This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] logs included, virtumonde!

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

First of all, THANKYOU for your time!!

virtumonde etc etc. here is the log .

I am interested in the BHO , and removal of a .dll (qwtwbxqz.dll)

and anything else you may notice.

symtoms im seeing are inernet explorer corruptions and gnereal system slowdowns.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:32:13 PM, on 4/28/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Portrait Displays\Shared\dtsrvc.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wbem\unsecapp.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Saitek\Software\ProfilerU.exe
C:\Program Files\Saitek\Software\SaiMfd.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Logitech\G-series Software\LCDMon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDCountdown\LCDCountdown.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDPop3\LCDPOP3.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Portrait Displays\forteManager\DTHtml.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDA.EXE
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
O1 - Hosts: ::1 localhost
O1 - Hosts: 91.212.65.122 browser-security.microsoft.com
O1 - Hosts: 91.212.65.122 antiwareprotect.com
O1 - Hosts: 91.212.65.122 www.antiwareprotect.com
O2 - BHO: (no name) - {034ECFCF-58F3-489A-BE6A-8D83D901317d} - C:\WINDOWS\system32\qwtwbxqz.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {85102217-7189-1180-0472-5599ca323026} - C:\Program Files\Common Files\System\mgmts_msrc.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {A3182E35-0BDC-4FF8-82D6-DC9A605369A0} - c:\windows\system32\bpwyqcl.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Protection Bar - {5d4831e0-5a7c-4a46-afd5-a79ab8ce36c2} - C:\Program Files\Video ActiveX Object\iesplugin.dll (file missing)
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [Profiler] C:\Program Files\Saitek\Software\ProfilerU.exe
O4 - HKLM\..\Run: [SaiMfd] C:\Program Files\Saitek\Software\SaiMfd.exe
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"
O4 - HKLM\..\Run: [DT LGE] C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe -LGE
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [autochk] rundll32.exe C:\WINDOWS\system32\autochk.dll,_IWMPEvents@16
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [EPSON Stylus CX7400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDA.EXE /FU "C:\WINDOWS\TEMP\E_S184.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [autochk] rundll32.exe C:\DOCUME~1\NETWOR~1\protect.dll,_IWMPEvents@16
O4 - Startup: ChkDisk.dll
O4 - Startup: ChkDisk.lnk = ?
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: Macromedia Section Initiation.exe
O4 - Global Startup: Microsoft Desktop Initiation.exe
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/278f5de3e1df47…ip/RdxIE601.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1175369253859
O20 - Winlogon Notify: lteltuha - C:\WINDOWS\SYSTEM32\bpwyqcl.dll
O22 - SharedTaskScheduler: discriminable - {4fbbdfd6-2ca9-4bba-93e4-aadf75321bca} - (no file)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\dtsrvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

–
End of file - 8642 bytes


Once agian, THANKYOU for your time. I look forward to donating to the site for any assistance on this.

-Nick.
Hi there and welcome lets see if we can cure your ills

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
O2 - BHO: (no name) - {034ECFCF-58F3-489A-BE6A-8D83D901317d} - C:\WINDOWS\system32\qwtwbxqz.dll
O2 - BHO: (no name) - {85102217-7189-1180-0472-5599ca323026} - C:\Program Files\Common Files\System\mgmts_msrc.dll
O2 - BHO: (no name) - {A3182E35-0BDC-4FF8-82D6-DC9A605369A0} - c:\windows\system32\bpwyqcl.dll
O3 - Toolbar: Protection Bar - {5d4831e0-5a7c-4a46-afd5-a79ab8ce36c2} - C:\Program Files\Video ActiveX Object\iesplugin.dll (file missing)
O4 - HKLM\..\Run: [autochk] rundll32.exe C:\WINDOWS\system32\autochk.dll,_IWMPEvents@16
O4 - HKCU\..\Run: [autochk] rundll32.exe C:\DOCUME~1\NETWOR~1\protect.dll,_IWMPEvents@16
O4 - Startup: ChkDisk.dll
O4 - Startup: ChkDisk.lnk = ?
O4 - Startup: Macromedia Section Initiation.exe
O4 - Global Startup: Microsoft Desktop Initiation.exe
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O20 - Winlogon Notify: lteltuha - C:\WINDOWS\SYSTEM32\bpwyqcl.dll
O22 - SharedTaskScheduler: discriminable - {4fbbdfd6-2ca9-4bba-93e4-aadf75321bca} - (no file)

Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.

FOLLOWED BY

Download the HostsXpert 4.2 - Hosts File Manager.
  • Unzip HostsXpert 4.2 - Hosts File Manager to a convenient folder such as C:\HostsXpert 4.2 - Hosts File Manager
  • Run HostsXpert 4.2 - Hosts File Manager from its new home
  • Click on "File Handling".
  • Click on "Restore MS Hosts File".
  • Click OK on the Confirmation box.
  • Click on "Make Read Only?"
  • Click the X to exit the program.
  • Note: If you were using a custom Hosts file you will need to replace any of those entries yourself.

THEN

[external image: Posted Image] Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.

FINALLY FOR NOW

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.

Logs required : MBAM and both OTListit logs
So far so good. its nice to see some weapons being applied to the villain!
i believe these are the logs requested sir.

Malwarebytes' Anti-Malware 1.36
Database version: 2055
Windows 5.1.2600 Service Pack 2

4/28/2009 4:12:06 PM
mbam-log-2009-04-28 (16-12-06).txt

Scan type: Quick Scan
Objects scanned: 74015
Time elapsed: 11 minute(s), 23 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 11
Registry Values Infected: 3
Registry Data Items Infected: 6
Folders Infected: 1
Files Infected: 20

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\qwtwbxqz.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\bpwyqcl.dll (Trojan.Vundo.H) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a3182e35-0bdc-4ff8-82d6-dc9a605369a0} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\lteltuha (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{a3182e35-0bdc-4ff8-82d6-dc9a605369a0} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{034ecfcf-58f3-489a-be6a-8d83d901317d} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{034ecfcf-58f3-489a-be6a-8d83d901317d} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{034ecfcf-58f3-489a-be6a-8d83d901317d} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\swwwwfaw (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\swwwwfaw (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swwwwfaw (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a3182e35-0bdc-4ff8-82d6-dc9a605369a0} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Dxdiag.exe (Security.Hijack) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_deletecookie (Backdoor.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_opt_deletesol (Backdoor.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: c:\windows\system32\sdra64.exe -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (C:\WINDOWS\SYSTEM32\Userinit.exe,C:\WINDOWS\system32\sdra64.exe,) Good: (userinit.exe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\WINDOWS\system32\lowsec (Stolen.Data) -> Delete on reboot.

Files Infected:
c:\WINDOWS\system32\bpwyqcl.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\qwtwbxqz.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\pwvwhgr.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\autochk.dll (Worm.Autorun) -> Quarantined and deleted successfully.
C:\Documents and Settings\Nick\Local Settings\Temp\msb.dll (Worm.Autorun) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\TMP0000001BE284AFC434CC094A (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\TMP000000213C40A1E71A5640F5 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\TMP000000271C4871513D9A6967 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\TMP00000005A440BB8D5E682C38 (Trojan.BHO) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\TMP000000073CFE70542C4559BE (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\protect.dll (Worm.Autorun) -> Quarantined and deleted successfully.
C:\Documents and Settings\Nick\protect.dll (Worm.Autorun) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lowsec\local.ds (Stolen.Data) -> Delete on reboot.
C:\WINDOWS\system32\lowsec\user.ds (Stolen.Data) -> Delete on reboot.
C:\Program Files\Common Files\System\Yahoo_Software_Initiation.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSSlxwp.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sdra64.exe (Trojan.FakeAlert) -> Delete on reboot.
C:\Documents and Settings\Nick\Favorites\Online Security Test.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\Documents and Settings\Nick\Local Settings\Temp\nsrbgxod.bak (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSStkdv.log (Trojan.TDSS) -> Quarantined and deleted successfully.


OTListIt logfile created on: 4/28/2009 4:16:04 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Nick\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.54 Gb Available Physical Memory | 77.02% Memory free
3.85 Gb Paging File | 3.46 Gb Available in Paging File | 89.90% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 97.75 Gb Total Space | 3.36 Gb Free Space | 3.44% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 274.87 Gb Total Space | 264.83 Gb Free Space | 96.35% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MASTA
Current User Name: Nick
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Common Files\Portrait Displays\Shared\dtsrvc.exe ()
PRC - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\system32\PnkBstrA.exe ()
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Saitek\Software\ProfilerU.exe (Saitek)
PRC - C:\Program Files\Saitek\Software\SaiMfd.exe (Saitek)
PRC - C:\Program Files\Logitech\G-series Software\LGDCore.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\G-series Software\LCDMon.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
PRC - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Logitech\G-series Software\Applets\LCDCountdown\LCDCountdown.exe (Logitech Inc.)
PRC - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDA.EXE (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Logitech\G-series Software\Applets\LCDPop3\LCDPOP3.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe (Logitech Inc.)
PRC - C:\Program Files\Portrait Displays\forteManager\DTHtml.exe (Portrait Displays, Inc)
PRC - C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe (Portrait Displays Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\Documents and Settings\Nick\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) – C:\WINDOWS\system32\ati2sgag.exe ()
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DTSRVC [Auto | Running]) – C:\Program Files\Common Files\Portrait Displays\Shared\dtsrvc.exe ()
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (IviRegMgr [Auto | Running]) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (PnkBstrA [Auto | Running]) – C:\WINDOWS\system32\PnkBstrA.exe ()
SRV - (swwwwfaw [Unknown | Stopped]) – File not found
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (Afc [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Afc.sys (Arcsoft, Inc.)
DRV - (aslm75 [System | Running]) – C:\WINDOWS\system32\drivers\aslm75.sys ()
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (cmudax [On_Demand | Running]) – C:\WINDOWS\system32\drivers\cmudax.sys (C-Media Inc.)
DRV - (dkhryfez [Boot | Running]) – C:\WINDOWS\system32\drivers\dkhryfez.sys (Microsoft Corporation)
DRV - (ENTECH [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\ENTECH.sys (EnTech Taiwan)
DRV - (HdAudAddService [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\HdAudio.sys (Windows ® Server 2003 DDK provider)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (MTsensor [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ASACPI.sys ()
DRV - (pdiddcci [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\pdiddcci.sys (Portrait Displays, Inc.)
DRV - (PdiPorts [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\PdiPorts.sys (Portrait Displays, Inc.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (SaiH0255 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\SaiH0255.sys (Saitek)
DRV - (SaiMini [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\SaiMini.sys (Saitek)
DRV - (SaiNtBus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\SaiBus.sys (Saitek)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (si3114r [Boot | Running]) – C:\WINDOWS\system32\drivers\si3114r.sys (Silicon Image, Inc)
DRV - (SiFilter [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (SiWinAcc [Boot | Running]) – C:\WINDOWS\system32\drivers\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (StillCam [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (yukonwxp [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\yk51x86.sys (Marvell)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default = CF CF 4E 03 F3 58 9A 48 BE 6A 8D 83 D9 01 31 7D [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.shoutcast.com/;http://www.radioparadise.com/;
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig?hl=en"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10

FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2008/12/29 21:31:32 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/28 09:59:17 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/28 09:59:17 | 00,000,000 | —D | M]

[2009/04/23 09:26:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\mozilla\Extensions
[2009/04/23 09:26:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/23 09:26:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\mozilla\Firefox\Profiles\kb4nvyhz.default\extensions
[2009/04/27 23:54:04 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/04/23 09:26:34 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/04/23 17:33:54 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/04/28 09:59:14 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/28 09:59:14 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/04/09 00:51:14 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/09 00:51:14 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/09 00:51:14 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/09 00:51:14 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/09 00:51:14 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/09 00:51:14 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/09 00:51:14 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (698 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: () - {A3182E35-0BDC-4FF8-82D6-DC9A605369A0} - c:\windows\system32\bpwyqcl.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {5D4831E0-5A7C-4A46-AFD5-A79AB8CE36C2} - C:\Program Files\Video ActiveX Object\iesplugin.dll File not found
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay (ATI Technologies Inc.)
O4 - HKLM..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd File not found
O4 - HKLM..\Run: [DT LGE] C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe -LGE ()
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler (Macrovision Corporation)
O4 - HKLM..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe" (Logitech Inc.)
O4 - HKLM..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE (Logitech Inc.)
O4 - HKLM..\Run: [Profiler] C:\Program Files\Saitek\Software\ProfilerU.exe (Saitek)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SaiMfd] C:\Program Files\Saitek\Software\SaiMfd.exe (Saitek)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide (Microsoft Corporation)
O4 - HKCU..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent File not found
O4 - HKCU..\Run: [EPSON Stylus CX7400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDA.EXE /FU "C:\WINDOWS\TEMP\E_S184.tmp" /EF "HKCU" (SEIKO EPSON CORPORATION)
O4 - Startup: C:\Documents and Settings\Nick\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnotes.com/download/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {3334504D-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/C…C4D/mp43dmo.CAB (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab (DLM Control)
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} http://software-dl.real.com/278f5de3e1df47…ip/RdxIE601.cab (RdxIE Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1175369253859 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\lteltuha: DllName - bpwyqcl.dll - C:\WINDOWS\system32\bpwyqcl.dll ()
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()

========== Files/Folders - Created Within 30 Days ==========

[5 C:\WINDOWS\*.tmp files]
[2009/04/28 16:15:05 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Nick\Desktop\OTListIt2.exe
[2009/04/28 15:35:39 | 00,000,000 | —D | C] – C:\Documents and Settings\Nick\Application Data\Malwarebytes
[2009/04/28 15:35:37 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/28 15:35:35 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/28 15:35:33 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/04/28 15:35:33 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/28 15:34:12 | 02,967,800 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Nick\Desktop\mbam-setup.exe
[2009/04/28 15:28:00 | 00,000,000 | —D | C] – C:\Documents and Settings\Nick\Desktop\HostsXpert
[2009/04/28 15:26:55 | 00,353,485 | —- | C] () – C:\Documents and Settings\Nick\Desktop\HostsXpert.zip
[2009/04/28 14:32:05 | 00,001,734 | —- | C] () – C:\Documents and Settings\Nick\Desktop\HijackThis.lnk
[2009/04/28 14:32:05 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/04/28 14:19:50 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/04/28 14:19:39 | 00,000,767 | —- | C] () – C:\Documents and Settings\Nick\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/04/28 14:19:37 | 00,000,592 | —- | C] () – C:\Documents and Settings\Nick\Desktop\ERUNT.lnk
[2009/04/28 14:19:37 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/04/28 13:21:22 | 00,015,688 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2009/04/28 13:14:56 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/04/28 13:14:18 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/04/28 13:14:15 | 00,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/04/27 23:34:00 | 22,839,919 | —- | C] () – C:\Documents and Settings\Nick\Desktop\transferrebuild.rar
[2009/04/27 23:18:31 | 00,000,000 | —D | C] – C:\Documents and Settings\Nick\Desktop\transferrebuild
[2009/04/23 18:11:41 | 02,348,928 | —- | C] () – C:\Documents and Settings\Nick\Desktop\D.exe
[2009/04/23 15:24:11 | 16,883,056 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Nick\Desktop\IE8-WindowsXP-x86-ENU.exe
[2009/04/23 15:16:46 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Windows OneCare Live
[2009/04/23 09:26:42 | 00,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/04/23 09:26:40 | 00,000,000 | —D | C] – C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla
[2009/04/23 09:26:33 | 00,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2009/04/23 09:23:09 | 00,000,330 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/04/23 09:19:36 | 00,000,000 | —D | C] – C:\Program Files\Windows Defender
[2009/04/23 01:29:17 | 00,000,434 | —- | C] () – C:\WINDOWS\tasks\At1.job
[2009/04/17 15:09:42 | 00,686,466 | —- | C] () – C:\Documents and Settings\Nick\Desktop\XPerl-3.0.3___WoW_3.1.0_Release_.zip
[2009/04/15 23:20:13 | 00,000,000 | —D | C] – C:\WINDOWS\solcache
[2009/04/15 23:19:07 | 00,000,000 | —D | C] – C:\SIERRA
[2009/04/15 23:19:07 | 00,000,000 | —D | C] – C:\Program Files\Sierra On-Line
[2009/04/15 23:18:34 | 00,000,421 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2009/04/15 23:18:34 | 00,000,231 | —- | C] () – C:\WINDOWS\system.bak
[2009/04/15 23:16:58 | 00,000,000 | —D | C] – C:\Documents and Settings\Nick\Desktop\RB3D
[2009/04/15 22:43:45 | 27,551,1022 | —- | C] () – C:\Documents and Settings\Nick\Desktop\rb3d.zip
[2009/04/15 21:47:39 | 00,399,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/04/15 21:47:39 | 00,283,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/04/15 21:47:39 | 00,060,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\colbact.dll
[2009/04/15 21:47:38 | 00,473,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/04/15 21:47:38 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/04/15 21:47:38 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/04/15 21:47:38 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/04/15 21:47:37 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/04/15 21:47:37 | 00,616,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/04/15 21:47:21 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/04/12 00:00:47 | 00,000,000 | —D | C] – C:\Documents and Settings\Nick\Desktop\website toons
[2009/04/11 00:34:05 | 00,000,000 | —D | C] – C:\Documents and Settings\Nick\Desktop\ratz
[2009/04/10 16:34:37 | 00,000,000 | —D | C] – C:\Documents and Settings\Nick\Application Data\KompoZer
[2009/04/10 16:34:18 | 00,000,000 | —D | C] – C:\Documents and Settings\Nick\Desktop\kompozer-0.7.10-win32
[2009/04/10 16:32:19 | 07,949,158 | —- | C] () – C:\Documents and Settings\Nick\Desktop\kompozer-0.7.10-win32.zip
[2009/04/04 07:56:46 | 00,189,472 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.xtr
[2009/02/12 04:03:16 | 00,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/11/15 18:04:05 | 00,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2008/09/25 11:44:25 | 00,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2008/09/25 11:43:38 | 00,000,079 | —- | C] () – C:\WINDOWS\EPSCX7400.ini
[2008/09/04 12:34:45 | 00,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2008/07/17 00:41:33 | 00,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2008/07/17 00:41:33 | 00,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2008/07/17 00:41:33 | 00,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/06/26 01:03:06 | 00,138,168 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2008/03/21 16:27:47 | 00,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/03/14 19:20:52 | 00,003,972 | —- | C] () – C:\WINDOWS\System32\drivers\PciBus.sys
[2008/02/02 20:42:52 | 00,765,952 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/02/02 20:42:52 | 00,164,352 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2007/12/11 14:46:02 | 03,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007/12/11 14:44:28 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2007/12/11 14:44:28 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dpl100.dll.manifest
[2007/12/11 14:43:44 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/05/13 09:20:37 | 00,000,705 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/01/14 11:03:12 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2006/07/27 22:36:52 | 00,205,824 | —- | C] () – C:\WINDOWS\patchw32.dll
[2006/07/27 22:36:22 | 00,205,824 | —- | C] () – C:\WINDOWS\pw32a.dll
[2006/07/27 22:36:21 | 00,205,824 | —- | C] () – C:\WINDOWS\System32\pw32a.dll
[2006/07/19 21:23:20 | 00,006,656 | —- | C] () – C:\WINDOWS\System32\drivers\AsProbe.sys
[2006/07/19 21:22:58 | 00,006,272 | —- | C] () – C:\WINDOWS\System32\drivers\ASLM75.SYS
[2006/07/19 21:16:29 | 00,028,672 | —- | C] () – C:\WINDOWS\System32\cmirmdrv.dll
[2006/07/19 21:15:48 | 00,005,810 | —- | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2006/07/19 21:15:46 | 00,008,094 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2006/07/19 21:15:44 | 00,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2003/03/31 07:00:00 | 00,143,872 | —- | C] () – C:\WINDOWS\System32\qwtwbxqz.dll
[2003/03/31 07:00:00 | 00,103,936 | —- | C] () – C:\WINDOWS\System32\pwvwhgr.dll
[2003/03/31 07:00:00 | 00,103,936 | —- | C] () – C:\WINDOWS\System32\bpwyqcl.dll
[2003/03/31 07:00:00 | 00,000,517 | —- | C] () – C:\WINDOWS\win.ini
[2003/03/31 07:00:00 | 00,000,231 | —- | C] () – C:\WINDOWS\system.ini

========== Files - Modified Within 30 Days ==========

[4 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/04/28 16:16:50 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/04/28 16:15:07 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Nick\Desktop\OTListIt2.exe
[2009/04/28 16:14:14 | 00,000,420 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{F5C1E708-14C3-4466-87EE-274879040027}.job
[2009/04/28 16:13:52 | 00,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/04/28 16:13:44 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/28 16:13:41 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/04/28 16:01:19 | 00,464,860 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/28 16:01:19 | 00,397,560 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/04/28 16:01:19 | 00,059,780 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/04/28 15:57:16 | 00,000,434 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2009/04/28 15:34:32 | 02,967,800 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Nick\Desktop\mbam-setup.exe
[2009/04/28 15:31:48 | 00,353,485 | —- | M] () – C:\Documents and Settings\Nick\Desktop\HostsXpert.zip
[2009/04/28 14:32:05 | 00,001,734 | —- | M] () – C:\Documents and Settings\Nick\Desktop\HijackThis.lnk
[2009/04/28 14:19:39 | 00,000,767 | —- | M] () – C:\Documents and Settings\Nick\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/04/28 14:19:37 | 00,000,592 | —- | M] () – C:\Documents and Settings\Nick\Desktop\ERUNT.lnk
[2009/04/28 13:17:27 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/04/28 13:14:15 | 00,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/04/28 02:05:49 | 22,839,919 | —- | M] () – C:\Documents and Settings\Nick\Desktop\transferrebuild.rar
[2009/04/27 23:36:39 | 00,193,024 | —- | M] () – C:\Documents and Settings\Nick\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/23 18:12:18 | 02,348,928 | —- | M] () – C:\Documents and Settings\Nick\Desktop\D.exe
[2009/04/23 15:52:23 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/04/23 15:24:27 | 16,883,056 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Nick\Desktop\IE8-WindowsXP-x86-ENU.exe
[2009/04/23 09:26:42 | 00,000,000 | —- | M] () – C:\WINDOWS\nsreg.dat
[2009/04/17 15:09:42 | 00,686,466 | —- | M] () – C:\Documents and Settings\Nick\Desktop\XPerl-3.0.3___WoW_3.1.0_Release_.zip
[2009/04/16 00:11:09 | 02,105,962 | -H– | M] () – C:\Documents and Settings\Nick\Local Settings\Application Data\IconCache.db
[2009/04/15 23:33:19 | 00,000,421 | —- | M] () – C:\WINDOWS\SIERRA.INI
[2009/04/15 23:23:34 | 02,456,676 | —- | M] () – C:\Documents and Settings\Nick\Desktop\RB3D_First_Aid_Kit_BETA101.zip
[2009/04/15 23:23:34 | 00,098,304 | —- | M] () – C:\Documents and Settings\Nick\Desktop\Glide Wrapper.exe
[2009/04/15 23:16:17 | 27,551,1022 | —- | M] () – C:\Documents and Settings\Nick\Desktop\rb3d.zip
[2009/04/10 16:32:35 | 07,949,158 | —- | M] () – C:\Documents and Settings\Nick\Desktop\kompozer-0.7.10-win32.zip
[2009/04/06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/06 07:57:26 | 24,921,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/04/05 12:19:51 | 00,138,168 | —- | M] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/04/05 12:19:42 | 00,189,472 | —- | M] () – C:\WINDOWS\System32\PnkBstrB.xtr
[2009/04/05 12:19:42 | 00,189,472 | —- | M] () – C:\WINDOWS\System32\PnkBstrB.exe

========== LOP Check ==========

[2009/04/28 15:35:33 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/04/28 13:14:18 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/04/17 12:56:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/10/04 19:04:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2008/10/04 19:04:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/10/15 18:32:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Blizzard
[2007/03/04 13:57:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2009/02/10 03:09:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2008/09/25 11:49:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2008/12/29 21:41:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FLEXnet
[2008/02/02 19:28:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2007/05/23 12:43:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kodak
[2009/04/28 13:14:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2006/07/20 18:32:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Logitech
[2009/04/28 15:35:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/23 09:19:36 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/06/10 01:17:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/01/25 09:03:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Uniblue
[2006/07/19 21:31:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/04/24 12:00:13 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Nick\Application Data
[2009/04/17 12:58:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Adobe
[2006/07/30 09:59:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Apple Computer
[2008/10/15 19:43:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\ArcSoft
[2006/07/19 21:39:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\ATI
[2007/03/04 13:57:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\CyberLink
[2007/03/04 13:10:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\DisplayTune
[2008/01/04 10:21:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\DivX
[2008/12/29 21:23:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Download Manager
[2008/05/16 20:10:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\GetRightToGo
[2008/10/05 22:34:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Google
[2008/02/09 21:51:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Help
[2008/02/08 17:51:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Hoyle FaceCreator
[2008/07/17 01:01:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Hoyle Puzzle and Board Games
[2006/07/19 20:15:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Identities
[2009/04/10 16:34:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\KompoZer
[2009/04/17 12:52:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Lavasoft
[2008/09/25 11:53:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Leadertech
[2006/07/20 18:45:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Macromedia
[2009/04/28 15:35:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Malwarebytes
[2008/05/16 20:17:08 | 00,000,000 | –SD | M] – C:\Documents and Settings\Nick\Application Data\Microsoft
[2009/04/23 09:26:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Mozilla
[2006/08/27 10:48:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Real
[2008/02/09 22:22:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Runes of Avalon
[2008/02/02 19:55:42 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Nick\Application Data\SecuROM
[2007/03/04 20:59:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Sun
[2008/01/25 09:03:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Uniblue
[2008/11/15 18:04:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Ventrilo
[2007/03/31 18:53:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\WinRAR
[2007/07/07 01:28:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\Xfire
[2009/04/28 13:17:27 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/04/28 15:57:16 | 00,000,434 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2003/03/31 07:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/04/28 16:16:50 | 00,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2009/04/28 16:13:44 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2009/04/28 16:14:14 | 00,000,420 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{F5C1E708-14C3-4466-87EE-274879040027}.job

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 487 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
< End of report >



OTListIt Extras logfile created on: 4/28/2009 4:16:04 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Nick\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.54 Gb Available Physical Memory | 77.02% Memory free
3.85 Gb Paging File | 3.46 Gb Available in Paging File | 89.90% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 97.75 Gb Total Space | 3.36 Gb Free Space | 3.44% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 274.87 Gb Total Space | 264.83 Gb Free Space | 96.35% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MASTA
Current User Name: Nick
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) File not found
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 (Microsoft Corporation)
C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) (Microsoft Corporation)
C:\Program Files\NCsoft\Exteel\System\Exteel.exe:*:Enabled:Exteel File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) File not found
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe:*:Enabled:DarkCrusade File not found
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare File not found
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 (Microsoft Corporation)
C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) (Microsoft Corporation)
C:\Program Files\NCsoft\Exteel\System\Exteel.exe:*:Enabled:Exteel File not found
C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe ()

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}" = Battlefield 2™
"{0D6D96F4-0CAF-4522-B05F-70A88EDECDFD}" = ArcSoft Print Creations
"{0DEA342C-15CB-4F52-97B6-06A9C4B9C06F}" = SDK
"{12452C5A-32E2-40C6-808D-DA4FB6DC35A5}" = ATI Catalyst Control Center
"{1883A84D-94AA-432C-9519-FA31B6B118B9}" = forteManager
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = InterVideo WinDVD 8
"{24ADC0E4-8D3E-40C4-9106-F2DE5E9112F1}" = EPSON Stylus CX7400 Series Scanner Driver Update
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 13
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{49672EC2-171B-47B4-8CE7-50D7806360D7}" = Windows Live Sign-in Assistant
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{5A080213-5AEC-4BF2-BB32-796EB0E421EC}" = Logitech G-series Keyboard Software
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6C5930D1-E4BC-4A10-AB5A-224C48CBA7E6}" = America's Army
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7A65E382-1843-4B46-861B-1BECB8354911}" = Falcon 4.0: Allied Force
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7F3AD00A-1819-4B15-BB7D-08B3586336D7}" = 3DMark06
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{9527A496-5DF9-412A-ADC7-168BA5379CA6}" = Microsoft Flight Simulator X
"{967FB80D-56BD-42EF-A942-9E8C78F984A4}" = Saitek SST Programming Software
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BCE72AED-3332-4863-9567-C5DCB9052CA2}" = Netflix Movie Viewer
"{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver
"{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
"{DB0A8A2A-4EA7-4FE3-802E-8A6DEE32696C}_is1" = Orban/Coding Technologies AAC/aacPlus Player Plugin™ 1.0
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F8024EB8-5B34-46FE-B15D-20ACF26FC20E}" = Hoyle Puzzle and Board Games
"Aces High II" = Aces High II
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"All ATI Software" = ATI - Software Uninstall Utility
"ASUS Probe V2.24.03" = ASUS Probe V2.24.03
"ATI Display Driver" = ATI Display Driver
"C-Media Audio Driver" = C-Media High Definition Audio Driver
"EPSON Printer and Utilities" = EPSON Printer Software
"ERUNT_is1" = ERUNT 1.1j
"Fraps" = Fraps
"FreshDevices - FreshView_is1" = FreshView
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = InterVideo WinDVD 8
"InstallShield_{9527A496-5DF9-412A-ADC7-168BA5379CA6}" = Microsoft Flight Simulator X
"KLiteCodecPack_is1" = K-Lite Codec Pack 3.7.0 Basic
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"R4" = R4
"RealPlayer 6.0" = RealPlayer
"Sierra Utilities" = Sierra Utilities
"Silent Package Run-Time Sample" = EPSON CX7400 User's Guide
"vis_BeatHarness.dllWinamp" = BeatHarness for Winamp 2x (remove only)
"vis_milk.dllWinamp" = MilkDrop for Winamp 2x (remove only)
"vis_MojoMaster.dllWinamp" = Mojo Master Winamp Visualizer for Winamp (remove only)
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 2
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"World of Warcraft" = World of Warcraft
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xfire" = Xfire (remove only)
"Xvid_is1" = Xvid 1.1.3 final uninstall

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/23/2009 12:29:18 PM | Computer Name = MASTA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 1/28/2009 7:31:29 PM | Computer Name = MASTA | Source = .NET Runtime | ID = 1023
Description = .NET Runtime version 2.0.50727.1433 - Fatal Execution Engine Error
(79FFEE24) (80131506)

Error - 2/2/2009 11:07:02 AM | Computer Name = MASTA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16762, faulting
module ntdll.dll, version 5.1.2600.2180, fault address 0x0003426d.

Error - 2/6/2009 12:39:03 AM | Computer Name = MASTA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16762, faulting
module wininet.dll, version 7.0.6000.16762, fault address 0x0000ef38.

Error - 2/15/2009 12:23:40 PM | Computer Name = MASTA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module ntdll.dll, version 5.1.2600.2180, fault address 0x0003215b.

Error - 2/15/2009 8:34:56 PM | Computer Name = MASTA | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module unknown, version 0.0.0.0, fault address 0x100031c9.

Error - 2/15/2009 8:38:41 PM | Computer Name = MASTA | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.2180, fault address 0x0001295d.

Error - 2/23/2009 1:48:06 AM | Computer Name = MASTA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module ole32.dll, version 5.1.2600.2726, fault address 0x0004d133.

Error - 2/26/2009 10:59:08 PM | Computer Name = MASTA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module msvcrt.dll, version 7.0.2600.2180, fault address 0x00037124.

Error - 2/28/2009 12:54:06 AM | Computer Name = MASTA | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module ntdll.dll, version 5.1.2600.2180, fault address 0x00011f6c.

[ System Events ]
Error - 4/28/2009 3:05:03 PM | Computer Name = MASTA | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD aslm75 Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip

Error - 4/28/2009 3:06:22 PM | Computer Name = MASTA | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 4/28/2009 3:06:42 PM | Computer Name = MASTA | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 4/28/2009 3:14:03 PM | Computer Name = MASTA | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 4/28/2009 3:15:27 PM | Computer Name = MASTA | Source = ati2mtag | ID = 45062
Description = CRT invalid display type

Error - 4/28/2009 4:25:35 PM | Computer Name = MASTA | Source = ati2mtag | ID = 45062
Description = CRT invalid display type

Error - 4/28/2009 4:47:57 PM | Computer Name = MASTA | Source = DCOM | ID = 10010
Description = The server {FFF2D28F-E4EE-44D9-8104-8E71556757F6} did not register
with DCOM within the required timeout.

Error - 4/28/2009 4:57:36 PM | Computer Name = MASTA | Source = ati2mtag | ID = 45062
Description = CRT invalid display type

Error - 4/28/2009 5:13:46 PM | Computer Name = MASTA | Source = Service Control Manager | ID = 7023
Description = The PnP ISA/EISA Bus Support service terminated with the following
error: %%193

Error - 4/28/2009 5:14:04 PM | Computer Name = MASTA | Source = ati2mtag | ID = 45062
Description = CRT invalid display type


< End of report >


does this help?
thankyou again sir.
OK you will need to get an Antivirus installed otherwise you will be back here again. There are several free ones to choose from
Avast
AVG
Avira

To continue with the massacre of the meanies, let me know how your system is on completion

Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
    SRV - (swwwwfaw [Unknown | Stopped]) – File not found
    O2 - BHO: () - {A3182E35-0BDC-4FF8-82D6-DC9A605369A0} - c:\windows\system32\bpwyqcl.dll ()
    O3 - HKLM\..\Toolbar: (no name) - Locked - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {5D4831E0-5A7C-4A46-AFD5-A79AB8CE36C2} - C:\Program Files\Video ActiveX Object\iesplugin.dll File not found
    O20 - Winlogon\Notify\lteltuha: DllName - bpwyqcl.dll - C:\WINDOWS\system32\bpwyqcl.dll ()
    [2009/04/23 18:11:41 | 02,348,928 | —- | C] () – C:\Documents and Settings\Nick\Desktop\D.exe
    [2009/04/23 01:29:17 | 00,000,434 | —- | C] () – C:\WINDOWS\tasks\At1.job
    [2003/03/31 07:00:00 | 00,143,872 | —- | C] () – C:\WINDOWS\System32\qwtwbxqz.dll
    [2003/03/31 07:00:00 | 00,103,936 | —- | C] () – C:\WINDOWS\System32\pwvwhgr.dll
    [2003/03/31 07:00:00 | 00,103,936 | —- | C] () – C:\WINDOWS\System32\bpwyqcl.dll
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )
I will be using the AVAST! . thankyou for the recomendation.

Here are the fresh logs. I am including the one from the ``fix`` run as well, only because it mention an error at the very top. and i may have miscopied your instructions into firld at the bottom of that program.

followed by the most recent scan log.

Error: Unable to interpret in the current context!
========== OTLISTIT ==========
Process Explorer.EXE killed successfully!
Service\Driver swwwwfaw not found.
Service\Driver swwwwfaw not found.
File File not found not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3182E35-0BDC-4FF8-82D6-DC9A605369A0}\ deleted successfully.
Unable to delete registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3182E35-0BDC-4FF8-82D6-DC9A605369A0}\ .
LoadLibrary failed for c:\windows\system32\bpwyqcl.dll
c:\windows\system32\bpwyqcl.dll NOT unregistered.
c:\windows\system32\bpwyqcl.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{5D4831E0-5A7C-4A46-AFD5-A79AB8CE36C2} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5D4831E0-5A7C-4A46-AFD5-A79AB8CE36C2}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\lteltuha\ deleted successfully.
File C:\WINDOWS\system32\bpwyqcl.dll not found.
File C:\Documents and Settings\Nick\Desktop\D.exe not found.
C:\WINDOWS\tasks\At1.job moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\qwtwbxqz.dll
C:\WINDOWS\System32\qwtwbxqz.dll NOT unregistered.
C:\WINDOWS\System32\qwtwbxqz.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\pwvwhgr.dll
C:\WINDOWS\System32\pwvwhgr.dll NOT unregistered.
C:\WINDOWS\System32\pwvwhgr.dll moved successfully.
File C:\WINDOWS\System32\bpwyqcl.dll not found.
========== COMMANDS ==========
File delete failed. C:\Documents and Settings\Nick\Local Settings\Temp\etilqs_rnJWHCVo7crNUISat2Hl scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Nick\Local Settings\Temp\Perflib_Perfdata_348.dat scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\Nick\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_7fc.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_91c.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\kb4nvyhz.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\kb4nvyhz.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\kb4nvyhz.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\kb4nvyhz.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\kb4nvyhz.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\kb4nvyhz.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTListIt2 by OldTimer - Version 2.0.14.0 log created on 04282009_175436

Files moved on Reboot…
File C:\Documents and Settings\Nick\Local Settings\Temp\etilqs_rnJWHCVo7crNUISat2Hl not found!
File C:\Documents and Settings\Nick\Local Settings\Temp\Perflib_Perfdata_348.dat not found!
File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
C:\WINDOWS\temp\Perflib_Perfdata_7fc.dat moved successfully.
File C:\WINDOWS\temp\Perflib_Perfdata_91c.dat not found!
C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\kb4nvyhz.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\kb4nvyhz.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\kb4nvyhz.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\kb4nvyhz.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\kb4nvyhz.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\kb4nvyhz.default\XUL.mfl moved successfully.

Registry entries deleted on Reboot…


and finally the most recent log as requested.

OTListIt logfile created on: 4/28/2009 6:01:09 PM - Run 2
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Nick\Desktop\weapons
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.42 Gb Available Physical Memory | 70.89% Memory free
3.85 Gb Paging File | 3.30 Gb Available in Paging File | 85.77% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 97.75 Gb Total Space | 7.92 Gb Free Space | 8.10% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 274.87 Gb Total Space | 264.83 Gb Free Space | 96.35% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MASTA
Current User Name: Nick
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Portrait Displays\Shared\dtsrvc.exe ()
PRC - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\system32\PnkBstrA.exe ()
PRC - C:\WINDOWS\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\WINDOWS\notepad.exe (Microsoft Corporation)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Saitek\Software\ProfilerU.exe (Saitek)
PRC - C:\Program Files\Saitek\Software\SaiMfd.exe (Saitek)
PRC - C:\Program Files\Logitech\G-series Software\LGDCore.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\G-series Software\LCDMon.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
PRC - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Logitech\G-series Software\Applets\LCDCountdown\LCDCountdown.exe (Logitech Inc.)
PRC - C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
PRC - C:\Program Files\Logitech\G-series Software\Applets\LCDPop3\LCDPOP3.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe (Logitech Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe (Logitech Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Portrait Displays\forteManager\DTHtml.exe (Portrait Displays, Inc)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe (Portrait Displays Inc.)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\Nick\Desktop\weapons\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) – C:\WINDOWS\system32\ati2sgag.exe ()
SRV - (avast! Antivirus [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DTSRVC [Auto | Running]) – C:\Program Files\Common Files\Portrait Displays\Shared\dtsrvc.exe ()
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (IviRegMgr [Auto | Running]) – C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (PnkBstrA [Auto | Running]) – C:\WINDOWS\system32\PnkBstrA.exe ()
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (Aavmker4 [System | Running]) – C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (Afc [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Afc.sys (Arcsoft, Inc.)
DRV - (aslm75 [System | Running]) – C:\WINDOWS\system32\drivers\aslm75.sys ()
DRV - (aswFsBlk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV - (aswMon2 [Auto | Running]) – C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Running]) – C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) – C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) – C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (cmudax [On_Demand | Running]) – C:\WINDOWS\system32\drivers\cmudax.sys (C-Media Inc.)
DRV - (ENTECH [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\ENTECH.sys (EnTech Taiwan)
DRV - (HdAudAddService [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\HdAudio.sys (Windows ® Server 2003 DDK provider)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (MTsensor [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ASACPI.sys ()
DRV - (pdiddcci [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\pdiddcci.sys (Portrait Displays, Inc.)
DRV - (PdiPorts [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\PdiPorts.sys (Portrait Displays, Inc.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (SaiH0255 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\SaiH0255.sys (Saitek)
DRV - (SaiMini [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\SaiMini.sys (Saitek)
DRV - (SaiNtBus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\SaiBus.sys (Saitek)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (si3114r [Boot | Running]) – C:\WINDOWS\system32\drivers\si3114r.sys (Silicon Image, Inc)
DRV - (SiFilter [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (SiWinAcc [Boot | Running]) – C:\WINDOWS\system32\drivers\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (StillCam [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (yukonwxp [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\yk51x86.sys (Marvell)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default = CF CF 4E 03 F3 58 9A 48 BE 6A 8D 83 D9 01 31 7D [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.shoutcast.com/;http://www.radioparadise.com/;
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig?hl=en"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10

FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2008/12/29 21:31:32 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/28 09:59:17 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/28 09:59:17 | 00,000,000 | —D | M]

[2009/04/23 09:26:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\mozilla\Extensions
[2009/04/23 09:26:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/23 09:26:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Nick\Application Data\mozilla\Firefox\Profiles\kb4nvyhz.default\extensions
[2009/04/27 23:54:04 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/04/23 09:26:34 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/04/23 17:33:54 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/04/28 09:59:14 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/28 09:59:14 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/04/09 00:51:14 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/09 00:51:14 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/09 00:51:14 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/09 00:51:14 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/09 00:51:14 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/09 00:51:14 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/09 00:51:14 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (698 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay (ATI Technologies Inc.)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd File not found
O4 - HKLM..\Run: [DT LGE] C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe -LGE ()
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler (Macrovision Corporation)
O4 - HKLM..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe" (Logitech Inc.)
O4 - HKLM..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE (Logitech Inc.)
O4 - HKLM..\Run: [Profiler] C:\Program Files\Saitek\Software\ProfilerU.exe (Saitek)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SaiMfd] C:\Program Files\Saitek\Software\SaiMfd.exe (Saitek)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide (Microsoft Corporation)
O4 - HKCU..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent File not found
O4 - HKCU..\Run: [EPSON Stylus CX7400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDA.EXE /FU "C:\WINDOWS\TEMP\E_S184.tmp" /EF "HKCU" (SEIKO EPSON CORPORATION)
O4 - Startup: C:\Documents and Settings\Nick\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnotes.com/download/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {3334504D-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/C…C4D/mp43dmo.CAB (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab (DLM Control)
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} http://software-dl.real.com/278f5de3e1df47…ip/RdxIE601.cab (RdxIE Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1175369253859 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()

========== Files/Folders - Created Within 30 Days ==========

[5 C:\WINDOWS\*.tmp files]
[2009/04/28 17:54:36 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/04/28 16:49:29 | 00,001,709 | —- | C] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/04/28 16:49:28 | 00,114,768 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2009/04/28 16:49:28 | 00,097,480 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\AvastSS.scr
[2009/04/28 16:49:28 | 00,094,032 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/04/28 16:49:28 | 00,093,296 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2009/04/28 16:49:28 | 00,051,376 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/04/28 16:49:28 | 00,026,944 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/04/28 16:49:28 | 00,023,152 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/04/28 16:49:28 | 00,020,560 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/04/28 16:49:18 | 01,256,296 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\aswBoot.exe
[2009/04/28 16:49:18 | 01,060,864 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MFC71.dll
[2009/04/28 16:49:18 | 00,499,712 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MSVCP71.dll
[2009/04/28 16:49:18 | 00,380,928 | —- | C] () – C:\WINDOWS\System32\actskin4.ocx
[2009/04/28 16:49:17 | 00,000,000 | —D | C] – C:\Program Files\Alwil Software
[2009/04/28 16:48:01 | 00,308,160 | —- | C] (ALWIL Software) – C:\Documents and Settings\Nick\Desktop\avast_home_setup.exe
[2009/04/28 15:35:39 | 00,000,000 | —D | C] – C:\Documents and Settings\Nick\Application Data\Malwarebytes
[2009/04/28 15:35:37 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/28 15:35:35 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/28 15:35:33 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/04/28 15:35:33 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/28 14:32:05 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/04/28 14:19:50 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/04/28 14:19:39 | 00,000,767 | —- | C] () – C:\Documents and Settings\Nick\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/04/28 14:19:37 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/04/28 13:21:22 | 00,015,688 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2009/04/28 13:14:56 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/04/28 13:14:18 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/04/27 23:18:31 | 00,000,000 | —D | C] – C:\Documents and Settings\Nick\Desktop\transferrebuild
[2009/04/23 15:24:11 | 16,883,056 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Nick\Desktop\IE8-WindowsXP-x86-ENU.exe
[2009/04/23 15:16:46 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Windows OneCare Live
[2009/04/23 09:26:42 | 00,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/04/23 09:26:40 | 00,000,000 | —D | C] – C:\Documents and Settings\Nick\Local Settings\Application Data\Mozilla
[2009/04/23 09:26:33 | 00,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2009/04/23 09:23:09 | 00,000,330 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/04/23 09:19:36 | 00,000,000 | —D | C] – C:\Program Files\Windows Defender
[2009/04/15 23:20:13 | 00,000,000 | —D | C] – C:\WINDOWS\solcache
[2009/04/15 23:19:07 | 00,000,000 | —D | C] – C:\SIERRA
[2009/04/15 23:19:07 | 00,000,000 | —D | C] – C:\Program Files\Sierra On-Line
[2009/04/15 23:18:34 | 00,000,421 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2009/04/15 23:18:34 | 00,000,231 | —- | C] () – C:\WINDOWS\system.bak
[2009/04/15 21:47:39 | 00,399,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/04/15 21:47:39 | 00,283,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/04/15 21:47:39 | 00,060,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\colbact.dll
[2009/04/15 21:47:38 | 00,473,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/04/15 21:47:38 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/04/15 21:47:38 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/04/15 21:47:38 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/04/15 21:47:37 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/04/15 21:47:37 | 00,616,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/04/15 21:47:21 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/04/11 00:34:05 | 00,000,000 | —D | C] – C:\Documents and Settings\Nick\Desktop\ratz
[2009/04/10 16:34:37 | 00,000,000 | —D | C] – C:\Documents and Settings\Nick\Application Data\KompoZer
[2009/04/04 07:56:46 | 00,189,472 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.xtr
[2009/02/12 04:03:16 | 00,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/11/15 18:04:05 | 00,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2008/09/25 11:44:25 | 00,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2008/09/25 11:43:38 | 00,000,079 | —- | C] () – C:\WINDOWS\EPSCX7400.ini
[2008/09/04 12:34:45 | 00,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2008/07/17 00:41:33 | 00,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2008/07/17 00:41:33 | 00,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2008/07/17 00:41:33 | 00,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/06/26 01:03:06 | 00,138,168 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2008/03/21 16:27:47 | 00,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/03/14 19:20:52 | 00,003,972 | —- | C] () – C:\WINDOWS\System32\drivers\PciBus.sys
[2008/02/02 20:42:52 | 00,765,952 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/02/02 20:42:52 | 00,164,352 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2007/12/11 14:46:02 | 03,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007/12/11 14:44:28 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2007/12/11 14:44:28 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dpl100.dll.manifest
[2007/12/11 14:43:44 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/05/13 09:20:37 | 00,000,705 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/01/14 11:03:12 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2006/07/27 22:36:52 | 00,205,824 | —- | C] () – C:\WINDOWS\patchw32.dll
[2006/07/27 22:36:22 | 00,205,824 | —- | C] () – C:\WINDOWS\pw32a.dll
[2006/07/27 22:36:21 | 00,205,824 | —- | C] () – C:\WINDOWS\System32\pw32a.dll
[2006/07/19 21:23:20 | 00,006,656 | —- | C] () – C:\WINDOWS\System32\drivers\AsProbe.sys
[2006/07/19 21:22:58 | 00,006,272 | —- | C] () – C:\WINDOWS\System32\drivers\ASLM75.SYS
[2006/07/19 21:16:29 | 00,028,672 | —- | C] () – C:\WINDOWS\System32\cmirmdrv.dll
[2006/07/19 21:15:48 | 00,005,810 | —- | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2006/07/19 21:15:46 | 00,008,094 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2006/07/19 21:15:44 | 00,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2003/03/31 07:00:00 | 00,000,517 | —- | C] () – C:\WINDOWS\win.ini
[2003/03/31 07:00:00 | 00,000,231 | —- | C] () – C:\WINDOWS\system.ini

========== Files - Modified Within 30 Days ==========

[4 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/04/28 18:00:58 | 00,397,560 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/04/28 18:00:58 | 00,059,780 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/04/28 18:00:57 | 00,464,860 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/28 17:59:44 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/04/28 17:57:13 | 00,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/04/28 17:56:45 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/28 17:56:39 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/04/28 17:54:33 | 00,000,420 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{F5C1E708-14C3-4466-87EE-274879040027}.job
[2009/04/28 16:49:29 | 00,001,709 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/04/28 16:49:28 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/04/28 16:48:01 | 00,308,160 | —- | M] (ALWIL Software) – C:\Documents and Settings\Nick\Desktop\avast_home_setup.exe
[2009/04/28 14:19:39 | 00,000,767 | —- | M] () – C:\Documents and Settings\Nick\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/04/28 13:17:27 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/04/27 23:36:39 | 00,193,024 | —- | M] () – C:\Documents and Settings\Nick\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/23 15:52:23 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/04/23 15:24:27 | 16,883,056 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Nick\Desktop\IE8-WindowsXP-x86-ENU.exe
[2009/04/23 09:26:42 | 00,000,000 | —- | M] () – C:\WINDOWS\nsreg.dat
[2009/04/16 00:11:09 | 02,105,962 | -H– | M] () – C:\Documents and Settings\Nick\Local Settings\Application Data\IconCache.db
[2009/04/15 23:33:19 | 00,000,421 | —- | M] () – C:\WINDOWS\SIERRA.INI
[2009/04/06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/06 07:57:26 | 24,921,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/04/05 12:19:51 | 00,138,168 | —- | M] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/04/05 12:19:42 | 00,189,472 | —- | M] () – C:\WINDOWS\System32\PnkBstrB.xtr
[2009/04/05 12:19:42 | 00,189,472 | —- | M] () – C:\WINDOWS\System32\PnkBstrB.exe
< End of report >


I have a victory beer ready to go, awaiting further orders captain!
_Nick
Ive got to say. sir. you are a hero! With the possible exception of the error from my copy paste mistake i think we are good to go.Unless you think I ought to take further action, lets call this case closed. Point me at the donation area kind sir. and THANKYOU!
After such fullsome praise what can I say but……………………… (OTLI worked around the error :thumbup: )

Now the best part of the day —– Your log now appears clean :thumbup:

A good workman always cleans up after himself so..Run OTListit and hit the cleanup button. It will remove all the programmes we have used plus itself. MBAM can be uninstalled via control panel add/remove along with ERUNT. But they may be useful tools to keep

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.

[external image: Posted Image] Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. Beware it is NOT supported for use in 9x or ME and probably will not install in those systems

Upgrading Java:
  • Download the latest version of Java SE Runtime Environment (JRE)JRE 6 Update 13.
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u13-windows-i586-p.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the jre-6u13-windows-i586-p.exe and select "Run as an Administrator.")

XP
Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:
  • Select Start > All Programs > Accessories > System tools > System Restore.
  • On the dialogue box that appears select Create a Restore Point
  • Click NEXT
  • Enter a name e.g. Clean
  • Click CREATE
You now have a clean restore point, to get rid of the bad ones:
  • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
  • In the Drop down box that appears select your main drive e.g. C
  • Click OK
  • The System will do some calculation and the display a dialogue box with TABS
  • Select the More Options Tab.
  • At the bottom will be a system restore box with a CLEANUP button click this
  • Accept the Warning and select OK again, the program will close and you are done

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
  • SpywareBlaster to help prevent spyware from installing in the first place.
  • SuperAntispyware Run weekly to keep your system clean
It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit

To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?
Keep safe :wavey:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI