This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Possible Trojan infection on my PC

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Windows XP stops responding entirely. When I manually shut down and restart the computer, upon login it appears as if an invisible Internet Explorer is opened. I hear the clicks that IE makes when loading a webpage. I also even hear the pop up blocker sound, and see the pop up block display on my desktop, but no actual IE window. Task Manager does not recognize that IE is open. Any help is greatly appreciated!!
Also, when I try to run Malwarebytes' Anti-Malware, nothing happens! The program will not open anymore. So I uninstalled, and installed it again. When I try and open the setup .EXE, nothing happens either. Very strange.
Here's an update to what else this nasty bug is doing. Whenever I run a Google search, the results page will load. Then when I click on a link on that page, I will be redirected to an advertisement page that has nothing to do with my search query, nor is of the same domain. So I can't search anymore. This is very frustrating!
GooredFix v1.92 by jpshortstuff
Log created at 10:58 on 27/05/2009 running Option #1 (Victor A. Vega)
Firefox version 3.0.10 (en-US)

=====Suspect Goored Entries=====

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"="C:\Program Files\Real\RealPlayer\browserrecord"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{9E21F5DF-0A73-4f7f-A28B-BDFF2D1C87AB}"="C:\Program Files\Autobahn\Extensions\{9E21F5DF-0A73-4f7f-A28B-BDFF2D1C87AB}"




OTL logfile created on: 5/27/2009 11:00:39 AM - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\Victor A. Vega\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 10000 50000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 460.96 Gb Total Space | 46.44 Gb Free Space | 10.07% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DHRCJ081
Current User Name: Victor A. Vega
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
PRC - C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
PRC - C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
PRC - C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE (Creative Technology Ltd)
PRC - C:\WINDOWS\system32\CTHELPER.EXE (Creative Technology Ltd)
PRC - C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (CyberLink Corp.)
PRC - C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
PRC - C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe ()
PRC - C:\Program Files\Philips\Philips Device Manager\Bin\DeviceManager.exe (Koninklijke Philips Electronics N.V.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe ()
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
PRC - C:\WINDOWS\system32\CTsvcCDA.EXE (Creative Technology Ltd)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
PRC - C:\Program Files\Philips\Philips Lime Service\bin\LimeAlive.exe (Philips)
PRC - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe (Intel Corporation)
PRC - C:\Program Files\Philips\Philips Lime Service\bin\Lime.exe (Koninklijke Philips Electronics N.V.)
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
PRC - c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
PRC - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe (Microsoft Corporation)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\WINDOWS\eHome\ehmsas.exe (Microsoft Corporation)
PRC - C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\Victor A. Vega\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Creative Service for CDROM Access [Auto | Running]) – C:\WINDOWS\system32\CTsvcCDA.EXE (Creative Technology Ltd)
SRV - (dlbt_device [On_Demand | Stopped]) – C:\WINDOWS\system32\dlbtcoms.exe (Dell)
SRV - (ehRecvr [Auto | Running]) – C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [Auto | Running]) – C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (GoogleDesktopManager-022208-143751 [On_Demand | Stopped]) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IAANTMon [Auto | Running]) – C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe (Intel Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (KodakCCS [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\KodakCCS.exe (Eastman Kodak Company)
SRV - (MBackMonitor [On_Demand | Stopped]) – C:\Program Files\McAfee\MBK\MBackMonitor.exe (McAfee)
SRV - (mcmscsvc [Auto | Running]) – C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (McNASvc [Auto | Running]) – c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
SRV - (McODS [On_Demand | Stopped]) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McProxy [Auto | Running]) – c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McrdSvc [Auto | Running]) – C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
SRV - (McShield [Unknown | Running]) – C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV - (McSysmon [On_Demand | Running]) – C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (MHN [On_Demand | Stopped]) – C:\WINDOWS\System32\mhn.dll (Microsoft Corporation)
SRV - (MpfService [Auto | Running]) – C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (MSSQL$MICROSOFTBCM [Auto | Running]) – C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (MSSQLServerADHelper [On_Demand | Stopped]) – C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NMSAccessU [Auto | Running]) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (SQLAgent$MICROSOFTBCM [On_Demand | Stopped]) – C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlagent.EXE (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (AliIde [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (CdaD10BA [Auto | Running]) – C:\WINDOWS\system32\drivers\CdaD10BA.SYS (Macrovision Europe Ltd)
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (ctac32k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (ctaud2k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctdvda2k [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (CW50 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\CW50.sys (CASIO COMPUTER CO.,LTD.)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (DcCam [System | Running]) – C:\WINDOWS\system32\DRIVERS\DcCam.sys (Eastman Kodak Company)
DRV - (DcFpoint [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\DcFpoint.sys (Eastman Kodak Company)
DRV - (DCFS2K [Auto | Running]) – C:\WINDOWS\system32\drivers\dcfs2k.sys (Eastman Kodak Company)
DRV - (DcLps [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\DcLps.sys (Eastman Kodak Company)
DRV - (DcPTP [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\DcPTP.sys (Eastman Kodak Company)
DRV - (drvmcdb [Boot | Running]) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm [Auto | Running]) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (E100B [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (emupia [On_Demand | Running]) – C:\WINDOWS\System32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (Exportit [System | Stopped]) – C:\WINDOWS\system32\DRIVERS\exportit.sys (Eastman Kodak Company)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (ha10kx2k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (hap16v2k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\hap16v2k.sys (Creative Technology Ltd)
DRV - (HDAudBus [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (HSFHWBS2 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSF_DP [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (iastor [Boot | Running]) – C:\WINDOWS\system32\drivers\iastor.sys (Intel Corporation)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (mfeavfk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfebopk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk [System | Running]) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdk [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (mfesmfk [On_Demand | Running]) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (MODEMCSA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (MPFP [System | Running]) – C:\WINDOWS\System32\Drivers\Mpfp.sys (McAfee, Inc.)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (NAL [On_Demand | Stopped]) – C:\WINDOWS\system32\Drivers\iqvw32.sys (Intel Corporation )
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (omci [System | Running]) – C:\WINDOWS\system32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (ossrv [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (OVT511Plus [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\omcamvid.sys (OmniVision Technologies, Inc.)
DRV - (PfModNT [Auto | Running]) – C:\WINDOWS\system32\drivers\PfModNT.sys (Creative Technology Ltd.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (Secdrv [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (SONYPVU1 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS (Sony Corporation)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sscdbhk5 [System | Running]) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln [System | Running]) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (STHDA [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (tfsnboio [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsncofs [Auto | Running]) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsndrct [Auto | Running]) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres [Auto | Running]) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (tfsnifs [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsnopio [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsnudf [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnudfa [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.facebook.com/home.php? [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig?sourceid=navclien…UTF-8&hl=en
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Ask"
FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query="
FF - prefs.js..browser.search.order.1: "Ask"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.2
FF - prefs.js..extensions.enabledItems: [removed]:1.10
FF - prefs.js..extensions.enabledItems: {1018e4d6-728f-4b20-ad56-37578a4de76b}:3.3.12
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:[removed]
FF - prefs.js..extensions.enabledItems: {3112ca9c-de6d-4884-a869-9855de68056c}:3.1.20081127W
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10
FF - prefs.js..keyword.URL: "http://toolbar.ask.com/toolbarv/askRedirect?o=20008&gct=&gc=1&q="


FF - HKLM\software\mozilla\Firefox\Extensions\\{9E21F5DF-0A73-4f7f-A28B-BDFF2D1C87AB}: C:\PROGRAM FILES\AUTOBAHN\EXTENSIONS\{9E21F5DF-0A73-4F7F-A28B-BDFF2D1C87AB} [2008/02/28 21:41:26 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD [2008/04/04 12:57:45 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/03/11 17:07:10 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/05/11 21:19:45 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/05/26 19:26:12 | 00,000,000 | —D | M]

[2008/06/17 19:26:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\mozilla\Extensions
[2008/06/17 19:26:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/05/26 16:35:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\mozilla\Firefox\Profiles\kyqyolkb.default\extensions
[2009/05/05 23:31:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\mozilla\Firefox\Profiles\kyqyolkb.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2009/04/29 22:06:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\mozilla\Firefox\Profiles\kyqyolkb.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
[2009/01/08 00:45:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\mozilla\Firefox\Profiles\kyqyolkb.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/04/29 22:06:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\mozilla\Firefox\Profiles\kyqyolkb.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/04/29 22:06:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\mozilla\Firefox\Profiles\kyqyolkb.default\extensions\[removed]
[2008/11/18 21:16:27 | 00,001,739 | —- | M] () – C:\Documents and Settings\Victor A. Vega\Application Data\Mozilla\FireFox\Profiles\kyqyolkb.default\searchplugins\aim-search.xml
[2008/02/23 09:07:53 | 00,001,877 | —- | M] () – C:\Documents and Settings\Victor A. Vega\Application Data\Mozilla\FireFox\Profiles\kyqyolkb.default\searchplugins\aolsearch.xml
[2008/12/23 11:33:47 | 00,000,681 | —- | M] () – C:\Documents and Settings\Victor A. Vega\Application Data\Mozilla\FireFox\Profiles\kyqyolkb.default\searchplugins\ask.xml
[2007/02/17 12:34:16 | 00,002,386 | —- | M] () – C:\Documents and Settings\Victor A. Vega\Application Data\Mozilla\FireFox\Profiles\kyqyolkb.default\searchplugins\siteadvisor.xml
[2008/06/19 07:55:00 | 00,000,681 | —- | M] () – C:\Documents and Settings\Victor A. Vega\Application Data\Mozilla\FireFox\Profiles\kyqyolkb.default\searchplugins\webster.xml
[2009/01/08 12:29:34 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/04/29 08:40:05 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/04/29 08:40:01 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/29 08:40:01 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/02/04 22:39:11 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/02/04 22:39:11 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/02/04 22:39:11 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/02/04 22:39:11 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/02/04 22:39:11 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/02/04 22:39:11 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/02/04 22:39:11 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (148 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 94.232.248.66 browser-security.microsoft.com
O1 - Hosts: 94.232.248.66 antivaresys.com
O1 - Hosts: 94.232.248.66 www.antivaresys.com
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - Reg Error: Key error. File not found
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {724D43A0-0D85-11D4-9908-00400523E39A} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {724D43A0-0D85-11D4-9908-00400523E39A} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE" (Creative Technology Ltd)
O4 - HKLM..\Run: [CTHelper] CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r (Creative Technology Ltd)
O4 - HKLM..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe" ()
O4 - HKLM..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [DLBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16 ()
O4 - HKLM..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup (Google)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start (InstallShield Software Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey (McAfee, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [PhilipsDM] "C:\Program Files\Philips\Philips Device Manager\Bin\DeviceManager.exe" (Koninklijke Philips Electronics N.V.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE (Creative Technology Ltd.)
O4 - HKCU..\Run: [Antispyware] C:\Program Files\Antispyware\Antispyware.exe -boot File not found
O4 - HKCU..\Run: [MalwareRemovalBot] C:\Program Files\MalwareRemovalBot\MalwareRemovalBot.exe -boot File not found
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [PhilipsLime] "C:\Program Files\Philips\Philips Lime Service\bin\LimeAlive.exe" (Philips)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1 (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm ()
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www1.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {483EB14D-AF1C-4951-81B0-4E2B41829FF6} https://www.select2perform.com/cabs/QOLCheck.ocx (QOLCheck Control)
O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} http://www.cyberlink.com/winxp/CheckDVD.cab (ChkDVDCtl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Fireplace Active Desktop Component) - E207A920-9461-468F-88B8-2021AF3B424D
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/19 17:07:14 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\GMTsetup.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/05/27 10:59:10 | 00,000,000 | —D | M]

========== Files/Folders - Created Within 30 Days ==========

[2099/01/01 12:00:00 | 00,006,456 | -H– | C] () – C:\WINDOWS\System32\logahiju
[2009/05/27 10:59:10 | 00,501,760 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Victor A. Vega\Desktop\OTL.exe
[2009/05/27 10:58:09 | 00,094,208 | —- | C] () – C:\Documents and Settings\Victor A. Vega\Desktop\GooredFix.exe
[2009/05/26 18:58:41 | 00,000,562 | —- | C] () – C:\WINDOWS\tasks\MalwareRemovalBot Scheduled Scan.job
[2009/05/26 18:58:41 | 00,000,000 | —D | C] – C:\Documents and Settings\Victor A. Vega\Application Data\MalwareRemovalBot
[2009/05/26 18:52:14 | 00,000,514 | —- | C] () – C:\WINDOWS\tasks\Antispyware Scheduled Scan.job
[2009/05/26 18:52:13 | 00,000,000 | —D | C] – C:\Documents and Settings\Victor A. Vega\Application Data\Antispyware
[2009/05/26 16:16:37 | 00,307,216 | —- | C] () – C:\WINDOWS\sysguard.exe
[2009/05/26 10:09:43 | 26,882,447 | —- | C] () – C:\Documents and Settings\Victor A. Vega\Desktop\01 Time Turns Elastic.m4a
[2008/10/06 00:09:08 | 00,000,039 | —- | C] () – C:\WINDOWS\Irremote.ini
[2008/07/01 15:44:33 | 00,000,094 | —- | C] () – C:\WINDOWS\awshkwv.ini
[2008/03/31 17:25:46 | 00,831,488 | —- | C] () – C:\WINDOWS\System32\divx_xx0a.dll
[2008/03/21 16:30:08 | 03,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/03/21 16:28:54 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2008/03/21 16:28:54 | 00,000,416 | —- | C] () – C:\WINDOWS\System32\dpl100.dll.manifest
[2008/03/21 16:28:20 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/11/21 12:24:43 | 00,000,046 | —- | C] () – C:\WINDOWS\webica.ini
[2007/06/16 01:05:43 | 00,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2007/02/02 20:56:40 | 00,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2007/01/16 20:31:53 | 00,000,004 | —- | C] () – C:\WINDOWS\UccSpecB.sys
[2006/12/31 19:55:48 | 00,262,144 | —- | C] () – C:\WINDOWS\System32\TwcToolbarIe7.dll
[2006/12/31 19:55:48 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\TwcToolbarBho.dll
[2006/05/21 18:55:40 | 00,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2006/05/21 18:55:40 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2006/05/21 18:55:40 | 00,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2006/05/21 18:55:40 | 00,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2006/05/21 18:55:39 | 00,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2006/05/21 18:55:39 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2006/03/19 16:20:39 | 00,000,021 | —- | C] () – C:\WINDOWS\atid.ini
[2005/10/16 00:33:39 | 00,051,207 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2005/10/08 11:58:14 | 00,000,023 | —- | C] () – C:\WINDOWS\kodakpcd.Victor A. Vega.ini
[2005/10/07 18:44:09 | 00,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005/09/12 22:12:53 | 00,528,384 | —- | C] () – C:\WINDOWS\System32\BladeEnc.dll
[2005/09/12 22:12:53 | 00,120,832 | —- | C] () – C:\WINDOWS\System32\ShnDll32.dll
[2005/09/12 22:09:09 | 00,001,125 | —- | C] () – C:\WINDOWS\winamp.ini
[2005/09/10 09:12:26 | 00,000,892 | —- | C] () – C:\WINDOWS\dellstat.ini
[2005/08/05 15:01:54 | 00,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/07/27 13:41:32 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/07/27 13:37:51 | 00,000,138 | —- | C] () – C:\WINDOWS\wininit.ini
[2005/07/27 13:26:31 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/07/27 13:24:04 | 00,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2005/07/27 13:23:45 | 00,014,424 | —- | C] () – C:\WINDOWS\System32\Aud2_Del.ini
[2005/07/27 13:23:45 | 00,000,030 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2005/07/27 13:23:44 | 00,000,194 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2005/07/27 13:23:43 | 00,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[2005/07/27 13:23:24 | 00,000,136 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2005/07/27 13:02:14 | 00,000,430 | —- | C] () – C:\WINDOWS\System32\dlbtplc.ini
[2005/07/27 13:01:10 | 00,000,375 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2005/07/15 14:35:56 | 00,831,488 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2005/07/15 14:35:56 | 00,159,744 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2004/11/09 19:11:08 | 00,114,688 | —- | C] () – C:\WINDOWS\System32\dlbtcur.dll
[2004/11/09 19:10:28 | 00,573,440 | —- | C] () – C:\WINDOWS\System32\dlbtjswr.dll
[2004/11/09 19:05:58 | 00,069,632 | —- | C] () – C:\WINDOWS\System32\dlbtcu.dll
[2004/11/09 18:59:26 | 00,405,504 | —- | C] () – C:\WINDOWS\System32\dlbtutil.dll
[2004/08/23 15:42:30 | 00,131,072 | —- | C] () – C:\WINDOWS\System32\dlbtsnls.dll
[2004/08/23 15:40:14 | 00,143,360 | —- | C] () – C:\WINDOWS\System32\dlbtcoin.dll
[2004/08/19 17:20:39 | 00,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/19 16:49:59 | 00,000,738 | —- | C] () – C:\WINDOWS\win.ini
[2004/08/19 16:49:56 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2003/10/08 15:09:46 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\dlbtvs.dll
[2003/01/07 16:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/09/18 12:00:00 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\bmpproc.dll
[2000/09/08 17:53:50 | 00,073,839 | —- | C] () – C:\WINDOWS\System32\KodakOneTouch.dll

========== Files - Modified Within 30 Days ==========

[14 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/05/27 10:59:10 | 00,501,760 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Victor A. Vega\Desktop\OTL.exe
[2009/05/27 10:58:09 | 00,094,208 | —- | M] () – C:\Documents and Settings\Victor A. Vega\Desktop\GooredFix.exe
[2009/05/27 10:52:50 | 00,011,631 | —- | M] () – C:\WINDOWS\System32\Config.MPF
[2009/05/27 10:52:47 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/05/27 10:52:17 | 00,007,275 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/05/27 10:52:14 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\Victor A. Vega\Local Settings\desktop.ini
[2009/05/27 10:52:09 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/05/27 10:52:05 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/05/27 10:52:04 | 34,877,23520 | -HS- | M] () – C:\hiberfil.sys
[2009/05/27 09:42:45 | 00,290,088 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/05/26 19:10:38 | 00,032,592 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000005-00000000-00000004-00001102-00000004-20061102}.rfx
[2009/05/26 19:10:38 | 00,032,592 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000005-00000000-00000004-00001102-00000004-20061102}.rfx
[2009/05/26 19:10:38 | 00,032,088 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000005-00000000-00000004-00001102-00000004-20061102}.rfx
[2009/05/26 19:10:38 | 00,032,088 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000005-00000000-00000004-00001102-00000004-20061102}.rfx
[2009/05/26 19:10:38 | 00,001,072 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2009/05/26 19:10:38 | 00,001,072 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2009/05/26 19:10:38 | 00,000,384 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000005-00000000-00000004-00001102-00000004-20061102}.dat
[2009/05/26 19:10:38 | 00,000,384 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000005-00000000-00000004-00001102-00000004-20061102}.dat
[2009/05/26 18:58:41 | 00,000,562 | —- | M] () – C:\WINDOWS\tasks\MalwareRemovalBot Scheduled Scan.job
[2009/05/26 18:52:14 | 00,000,514 | —- | M] () – C:\WINDOWS\tasks\Antispyware Scheduled Scan.job
[2009/05/26 16:16:13 | 00,307,216 | —- | M] () – C:\WINDOWS\sysguard.exe
[2009/05/26 10:10:27 | 26,882,447 | —- | M] () – C:\Documents and Settings\Victor A. Vega\Desktop\01 Time Turns Elastic.m4a
[2009/05/21 21:08:57 | 00,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/05/15 01:40:37 | 00,000,358 | —- | M] () – C:\WINDOWS\tasks\McDefragTask.job
[2009/05/07 03:16:29 | 24,699,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/05/01 01:00:21 | 00,000,350 | —- | M] () – C:\WINDOWS\tasks\McQcTask.job
[2009/04/27 20:46:53 | 00,002,187 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk

========== LOP Check ==========

[2009/03/26 08:01:07 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/03/26 08:01:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2008/11/18 21:11:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2006/10/10 08:25:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2005/12/05 21:23:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe Systems
[2005/10/07 21:28:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ahead
[2006/03/19 16:25:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2008/11/18 21:14:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL Downloads
[2006/10/31 19:54:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL OCP
[2008/02/01 20:59:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2006/11/01 21:25:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/01/26 01:03:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Dell
[2004/08/19 17:16:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DIGStream
[2008/05/19 11:26:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2009/02/09 12:23:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2009/01/29 23:21:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2005/07/27 13:34:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2005/07/27 13:37:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2005/10/08 10:59:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kodak
[2009/02/04 14:45:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/12 04:32:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2007/02/17 10:02:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2008/03/15 13:02:35 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/12/07 20:57:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2009/03/11 17:37:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nero
[2005/09/13 21:56:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Otto
[2005/10/22 10:13:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2008/03/15 12:48:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2005/07/27 13:36:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2006/11/17 22:51:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2004/08/19 17:22:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2008/08/28 22:37:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SiteAdvisor
[2008/12/29 21:23:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Skype
[2005/11/28 18:08:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2009/01/29 22:45:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/07/05 19:24:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2007/01/30 21:05:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2009/05/26 18:58:41 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Victor A. Vega\Application Data
[2006/02/02 21:32:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\.bittorrent
[2006/03/19 16:26:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\acccore
[2008/08/10 17:07:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Adobe
[2006/03/23 21:29:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\AdobeAUM
[2006/12/27 20:22:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\AdobeUM
[2005/10/07 21:19:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Ahead
[2006/11/20 23:07:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Aim
[2009/05/26 18:52:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Antispyware
[2008/08/13 19:11:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Apple Computer
[2007/07/06 22:45:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Audacity
[2009/03/11 17:08:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Canneverbe_Limited
[2006/03/03 23:00:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Creative
[2006/11/26 14:47:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\CyberLink
[2008/06/12 21:55:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Digsby
[2006/12/27 17:25:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\DivX
[2008/06/18 13:35:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\eFax Messenger
[2005/11/28 18:09:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\funkitron
[2008/08/03 21:56:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\GARMIN
[2006/01/22 22:53:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Google
[2009/01/29 23:21:34 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Gtek
[2005/11/06 10:40:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Help
[2009/02/05 19:03:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\ICAClient
[2004/08/19 17:14:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Identities
[2006/05/21 19:10:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\InterVideo
[2005/07/27 13:34:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Jasc Software Inc
[2005/10/29 14:05:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Lavasoft
[2005/09/10 10:55:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Leadertech
[2008/07/01 15:44:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Macromedia
[2009/02/04 14:45:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Malwarebytes
[2009/05/26 18:58:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\MalwareRemovalBot
[2008/11/18 14:26:52 | 00,000,000 | –SD | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Microsoft
[2008/06/17 19:26:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Mozilla
[2006/11/20 23:10:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\MSNInstaller
[2006/11/20 23:10:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Musicmatch
[2007/01/04 21:14:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\MySpace
[2008/10/06 08:15:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Nero
[2005/09/13 22:42:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Opera
[2005/09/13 21:56:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Otto
[2005/10/22 11:03:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\PlayFirst
[2008/11/18 21:16:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\QQ Games Plugin
[2006/02/26 18:53:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Raptisoft
[2008/03/28 16:53:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Real
[2009/03/19 09:48:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Sibelius Software
[2008/09/01 08:07:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\skypePM
[2007/08/05 15:15:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\SmartDraw
[2006/05/03 18:20:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Snapfish
[2005/09/10 10:56:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Sonic
[2005/07/27 13:19:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Sun
[2005/10/07 19:21:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Talkback
[2008/11/18 21:14:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\Tencent
[2009/05/27 10:43:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\uTorrent
[2006/08/16 21:57:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor A. Vega\Application Data\verbix
[2009/05/26 18:52:14 | 00,000,514 | —- | M] () – C:\WINDOWS\Tasks\Antispyware Scheduled Scan.job
[2004/08/10 06:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/05/26 18:58:41 | 00,000,562 | —- | M] () – C:\WINDOWS\Tasks\MalwareRemovalBot Scheduled Scan.job
[2009/05/15 01:40:37 | 00,000,358 | —- | M] () – C:\WINDOWS\Tasks\McDefragTask.job
[2009/05/01 01:00:21 | 00,000,350 | —- | M] () – C:\WINDOWS\Tasks\McQcTask.job
[2009/05/27 10:52:09 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

< End of report >
GMER.EXE will not run on my PC. I have unzipped it to my desktop, I double-click the icon, I select Run, and nothing happens.
Can someone please help me?? I attend an online university and this is severely impacting my ability to do my work! Thank you!
Hi,

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2
Link 3

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–

Right-click on Combo-Fix.exe, select Run As Administrator… & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a HijackThis log so we can continue cleaning the system.
If you know the password for your Administrator account use that one, otherwise just run it as the current user.
I am receiving the following error message when trying to run Combo-Fix.exe:

C:\Documents and Settings\Victor A. Vega\Desktop\Combo-Fix.exe is not a valid Win32 application.


:smack:
Hi,

Download Rooter.exe to your desktop
  • Doubleclick it to start the tool.
  • A Notepad file containing the report will open, also found at %systemdrive%(usually C:)\Rooter.txt. Copy and paste it into your next reply.

Please download DDS and save it to your desktop.
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
I can't run either of those programs either. The same error message appears telling me that they are not valid Win32 applications.
Hmm, this doesn't look good.

We need to upload a file to Jotti

1. Click HERE to get to Jotti's site.

2. At the top of the Jotti window, use the Browse button to locate the following file on your system:

C:\WINDOWS\system32\userinit.exe

3. Once you have located the file, click SUBMIT and the content of the file will be uploaded by the site and analysed.

4. Please provide me with the results of the analysis.

5. Please repeat steps 2-4 for the following files:
C:\WINDOWS\system32\svchost.exe

Thanks.
Filename: userinit.exe Status: Scan finished. 0 out of 19 scanners reported malware. Filename: svchost.exe Status: Scan finished. 0 out of 20 scanners reported malware.
Nope, not the infection I thought it might be.

Click Start >> Control Panel >> Add/Remove Programs. Find and Remove these items (if present):
AntiSyware
MalwareRemovalBot



Please Right Click your Start button, and click Explore.
Next, locate and delete the following files and folders (if present):

C:\WINDOWS\System32\logahiju
C:\WINDOWS\sysguard.exe

If any of them aren't there then don't worry, but if you have a problem deleting one of them then please let me know.


Please try booting into Safe Mode (restart and tap F8 before Windows loads) and try running Combo-Fix or the other failed tools again. Do you have a Windows Installation Disk?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI