This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Popups and comp running slowly

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:52:12 AM, on 4/5/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
C:\Windows\zHotkey.exe
C:\Windows\ModPS2Key.exe
C:\Windows\sttray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Trillian\trillian.exe
C:\Windows\system32\wermgr.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…TP&M=GT5404
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch…TP&M=GT5404
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…TP&M=GT5404
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gateway.com/g/sidepanel.html?Ch…TP&M=GT5404
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {a84e6d05-9fad-4976-af9e-24b9c775dffd} - C:\Windows\system32\lakofote.dll
O4 - HKLM\..\Run: [CCUTRAYICON] C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
O4 - HKLM\..\Run: [NMSSupport] "C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ModPS2] ModPS2Key.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [BigFix] c:\program files\Bigfix\bigfix.exe /atstartup
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Update32] C:\Windows\system32:nskrnl32.exe
O4 - HKLM\..\Run: [fumogogiha] Rundll32.exe "C:\Windows\system32\jebihote.dll",s
O4 - HKLM\..\Run: [a2a56c9a] rundll32.exe "C:\Windows\system32\kegorafa.dll",b
O4 - HKLM\..\Run: [CPMa1965f06] Rundll32.exe "c:\windows\system32\jinohila.dll",a
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O20 - AppInit_DLLs: C:\Windows\system32\wijariwo.dll c:\windows\system32\jinohila.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\jinohila.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\jinohila.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Intel® Alert Service (AlertService) - Intel® Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Intel® Software Services Manager (ISSM) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Intel® Viiv™ Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Intel® Application Tracker (MCLServiceATL) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Intel® Remoting Service (Remote UI Service) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe

–
End of file - 5717 bytes
Hi there lets see if we can kill this in one fell swoop

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
Thank you so much for the help!

OTListIt Extras logfile created on: 4/5/2009 9:53:05 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.11.0 Folder = C:\Users\Adam\Desktop
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1013.41 Mb Total Physical Memory | 479.81 Mb Available Physical Memory | 47.35% Memory free
2.23 Gb Paging File | 1.43 Gb Available in Paging File | 64.06% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223.06 Gb Total Space | 90.61 Gb Free Space | 40.62% Space Free | Partition Type: NTFS
Drive D: | 9.82 Gb Total Space | 4.47 Gb Free Space | 45.53% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ADAM-PC
Current User Name: Adam
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0
"UpdatesDisableNotify" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-1503100673-2415758853-3373541529-1001]
"EnableNotificationsRef" = 2
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-1503100673-2415758853-3373541529-500]
"EnableNotificationsRef" = 2

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"DisableNotifications" = 0
"EnableFirewall" = 1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent (BitTorrent, Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0C2AF762-0565-4C91-9F55-B8B53BB82A38}" = Microsoft Office Accounting 2008 Equifax Addin
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{26C610BF-761B-4209-BD6A-A0F1B73D6DDE}" = Intel® Viiv™ Software
"{270940EA-C235-40D9-B2AE-2D450356DF8E}" = Microsoft Office Accounting 2008
"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = Browser Address Error Redirector
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go 5.0
"{44C05309-60F4-410B-BC32-31733CFF1A41}" = Microsoft Digital Image Starter Edition 2006 Editor
"{4FE542EB-FF0B-4739-94DD-25C8AE0AB251}" = Microsoft Digital Image Starter Edition 2006 Library
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{5FA793A6-0071-42C1-9355-8F69A428C44F}" = Microsoft Office Accounting ADP Payroll Addin
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7F3BCF8A-8E02-4659-AF25-F9AB66BD6718}" = Gateway Recovery Center Installer
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A5FB086B-B602-4452-8FE9-DF6BFBCE3D09}" = Cubase Studio 4
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B391EECE-DFEA-4FC5-9D40-47FA43E2DBE6}" = Microsoft Office Accounting 2008 PayPal Addin
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BE2CC4A5-2128-4EA2-941D-14F7A6A1AB61}" = Digital Media Reader
"{CF1D7323-8A0A-49C7-83B0-088DB90721E2}" = AmpegSVX
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E3DF6916-2472-43D9-8B3C-9F2F0AAB01B5}" = Microsoft Office Accounting 2008 Fixed Asset Manager
"{E9F44C98-B8B6-480F-AF7B-E42A0A46F4E3}" = Microsoft SQL Server VSS Writer
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F9B3DD02-B0B3-42E9-8650-030DFF0D133D}" = Microsoft SQL Server Native Client
"{FF262740-C85A-11D5-BBEC-00D0B740900A}" = PS2 Multimedia Keyboard Driver
"Ableton Live v5.0.3" = Ableton Live v5.0.3
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"Agere Systems Soft Modem" = Agere Systems PCI-SV92PP Soft Modem
"Antares AVOX Vocal Kit Bundle VST v1.02" = Antares AVOX Vocal Kit Bundle VST v1.02
"ArtsAcoustic Reverb VST v1.1.0.1" = ArtsAcoustic Reverb VST v1.1.0.1
"Audio Damage 907A VST v1.0.0.7" = Audio Damage 907A VST v1.0.0.7
"Audio Damage DeVerb VST v1.0" = Audio Damage DeVerb VST v1.0
"Audio Damage DubStation VST v1.0.2.0" = Audio Damage DubStation VST v1.0.2.0
"Audio.Damage.Ronin.v1.0.VST-DAC" = Audio.Damage.Ronin.v1.0.VST-DAC
"BigSeq VST plug-in" = BigSeq VST plug-in
"Camel Audio Camel Space VST v1.15" = Camel Audio Camel Space VST v1.15
"DiscoDSP FX Bundle v1.0a" = DiscoDSP FX Bundle v1.0a
"Echo24 PCI" = Echo24 PCI
"Focusrite Saffire Bundle VST v2.0" = Focusrite Saffire Bundle VST v2.0
"Haihaisoft Universal Player" = Haihaisoft Universal Player
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"InstallShield_{BE2CC4A5-2128-4EA2-941D-14F7A6A1AB61}" = Digital Media Reader
"Intel® Configuration Center" = Intel® Viiv™ Software
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 3.7.5
"Live 6.0.9" = Live 6.0.9
"Microsoft Office Accounting 2008" = Microsoft Office Accounting 2008
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Money2006b" = Microsoft Money 2006
"Mozilla Firefox (3.0.8)" = Mozilla Firefox (3.0.8)
"MP3Suite" = MP3Suite
"Native Instruments - Rig Kontrol 2 Driver" = Native Instruments - Rig Kontrol 2 Driver
"Native Instruments GuitarRig2 RTAS VSTi DXi" = Native Instruments GuitarRig2 RTAS VSTi DXi
"OrangeVocoder v2.0-OxYGeN" = OrangeVocoder v2.0-OxYGeN
"PCSI" = Prevx CSI
"PhaseTwo VST plug-in" = PhaseTwo VST plug-in
"PictureItSuiteTrial_v12" = Microsoft Digital Image Starter Edition 2006
"PROR" = Microsoft Office Professional 2007 Trial
"PROSet" = Intel® PRO Network Connections Drivers
"QuickTime" = QuickTime
"Reverence VST plug-in" = Reverence VST plug-in
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SSL LMC-1" = SSL LMC-1 v1.0
"Steinberg Cubase SX v2.2.0.35" = Steinberg Cubase SX v2.2.0.35
"Switch" = Switch
"Syncrosoft License Control" = Syncrosoft License Control
"Trillian" = Trillian
"Vienna" = Vienna SoundFont Studio
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VideoLAN VLC media player 0.8.6c
"Voxengo Soniformer VST v2.3" = Voxengo Soniformer VST v2.3
"Voxengo_Polysquasher_1.0" = Polysquasher VST 1.0
"Waves Diamond Bundle v5.0" = Waves Diamond Bundle v5.0
"Waves SSL Collection v1.2" = Waves SSL Collection v1.2
"Waves Vocal Bundle v1.1" = Waves Vocal Bundle v1.1
"Winamp" = Winamp (remove only)
"WinRAR archiver" = WinRAR archiver
"WT014954" = Polar Bowler
"WT014956" = Polar Golfer
"WT014962" = SCRABBLE

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent" = BitTorrent
"BitTorrent DNA" = DNA

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/31/2009 7:05:23 PM | Computer Name = Adam-PC | Source = EventSystem | ID = 4609
Description =

Error - 4/2/2009 8:11:22 PM | Computer Name = Adam-PC | Source = EventSystem | ID = 4609
Description =

Error - 4/2/2009 9:52:59 PM | Computer Name = Adam-PC | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3334, time stamp 0x499db224,
faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code
0xc0000005, fault offset 0xffff7085, process id 0x17e0, application start time 0x01c9b3fb1a56b673.

Error - 4/3/2009 7:53:55 AM | Computer Name = Adam-PC | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3334, time stamp 0x499db224,
faulting module xul.dll, version 1.9.0.3334, time stamp 0x499db2f3, exception code
0xc0000409, fault offset 0x0057d996, process id 0x1080, application start time 0x01c9b45278286e93.

Error - 4/3/2009 8:04:35 AM | Computer Name = Adam-PC | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3334, time stamp 0x499db224,
faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code
0xc0000005, fault offset 0x00610077, process id 0x1568, application start time 0x01c9b452e14aa5a3.

Error - 4/3/2009 6:52:07 PM | Computer Name = Adam-PC | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3334, time stamp 0x499db224,
faulting module xul.dll, version 1.9.0.3334, time stamp 0x499db2f3, exception code
0xc0000005, fault offset 0x00115797, process id 0xc18, application start time 0x01c9b4ad6a6128c0.

Error - 4/4/2009 12:00:37 AM | Computer Name = Adam-PC | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3334, time stamp 0x499db224,
faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code
0xc0000005, fault offset 0xb5ff0f74, process id 0x1d8, application start time 0x01c9b4aed745aa50.

Error - 4/4/2009 8:53:38 AM | Computer Name = Adam-PC | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3334, time stamp 0x499db224,
faulting module hareyiyi.dll, version 0.0.0.0, time stamp 0x499ecba7, exception
code 0xc0000005, fault offset 0x00001c60, process id 0x1d8, application start time
0x01c9b4aed745aa50.

Error - 4/4/2009 12:53:42 PM | Computer Name = Adam-PC | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3372, time stamp 0x49cbcea4,
faulting module xul.dll, version 1.9.0.3372, time stamp 0x49cbcf01, exception code
0xc0000005, fault offset 0x00042dd7, process id 0x1444, application start time 0x01c9b5247cc679d0.

Error - 4/5/2009 8:12:30 AM | Computer Name = Adam-PC | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3372, time stamp 0x49cbcea4,
faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code
0xc0000005, fault offset 0x54c08304, process id 0x36c, application start time 0x01c9b545ec7fff00.

[ System Events ]
Error - 4/5/2009 9:22:06 AM | Computer Name = Adam-PC | Source = DCOM | ID = 10016
Description =

Error - 4/5/2009 9:22:09 AM | Computer Name = Adam-PC | Source = DCOM | ID = 10016
Description =

Error - 4/5/2009 9:22:09 AM | Computer Name = Adam-PC | Source = DCOM | ID = 10016
Description =

Error - 4/5/2009 9:22:09 AM | Computer Name = Adam-PC | Source = DCOM | ID = 10016
Description =

Error - 4/5/2009 9:28:14 AM | Computer Name = Adam-PC | Source = DCOM | ID = 10016
Description =

Error - 4/5/2009 9:28:18 AM | Computer Name = Adam-PC | Source = DCOM | ID = 10016
Description =

Error - 4/5/2009 9:28:23 AM | Computer Name = Adam-PC | Source = DCOM | ID = 10016
Description =

Error - 4/5/2009 9:33:47 AM | Computer Name = Adam-PC | Source = DCOM | ID = 10016
Description =

Error - 4/5/2009 9:33:55 AM | Computer Name = Adam-PC | Source = DCOM | ID = 10016
Description =

Error - 4/5/2009 9:34:09 AM | Computer Name = Adam-PC | Source = DCOM | ID = 10016
Description =


< End of report >





================================================================================
==============



OTListIt logfile created on: 4/5/2009 9:53:04 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.11.0 Folder = C:\Users\Adam\Desktop
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1013.41 Mb Total Physical Memory | 479.81 Mb Available Physical Memory | 47.35% Memory free
2.23 Gb Paging File | 1.43 Gb Available in Paging File | 64.06% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223.06 Gb Total Space | 90.61 Gb Free Space | 40.62% Space Free | Partition Type: NTFS
Drive D: | 9.82 Gb Total Space | 4.47 Gb Free Space | 45.53% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ADAM-PC
Current User Name: Adam
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Windows\system32\AUDIODG.EXE (Microsoft Corporation)
PRC - C:\Windows\system32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe ()
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
PRC - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe (SigmaTel, Inc.)
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe (Intel® Corporation)
PRC - C:\Windows\zHotkey.exe ()
PRC - C:\Windows\ModPS2Key.exe (Chicony)
PRC - C:\Windows\sttray.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Windows\System32\hkcmd.exe (Intel Corporation)
PRC - C:\Windows\System32\igfxpers.exe (Intel Corporation)
PRC - C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe (Intel® Corporation)
PRC - C:\Program Files\Internet Explorer\ieuser.exe (Microsoft Corporation)
PRC - C:\Windows\system32\wermgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Windows\system32\WUDFHost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\mobsync.exe (Microsoft Corporation)
PRC - C:\Program Files\Prevx\prevx.exe (Prevx)
PRC - C:\Program Files\Prevx\prevx.exe (Prevx)
PRC - C:\Users\Adam\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (AgereModemAudio [Auto | Running]) – C:\Windows\system32\agrsmsvc.exe (Agere Systems)
SRV - (AlertService [On_Demand | Running]) – C:\Program Files\Intel\IntelDH\CCU\AlertService.exe (Intel® Corporation)
SRV - (Automatic LiveUpdate Scheduler [Auto | Stopped]) – File not found
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DQLWinService [Auto | Running]) – C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe ()
SRV - (ehRecvr [On_Demand | Stopped]) – C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) – C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (IAANTMON [Auto | Running]) – C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Intel Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (ISSM [On_Demand | Stopped]) – C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe (Intel® Corporation)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LiveUpdate [Disabled | Stopped]) – File not found
SRV - (M1 Server [On_Demand | Stopped]) – C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe ()
SRV - (McciCMService [Auto | Running]) – C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
SRV - (MCLServiceATL [On_Demand | Stopped]) – C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe (Intel® Corporation)
SRV - (MSSQL$MSSMLBIZ [Auto | Running]) – c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (MSSQLServerADHelper [Disabled | Stopped]) – c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PrismXL [Auto | Running]) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
SRV - (Remote UI Service [On_Demand | Stopped]) – C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe (Intel® Corporation)
SRV - (SQLBrowser [Disabled | Stopped]) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (SQLWriter [Auto | Running]) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (STacSV [Auto | Running]) – C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe (SigmaTel, Inc.)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (CSIScanner [Auto | Running]) – C:\Program Files\Prevx\prevx.exe (Prevx)

========== Driver Services (SafeList) ==========

DRV - (ac97intc [On_Demand | Stopped]) – C:\Windows\system32\drivers\ac97intc.sys (Intel Corporation)
DRV - (adp94xx [Disabled | Stopped]) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (adpahci [Disabled | Stopped]) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (adpu160m [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (adpu320 [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (AgereSoftModem [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\AGRSM.sys (Agere Systems)
DRV - (aic78xx [Disabled | Stopped]) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (aliide [Disabled | Stopped]) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (arc [Disabled | Stopped]) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (arcsas [Disabled | Stopped]) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (bcm4sbxp [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (BrFiltLo [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (Brserid [Disabled | Stopped]) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrSerWdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer [On_Demand | Stopped]) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (Cdr4_xp [System | Running]) – C:\Windows\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (Cdralw2k [System | Running]) – C:\Windows\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (cmdide [Disabled | Stopped]) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (E100B [On_Demand | Running]) – C:\Windows\system32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (E1G60 [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\E1G60I32.sys (Intel Corporation)
DRV - (echo24 [On_Demand | Running]) – C:\Windows\system32\drivers\echo24.sys (Echo Digital Audio Corp.)
DRV - (elxstor [Disabled | Stopped]) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (FVNETusb [On_Demand | Running]) – C:\Windows\system32\DRIVERS\vnet558x.sys (ATMEL)
DRV - (HpCISSs [Disabled | Stopped]) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (ialm [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\igdkmd32.sys (Intel Corporation)
DRV - (iaStor [Boot | Running]) – C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (iaStorV [Boot | Running]) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (igfx [On_Demand | Running]) – C:\Windows\system32\DRIVERS\igdkmd32.sys (Intel Corporation)
DRV - (iirsp [Disabled | Stopped]) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (IntelDH [On_Demand | Running]) – C:\Windows\System32\Drivers\IntelDH.sys (Intel Corporation)
DRV - (iteatapi [Disabled | Stopped]) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (iteraid [Disabled | Stopped]) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (Lbd [Boot | Running]) – C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (LSI_FC [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (LSI_SAS [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (LSI_SCSI [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (megasas [Disabled | Stopped]) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Mraid35x [Disabled | Stopped]) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (MREMP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (NETw2v32 [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\NETw2v32.sys (Intel® Corporation)
DRV - (nfrd960 [Disabled | Stopped]) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (nmsgopro [Auto | Running]) – C:\Windows\system32\DRIVERS\nmsgopro.sys (Gteko Ltd.)
DRV - (nmsunidr [Auto | Running]) – C:\Windows\system32\DRIVERS\nmsunidr.sys (Gteko Ltd.)
DRV - (ntrigdigi [Disabled | Stopped]) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (nvraid [Disabled | Stopped]) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor [Disabled | Stopped]) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (PxHelp20 [Boot | Running]) – C:\Windows\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql2300 [Disabled | Stopped]) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (ql40xx [Disabled | Stopped]) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (secdrv [Auto | Running]) – C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiSRaid2 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (SiSRaid4 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (STHDA [On_Demand | Running]) – C:\Windows\system32\drivers\stwrt.sys (SigmaTel, Inc.)
DRV - (Symc8xx [Disabled | Stopped]) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_hi [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Sym_u3 [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (SynasUSB [On_Demand | Stopped]) – C:\Windows\system32\drivers\SynasUSB.sys (SIA Syncrosoft)
DRV - (TSHWMDTCP [On_Demand | Stopped]) – C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.sys ()
DRV - (uliahci [Disabled | Stopped]) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (UlSata [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (ulsata2 [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\Windows\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (viaide [Disabled | Stopped]) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (vsmraid [Disabled | Stopped]) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (pxscan [Boot | Running]) – C:\Windows\System32\drivers\pxscan.sys (Prevx)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch…TP&M;=GT5404
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…TP&M;=GT5404
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gateway.com/g/sidepanel.html?Ch…TP&M;=GT5404

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…TP&M;=GT5404
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2}:0.9.84
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071101000055
FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:3.0.0
FF - prefs.js..extensions.enabledItems: {2e61e246-e640-4c56-b1ed-f146dbed48cd}:0.7.6
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/04 07:54:18 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/04 07:54:18 | 00,000,000 | —D | M]

[2009/03/07 10:55:27 | 00,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\mozilla\Extensions
[2009/03/07 10:55:27 | 00,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/04 19:53:47 | 00,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\mozilla\Firefox\Profiles\099nppdp.default\extensions
[2009/03/07 10:56:03 | 00,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\mozilla\Firefox\Profiles\099nppdp.default\extensions\{2e61e246-e640-4c56-b1ed-f146dbed48cd}
[2009/03/07 10:56:03 | 00,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\mozilla\Firefox\Profiles\099nppdp.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2008/07/29 03:40:17 | 00,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\mozilla\Firefox\Profiles\099nppdp.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
[2009/02/08 18:44:12 | 00,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\mozilla\Firefox\Profiles\099nppdp.default\extensions\[removed]
[2009/03/07 10:55:28 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/04/04 07:54:18 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/04/04 07:54:02 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/04 07:54:02 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/04/04 07:54:12 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/04 07:54:12 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/04 07:54:12 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/04 07:54:12 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/04 07:54:12 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/04 07:54:12 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/04 07:54:13 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (728 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {a84e6d05-9fad-4976-af9e-24b9c775dffd} - C:\Windows\system32\lakofote.dll ()
O4 - HKLM..\Run: [a2a56c9a] rundll32.exe "C:\Windows\system32\kegorafa.dll",b (ICQ)
O4 - HKLM..\Run: [BigFix] c:\program files\Bigfix\bigfix.exe /atstartup File not found
O4 - HKLM..\Run: [CCUTRAYICON] C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe (Intel® Corporation)
O4 - HKLM..\Run: [CHotkey] zHotkey.exe ()
O4 - HKLM..\Run: [CPMa1965f06] Rundll32.exe "c:\windows\system32\jinohila.dll",a ()
O4 - HKLM..\Run: [fumogogiha] Rundll32.exe "C:\Windows\system32\jebihote.dll",s ()
O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [ModPS2] ModPS2Key.exe (Chicony)
O4 - HKLM..\Run: [NMSSupport] "C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup (Intel Corporation)
O4 - HKLM..\Run: [Persistence] C:\Windows\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [SigmatelSysTrayApp] sttray.exe (SigmaTel, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\windows\system32\jinohila.dll) - c:\windows\system32\jinohila.dll ()
O20 - AppInit_DLLs: (C:\Windows\system32\wijariwo.dll) - C:\Windows\system32\wijariwo.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\system32\igfxdev.dll (Intel Corporation)
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\jinohila.dll ()
O22 - SharedTaskScheduler: {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - STS - c:\windows\system32\jinohila.dll ()
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\autoexec.bat () - [ NTFS ]
O32 - Autorun File - D:\autorun.inf () - [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()

========== Files/Folders - Created Within 30 Days ==========

[2 C:\Windows\System32\*.tmp files]
[2009/04/05 09:50:05 | 00,499,200 | —- | C] (OldTimer Tools) – C:\Users\Adam\Desktop\OTListIt2.exe
[2009/04/05 09:23:54 | 00,022,024 | —- | C] (Prevx) – C:\Windows\System32\drivers\pxscan.sys
[2009/04/05 09:23:54 | 00,000,000 | —D | C] – C:\Program Files\Prevx
[2009/04/05 09:23:50 | 00,000,000 | —D | C] – C:\ProgramData\PrevxCSI
[2009/04/05 09:23:49 | 00,000,065 | —- | C] () – C:\Windows\wininit.ini
[2009/04/05 07:23:11 | 01,422,825 | -HS- | C] () – C:\Windows\System32\afarogek.ini
[2009/04/04 19:22:49 | 01,422,803 | -HS- | C] () – C:\Windows\System32\ibigutik.ini
[2009/04/04 07:22:45 | 01,422,834 | -HS- | C] () – C:\Windows\System32\iyakimer.ini
[2009/04/03 21:10:29 | 00,054,156 | -H– | C] () – C:\Windows\QTFont.qfn
[2009/04/03 21:10:29 | 00,001,409 | —- | C] () – C:\Windows\QTFont.for
[2009/04/03 19:22:35 | 01,422,825 | -HS- | C] () – C:\Windows\System32\enilowes.ini
[2009/04/03 17:41:58 | 00,000,060 | -H– | C] () – C:\aaw7boot.cmd
[2009/04/03 07:22:24 | 01,422,825 | -HS- | C] () – C:\Windows\System32\asivefeh.ini
[2009/04/02 19:22:13 | 01,418,378 | -HS- | C] () – C:\Windows\System32\arovofuh.ini
[2009/04/02 19:21:05 | 10,632,19200 | -HS- | C] () – C:\hiberfil.sys
[2009/04/01 07:08:17 | 00,000,680 | —- | C] () – C:\Users\Adam\AppData\Local\d3d9caps.dat
[2009/03/31 18:10:21 | 00,000,552 | —- | C] () – C:\Users\Adam\AppData\Local\d3d8caps.dat
[2009/03/31 14:08:05 | 00,000,002 | —- | C] () – C:\-1566217163
[2009/03/26 00:10:41 | 00,037,355 | —- | C] () – C:\Users\Adam\Desktop\n1063746744_166822_6363615.jpg
[2009/03/24 21:42:28 | 00,142,336 | -HS- | C] (ICQ) – C:\Windows\System32\ksougj.dll
[2009/03/24 21:42:27 | 01,418,387 | -HS- | C] () – C:\Windows\System32\ogajodig.ini
[2009/03/24 09:42:22 | 00,141,824 | -HS- | C] (ICQ) – C:\Windows\System32\dlzynh.dll
[2009/03/24 09:42:20 | 01,420,795 | -HS- | C] () – C:\Windows\System32\ebabales.ini
[2009/03/23 22:59:00 | 00,129,664 | —- | C] () – C:\Users\Adam\Desktop\artofbookcover.jpg
[2009/03/23 21:42:19 | 00,141,312 | -HS- | C] (ICQ) – C:\Windows\System32\aknvvd.dll
[2009/03/23 21:42:17 | 01,420,795 | -HS- | C] () – C:\Windows\System32\ivoreroj.ini
[2009/03/23 09:42:12 | 00,140,800 | -HS- | C] (ICQ) – C:\Windows\System32\grsziv.dll
[2009/03/23 09:42:07 | 01,802,266 | -HS- | C] () – C:\Windows\System32\avigehem.ini
[2009/03/22 21:41:59 | 00,140,800 | -HS- | C] (ICQ) – C:\Windows\System32\rhnvxs.dll
[2009/03/22 21:41:57 | 01,801,911 | -HS- | C] () – C:\Windows\System32\uwuwudun.ini
[2009/03/22 21:09:00 | 00,436,629 | —- | C] () – C:\Users\Adam\Desktop\Backroom Boom Boom Rendered.wav.asd
[2009/03/22 21:05:46 | 37,895,472 | —- | C] () – C:\Users\Adam\Desktop\Backroom Boom Boom Rendered.wav
[2009/03/22 09:41:48 | 00,140,800 | -HS- | C] (ICQ) – C:\Windows\System32\nyytqc.dll
[2009/03/22 09:41:45 | 01,801,920 | -HS- | C] () – C:\Windows\System32\idiwalur.ini
[2009/03/21 21:41:40 | 00,141,824 | -HS- | C] (ICQ) – C:\Windows\System32\cvhxxw.dll
[2009/03/21 21:41:37 | 01,801,911 | -HS- | C] () – C:\Windows\System32\oyijejer.ini
[2009/03/21 19:21:32 | 01,524,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll
[2009/03/21 19:21:32 | 00,051,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuauclt.exe
[2009/03/21 19:21:32 | 00,043,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2009/03/21 19:21:31 | 01,809,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuaueng.dll
[2009/03/21 19:18:35 | 00,162,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2009/03/21 19:18:35 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2009/03/21 09:41:28 | 00,142,848 | -HS- | C] (ICQ) – C:\Windows\System32\ipiiko.dll
[2009/03/21 09:41:25 | 01,801,920 | -HS- | C] () – C:\Windows\System32\osaradeh.ini
[2009/03/20 21:41:21 | 01,801,911 | -HS- | C] () – C:\Windows\System32\ofuhesek.ini
[2009/03/20 21:41:18 | 00,142,848 | -HS- | C] (ICQ) – C:\Windows\System32\xfpwaf.dll
[2009/03/20 09:41:12 | 01,799,769 | -HS- | C] () – C:\Windows\System32\ebadegez.ini
[2009/03/19 21:41:07 | 01,799,218 | -HS- | C] () – C:\Windows\System32\ujekunot.ini
[2009/03/19 09:41:01 | 01,795,884 | -HS- | C] () – C:\Windows\System32\obuzokit.ini
[2009/03/18 21:40:59 | 01,795,884 | -HS- | C] () – C:\Windows\System32\ufosonev.ini
[2009/03/17 21:40:29 | 01,957,494 | -HS- | C] () – C:\Windows\System32\ifirewur.ini
[2009/03/17 09:40:21 | 01,933,175 | -HS- | C] () – C:\Windows\System32\ihawureg.ini
[2009/03/16 21:39:53 | 01,932,881 | -HS- | C] () – C:\Windows\System32\efaheyol.ini
[2009/03/16 20:54:24 | 00,000,000 | R–D | C] – C:\Users\Adam\Desktop\Backroom Boom Boom Project
[2009/03/16 19:22:09 | 00,000,000 | —D | C] – C:\VundoFix Backups
[2009/03/16 09:39:39 | 01,912,660 | -HS- | C] () – C:\Windows\System32\uzetobav.ini
[2009/03/15 21:39:31 | 01,912,660 | -HS- | C] () – C:\Windows\System32\utopunip.ini
[2009/03/15 09:39:20 | 01,912,660 | -HS- | C] () – C:\Windows\System32\urelowid.ini
[2009/03/14 21:39:11 | 01,912,660 | -HS- | C] () – C:\Windows\System32\irelefog.ini
[2009/03/14 10:02:35 | 00,001,874 | —- | C] () – C:\Users\Adam\Desktop\HijackThis.lnk
[2009/03/14 10:02:35 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/03/14 09:39:03 | 01,912,660 | -HS- | C] () – C:\Windows\System32\ubuvikes.ini
[2009/03/14 07:55:31 | 00,064,160 | —- | C] (Lavasoft AB) – C:\Windows\System32\drivers\Lbd.sys
[2009/03/13 21:38:52 | 01,912,660 | -HS- | C] () – C:\Windows\System32\utoveton.ini
[2009/03/13 09:38:26 | 01,912,680 | -HS- | C] () – C:\Windows\System32\arirayew.ini
[2009/03/12 21:38:10 | 01,808,081 | -HS- | C] () – C:\Windows\System32\ajedafet.ini
[2009/03/12 21:38:07 | 00,142,336 | -HS- | C] () – C:\Windows\System32\noxnkk.dll
[2009/03/12 12:02:27 | 01,808,081 | -HS- | C] () – C:\Windows\System32\eyanofef.ini
[2009/03/12 09:37:52 | 00,143,360 | -HS- | C] () – C:\Windows\System32\zmvxeu.dll
[2009/03/07 09:08:13 | 00,015,688 | —- | C] () – C:\Windows\System32\lsdelete.exe
[2009/03/07 08:51:01 | 00,000,472 | —- | C] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2009/03/07 08:50:46 | 00,000,000 | —D | C] – C:\Windows\System32\DRVSTORE
[2009/03/07 08:50:02 | 00,000,000 | -H-D | C] – C:\ProgramData\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/03/07 08:50:00 | 00,001,007 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2009/03/07 08:49:47 | 00,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2009/03/07 08:49:47 | 00,000,000 | —D | C] – C:\Program Files\Lavasoft
[2009/03/07 08:44:39 | 34,543,112 | —- | C] (Lavasoft ) – C:\Users\Adam\Desktop\Ad-AwareAE.exe
[2009/01/08 00:39:26 | 00,000,016 | —- | C] () – C:\Windows\System32\msvcsv60.dll
[2009/01/05 07:23:04 | 00,104,960 | -HS- | C] () – C:\Windows\System32\jinohila.dll
[2008/07/22 18:51:01 | 00,000,092 | —- | C] () – C:\Windows\mp3wavcon.ini
[2008/07/22 18:26:58 | 00,237,568 | —- | C] () – C:\Windows\System32\lame_enc.dll
[2008/01/10 07:16:20 | 00,159,839 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2008/01/10 07:15:30 | 00,755,027 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2007/09/25 16:59:58 | 00,007,168 | —- | C] () – C:\Windows\System32\Echo24Wrap.dll
[2007/09/04 11:56:10 | 00,164,352 | —- | C] () – C:\Windows\System32\unrar.dll
[2007/05/07 09:11:09 | 00,000,061 | —- | C] () – C:\Windows\SBWIN.INI
[2007/03/27 02:55:48 | 03,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2007/01/25 14:53:19 | 00,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1114.dll
[2007/01/25 14:53:16 | 00,077,824 | —- | C] () – C:\Windows\System32\hccutils.dll
[2007/01/25 14:20:32 | 00,532,544 | —- | C] () – C:\Windows\PIC.dll
[2007/01/25 14:20:32 | 00,024,576 | —- | C] () – C:\Windows\HKNTDLL.dll
[2006/12/12 11:24:42 | 00,012,288 | —- | C] () – C:\Windows\System32\DivXWMPExtType.dll
[2006/12/12 11:13:50 | 00,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1147.dll
[2006/12/12 10:02:50 | 00,053,248 | —- | C] () – C:\Windows\System32\oemdspif.dll
[2006/11/22 17:16:18 | 00,003,612 | —- | C] () – C:\Windows\ReaderString.ini
[2006/11/21 13:50:06 | 00,000,037 | —- | C] () – C:\Windows\sunkist.ini
[2006/11/02 07:56:07 | 00,000,082 | -HS- | C] () – C:\Windows\System32\desktop.ini
[2006/11/02 07:35:32 | 00,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 05:33:01 | 00,786,636 | —- | C] () – C:\Windows\System32\PerfStringBackup.INI
[2006/11/02 05:25:21 | 00,061,440 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2006/11/02 05:24:31 | 00,001,405 | —- | C] () – C:\Windows\msdfmap.ini
[2006/11/02 05:23:31 | 00,000,244 | —- | C] () – C:\Windows\win.ini
[2006/11/02 05:23:31 | 00,000,219 | —- | C] () – C:\Windows\system.ini
[2006/11/02 03:23:38 | 00,055,858 | —- | C] () – C:\Windows\System32\tcpmon.ini
[2006/11/02 02:40:29 | 00,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 02:09:45 | 00,027,097 | —- | C] () – C:\Windows\System32\country.sys
[2006/11/02 02:09:44 | 00,042,809 | —- | C] () – C:\Windows\System32\KEY01.SYS
[2006/11/02 02:09:44 | 00,042,537 | —- | C] () – C:\Windows\System32\KEYBOARD.SYS
[2006/11/02 02:09:42 | 00,009,029 | —- | C] () – C:\Windows\System32\ANSI.SYS
[2006/11/02 02:09:41 | 00,004,768 | —- | C] () – C:\Windows\System32\HIMEM.SYS
[2006/11/02 02:09:40 | 00,029,274 | —- | C] () – C:\Windows\System32\NTDOS412.SYS
[2006/11/02 02:09:38 | 00,029,370 | —- | C] () – C:\Windows\System32\NTDOS411.SYS
[2006/11/02 02:09:35 | 00,029,146 | —- | C] () – C:\Windows\System32\NTDOS404.SYS
[2006/11/02 02:09:31 | 00,029,146 | —- | C] () – C:\Windows\System32\NTDOS804.SYS
[2006/11/02 02:09:29 | 00,027,866 | —- | C] () – C:\Windows\System32\NTDOS.SYS
[2006/11/02 02:09:26 | 00,035,536 | —- | C] () – C:\Windows\System32\NTIO412.SYS
[2006/11/02 02:09:24 | 00,035,776 | —- | C] () – C:\Windows\System32\NTIO411.SYS
[2006/11/02 02:09:23 | 00,034,672 | —- | C] () – C:\Windows\System32\NTIO404.SYS
[2006/11/02 02:09:22 | 00,034,672 | —- | C] () – C:\Windows\System32\NTIO804.SYS
[2006/11/02 02:09:20 | 00,033,952 | —- | C] () – C:\Windows\System32\NTIO.SYS
[2006/11/02 01:47:51 | 00,364,544 | —- | C] () – C:\Windows\System32\msjetoledb40.dll
[2006/11/02 01:25:08 | 00,013,312 | —- | C] () – C:\Windows\System32\win87em.dll
[2006/10/03 10:53:03 | 00,069,632 | —- | C] () – C:\Windows\System32\com.fxpansion.fxshared.dll
[2006/06/23 12:09:34 | 00,019,968 | R— | C] () – C:\Windows\System32\cpuinf32.dll
[2006/05/26 08:29:14 | 00,005,120 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2006/04/03 07:26:36 | 00,000,547 | —- | C] () – C:\Windows\System32\ff_vfw.dll.manifest
[1900/01/01 12:00:00 | 00,143,360 | -HS- | C] () – C:\Windows\System32\ramemori.dll
[1900/01/01 12:00:00 | 00,142,336 | -HS- | C] () – C:\Windows\System32\talopoja.dll
[1900/01/01 12:00:00 | 00,108,032 | -HS- | C] () – C:\Windows\System32\remizalu.dll
[1900/01/01 12:00:00 | 00,108,032 | -HS- | C] () – C:\Windows\System32\nemulopi.dll
[1900/01/01 12:00:00 | 00,108,032 | -HS- | C] () – C:\Windows\System32\jeruwuke.dll
[1900/01/01 12:00:00 | 00,108,032 | -HS- | C] () – C:\Windows\System32\davewodu.dll
[1900/01/01 12:00:00 | 00,107,520 | -HS- | C] () – C:\Windows\System32\setegabo.dll
[1900/01/01 12:00:00 | 00,107,520 | -HS- | C] () – C:\Windows\System32\howewufu.dll
[1900/01/01 12:00:00 | 00,107,520 | -HS- | C] () – C:\Windows\System32\gidalepu.dll
[1900/01/01 12:00:00 | 00,107,008 | -HS- | C] () – C:\Windows\System32\zovadejo.dll
[1900/01/01 12:00:00 | 00,105,984 | -HS- | C] () – C:\Windows\System32\tutogupo.dll
[1900/01/01 12:00:00 | 00,105,984 | -HS- | C] () – C:\Windows\System32\hitoremi.dll
[1900/01/01 12:00:00 | 00,105,984 | -HS- | C] () – C:\Windows\System32\gijudefu.dll
[1900/01/01 12:00:00 | 00,069,120 | -HS- | C] () – C:\Windows\System32\wijariwo.dll
[1900/01/01 12:00:00 | 00,069,120 | -HS- | C] () – C:\Windows\System32\lakofote.dll
[1900/01/01 12:00:00 | 00,069,120 | -HS- | C] () – C:\Windows\System32\jebihote.dll
[1900/01/01 12:00:00 | 00,002,713 | -HS- | C] () – C:\Windows\System32\wegayalu.dll
[1900/01/01 12:00:00 | 00,002,713 | -HS- | C] () – C:\Windows\System32\tuyotete.dll
[1900/01/01 12:00:00 | 00,002,713 | -HS- | C] () – C:\Windows\System32\rafinuno.dll
[1900/01/01 12:00:00 | 00,002,713 | -HS- | C] () – C:\Windows\System32\hajifobu.dll

========== Files - Modified Within 30 Days ==========

[2 C:\Windows\System32\*.tmp files]
[1 C:\Windows\*.tmp files]
[2009/04/05 09:58:51 | 00,011,168 | -H– | M] () – C:\Windows\System32\kujadebo
[2009/04/05 09:50:07 | 00,499,200 | —- | M] (OldTimer Tools) – C:\Users\Adam\Desktop\OTListIt2.exe
[2009/04/05 09:24:09 | 00,003,072 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/04/05 09:24:09 | 00,003,072 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/04/05 09:23:54 | 00,022,024 | —- | M] (Prevx) – C:\Windows\System32\drivers\pxscan.sys
[2009/04/05 09:23:49 | 00,000,065 | —- | M] () – C:\Windows\wininit.ini
[2009/04/05 08:47:36 | 01,422,825 | -HS- | M] () – C:\Windows\System32\afarogek.ini
[2009/04/05 07:27:19 | 00,000,728 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2009/04/05 07:23:08 | 00,104,960 | -HS- | M] () – C:\Windows\System32\jinohila.dll
[2009/04/05 07:23:06 | 00,100,352 | -HS- | M] (ICQ) – C:\Windows\System32\kegorafa.dll
[2009/04/05 07:23:05 | 00,061,440 | -HS- | M] () – C:\Windows\System32\juhonemo.exe
[2009/04/04 19:45:02 | 01,422,803 | -HS- | M] () – C:\Windows\System32\ibigutik.ini
[2009/04/04 19:22:45 | 00,099,840 | —- | M] (ICQ) – C:\Windows\System32\kitugibi.dll
[2009/04/04 19:22:44 | 00,061,440 | -HS- | M] () – C:\Windows\System32\bubesomu.exe
[2009/04/04 19:22:43 | 00,106,496 | -HS- | M] (ICQ) – C:\Windows\System32\zayiwomo.dll
[2009/04/04 12:19:26 | 01,422,834 | -HS- | M] () – C:\Windows\System32\iyakimer.ini
[2009/04/04 07:50:55 | 00,000,472 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2009/04/04 07:22:39 | 00,104,960 | -HS- | M] (ICQ) – C:\Windows\System32\hareyiyi.dll
[2009/04/04 07:22:39 | 00,100,352 | —- | M] (ICQ) – C:\Windows\System32\remikayi.dll
[2009/04/04 07:22:38 | 00,061,440 | -HS- | M] () – C:\Windows\System32\pibosine.exe
[2009/04/03 22:54:42 | 01,422,825 | -HS- | M] () – C:\Windows\System32\enilowes.ini
[2009/04/03 21:10:29 | 00,054,156 | -H– | M] () – C:\Windows\QTFont.qfn
[2009/04/03 21:10:29 | 00,001,409 | —- | M] () – C:\Windows\QTFont.for
[2009/04/03 19:22:31 | 00,099,328 | —- | M] (ICQ) – C:\Windows\System32\sewoline.dll
[2009/04/03 19:22:30 | 00,061,440 | -HS- | M] () – C:\Windows\System32\jepeyumu.exe
[2009/04/03 19:22:29 | 00,104,960 | -HS- | M] (ICQ) – C:\Windows\System32\mawisega.dll
[2009/04/03 17:52:01 | 01,422,825 | -HS- | M] () – C:\Windows\System32\asivefeh.ini
[2009/04/03 17:41:58 | 00,000,060 | -H– | M] () – C:\aaw7boot.cmd
[2009/04/03 07:30:21 | 00,786,636 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2009/04/03 07:30:21 | 00,668,022 | —- | M] () – C:\Windows\System32\perfh009.dat
[2009/04/03 07:30:21 | 00,122,184 | —- | M] () – C:\Windows\System32\perfc009.dat
[2009/04/03 07:24:06 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/04/03 07:24:01 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/04/03 07:23:53 | 10,632,19200 | -HS- | M] () – C:\hiberfil.sys
[2009/04/03 07:22:24 | 00,061,440 | -HS- | M] () – C:\Windows\System32\zekazide.exe
[2009/04/03 07:22:23 | 00,103,936 | -HS- | M] (ICQ) – C:\Windows\System32\fofajivo.dll
[2009/04/03 07:22:23 | 00,100,352 | —- | M] (ICQ) – C:\Windows\System32\hefevisa.dll
[2009/04/03 06:53:53 | 01,418,387 | -HS- | M] () – C:\Windows\System32\ogajodig.ini
[2009/04/02 19:24:47 | 01,418,378 | -HS- | M] () – C:\Windows\System32\arovofuh.ini
[2009/04/02 19:22:03 | 00,105,472 | -HS- | M] (ICQ) – C:\Windows\System32\norupeze.dll
[2009/04/02 19:22:00 | 00,061,440 | -HS- | M] () – C:\Windows\System32\davagadu.exe
[2009/04/01 07:08:57 | 00,000,680 | —- | M] () – C:\Users\Adam\AppData\Local\d3d9caps.dat
[2009/03/31 18:10:21 | 00,000,552 | —- | M] () – C:\Users\Adam\AppData\Local\d3d8caps.dat
[2009/03/31 14:08:05 | 00,000,002 | —- | M] () – C:\-1566217163
[2009/03/26 00:10:46 | 00,037,355 | —- | M] () – C:\Users\Adam\Desktop\n1063746744_166822_6363615.jpg
[2009/03/25 07:19:37 | 00,224,256 | —- | M] () – C:\Users\Adam\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/24 21:42:28 | 00,142,336 | -HS- | M] (ICQ) – C:\Windows\System32\pazesomu.dll
[2009/03/24 21:42:28 | 00,142,336 | -HS- | M] (ICQ) – C:\Windows\System32\ksougj.dll
[2009/03/24 21:42:26 | 00,107,520 | -HS- | M] (ICQ) – C:\Windows\System32\yikelido.dll
[2009/03/24 10:03:43 | 01,420,795 | -HS- | M] () – C:\Windows\System32\ebabales.ini
[2009/03/24 09:42:22 | 00,141,824 | -HS- | M] (ICQ) – C:\Windows\System32\pevowuhi.dll
[2009/03/24 09:42:22 | 00,141,824 | -HS- | M] (ICQ) – C:\Windows\System32\dlzynh.dll
[2009/03/24 09:42:22 | 00,108,544 | -HS- | M] (ICQ) – C:\Windows\System32\kigirefu.dll
[2009/03/24 09:42:20 | 00,100,352 | —- | M] (ICQ) – C:\Windows\System32\selababe.dll
[2009/03/23 22:59:02 | 00,129,664 | —- | M] () – C:\Users\Adam\Desktop\artofbookcover.jpg
[2009/03/23 22:04:36 | 01,420,795 | -HS- | M] () – C:\Windows\System32\ivoreroj.ini
[2009/03/23 21:42:20 | 00,108,032 | -HS- | M] (ICQ) – C:\Windows\System32\zatidege.dll
[2009/03/23 21:42:19 | 00,141,312 | -HS- | M] (ICQ) – C:\Windows\System32\jahitipa.dll
[2009/03/23 21:42:19 | 00,141,312 | -HS- | M] (ICQ) – C:\Windows\System32\aknvvd.dll
[2009/03/23 21:42:17 | 00,102,400 | —- | M] (ICQ) – C:\Windows\System32\jorerovi.dll
[2009/03/23 10:03:31 | 01,802,266 | -HS- | M] () – C:\Windows\System32\avigehem.ini
[2009/03/23 09:42:12 | 00,140,800 | -HS- | M] (ICQ) – C:\Windows\System32\lurujako.dll
[2009/03/23 09:42:12 | 00,140,800 | -HS- | M] (ICQ) – C:\Windows\System32\grsziv.dll
[2009/03/23 09:42:07 | 00,106,496 | -HS- | M] (ICQ) – C:\Windows\System32\jikodiwa.dll
[2009/03/23 09:42:07 | 00,102,912 | —- | M] (ICQ) – C:\Windows\System32\mehegiva.dll
[2009/03/22 22:03:22 | 01,801,911 | -HS- | M] () – C:\Windows\System32\uwuwudun.ini
[2009/03/22 21:41:59 | 00,140,800 | -HS- | M] (ICQ) – C:\Windows\System32\sebiluza.dll
[2009/03/22 21:41:59 | 00,140,800 | -HS- | M] (ICQ) – C:\Windows\System32\rhnvxs.dll
[2009/03/22 21:41:56 | 00,101,376 | —- | M] (ICQ) – C:\Windows\System32\nuduwuwu.dll
[2009/03/22 21:41:55 | 00,105,472 | -HS- | M] (ICQ) – C:\Windows\System32\yupujeba.dll
[2009/03/22 21:09:00 | 00,436,629 | —- | M] () – C:\Users\Adam\Desktop\Backroom Boom Boom Rendered.wav.asd
[2009/03/22 21:05:47 | 37,895,472 | —- | M] () – C:\Users\Adam\Desktop\Backroom Boom Boom Rendered.wav
[2009/03/22 16:22:22 | 01,801,920 | -HS- | M] () – C:\Windows\System32\idiwalur.ini
[2009/03/22 09:41:49 | 00,104,960 | -HS- | M] (ICQ) – C:\Windows\System32\gomewihe.dll
[2009/03/22 09:41:47 | 00,140,800 | -HS- | M] (ICQ) – C:\Windows\System32\nyytqc.dll
[2009/03/22 09:41:47 | 00,140,800 | -HS- | M] (ICQ) – C:\Windows\System32\lopisedu.dll
[2009/03/22 09:41:45 | 00,101,888 | —- | M] (ICQ) – C:\Windows\System32\rulawidi.dll
[2009/03/21 22:03:01 | 01,801,911 | -HS- | M] () – C:\Windows\System32\oyijejer.ini
[2009/03/21 21:41:39 | 00,141,824 | -HS- | M] (ICQ) – C:\Windows\System32\nopefine.dll
[2009/03/21 21:41:39 | 00,141,824 | -HS- | M] (ICQ) – C:\Windows\System32\cvhxxw.dll
[2009/03/21 21:41:36 | 00,101,888 | —- | M] (ICQ) – C:\Windows\System32\rejejiyo.dll
[2009/03/21 21:41:35 | 00,104,448 | -HS- | M] (ICQ) – C:\Windows\System32\zutedizo.dll
[2009/03/21 19:21:32 | 01,524,736 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll
[2009/03/21 19:21:32 | 00,051,224 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wuauclt.exe
[2009/03/21 19:21:32 | 00,043,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2009/03/21 19:21:31 | 01,809,944 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wuaueng.dll
[2009/03/21 19:18:35 | 00,162,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2009/03/21 19:18:35 | 00,031,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2009/03/21 19:14:40 | 01,801,920 | -HS- | M] () – C:\Windows\System32\osaradeh.ini
[2009/03/21 09:41:27 | 00,142,848 | -HS- | M] (ICQ) – C:\Windows\System32\tekigobe.dll
[2009/03/21 09:41:27 | 00,142,848 | -HS- | M] (ICQ) – C:\Windows\System32\ipiiko.dll
[2009/03/21 09:41:26 | 00,107,520 | -HS- | M] (ICQ) – C:\Windows\System32\fuyozafe.dll
[2009/03/21 09:41:25 | 00,098,816 | —- | M] (ICQ) – C:\Windows\System32\hedaraso.dll
[2009/03/20 22:02:43 | 01,801,911 | -HS- | M] () – C:\Windows\System32\ofuhesek.ini
[2009/03/20 21:41:20 | 00,106,496 | -HS- | M] (ICQ) – C:\Windows\System32\lokabuki.dll
[2009/03/20 21:41:20 | 00,101,888 | —- | M] (ICQ) – C:\Windows\System32\kesehufo.dll
[2009/03/20 21:41:18 | 00,142,848 | -HS- | M] (ICQ) – C:\Windows\System32\xfpwaf.dll
[2009/03/20 21:41:18 | 00,142,848 | -HS- | M] (ICQ) – C:\Windows\System32\kewakiti.dll
[2009/03/20 18:35:39 | 01,799,769 | -HS- | M] () – C:\Windows\System32\ebadegez.ini
[2009/03/19 23:54:52 | 01,799,218 | -HS- | M] () – C:\Windows\System32\ujekunot.ini
[2009/03/19 18:28:27 | 01,795,884 | -HS- | M] () – C:\Windows\System32\obuzokit.ini
[2009/03/19 07:05:03 | 01,795,884 | -HS- | M] () – C:\Windows\System32\ufosonev.ini
[2009/03/18 17:42:59 | 01,957,494 | -HS- | M] () – C:\Windows\System32\ifirewur.ini
[2009/03/17 17:01:22 | 01,933,175 | -HS- | M] () – C:\Windows\System32\ihawureg.ini
[2009/03/17 03:07:00 | 01,932,881 | -HS- | M] () – C:\Windows\System32\efaheyol.ini
[2009/03/16 10:01:02 | 01,912,660 | -HS- | M] () – C:\Windows\System32\uzetobav.ini
[2009/03/15 22:00:53 | 01,912,660 | -HS- | M] () – C:\Windows\System32\utopunip.ini
[2009/03/15 10:00:42 | 01,912,660 | -HS- | M] () – C:\Windows\System32\urelowid.ini
[2009/03/14 22:00:33 | 01,912,660 | -HS- | M] () – C:\Windows\System32\irelefog.ini
[2009/03/14 10:02:35 | 00,001,874 | —- | M] () – C:\Users\Adam\Desktop\HijackThis.lnk
[2009/03/14 10:00:26 | 01,912,660 | -HS- | M] () – C:\Windows\System32\ubuvikes.ini
[2009/03/14 07:54:48 | 00,015,688 | —- | M] () – C:\Windows\System32\lsdelete.exe
[2009/03/14 07:54:19 | 00,064,160 | —- | M] (Lavasoft AB) – C:\Windows\System32\drivers\Lbd.sys
[2009/03/13 22:00:16 | 01,912,660 | -HS- | M] () – C:\Windows\System32\utoveton.ini
[2009/03/13 10:00:38 | 01,912,680 | -HS- | M] () – C:\Windows\System32\arirayew.ini
[2009/03/12 23:20:33 | 01,808,081 | -HS- | M] () – C:\Windows\System32\ajedafet.ini
[2009/03/12 21:38:07 | 00,142,336 | -HS- | M] () – C:\Windows\System32\talopoja.dll
[2009/03/12 21:38:07 | 00,142,336 | -HS- | M] () – C:\Windows\System32\noxnkk.dll
[2009/03/12 21:38:04 | 00,108,032 | -HS- | M] () – C:\Windows\System32\remizalu.dll
[2009/03/12 12:23:37 | 01,808,081 | -HS- | M] () – C:\Windows\System32\eyanofef.ini
[2009/03/12 09:37:52 | 00,143,360 | -HS- | M] () – C:\Windows\System32\zmvxeu.dll
[2009/03/12 09:37:52 | 00,143,360 | -HS- | M] () – C:\Windows\System32\ramemori.dll
[2009/03/12 09:37:50 | 00,105,984 | -HS- | M] () – C:\Windows\System32\hitoremi.dll
[2009/03/11 21:37:47 | 00,108,032 | -HS- | M] () – C:\Windows\System32\nemulopi.dll
[2009/03/11 09:37:35 | 00,107,008 | -HS- | M] () – C:\Windows\System32\zovadejo.dll
[2009/03/10 21:37:18 | 00,108,032 | -HS- | M] () – C:\Windows\System32\davewodu.dll
[2009/03/09 21:36:59 | 00,107,520 | -HS- | M] () – C:\Windows\System32\howewufu.dll
[2009/03/09 09:36:36 | 00,105,984 | -HS- | M] () – C:\Windows\System32\tutogupo.dll
[2009/03/08 20:36:23 | 00,107,520 | -HS- | M] () – C:\Windows\System32\setegabo.dll
[2009/03/08 08:36:19 | 00,107,520 | -HS- | M] () – C:\Windows\System32\gidalepu.dll
[2009/03/07 20:36:16 | 00,108,032 | -HS- | M] () – C:\Windows\System32\jeruwuke.dll
[2009/03/07 08:50:00 | 00,001,007 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2009/03/07 08:47:22 | 34,543,112 | —- | M] (Lavasoft ) – C:\Users\Adam\Desktop\Ad-AwareAE.exe
[2009/03/07 08:36:37 | 00,105,984 | -HS- | M] () – C:\Windows\System32\gijudefu.dll

========== LOP Check ==========

[2009/04/04 07:50:55 | 00,000,472 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2009/04/03 07:24:06 | 00,000,006 | -H– | M] () – C:\Windows\Tasks\SA.DAT
[2009/03/13 16:30:07 | 00,032,638 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 43520 bytes -> C:\Windows\System32:nskrnl32.exe
@Alternate Data Stream - 1073 bytes -> C:\Windows\System32:nskrnl32
< End of report >
Lots and lots to kill - I am not sure I got all of them as there were so many - so on completion re-run OTListit again for a double check

Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
    O2 - BHO: (no name) - {a84e6d05-9fad-4976-af9e-24b9c775dffd} - C:\Windows\system32\lakofote.dll ()
    O4 - HKLM..\Run: [a2a56c9a] rundll32.exe "C:\Windows\system32\kegorafa.dll",b (ICQ)
    O4 - HKLM..\Run: [CPMa1965f06] Rundll32.exe "c:\windows\system32\jinohila.dll",a ()
    O4 - HKLM..\Run: [fumogogiha] Rundll32.exe "C:\Windows\system32\jebihote.dll",s ()
    O20 - AppInit_DLLs: (c:\windows\system32\jinohila.dll) - c:\windows\system32\jinohila.dll ()
    O20 - AppInit_DLLs: (C:\Windows\system32\wijariwo.dll) - C:\Windows\system32\wijariwo.dll ()
    O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\jinohila.dll ()
    O22 - SharedTaskScheduler: {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - STS - c:\windows\system32\jinohila.dll ()
    
    :Files
    C:\Windows\System32\afarogek.ini
    C:\Windows\System32\ibigutik.ini
    C:\Windows\System32\iyakimer.ini
    C:\Windows\System32\enilowes.ini
    C:\Windows\System32\asivefeh.ini
    C:\Windows\System32\arovofuh.ini
    C:\-1566217163
    C:\Windows\System32\ksougj.dll
    C:\Windows\System32\ogajodig.ini
    C:\Windows\System32\dlzynh.dll
    C:\Windows\System32\ebabales.ini
    C:\Windows\System32\aknvvd.dll
    C:\Windows\System32\ivoreroj.ini
    C:\Windows\System32\grsziv.dll
    C:\Windows\System32\avigehem.ini
    C:\Windows\System32\rhnvxs.dll
    C:\Windows\System32\uwuwudun.ini
    C:\Windows\System32\nyytqc.dll
    C:\Windows\System32\idiwalur.ini
    C:\Windows\System32\cvhxxw.dll
    C:\Windows\System32\oyijejer.ini
    c:\Windows\System32\ipiiko.dll
    C:\Windows\System32\osaradeh.ini
    C:\Windows\System32\ofuhesek.ini
    C:\Windows\System32\xfpwaf.dll
    C:\Windows\System32\ebadegez.ini
    C:\Windows\System32\ujekunot.ini
    C:\Windows\System32\obuzokit.ini
    C:\Windows\System32\ufosonev.ini
    C:\Windows\System32\ifirewur.ini
    C:\Windows\System32\ihawureg.ini
    C:\Windows\System32\efaheyol.ini
    C:\Windows\System32\uzetobav.ini
    C:\Windows\System32\utopunip.ini
    C:\Windows\System32\urelowid.ini
    C:\Windows\System32\irelefog.ini
    C:\Windows\System32\ubuvikes.ini
    C:\Windows\System32\utoveton.ini
    C:\Windows\System32\arirayew.ini
    C:\Windows\System32\ajedafet.ini
    C:\Windows\System32\noxnkk.dll
    C:\Windows\System32\eyanofef.ini
    C:\Windows\System32\zmvxeu.dll
    C:\Windows\System32\jinohila.dll
    C:\Windows\System32\ramemori.dll
    C:\Windows\System32\talopoja.dll
    C:\Windows\System32\remizalu.dll
    C:\Windows\System32\nemulopi.dll
    C:\Windows\System32\jeruwuke.dll
    C:\Windows\System32\davewodu.dll
    C:\Windows\System32\setegabo.dll
    C:\Windows\System32\howewufu.dll
    C:\Windows\System32\gidalepu.dll
    C:\Windows\System32\zovadejo.dll
    C:\Windows\System32\tutogupo.dll
    C:\Windows\System32\hitoremi.dll
    C:\Windows\System32\gijudefu.dll
    C:\Windows\System32\wijariwo.dll
    C:\Windows\System32\lakofote.dll
    C:\Windows\System32\jebihote.dll
    C:\Windows\System32\wegayalu.dll
    C:\Windows\System32\tuyotete.dll
    C:\Windows\System32\rafinuno.dll
    C:\Windows\System32\hajifobu.dll
    C:\Windows\System32\kujadebo
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )
OTListIt logfile created on: 4/5/2009 10:27:25 AM - Run 2
OTListIt2 by OldTimer - Version 2.0.11.0 Folder = C:\Users\Adam\Desktop
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1013.41 Mb Total Physical Memory | 466.36 Mb Available Physical Memory | 46.02% Memory free
2.24 Gb Paging File | 1.66 Gb Available in Paging File | 73.91% Paging File free
Paging file location(s): ?:\pagefile.sys;

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223.06 Gb Total Space | 93.44 Gb Free Space | 41.89% Space Free | Partition Type: NTFS
Drive D: | 9.82 Gb Total Space | 4.47 Gb Free Space | 45.53% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ADAM-PC
Current User Name: Adam
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Windows\system32\AUDIODG.EXE (Microsoft Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Windows\system32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\Prevx\prevx.exe (Prevx)
PRC - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe ()
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
PRC - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
PRC - c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
PRC - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe (SigmaTel, Inc.)
PRC - C:\Windows\system32\WUDFHost.exe (Microsoft Corporation)
PRC - C:\Windows\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Windows\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Prevx\prevx.exe (Prevx)
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe (Intel® Corporation)
PRC - C:\Windows\zHotkey.exe ()
PRC - C:\Windows\ModPS2Key.exe (Chicony)
PRC - C:\Windows\sttray.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Windows\System32\hkcmd.exe (Intel Corporation)
PRC - C:\Windows\System32\igfxpers.exe (Intel Corporation)
PRC - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe (Intel® Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe (Intel® Corporation)
PRC - C:\Windows\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Users\Adam\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (AgereModemAudio [Auto | Running]) – C:\Windows\system32\agrsmsvc.exe (Agere Systems)
SRV - (AlertService [On_Demand | Running]) – C:\Program Files\Intel\IntelDH\CCU\AlertService.exe (Intel® Corporation)
SRV - (Automatic LiveUpdate Scheduler [Auto | Stopped]) – File not found
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CSIScanner [Auto | Running]) – C:\Program Files\Prevx\prevx.exe (Prevx)
SRV - (DQLWinService [Auto | Running]) – C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe ()
SRV - (ehRecvr [On_Demand | Stopped]) – C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) – C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (IAANTMON [Auto | Running]) – C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Intel Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (ISSM [On_Demand | Stopped]) – C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe (Intel® Corporation)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LiveUpdate [Disabled | Stopped]) – File not found
SRV - (M1 Server [On_Demand | Stopped]) – C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe ()
SRV - (McciCMService [Auto | Running]) – C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
SRV - (MCLServiceATL [On_Demand | Stopped]) – C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe (Intel® Corporation)
SRV - (MSSQL$MSSMLBIZ [Auto | Running]) – c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (MSSQLServerADHelper [Disabled | Stopped]) – c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PrismXL [Auto | Running]) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
SRV - (Remote UI Service [On_Demand | Stopped]) – C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe (Intel® Corporation)
SRV - (SQLBrowser [Disabled | Stopped]) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation)
SRV - (SQLWriter [Auto | Running]) – c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation)
SRV - (STacSV [Auto | Running]) – C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe (SigmaTel, Inc.)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ac97intc [On_Demand | Stopped]) – C:\Windows\system32\drivers\ac97intc.sys (Intel Corporation)
DRV - (adp94xx [Disabled | Stopped]) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (adpahci [Disabled | Stopped]) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (adpu160m [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (adpu320 [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (AgereSoftModem [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\AGRSM.sys (Agere Systems)
DRV - (aic78xx [Disabled | Stopped]) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (aliide [Disabled | Stopped]) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (arc [Disabled | Stopped]) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (arcsas [Disabled | Stopped]) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (bcm4sbxp [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (BrFiltLo [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (Brserid [Disabled | Stopped]) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrSerWdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer [On_Demand | Stopped]) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (Cdr4_xp [System | Running]) – C:\Windows\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (Cdralw2k [System | Running]) – C:\Windows\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (cmdide [Disabled | Stopped]) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (E100B [On_Demand | Running]) – C:\Windows\system32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (E1G60 [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\E1G60I32.sys (Intel Corporation)
DRV - (echo24 [On_Demand | Running]) – C:\Windows\system32\drivers\echo24.sys (Echo Digital Audio Corp.)
DRV - (elxstor [Disabled | Stopped]) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (FVNETusb [On_Demand | Running]) – C:\Windows\system32\DRIVERS\vnet558x.sys (ATMEL)
DRV - (HpCISSs [Disabled | Stopped]) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (ialm [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\igdkmd32.sys (Intel Corporation)
DRV - (iaStor [Boot | Running]) – C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (iaStorV [Boot | Running]) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (igfx [On_Demand | Running]) – C:\Windows\system32\DRIVERS\igdkmd32.sys (Intel Corporation)
DRV - (iirsp [Disabled | Stopped]) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (IntelDH [On_Demand | Running]) – C:\Windows\System32\Drivers\IntelDH.sys (Intel Corporation)
DRV - (iteatapi [Disabled | Stopped]) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (iteraid [Disabled | Stopped]) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (Lbd [Boot | Running]) – C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (LSI_FC [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (LSI_SAS [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (LSI_SCSI [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (megasas [Disabled | Stopped]) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Mraid35x [Disabled | Stopped]) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (MREMP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (NETw2v32 [On_Demand | Stopped]) – C:\Windows\system32\DRIVERS\NETw2v32.sys (Intel® Corporation)
DRV - (nfrd960 [Disabled | Stopped]) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (nmsgopro [Auto | Running]) – C:\Windows\system32\DRIVERS\nmsgopro.sys (Gteko Ltd.)
DRV - (nmsunidr [Auto | Running]) – C:\Windows\system32\DRIVERS\nmsunidr.sys (Gteko Ltd.)
DRV - (ntrigdigi [Disabled | Stopped]) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (nvraid [Disabled | Stopped]) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor [Disabled | Stopped]) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (PxHelp20 [Boot | Running]) – C:\Windows\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (pxscan [Boot | Running]) – C:\Windows\System32\drivers\pxscan.sys (Prevx)
DRV - (ql2300 [Disabled | Stopped]) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (ql40xx [Disabled | Stopped]) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (secdrv [Auto | Running]) – C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiSRaid2 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (SiSRaid4 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (STHDA [On_Demand | Running]) – C:\Windows\system32\drivers\stwrt.sys (SigmaTel, Inc.)
DRV - (Symc8xx [Disabled | Stopped]) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_hi [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Sym_u3 [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (SynasUSB [On_Demand | Stopped]) – C:\Windows\system32\drivers\SynasUSB.sys (SIA Syncrosoft)
DRV - (TSHWMDTCP [On_Demand | Stopped]) – C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.sys ()
DRV - (uliahci [Disabled | Stopped]) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (UlSata [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (ulsata2 [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\Windows\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (viaide [Disabled | Stopped]) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (vsmraid [Disabled | Stopped]) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch…TP&M;=GT5404
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…TP&M;=GT5404
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gateway.com/g/sidepanel.html?Ch…TP&M;=GT5404

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…TP&M;=GT5404
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2}:0.9.84
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071101000055
FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:3.0.0
FF - prefs.js..extensions.enabledItems: {2e61e246-e640-4c56-b1ed-f146dbed48cd}:0.7.6
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/04 07:54:18 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/04 07:54:18 | 00,000,000 | —D | M]

[2009/03/07 10:55:27 | 00,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\mozilla\Extensions
[2009/03/07 10:55:27 | 00,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/04 19:53:47 | 00,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\mozilla\Firefox\Profiles\099nppdp.default\extensions
[2009/03/07 10:56:03 | 00,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\mozilla\Firefox\Profiles\099nppdp.default\extensions\{2e61e246-e640-4c56-b1ed-f146dbed48cd}
[2009/03/07 10:56:03 | 00,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\mozilla\Firefox\Profiles\099nppdp.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2008/07/29 03:40:17 | 00,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\mozilla\Firefox\Profiles\099nppdp.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
[2009/02/08 18:44:12 | 00,000,000 | —D | M] – C:\Users\Adam\AppData\Roaming\mozilla\Firefox\Profiles\099nppdp.default\extensions\[removed]
[2009/03/07 10:55:28 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/04/04 07:54:18 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/04/04 07:54:02 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/04 07:54:02 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/04/04 07:54:12 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/04 07:54:12 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/04 07:54:12 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/04 07:54:12 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/04 07:54:12 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/04 07:54:12 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/04 07:54:13 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (1070 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 82.98.231.89 browser-security.microsoft.com
O1 - Hosts: 82.98.231.89 best-click-scanner.info
O1 - Hosts: 82.98.231.89 antivirus-xp-pro-2009.com
O1 - Hosts: 82.98.231.89 microsoft.infosecuritycenter.com
O1 - Hosts: 82.98.231.89 microsoft.softwaresecurityhelp.com
O1 - Hosts: 82.98.231.89 onlinenotifyq.net
O1 - Hosts: 82.98.231.89 antivirusxp-pro-2009.com
O1 - Hosts: 82.98.231.89 microsoft.browser-security-center.com
O2 - BHO: (no name) - {a84e6d05-9fad-4976-af9e-24b9c775dffd} - C:\Windows\system32\lakofote.dll File not found
O4 - HKLM..\Run: [BigFix] c:\program files\Bigfix\bigfix.exe /atstartup File not found
O4 - HKLM..\Run: [CCUTRAYICON] C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe (Intel® Corporation)
O4 - HKLM..\Run: [CHotkey] zHotkey.exe ()
O4 - HKLM..\Run: [CPMa1965f06] Rundll32.exe "c:\windows\system32\gubagedu.dll",a ()
O4 - HKLM..\Run: [fumogogiha] Rundll32.exe "C:\Windows\system32\jebihote.dll",s File not found
O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [ModPS2] ModPS2Key.exe (Chicony)
O4 - HKLM..\Run: [NMSSupport] "C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup (Intel Corporation)
O4 - HKLM..\Run: [Persistence] C:\Windows\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [SigmatelSysTrayApp] sttray.exe (SigmaTel, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (\w耀閂䬏蠀d\wi閅䬏蠀d\wi閈䬏耀) - File not found
O20 - AppInit_DLLs: (.) - File not found
O20 - AppInit_DLLs: (開䬏耀#:\䬎耀閎䬏耀&:\'Y閑) - File not found
O20 - AppInit_DLLs: (C:\Windows\system32\wijariwo.dll) - C:\Windows\system32\wijariwo.dll File not found
O20 - AppInit_DLLs: (c:\windows\system32\howewufu.dll) - c:\windows\system32\howewufu.dll File not found
O20 - AppInit_DLLs: (c:\windows\system32\gubagedu.dll) - c:\windows\system32\gubagedu.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\system32\igfxdev.dll (Intel Corporation)
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\gubagedu.dll ()
O22 - SharedTaskScheduler: {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - STS - c:\windows\system32\gubagedu.dll ()
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\autoexec.bat () - [ NTFS ]
O32 - Autorun File - D:\autorun.inf () - [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()

========== Files/Folders - Created Within 30 Days ==========

[2 C:\Windows\System32\*.tmp files]
[2009/04/05 10:24:06 | 00,974,196 | -H– | C] () – C:\Users\Adam\AppData\Local\IconCache.db
[2009/04/05 10:22:40 | 00,001,744 | -H– | C] () – C:\Windows\System32\kujadebo
[2009/04/05 10:21:06 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/04/05 09:50:05 | 00,499,200 | —- | C] (OldTimer Tools) – C:\Users\Adam\Desktop\OTListIt2.exe
[2009/04/05 09:23:54 | 00,022,024 | —- | C] (Prevx) – C:\Windows\System32\drivers\pxscan.sys
[2009/04/05 09:23:54 | 00,000,000 | —D | C] – C:\Program Files\Prevx
[2009/04/05 09:23:50 | 00,000,000 | —D | C] – C:\ProgramData\PrevxCSI
[2009/04/05 09:23:49 | 00,000,065 | —- | C] () – C:\Windows\wininit.ini
[2009/04/03 21:10:29 | 00,054,156 | -H– | C] () – C:\Windows\QTFont.qfn
[2009/04/03 21:10:29 | 00,001,409 | —- | C] () – C:\Windows\QTFont.for
[2009/04/02 19:21:05 | 10,632,19200 | -HS- | C] () – C:\hiberfil.sys
[2009/04/01 07:08:17 | 00,000,680 | —- | C] () – C:\Users\Adam\AppData\Local\d3d9caps.dat
[2009/03/31 18:10:21 | 00,000,552 | —- | C] () – C:\Users\Adam\AppData\Local\d3d8caps.dat
[2009/03/26 00:10:41 | 00,037,355 | —- | C] () – C:\Users\Adam\Desktop\n1063746744_166822_6363615.jpg
[2009/03/23 22:59:00 | 00,129,664 | —- | C] () – C:\Users\Adam\Desktop\artofbookcover.jpg
[2009/03/22 21:09:00 | 00,436,629 | —- | C] () – C:\Users\Adam\Desktop\Backroom Boom Boom Rendered.wav.asd
[2009/03/22 21:05:46 | 37,895,472 | —- | C] () – C:\Users\Adam\Desktop\Backroom Boom Boom Rendered.wav
[2009/03/21 19:21:32 | 01,524,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll
[2009/03/21 19:21:32 | 00,051,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuauclt.exe
[2009/03/21 19:21:32 | 00,043,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2009/03/21 19:21:31 | 01,809,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuaueng.dll
[2009/03/21 19:18:35 | 00,162,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2009/03/21 19:18:35 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2009/03/16 20:54:24 | 00,000,000 | R–D | C] – C:\Users\Adam\Desktop\Backroom Boom Boom Project
[2009/03/16 19:22:09 | 00,000,000 | —D | C] – C:\VundoFix Backups
[2009/03/14 10:02:35 | 00,001,874 | —- | C] () – C:\Users\Adam\Desktop\HijackThis.lnk
[2009/03/14 10:02:35 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/03/14 07:55:31 | 00,064,160 | —- | C] (Lavasoft AB) – C:\Windows\System32\drivers\Lbd.sys
[2009/03/07 09:08:13 | 00,015,688 | —- | C] () – C:\Windows\System32\lsdelete.exe
[2009/03/07 08:51:01 | 00,000,472 | —- | C] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2009/03/07 08:50:46 | 00,000,000 | —D | C] – C:\Windows\System32\DRVSTORE
[2009/03/07 08:50:02 | 00,000,000 | -H-D | C] – C:\ProgramData\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/03/07 08:50:00 | 00,001,007 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2009/03/07 08:49:47 | 00,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2009/03/07 08:49:47 | 00,000,000 | —D | C] – C:\Program Files\Lavasoft
[2009/03/07 08:44:39 | 34,543,112 | —- | C] (Lavasoft ) – C:\Users\Adam\Desktop\Ad-AwareAE.exe
[2009/01/08 00:39:26 | 00,000,016 | —- | C] () – C:\Windows\System32\msvcsv60.dll
[2009/01/05 10:22:43 | 00,104,960 | -HS- | C] () – C:\Windows\System32\gubagedu.dll
[2008/07/22 18:51:01 | 00,000,092 | —- | C] () – C:\Windows\mp3wavcon.ini
[2008/07/22 18:26:58 | 00,237,568 | —- | C] () – C:\Windows\System32\lame_enc.dll
[2008/01/10 07:16:20 | 00,159,839 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2008/01/10 07:15:30 | 00,755,027 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2007/09/25 16:59:58 | 00,007,168 | —- | C] () – C:\Windows\System32\Echo24Wrap.dll
[2007/09/04 11:56:10 | 00,164,352 | —- | C] () – C:\Windows\System32\unrar.dll
[2007/05/07 09:11:09 | 00,000,061 | —- | C] () – C:\Windows\SBWIN.INI
[2007/03/27 02:55:48 | 03,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2007/01/25 14:53:19 | 00,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1114.dll
[2007/01/25 14:53:16 | 00,077,824 | —- | C] () – C:\Windows\System32\hccutils.dll
[2007/01/25 14:20:32 | 00,532,544 | —- | C] () – C:\Windows\PIC.dll
[2007/01/25 14:20:32 | 00,024,576 | —- | C] () – C:\Windows\HKNTDLL.dll
[2006/12/12 11:24:42 | 00,012,288 | —- | C] () – C:\Windows\System32\DivXWMPExtType.dll
[2006/12/12 11:13:50 | 00,204,800 | —- | C] () – C:\Windows\System32\igfxCoIn_v1147.dll
[2006/12/12 10:02:50 | 00,053,248 | —- | C] () – C:\Windows\System32\oemdspif.dll
[2006/11/22 17:16:18 | 00,003,612 | —- | C] () – C:\Windows\ReaderString.ini
[2006/11/21 13:50:06 | 00,000,037 | —- | C] () – C:\Windows\sunkist.ini
[2006/11/02 07:56:07 | 00,000,082 | -HS- | C] () – C:\Windows\System32\desktop.ini
[2006/11/02 07:35:32 | 00,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 05:33:01 | 00,786,636 | —- | C] () – C:\Windows\System32\PerfStringBackup.INI
[2006/11/02 05:25:21 | 00,061,440 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2006/11/02 05:24:31 | 00,001,405 | —- | C] () – C:\Windows\msdfmap.ini
[2006/11/02 05:23:31 | 00,000,244 | —- | C] () – C:\Windows\win.ini
[2006/11/02 05:23:31 | 00,000,219 | —- | C] () – C:\Windows\system.ini
[2006/11/02 03:23:38 | 00,055,858 | —- | C] () – C:\Windows\System32\tcpmon.ini
[2006/11/02 02:40:29 | 00,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 02:09:45 | 00,027,097 | —- | C] () – C:\Windows\System32\country.sys
[2006/11/02 02:09:44 | 00,042,809 | —- | C] () – C:\Windows\System32\KEY01.SYS
[2006/11/02 02:09:44 | 00,042,537 | —- | C] () – C:\Windows\System32\KEYBOARD.SYS
[2006/11/02 02:09:42 | 00,009,029 | —- | C] () – C:\Windows\System32\ANSI.SYS
[2006/11/02 02:09:41 | 00,004,768 | —- | C] () – C:\Windows\System32\HIMEM.SYS
[2006/11/02 02:09:40 | 00,029,274 | —- | C] () – C:\Windows\System32\NTDOS412.SYS
[2006/11/02 02:09:38 | 00,029,370 | —- | C] () – C:\Windows\System32\NTDOS411.SYS
[2006/11/02 02:09:35 | 00,029,146 | —- | C] () – C:\Windows\System32\NTDOS404.SYS
[2006/11/02 02:09:31 | 00,029,146 | —- | C] () – C:\Windows\System32\NTDOS804.SYS
[2006/11/02 02:09:29 | 00,027,866 | —- | C] () – C:\Windows\System32\NTDOS.SYS
[2006/11/02 02:09:26 | 00,035,536 | —- | C] () – C:\Windows\System32\NTIO412.SYS
[2006/11/02 02:09:24 | 00,035,776 | —- | C] () – C:\Windows\System32\NTIO411.SYS
[2006/11/02 02:09:23 | 00,034,672 | —- | C] () – C:\Windows\System32\NTIO404.SYS
[2006/11/02 02:09:22 | 00,034,672 | —- | C] () – C:\Windows\System32\NTIO804.SYS
[2006/11/02 02:09:20 | 00,033,952 | —- | C] () – C:\Windows\System32\NTIO.SYS
[2006/11/02 01:47:51 | 00,364,544 | —- | C] () – C:\Windows\System32\msjetoledb40.dll
[2006/11/02 01:25:08 | 00,013,312 | —- | C] () – C:\Windows\System32\win87em.dll
[2006/10/03 10:53:03 | 00,069,632 | —- | C] () – C:\Windows\System32\com.fxpansion.fxshared.dll
[2006/06/23 12:09:34 | 00,019,968 | R— | C] () – C:\Windows\System32\cpuinf32.dll
[2006/05/26 08:29:14 | 00,005,120 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2006/04/03 07:26:36 | 00,000,547 | —- | C] () – C:\Windows\System32\ff_vfw.dll.manifest

========== Files - Modified Within 30 Days ==========

[2 C:\Windows\System32\*.tmp files]
[1 C:\Windows\*.tmp files]
[2009/04/05 10:29:59 | 00,786,636 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2009/04/05 10:29:59 | 00,668,022 | —- | M] () – C:\Windows\System32\perfh009.dat
[2009/04/05 10:29:59 | 00,122,184 | —- | M] () – C:\Windows\System32\perfc009.dat
[2009/04/05 10:25:38 | 00,003,072 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/04/05 10:25:38 | 00,003,072 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/04/05 10:25:37 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/04/05 10:25:31 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/04/05 10:25:29 | 10,632,19200 | -HS- | M] () – C:\hiberfil.sys
[2009/04/05 10:24:25 | 00,001,744 | -H– | M] () – C:\Windows\System32\kujadebo
[2009/04/05 10:24:06 | 00,974,196 | -H– | M] () – C:\Users\Adam\AppData\Local\IconCache.db
[2009/04/05 10:22:46 | 00,100,352 | -HS- | M] (ICQ) – C:\Windows\System32\ramomeje.dll
[2009/04/05 10:22:44 | 00,104,960 | -HS- | M] () – C:\Windows\System32\gubagedu.dll
[2009/04/05 10:22:44 | 00,001,070 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2009/04/05 10:22:43 | 00,061,440 | -HS- | M] () – C:\Windows\System32\wepofemu.exe
[2009/04/05 09:50:07 | 00,499,200 | —- | M] (OldTimer Tools) – C:\Users\Adam\Desktop\OTListIt2.exe
[2009/04/05 09:23:54 | 00,022,024 | —- | M] (Prevx) – C:\Windows\System32\drivers\pxscan.sys
[2009/04/05 09:23:49 | 00,000,065 | —- | M] () – C:\Windows\wininit.ini
[2009/04/05 07:23:05 | 00,061,440 | -HS- | M] () – C:\Windows\System32\juhonemo.exe
[2009/04/04 19:22:45 | 00,099,840 | —- | M] (ICQ) – C:\Windows\System32\kitugibi.dll
[2009/04/04 19:22:44 | 00,061,440 | -HS- | M] () – C:\Windows\System32\bubesomu.exe
[2009/04/04 19:22:43 | 00,106,496 | -HS- | M] (ICQ) – C:\Windows\System32\zayiwomo.dll
[2009/04/04 07:50:55 | 00,000,472 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2009/04/04 07:22:39 | 00,104,960 | -HS- | M] (ICQ) – C:\Windows\System32\hareyiyi.dll
[2009/04/04 07:22:39 | 00,100,352 | —- | M] (ICQ) – C:\Windows\System32\remikayi.dll
[2009/04/04 07:22:38 | 00,061,440 | -HS- | M] () – C:\Windows\System32\pibosine.exe
[2009/04/03 21:10:29 | 00,054,156 | -H– | M] () – C:\Windows\QTFont.qfn
[2009/04/03 21:10:29 | 00,001,409 | —- | M] () – C:\Windows\QTFont.for
[2009/04/03 19:22:31 | 00,099,328 | —- | M] (ICQ) – C:\Windows\System32\sewoline.dll
[2009/04/03 19:22:30 | 00,061,440 | -HS- | M] () – C:\Windows\System32\jepeyumu.exe
[2009/04/03 19:22:29 | 00,104,960 | -HS- | M] (ICQ) – C:\Windows\System32\mawisega.dll
[2009/04/03 07:22:24 | 00,061,440 | -HS- | M] () – C:\Windows\System32\zekazide.exe
[2009/04/03 07:22:23 | 00,103,936 | -HS- | M] (ICQ) – C:\Windows\System32\fofajivo.dll
[2009/04/03 07:22:23 | 00,100,352 | —- | M] (ICQ) – C:\Windows\System32\hefevisa.dll
[2009/04/02 19:22:03 | 00,105,472 | -HS- | M] (ICQ) – C:\Windows\System32\norupeze.dll
[2009/04/02 19:22:00 | 00,061,440 | -HS- | M] () – C:\Windows\System32\davagadu.exe
[2009/04/01 07:08:57 | 00,000,680 | —- | M] () – C:\Users\Adam\AppData\Local\d3d9caps.dat
[2009/03/31 18:10:21 | 00,000,552 | —- | M] () – C:\Users\Adam\AppData\Local\d3d8caps.dat
[2009/03/26 00:10:46 | 00,037,355 | —- | M] () – C:\Users\Adam\Desktop\n1063746744_166822_6363615.jpg
[2009/03/25 07:19:37 | 00,224,256 | —- | M] () – C:\Users\Adam\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/24 21:42:28 | 00,142,336 | -HS- | M] (ICQ) – C:\Windows\System32\pazesomu.dll
[2009/03/24 21:42:26 | 00,107,520 | -HS- | M] (ICQ) – C:\Windows\System32\yikelido.dll
[2009/03/24 09:42:22 | 00,141,824 | -HS- | M] (ICQ) – C:\Windows\System32\pevowuhi.dll
[2009/03/24 09:42:22 | 00,108,544 | -HS- | M] (ICQ) – C:\Windows\System32\kigirefu.dll
[2009/03/24 09:42:20 | 00,100,352 | —- | M] (ICQ) – C:\Windows\System32\selababe.dll
[2009/03/23 22:59:02 | 00,129,664 | —- | M] () – C:\Users\Adam\Desktop\artofbookcover.jpg
[2009/03/23 21:42:20 | 00,108,032 | -HS- | M] (ICQ) – C:\Windows\System32\zatidege.dll
[2009/03/23 21:42:19 | 00,141,312 | -HS- | M] (ICQ) – C:\Windows\System32\jahitipa.dll
[2009/03/23 21:42:17 | 00,102,400 | —- | M] (ICQ) – C:\Windows\System32\jorerovi.dll
[2009/03/23 09:42:12 | 00,140,800 | -HS- | M] (ICQ) – C:\Windows\System32\lurujako.dll
[2009/03/23 09:42:07 | 00,106,496 | -HS- | M] (ICQ) – C:\Windows\System32\jikodiwa.dll
[2009/03/23 09:42:07 | 00,102,912 | —- | M] (ICQ) – C:\Windows\System32\mehegiva.dll
[2009/03/22 21:41:59 | 00,140,800 | -HS- | M] (ICQ) – C:\Windows\System32\sebiluza.dll
[2009/03/22 21:41:56 | 00,101,376 | —- | M] (ICQ) – C:\Windows\System32\nuduwuwu.dll
[2009/03/22 21:41:55 | 00,105,472 | -HS- | M] (ICQ) – C:\Windows\System32\yupujeba.dll
[2009/03/22 21:09:00 | 00,436,629 | —- | M] () – C:\Users\Adam\Desktop\Backroom Boom Boom Rendered.wav.asd
[2009/03/22 21:05:47 | 37,895,472 | —- | M] () – C:\Users\Adam\Desktop\Backroom Boom Boom Rendered.wav
[2009/03/22 09:41:49 | 00,104,960 | -HS- | M] (ICQ) – C:\Windows\System32\gomewihe.dll
[2009/03/22 09:41:47 | 00,140,800 | -HS- | M] (ICQ) – C:\Windows\System32\lopisedu.dll
[2009/03/22 09:41:45 | 00,101,888 | —- | M] (ICQ) – C:\Windows\System32\rulawidi.dll
[2009/03/21 21:41:39 | 00,141,824 | -HS- | M] (ICQ) – C:\Windows\System32\nopefine.dll
[2009/03/21 21:41:36 | 00,101,888 | —- | M] (ICQ) – C:\Windows\System32\rejejiyo.dll
[2009/03/21 21:41:35 | 00,104,448 | -HS- | M] (ICQ) – C:\Windows\System32\zutedizo.dll
[2009/03/21 19:21:32 | 01,524,736 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll
[2009/03/21 19:21:32 | 00,051,224 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wuauclt.exe
[2009/03/21 19:21:32 | 00,043,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2009/03/21 19:21:31 | 01,809,944 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wuaueng.dll
[2009/03/21 19:18:35 | 00,162,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2009/03/21 19:18:35 | 00,031,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2009/03/21 09:41:27 | 00,142,848 | -HS- | M] (ICQ) – C:\Windows\System32\tekigobe.dll
[2009/03/21 09:41:26 | 00,107,520 | -HS- | M] (ICQ) – C:\Windows\System32\fuyozafe.dll
[2009/03/21 09:41:25 | 00,098,816 | —- | M] (ICQ) – C:\Windows\System32\hedaraso.dll
[2009/03/20 21:41:20 | 00,106,496 | -HS- | M] (ICQ) – C:\Windows\System32\lokabuki.dll
[2009/03/20 21:41:20 | 00,101,888 | —- | M] (ICQ) – C:\Windows\System32\kesehufo.dll
[2009/03/20 21:41:18 | 00,142,848 | -HS- | M] (ICQ) – C:\Windows\System32\kewakiti.dll
[2009/03/14 10:02:35 | 00,001,874 | —- | M] () – C:\Users\Adam\Desktop\HijackThis.lnk
[2009/03/14 07:54:48 | 00,015,688 | —- | M] () – C:\Windows\System32\lsdelete.exe
[2009/03/14 07:54:19 | 00,064,160 | —- | M] (Lavasoft AB) – C:\Windows\System32\drivers\Lbd.sys
[2009/03/07 08:50:00 | 00,001,007 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2009/03/07 08:47:22 | 34,543,112 | —- | M] (Lavasoft ) – C:\Users\Adam\Desktop\Ad-AwareAE.exe

========== Alternate Data Streams ==========

@Alternate Data Stream - 43520 bytes -> C:\Windows\System32:nskrnl32.exe
@Alternate Data Stream - 1073 bytes -> C:\Windows\System32:nskrnl32
< End of report >
Nice that revealed a few more and some ADS so kill those and then run MBAM to find any orphans

Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
    
    O2 - BHO: (no name) - {a84e6d05-9fad-4976-af9e-24b9c775dffd} - C:\Windows\system32\lakofote.dll File not found
    O4 - HKLM..\Run: [CPMa1965f06] Rundll32.exe "c:\windows\system32\gubagedu.dll",a ()
    O4 - HKLM..\Run: [fumogogiha] Rundll32.exe "C:\Windows\system32\jebihote.dll",s File not found
    O20 - AppInit_DLLs: (\w耀閂䬏蠀d\wi閅䬏蠀d\wi閈䬏耀) - File not found
    O20 - AppInit_DLLs: (.) - File not found
    O20 - AppInit_DLLs: (開䬏耀#:\䬎耀閎䬏耀&:\'Y閑) - File not found
    O20 - AppInit_DLLs: (C:\Windows\system32\wijariwo.dll) - C:\Windows\system32\wijariwo.dll File not found
    O20 - AppInit_DLLs: (c:\windows\system32\howewufu.dll) - c:\windows\system32\howewufu.dll File not found
    O20 - AppInit_DLLs: (c:\windows\system32\gubagedu.dll) - c:\windows\system32\gubagedu.dll ()
    O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\gubagedu.dll ()
    O22 - SharedTaskScheduler: {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - STS - c:\windows\system32\gubagedu.dll ()
    
    :Files
    C:\Windows\System32\kujadebo
    C:\Windows\System32\gubagedu.dll
    C:\Windows\System32\ramomeje.dll
    c:\Windows\System32\juhonemo.exe
    C:\Windows\System32\kitugibi.dll
    C:\Windows\System32\bubesomu.exe
    C:\Windows\System32\zayiwomo.dll
    C:\Windows\System32\hareyiyi.dll
    C:\Windows\System32\remikayi.dll
    C:\Windows\System32\pibosine.exe
    C:\Windows\System32\sewoline.dll
    C:\Windows\System32\jepeyumu.exe
    C:\Windows\System32\mawisega.dll
    C:\Windows\System32\zekazide.exe
    C:\Windows\System32\fofajivo.dll
    C:\Windows\System32\hefevisa.dll
    C:\Windows\System32\norupeze.dll
    C:\Windows\System32\davagadu.exe
    C:\Windows\System32\pazesomu.dll
    C:\Windows\System32\yikelido.dll
    C:\Windows\System32\pevowuhi.dll
    C:\Windows\System32\kigirefu.dll
    C:\Windows\System32\selababe.dll
    C:\Windows\System32\zatidege.dll
    C:\Windows\System32\jahitipa.dll
    C:\Windows\System32\jorerovi.dll
    C:\Windows\System32\lurujako.dll
    C:\Windows\System32\jikodiwa.dll
    C:\Windows\System32\mehegiva.dll
    C:\Windows\System32\sebiluza.dll
    C:\Windows\System32\nuduwuwu.dll
    C:\Windows\System32\yupujeba.dll
    C:\Windows\System32\gomewihe.dll
    C:\Windows\System32\lopisedu.dll
    C:\Windows\System32\rulawidi.dll
    C:\Windows\System32\nopefine.dll
    C:\Windows\System32\rejejiyo.dll
    C:\Windows\System32\zutedizo.dll
    C:\Windows\System32\tekigobe.dll
    C:\Windows\System32\fuyozafe.dll
    C:\Windows\System32\hedaraso.dll
    C:\Windows\System32\lokabuki.dll
    C:\Windows\System32\kesehufo.dll
    C:\Windows\System32\kewakiti.dll
    @C:\Windows\System32:nskrnl32.exe
    @C:\Windows\System32:nskrnl32
    
    :Commands
    [resethosts]
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )

THEN

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI