | 00,008,313 | -HS- | C] () – C:\WINDOWS\System32\tssCdccf.ini2
[2009/04/04 12:10:50 | 00,000,095 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/04/04 11:18:47 | 00,000,933 | —- | C] () – C:\Documents and Settings\Main\Desktop\Spybot - Search & Destroy.lnk
[2009/04/04 11:18:38 | 00,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2009/04/04 11:18:38 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/04/04 11:18:37 | 00,001,734 | —- | C] () – C:\Documents and Settings\Main\Desktop\HijackThis.lnk
[2009/04/04 10:32:09 | 00,000,330 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/04/04 10:28:51 | 00,000,000 | —D | C] – C:\Program Files\Windows Defender
[2009/04/04 09:27:33 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\wacouvlb.dll
[2009/04/04 09:24:30 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\yblhijmh.dll
[2009/04/03 20:05:25 | 00,000,000 | —D | C] – C:\Program Files\RegistryFix7
[2009/04/03 11:14:56 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\devbvvww.dll
[2009/04/03 11:11:56 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\wagymaby.dll
[2009/04/02 23:11:56 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\hpcvuxfm.dll
[2009/04/02 11:12:47 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\mvgnwgfr.dll
[2009/04/02 11:12:46 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ymaplkre.dll
[2009/04/01 23:18:45 | 00,061,440 | —- | C] () – C:\WINDOWS\System32\rvuljqve.exe
[2009/04/01 23:15:44 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\hopeycbu.dll
[2009/04/01 23:12:45 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\yuskhwwb.dll
[2009/04/01 11:14:59 | 00,061,440 | —- | C] () – C:\WINDOWS\System32\cauyxwrb.exe
[2009/04/01 11:14:55 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\gaaoxvld.dll
[2009/04/01 11:11:56 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\tbsswljo.dll
[2009/03/31 15:50:57 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\fqefrwpx.dll
[2009/03/30 23:34:50 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\njtynmgo.dll
[2009/03/30 23:31:51 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\vxgmytmh.dll
[2009/03/29 11:55:07 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\luyejngb.dll
[2009/03/29 11:52:56 | 00,104,448 | —- | C] () – C:\WINDOWS\System32\dhqgul.dll
[2009/03/29 11:52:49 | 00,104,448 | —- | C] () – C:\WINDOWS\System32\aoorbxep.dll
[2009/03/28 10:10:10 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\bnescwdu.dll
[2009/03/28 10:05:26 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ltscijqs.dll
[2009/03/27 06:41:51 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\lflxtcpd.dll
[2009/03/27 06:38:52 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\huqngxqh.dll
[2009/03/26 18:41:54 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\qqfjqodl.dll
[2009/03/26 18:41:53 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\wayfwmay.dll
[2009/03/26 06:44:51 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\mdqjiqxh.dll
[2009/03/26 06:41:51 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\xgkrwbqm.dll
[2009/03/25 18:28:36 | 00,000,000 | —D | C] – C:\Documents and Settings\Main\Desktop\sharnie
[2009/03/25 18:26:00 | 00,000,000 | —D | C] – C:\Documents and Settings\Main\My Documents\sharnie
[2009/03/25 11:23:25 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ejwkxavh.dll
[2009/03/25 11:20:55 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\cqfhvcdr.dll
[2009/03/24 16:26:21 | 00,100,642 | —- | C] () – C:\Documents and Settings\Main\My Documents\m2e.pdf
[2009/03/24 16:24:31 | 00,100,642 | —- | C] () – C:\Documents and Settings\Main\My Documents\m2e - GE Request.pdf
[2009/03/24 11:44:45 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\byeqdfog.dll
[2009/03/23 21:41:45 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ssswdpmu.dll
[2009/03/23 21:38:45 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\wygowcfk.dll
[2009/03/23 09:42:43 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\dfxwxlvb.dll
[2009/03/23 09:39:43 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\baisxvxh.dll
[2009/03/22 21:42:43 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\qcbwauql.dll
[2009/03/22 20:09:42 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\fopyofuy.dll
[2009/03/21 07:30:41 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\hkbfkvct.dll
[2009/03/20 19:30:26 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\tohcrtxd.dll
[2009/03/20 19:21:03 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\vhjdfjee.dll
[2009/03/19 21:34:15 | 00,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2009/03/19 21:09:17 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2009/03/19 21:08:50 | 00,055,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\fssfltr_tdi.sys
[2009/03/19 21:04:28 | 00,000,000 | R-SD | C] – C:\WINDOWS\assembly
[2009/03/19 20:58:21 | 00,000,000 | —D | C] – C:\WINDOWS\Microsoft.NET
[2009/03/19 20:50:11 | 00,000,000 | —D | C] – C:\Program Files\Microsoft
[2009/03/19 20:49:34 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\microsoft
[2009/03/19 20:48:40 | 00,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2009/03/19 20:26:44 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\sygvscyp.dll
[2009/03/19 20:23:46 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\wwxftwfi.dll
[2009/03/19 19:47:53 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2009/03/19 08:23:42 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\tefgcmkq.dll
[2009/03/18 15:45:16 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\xbjcprbj.dll
[2009/03/18 03:45:14 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\rxvaummx.dll
[2009/03/17 15:43:09 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\ytfueqjp.dll
[2009/03/17 15:43:07 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\yfvhwahk.dll
[2009/03/16 07:42:41 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ifqdwtid.dll
[2009/03/16 00:12:46 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\ambkokqe.dll
[2009/03/15 12:35:52 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\fqggapua.dll
[2009/03/15 12:12:37 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\tkkqdbja.dll
[2009/03/14 23:16:26 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\dnddfyao.dll
[2009/03/14 23:09:35 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\xraejfbq.dll
[2009/03/14 11:12:35 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\jgvvjvcy.dll
[2009/03/14 11:09:40 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\strsfxsr.dll
[2009/03/14 08:42:20 | 02,530,850 | —- | C] () – C:\Documents and Settings\Main\My Documents\2009Catalogue.pdf
[2009/03/13 22:07:43 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\yfmwjvpj.dll
[2009/03/13 22:07:41 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\msumncjk.dll
[2009/03/13 22:05:50 | 00,016,384 | —- | C] () – C:\WINDOWS\DCEBoot.exe
[2009/03/13 10:07:24 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\pjgvvnbj.dll
[2009/03/13 10:07:23 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\sohyhmso.dll
[2009/03/12 20:04:22 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\dfdqqodd.dll
[2009/03/12 20:01:22 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\phreelqa.dll
[2009/03/12 01:05:49 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\qtflxbfk.dll
[2009/03/12 01:02:49 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\xffecacc.dll
[2009/03/11 13:02:51 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\lrkriggo.dll
[2009/03/11 13:02:49 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\blvbxadn.dll
[2009/03/10 23:35:51 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\ewudiymt.dll
[2009/03/10 23:35:50 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ovkqqmpd.dll
[2009/03/10 11:35:49 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\uflaeoww.dll
[2009/03/10 10:08:50 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\unxrcrrl.dll
[2009/03/09 11:35:04 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\oukovvqk.dll
[2009/03/09 11:35:02 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\qnsfidhp.dll
[2009/03/08 21:29:06 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\bgwfuwgk.dll
[2009/03/08 21:29:04 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\tnutglap.dll
[2009/03/08 12:20:35 | 00,000,000 | —D | C] – C:\Program Files\The Bar
[2009/03/08 09:32:02 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\vwkgxavx.dll
[2009/03/08 09:29:02 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\ljjtoxne.dll
[2009/03/08 08:41:28 | 00,008,678 | -HS- | C] () – C:\Documents and Settings\Main\Desktop\Folder.jpg
[2009/03/08 08:41:28 | 00,002,388 | -HS- | C] () – C:\Documents and Settings\Main\Desktop\AlbumArtSmall.jpg
[2009/03/07 18:20:03 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\ndnkostt.dll
[2009/03/07 03:08:18 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ncsutuxx.dll
[2009/03/07 03:08:15 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\cslvwuva.dll
[2009/03/06 11:58:55 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\oxyimmgj.dll
[2009/03/03 22:00:47 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\hafntoso.dll
[2009/03/03 21:57:47 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\xhepesrq.dll
[2009/03/02 21:56:20 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\jhntqtxt.dll
[2009/03/02 21:56:17 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\hpsbtymx.dll
[2009/03/02 21:55:48 | 00,008,313 | -HS- | C] () – C:\WINDOWS\System32\tssCdccf.ini
[2009/03/02 21:55:41 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\byXPIxyA.dll
[2009/03/02 21:55:30 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\awtqrpoO.dll
[2009/03/02 21:55:18 | 00,236,544 | —- | C] () – C:\WINDOWS\System32\fccdCsst.dll
[2009/03/02 21:54:53 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\hgGxYPFw.dll
[2009/03/02 21:54:28 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\hgGvvtQG.dll
[2009/03/02 21:53:31 | 00,000,026 | —- | C] () – C:\WINDOWS\dksav1.ini
[2009/03/02 21:52:07 | 00,000,018 | —- | C] () – C:\WINDOWS\cnc.ini
[2009/03/02 21:50:37 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\fccdATJY.dll
[2009/03/02 21:50:36 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\nnnoNeEu.dll
[2009/03/02 21:50:10 | 00,005,639 | —- | C] () – C:\WINDOWS\System32\ddcAqNgF.dll
[2009/03/02 21:50:09 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\ljJCtuSi.dll
[2009/03/02 21:50:06 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\pmnkHAtR.dll
[2009/03/02 21:50:06 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\mlJYqQki.dll
[2009/03/02 21:50:06 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\mlJAtULB.dll
[2009/03/02 21:50:06 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\ddcBRkLd.dll
[2009/02/26 08:16:19 | 00,063,488 | —- | C] () – C:\WINDOWS\xobglu16.dll
[2009/02/26 08:16:19 | 00,026,046 | —- | C] () – C:\WINDOWS\xobglu32.dll
[2009/02/11 18:25:13 | 00,000,024 | —- | C] () – C:\WINDOWS\Woabc123.ini
[2009/02/11 18:23:16 | 00,000,108 | —- | C] () – C:\WINDOWS\ABC.ini
[2009/02/11 18:19:39 | 00,000,114 | —- | C] () – C:\WINDOWS\CIF.ini
[2009/02/11 18:14:01 | 00,000,087 | —- | C] () – C:\WINDOWS\KPP.INI
[2009/02/11 18:08:22 | 00,000,082 | —- | C] () – C:\WINDOWS\E1000g.ini
[2009/02/11 17:55:01 | 00,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2009/02/11 17:54:44 | 00,000,095 | —- | C] () – C:\WINDOWS\101kgv1.ini
[2009/02/09 19:21:28 | 00,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2008/12/16 14:11:00 | 00,000,026 | —- | C] () – C:\WINDOWS\WAR2R.INI
[2008/10/09 13:26:57 | 00,000,261 | —- | C] () – C:\WINDOWS\LEXSTAT.INI
[2008/08/25 16:41:01 | 00,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/08/20 18:50:28 | 01,355,899 | —- | C] () – C:\WINDOWS\UnInstallNetCommADSL.dll
[2008/08/20 09:37:55 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/08/20 09:09:28 | 00,147,456 | R— | C] () – C:\WINDOWS\System32\igfxCoIn_v4864.dll
[2008/08/19 00:49:04 | 00,000,000 | —- | C] () – C:\WINDOWS\control.ini
[2008/08/19 00:47:37 | 00,000,002 | —- | C] () – C:\WINDOWS\System32\desktop.ini
[2008/08/19 00:47:37 | 00,000,002 | —- | C] () – C:\WINDOWS\desktop.ini
[2008/08/19 00:47:18 | 00,000,037 | —- | C] () – C:\WINDOWS\vbaddin.ini
[2008/08/19 00:47:18 | 00,000,036 | —- | C] () – C:\WINDOWS\vb.ini
[2008/08/19 00:46:43 | 00,013,223 | —- | C] () – C:\WINDOWS\System32\tslabels.ini
[2008/08/19 00:46:43 | 00,001,931 | —- | C] () – C:\WINDOWS\System32\msdtcprf.ini
[2008/08/19 00:37:09 | 00,498,742 | —- | C] () – C:\WINDOWS\System32\dxmasf.dll
[2008/08/19 00:37:09 | 00,004,126 | —- | C] () – C:\WINDOWS\System32\msdxmlc.dll
[2008/08/19 00:37:09 | 00,000,576 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2008/08/19 00:37:03 | 00,053,478 | —- | C] () – C:\WINDOWS\System32\tcpmon.ini
[2008/08/19 00:37:03 | 00,015,360 | —- | C] () – C:\WINDOWS\System32\tsd32.dll
[2008/08/19 00:37:03 | 00,013,312 | —- | C] () – C:\WINDOWS\System32\win87em.dll
[2008/08/19 00:37:03 | 00,000,541 | —- | C] () – C:\WINDOWS\win.ini
[2008/08/19 00:37:03 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2008/08/19 00:37:01 | 00,270,848 | —- | C] () – C:\WINDOWS\System32\sbe.dll
[2008/08/19 00:37:01 | 00,012,082 | —- | C] () – C:\WINDOWS\System32\rsvp.ini
[2008/08/19 00:37:00 | 01,288,192 | —- | C] () – C:\WINDOWS\System32\quartz.dll
[2008/08/19 00:37:00 | 00,733,696 | —- | C] () – C:\WINDOWS\System32\qedwipes.dll
[2008/08/19 00:37:00 | 00,562,176 | —- | C] () – C:\WINDOWS\System32\qedit.dll
[2008/08/19 00:37:00 | 00,386,048 | —- | C] () – C:\WINDOWS\System32\qdvd.dll
[2008/08/19 00:37:00 | 00,279,040 | —- | C] () – C:\WINDOWS\System32\qdv.dll
[2008/08/19 00:37:00 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\qcap.dll
[2008/08/19 00:37:00 | 00,006,877 | —- | C] () – C:\WINDOWS\System32\pschdprf.ini
[2008/08/19 00:37:00 | 00,003,458 | —- | C] () – C:\WINDOWS\System32\rasctrs.ini
[2008/08/19 00:37:00 | 00,002,891 | —- | C] () – C:\WINDOWS\System32\perfci.ini
[2008/08/19 00:37:00 | 00,002,732 | —- | C] () – C:\WINDOWS\System32\perfwci.ini
[2008/08/19 00:37:00 | 00,001,152 | —- | C] () – C:\WINDOWS\System32\perffilt.ini
[2008/08/19 00:37:00 | 00,000,343 | —- | C] () – C:\WINDOWS\System32\prodspec.ini
[2008/08/19 00:36:59 | 00,035,648 | —- | C] () – C:\WINDOWS\System32\ntio411.sys
[2008/08/19 00:36:59 | 00,035,424 | —- | C] () – C:\WINDOWS\System32\ntio412.sys
[2008/08/19 00:36:59 | 00,034,560 | —- | C] () – C:\WINDOWS\System32\ntio804.sys
[2008/08/19 00:36:59 | 00,034,560 | —- | C] () – C:\WINDOWS\System32\ntio404.sys
[2008/08/19 00:36:59 | 00,033,840 | —- | C] () – C:\WINDOWS\System32\ntio.sys
[2008/08/19 00:36:59 | 00,029,370 | —- | C] () – C:\WINDOWS\System32\ntdos411.sys
[2008/08/19 00:36:59 | 00,029,274 | —- | C] () – C:\WINDOWS\System32\ntdos412.sys
[2008/08/19 00:36:59 | 00,029,146 | —- | C] () – C:\WINDOWS\System32\ntdos804.sys
[2008/08/19 00:36:59 | 00,029,146 | —- | C] () – C:\WINDOWS\System32\ntdos404.sys
[2008/08/19 00:36:59 | 00,027,866 | —- | C] () – C:\WINDOWS\System32\ntdos.sys
[2008/08/19 00:36:58 | 00,094,282 | —- | C] () – C:\WINDOWS\System32\msencode.dll
[2008/08/19 00:36:58 | 00,014,336 | —- | C] () – C:\WINDOWS\System32\msdmo.dll
[2008/08/19 00:36:58 | 00,001,405 | —- | C] () – C:\WINDOWS\msdfmap.ini
[2008/08/19 00:36:57 | 00,035,328 | —- | C] () – C:\WINDOWS\System32\mciqtz32.dll
[2008/08/19 00:36:56 | 00,199,168 | —- | C] () – C:\WINDOWS\System32\ir32_32.dll
[2008/08/19 00:36:56 | 00,042,809 | —- | C] () – C:\WINDOWS\System32\key01.sys
[2008/08/19 00:36:56 | 00,042,537 | —- | C] () – C:\WINDOWS\System32\keyboard.sys
[2008/08/19 00:36:55 | 01,015,477 | —- | C] () – C:\WINDOWS\System32\esentprf.ini
[2008/08/19 00:36:55 | 00,186,880 | —- | C] () – C:\WINDOWS\System32\encdec.dll
[2008/08/19 00:36:55 | 00,004,768 | —- | C] () – C:\WINDOWS\System32\himem.sys
[2008/08/19 00:36:53 | 00,059,904 | —- | C] () – C:\WINDOWS\System32\devenum.dll
[2008/08/19 00:36:52 | 00,355,112 | —- | C] () – C:\WINDOWS\System32\msjetoledb40.dll
[2008/08/19 00:36:52 | 00,252,928 | —- | C] () – C:\WINDOWS\System32\compatui.dll
[2008/08/19 00:36:52 | 00,070,656 | —- | C] () – C:\WINDOWS\System32\amstream.dll
[2008/08/19 00:36:52 | 00,027,097 | —- | C] () – C:\WINDOWS\System32\country.sys
[2008/08/19 00:36:52 | 00,009,029 | —- | C] () – C:\WINDOWS\System32\ansi.sys
[2008/08/18 17:43:21 | 00,458,164 | —- | C] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2008/08/18 17:43:20 | 00,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2001/08/18 08:36:28 | 00,157,696 | —- | C] () – C:\WINDOWS\System32\paqsp.dll

========== Files - Modified Within 30 Days ==========

[2 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/04/05 18:16:14 | 00,008,313 | -HS- | M] () – C:\WINDOWS\System32\tssCdccf.ini
[2009/04/05 18:15:30 | 00,008,313 | -HS- | M] () – C:\WINDOWS\System32\tssCdccf.ini2
[2009/04/05 18:12:03 | 00,499,200 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Main\Desktop\OTListIt2.exe
[2009/04/05 18:10:46 | 00,000,728 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/04/05 16:21:59 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\wulbicyu.dll
[2009/04/05 16:21:57 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\gehqvkdg.dll
[2009/04/05 11:11:23 | 00,458,164 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/05 11:11:23 | 00,392,958 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/04/05 11:11:23 | 00,059,148 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/04/05 04:24:55 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\wnhthpjx.dll
[2009/04/05 04:21:55 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\isalhhpy.dll
[2009/04/05 02:20:02 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/04/04 16:18:46 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/04 16:18:20 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/04/04 12:10:50 | 00,000,095 | —- | M] () – C:\WINDOWS\wininit.ini
[2009/04/04 11:18:48 | 00,000,933 | —- | M] () – C:\Documents and Settings\Main\Desktop\Spybot - Search & Destroy.lnk
[2009/04/04 11:18:37 | 00,001,734 | —- | M] () – C:\Documents and Settings\Main\Desktop\HijackThis.lnk
[2009/04/04 10:28:35 | 00,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/04/04 09:27:33 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\wacouvlb.dll
[2009/04/04 09:24:30 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\yblhijmh.dll
[2009/04/03 12:04:06 | 00,001,167 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.bak
[2009/04/03 11:14:56 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\devbvvww.dll
[2009/04/03 11:11:56 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\wagymaby.dll
[2009/04/02 23:11:56 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\hpcvuxfm.dll
[2009/04/02 11:12:47 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\mvgnwgfr.dll
[2009/04/02 11:12:46 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\ymaplkre.dll
[2009/04/01 23:18:47 | 00,001,108 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.msn
[2009/04/01 23:18:45 | 00,061,440 | —- | M] () – C:\WINDOWS\System32\rvuljqve.exe
[2009/04/01 23:15:44 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\hopeycbu.dll
[2009/04/01 23:12:45 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\yuskhwwb.dll
[2009/04/01 16:02:42 | 00,016,384 | —- | M] () – C:\WINDOWS\DCEBoot.exe
[2009/04/01 11:15:01 | 00,061,440 | —- | M] () – C:\WINDOWS\System32\cauyxwrb.exe
[2009/04/01 11:14:55 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\gaaoxvld.dll
[2009/04/01 11:11:56 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\tbsswljo.dll
[2009/03/31 15:50:57 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\fqefrwpx.dll
[2009/03/31 15:50:28 | 00,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/03/30 23:34:50 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\njtynmgo.dll
[2009/03/30 23:31:51 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\vxgmytmh.dll
[2009/03/30 08:48:02 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/03/29 11:55:07 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\luyejngb.dll
[2009/03/29 11:52:55 | 00,104,448 | —- | M] () – C:\WINDOWS\System32\dhqgul.dll
[2009/03/29 11:52:55 | 00,104,448 | —- | M] () – C:\WINDOWS\System32\aoorbxep.dll
[2009/03/28 10:10:10 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\bnescwdu.dll
[2009/03/28 10:05:26 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\ltscijqs.dll
[2009/03/27 13:55:26 | 00,000,668 | —- | M] () – C:\Documents and Settings\Main\Application Data\vso_ts_preview.xml
[2009/03/27 06:41:51 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\lflxtcpd.dll
[2009/03/27 06:38:52 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\huqngxqh.dll
[2009/03/26 18:41:54 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\qqfjqodl.dll
[2009/03/26 18:41:53 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\wayfwmay.dll
[2009/03/26 06:44:51 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\mdqjiqxh.dll
[2009/03/26 06:41:51 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\xgkrwbqm.dll
[2009/03/25 18:25:38 | 00,054,272 | -HS- | M] () – C:\Documents and Settings\Main\My Documents\Thumbs.db
[2009/03/25 11:23:25 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\ejwkxavh.dll
[2009/03/25 11:20:55 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\cqfhvcdr.dll
[2009/03/24 16:26:21 | 00,100,642 | —- | M] () – C:\Documents and Settings\Main\My Documents\m2e.pdf
[2009/03/24 16:24:31 | 00,100,642 | —- | M] () – C:\Documents and Settings\Main\My Documents\m2e - GE Request.pdf
[2009/03/24 11:44:45 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\byeqdfog.dll
[2009/03/23 21:41:45 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\ssswdpmu.dll
[2009/03/23 21:38:45 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\wygowcfk.dll
[2009/03/23 09:42:43 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\dfxwxlvb.dll
[2009/03/23 09:39:43 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\baisxvxh.dll
[2009/03/22 21:42:43 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\qcbwauql.dll
[2009/03/22 20:09:42 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\fopyofuy.dll
[2009/03/21 07:30:41 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\hkbfkvct.dll
[2009/03/20 19:30:26 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\tohcrtxd.dll
[2009/03/20 19:21:03 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\vhjdfjee.dll
[2009/03/20 19:14:29 | 00,120,544 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/19 21:11:28 | 00,019,448 | —- | M] () – C:\Documents and Settings\Main\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/03/19 20:51:35 | 00,000,896 | —- | M] () – C:\Documents and Settings\Main\My Documents\My Sharing Folders.lnk
[2009/03/19 20:26:44 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\sygvscyp.dll
[2009/03/19 20:23:46 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\wwxftwfi.dll
[2009/03/19 08:23:42 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\tefgcmkq.dll
[2009/03/18 15:45:16 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\xbjcprbj.dll
[2009/03/18 03:45:14 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\rxvaummx.dll
[2009/03/17 15:43:09 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\ytfueqjp.dll
[2009/03/17 15:43:07 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\yfvhwahk.dll
[2009/03/16 07:42:41 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\ifqdwtid.dll
[2009/03/16 00:12:46 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\ambkokqe.dll
[2009/03/15 12:35:52 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\fqggapua.dll
[2009/03/15 12:12:37 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\tkkqdbja.dll
[2009/03/14 23:16:26 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\dnddfyao.dll
[2009/03/14 23:09:35 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\xraejfbq.dll
[2009/03/14 11:12:35 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\jgvvjvcy.dll
[2009/03/14 11:09:40 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\strsfxsr.dll
[2009/03/14 08:43:40 | 02,530,850 | —- | M] () – C:\Documents and Settings\Main\My Documents\2009Catalogue.pdf
[2009/03/13 22:07:43 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\yfmwjvpj.dll
[2009/03/13 22:07:41 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\msumncjk.dll
[2009/03/13 10:07:24 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\pjgvvnbj.dll
[2009/03/13 10:07:23 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\sohyhmso.dll
[2009/03/12 20:04:22 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\dfdqqodd.dll
[2009/03/12 20:01:22 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\phreelqa.dll
[2009/03/12 01:05:49 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\qtflxbfk.dll
[2009/03/12 01:02:49 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\xffecacc.dll
[2009/03/11 13:02:51 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\lrkriggo.dll
[2009/03/11 13:02:49 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\blvbxadn.dll
[2009/03/10 23:35:51 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\ewudiymt.dll
[2009/03/10 23:35:50 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\ovkqqmpd.dll
[2009/03/10 11:35:49 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\uflaeoww.dll
[2009/03/10 10:08:50 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\unxrcrrl.dll
[2009/03/09 13:16:31 | 00,018,944 | —- | M] () – C:\Documents and Settings\Main\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/09 11:35:04 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\oukovvqk.dll
[2009/03/09 11:35:02 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\qnsfidhp.dll
[2009/03/08 21:29:06 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\bgwfuwgk.dll
[2009/03/08 21:29:04 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\tnutglap.dll
[2009/03/08 09:32:02 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\vwkgxavx.dll
[2009/03/08 09:29:02 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\ljjtoxne.dll
[2009/03/08 08:41:28 | 00,008,678 | -HS- | M] () – C:\Documents and Settings\Main\Desktop\Folder.jpg
[2009/03/08 08:41:28 | 00,002,388 | -HS- | M] () – C:\Documents and Settings\Main\Desktop\AlbumArtSmall.jpg
[2009/03/07 18:20:03 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\ndnkostt.dll
[2009/03/07 03:08:18 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\ncsutuxx.dll
[2009/03/07 03:08:15 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\cslvwuva.dll

========== LOP Check ==========

[2009/04/04 11:18:38 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/12/08 19:47:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/08/20 11:32:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/12/08 19:46:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2008/12/08 19:47:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/03/13 09:38:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2008/08/20 20:18:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2008/08/21 20:14:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2009/04/04 10:28:51 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/08/19 18:51:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nero
[2009/04/04 11:21:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/01/08 23:03:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/08/21 17:34:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trend Micro
[2008/10/06 19:04:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2008/08/28 21:37:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/08/21 11:14:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WLInstaller
[2009/03/25 18:40:00 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Main\Application Data
[2008/09/28 16:00:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Adobe
[2008/08/20 19:20:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\AdobeUM
[2008/11/12 19:35:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Ahead
[2008/12/08 23:05:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Apple Computer
[2009/02/09 20:03:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Atari
[2008/08/20 21:07:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Google
[2008/10/15 01:30:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Help
[2009/03/04 23:41:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Hoyle
[2009/01/01 09:39:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Hoyle FaceCreator
[2008/08/19 00:49:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Identities
[2008/11/12 17:48:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\ImgBurn
[2008/08/20 09:11:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\InstallShield
[2009/02/11 18:17:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\InterTrust
[2009/02/09 19:19:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Leadertech
[2008/12/18 23:06:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\LG Electronics
[2009/03/22 17:03:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\LimeWire
[2008/08/22 11:02:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Macromedia
[2009/03/19 20:57:38 | 00,000,000 | –SD | M] – C:\Documents and Settings\Main\Application Data\Microsoft
[2008/12/17 16:04:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Mozilla
[2009/03/10 12:45:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\OpenOffice.org2
[2008/08/25 10:16:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\SecondLife
[2009/01/26 19:58:15 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Main\Application Data\SecuROM
[2008/08/20 20:36:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Sun
[2009/02/22 12:38:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\uTorrent
[2009/03/27 13:55:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\Vso
[2008/10/06 18:46:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\WinRAR
[2009/03/30 08:48:02 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004/08/04 22:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/04/05 02:20:02 | 00,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2009/04/04 16:18:46 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:93EB7685
< End of report >
Hi,

Please do the following:

NOTEMake sure teatimer is disabled for this fix. (when it is re-enabled - ALLOW the changes we have made)

There are a lot of files we need to delete please make sure you copy EVERYTHING INSIDE the code box

Run OTList2.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTLI2 (start with the colon in front of :OTLI - do not copy the word code)

    :OTLI
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O2 - BHO: (no name) - {209ba86b-cd8c-4393-951e-b172ffbca90c} - Reg Error: Key error. File not found
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Key error. File not found
    O2 - BHO: (no name) - {EAC84402-1B6F-46C2-AB0F-D4B9AA17E552} - Reg Error: Key error. File not found
    O2 - BHO: (no name) - {F6D66EE9-88BE-415C-8DD4-B8C7FDCF484A} - C:\WINDOWS\system32\fccdCsst.dll ()
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - Reg Error: Key error. File not found
    O4 - Startup: C:\Documents and Settings\Main\Start Menu\Programs\Startup\RollerCoaster Tycoon 3 Registration.lnk = C:\Documents and Settings\Main\Local Settings\Temp\{AF7A94F2-F7B1-4646-B835-8EBDC369D400}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe File not found
    O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    [2009/04/05 16:21:59 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\wulbicyu.dll
    [2009/04/05 16:21:57 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\gehqvkdg.dll
    [2009/04/05 04:24:55 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\wnhthpjx.dll
    [2009/04/05 04:21:55 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\isalhhpy.dll
    [2009/04/04 09:27:33 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\wacouvlb.dll
    [2009/04/04 09:24:30 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\yblhijmh.dll
    [2009/04/03 11:14:56 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\devbvvww.dll
    [2009/04/03 11:11:56 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\wagymaby.dll
    [2009/04/02 23:11:56 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\hpcvuxfm.dll
    [2009/04/02 11:12:47 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\mvgnwgfr.dll
    [2009/04/02 11:12:46 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ymaplkre.dll
    [2009/04/01 23:18:45 | 00,061,440 | —- | C] () – C:\WINDOWS\System32\rvuljqve.exe
    [2009/04/01 23:15:44 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\hopeycbu.dll
    [2009/04/01 23:12:45 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\yuskhwwb.dll
    [2009/04/01 11:14:59 | 00,061,440 | —- | C] () – C:\WINDOWS\System32\cauyxwrb.exe
    [2009/04/01 11:14:55 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\gaaoxvld.dll
    [2009/04/01 11:11:56 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\tbsswljo.dll
    [2009/03/31 15:50:57 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\fqefrwpx.dll
    [2009/03/30 23:34:50 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\njtynmgo.dll
    [2009/03/30 23:31:51 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\vxgmytmh.dll
    [2009/03/29 11:55:07 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\luyejngb.dll
    [2009/03/29 11:52:56 | 00,104,448 | —- | C] () – C:\WINDOWS\System32\dhqgul.dll
    [2009/03/29 11:52:49 | 00,104,448 | —- | C] () – C:\WINDOWS\System32\aoorbxep.dll
    [2009/03/28 10:10:10 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\bnescwdu.dll
    [2009/03/28 10:05:26 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ltscijqs.dll
    [2009/03/27 06:41:51 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\lflxtcpd.dll
    [2009/03/27 06:38:52 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\huqngxqh.dll
    [2009/03/26 18:41:54 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\qqfjqodl.dll
    [2009/03/26 18:41:53 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\wayfwmay.dll
    [2009/03/26 06:44:51 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\mdqjiqxh.dll
    [2009/03/26 06:41:51 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\xgkrwbqm.dll
    [2009/03/25 11:23:25 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ejwkxavh.dll
    [2009/03/25 11:20:55 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\cqfhvcdr.dll
    [2009/03/24 11:44:45 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\byeqdfog.dll
    [2009/03/23 21:41:45 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ssswdpmu.dll
    [2009/03/23 21:38:45 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\wygowcfk.dll
    [2009/03/23 09:42:43 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\dfxwxlvb.dll
    [2009/03/23 09:39:43 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\baisxvxh.dll
    [2009/03/22 21:42:43 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\qcbwauql.dll
    [2009/03/22 20:09:42 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\fopyofuy.dll
    [2009/03/21 07:30:41 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\hkbfkvct.dll
    [2009/03/20 19:30:26 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\tohcrtxd.dll
    [2009/03/20 19:21:03 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\vhjdfjee.dll
    [2009/03/19 20:26:44 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\sygvscyp.dll
    [2009/03/19 20:23:46 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\wwxftwfi.dll
    [2009/03/19 08:23:42 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\tefgcmkq.dll
    [2009/03/18 15:45:16 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\xbjcprbj.dll
    [2009/03/18 03:45:14 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\rxvaummx.dll
    [2009/03/17 15:43:09 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\ytfueqjp.dll
    [2009/03/17 15:43:07 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\yfvhwahk.dll
    [2009/03/16 07:42:41 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ifqdwtid.dll
    [2009/03/16 00:12:46 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\ambkokqe.dll
    [2009/03/15 12:35:52 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\fqggapua.dll
    [2009/03/15 12:12:37 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\tkkqdbja.dll
    [2009/03/14 23:16:26 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\dnddfyao.dll
    [2009/03/14 23:09:35 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\xraejfbq.dll
    [2009/03/14 11:12:35 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\jgvvjvcy.dll
    [2009/03/14 11:09:40 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\strsfxsr.dll
    [2009/03/13 22:07:43 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\yfmwjvpj.dll
    [2009/03/13 22:07:41 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\msumncjk.dll
    [2009/03/13 10:07:24 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\pjgvvnbj.dll
    [2009/03/13 10:07:23 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\sohyhmso.dll
    [2009/03/12 20:04:22 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\dfdqqodd.dll
    [2009/03/12 20:01:22 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\phreelqa.dll
    [2009/03/12 01:05:49 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\qtflxbfk.dll
    [2009/03/12 01:02:49 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\xffecacc.dll
    [2009/03/11 13:02:51 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\lrkriggo.dll
    [2009/03/11 13:02:49 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\blvbxadn.dll
    [2009/03/10 23:35:51 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\ewudiymt.dll
    [2009/03/10 23:35:50 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ovkqqmpd.dll
    [2009/03/10 11:35:49 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\uflaeoww.dll
    [2009/03/10 10:08:50 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\unxrcrrl.dll
    [2009/03/09 11:35:04 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\oukovvqk.dll
    [2009/03/09 11:35:02 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\qnsfidhp.dll
    [2009/03/08 21:29:06 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\bgwfuwgk.dll
    [2009/03/08 21:29:04 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\tnutglap.dll
    [2009/03/08 09:32:02 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\vwkgxavx.dll
    [2009/03/08 09:29:02 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\ljjtoxne.dll
    [2009/03/07 18:20:03 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\ndnkostt.dll
    [2009/03/07 03:08:18 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ncsutuxx.dll
    [2009/03/07 03:08:15 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\cslvwuva.dll
    [2009/03/06 11:58:55 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\oxyimmgj.dll
    [2009/03/03 22:00:47 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\hafntoso.dll
    [2009/03/03 21:57:47 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\xhepesrq.dll
    [2009/03/02 21:56:20 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\jhntqtxt.dll
    [2009/03/02 21:56:17 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\hpsbtymx.dll
    [2009/03/02 21:55:48 | 00,008,313 | -HS- | C] () – C:\WINDOWS\System32\tssCdccf.ini
    [2009/03/02 21:55:41 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\byXPIxyA.dll
    [2009/03/02 21:55:30 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\awtqrpoO.dll
    [2009/03/02 21:55:18 | 00,236,544 | —- | C] () – C:\WINDOWS\System32\fccdCsst.dll
    [2009/03/02 21:54:53 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\hgGxYPFw.dll
    [2009/03/02 21:54:28 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\hgGvvtQG.dll
    [2009/03/19 21:34:15 | 00,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
    [2009/03/02 21:50:37 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\fccdATJY.dll
    [2009/03/02 21:50:36 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\nnnoNeEu.dll
    [2009/03/02 21:50:10 | 00,005,639 | —- | C] () – C:\WINDOWS\System32\ddcAqNgF.dll
    [2009/03/02 21:50:09 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\ljJCtuSi.dll
    [2009/03/02 21:50:06 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\pmnkHAtR.dll
    [2009/03/02 21:50:06 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\mlJYqQki.dll
    [2009/03/02 21:50:06 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\mlJAtULB.dll
    [2009/03/02 21:50:06 | 00,037,376 | —- | C] () – C:\WINDOWS\System32\ddcBRkLd.dll
    [2009/02/26 08:16:19 | 00,063,488 | —- | C] () – C:\WINDOWS\xobglu16.dll
    [2009/02/26 08:16:19 | 00,026,046 | —- | C] () – C:\WINDOWS\xobglu32.dll
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )


NEXT

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.


NEXT

Go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

In your next reply I need

  • OTListIt2 log
  • MBAM Log
  • Kaspersky report
Hello Catbyte,
Here are my logs for the things you have asked for and thanks again


OTListIt2 log

OTListIt logfile created on: 7/04/2009 9:33:45 PM - Run 4
OTListIt2 by OldTimer - Version 2.0.11.0 Folder = C:\Documents and Settings\Main\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1.99 Gb Total Physical Memory | 1.39 Gb Available Physical Memory | 69.74% Memory free
3.84 Gb Paging File | 3.07 Gb Available in Paging File | 80.07% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 110.45 Gb Free Space | 47.43% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DOLPHIN
Current User Name: Main
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\system32\LEXPPS.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Java\jre6\bin\java.exe (Sun Microsystems, Inc.)
PRC - C:\Documents and Settings\Main\Local Settings\Temp\jkos-Main\binaries\ScanningProcess.exe (Kaspersky Lab.)
PRC - C:\Documents and Settings\Main\Local Settings\Temp\jkos-Main\binaries\ScanningProcess.exe (Kaspersky Lab.)
PRC - C:\Documents and Settings\Main\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (fsssvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (InCDsrv [Auto | Running]) – C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe (Nero AG)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LexBceS [Auto | Running]) – C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (NMIndexingService [On_Demand | Stopped]) – C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (Nero AG)
SRV - (SfCtlCom [Auto | Stopped]) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Trend Micro Inc.)
SRV - (TMBMServer [Auto | Stopped]) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
SRV - (TmPfw [On_Demand | Stopped]) – C:\Program Files\Trend Micro\Internet Security\TmPfw.exe (Trend Micro Inc.)
SRV - (tmproxy [On_Demand | Stopped]) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (E100B [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (fssfltr [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (gdrv [On_Demand | Stopped]) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\igxpmp32.sys (Intel Corporation)
DRV - (InCDfs [Disabled | Running]) – C:\WINDOWS\system32\drivers\InCDFs.sys (Nero AG)
DRV - (InCDPass [System | Running]) – C:\WINDOWS\system32\drivers\InCDPass.sys (Nero AG)
DRV - (incdrm [System | Running]) – C:\WINDOWS\system32\drivers\InCDRm.sys (Nero AG)
DRV - (IntcAzAudAddService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (pcouffin [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\pcouffin.sys (VSO Software)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (RTLE8023xp [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (Secdrv [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (tmactmon [Auto | Stopped]) – C:\WINDOWS\system32\drivers\tmactmon.sys (Trend Micro Inc.)
DRV - (tmcfw [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\TM_CFW.sys (Trend Micro Inc.)
DRV - (tmcomm [Auto | Running]) – C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (tmevtmgr [Auto | Stopped]) – C:\WINDOWS\system32\drivers\tmevtmgr.sys (Trend Micro Inc.)
DRV - (tmpreflt [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\tmpreflt.sys (Trend Micro Inc.)
DRV - (tmtdi [System | Running]) – C:\WINDOWS\system32\DRIVERS\tmtdi.sys (Trend Micro Inc.)
DRV - (tmxpflt [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\tmxpflt.sys (Trend Micro Inc.)
DRV - (usbbus [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\lgusbbus.sys (LG Electronics Inc.)
DRV - (UsbDiag [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys (LG Electronics Inc.)
DRV - (USB_RNDIS [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\usb8023.sys (Microsoft Corporation)
DRV - (vsapint [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\vsapint.sys (Trend Micro Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com.au
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com.au
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,AutoSearch = http://ie.search.msn.com/{SUB_RFC1766}/src…autosearch.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.google.com.au"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.6

FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/02/11 17:01:11 | 00,000,000 | —D | M]

[2008/12/17 16:04:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\mozilla\Extensions
[2008/12/17 16:04:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2008/12/17 16:04:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Main\Application Data\mozilla\Firefox\Profiles\1mqicrfg.default\extensions
[2009/03/08 12:22:37 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/02/11 17:01:20 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}

O1 HOSTS File: (728 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (no name) - {209ba86b-cd8c-4393-951e-b172ffbca90c} - Reg Error: Key error. File not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {5FEE60AE-DC68-4044-8B05-C436A21D6513} - Reg Error: Key error. File not found
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (Google Inc.)
O2 - BHO: (no name) - {C7E7F703-357D-4C46-BD17-C2E86E826EBB} - Reg Error: Key error. File not found
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (Google Inc.)
O2 - BHO: (no name) - {CAB1BF85-D8D1-4090-8870-47CD2BD4199E} - Reg Error: Key error. File not found
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {EAC84402-1B6F-46C2-AB0F-D4B9AA17E552} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {F6D66EE9-88BE-415C-8DD4-B8C7FDCF484A} - Reg Error: Key error. File not found
O3 - HKLM\..\Toolbar: (&Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" (Trend Micro Inc.)
O4 - HKLM..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide (Microsoft Corporation)
O4 - HKCU..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\Main\Start Menu\Programs\Startup\RollerCoaster Tycoon 3 Registration.lnk = C:\Documents and Settings\Main\Local Settings\Temp\{AF7A94F2-F7B1-4646-B835-8EBDC369D400}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe (UltimateBet)
O9 - Extra 'Tools' menuitem : UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe (UltimateBet)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} http://www.worldwinner.com/games/v47/scrab…rabblecubes.cab (ScrabbleCubes Control)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} http://www.bebo.com/files/BeboUploader.5.1.4.cab (Bebo Uploader Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://active.macromedia.com/director/cabs/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2C153C75-8476-434B-B3C3-57B63A3D1939} http://www.worldwinner.com/games/v48/brickout/brickout.cab (Brickout Control)
O16 - DPF: {42FDC231-A411-45F8-B8B6-3B5026111DA8} http://www.worldwinner.com/games/v47/solit…litairerush.cab (SolitaireRush Control)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {555F1BBC-6EC2-474F-84AF-633EF097FF54} http://www.worldwinner.com/games/v52/wwhearts/wwhearts.cab (WWHearts Control)
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} http://www.worldwinner.com/games/v63/bjattack/bja.cab (BJA Control)
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab (Bejeweled Control)
O16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} http://www.worldwinner.com/games/v49/blockwerx/blockwerx.cab (Blockwerx Control)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} http://www.nick.com/common/groove/gx/GrooveAX27.cab (Groove Control)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} http://www.worldwinner.com/games/v57/cubis/cubis.cab (Cubis Control)
O16 - DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} http://www.worldwinner.com/games/v49/luxor/luxor.cab (WwLuxor Control)
O16 - DPF: {C5326A4D-E9AA-40AD-A09A-E74304D86B47} http://www.worldwinner.com/games/v50/dinerdash/dinerdash.cab (DinerDash Control)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} http://www.worldwinner.com/games/v47/famil…/familyfeud.cab (FamilyFeud Control)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://games.myspace.com/Gameshell/GameHos…ronGameHost.cab (Oberon Flash Game Host)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe (Virtools WebPlayer Class)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {196d8e11-fd4e-4caa-86d2-58f64970f4ad} - Reg Error: Key error. File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (MACHINE BootExecut) - File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\*.tmp files]
[2009/04/07 19:13:11 | 01,789,740 | —- | C] () – C:\Documents and Settings\Main\My Documents\Bedroom Autumn 09.pdf
[2009/04/07 19:03:51 | 05,123,425 | —- | C] () – C:\Documents and Settings\Main\My Documents\cat-7-2008.pdf
[2009/04/07 14:31:50 | 00,000,000 | —D | C] – C:\Documents and Settings\Main\Application Data\Malwarebytes
[2009/04/07 14:31:47 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/07 14:31:47 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/07 14:31:45 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/07 14:31:44 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/04/07 14:31:44 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/07 13:55:19 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/04/07 06:48:48 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\frduwlck.dll
[2009/04/07 06:48:46 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\chofsldx.dll
[2009/04/06 10:51:09 | 00,001,804 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/04/06 10:50:28 | 00,000,000 | —D | C] – C:\Program Files\iPod
[2009/04/06 10:50:24 | 00,000,000 | —D | C] – C:\Program Files\iTunes
[2009/04/06 10:50:24 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2009/04/06 10:47:45 | 00,001,604 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2009/04/06 10:47:09 | 00,000,000 | —D | C] – C:\Program Files\QuickTime
[2009/04/06 10:45:46 | 00,000,000 | -HSD | C] – C:\Config.Msi
[2009/04/06 07:38:27 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\eoxvujyk.dll
[2009/04/06 07:35:27 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\goahrsor.dll
[2009/04/05 18:12:00 | 00,499,200 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Main\Desktop\OTListIt2.exe
[2009/04/05 16:21:59 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\wulbicyu.dll
[2009/04/05 16:21:57 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\gehqvkdg.dll
[2009/04/05 04:24:55 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\wnhthpjx.dll
[2009/04/05 04:21:55 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\isalhhpy.dll
[2009/04/04 12:10:50 | 00,000,095 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/04/04 11:18:47 | 00,000,933 | —- | C] () – C:\Documents and Settings\Main\Desktop\Spybot - Search & Destroy.lnk
[2009/04/04 11:18:38 | 00,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2009/04/04 11:18:38 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/04/04 11:18:37 | 00,001,734 | —- | C] () – C:\Documents and Settings\Main\Desktop\HijackThis.lnk
[2009/04/04 10:32:09 | 00,000,330 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/04/04 10:28:51 | 00,000,000 | —D | C] – C:\Program Files\Windows Defender
[2009/04/04 09:27:33 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\wacouvlb.dll
[2009/04/04 09:24:30 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\yblhijmh.dll
[2009/04/03 20:05:25 | 00,000,000 | —D | C] – C:\Program Files\RegistryFix7
[2009/04/03 11:14:56 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\devbvvww.dll
[2009/04/03 11:11:56 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\wagymaby.dll
[2009/04/02 23:11:56 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\hpcvuxfm.dll
[2009/04/02 11:12:47 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\mvgnwgfr.dll
[2009/04/02 11:12:46 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ymaplkre.dll
[2009/04/01 23:15:44 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\hopeycbu.dll
[2009/04/01 23:12:45 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\yuskhwwb.dll
[2009/04/01 11:14:55 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\gaaoxvld.dll
[2009/04/01 11:11:56 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\tbsswljo.dll
[2009/03/31 15:50:57 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\fqefrwpx.dll
[2009/03/30 23:34:50 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\njtynmgo.dll
[2009/03/30 23:31:51 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\vxgmytmh.dll
[2009/03/29 11:55:07 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\luyejngb.dll
[2009/03/28 10:10:10 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\bnescwdu.dll
[2009/03/28 10:05:26 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ltscijqs.dll
[2009/03/27 06:41:51 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\lflxtcpd.dll
[2009/03/27 06:38:52 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\huqngxqh.dll
[2009/03/26 18:41:54 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\qqfjqodl.dll
[2009/03/26 18:41:53 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\wayfwmay.dll
[2009/03/26 06:44:51 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\mdqjiqxh.dll
[2009/03/26 06:41:51 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\xgkrwbqm.dll
[2009/03/25 18:28:36 | 00,000,000 | —D | C] – C:\Documents and Settings\Main\Desktop\sharnie
[2009/03/25 18:26:00 | 00,000,000 | —D | C] – C:\Documents and Settings\Main\My Documents\sharnie
[2009/03/25 11:23:25 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ejwkxavh.dll
[2009/03/25 11:20:55 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\cqfhvcdr.dll
[2009/03/24 16:26:21 | 00,100,642 | —- | C] () – C:\Documents and Settings\Main\My Documents\m2e.pdf
[2009/03/24 16:24:31 | 00,100,642 | —- | C] () – C:\Documents and Settings\Main\My Documents\m2e - GE Request.pdf
[2009/03/24 11:44:45 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\byeqdfog.dll
[2009/03/23 21:41:45 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ssswdpmu.dll
[2009/03/23 21:38:45 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\wygowcfk.dll
[2009/03/23 09:42:43 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\dfxwxlvb.dll
[2009/03/23 09:39:43 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\baisxvxh.dll
[2009/03/22 21:42:43 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\qcbwauql.dll
[2009/03/22 20:09:42 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\fopyofuy.dll
[2009/03/21 07:30:41 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\hkbfkvct.dll
[2009/03/20 19:30:26 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\tohcrtxd.dll
[2009/03/20 19:21:03 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\vhjdfjee.dll
[2009/03/19 21:34:15 | 00,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2009/03/19 21:09:17 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2009/03/19 21:08:50 | 00,055,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\fssfltr_tdi.sys
[2009/03/19 21:04:28 | 00,000,000 | R-SD | C] – C:\WINDOWS\assembly
[2009/03/19 20:58:21 | 00,000,000 | —D | C] – C:\WINDOWS\Microsoft.NET
[2009/03/19 20:50:11 | 00,000,000 | —D | C] – C:\Program Files\Microsoft
[2009/03/19 20:49:34 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\microsoft
[2009/03/19 20:48:40 | 00,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2009/03/19 20:26:44 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\sygvscyp.dll
[2009/03/19 20:23:46 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\wwxftwfi.dll
[2009/03/19 19:47:53 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2009/03/19 08:23:42 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\tefgcmkq.dll
[2009/03/18 15:45:16 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\xbjcprbj.dll
[2009/03/18 03:45:14 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\rxvaummx.dll
[2009/03/17 15:43:09 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\ytfueqjp.dll
[2009/03/17 15:43:07 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\yfvhwahk.dll
[2009/03/16 07:42:41 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ifqdwtid.dll
[2009/03/16 00:12:46 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\ambkokqe.dll
[2009/03/15 12:35:52 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\fqggapua.dll
[2009/03/15 12:12:37 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\tkkqdbja.dll
[2009/03/14 23:16:26 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\dnddfyao.dll
[2009/03/14 23:09:35 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\xraejfbq.dll
[2009/03/14 11:12:35 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\jgvvjvcy.dll
[2009/03/14 11:09:40 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\strsfxsr.dll
[2009/03/14 08:42:20 | 02,530,850 | —- | C] () – C:\Documents and Settings\Main\My Documents\2009Catalogue.pdf
[2009/03/13 22:07:43 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\yfmwjvpj.dll
[2009/03/13 22:07:41 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\msumncjk.dll
[2009/03/13 22:05:50 | 00,016,384 | —- | C] () – C:\WINDOWS\DCEBoot.exe
[2009/03/13 10:07:24 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\pjgvvnbj.dll
[2009/03/13 10:07:23 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\sohyhmso.dll
[2009/03/12 20:04:22 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\dfdqqodd.dll
[2009/03/12 20:01:22 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\phreelqa.dll
[2009/03/12 01:05:49 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\qtflxbfk.dll
[2009/03/12 01:02:49 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\xffecacc.dll
[2009/03/11 13:02:51 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\lrkriggo.dll
[2009/03/11 13:02:49 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\blvbxadn.dll
[2009/03/10 23:35:51 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\ewudiymt.dll
[2009/03/10 23:35:50 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ovkqqmpd.dll
[2009/03/10 11:35:49 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\uflaeoww.dll
[2009/03/10 10:08:50 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\unxrcrrl.dll
[2009/03/09 11:35:04 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\oukovvqk.dll
[2009/03/09 11:35:02 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\qnsfidhp.dll
[2009/03/08 21:29:06 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\bgwfuwgk.dll
[2009/03/08 21:29:04 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\tnutglap.dll
[2009/03/08 09:32:02 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\vwkgxavx.dll
[2009/03/07 18:20:03 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\ndnkostt.dll
[2009/03/07 03:08:18 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\ncsutuxx.dll
[2009/03/07 03:08:15 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\cslvwuva.dll
[2009/03/06 11:58:55 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\oxyimmgj.dll
[2009/03/03 22:00:47 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\hafntoso.dll
[2009/03/03 21:57:47 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\xhepesrq.dll
[2009/03/02 21:56:20 | 00,005,749 | —- | C] () – C:\WINDOWS\System32\jhntqtxt.dll
[2009/03/02 21:56:17 | 00,005,745 | —- | C] () – C:\WINDOWS\System32\hpsbtymx.dll
[2009/03/02 21:53:31 | 00,000,026 | —- | C] () – C:\WINDOWS\dksav1.ini
[2009/03/02 21:52:07 | 00,000,018 | —- | C] () – C:\WINDOWS\cnc.ini
[2009/02/26 08:16:19 | 00,063,488 | —- | C] () – C:\WINDOWS\xobglu16.dll
[2009/02/26 08:16:19 | 00,026,046 | —- | C] () – C:\WINDOWS\xobglu32.dll
[2009/02/11 18:25:13 | 00,000,024 | —- | C] () – C:\WINDOWS\Woabc123.ini
[2009/02/11 18:23:16 | 00,000,108 | —- | C] () – C:\WINDOWS\ABC.ini
[2009/02/11 18:19:39 | 00,000,114 | —- | C] () – C:\WINDOWS\CIF.ini
[2009/02/11 18:14:01 | 00,000,087 | —- | C] () – C:\WINDOWS\KPP.INI
[2009/02/11 18:08:22 | 00,000,082 | —- | C] () – C:\WINDOWS\E1000g.ini
[2009/02/11 17:55:01 | 00,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2009/02/11 17:54:44 | 00,000,095 | —- | C] () – C:\WINDOWS\101kgv1.ini
[2009/02/09 19:21:28 | 00,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2008/12/16 14:11:00 | 00,000,026 | —- | C] () – C:\WINDOWS\WAR2R.INI
[2008/10/09 13:26:57 | 00,000,261 | —- | C] () – C:\WINDOWS\LEXSTAT.INI
[2008/08/25 16:41:01 | 00,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/08/20 18:50:28 | 01,355,899 | —- | C] () – C:\WINDOWS\UnInstallNetCommADSL.dll
[2008/08/20 09:37:55 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/08/20 09:09:28 | 00,147,456 | R— | C] () – C:\WINDOWS\System32\igfxCoIn_v4864.dll
[2008/08/19 00:49:04 | 00,000,000 | —- | C] () – C:\WINDOWS\control.ini
[2008/08/19 00:47:37 | 00,000,002 | —- | C] () – C:\WINDOWS\System32\desktop.ini
[2008/08/19 00:47:37 | 00,000,002 | —- | C] () – C:\WINDOWS\desktop.ini
[2008/08/19 00:47:18 | 00,000,037 | —- | C] () – C:\WINDOWS\vbaddin.ini
[2008/08/19 00:47:18 | 00,000,036 | —- | C] () – C:\WINDOWS\vb.ini
[2008/08/19 00:46:43 | 00,013,223 | —- | C] () – C:\WINDOWS\System32\tslabels.ini
[2008/08/19 00:46:43 | 00,001,931 | —- | C] () – C:\WINDOWS\System32\msdtcprf.ini
[2008/08/19 00:37:09 | 00,498,742 | —- | C] () – C:\WINDOWS\System32\dxmasf.dll
[2008/08/19 00:37:09 | 00,004,126 | —- | C] () – C:\WINDOWS\System32\msdxmlc.dll
[2008/08/19 00:37:09 | 00,000,576 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2008/08/19 00:37:03 | 00,053,478 | —- | C] () – C:\WINDOWS\System32\tcpmon.ini
[2008/08/19 00:37:03 | 00,015,360 | —- | C] () – C:\WINDOWS\System32\tsd32.dll
[2008/08/19 00:37:03 | 00,013,312 | —- | C] () – C:\WINDOWS\System32\win87em.dll
[2008/08/19 00:37:03 | 00,000,541 | —- | C] () – C:\WINDOWS\win.ini
[2008/08/19 00:37:03 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2008/08/19 00:37:01 | 00,270,848 | —- | C] () – C:\WINDOWS\System32\sbe.dll
[2008/08/19 00:37:01 | 00,012,082 | —- | C] () – C:\WINDOWS\System32\rsvp.ini
[2008/08/19 00:37:00 | 01,288,192 | —- | C] () – C:\WINDOWS\System32\quartz.dll
[2008/08/19 00:37:00 | 00,733,696 | —- | C] () – C:\WINDOWS\System32\qedwipes.dll
[2008/08/19 00:37:00 | 00,562,176 | —- | C] () – C:\WINDOWS\System32\qedit.dll
[2008/08/19 00:37:00 | 00,386,048 | —- | C] () – C:\WINDOWS\System32\qdvd.dll
[2008/08/19 00:37:00 | 00,279,040 | —- | C] () – C:\WINDOWS\System32\qdv.dll
[2008/08/19 00:37:00 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\qcap.dll
[2008/08/19 00:37:00 | 00,006,877 | —- | C] () – C:\WINDOWS\System32\pschdprf.ini
[2008/08/19 00:37:00 | 00,003,458 | —- | C] () – C:\WINDOWS\System32\rasctrs.ini
[2008/08/19 00:37:00 | 00,002,891 | —- | C] () – C:\WINDOWS\System32\perfci.ini
[2008/08/19 00:37:00 | 00,002,732 | —- | C] () – C:\WINDOWS\System32\perfwci.ini
[2008/08/19 00:37:00 | 00,001,152 | —- | C] () – C:\WINDOWS\System32\perffilt.ini
[2008/08/19 00:37:00 | 00,000,343 | —- | C] () – C:\WINDOWS\System32\prodspec.ini
[2008/08/19 00:36:59 | 00,035,648 | —- | C] () – C:\WINDOWS\System32\ntio411.sys
[2008/08/19 00:36:59 | 00,035,424 | —- | C] () – C:\WINDOWS\System32\ntio412.sys
[2008/08/19 00:36:59 | 00,034,560 | —- | C] () – C:\WINDOWS\System32\ntio804.sys
[2008/08/19 00:36:59 | 00,034,560 | —- | C] () – C:\WINDOWS\System32\ntio404.sys
[2008/08/19 00:36:59 | 00,033,840 | —- | C] () – C:\WINDOWS\System32\ntio.sys
[2008/08/19 00:36:59 | 00,029,370 | —- | C] () – C:\WINDOWS\System32\ntdos411.sys
[2008/08/19 00:36:59 | 00,029,274 | —- | C] () – C:\WINDOWS\System32\ntdos412.sys
[2008/08/19 00:36:59 | 00,029,146 | —- | C] () – C:\WINDOWS\System32\ntdos804.sys
[2008/08/19 00:36:59 | 00,029,146 | —- | C] () – C:\WINDOWS\System32\ntdos404.sys
[2008/08/19 00:36:59 | 00,027,866 | —- | C] () – C:\WINDOWS\System32\ntdos.sys
[2008/08/19 00:36:58 | 00,094,282 | —- | C] () – C:\WINDOWS\System32\msencode.dll
[2008/08/19 00:36:58 | 00,014,336 | —- | C] () – C:\WINDOWS\System32\msdmo.dll
[2008/08/19 00:36:58 | 00,001,405 | —- | C] () – C:\WINDOWS\msdfmap.ini
[2008/08/19 00:36:57 | 00,035,328 | —- | C] () – C:\WINDOWS\System32\mciqtz32.dll
[2008/08/19 00:36:56 | 00,199,168 | —- | C] () – C:\WINDOWS\System32\ir32_32.dll
[2008/08/19 00:36:56 | 00,042,809 | —- | C] () – C:\WINDOWS\System32\key01.sys
[2008/08/19 00:36:56 | 00,042,537 | —- | C] () – C:\WINDOWS\System32\keyboard.sys
[2008/08/19 00:36:55 | 01,015,477 | —- | C] () – C:\WINDOWS\System32\esentprf.ini
[2008/08/19 00:36:55 | 00,186,880 | —- | C] () – C:\WINDOWS\System32\encdec.dll
[2008/08/19 00:36:55 | 00,004,768 | —- | C] () – C:\WINDOWS\System32\himem.sys
[2008/08/19 00:36:53 | 00,059,904 | —- | C] () – C:\WINDOWS\System32\devenum.dll
[2008/08/19 00:36:52 | 00,355,112 | —- | C] () – C:\WINDOWS\System32\msjetoledb40.dll
[2008/08/19 00:36:52 | 00,252,928 | —- | C] () – C:\WINDOWS\System32\compatui.dll
[2008/08/19 00:36:52 | 00,070,656 | —- | C] () – C:\WINDOWS\System32\amstream.dll
[2008/08/19 00:36:52 | 00,027,097 | —- | C] () – C:\WINDOWS\System32\country.sys
[2008/08/19 00:36:52 | 00,009,029 | —- | C] () – C:\WINDOWS\System32\ansi.sys
[2008/08/18 17:43:21 | 00,458,164 | —- | C] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2008/08/18 17:43:20 | 00,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2001/08/18 08:36:28 | 00,157,696 | —- | C] () – C:\WINDOWS\System32\paqsp.dll

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/04/07 19:13:13 | 01,789,740 | —- | M] () – C:\Documents and Settings\Main\My Documents\Bedroom Autumn 09.pdf
[2009/04/07 19:05:19 | 05,123,425 | —- | M] () – C:\Documents and Settings\Main\My Documents\cat-7-2008.pdf
[2009/04/07 18:37:02 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/04/07 18:34:05 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/07 18:33:55 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/04/07 14:31:47 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/07 06:48:48 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\frduwlck.dll
[2009/04/07 06:48:46 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\chofsldx.dll
[2009/04/06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/06 10:51:09 | 00,001,804 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/04/06 10:47:46 | 00,001,604 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2009/04/06 09:48:02 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/04/06 07:38:27 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\eoxvujyk.dll
[2009/04/06 07:35:27 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\goahrsor.dll
[2009/04/06 06:28:58 | 00,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/04/05 18:12:03 | 00,499,200 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Main\Desktop\OTListIt2.exe
[2009/04/05 18:10:46 | 00,000,728 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/04/05 16:21:59 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\wulbicyu.dll
[2009/04/05 16:21:57 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\gehqvkdg.dll
[2009/04/05 11:11:23 | 00,458,164 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/05 11:11:23 | 00,392,958 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/04/05 11:11:23 | 00,059,148 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/04/05 04:24:55 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\wnhthpjx.dll
[2009/04/05 04:21:55 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\isalhhpy.dll
[2009/04/04 12:10:50 | 00,000,095 | —- | M] () – C:\WINDOWS\wininit.ini
[2009/04/04 11:18:48 | 00,000,933 | —- | M] () – C:\Documents and Settings\Main\Desktop\Spybot - Search & Destroy.lnk
[2009/04/04 11:18:37 | 00,001,734 | —- | M] () – C:\Documents and Settings\Main\Desktop\HijackThis.lnk
[2009/04/04 09:27:33 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\wacouvlb.dll
[2009/04/04 09:24:30 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\yblhijmh.dll
[2009/04/03 12:04:06 | 00,001,167 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.bak
[2009/04/03 11:14:56 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\devbvvww.dll
[2009/04/03 11:11:56 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\wagymaby.dll
[2009/04/02 23:11:56 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\hpcvuxfm.dll
[2009/04/02 11:12:47 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\mvgnwgfr.dll
[2009/04/02 11:12:46 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\ymaplkre.dll
[2009/04/01 23:18:47 | 00,001,108 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.msn
[2009/04/01 23:15:44 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\hopeycbu.dll
[2009/04/01 23:12:45 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\yuskhwwb.dll
[2009/04/01 16:02:42 | 00,016,384 | —- | M] () – C:\WINDOWS\DCEBoot.exe
[2009/04/01 11:14:55 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\gaaoxvld.dll
[2009/04/01 11:11:56 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\tbsswljo.dll
[2009/03/31 15:50:57 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\fqefrwpx.dll
[2009/03/31 15:50:28 | 00,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/03/30 23:34:50 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\njtynmgo.dll
[2009/03/30 23:31:51 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\vxgmytmh.dll
[2009/03/29 11:55:07 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\luyejngb.dll
[2009/03/28 10:10:10 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\bnescwdu.dll
[2009/03/28 10:05:26 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\ltscijqs.dll
[2009/03/27 13:55:26 | 00,000,668 | —- | M] () – C:\Documents and Settings\Main\Application Data\vso_ts_preview.xml
[2009/03/27 06:41:51 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\lflxtcpd.dll
[2009/03/27 06:38:52 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\huqngxqh.dll
[2009/03/26 18:41:54 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\qqfjqodl.dll
[2009/03/26 18:41:53 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\wayfwmay.dll
[2009/03/26 06:44:51 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\mdqjiqxh.dll
[2009/03/26 06:41:51 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\xgkrwbqm.dll
[2009/03/25 18:25:38 | 00,054,272 | -HS- | M] () – C:\Documents and Settings\Main\My Documents\Thumbs.db
[2009/03/25 11:23:25 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\ejwkxavh.dll
[2009/03/25 11:20:55 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\cqfhvcdr.dll
[2009/03/24 16:26:21 | 00,100,642 | —- | M] () – C:\Documents and Settings\Main\My Documents\m2e.pdf
[2009/03/24 16:24:31 | 00,100,642 | —- | M] () – C:\Documents and Settings\Main\My Documents\m2e - GE Request.pdf
[2009/03/24 11:44:45 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\byeqdfog.dll
[2009/03/23 21:41:45 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\ssswdpmu.dll
[2009/03/23 21:38:45 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\wygowcfk.dll
[2009/03/23 09:42:43 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\dfxwxlvb.dll
[2009/03/23 09:39:43 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\baisxvxh.dll
[2009/03/22 21:42:43 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\qcbwauql.dll
[2009/03/22 20:09:42 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\fopyofuy.dll
[2009/03/21 07:30:41 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\hkbfkvct.dll
[2009/03/20 19:30:26 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\tohcrtxd.dll
[2009/03/20 19:21:03 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\vhjdfjee.dll
[2009/03/20 19:14:29 | 00,120,544 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/19 21:11:28 | 00,019,448 | —- | M] () – C:\Documents and Settings\Main\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/03/19 20:51:35 | 00,000,896 | —- | M] () – C:\Documents and Settings\Main\My Documents\My Sharing Folders.lnk
[2009/03/19 20:26:44 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\sygvscyp.dll
[2009/03/19 20:23:46 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\wwxftwfi.dll
[2009/03/19 08:23:42 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\tefgcmkq.dll
[2009/03/18 15:45:16 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\xbjcprbj.dll
[2009/03/18 03:45:14 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\rxvaummx.dll
[2009/03/17 15:43:09 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\ytfueqjp.dll
[2009/03/17 15:43:07 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\yfvhwahk.dll
[2009/03/16 07:42:41 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\ifqdwtid.dll
[2009/03/16 00:12:46 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\ambkokqe.dll
[2009/03/15 12:35:52 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\fqggapua.dll
[2009/03/15 12:12:37 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\tkkqdbja.dll
[2009/03/14 23:16:26 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\dnddfyao.dll
[2009/03/14 23:09:35 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\xraejfbq.dll
[2009/03/14 11:12:35 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\jgvvjvcy.dll
[2009/03/14 11:09:40 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\strsfxsr.dll
[2009/03/14 08:43:40 | 02,530,850 | —- | M] () – C:\Documents and Settings\Main\My Documents\2009Catalogue.pdf
[2009/03/13 22:07:43 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\yfmwjvpj.dll
[2009/03/13 22:07:41 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\msumncjk.dll
[2009/03/13 10:07:24 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\pjgvvnbj.dll
[2009/03/13 10:07:23 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\sohyhmso.dll
[2009/03/12 20:04:22 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\dfdqqodd.dll
[2009/03/12 20:01:22 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\phreelqa.dll
[2009/03/12 01:05:49 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\qtflxbfk.dll
[2009/03/12 01:02:49 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\xffecacc.dll
[2009/03/11 13:02:51 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\lrkriggo.dll
[2009/03/11 13:02:49 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\blvbxadn.dll
[2009/03/10 23:35:51 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\ewudiymt.dll
[2009/03/10 23:35:50 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\ovkqqmpd.dll
[2009/03/10 11:35:49 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\uflaeoww.dll
[2009/03/10 10:08:50 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\unxrcrrl.dll
[2009/03/09 13:16:31 | 00,018,944 | —- | M] () – C:\Documents and Settings\Main\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/09 11:35:04 | 00,005,745 | —- | M] () – C:\WINDOWS\System32\oukovvqk.dll
[2009/03/09 11:35:02 | 00,005,749 | —- | M] () – C:\WINDOWS\System32\qnsfidhp.dll
< End of report >



MBAM Log

Malwarebytes' Anti-Malware 1.36
Database version: 1946
Windows 5.1.2600 Service Pack 3

7/04/2009 2:36:37 PM
mbam-log-2009-04-07 (14-36-37).txt

Scan type: Quick Scan
Objects scanned: 69427
Time elapsed: 1 minute(s), 59 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 10
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 22

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\fccdCsst.dll (Trojan.Vundo.H) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cab1bf85-d8d1-4090-8870-47cd2bd4199e} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{cab1bf85-d8d1-4090-8870-47cd2bd4199e} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{cab1bf85-d8d1-4090-8870-47cd2bd4199e} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\cs41275 (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\fccdcsst -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\fccdcsst -> Delete on reboot.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\fccdCsst.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\tssCdccf.ini (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\tssCdccf.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mlJAtULB.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mlJYqQki.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\awtqrpoO.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fccdATJY.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hgGvvtQG.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hgGxYPFw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ljJCtuSi.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pmnkHAtR.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dhqgul.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ddcBRkLd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\byXPIxyA.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cauyxwrb.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\aoorbxep.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rvuljqve.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nnnoNeEu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ddcAqNgF.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ljjtoxne.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\RECYCLER\ADAPT_Installer.exe (Heuristics.Malware) -> Quarantined and deleted successfully.




Kaspersky report

——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Tuesday, April 7, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Tuesday, April 07, 2009 08:08:41
Records in database: 2020374
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\

Scan statistics:
Files scanned: 110241
Threat name: 6
Infected objects: 13
Suspicious objects: 0
Duration of the scan: 01:34:09


File name / Threat name / Threats count
C:\Documents and Settings\Main\Desktop\sam\you can have whatever want ti (best quality).mp3 Infected: Trojan-Downloader.WMA.GetCodec.u 1
C:\Documents and Settings\Main\My Documents\LimeWire\Incomplete\T-5745425-Kasey Chambers and Paul Kelly - I still Pray.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Documents and Settings\Main\My Documents\LimeWire\Saved\acid eyeliner - greatest hits.wma Infected: Trojan-Downloader.WMA.Wimad.n 1
C:\Documents and Settings\Main\My Documents\LimeWire\Saved\ill come for you nickelback.mp3 Infected: Trojan-Downloader.WMA.GetCodec.aa 1
C:\Documents and Settings\Main\My Documents\LimeWire\Saved\one day at time merle haggard 192kb.mp3 Infected: Trojan-Downloader.WMA.GetCodec.f 1
C:\Documents and Settings\Main\My Documents\LimeWire\Saved\summer lovin grease lightning .wma Infected: Trojan-Downloader.WMA.Wimad.n 1
C:\Documents and Settings\Main\My Documents\LimeWire\Saved\you can have whatever want ti (best quality).mp3 Infected: Trojan-Downloader.WMA.GetCodec.u 1
C:\Documents and Settings\Main\My Documents\My Games\Donkey.KongCollection\Donkey.KongCollection\Donkey Kong Island 2\dk.exe Infected: Trojan-Downloader.Win32.Injecter.cjz 1
C:\Documents and Settings\Main\My Documents\My Games\Donkey.KongCollection\Donkey.KongCollection\Donkey Kong Jr\DKongJr.exe Infected: Trojan-Downloader.Win32.Injecter.cjz 1
C:\Documents and Settings\Main\My Documents\My Games\Donkey.KongCollection\Donkey.KongCollection\Donkey.Kong\VirtuaNES.exe Infected: Trojan-Downloader.Win32.Injecter.cjz 1
C:\Documents and Settings\Main\My Documents\My Games\Donkey.KongCollection.rar Infected: Trojan-Downloader.Win32.Injecter.cjz 3

The selected area was scanned.
hello again, I dont understand most of this post, but i see just above there are file names that are on my computer, is that meaning these files are infected with a virus and should i delete these manually? thanks
Hi yes those files are infected. please don't start deleting anything on your own. That's what I'm here for. Give me sometime to analyze the logs and I will post back with further instructions Don't worry, we'll get this computer cleaned up…. CB
Hi,

Please do the following:

Open HijackThis.
Click Do a System Scan Only.
Put a checkmark in the box on the left side of these entries only: (If they are still there)


O2 - BHO: (no name) - {209ba86b-cd8c-4393-951e-b172ffbca90c} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {5FEE60AE-DC68-4044-8B05-C436A21D6513} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {C7E7F703-357D-4C46-BD17-C2E86E826EBB} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {CAB1BF85-D8D1-4090-8870-47CD2BD4199E} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {EAC84402-1B6F-46C2-AB0F-D4B9AA17E552} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {F6D66EE9-88BE-415C-8DD4-B8C7FDCF484A} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - Reg Error: Key error. File not found

Close ALL windows and browsers except HijackThis and click "Fix checked"
Exit HijackThis


Next

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Do not copy the word "code" - note that the fix starts with the faint colon in front of the word :Processes

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\Documents and Settings\Main\Desktop\sam\you can have whatever want ti (best quality).mp3
    C:\Documents and Settings\Main\My Documents\LimeWire\Incomplete\T-5745425-Kasey Chambers and Paul Kelly - I still Pray.mp3 
    C:\Documents and Settings\Main\My Documents\LimeWire\Saved\acid eyeliner - greatest hits.wma
    C:\Documents and Settings\Main\My Documents\LimeWire\Saved\ill come for you nickelback.mp3 
    C:\Documents and Settings\Main\My Documents\LimeWire\Saved\one day at time merle haggard 192kb.mp3 
    C:\Documents and Settings\Main\My Documents\LimeWire\Saved\summer lovin grease lightning .wma
    C:\Documents and Settings\Main\My Documents\LimeWire\Saved\you can have whatever want ti (best quality).mp3 
    C:\Documents and Settings\Main\My Documents\My Games\Donkey.KongCollection\Donkey.KongCollection\Donkey Kong Island 2\dk.exe 
    C:\Documents and Settings\Main\My Documents\My Games\Donkey.KongCollection\Donkey.KongCollection\Donkey Kong Jr\DKongJr.exe 
    C:\Documents and Settings\Main\My Documents\My Games\Donkey.KongCollection\Donkey.KongCollection\Donkey.Kong\VirtuaNES.exe 
    C:\Documents and Settings\Main\My Documents\My Games\Donkey.KongCollection.rar 
    
    :Commands
    [Purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

*Make sure you allow OTMOVEIT3 to reboot your computer when prompted.



NEXT

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
Double click on ComboFix.exe & follow the prompts.

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

  • Notes:
  • Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
  • CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

In
In your next reply please include
  • OTMoveIt3 log
  • combo fix log
  • Fresh HJT log

Also, please describe how your computer is running now
wow my computer already seems to be running alot better, it use to go very slow during start up and now doesnt seem as bad at all, and i havnt noticed any pop ups today but havnt been on the computer much either… thanks and here are the lists…


OTMoveIt3 log

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
File/Folder C:\Documents and Settings\Main\Desktop\sam\you can have whatever want ti (best quality).mp3 not found.
File/Folder C:\Documents and Settings\Main\My Documents\LimeWire\Incomplete\T-5745425-Kasey Chambers and Paul Kelly - I still Pray.mp3 not found.
File/Folder C:\Documents and Settings\Main\My Documents\LimeWire\Saved\acid eyeliner - greatest hits.wma not found.
File/Folder C:\Documents and Settings\Main\My Documents\LimeWire\Saved\ill come for you nickelback.mp3 not found.
File/Folder C:\Documents and Settings\Main\My Documents\LimeWire\Saved\one day at time merle haggard 192kb.mp3 not found.
File/Folder C:\Documents and Settings\Main\My Documents\LimeWire\Saved\summer lovin grease lightning .wma not found.
File/Folder C:\Documents and Settings\Main\My Documents\LimeWire\Saved\you can have whatever want ti (best quality).mp3 not found.
File/Folder C:\Documents and Settings\Main\My Documents\My Games\Donkey.KongCollection\Donkey.KongCollection\Donkey Kong Island 2\dk.exe not found.
File/Folder C:\Documents and Settings\Main\My Documents\My Games\Donkey.KongCollection\Donkey.KongCollection\Donkey Kong Jr\DKongJr.exe not found.
File/Folder C:\Documents and Settings\Main\My Documents\My Games\Donkey.KongCollection\Donkey.KongCollection\Donkey.Kong\VirtuaNES.exe not found.
File/Folder C:\Documents and Settings\Main\My Documents\My Games\Donkey.KongCollection.rar not found.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Main\LOCALS~1\Temp\~DF3862.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Main\LOCALS~1\Temp\~DF3873.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\Main\Local Settings\Temporary Internet Files\Content.IE5\ZH8S3ECB\plz_help_pop_ups_www_url_adtrgt_com_fake_anti_spyware_ads_will_t101693[1].h
tm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Main\Local Settings\Temporary Internet Files\Content.IE5\CZH2MITK\iframe[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Main\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Main\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_2d4.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.10.0 log created on 04082009_093415



combo fix log

ComboFix 09-04-04.01 - Main 2009-04-08 9:59:22.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2037.1619 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Trend Micro Internet Security *On-access scanning disabled* (Updated)
FW: Trend Micro Personal Firewall *disabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Main\Application Data\inst.exe

.
((((((((((((((((((((((((( Files Created from 2009-03-07 to 2009-04-07 )))))))))))))))))))))))))))))))
.

2009-04-08 09:34 . 2009-04-08 09:34 d——– C:\_OTMoveIt
2009-04-07 14:31 . 2009-04-07 14:31 d——– c:\program files\Malwarebytes' Anti-Malware
2009-04-07 14:31 . 2009-04-07 14:31 d——– c:\documents and settings\Main\Application Data\Malwarebytes
2009-04-07 14:31 . 2009-04-07 14:31 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-07 14:31 . 2009-04-06 15:32 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-07 14:31 . 2009-04-06 15:32 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-04-07 13:55 . 2009-04-07 13:55 d——– C:\_OTListIt
2009-04-07 06:48 . 2009-04-07 06:48 5,749 –a—— c:\windows\system32\frduwlck.dll
2009-04-07 06:48 . 2009-04-07 06:48 5,745 –a—— c:\windows\system32\chofsldx.dll
2009-04-06 10:50 . 2009-04-06 10:51 d——– c:\program files\iTunes
2009-04-06 10:50 . 2009-04-06 10:50 d——– c:\program files\iPod
2009-04-06 10:50 . 2009-04-06 10:51 d——– c:\documents and settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-04-06 10:47 . 2009-04-06 10:48 d——– c:\program files\QuickTime
2009-04-06 07:38 . 2009-04-06 07:38 5,745 –a—— c:\windows\system32\eoxvujyk.dll
2009-04-06 07:35 . 2009-04-06 07:35 5,749 –a—— c:\windows\system32\goahrsor.dll
2009-04-05 16:21 . 2009-04-05 16:21 5,749 –a—— c:\windows\system32\wulbicyu.dll
2009-04-05 16:21 . 2009-04-05 16:21 5,745 –a—— c:\windows\system32\gehqvkdg.dll
2009-04-05 04:24 . 2009-04-05 04:24 5,749 –a—— c:\windows\system32\wnhthpjx.dll
2009-04-05 04:21 . 2009-04-05 04:21 5,745 –a—— c:\windows\system32\isalhhpy.dll
2009-04-04 12:10 . 2009-04-04 12:10 95 –a—— c:\windows\wininit.ini
2009-04-04 11:18 . 2009-04-04 11:21 d——– c:\program files\Spybot - Search & Destroy
2009-04-04 11:18 . 2009-04-04 11:21 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-04 10:28 . 2009-04-04 10:28 d——– c:\program files\Windows Defender
2009-04-04 09:27 . 2009-04-04 09:27 5,745 –a—— c:\windows\system32\wacouvlb.dll
2009-04-04 09:24 . 2009-04-04 09:24 5,749 –a—— c:\windows\system32\yblhijmh.dll
2009-04-03 20:05 . 2009-04-04 12:52 d——– c:\program files\RegistryFix7
2009-04-03 11:14 . 2009-04-03 11:14 5,749 –a—— c:\windows\system32\devbvvww.dll
2009-04-03 11:11 . 2009-04-03 11:11 5,745 –a—— c:\windows\system32\wagymaby.dll
2009-04-02 23:11 . 2009-04-02 23:11 5,745 –a—— c:\windows\system32\hpcvuxfm.dll
2009-04-02 11:12 . 2009-04-02 11:12 5,749 –a—— c:\windows\system32\ymaplkre.dll
2009-04-02 11:12 . 2009-04-02 11:12 5,745 –a—— c:\windows\system32\mvgnwgfr.dll
2009-04-01 23:15 . 2009-04-01 23:15 5,749 –a—— c:\windows\system32\hopeycbu.dll
2009-04-01 23:12 . 2009-04-01 23:12 5,745 –a—— c:\windows\system32\yuskhwwb.dll
2009-04-01 11:14 . 2009-04-01 11:14 5,745 –a—— c:\windows\system32\gaaoxvld.dll
2009-04-01 11:11 . 2009-04-01 11:11 5,749 –a—— c:\windows\system32\tbsswljo.dll
2009-03-31 15:50 . 2009-03-31 15:50 5,745 –a—— c:\windows\system32\fqefrwpx.dll
2009-03-30 23:34 . 2009-03-30 23:34 5,749 –a—— c:\windows\system32\njtynmgo.dll
2009-03-30 23:31 . 2009-03-30 23:31 5,745 –a—— c:\windows\system32\vxgmytmh.dll
2009-03-29 11:55 . 2009-03-29 11:55 5,745 –a—— c:\windows\system32\luyejngb.dll
2009-03-28 10:10 . 2009-03-28 10:10 5,745 –a—— c:\windows\system32\bnescwdu.dll
2009-03-28 10:05 . 2009-03-28 10:05 5,749 –a—— c:\windows\system32\ltscijqs.dll
2009-03-27 06:41 . 2009-03-27 06:41 5,749 –a—— c:\windows\system32\lflxtcpd.dll
2009-03-27 06:38 . 2009-03-27 06:38 5,745 –a—— c:\windows\system32\huqngxqh.dll
2009-03-26 18:41 . 2009-03-26 18:41 5,749 –a—— c:\windows\system32\qqfjqodl.dll
2009-03-26 18:41 . 2009-03-26 18:41 5,745 –a—— c:\windows\system32\wayfwmay.dll
2009-03-26 06:44 . 2009-03-26 06:44 5,749 –a—— c:\windows\system32\mdqjiqxh.dll
2009-03-26 06:41 . 2009-03-26 06:41 5,745 –a—— c:\windows\system32\xgkrwbqm.dll
2009-03-25 11:23 . 2009-03-25 11:23 5,749 –a—— c:\windows\system32\ejwkxavh.dll
2009-03-25 11:20 . 2009-03-25 11:20 5,745 –a—— c:\windows\system32\cqfhvcdr.dll
2009-03-24 15:54 . 2009-04-07 09:14 d——– c:\documents and settings\Other\Tracing
2009-03-24 11:44 . 2009-03-24 11:44 5,749 –a—— c:\windows\system32\byeqdfog.dll
2009-03-23 21:41 . 2009-03-23 21:41 5,749 –a—— c:\windows\system32\ssswdpmu.dll
2009-03-23 21:38 . 2009-03-23 21:38 5,745 –a—— c:\windows\system32\wygowcfk.dll
2009-03-23 09:42 . 2009-03-23 09:42 5,749 –a—— c:\windows\system32\dfxwxlvb.dll
2009-03-23 09:39 . 2009-03-23 09:39 5,745 –a—— c:\windows\system32\baisxvxh.dll
2009-03-22 21:42 . 2009-03-22 21:42 5,745 –a—— c:\windows\system32\qcbwauql.dll
2009-03-22 20:09 . 2009-03-22 20:09 5,745 –a—— c:\windows\system32\fopyofuy.dll
2009-03-21 07:30 . 2009-03-21 07:30 5,745 –a—— c:\windows\system32\hkbfkvct.dll
2009-03-20 19:30 . 2009-03-20 19:30 5,745 –a—— c:\windows\system32\tohcrtxd.dll
2009-03-20 19:21 . 2009-03-20 19:21 5,749 –a—— c:\windows\system32\vhjdfjee.dll
2009-03-19 21:34 . 2009-03-20 19:14 d——– c:\windows\SxsCaPendDel
2009-03-19 21:12 . 2009-04-08 09:51 d——– c:\documents and settings\Main\Tracing
2009-03-19 21:09 . 2009-03-19 21:09 d——– c:\program files\Microsoft Silverlight
2009-03-19 21:08 . 2009-02-06 17:08 55,152 –a—— c:\windows\system32\drivers\fssfltr_tdi.sys
2009-03-19 20:50 . 2009-03-19 20:50 d——– c:\program files\Microsoft
2009-03-19 20:48 . 2009-03-19 20:48 d——– c:\program files\Windows Live SkyDrive
2009-03-19 20:26 . 2009-03-19 20:26 5,745 –a—— c:\windows\system32\sygvscyp.dll
2009-03-19 20:23 . 2009-03-19 20:23 5,749 –a—— c:\windows\system32\wwxftwfi.dll
2009-03-19 19:47 . 2009-03-19 19:47 d——– c:\program files\Common Files\Windows Live
2009-03-19 08:23 . 2009-03-19 08:23 5,749 –a—— c:\windows\system32\tefgcmkq.dll
2009-03-18 15:45 . 2009-03-18 15:45 5,745 –a—— c:\windows\system32\xbjcprbj.dll
2009-03-18 03:45 . 2009-03-18 03:45 5,745 –a—— c:\windows\system32\rxvaummx.dll
2009-03-17 15:43 . 2009-03-17 15:43 5,749 –a—— c:\windows\system32\yfvhwahk.dll
2009-03-17 15:43 . 2009-03-17 15:43 5,745 –a—— c:\windows\system32\ytfueqjp.dll
2009-03-16 07:42 . 2009-03-16 07:42 5,749 –a—— c:\windows\system32\ifqdwtid.dll
2009-03-16 00:12 . 2009-03-16 00:12 5,745 –a—— c:\windows\system32\ambkokqe.dll
2009-03-15 12:35 . 2009-03-15 12:35 5,749 –a—— c:\windows\system32\fqggapua.dll
2009-03-15 12:12 . 2009-03-15 12:12 5,745 –a—— c:\windows\system32\tkkqdbja.dll
2009-03-14 23:16 . 2009-03-14 23:16 5,749 –a—— c:\windows\system32\dnddfyao.dll
2009-03-14 23:09 . 2009-03-14 23:09 5,745 –a—— c:\windows\system32\xraejfbq.dll
2009-03-14 11:12 . 2009-03-14 11:12 5,745 –a—— c:\windows\system32\jgvvjvcy.dll
2009-03-14 11:09 . 2009-03-14 11:09 5,749 –a—— c:\windows\system32\strsfxsr.dll
2009-03-13 22:07 . 2009-03-13 22:07 5,749 –a—— c:\windows\system32\msumncjk.dll
2009-03-13 22:07 . 2009-03-13 22:07 5,745 –a—— c:\windows\system32\yfmwjvpj.dll
2009-03-13 22:05 . 2009-04-01 16:02 16,384 –a—— c:\windows\DCEBoot.exe
2009-03-13 10:07 . 2009-03-13 10:07 5,749 –a—— c:\windows\system32\pjgvvnbj.dll
2009-03-13 10:07 . 2009-03-13 10:07 5,745 –a—— c:\windows\system32\sohyhmso.dll
2009-03-12 20:04 . 2009-03-12 20:04 5,749 –a—— c:\windows\system32\dfdqqodd.dll
2009-03-12 20:01 . 2009-03-12 20:01 5,745 –a—— c:\windows\system32\phreelqa.dll
2009-03-12 01:05 . 2009-03-12 01:05 5,749 –a—— c:\windows\system32\qtflxbfk.dll
2009-03-12 01:02 . 2009-03-12 01:02 5,745 –a—— c:\windows\system32\xffecacc.dll
2009-03-11 13:02 . 2009-03-11 13:02 5,749 –a—— c:\windows\system32\blvbxadn.dll
2009-03-11 13:02 . 2009-03-11 13:02 5,745 –a—— c:\windows\system32\lrkriggo.dll
2009-03-10 23:35 . 2009-03-10 23:35 5,749 –a—— c:\windows\system32\ovkqqmpd.dll
2009-03-10 23:35 . 2009-03-10 23:35 5,745 –a—— c:\windows\system32\ewudiymt.dll
2009-03-10 11:35 . 2009-03-10 11:35 5,745 –a—— c:\windows\system32\uflaeoww.dll
2009-03-10 10:08 . 2009-03-10 10:08 5,745 –a—— c:\windows\system32\unxrcrrl.dll
2009-03-09 11:35 . 2009-03-09 11:35 5,749 –a—— c:\windows\system32\qnsfidhp.dll
2009-03-09 11:35 . 2009-03-09 11:35 5,745 –a—— c:\windows\system32\oukovvqk.dll
2009-03-08 21:29 . 2009-03-08 21:29 5,749 –a—— c:\windows\system32\bgwfuwgk.dll
2009-03-08 21:29 . 2009-03-08 21:29 5,745 –a—— c:\windows\system32\tnutglap.dll
2009-03-08 12:20 . 2009-03-19 21:28 d——– c:\program files\The Bar
2009-03-08 09:32 . 2009-03-08 09:32 5,749 –a—— c:\windows\system32\vwkgxavx.dll
2009-03-07 18:20 . 2009-03-07 18:20 5,745 –a—— c:\windows\system32\ndnkostt.dll
2009-03-07 03:08 . 2009-03-07 03:08 5,749 –a—— c:\windows\system32\ncsutuxx.dll
2009-03-07 03:08 . 2009-03-07 03:08 5,745 –a—— c:\windows\system32\cslvwuva.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-06 00:50 ——— d—–w c:\program files\Common Files\Apple
2009-04-04 01:18 ——— d—–w c:\program files\Trend Micro
2009-04-04 00:03 ——— d—–w c:\program files\MJ 3.0
2009-04-03 23:46 ——— d—–w c:\program files\Java
2009-03-27 03:55 ——— d—–w c:\documents and settings\Main\Application Data\Vso
2009-03-22 07:03 ——— d—–w c:\documents and settings\Main\Application Data\LimeWire
2009-03-19 11:08 ——— d—–w c:\program files\Windows Live
2009-03-12 23:38 ——— d—–w c:\documents and settings\All Users\Application Data\DVD Shrink
2009-03-10 02:45 ——— d—–w c:\documents and settings\Main\Application Data\OpenOffice.org2
2009-03-08 18:19 410,984 —-a-w c:\windows\system32\deploytk.dll
2009-03-06 01:58 5,749 —-a-w c:\windows\system32\oxyimmgj.dll
2009-03-04 13:41 ——— d—–w c:\documents and settings\Main\Application Data\Hoyle
2009-03-03 12:00 5,745 —-a-w c:\windows\system32\hafntoso.dll
2009-03-03 11:57 5,749 —-a-w c:\windows\system32\xhepesrq.dll
2009-03-02 11:56 5,749 —-a-w c:\windows\system32\jhntqtxt.dll
2009-03-02 11:56 5,745 —-a-w c:\windows\system32\hpsbtymx.dll
2009-03-02 11:52 172,544 —-a-w c:\windows\system32\cncs32.dll
2009-03-01 21:52 ——— d—–w c:\program files\Password Safe
2009-02-25 22:16 63,488 —-a-w c:\windows\xobglu16.dll
2009-02-25 22:16 26,046 —-a-w c:\windows\xobglu32.dll
2009-02-22 02:38 ——— d—–w c:\documents and settings\Main\Application Data\uTorrent
2009-02-19 01:56 ——— d—–w c:\program files\Google
2009-02-15 21:57 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-15 21:57 ——— d—–w c:\program files\SCi
2009-02-15 21:56 ——— d—–w c:\program files\Common Files\InstallShield
2009-02-14 13:18 ——— d—–w c:\program files\OJOsoft
2009-02-14 13:18 ——— d—–w c:\program files\Common Files\Common Share
2009-02-11 09:19 ——— d–h–w c:\program files\Zero G Registry
2009-02-11 09:16 ——— d—–w c:\program files\THQ
2009-02-11 08:25 ——— d—–w c:\program files\WiseOwl
2009-02-11 08:22 ——— d—–w c:\program files\Nodtronics
2009-02-11 08:17 ——— d—–w c:\program files\Common Files\Adobe
2009-02-11 08:17 ——— d—–w c:\documents and settings\Main\Application Data\InterTrust
2009-02-11 08:01 ——— d—–w c:\program files\Eureka
2009-02-09 10:03 ——— d—–w c:\documents and settings\Main\Application Data\Atari
2009-02-09 09:38 ——— d—–w c:\program files\Atari
2009-02-09 09:21 43,520 —-a-w c:\windows\system32\CmdLineExt03.dll
2009-02-09 09:19 ——— d—–w c:\documents and settings\Main\Application Data\Leadertech
2009-02-06 08:03 307,576 —-a-w c:\windows\WLXPGSS.SCR
2009-02-06 07:52 49,504 —-a-w c:\windows\system32\sirenacm.dll
2009-01-26 09:58 107,888 —-a-w c:\windows\system32\CmdLineExt.dll
2008-10-06 08:48 47,360 —-a-w c:\documents and settings\Main\Application Data\pcouffin.sys
2008-10-28 14:11 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008102920081030\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-16 68856]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2009-01-31 1398024]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-12 342312]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Main^Start Menu^Programs^Startup^OpenOffice.org 2.0.lnk]
backup=c:\windows\pss\OpenOffice.org 2.0.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GEST]
m‘|\ü [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
–a—— 2007-06-27 19:03 152872 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
-ra—— 2007-09-05 19:13 166424 c:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
-ra—— 2007-09-05 19:13 141848 c:\windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
–a—— 2007-06-25 08:47 1057064 c:\program files\Nero\Nero 7\InCD\InCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
–a—— 2007-08-23 17:36 455968 c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2007-03-01 15:57 153136 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
-ra—— 2007-09-05 19:13 137752 c:\windows\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SecurDisc]
–a—— 2007-06-25 08:47 1629480 c:\program files\Nero\Nero 7\InCD\NBHGui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-ra—— 2005-05-03 20:43 69632 c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-ra—— 2008-02-13 16:31 16857600 c:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-03-19 55152]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2008-02-16 36368]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2008-02-16 333328]
S2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2008-08-21 52240]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [2008-08-21 488768]
S3 tmproxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2008-08-21 648456]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder

2009-04-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2009-04-07 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
- - - - ORPHANS REMOVED - - - -

BHO-{209ba86b-cd8c-4393-951e-b172ffbca90c} - (no file)
BHO-{5FEE60AE-DC68-4044-8B05-C436A21D6513} - (no file)
BHO-{C7E7F703-357D-4C46-BD17-C2E86E826EBB} - (no file)
BHO-{CAB1BF85-D8D1-4090-8870-47CD2BD4199E} - (no file)
BHO-{EAC84402-1B6F-46C2-AB0F-D4B9AA17E552} - (no file)
BHO-{F6D66EE9-88BE-415C-8DD4-B8C7FDCF484A} - (no file)
ShellExecuteHooks-{196d8e11-fd4e-4caa-86d2-58f64970f4ad} - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com.au
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.google.com.au
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-08 10:00:14
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1072721967-1783874425-2766501852-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:23,4a,cb,8c,a6,c5,61,63,fb,c1,a3,90,68,6f,aa,47,17,b5,f8,3c,c3,4d,87,
80,2b,3f,75,74,34,de,b6,2b,d7,71,99,48,61,92,7d,8e,3e,9f,43,b1,7b,5b,70,c7,\
"??"=hex:70,de,27,bf,0f,85,e2,bc,cf,60,44,00,06,fa,f8,9c
.
Completion time: 2009-04-08 10:01:08
ComboFix-quarantined-files.txt 2009-04-08 00:01:06

Pre-Run: 118,660,448,256 bytes free
Post-Run: 118,659,510,272 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

287 — E O F — 2009-02-25 16:00:36




Fresh HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:04:15 AM, on 8/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\lexpps.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {209ba86b-cd8c-4393-951e-b172ffbca90c} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: (no name) - {5FEE60AE-DC68-4044-8B05-C436A21D6513} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: (no name) - {C7E7F703-357D-4C46-BD17-C2E86E826EBB} - (no file)
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: (no name) - {CAB1BF85-D8D1-4090-8870-47CD2BD4199E} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {EAC84402-1B6F-46C2-AB0F-D4B9AA17E552} - (no file)
O2 - BHO: (no name) - {F6D66EE9-88BE-415C-8DD4-B8C7FDCF484A} - (no file)
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: RollerCoaster Tycoon 3 Registration.lnk = C:\Documents and Settings\Main\Local Settings\Temp\{AF7A94F2-F7B1-4646-B835-8EBDC369D400}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.google.com
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinner.com/games/v47/scrab…rabblecubes.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - http://www.bebo.com/files/BeboUploader.5.1.4.cab
O16 - DPF: {2C153C75-8476-434B-B3C3-57B63A3D1939} (Brickout Control) - http://www.worldwinner.com/games/v48/brickout/brickout.cab
O16 - DPF: {42FDC231-A411-45F8-B8B6-3B5026111DA8} (SolitaireRush Control) - http://www.worldwinner.com/games/v47/solit…litairerush.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {555F1BBC-6EC2-474F-84AF-633EF097FF54} (WWHearts Control) - http://www.worldwinner.com/games/v52/wwhearts/wwhearts.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinner.com/games/v63/bjattack/bja.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
O16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} (Blockwerx Control) - http://www.worldwinner.com/games/v49/blockwerx/blockwerx.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} (Cubis Control) - http://www.worldwinner.com/games/v57/cubis/cubis.cab
O16 - DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} (WwLuxor Control) - http://www.worldwinner.com/games/v49/luxor/luxor.cab
O16 - DPF: {C5326A4D-E9AA-40AD-A09A-E74304D86B47} (DinerDash Control) - http://www.worldwinner.com/games/v50/dinerdash/dinerdash.cab
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} (FamilyFeud Control) - http://www.worldwinner.com/games/v47/famil…/familyfeud.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHos…ronGameHost.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe

–
End of file - 10108 bytes
my computer seems alot better, i am going to let you know tomorrow if it still seems like it is going to freeze up or if any of those pop ups happen again today… but when i run spybot it has always come up with infected files, and i delte them but they come back onyl after a few hours and spybot isnt picking the same trogen file name up anymore which is a relief… just one question, i always pay for my antivirus program, and after all this trouble i wonder why, is it even worth paying for an antivirus programs when other things found online like we just done seem to work better?
Hi,

Please do the following:

There are a lot of files there to copy, please make sure you get them all.

It is very important to disable teatimer - then when you re-enable tea timer make sure you ALLOW the changes.

We may have to do this again as I may have missed the odd one…we'll see how it goes.


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')


KillAll::

Collect::
c:\windows\system32\frduwlck.dll
c:\windows\system32\chofsldx.dll
c:\windows\system32\eoxvujyk.dll
c:\windows\system32\goahrsor.dll
c:\windows\system32\wulbicyu.dll
c:\windows\system32\gehqvkdg.dll
c:\windows\system32\wnhthpjx.dll
c:\windows\system32\isalhhpy.dll
c:\windows\system32\wacouvlb.dll
c:\windows\system32\yblhijmh.dll
c:\windows\system32\devbvvww.dll
 c:\windows\system32\wagymaby.dll
c:\windows\system32\hpcvuxfm.dll
c:\windows\system32\ymaplkre.dll
c:\windows\system32\mvgnwgfr.dll
c:\windows\system32\hopeycbu.dll
c:\windows\system32\yuskhwwb.dll
c:\windows\system32\gaaoxvld.dll
c:\windows\system32\tbsswljo.dll
c:\windows\system32\fqefrwpx.dll
c:\windows\system32\njtynmgo.dll
c:\windows\system32\vxgmytmh.dll
c:\windows\system32\luyejngb.dll
c:\windows\system32\bnescwdu.dll
c:\windows\system32\ltscijqs.dll
c:\windows\system32\lflxtcpd.dll
c:\windows\system32\huqngxqh.dll
c:\windows\system32\qqfjqodl.dll
c:\windows\system32\wayfwmay.dll
c:\windows\system32\mdqjiqxh.dll
c:\windows\system32\xgkrwbqm.dll
c:\windows\system32\ejwkxavh.dll
c:\windows\system32\cqfhvcdr.dll
c:\windows\system32\byeqdfog.dll
c:\windows\system32\ssswdpmu.dll
c:\windows\system32\wygowcfk.dll
c:\windows\system32\dfxwxlvb.dll
c:\windows\system32\baisxvxh.dll
c:\windows\system32\qcbwauql.dll
c:\windows\system32\fopyofuy.dll
c:\windows\system32\hkbfkvct.dll
c:\windows\system32\tohcrtxd.dll
c:\windows\system32\vhjdfjee.dll
c:\windows\system32\sygvscyp.dll
c:\windows\system32\wwxftwfi.dll
c:\windows\system32\tefgcmkq.dll
c:\windows\system32\xbjcprbj.dll
c:\windows\system32\rxvaummx.dll
c:\windows\system32\yfvhwahk.dll
c:\windows\system32\ytfueqjp.dll
c:\windows\system32\ifqdwtid.dll
c:\windows\system32\ambkokqe.dll
c:\windows\system32\fqggapua.dll
c:\windows\system32\tkkqdbja.dll
c:\windows\system32\dnddfyao.dll
c:\windows\system32\xraejfbq.dll
c:\windows\system32\jgvvjvcy.dll
c:\windows\system32\strsfxsr.dll
c:\windows\system32\msumncjk.dll
c:\windows\system32\yfmwjvpj.dll
c:\windows\system32\pjgvvnbj.dll
c:\windows\system32\sohyhmso.dll
c:\windows\system32\dfdqqodd.dll
c:\windows\system32\phreelqa.dll
c:\windows\system32\qtflxbfk.dll
c:\windows\system32\xffecacc.dll
c:\windows\system32\blvbxadn.dll
c:\windows\system32\lrkriggo.dll
c:\windows\system32\ovkqqmpd.dll
c:\windows\system32\ewudiymt.dll
c:\windows\system32\uflaeoww.dll
c:\windows\system32\unxrcrrl.dll
c:\windows\system32\qnsfidhp.dll
c:\windows\system32\oukovvqk.dll
c:\windows\system32\bgwfuwgk.dll
c:\windows\system32\tnutglap.dll
c:\windows\system32\vwkgxavx.dll
c:\windows\system32\ndnkostt.dll
c:\windows\system32\ncsutuxx.dll
c:\windows\system32\cslvwuva.dll
c:\windows\system32\oxyimmgj.dll
c:\windows\system32\hafntoso.dll
c:\windows\system32\xhepesrq.dll
c:\windows\system32\jhntqtxt.dll
c:\windows\system32\hpsbtymx.dll

File::

Folder::

Registry::

Driver::

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]

* Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
* ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
* When finished, it shall produce a log for you.
* Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

NOTE: CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

please post back the Combo fix log..
okay hope this works, here is the combofix log


ComboFix 09-04-04.01 - Main 2009-04-08 18:39:17.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2037.1617 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Main\Desktop\CFScript.txt
AV: Trend Micro Internet Security *On-access scanning disabled* (Updated)
FW: Trend Micro Personal Firewall *disabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\ambkokqe.dll
c:\windows\system32\baisxvxh.dll
c:\windows\system32\bgwfuwgk.dll
c:\windows\system32\blvbxadn.dll
c:\windows\system32\bnescwdu.dll
c:\windows\system32\byeqdfog.dll
c:\windows\system32\chofsldx.dll
c:\windows\system32\cqfhvcdr.dll
c:\windows\system32\cslvwuva.dll
c:\windows\system32\devbvvww.dll
c:\windows\system32\dfdqqodd.dll
c:\windows\system32\dfxwxlvb.dll
c:\windows\system32\dnddfyao.dll
c:\windows\system32\ejwkxavh.dll
c:\windows\system32\eoxvujyk.dll
c:\windows\system32\ewudiymt.dll
c:\windows\system32\fopyofuy.dll
c:\windows\system32\fqefrwpx.dll
c:\windows\system32\fqggapua.dll
c:\windows\system32\frduwlck.dll
c:\windows\system32\gaaoxvld.dll
c:\windows\system32\gehqvkdg.dll
c:\windows\system32\goahrsor.dll
c:\windows\system32\hafntoso.dll
c:\windows\system32\hkbfkvct.dll
c:\windows\system32\hopeycbu.dll
c:\windows\system32\hpcvuxfm.dll
c:\windows\system32\hpsbtymx.dll
c:\windows\system32\huqngxqh.dll
c:\windows\system32\ifqdwtid.dll
c:\windows\system32\isalhhpy.dll
c:\windows\system32\jgvvjvcy.dll
c:\windows\system32\jhntqtxt.dll
c:\windows\system32\lflxtcpd.dll
c:\windows\system32\lrkriggo.dll
c:\windows\system32\ltscijqs.dll
c:\windows\system32\luyejngb.dll
c:\windows\system32\mdqjiqxh.dll
c:\windows\system32\msumncjk.dll
c:\windows\system32\mvgnwgfr.dll
c:\windows\system32\ncsutuxx.dll
c:\windows\system32\ndnkostt.dll
c:\windows\system32\njtynmgo.dll
c:\windows\system32\oukovvqk.dll
c:\windows\system32\ovkqqmpd.dll
c:\windows\system32\oxyimmgj.dll
c:\windows\system32\phreelqa.dll
c:\windows\system32\pjgvvnbj.dll
c:\windows\system32\qcbwauql.dll
c:\windows\system32\qnsfidhp.dll
c:\windows\system32\qqfjqodl.dll
c:\windows\system32\qtflxbfk.dll
c:\windows\system32\rxvaummx.dll
c:\windows\system32\sohyhmso.dll
c:\windows\system32\ssswdpmu.dll
c:\windows\system32\strsfxsr.dll
c:\windows\system32\sygvscyp.dll
c:\windows\system32\tbsswljo.dll
c:\windows\system32\tefgcmkq.dll
c:\windows\system32\tkkqdbja.dll
c:\windows\system32\tnutglap.dll
c:\windows\system32\tohcrtxd.dll
c:\windows\system32\uflaeoww.dll
c:\windows\system32\unxrcrrl.dll
c:\windows\system32\vhjdfjee.dll
c:\windows\system32\vwkgxavx.dll
c:\windows\system32\vxgmytmh.dll
c:\windows\system32\wacouvlb.dll
c:\windows\system32\wagymaby.dll
c:\windows\system32\wayfwmay.dll
c:\windows\system32\wnhthpjx.dll
c:\windows\system32\wulbicyu.dll
c:\windows\system32\wwxftwfi.dll
c:\windows\system32\wygowcfk.dll
c:\windows\system32\xbjcprbj.dll
c:\windows\system32\xffecacc.dll
c:\windows\system32\xgkrwbqm.dll
c:\windows\system32\xhepesrq.dll
c:\windows\system32\xraejfbq.dll
c:\windows\system32\yblhijmh.dll
c:\windows\system32\yfmwjvpj.dll
c:\windows\system32\yfvhwahk.dll
c:\windows\system32\ymaplkre.dll
c:\windows\system32\ytfueqjp.dll
c:\windows\system32\yuskhwwb.dll

.
((((((((((((((((((((((((( Files Created from 2009-03-08 to 2009-04-08 )))))))))))))))))))))))))))))))
.

2009-04-08 17:07 . 2009-04-08 17:07 d——– c:\program files\Common Files\DirectX
2009-04-08 17:05 . 2009-04-08 17:05 d——– c:\program files\Midas Interactive
2009-04-08 15:25 . 2009-04-08 15:25 d——– c:\program files\JoWooD Productions
2009-04-08 09:34 . 2009-04-08 09:34 d——– C:\_OTMoveIt
2009-04-07 14:31 . 2009-04-07 14:31 d——– c:\program files\Malwarebytes' Anti-Malware
2009-04-07 14:31 . 2009-04-07 14:31 d——– c:\documents and settings\Main\Application Data\Malwarebytes
2009-04-07 14:31 . 2009-04-07 14:31 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-07 14:31 . 2009-04-06 15:32 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-07 14:31 . 2009-04-06 15:32 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-04-07 13:55 . 2009-04-07 13:55 d——– C:\_OTListIt
2009-04-06 10:50 . 2009-04-06 10:51 d——– c:\program files\iTunes
2009-04-06 10:50 . 2009-04-06 10:50 d——– c:\program files\iPod
2009-04-06 10:50 . 2009-04-06 10:51 d——– c:\documents and settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-04-06 10:47 . 2009-04-06 10:48 d——– c:\program files\QuickTime
2009-04-04 12:10 . 2009-04-04 12:10 95 –a—— c:\windows\wininit.ini
2009-04-04 11:18 . 2009-04-04 11:21 d——– c:\program files\Spybot - Search & Destroy
2009-04-04 11:18 . 2009-04-04 11:21 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-04 10:28 . 2009-04-04 10:28 d——– c:\program files\Windows Defender
2009-04-03 20:05 . 2009-04-04 12:52 d——– c:\program files\RegistryFix7
2009-03-24 15:54 . 2009-04-07 09:14 d——– c:\documents and settings\Other\Tracing
2009-03-19 21:34 . 2009-03-20 19:14 d——– c:\windows\SxsCaPendDel
2009-03-19 21:12 . 2009-04-08 18:54 d——– c:\documents and settings\Main\Tracing
2009-03-19 21:09 . 2009-03-19 21:09 d——– c:\program files\Microsoft Silverlight
2009-03-19 21:08 . 2009-02-06 17:08 55,152 –a—— c:\windows\system32\drivers\fssfltr_tdi.sys
2009-03-19 20:50 . 2009-03-19 20:50 d——– c:\program files\Microsoft
2009-03-19 20:48 . 2009-03-19 20:48 d——– c:\program files\Windows Live SkyDrive
2009-03-19 19:47 . 2009-03-19 19:47 d——– c:\program files\Common Files\Windows Live
2009-03-08 12:20 . 2009-03-19 21:28 d——– c:\program files\The Bar

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-08 00:04 ——— d—–w c:\documents and settings\Main\Application Data\OpenOffice.org2
2009-04-06 00:50 ——— d—–w c:\program files\Common Files\Apple
2009-04-04 01:18 ——— d—–w c:\program files\Trend Micro
2009-04-04 00:03 ——— d—–w c:\program files\MJ 3.0
2009-04-03 23:46 ——— d—–w c:\program files\Java
2009-03-27 03:55 ——— d—–w c:\documents and settings\Main\Application Data\Vso
2009-03-22 07:03 ——— d—–w c:\documents and settings\Main\Application Data\LimeWire
2009-03-19 11:08 ——— d—–w c:\program files\Windows Live
2009-03-12 23:38 ——— d—–w c:\documents and settings\All Users\Application Data\DVD Shrink
2009-03-04 13:41 ——— d—–w c:\documents and settings\Main\Application Data\Hoyle
2009-03-01 21:52 ——— d—–w c:\program files\Password Safe
2009-02-25 22:16 63,488 —-a-w c:\windows\xobglu16.dll
2009-02-25 22:16 26,046 —-a-w c:\windows\xobglu32.dll
2009-02-22 02:38 ——— d—–w c:\documents and settings\Main\Application Data\uTorrent
2009-02-19 01:56 ——— d—–w c:\program files\Google
2009-02-15 21:57 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-15 21:57 ——— d—–w c:\program files\SCi
2009-02-15 21:56 ——— d—–w c:\program files\Common Files\InstallShield
2009-02-14 13:18 ——— d—–w c:\program files\OJOsoft
2009-02-14 13:18 ——— d—–w c:\program files\Common Files\Common Share
2009-02-11 09:19 ——— d–h–w c:\program files\Zero G Registry
2009-02-11 09:16 ——— d—–w c:\program files\THQ
2009-02-11 08:25 ——— d—–w c:\program files\WiseOwl
2009-02-11 08:22 ——— d—–w c:\program files\Nodtronics
2009-02-11 08:17 ——— d—–w c:\program files\Common Files\Adobe
2009-02-11 08:17 ——— d—–w c:\documents and settings\Main\Application Data\InterTrust
2009-02-11 08:01 ——— d—–w c:\program files\Eureka
2009-02-09 10:03 ——— d—–w c:\documents and settings\Main\Application Data\Atari
2009-02-09 09:38 ——— d—–w c:\program files\Atari
2009-02-09 09:19 ——— d—–w c:\documents and settings\Main\Application Data\Leadertech
2009-02-06 08:03 307,576 —-a-w c:\windows\WLXPGSS.SCR
2008-10-06 08:48 47,360 —-a-w c:\documents and settings\Main\Application Data\pcouffin.sys
2008-10-28 14:11 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008102920081030\index.dat
.

((((((((((((((((((((((((((((( SnapShot@2009-04-08_10.00.34.10 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-08 08:50:28 16,384 —-atw c:\windows\temp\Perflib_Perfdata_59c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-16 68856]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2009-01-31 1398024]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-12 342312]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Main^Start Menu^Programs^Startup^OpenOffice.org 2.0.lnk]
backup=c:\windows\pss\OpenOffice.org 2.0.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GEST]
m‘|\ü [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
–a—— 2007-06-27 19:03 152872 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
-ra—— 2007-09-05 19:13 166424 c:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
-ra—— 2007-09-05 19:13 141848 c:\windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
–a—— 2007-06-25 08:47 1057064 c:\program files\Nero\Nero 7\InCD\InCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
–a—— 2007-08-23 17:36 455968 c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2007-03-01 15:57 153136 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
-ra—— 2007-09-05 19:13 137752 c:\windows\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SecurDisc]
–a—— 2007-06-25 08:47 1629480 c:\program files\Nero\Nero 7\InCD\NBHGui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-ra—— 2005-05-03 20:43 69632 c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-ra—— 2008-02-13 16:31 16857600 c:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-03-19 55152]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2008-02-16 36368]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2008-02-16 333328]
S2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2008-08-21 52240]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [2008-08-21 488768]
S3 tmproxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2008-08-21 648456]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder

2009-04-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2009-04-08 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
- - - - ORPHANS REMOVED - - - -

BHO-{209ba86b-cd8c-4393-951e-b172ffbca90c} - (no file)
BHO-{5FEE60AE-DC68-4044-8B05-C436A21D6513} - (no file)
BHO-{C7E7F703-357D-4C46-BD17-C2E86E826EBB} - (no file)
BHO-{CAB1BF85-D8D1-4090-8870-47CD2BD4199E} - (no file)
BHO-{EAC84402-1B6F-46C2-AB0F-D4B9AA17E552} - (no file)
BHO-{F6D66EE9-88BE-415C-8DD4-B8C7FDCF484A} - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com.au
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.google.com.au
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-08 18:54:32
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1072721967-1783874425-2766501852-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:23,4a,cb,8c,a6,c5,61,63,fb,c1,a3,90,68,6f,aa,47,17,b5,f8,3c,c3,4d,87,
80,2b,3f,75,74,34,de,b6,2b,d7,71,99,48,61,92,7d,8e,3e,9f,43,b1,7b,5b,70,c7,\
"??"=hex:70,de,27,bf,0f,85,e2,bc,cf,60,44,00,06,fa,f8,9c
.
———————— Other Running Processes ————————
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Nero\Nero 7\InCD\InCDsrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-04-08 18:56:57 - machine was rebooted [Main]
ComboFix-quarantined-files.txt 2009-04-08 08:56:54
ComboFix2.txt 2009-04-08 00:01:09

Pre-Run: 116,779,356,160 bytes free
Post-Run: 116,766,408,704 bytes free

296 — E O F — 2009-02-25 16:00:36
Hi,

That's looking better,

Please do the following:


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.


Also post a fresh HJT log along with the MBAM Log
well it seems good news so far, no threats were found :)… here are the logs


MBAB Log

Malwarebytes' Anti-Malware 1.36
Database version: 1951
Windows 5.1.2600 Service Pack 3

8/04/2009 7:17:04 PM
mbam-log-2009-04-08 (19-17-04).txt

Scan type: Quick Scan
Objects scanned: 68247
Time elapsed: 1 minute(s), 30 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



HJT Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:19:03 PM, on 8/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: RollerCoaster Tycoon 3 Registration.lnk = C:\Documents and Settings\Main\Local Settings\Temp\{AF7A94F2-F7B1-4646-B835-8EBDC369D400}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.google.com
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinner.com/games/v47/scrab…rabblecubes.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - http://www.bebo.com/files/BeboUploader.5.1.4.cab
O16 - DPF: {2C153C75-8476-434B-B3C3-57B63A3D1939} (Brickout Control) - http://www.worldwinner.com/games/v48/brickout/brickout.cab
O16 - DPF: {42FDC231-A411-45F8-B8B6-3B5026111DA8} (SolitaireRush Control) - http://www.worldwinner.com/games/v47/solit…litairerush.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {555F1BBC-6EC2-474F-84AF-633EF097FF54} (WWHearts Control) - http://www.worldwinner.com/games/v52/wwhearts/wwhearts.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinner.com/games/v63/bjattack/bja.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
O16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} (Blockwerx Control) - http://www.worldwinner.com/games/v49/blockwerx/blockwerx.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} (Cubis Control) - http://www.worldwinner.com/games/v57/cubis/cubis.cab
O16 - DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} (WwLuxor Control) - http://www.worldwinner.com/games/v49/luxor/luxor.cab
O16 - DPF: {C5326A4D-E9AA-40AD-A09A-E74304D86B47} (DinerDash Control) - http://www.worldwinner.com/games/v50/dinerdash/dinerdash.cab
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} (FamilyFeud Control) - http://www.worldwinner.com/games/v47/famil…/familyfeud.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHos…ronGameHost.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe

–
End of file - 9846 bytes
Good news, your logs are clean :thumbup:

Now we need to clean up after ourselves:

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT

Clean up with OTListIt2:
  • Double-click OTListIt2.exe to start the program.
  • Close all other programs apart from OTListIt2 as this step will require a reboot
  • On the OTListIt2 main screen, press the [external image: Posted Image] button
  • Say Yes to the prompt and then allow the program to reboot your computer.

NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.
  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.
  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.
  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more.  Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
  • For Firefox, I highly recommend these add-ons to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
    • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories.  This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.
  • Please read the guide by Rorschach112on how to prevent malware and about safe computing here
Thank you for your patience, and performing all of the procedures requested.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI