This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Possible Viruses...

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Have followed the instructions posted on another forum….I have downloaded and ran ERUNT, OTL, SDFIX, MALWAREBYTES, created a system restore point, and did a root repeal.

Here are the logs:

OTL

OTL logfile created on: 8/8/2009 2:45:16 PM - Run 2
OTL by OldTimer - Version 3.0.10.4 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Tablet PC Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.04 Mb Total Physical Memory | 478.23 Mb Available Physical Memory | 47.16% Memory free
2.38 Gb Paging File | 1.86 Gb Available in Paging File | 78.04% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 86.31 Gb Total Space | 41.86 Gb Free Space | 48.50% Space Free | Partition Type: NTFS
Drive D: | 6.83 Gb Total Space | 3.08 Gb Free Space | 45.16% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-E82B12DEB8
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2005/12/28 12:45:02 | 00,114,753 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
PRC - [2004/08/04 07:00:00 | 00,029,696 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Ink\KeyboardSurrogate.exe
PRC - [2005/12/28 12:47:10 | 00,540,745 | —- | M] (Intel Corporation ) – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
PRC - [2009/02/05 15:01:25 | 00,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/02/05 15:08:40 | 00,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2004/08/04 07:00:00 | 00,293,376 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\WISPTIS.EXE
PRC - [2002/08/29 05:41:28 | 00,035,328 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tabbtnu.exe
PRC - [2004/08/04 07:00:00 | 01,032,192 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2004/08/04 07:00:00 | 00,043,520 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Ink\TCServer.exe
PRC - [2008/12/16 02:43:13 | 00,169,984 | —- | M] () – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
PRC - [2004/11/05 10:47:00 | 00,098,394 | —- | M] (Synaptics, Inc.) – C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
PRC - [2004/10/15 15:54:14 | 00,100,016 | —- | M] (America Online, Inc) – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
PRC - [2004/08/04 07:00:00 | 00,271,872 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Ink\TabTip.exe
PRC - [2004/11/05 10:47:00 | 00,688,218 | —- | M] (Synaptics, Inc.) – C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2005/10/12 13:30:24 | 00,086,140 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
PRC - [2004/10/15 15:54:12 | 00,046,768 | —- | M] (America Online Inc) – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
PRC - [2008/12/16 02:43:13 | 00,555,008 | —- | M] () – C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
PRC - [2008/12/16 02:59:47 | 00,172,032 | —- | M] (New Boundary Technologies, Inc.) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
PRC - [2005/10/12 13:30:42 | 00,139,264 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
PRC - [2008/12/16 02:43:13 | 00,415,744 | —- | M] () – C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
PRC - [2005/12/28 12:44:24 | 00,217,164 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
PRC - [2006/01/20 15:34:26 | 00,544,768 | —- | M] (Motorola Inc.) – C:\WINDOWS\sm56hlpr.exe
PRC - [2008/12/16 18:51:39 | 00,570,880 | —- | M] (Crawler.com) – C:\Program Files\Spyware Terminator\sp_rsser.exe
PRC - [2005/01/12 04:01:32 | 00,032,768 | —- | M] (Cyberlink Corp.) – C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
PRC - [2006/03/23 15:13:40 | 00,077,824 | —- | M] (Intel Corporation) – C:\WINDOWS\System32\hkcmd.exe
PRC - [2006/03/23 15:17:50 | 00,118,784 | —- | M] (Intel Corporation) – C:\WINDOWS\System32\igfxpers.exe
PRC - [2006/03/23 15:13:30 | 00,163,840 | —- | M] (Intel Corporation) – C:\WINDOWS\System32\igfxsrvc.exe
PRC - [2005/12/28 12:55:40 | 00,667,718 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
PRC - [2004/08/11 02:45:04 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wdfmgr.exe
PRC - [2004/11/03 16:03:00 | 00,125,528 | —- | M] (America Online, Inc.) – C:\Program Files\Common Files\AOL\1229413987\EE\AOLHostManager.exe
PRC - [2005/12/28 12:56:16 | 00,602,182 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
PRC - [2005/12/27 11:20:14 | 00,413,696 | —- | M] (SigmaTel, Inc.) – C:\WINDOWS\stsystra.exe
PRC - [2008/12/16 02:54:12 | 00,098,304 | —- | M] (Apple Computer, Inc.) – C:\Program Files\QuickTime\qttask.exe
PRC - [2004/11/03 16:03:00 | 00,110,680 | —- | M] (America Online, Inc.) – C:\Program Files\Common Files\AOL\1229413987\EE\AOLServiceHost.exe
PRC - [2008/06/10 04:27:04 | 00,144,784 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
PRC - [2008/12/16 18:51:39 | 01,783,808 | —- | M] (Crawler.com) – C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
PRC - [2009/02/05 15:08:45 | 00,081,000 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009/05/09 18:28:24 | 00,068,856 | —- | M] (Google Inc.) – C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2009/01/09 19:57:32 | 07,424,000 | —- | M] (OpenOffice.org) – C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2009/01/09 20:00:52 | 07,418,368 | —- | M] (OpenOffice.org) – C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2009/02/05 15:08:26 | 00,254,040 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/02/05 15:06:04 | 00,352,920 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2005/12/28 12:52:32 | 00,397,381 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
PRC - [2009/08/05 17:35:35 | 00,307,704 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/07/01 11:33:33 | 02,426,728 | —- | M] (Crawler.com) – C:\Program Files\Crawler\CToolbar.exe
PRC - [2009/08/07 20:05:58 | 00,514,048 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe

========== Win32 Services (SafeList) ==========

SRV - [2004/10/15 15:54:14 | 00,100,016 | —- | M] (America Online, Inc) – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe – (AOL TopSpeedMonitor [Auto | Running])
SRV - [2005/09/23 08:28:32 | 00,029,896 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2009/02/05 15:01:25 | 00,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe – (aswUpdSv [Auto | Running])
SRV - [2009/02/05 15:08:40 | 00,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe – (avast! Antivirus [Auto | Running])
SRV - [2009/02/05 15:08:26 | 00,254,040 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe – (avast! Mail Scanner [On_Demand | Running])
SRV - [2009/02/05 15:06:04 | 00,352,920 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe – (avast! Web Scanner [On_Demand | Running])
SRV - [2005/09/23 08:28:56 | 00,066,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2005/12/28 12:45:02 | 00,114,753 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe – (EvtEng [Auto | Running])
SRV - [2008/12/01 11:59:52 | 00,033,752 | —- | M] (NOS Microsystems Ltd.) – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe – (getPlus® Helper [On_Demand | Stopped])
SRV - [2009/07/21 07:38:00 | 00,182,768 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc [On_Demand | Stopped])
SRV - [2004/08/04 07:00:00 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2005/10/12 13:30:24 | 00,086,140 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe – (IAANTMon [Auto | Running])
SRV - [2004/10/22 03:24:18 | 00,073,728 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
SRV - [2003/07/28 15:28:22 | 00,089,136 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2008/12/16 02:59:47 | 00,172,032 | —- | M] (New Boundary Technologies, Inc.) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS – (PrismXL [Auto | Running])
SRV - [2005/12/28 12:44:24 | 00,217,164 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe – (RegSrvc [Auto | Running])
SRV - [2005/12/28 12:47:10 | 00,540,745 | —- | M] (Intel Corporation ) – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe – (S24EventMonitor [Auto | Running])
SRV - [2008/12/16 18:51:39 | 00,570,880 | —- | M] (Crawler.com) – C:\Program Files\Spyware Terminator\sp_rsser.exe – (sp_rssrv [Auto | Running])
SRV - [2004/08/11 02:45:04 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wdfmgr.exe – (UMWdf [Auto | Running])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60076
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - URLSearchHook: {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\Program Files\Crawler\ctbr.dll (Crawler.com)
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?fr=ffsp1&p;="
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {4B3803EA-5230-4DC3-A7FC-33638F3D3542}:1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071303000006
FF - prefs.js..extensions.enabledItems: {9D6218B8-03C7-4b91-AA43-680B305DD35C}:[removed]
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.2.20080910
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.13
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=ffds1&p;="


FF - HKLM\software\mozilla\Firefox\Extensions\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}: C:\Program Files\Crawler\firefox\ [2009/04/30 18:07:13 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/08/05 17:35:42 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/08/05 17:35:42 | 00,000,000 | —D | M]

[2008/12/28 16:59:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions
[2008/12/28 16:59:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/08/07 22:04:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\pe030i71.default\extensions
[2009/03/22 20:42:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\pe030i71.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/01/07 18:27:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\pe030i71.default\extensions\{9D6218B8-03C7-4b91-AA43-680B305DD35C}
[2009/04/03 20:55:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\pe030i71.default\extensions\[removed]
[2009/08/07 22:04:40 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/08/05 17:35:35 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/03/22 22:32:02 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2009/08/05 17:35:35 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/08/05 17:35:35 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/08/05 17:35:36 | 00,065,528 | —- | M] (mozilla.org) – C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2009/01/14 22:07:44 | 00,106,496 | —- | M] (Apple Computer, Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/01/14 22:07:44 | 00,106,496 | —- | M] (Apple Computer, Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/01/14 22:07:44 | 00,106,496 | —- | M] (Apple Computer, Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/01/14 22:07:44 | 00,106,496 | —- | M] (Apple Computer, Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/01/14 22:07:44 | 00,106,496 | —- | M] (Apple Computer, Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/01/14 22:07:44 | 00,106,496 | —- | M] (Apple Computer, Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/04/14 22:49:18 | 00,221,184 | —- | M] (CNN) – C:\Program Files\mozilla firefox\plugins\NPTURNMED.dll
[2008/12/02 03:04:40 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/12/02 03:04:40 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2007/07/26 12:05:16 | 00,001,329 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\crawlersrch.xml
[2008/12/02 03:04:40 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/12/02 03:04:40 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/12/02 03:04:40 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/12/02 03:04:40 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/12/02 03:04:40 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (797 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 82.98.231.89 url.adtrgt.com
O1 - Hosts: 82.98.231.89 googleads2.gdoubleclick.net
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: () - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\Program Files\Crawler\ctbr.dll (Crawler.com)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\WINDOWS\System32\BAE.dll (Gateway Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Crawler; Toolbar) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Program Files\Crawler\ctbr.dll (Crawler.com)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Crawler; Toolbar) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Program Files\Crawler\ctbr.dll (Crawler.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Crawler; Toolbar) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Program Files\Crawler\ctbr.dll (Crawler.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe ()
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1229413987\EE\AOLHostManager.exe (America Online, Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE ()
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SMSERIAL] C:\WINDOWS\sm56hlpr.exe (Motorola Inc.)
O4 - HKLM..\Run: [Snippet] C:\Program Files\Microsoft Experience Pack\Snipping Tool\SnippingTool.exe (Microsoft Corporation)
O4 - HKLM..\Run: [SpywareTerminator] C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe (Crawler.com)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TabletTip] C:\Program Files\Common Files\microsoft shared\ink\tabtip.exe (Microsoft Corporation)
O4 - HKLM..\Run: [TabletWizard] C:\WINDOWS\help\SplshWrp.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: Crawler Search - File not found
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 28 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab (YInstStarter Class)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo2.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {8C279F4E-917E-4CD2-8DF0-D9C73C0CE763} http://zone.msn.com/bingame/zpagames/zpa_wof.cab55579.cab (ZPA_WheelOfFortune Object)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…k.cab102118.cab (MSN Games - Installer)
O16 - DPF: {C75BE5CC-7F80-458C-8B66-FAB86E3B13C3} http://images.fotki.com/activex/FotkiUploader.cab (FotkiUploader Control)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://l.yimg.com/jh/games/popcap/zuma/popcaploader_v6.cab (PopCapLoader Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\tbr {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\Program Files\Crawler\ctbr.dll (Crawler.com)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\loginkey: DllName - C:\Program Files\Common Files\Microsoft Shared\Ink\loginkey.dll - C:\Program Files\Common Files\Microsoft Shared\Ink\loginkey.dll (Microsoft Corporation)
O20 - Winlogon\Notify\TabBtnWL: DllName - TabBtnWL.dll - C:\WINDOWS\System32\TabBtnWL.dll (Microsoft Corporation)
O20 - Winlogon\Notify\tpgwlnotify: DllName - tpgwlnot.dll - C:\WINDOWS\System32\tpgwlnot.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/06/22 05:32:11 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2005/06/22 05:32:12 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/09/13 13:15:24 | 00,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

NetSvcs: 6to4 - Service key not found. File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Iprip - Service key not found. File not found
NetSvcs: Irmon - Service key not found. File not found
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)

========== Files/Folders - Created Within 14 Days ==========

[2009/08/08 14:07:24 | 00,000,000 | —- | C] () – C:\Documents and Settings\Owner\Desktop\windows-kb890830-v2.12.exe
[2009/08/07 22:27:34 | 00,608,344 | —- | C] () – C:\Documents and Settings\Owner\Desktop\MCPR.exe
[2009/08/07 20:14:17 | 00,463,768 | —- | C] () – C:\Documents and Settings\Owner\Desktop\RootRepeal.rar
[2009/08/07 20:05:58 | 00,514,048 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/08/07 19:34:00 | 00,000,201 | —- | C] () – C:\Boot.bak
[2009/08/07 19:33:56 | 00,260,272 | —- | C] () – C:\cmldr
[2009/08/07 19:33:46 | 00,000,000 | —D | C] – C:\cmdcons
[2009/08/07 19:31:44 | 00,217,088 | —- | C] () – C:\WINDOWS\PEV.exe
[2009/08/07 19:31:44 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/08/07 19:31:44 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/08/07 19:31:44 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/08/07 19:31:44 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/08/07 19:31:44 | 00,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2009/08/07 19:31:43 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/08/07 19:31:43 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/08/07 19:31:28 | 00,000,000 | –SD | C] – C:\ComboFix
[2009/08/07 19:29:49 | 00,000,000 | —D | C] – C:\Qoobox
[2009/08/07 19:29:35 | 00,000,000 | —D | C] – C:\32788R22FWJFW
[2009/08/07 19:18:23 | 00,000,000 | —D | C] – C:\SDFix
[2009/08/07 19:17:53 | 01,529,241 | —- | C] () – C:\Documents and Settings\Owner\Desktop\SDFix.exe
[2009/08/07 18:29:25 | 00,051,376 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/08/07 18:29:25 | 00,026,944 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/08/07 18:29:25 | 00,023,152 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/08/07 18:29:25 | 00,001,709 | —- | C] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/08/07 18:29:23 | 00,097,480 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\AvastSS.scr
[2009/08/07 18:29:22 | 00,114,768 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2009/08/07 18:29:22 | 00,094,032 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/08/07 18:29:22 | 00,093,296 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2009/08/07 18:29:22 | 00,020,560 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/08/07 18:29:05 | 01,256,296 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\aswBoot.exe
[2009/08/07 18:29:05 | 00,380,928 | —- | C] () – C:\WINDOWS\System32\actskin4.ocx
[2009/08/07 18:29:01 | 00,000,000 | —D | C] – C:\Program Files\Alwil Software
[2009/08/07 18:09:14 | 00,308,160 | —- | C] (ALWIL Software) – C:\Documents and Settings\Owner\Desktop\avast_home_setup.exe
[2009/08/07 17:46:50 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/08/07 17:46:22 | 00,000,611 | —- | C] () – C:\Documents and Settings\Owner\Desktop\NTREGOPT.lnk
[2009/08/07 17:46:22 | 00,000,592 | —- | C] () – C:\Documents and Settings\Owner\Desktop\ERUNT.lnk
[2009/08/07 17:46:21 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/08/07 17:45:40 | 00,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\Owner\Desktop\erunt_setup.exe
[2009/08/07 17:44:28 | 00,021,504 | —- | C] (Doug Knox) – C:\Documents and Settings\Owner\Desktop\SysRestorePoint(2).exe
[2009/08/07 17:43:26 | 00,021,504 | —- | C] (Doug Knox) – C:\Documents and Settings\Owner\Desktop\SysRestorePoint.exe
[2009/08/07 17:31:53 | 00,000,831 | —- | C] () – C:\WINDOWS\System32\critical_warning.html
[2009/08/07 17:22:05 | 00,272,384 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\TFC.exe
[2009/08/07 16:52:51 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\winhelper.dll
[2009/08/07 16:52:51 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\AVR09.exe
[2009/08/06 22:41:48 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/08/06 22:41:48 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for

========== Files - Modified Within 14 Days ==========

[2009/08/08 14:22:41 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/08/08 14:21:55 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/08/08 14:21:49 | 10,633,74848 | -HS- | M] () – C:\hiberfil.sys
[2009/08/08 14:07:24 | 00,000,000 | —- | M] () – C:\Documents and Settings\Owner\Desktop\windows-kb890830-v2.12.exe
[2009/08/07 22:27:36 | 00,608,344 | —- | M] () – C:\Documents and Settings\Owner\Desktop\MCPR.exe
[2009/08/07 21:50:37 | 00,112,832 | —- | M] () – C:\WINDOWS\System32\Status.MPF
[2009/08/07 20:14:17 | 00,463,768 | —- | M] () – C:\Documents and Settings\Owner\Desktop\RootRepeal.rar
[2009/08/07 20:05:58 | 00,514,048 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/08/07 19:34:00 | 00,000,270 | RHS- | M] () – C:\boot.ini
[2009/08/07 19:18:04 | 01,529,241 | —- | M] () – C:\Documents and Settings\Owner\Desktop\SDFix.exe
[2009/08/07 18:29:25 | 00,001,709 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/08/07 18:29:22 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/08/07 18:20:27 | 00,001,891 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/08/07 18:09:14 | 00,308,160 | —- | M] (ALWIL Software) – C:\Documents and Settings\Owner\Desktop\avast_home_setup.exe
[2009/08/07 18:03:18 | 00,000,714 | —- | M] () – C:\WINDOWS\win.ini
[2009/08/07 17:46:22 | 00,000,611 | —- | M] () – C:\Documents and Settings\Owner\Desktop\NTREGOPT.lnk
[2009/08/07 17:46:22 | 00,000,592 | —- | M] () – C:\Documents and Settings\Owner\Desktop\ERUNT.lnk
[2009/08/07 17:45:42 | 00,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Owner\Desktop\erunt_setup.exe
[2009/08/07 17:44:29 | 00,021,504 | —- | M] (Doug Knox) – C:\Documents and Settings\Owner\Desktop\SysRestorePoint(2).exe
[2009/08/07 17:43:26 | 00,021,504 | —- | M] (Doug Knox) – C:\Documents and Settings\Owner\Desktop\SysRestorePoint.exe
[2009/08/07 17:32:04 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\AVR09.exe
[2009/08/07 17:32:00 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\winhelper.dll
[2009/08/07 17:31:53 | 00,000,831 | —- | M] () – C:\WINDOWS\System32\critical_warning.html
[2009/08/07 17:22:06 | 00,272,384 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\TFC.exe
[2009/08/07 10:24:57 | 00,217,088 | —- | M] () – C:\WINDOWS\PEV.exe
[2009/08/06 22:41:48 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/08/06 22:41:48 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for

========== LOP Check ==========

[2009/05/09 20:23:34 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/12/16 02:56:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Agilix
[2008/12/16 02:56:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Agilix GoBinder
[2009/05/03 16:09:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2008/12/16 19:20:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intel
[2008/12/16 02:52:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2009/03/20 00:00:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2008/12/16 02:37:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Prism Deploy
[2008/12/16 02:53:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pure Networks
[2009/08/08 00:00:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spyware Terminator
[2009/04/27 19:54:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/12/16 02:53:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/05/03 16:09:58 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Owner\Application Data
[2009/05/25 17:53:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\CyberLink
[2009/04/04 23:57:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\EBookSys
[2009/04/10 12:56:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GetRightToGo
[2008/12/16 19:20:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Intel
[2009/05/16 19:25:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Move Networks
[2009/03/22 22:35:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\OpenOffice.org
[2008/12/16 02:58:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2009/02/15 15:01:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Snapfish
[2009/08/08 00:00:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Spyware Terminator
[2008/12/17 19:50:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Viewpoint
[2008/12/16 02:54:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\You've Got Pictures Screensaver
[2004/08/04 07:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/08/08 14:22:41 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >

========== Alternate Data Streams ==========

@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >

MBAM

Malwarebytes' Anti-Malware 1.36
Database version: 2067
Windows 5.1.2600 Service Pack 2

8/7/2009 10:48:18 PM
mbam-log-2009-08-07 (22-48-18).txt

Scan type: Quick Scan
Objects scanned: 80272
Time elapsed: 6 minute(s), 54 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

OTL

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/08 14:52
Program Version: Version 1.3.3.0
Windows Version: Windows XP Tablet PC Edition SP2
==================================================

Drivers
——————-
Name: dump_iaStor.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_iaStor.sys
Address: 0xAA3E0000 Size: 876544 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA8C16000 Size: 49152 File Visible: No Signed: -
Status: -

SSDT
——————-
#: 025 Function Name: NtClose
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xaa4e16b8

#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xaa4e1574

#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xaa4e1a52

#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xaa4e114c

#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xaa4e164e

#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xaa4e108c

#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xaa4e10f0

#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xaa4e176e

#: 204 Function Name: NtRestoreKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xaa4e172e

#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xaa4e18ae

==EOF==
Hi moniero, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

You have also ran combofix. This is a very powerful tool and should not be used without supervision. Please post the log that is located at C:\Combofix.txt

Do you have a log from SDFix? It will be located in the SDFix folder found at C:\SDFix If you haven't used SDFix, please Do Not run it.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:OTL
[2009/08/07 17:32:04 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\AVR09.exe
[2009/08/07 17:32:00 | 00,000,000 | —- | M] () – C:\WINDOWS\System32\winhelper.dll
[2009/08/07 17:31:53 | 00,000,831 | —- | M] () – C:\WINDOWS\System32\critical_warning.html

:Services

:Reg

:Files

:Commands
[resethosts]
[purity]
[emptytemp]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL log


Next

Please obtain a new OTL log. Before starting the scan
  • In the Extra Registry, make sure Safe List is selected
Two logs will be produced, OTL.tst and Extra.txt. Please post both

Post back with
  • OTL fix log
  • combofix log from previous run
  • SDfix log, if you have used the tool previously
How is the computer?

Thanks
I did download the combo fix, but it did not download or run properly, and the process was never completed. When I search for C:\Combofix.txt, my computer says it can not be found.

I did run the SDFIX but cannot find the log.

Here is the OTL LOG

All processes killed
========== OTL ==========
C:\WINDOWS\System32\AVR09.exe moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\winhelper.dll
C:\WINDOWS\System32\winhelper.dll NOT unregistered.
C:\WINDOWS\System32\winhelper.dll moved successfully.
C:\WINDOWS\System32\critical_warning.html moved successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 65984 bytes
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Owner
File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\~DF8AC6.tmp scheduled to be deleted on reboot.
->Temp folder emptied: 139401721 bytes
->Temporary Internet Files folder emptied: 2225344 bytes
->Java cache emptied: 248380 bytes
->FireFox cache emptied: 86940053 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_94.dat scheduled to be deleted on reboot.
Windows Temp folder emptied: 251090 bytes
RecycleBin emptied: 9448216 bytes

Total Files Cleaned = 227.59 mb


OTL by OldTimer - Version 3.0.10.4 log created on 08082009_160951

Files\Folders moved on Reboot…
C:\Documents and Settings\Owner\Local Settings\Temp\~DF8AC6.tmp moved successfully.
File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
File\Folder C:\WINDOWS\temp\Perflib_Perfdata_94.dat not found!

Registry entries deleted on Reboot…


OTL Extras logfile created on: 8/8/2009 4:24:31 PM - Run 4
OTL by OldTimer - Version 3.0.10.4 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Tablet PC Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.04 Mb Total Physical Memory | 421.87 Mb Available Physical Memory | 41.60% Memory free
2.38 Gb Paging File | 1.85 Gb Available in Paging File | 77.76% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 86.31 Gb Total Space | 42.02 Gb Free Space | 48.68% Space Free | Partition Type: NTFS
Drive D: | 6.83 Gb Total Space | 3.08 Gb Free Space | 45.16% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-E82B12DEB8
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – File not found
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – File not found
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe" = C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon – (America Online, Inc)
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe" = C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed – (America Online Inc)
"C:\Program Files\Common Files\AOL\1229413987\EE\AOLServiceHost.exe" = C:\Program Files\Common Files\AOL\1229413987\EE\AOLServiceHost.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\System Information\sinf.exe" = C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL – (America Online Inc.)
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe" = C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:*:Enabled:AOL – File not found
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe" = C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:*:Enabled:AOL – File not found
"C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe" = C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL – File not found
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – File not found
"C:\Program Files\Avira\AntiVir PersonalEdition Classic\avwsc.exe" = C:\Program Files\Avira\AntiVir PersonalEdition Classic\avwsc.exe:*:Enabled:avwsc – File not found
"C:\Program Files\Avira\AntiVir PersonalEdition Classic\guardgui.exe" = C:\Program Files\Avira\AntiVir PersonalEdition Classic\guardgui.exe:*:Enabled:GUARDGUI – File not found
"C:\Program Files\McAfee.com\VSO\oasclnt.exe" = C:\Program Files\McAfee.com\VSO\oasclnt.exe:*:Enabled:OasClnt – File not found
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0759CACC-6CF9-4C3C-92C5-39668679AB16}" = Microsoft Ink Desktop
"{0CAD092C-5D1E-48AD-A845-E1EBA9AF1AF8}" = Tablet PC Tutorials for Microsoft Windows XP SP2
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"{15377C3E-9655-400F-B441-E69F0A6BEAFE}" = Recovery Software Suite Gateway
"{1759CACC-6CF9-4C3C-92C5-39668679AB17}" = Microsoft Ink Crossword
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1FBEE61B-F90E-4EE3-AE94-FCB8BD6EC443}" = Ink Art
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Solution
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = Browser Address Error Redirector
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go 4.0
"{40FFC202-F842-44C7-ACBE-8B0EA690B1A3}" = Microsoft Education Pack for Windows XP Tablet PC Edition
"{5D95AD35-368F-47D5-B63A-A082DDF00111}" = Microsoft Digital Image Starter Edition 2006 Editor
"{5E71102C-2CEB-4C8B-99D3-D33B9741EEDA}" = Agilix GoBinder Lite
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{691F4068-81BF-49E3-B32E-FE3E16400111}" = Microsoft Digital Image Starter Edition 2006 Library
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A}" = TIPCI
"{8853C080-7F5C-4020-B663-C57FE29BB858}" = Microsoft Snipping Tool 2.0
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8C6BB412-D3A8-4AAE-A01B-35B681789D68}" = mHelp
"{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}" = Napster Burn Engine
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel Matrix Storage Manager
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{91A10409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office OneNote 2003
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{BBBCAE4B-B416-4182-A6F2-438180894A81}" = Napster
"{C12EB29D-9D64-4ACA-84C2-33D8729AABD3}" = Microsoft Experience Pack for Tablet PC
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus® for Adobe
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}" = PL-2303 USB-to-Serial
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F44DA61E-720D-4E79-871F-F6E628B33242}" = OpenOffice.org 3.0
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{F6C2D09F-6C82-48BB-A9D5-6A0478F52BD6}" = Microsoft Media Transfer
"{FA7314E7-9428-4866-80A8-762A538444DB}" = Microsoft Energy Blue Theme Pack
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"America Online us" = America Online (Choose which version to remove)
"AntiVir PersonalEdition Classic" = Avira AntiVir Personal - Free Antivirus
"avast!" = avast! Antivirus
"CToolbar_UNINSTALL" = Crawler Toolbar with Web Security Guard
"Cucusoft DVD to iPod + iPod Video Converter Suite_is1" = Cucusoft DVD to iPod + iPod Video Converter Suite [removed]
"ERUNT_is1" = ERUNT 1.1j
"Google Desktop" = Google Desktop
"gtw_logo" = gtw_logo
"InstallShield_{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"InstallShield_{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Money2006b" = Microsoft Money 2006
"Mozilla Firefox (3.0.13)" = Mozilla Firefox (3.0.13)
"PictureItSuiteTrial_v11" = Microsoft Digital Image Starter Edition 2006
"Port Magic" = Pure Networks Port Magic
"ProInst" = Intel® PROSet/Wireless Software
"PROSet" = Intel® PRO Network Connections Drivers
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer Basic
"SMSERIAL" = Motorola SM56 Data Fax Modem
"Spyware Terminator_is1" = Spyware Terminator
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"ViewpointMediaPlayer" = Viewpoint Media Player
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Yahoo! Companion" = Yahoo! Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/23/2009 1:42:33 PM | Computer Name = YOUR-E82B12DEB8 | Source = ESENT | ID = 489
Description = svchost (1248) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

Error - 6/23/2009 1:42:34 PM | Computer Name = YOUR-E82B12DEB8 | Source = ESENT | ID = 489
Description = svchost (1248) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

Error - 6/23/2009 1:42:35 PM | Computer Name = YOUR-E82B12DEB8 | Source = ESENT | ID = 489
Description = svchost (1248) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

Error - 6/23/2009 1:42:36 PM | Computer Name = YOUR-E82B12DEB8 | Source = ESENT | ID = 489
Description = svchost (1248) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

Error - 6/23/2009 1:42:37 PM | Computer Name = YOUR-E82B12DEB8 | Source = ESENT | ID = 489
Description = svchost (1248) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

Error - 6/23/2009 1:42:38 PM | Computer Name = YOUR-E82B12DEB8 | Source = ESENT | ID = 489
Description = svchost (1248) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

Error - 6/23/2009 1:42:39 PM | Computer Name = YOUR-E82B12DEB8 | Source = ESENT | ID = 489
Description = svchost (1248) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

Error - 6/23/2009 1:42:40 PM | Computer Name = YOUR-E82B12DEB8 | Source = ESENT | ID = 489
Description = svchost (1248) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

Error - 6/23/2009 1:42:41 PM | Computer Name = YOUR-E82B12DEB8 | Source = ESENT | ID = 489
Description = svchost (1248) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

Error - 6/23/2009 1:42:42 PM | Computer Name = YOUR-E82B12DEB8 | Source = ESENT | ID = 489
Description = svchost (1248) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb"
for read only access failed with system error 32 (0x00000020): "The process cannot
access the file because it is being used by another process. ". The open file
operation will fail with error -1032 (0xfffffbf8).

[ System Events ]
Error - 8/7/2009 11:50:30 PM | Computer Name = YOUR-E82B12DEB8 | Source = DCOM | ID = 10010
Description = The server {E60687F7-01A1-40AA-86AC-DB1CBF673334} did not register
with DCOM within the required timeout.

Error - 8/8/2009 1:56:49 AM | Computer Name = YOUR-E82B12DEB8 | Source = DCOM | ID = 10010
Description = The server {1F87137D-0E7C-44D5-8C73-4EFFB68962F2} did not register
with DCOM within the required timeout.

Error - 8/8/2009 5:09:52 PM | Computer Name = YOUR-E82B12DEB8 | Source = Service Control Manager | ID = 7034
Description = The Intel® PROSet/Wireless Event Log service terminated unexpectedly.
It has done this 1 time(s).

Error - 8/8/2009 5:09:52 PM | Computer Name = YOUR-E82B12DEB8 | Source = Service Control Manager | ID = 7034
Description = The Intel® PROSet/Wireless Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 8/8/2009 5:09:53 PM | Computer Name = YOUR-E82B12DEB8 | Source = Service Control Manager | ID = 7031
Description = The AOL TopSpeed Monitor service terminated unexpectedly. It has
done this 1 time(s). The following corrective action will be taken in 1000 milliseconds:
Restart the service.

Error - 8/8/2009 5:09:53 PM | Computer Name = YOUR-E82B12DEB8 | Source = Service Control Manager | ID = 7034
Description = The Intel® Matrix Storage Event Monitor service terminated unexpectedly.
It has done this 1 time(s).

Error - 8/8/2009 5:09:53 PM | Computer Name = YOUR-E82B12DEB8 | Source = Service Control Manager | ID = 7034
Description = The PrismXL service terminated unexpectedly. It has done this 1 time(s).

Error - 8/8/2009 5:09:54 PM | Computer Name = YOUR-E82B12DEB8 | Source = Service Control Manager | ID = 7034
Description = The Intel® PROSet/Wireless Registry Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 8/8/2009 5:09:54 PM | Computer Name = YOUR-E82B12DEB8 | Source = Service Control Manager | ID = 7034
Description = The Spyware Terminator Realtime Shield Service service terminated
unexpectedly. It has done this 1 time(s).

Error - 8/8/2009 5:09:55 PM | Computer Name = YOUR-E82B12DEB8 | Source = Service Control Manager | ID = 7034
Description = The Windows User Mode Driver Framework service terminated unexpectedly.
It has done this 1 time(s).


< End of report >


OTL logfile created on: 8/8/2009 4:24:31 PM - Run 4
OTL by OldTimer - Version 3.0.10.4 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Tablet PC Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.04 Mb Total Physical Memory | 421.87 Mb Available Physical Memory | 41.60% Memory free
2.38 Gb Paging File | 1.85 Gb Available in Paging File | 77.76% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 86.31 Gb Total Space | 42.02 Gb Free Space | 48.68% Space Free | Partition Type: NTFS
Drive D: | 6.83 Gb Total Space | 3.08 Gb Free Space | 45.16% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-E82B12DEB8
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2005/12/28 12:45:02 | 00,114,753 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
PRC - [2004/08/04 07:00:00 | 00,029,696 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Ink\KeyboardSurrogate.exe
PRC - [2005/12/28 12:47:10 | 00,540,745 | —- | M] (Intel Corporation ) – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
PRC - [2009/02/05 15:01:25 | 00,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/02/05 15:08:40 | 00,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2004/08/04 07:00:00 | 00,293,376 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\WISPTIS.EXE
PRC - [2002/08/29 05:41:28 | 00,035,328 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tabbtnu.exe
PRC - [2004/08/04 07:00:00 | 01,032,192 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2004/08/04 07:00:00 | 00,043,520 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Ink\TCServer.exe
PRC - [2004/10/15 15:54:14 | 00,100,016 | —- | M] (America Online, Inc) – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
PRC - [2005/10/12 13:30:24 | 00,086,140 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
PRC - [2004/10/15 15:54:12 | 00,046,768 | —- | M] (America Online Inc) – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
PRC - [2008/12/16 02:59:47 | 00,172,032 | —- | M] (New Boundary Technologies, Inc.) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
PRC - [2005/12/28 12:44:24 | 00,217,164 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
PRC - [2008/12/16 18:51:39 | 00,570,880 | —- | M] (Crawler.com) – C:\Program Files\Spyware Terminator\sp_rsser.exe
PRC - [2004/08/11 02:45:04 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wdfmgr.exe
PRC - [2009/02/05 15:08:26 | 00,254,040 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/02/05 15:06:04 | 00,352,920 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2004/08/04 07:00:00 | 00,069,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\notepad.exe
PRC - [2008/12/16 02:43:13 | 00,169,984 | —- | M] () – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
PRC - [2004/11/05 10:47:00 | 00,098,394 | —- | M] (Synaptics, Inc.) – C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
PRC - [2004/11/05 10:47:00 | 00,688,218 | —- | M] (Synaptics, Inc.) – C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2005/10/12 13:30:42 | 00,139,264 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
PRC - [2004/08/04 07:00:00 | 00,271,872 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Ink\TabTip.exe
PRC - [2006/01/20 15:34:26 | 00,544,768 | —- | M] (Motorola Inc.) – C:\WINDOWS\sm56hlpr.exe
PRC - [2005/01/12 04:01:32 | 00,032,768 | —- | M] (Cyberlink Corp.) – C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
PRC - [2008/12/16 02:43:13 | 00,555,008 | —- | M] () – C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
PRC - [2006/03/23 15:13:40 | 00,077,824 | —- | M] (Intel Corporation) – C:\WINDOWS\System32\hkcmd.exe
PRC - [2008/12/16 02:43:13 | 00,415,744 | —- | M] () – C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
PRC - [2006/03/23 15:17:50 | 00,118,784 | —- | M] (Intel Corporation) – C:\WINDOWS\System32\igfxpers.exe
PRC - [2006/03/23 15:13:30 | 00,163,840 | —- | M] (Intel Corporation) – C:\WINDOWS\System32\igfxsrvc.exe
PRC - [2005/12/28 12:55:40 | 00,667,718 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
PRC - [2004/11/03 16:03:00 | 00,125,528 | —- | M] (America Online, Inc.) – C:\Program Files\Common Files\AOL\1229413987\EE\AOLHostManager.exe
PRC - [2005/12/28 12:56:16 | 00,602,182 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
PRC - [2004/11/03 16:03:00 | 00,110,680 | —- | M] (America Online, Inc.) – C:\Program Files\Common Files\AOL\1229413987\EE\AOLServiceHost.exe
PRC - [2005/12/27 11:20:14 | 00,413,696 | —- | M] (SigmaTel, Inc.) – C:\WINDOWS\stsystra.exe
PRC - [2008/12/16 02:54:12 | 00,098,304 | —- | M] (Apple Computer, Inc.) – C:\Program Files\QuickTime\qttask.exe
PRC - [2008/06/10 04:27:04 | 00,144,784 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
PRC - [2008/12/16 18:51:39 | 01,783,808 | —- | M] (Crawler.com) – C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
PRC - [2009/02/05 15:08:45 | 00,081,000 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009/05/09 18:28:24 | 00,068,856 | —- | M] (Google Inc.) – C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2005/12/28 12:52:32 | 00,397,381 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
PRC - [2009/01/09 19:57:32 | 07,424,000 | —- | M] (OpenOffice.org) – C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2009/01/09 20:00:52 | 07,418,368 | —- | M] (OpenOffice.org) – C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2009/08/05 17:35:35 | 00,307,704 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/07/01 11:33:33 | 02,426,728 | —- | M] (Crawler.com) – C:\Program Files\Crawler\CToolbar.exe
PRC - [2004/08/04 07:00:00 | 00,069,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\notepad.exe
PRC - [2009/08/07 20:05:58 | 00,514,048 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe

========== Win32 Services (SafeList) ==========

SRV - [2004/10/15 15:54:14 | 00,100,016 | —- | M] (America Online, Inc) – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe – (AOL TopSpeedMonitor [Auto | Running])
SRV - [2005/09/23 08:28:32 | 00,029,896 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2009/02/05 15:01:25 | 00,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe – (aswUpdSv [Auto | Running])
SRV - [2009/02/05 15:08:40 | 00,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe – (avast! Antivirus [Auto | Running])
SRV - [2009/02/05 15:08:26 | 00,254,040 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe – (avast! Mail Scanner [On_Demand | Running])
SRV - [2009/02/05 15:06:04 | 00,352,920 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe – (avast! Web Scanner [On_Demand | Running])
SRV - [2005/09/23 08:28:56 | 00,066,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2005/12/28 12:45:02 | 00,114,753 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe – (EvtEng [Auto | Running])
SRV - [2008/12/01 11:59:52 | 00,033,752 | —- | M] (NOS Microsystems Ltd.) – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe – (getPlus® Helper [On_Demand | Stopped])
SRV - [2009/07/21 07:38:00 | 00,182,768 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc [On_Demand | Stopped])
SRV - [2004/08/04 07:00:00 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2005/10/12 13:30:24 | 00,086,140 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe – (IAANTMon [Auto | Running])
SRV - [2004/10/22 03:24:18 | 00,073,728 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
SRV - [2003/07/28 15:28:22 | 00,089,136 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2008/12/16 02:59:47 | 00,172,032 | —- | M] (New Boundary Technologies, Inc.) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS – (PrismXL [Auto | Running])
SRV - [2005/12/28 12:44:24 | 00,217,164 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe – (RegSrvc [Auto | Running])
SRV - [2005/12/28 12:47:10 | 00,540,745 | —- | M] (Intel Corporation ) – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe – (S24EventMonitor [Auto | Running])
SRV - [2008/12/16 18:51:39 | 00,570,880 | —- | M] (Crawler.com) – C:\Program Files\Spyware Terminator\sp_rsser.exe – (sp_rssrv [Auto | Running])
SRV - [2004/08/11 02:45:04 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wdfmgr.exe – (UMWdf [Auto | Running])

========== Driver Services (SafeList) ==========

DRV - [2009/02/05 15:05:11 | 00,026,944 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys – (Aavmker4 [System | Running])
DRV - [2008/12/16 19:20:27 | 00,021,275 | —- | M] (Meetinghouse Data Communications) – C:\WINDOWS\System32\DRIVERS\AegisP.sys – (AegisP [Auto | Running])
DRV - [2004/08/04 07:00:00 | 00,005,248 | —- | M] (Acer Laboratories Inc.) – C:\WINDOWS\system32\DRIVERS\aliide.sys – (AliIde [Boot | Running])
DRV - [2004/08/03 18:07:44 | 00,043,008 | —- | M] (Advanced Micro Devices, Inc.) – C:\WINDOWS\system32\DRIVERS\amdagp.sys – (amdagp [Boot | Running])
DRV - [2004/08/04 07:00:00 | 00,026,496 | —- | M] (Advanced System Products, Inc.) – C:\WINDOWS\system32\DRIVERS\asc.sys – (asc [Boot | Running])
DRV - [2004/08/04 07:00:00 | 00,014,848 | —- | M] (Advanced System Products, Inc.) – C:\WINDOWS\system32\DRIVERS\asc3550.sys – (asc3550 [Boot | Running])
DRV - [2008/12/16 02:54:00 | 00,008,552 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\System32\drivers\asctrm.sys – (ASCTRM [Auto | Running])
DRV - [2009/02/05 15:07:12 | 00,020,560 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\DRIVERS\aswFsBlk.sys – (aswFsBlk [Auto | Running])
DRV - [2009/02/05 15:08:10 | 00,094,032 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys – (aswMon2 [Auto | Running])
DRV - [2009/02/05 15:06:10 | 00,023,152 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys – (aswRdr [On_Demand | Running])
DRV - [2009/02/05 15:07:23 | 00,114,768 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys – (aswSP [System | Running])
DRV - [2009/02/05 15:06:20 | 00,051,376 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys – (aswTdi [System | Running])
DRV - [2004/11/10 20:27:34 | 00,044,288 | —- | M] (Roxio) – C:\WINDOWS\System32\drivers\cdr4_xp.sys – (Cdr4_xp [System | Running])
DRV - [2004/11/10 20:30:18 | 00,024,832 | —- | M] (Roxio) – C:\WINDOWS\System32\drivers\cdralw2k.sys – (Cdralw2k [System | Running])
DRV - [2004/08/04 07:00:00 | 00,006,656 | —- | M] (CMD Technology, Inc.) – C:\WINDOWS\system32\DRIVERS\cmdide.sys – (CmdIde [Boot | Running])
DRV - [2004/08/04 07:00:00 | 00,179,584 | —- | M] (Mylex Corporation) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys – (dac2w2k [Boot | Running])
DRV - [2005/09/14 20:24:08 | 00,179,200 | —- | M] (Intel Corporation) – C:\WINDOWS\System32\DRIVERS\e1e5132.sys – (e1express [On_Demand | Running])
DRV - [2001/08/17 07:10:58 | 00,069,692 | —- | M] (3Com Corporation) – C:\WINDOWS\System32\DRIVERS\el575nd5.sys – (el575nd5 [On_Demand | Stopped])
DRV - [2006/06/13 10:02:44 | 00,018,816 | —- | M] (FinePoint Innovations) – C:\WINDOWS\System32\DRIVERS\FpHidDrv.sys – (FinePnt [On_Demand | Running])
DRV - [2005/01/07 20:07:18 | 00,138,752 | —- | M] (Windows ® Server 2003 DDK provider) – C:\WINDOWS\System32\DRIVERS\HDAudBus.sys – (HDAudBus [On_Demand | Running])
DRV - [2006/03/23 13:47:06 | 01,166,972 | —- | M] (Intel Corporation) – C:\WINDOWS\System32\DRIVERS\ialmnt5.sys – (ialm [On_Demand | Running])
DRV - [2005/10/12 14:07:12 | 00,874,240 | —- | M] (Intel Corporation) – C:\WINDOWS\SYSTEM32\DRIVERS\IASTOR.SYS – (iaStor [Boot | Running])
DRV - [2004/08/04 07:00:00 | 00,017,280 | —- | M] (American Megatrends Inc.) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys – (mraid35x [Boot | Running])
DRV - [2005/07/26 13:27:46 | 00,009,600 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\System32\DRIVERS\MSTabBtn.sys – (MSTabBtn [On_Demand | Running])
DRV - [2004/08/04 07:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\System32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2004/08/04 07:00:00 | 00,040,320 | —- | M] (QLogic Corporation) – C:\WINDOWS\system32\DRIVERS\ql1080.sys – (ql1080 [Boot | Running])
DRV - [2004/08/04 07:00:00 | 00,045,312 | —- | M] (QLogic Corporation) – C:\WINDOWS\system32\DRIVERS\ql12160.sys – (ql12160 [Boot | Running])
DRV - [2004/08/04 07:00:00 | 00,049,024 | —- | M] (QLogic Corporation) – C:\WINDOWS\system32\DRIVERS\ql1280.sys – (ql1280 [Boot | Running])
DRV - [2005/12/28 14:22:08 | 00,013,568 | —- | M] (Intel Corporation) – C:\WINDOWS\System32\DRIVERS\s24trans.sys – (s24trans [Auto | Running])
DRV - [2004/08/04 07:00:00 | 00,027,440 | —- | M] () – C:\WINDOWS\System32\DRIVERS\secdrv.sys – (Secdrv [On_Demand | Stopped])
DRV - [2004/08/03 18:07:44 | 00,041,088 | —- | M] (Silicon Integrated Systems Corporation) – C:\WINDOWS\system32\DRIVERS\sisagp.sys – (sisagp [Boot | Running])
DRV - [2006/01/20 15:44:42 | 00,862,340 | —- | M] (Motorola Inc.) – C:\WINDOWS\System32\DRIVERS\smserial.sys – (smserial [On_Demand | Running])
DRV - [2004/08/04 07:00:00 | 00,019,072 | —- | M] (Adaptec, Inc.) – C:\WINDOWS\system32\DRIVERS\sparrow.sys – (Sparrow [Boot | Running])
DRV - [2008/12/16 18:51:39 | 00,141,312 | —- | M] () – C:\WINDOWS\System32\drivers\sp_rsdrv2.sys – (sp_rsdrv2 [System | Running])
DRV - [2006/06/15 16:28:04 | 01,179,784 | —- | M] (SigmaTel, Inc.) – C:\WINDOWS\System32\drivers\sthda.sys – (STHDA [On_Demand | Running])
DRV - [2004/08/04 07:00:00 | 00,016,256 | —- | M] (Symbios Logic Inc.) – C:\WINDOWS\system32\DRIVERS\symc810.sys – (symc810 [Boot | Running])
DRV - [2004/08/04 07:00:00 | 00,032,640 | —- | M] (LSI Logic) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys – (symc8xx [Boot | Running])
DRV - [2004/08/04 07:00:00 | 00,028,384 | —- | M] (LSI Logic) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys – (sym_hi [Boot | Running])
DRV - [2004/08/04 07:00:00 | 00,030,688 | —- | M] (LSI Logic) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys – (sym_u3 [Boot | Running])
DRV - [2004/11/05 10:47:00 | 00,185,824 | —- | M] (Synaptics, Inc.) – C:\WINDOWS\System32\DRIVERS\SynTP.sys – (SynTP [On_Demand | Running])
DRV - [2005/09/21 03:30:56 | 00,162,432 | —- | M] (Texas Instruments) – C:\WINDOWS\System32\drivers\tifm21.sys – (tifm21 [On_Demand | Running])
DRV - [2004/08/04 07:00:00 | 00,036,736 | —- | M] (Promise Technology, Inc.) – C:\WINDOWS\system32\DRIVERS\ultra.sys – (ultra [Boot | Running])
DRV - [2005/12/05 01:55:30 | 01,428,096 | —- | M] (Intel® Corporation) – C:\WINDOWS\System32\DRIVERS\w39n51.sys – (w39n51 [On_Demand | Running])
DRV - [2003/01/10 16:13:04 | 00,033,588 | —- | M] (America Online, Inc.) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys – (wanatw [On_Demand | Stopped])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60076
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - URLSearchHook: {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\Program Files\Crawler\ctbr.dll (Crawler.com)
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?fr=ffsp1&p="
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {4B3803EA-5230-4DC3-A7FC-33638F3D3542}:1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071303000006
FF - prefs.js..extensions.enabledItems: {9D6218B8-03C7-4b91-AA43-680B305DD35C}:[removed]
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.2.20080910
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.13
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=ffds1&p="


FF - HKLM\software\mozilla\Firefox\Extensions\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}: C:\Program Files\Crawler\firefox\ [2009/04/30 18:07:13 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/08/05 17:35:42 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/08/05 17:35:42 | 00,000,000 | —D | M]

[2008/12/28 16:59:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions
[2008/12/28 16:59:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/08/07 22:04:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\pe030i71.default\extensions
[2009/03/22 20:42:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\pe030i71.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/01/07 18:27:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\pe030i71.default\extensions\{9D6218B8-03C7-4b91-AA43-680B305DD35C}
[2009/04/03 20:55:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\pe030i71.default\extensions\[removed]
[2009/08/07 22:04:40 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/08/05 17:35:35 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/03/22 22:32:02 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2009/08/05 17:35:35 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/08/05 17:35:35 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/08/05 17:35:36 | 00,065,528 | —- | M] (mozilla.org) – C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2009/01/14 22:07:44 | 00,106,496 | —- | M] (Apple Computer, Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/01/14 22:07:44 | 00,106,496 | —- | M] (Apple Computer, Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/01/14 22:07:44 | 00,106,496 | —- | M] (Apple Computer, Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/01/14 22:07:44 | 00,106,496 | —- | M] (Apple Computer, Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/01/14 22:07:44 | 00,106,496 | —- | M] (Apple Computer, Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/01/14 22:07:44 | 00,106,496 | —- | M] (Apple Computer, Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/04/14 22:49:18 | 00,221,184 | —- | M] (CNN) – C:\Program Files\mozilla firefox\plugins\NPTURNMED.dll
[2008/12/02 03:04:40 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/12/02 03:04:40 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2007/07/26 12:05:16 | 00,001,329 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\crawlersrch.xml
[2008/12/02 03:04:40 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/12/02 03:04:40 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/12/02 03:04:40 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/12/02 03:04:40 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/12/02 03:04:40 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (56 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: () - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\Program Files\Crawler\ctbr.dll (Crawler.com)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\WINDOWS\System32\BAE.dll (Gateway Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Crawler Toolbar) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Program Files\Crawler\ctbr.dll (Crawler.com)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Crawler Toolbar) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Program Files\Crawler\ctbr.dll (Crawler.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Crawler Toolbar) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\Program Files\Crawler\ctbr.dll (Crawler.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe ()
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1229413987\EE\AOLHostManager.exe (America Online, Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE ()
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SMSERIAL] C:\WINDOWS\sm56hlpr.exe (Motorola Inc.)
O4 - HKLM..\Run: [Snippet] C:\Program Files\Microsoft Experience Pack\Snipping Tool\SnippingTool.exe (Microsoft Corporation)
O4 - HKLM..\Run: [SpywareTerminator] C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe (Crawler.com)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TabletTip] C:\Program Files\Common Files\microsoft shared\ink\tabtip.exe (Microsoft Corporation)
O4 - HKLM..\Run: [TabletWizard] C:\WINDOWS\help\SplshWrp.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: Crawler Search - File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 28 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab (YInstStarter Class)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo2.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {8C279F4E-917E-4CD2-8DF0-D9C73C0CE763} http://zone.msn.com/bingame/zpagames/zpa_wof.cab55579.cab (ZPA_WheelOfFortune Object)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…k.cab102118.cab (MSN Games - Installer)
O16 - DPF: {C75BE5CC-7F80-458C-8B66-FAB86E3B13C3} http://images.fotki.com/activex/FotkiUploader.cab (FotkiUploader Control)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://l.yimg.com/jh/games/popcap/zuma/popcaploader_v6.cab (PopCapLoader Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\tbr {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\Program Files\Crawler\ctbr.dll (Crawler.com)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\loginkey: DllName - C:\Program Files\Common Files\Microsoft Shared\Ink\loginkey.dll - C:\Program Files\Common Files\Microsoft Shared\Ink\loginkey.dll (Microsoft Corporation)
O20 - Winlogon\Notify\TabBtnWL: DllName - TabBtnWL.dll - C:\WINDOWS\System32\TabBtnWL.dll (Microsoft Corporation)
O20 - Winlogon\Notify\tpgwlnotify: DllName - tpgwlnot.dll - C:\WINDOWS\System32\tpgwlnot.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/06/22 05:32:11 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2005/06/22 05:32:12 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/09/13 13:15:24 | 00,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O33 - MountPoints2\{08ff2b7d-cb78-11dd-8c24-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{08ff2b7d-cb78-11dd-8c24-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/08/08 16:09:51 | 00,000,000 | —D | C] – C:\_OTL
[2009/08/08 14:09:29 | 09,021,376 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Owner\Desktop\windows-kb890830-v2.12(2).exe
[2009/08/08 14:07:24 | 00,000,000 | —- | C] () – C:\Documents and Settings\Owner\Desktop\windows-kb890830-v2.12.exe
[2009/08/08 14:07:22 | 01,338,134 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Owner\Desktop\windows-kb890830-v2.12.exe.part
[2009/08/07 22:27:34 | 00,608,344 | —- | C] () – C:\Documents and Settings\Owner\Desktop\MCPR.exe
[2009/08/07 20:14:17 | 00,463,768 | —- | C] () – C:\Documents and Settings\Owner\Desktop\RootRepeal.rar
[2009/08/07 20:05:58 | 00,514,048 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/08/07 19:34:00 | 00,000,201 | —- | C] () – C:\Boot.bak
[2009/08/07 19:33:56 | 00,260,272 | —- | C] () – C:\cmldr
[2009/08/07 19:33:46 | 00,000,000 | —D | C] – C:\cmdcons
[2009/08/07 19:31:44 | 00,217,088 | —- | C] () – C:\WINDOWS\PEV.exe
[2009/08/07 19:31:44 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/08/07 19:31:44 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/08/07 19:31:44 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/08/07 19:31:44 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/08/07 19:31:44 | 00,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2009/08/07 19:31:43 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/08/07 19:31:43 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/08/07 19:31:28 | 00,000,000 | –SD | C] – C:\ComboFix
[2009/08/07 19:31:27 | 00,388,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\CF6939.exe
[2009/08/07 19:29:49 | 00,000,000 | —D | C] – C:\Qoobox
[2009/08/07 19:29:35 | 00,000,000 | —D | C] – C:\32788R22FWJFW
[2009/08/07 19:18:23 | 00,000,000 | —D | C] – C:\SDFix
[2009/08/07 19:17:53 | 01,529,241 | —- | C] () – C:\Documents and Settings\Owner\Desktop\SDFix.exe
[2009/08/07 18:29:25 | 00,051,376 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/08/07 18:29:25 | 00,026,944 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/08/07 18:29:25 | 00,023,152 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/08/07 18:29:25 | 00,001,709 | —- | C] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/08/07 18:29:23 | 00,097,480 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\AvastSS.scr
[2009/08/07 18:29:22 | 00,114,768 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2009/08/07 18:29:22 | 00,094,032 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/08/07 18:29:22 | 00,093,296 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2009/08/07 18:29:22 | 00,020,560 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/08/07 18:29:05 | 01,256,296 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\aswBoot.exe
[2009/08/07 18:29:05 | 00,380,928 | —- | C] () – C:\WINDOWS\System32\actskin4.ocx
[2009/08/07 18:29:01 | 00,000,000 | —D | C] – C:\Program Files\Alwil Software
[2009/08/07 18:09:14 | 00,308,160 | —- | C] (ALWIL Software) – C:\Documents and Settings\Owner\Desktop\avast_home_setup.exe
[2009/08/07 17:46:50 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/08/07 17:46:22 | 00,000,611 | —- | C] () – C:\Documents and Settings\Owner\Desktop\NTREGOPT.lnk
[2009/08/07 17:46:22 | 00,000,592 | —- | C] () – C:\Documents and Settings\Owner\Desktop\ERUNT.lnk
[2009/08/07 17:46:21 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/08/07 17:45:40 | 00,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\Owner\Desktop\erunt_setup.exe
[2009/08/07 17:44:28 | 00,021,504 | —- | C] (Doug Knox) – C:\Documents and Settings\Owner\Desktop\SysRestorePoint(2).exe
[2009/08/07 17:43:26 | 00,021,504 | —- | C] (Doug Knox) – C:\Documents and Settings\Owner\Desktop\SysRestorePoint.exe
[2009/08/07 17:22:05 | 00,272,384 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\TFC.exe
[2009/08/06 22:41:48 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/08/06 22:41:48 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/04/10 12:56:53 | 00,007,680 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/04/10 12:56:53 | 00,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009/04/10 12:56:49 | 00,348,160 | —- | C] () – C:\WINDOWS\System32\cdga.dll
[2008/12/16 18:51:39 | 00,141,312 | —- | C] () – C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2008/12/16 03:08:19 | 00,023,552 | —- | C] () – C:\WINDOWS\System32\jesterss.dll
[2008/12/16 02:56:42 | 00,167,936 | R— | C] () – C:\WINDOWS\System32\GBInf.dll
[2008/12/16 02:44:49 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/12/16 01:52:40 | 00,098,304 | —- | C] () – C:\WINDOWS\System32\FpWinTab.dll
[2006/10/10 20:26:48 | 00,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2006/05/23 15:57:58 | 00,069,632 | —- | C] () – C:\WINDOWS\sm56spn.dll
[2006/05/23 15:57:58 | 00,069,632 | —- | C] () – C:\WINDOWS\sm56itl.dll
[2006/05/23 15:57:58 | 00,069,632 | —- | C] () – C:\WINDOWS\sm56eng.dll
[2006/05/23 15:57:58 | 00,069,632 | —- | C] () – C:\WINDOWS\sm56brz.dll
[2006/05/23 15:57:58 | 00,061,440 | —- | C] () – C:\WINDOWS\sm56ger.dll
[2006/05/23 15:57:58 | 00,061,440 | —- | C] () – C:\WINDOWS\sm56fra.dll
[2006/05/23 15:57:58 | 00,053,248 | —- | C] () – C:\WINDOWS\sm56jpn.dll
[2006/05/23 15:57:58 | 00,049,152 | —- | C] () – C:\WINDOWS\sm56cht.dll
[2006/05/23 15:57:58 | 00,049,152 | —- | C] () – C:\WINDOWS\sm56chs.dll
[2005/06/22 07:13:13 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/06/22 05:12:17 | 00,001,280 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2005/06/22 05:12:17 | 00,000,473 | —- | C] () – C:\WINDOWS\System32\emver.ini
[2005/06/22 05:11:38 | 00,000,714 | —- | C] () – C:\WINDOWS\win.ini
[2005/06/22 05:11:33 | 00,000,288 | —- | C] () – C:\WINDOWS\system.ini
[2004/01/14 12:46:34 | 00,172,032 | —- | C] () – C:\WINDOWS\System32\tifmicon.dll
[2003/01/07 18:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== Files - Modified Within 30 Days ==========

[2009/08/08 16:12:00 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/08/08 16:11:22 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/08/08 16:11:16 | 10,633,74848 | -HS- | M] () – C:\hiberfil.sys
[2009/08/08 16:10:10 | 00,000,056 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2009/08/08 14:10:11 | 09,021,376 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Owner\Desktop\windows-kb890830-v2.12(2).exe
[2009/08/08 14:07:29 | 01,338,134 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Owner\Desktop\windows-kb890830-v2.12.exe.part
[2009/08/08 14:07:24 | 00,000,000 | —- | M] () – C:\Documents and Settings\Owner\Desktop\windows-kb890830-v2.12.exe
[2009/08/07 22:27:36 | 00,608,344 | —- | M] () – C:\Documents and Settings\Owner\Desktop\MCPR.exe
[2009/08/07 21:50:37 | 00,112,832 | —- | M] () – C:\WINDOWS\System32\Status.MPF
[2009/08/07 20:14:17 | 00,463,768 | —- | M] () – C:\Documents and Settings\Owner\Desktop\RootRepeal.rar
[2009/08/07 20:05:58 | 00,514,048 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/08/07 19:34:00 | 00,000,270 | RHS- | M] () – C:\boot.ini
[2009/08/07 19:29:45 | 00,388,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\CF6939.exe
[2009/08/07 19:18:04 | 01,529,241 | —- | M] () – C:\Documents and Settings\Owner\Desktop\SDFix.exe
[2009/08/07 18:29:25 | 00,001,709 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/08/07 18:29:22 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/08/07 18:20:27 | 00,001,891 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/08/07 18:09:14 | 00,308,160 | —- | M] (ALWIL Software) – C:\Documents and Settings\Owner\Desktop\avast_home_setup.exe
[2009/08/07 18:03:18 | 00,000,714 | —- | M] () – C:\WINDOWS\win.ini
[2009/08/07 17:46:22 | 00,000,611 | —- | M] () – C:\Documents and Settings\Owner\Desktop\NTREGOPT.lnk
[2009/08/07 17:46:22 | 00,000,592 | —- | M] () – C:\Documents and Settings\Owner\Desktop\ERUNT.lnk
[2009/08/07 17:45:42 | 00,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Owner\Desktop\erunt_setup.exe
[2009/08/07 17:44:29 | 00,021,504 | —- | M] (Doug Knox) – C:\Documents and Settings\Owner\Desktop\SysRestorePoint(2).exe
[2009/08/07 17:43:26 | 00,021,504 | —- | M] (Doug Knox) – C:\Documents and Settings\Owner\Desktop\SysRestorePoint.exe
[2009/08/07 17:22:06 | 00,272,384 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\TFC.exe
[2009/08/07 10:24:57 | 00,217,088 | —- | M] () – C:\WINDOWS\PEV.exe
[2009/08/06 22:41:48 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/08/06 22:41:48 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/07/18 11:20:31 | 03,062,272 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.dll
[2009/07/18 11:20:31 | 03,062,272 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2009/07/18 11:20:31 | 01,506,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\shdocvw.dll
[2009/07/18 11:20:31 | 01,506,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shdocvw.dll
[2009/07/11 01:30:38 | 00,006,144 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
< End of report >


The computer is running better, and that "Your system is Infected" blue screeen is gone. Thanks for replying so quickly.
Hi moniero,

You're welcome. Still some more to do.

I see AntiVir PersonalEdition Classic in the uninstall list but don't see it in the logs. What happened to it?

Please disable Spyware Terminator's real time protection as it may be interfering. Please leave it disabled until we are done.

Click on the "Real-time Protection" tab, uncheck the "Use Real-time Protection" box and click on the "Save Changes" button.



You will also need to disable Avast before running this next tool.

AVAST
Right click on the avast! icon in system tray (looks like this: [external image: Posted Image]) and choose (Stop On-Access Protection)



Please locate combofix.exe on your desktop, right click it and select delete. Then download a new copy from either of the links below.

Please read through the instructions to familarize youself with what to expect when the tool runs.


It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]

[external image: Posted Image]

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the combofix log.

Thanks
I tried to update it, and it wouldn't work (AntiVir PersonalEdition Classic). So, I then tried to uninstall it but it wouldn't. When I go to programs and click uninstall it says something about cannot locate the resource file. I tried to run COMBOFIX and it says that AntiVir is running, and for me to stop it before I continue…What to do?
Hi moniero,

We'll deal with Antivir later. Let try to get combofix to run with a command.


Click your start button, click run. Copy and paste the following command into the run box and click ok.

"%userprofile%\desktop\combofix.exe" /killall

Don't miss the " at the beginning. Make sure you disable Avast.

Thanks
ComboFix 09-08-09.03 - Owner 08/09/2009 13:55.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.699 [GMT -5:00]
Running from: c:\documents and settings\[removed]\desktop\combo-fix.exe
Command switches used :: /killall
AV: *On-access scanning disabled* (Outdated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: avast! antivirus 4.8.1335 [VPS 090808-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\recycler\S-1-5-21-3368119922-3208942995-791104651-500
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\Installer\105a0d3.msi
D:\Autorun.inf

—– BITS: Possible infected sites —–

hxxp://au.download.windoj+|Cv+@J:NGD_DQ{ztHG.X;[@~+rdl1.S-1-5-21-3990573909-1093575952-515971331-1006XtD$?US.A? US.AUS.A6VwoQZCDHM6VwoQZCDHMXXGRxaGRxaGRbx0tHG.XGD_DQ{zGD_DQ{zGD_DQ{z+@J:Nj+|CvS-1-5-21-3990573909-1093575952-515971331-1006XtD$?US.A? US.AUS.A6VwoQZCDHM6VwoQZCDHMXXGRxaGRxaGRux0tHG.XtHG.Xz.K@WWU Client DownloadS-1-5-18`HT4?? 6VwoQZCDHM6VwoQZCDHMXu!v!v!v!vWO
.
((((((((((((((((((((((((( Files Created from 2009-07-09 to 2009-08-09 )))))))))))))))))))))))))))))))
.

2009-08-08 21:09 . 2009-08-08 21:09 ——– d—–w- C:\_OTL
2009-08-08 01:15 . 2009-08-08 01:17 15 —-a-w- c:\documents and settings\Owner\settings.dat
2009-08-08 00:31 . 2009-08-09 18:53 ——– d-s—w- C:\ComboFix
2009-08-08 00:18 . 2009-08-08 21:07 ——– d—–w- C:\SDFix
2009-08-07 23:29 . 2009-02-05 20:06 51376 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-07 23:29 . 2009-02-05 20:06 23152 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-07 23:29 . 2009-02-05 20:05 26944 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-07 23:29 . 2009-02-05 20:04 97480 —-a-w- c:\windows\system32\AvastSS.scr
2009-08-07 23:29 . 2009-02-05 20:08 93296 —-a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-07 23:29 . 2009-02-05 20:08 94032 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-07 23:29 . 2009-02-05 20:07 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-07 23:29 . 2009-02-05 20:07 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-07 23:29 . 2009-02-05 20:11 1256296 —-a-w- c:\windows\system32\aswBoot.exe
2009-08-07 23:29 . 2009-08-07 23:29 ——– d—–w- c:\program files\Alwil Software
2009-08-07 22:46 . 2009-08-07 22:46 ——– d—–w- c:\program files\ERUNT

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-09 16:55 . 2009-04-30 23:06 ——– d—–w- c:\program files\Crawler
2009-08-09 05:00 . 2008-12-16 23:51 ——– d—–w- c:\documents and settings\Owner\Application Data\Spyware Terminator
2009-08-09 05:00 . 2008-12-16 23:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2009-08-08 04:52 . 2008-12-16 23:42 ——– d—–w- c:\program files\Yahoo!
2009-08-08 00:52 . 2008-12-16 07:52 ——– d—–w- c:\program files\Common Files\AOL
2009-08-08 00:52 . 2008-12-16 07:53 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL
2009-08-07 23:13 . 2008-12-16 07:49 ——– d—–w- c:\program files\BigFix
2009-08-06 06:06 . 2009-03-23 03:36 1 —-a-w- c:\documents and settings\Owner\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-07-21 12:27 . 2008-12-16 07:43 ——– d—–w- c:\program files\Google
2009-06-26 16:18 . 2006-10-11 01:27 659456 —-a-w- c:\windows\system32\wininet.dll
2009-06-26 16:18 . 2006-10-11 01:23 81920 —-a-w- c:\windows\system32\ieencode.dll
2009-06-16 14:55 . 2006-10-11 01:27 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:55 . 2006-10-11 01:23 82432 —-a-w- c:\windows\system32\fontsub.dll
2009-06-03 19:27 . 2006-10-11 01:26 1290752 —-a-w- c:\windows\system32\quartz.dll
2009-05-17 00:24 . 2009-05-17 00:24 34062 —-a-w- c:\documents and settings\Owner\Application Data\Move Networks\ie_bin\Uninst.exe
2009-05-02 18:17 . 2009-05-02 18:17 15584 –sh–w- c:\windows\system32\jiziveji.exe
2009-05-02 05:41 . 2009-05-02 05:41 15584 –sh–w- c:\windows\system32\wopimiga.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-09 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TabletWizard"="c:\windows\help\SplshWrp.exe" [2004-08-04 16384]
"TabletTip"="c:\program files\Common Files\microsoft shared\ink\tabtip.exe" [2004-08-04 271872]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-12-16 169984]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 688218]
"HostManager"="c:\program files\Common Files\AOL\1229413987\EE\AOLHostManager.exe" [2004-11-03 125528]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-10-12 139264]
"Snippet"="c:\program files\Microsoft Experience Pack\Snipping Tool\SnippingTool.exe" [2005-02-25 68296]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 32768]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 602182]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-12-16 98304]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-12-16 1783808]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 1121792]
"SMSERIAL"="sm56hlpr.exe" - c:\windows\sm56hlpr.exe [2006-01-20 544768]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-12-27 413696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-12-15 384000]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\loginkey]
2004-08-04 12:00 47104 —-a-w- c:\program files\Common Files\Microsoft Shared\Ink\LoginKey.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\TabBtnWL]
2002-08-29 10:41 11776 —-a-w- c:\windows\system32\tabbtnwl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpgwlnotify]
2004-08-04 12:00 30208 —-a-w- c:\windows\system32\tpgwlnot.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1229413987\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [8/7/2009 6:29 PM 114768]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [12/16/2008 6:51 PM 141312]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8/7/2009 6:29 PM 20560]
R3 FinePnt;FinePoint Innovations HID Driver;c:\windows\system32\drivers\FpHidDrv.sys [12/16/2008 1:52 AM 18816]
R3 MSTabBtn;Tablet PC Buttons HID Driver;c:\windows\system32\drivers\MSTabBtn.sys [12/16/2008 1:52 AM 9600]
S3 el575nd5;3Com Megahertz 10/100 LAN CardBus PC Card Driver;c:\windows\system32\drivers\el575ND5.sys [12/16/2008 1:48 AM 69692]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [12/16/2008 7:41 PM 33752]
.
- - - - ORPHANS REMOVED - - - -

HKU-Default-Run-TabletWizard - c:\windows\help\wizard.hta
SafeBoot-Winnx76.sys


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&Br;=GTW&Loc;=ENG_US&Sys;=PTB&M;=CX2724
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Crawler Search - tbr:iemenu
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\ctbr.dll
DPF: {C75BE5CC-7F80-458C-8B66-FAB86E3B13C3} - hxxp://images.fotki.com/activex/FotkiUploader.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\pe030i71.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p;=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p;=
FF - component: c:\program files\Crawler\firefox\components\xcomm.dll
FF - component: c:\program files\Crawler\firefox\components\xshared.dll
FF - component: c:\program files\Crawler\firefox\components\xsupport.dll
FF - component: c:\program files\Crawler\firefox\components\xwsg.dll
FF - plugin: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\pe030i71.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-09 14:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(1356)
c:\windows\system32\msi.dll
c:\program files\windows journal\nbmaptip.dll
c:\windows\IME\SPGRMR.DLL
c:\windows\system32\shdoclc.dll
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Common Files\Microsoft Shared\Ink\KeyboardSurrogate.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\wisptis.exe
c:\windows\system32\tabbtnu.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Common Files\Microsoft Shared\Ink\TCServer.exe
c:\program files\Google\Google Desktop Search\GoogleDesktopIndex.exe
c:\program files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
c:\windows\system32\igfxsrvc.exe
c:\progra~1\COMMON~1\AOL\122941~1\EE\AOLServiceHost.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
.
**************************************************************************
.
Completion time: 2009-08-09 14:16 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-09 19:16

Pre-Run: 45,186,908,160 bytes free
Post-Run: 44,973,211,648 bytes free

198 — E O F — 2009-08-08 01:31


Again, THANK YOU! :woot:
Hi moniero,

A little more to do.

There's some stray McAfee showing in the combofix log. We'll take them one at a time.

First we'll do this.

[external image: Posted Image] ERUNT - Download - Homepage
This ensures we have a valid registry backup. ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore if needed.

  • Download ERUNT
  • Double-click erunt_setup.exe to run.
  • Follow the prompts and install using the default configuration (setup language, install location, shortcuts…).
  • Say No to the portion that asks you to add ERUNT to the start-up folder, if you like you can enable this option later.
    [external image: Posted Image]
  • Start ERUNT
  • Choose a location for the backup
    The default location C:\WINDOWS\ERDNT\[today's date] is preferred
    [external image: Posted Image]
  • The first two check boxes are ticked by default (System registry and Current user registry).
  • Press OK
  • When prompted, click YES to create a new folder.
  • Progress bars will show backup status.
  • A confirmation window will popup when complete. Click OK to close.


Download the Mcafee removal tool from Here and save it to your desktop.

  • Double-click MCPR.exe to run the removal tool.
  • Restart your computer after receiving the message CleanUp Successful

Next Download AntiVir Registry Cleaner
  • unzip registrycleaner.zip
  • Double click Avira RegistryCleaner.exe
  • when it has finished, reboot
Then make sure your Windows firewall is turned on,

Click start, click control panel, click Security Center. At the bottom of Security Center click windows firewall. Ensure it is set to On.


We will be using Combofix again but will run it differently. Please read these instruction so you know what to expect.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the all of the text in the code box below into the Notepad, (including the URL). Do Not copy the word CODE

http://forums.whatthetech.com/Possible_Viruses_t105951.html

KillAll::

Collect::[4]
c:\windows\system32\jiziveji.exe
c:\windows\system32\wopimiga.exe

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.

Please post back with the combofix log. Any problems?

Thanks
Goodmorning Oldman960, I tried to run the antivir registry cleaner several time and it stalled…Combofix still says its running…so I did not complete the Combofix process…Should I? Thanks, Moniero :unsure:
Hi, Oldman960 has a couple of days off, so has asked if I'd look after you. Please go to task manager (Ctrl + Alt + Del) and see if there are any processes running that relate to Avira. If you don't see any go ahead and run ComboFix If you see the Avira process running - click on it and choose to 'end process' - OK and close post the resulting log
Here is the log, and thank you for helping…. :D


ComboFix 09-08-10.01 - Owner 08/10/2009 17:28.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.579 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\combo-fix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090810-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}

file zipped: c:\windows\system32\jiziveji.exe
file zipped: c:\windows\system32\wopimiga.exe
.

((((((((((((((((((((((((( Files Created from 2009-07-10 to 2009-08-10 )))))))))))))))))))))))))))))))
.

2009-08-10 07:47 . 2009-06-29 16:12 52224 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-08-10 07:47 . 2009-06-29 16:12 459264 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2009-08-10 07:47 . 2009-06-29 11:07 13824 -c—-w- c:\windows\system32\dllcache\ieudinit.exe
2009-08-10 07:46 . 2009-06-29 16:12 268288 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2009-08-10 07:46 . 2009-07-19 13:32 6067200 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2009-08-10 07:46 . 2009-06-29 16:12 380928 -c—-w- c:\windows\system32\dllcache\ieapfltr.dll
2009-08-10 07:46 . 2009-06-29 08:33 2452872 -c—-w- c:\windows\system32\dllcache\ieapfltr.dat
2009-08-10 07:46 . 2009-06-29 16:12 63488 -c—-w- c:\windows\system32\dllcache\icardie.dll
2009-08-08 21:09 . 2009-08-08 21:09 ——– d—–w- C:\_OTL
2009-08-08 01:15 . 2009-08-08 01:17 15 —-a-w- c:\documents and settings\Owner\settings.dat
2009-08-08 00:31 . 2009-08-09 18:53 ——– d-s—w- C:\ComboFix
2009-08-08 00:18 . 2009-08-08 21:07 ——– d—–w- C:\SDFix
2009-08-07 23:29 . 2009-02-05 20:06 51376 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-07 23:29 . 2009-02-05 20:06 23152 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-07 23:29 . 2009-02-05 20:05 26944 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-07 23:29 . 2009-02-05 20:04 97480 —-a-w- c:\windows\system32\AvastSS.scr
2009-08-07 23:29 . 2009-02-05 20:08 93296 —-a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-07 23:29 . 2009-02-05 20:08 94032 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-07 23:29 . 2009-02-05 20:07 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-07 23:29 . 2009-02-05 20:07 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-07 23:29 . 2009-02-05 20:11 1256296 —-a-w- c:\windows\system32\aswBoot.exe
2009-08-07 23:29 . 2009-08-07 23:29 ——– d—–w- c:\program files\Alwil Software
2009-08-07 22:46 . 2009-08-07 22:46 ——– d—–w- c:\program files\ERUNT

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-10 22:28 . 2009-05-02 05:41 15584 –sha-w- c:\windows\system32\wopimiga.exe
2009-08-10 22:28 . 2009-05-02 18:17 15584 –sha-w- c:\windows\system32\jiziveji.exe
2009-08-10 16:27 . 2009-04-30 23:06 ——– d—–w- c:\program files\Crawler
2009-08-10 07:55 . 2008-12-16 23:51 ——– d—–w- c:\documents and settings\Owner\Application Data\Spyware Terminator
2009-08-10 07:55 . 2008-12-16 23:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2009-08-08 04:52 . 2008-12-16 23:42 ——– d—–w- c:\program files\Yahoo!
2009-08-08 00:52 . 2008-12-16 07:52 ——– d—–w- c:\program files\Common Files\AOL
2009-08-08 00:52 . 2008-12-16 07:53 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL
2009-08-07 23:13 . 2008-12-16 07:49 ——– d—–w- c:\program files\BigFix
2009-08-06 06:06 . 2009-03-23 03:36 1 —-a-w- c:\documents and settings\Owner\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-07-21 12:27 . 2008-12-16 07:43 ——– d—–w- c:\program files\Google
2009-06-29 16:12 . 2006-10-11 01:27 827392 —-a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2006-10-11 01:23 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2006-10-11 01:22 17408 ——w- c:\windows\system32\corpol.dll
2009-06-16 14:55 . 2006-10-11 01:27 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:55 . 2006-10-11 01:23 82432 —-a-w- c:\windows\system32\fontsub.dll
2009-06-03 19:27 . 2006-10-11 01:26 1290752 —-a-w- c:\windows\system32\quartz.dll
2009-05-17 00:24 . 2009-05-17 00:24 34062 —-a-w- c:\documents and settings\Owner\Application Data\Move Networks\ie_bin\Uninst.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-08-09_19.05.47 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-10 22:36 . 2009-08-10 22:36 16384 c:\windows\Temp\Perflib_Perfdata_2b4.dat
+ 2009-08-10 16:26 . 2009-08-10 16:26 16384 c:\windows\Temp\Perflib_Perfdata_1f4.dat
+ 2008-12-17 00:21 . 2008-07-08 13:02 17272 c:\windows\system32\spmsg.dll
- 2008-12-17 00:21 . 2009-05-26 11:40 17272 c:\windows\system32\spmsg.dll
+ 2006-10-11 01:26 . 2009-06-29 16:12 44544 c:\windows\system32\pngfilt.dll
+ 2006-06-29 13:05 . 2006-06-29 13:05 23552 c:\windows\system32\normaliz.dll
+ 2006-06-28 22:59 . 2006-06-28 22:59 24576 c:\windows\system32\nlsdl.dll
+ 2006-10-11 01:25 . 2007-08-13 23:01 48128 c:\windows\system32\mshtmler.dll
+ 2006-10-11 01:25 . 2007-08-13 23:32 45568 c:\windows\system32\mshta.exe
+ 2007-08-13 23:36 . 2007-08-13 23:36 12288 c:\windows\system32\msfeedssync.exe
+ 2007-08-13 23:54 . 2009-06-29 16:12 52224 c:\windows\system32\msfeedsbs.dll
+ 2006-10-11 01:24 . 2007-08-13 23:44 40960 c:\windows\system32\licmgr10.dll
+ 2006-10-11 01:23 . 2009-06-29 16:12 27648 c:\windows\system32\jsproxy.dll
+ 2006-10-11 01:23 . 2007-08-13 23:39 92672 c:\windows\system32\inseng.dll
+ 2006-10-11 01:23 . 2007-08-13 23:36 36352 c:\windows\system32\imgutil.dll
+ 2007-08-13 23:39 . 2009-06-29 11:07 13824 c:\windows\system32\ieudinit.exe
+ 2006-10-11 01:23 . 2007-08-13 23:39 55296 c:\windows\system32\iesetup.dll
+ 2006-10-11 01:23 . 2009-06-29 16:12 44544 c:\windows\system32\iernonce.dll
+ 2006-10-11 01:23 . 2009-06-29 11:07 70656 c:\windows\system32\ie4uinit.exe
+ 2006-06-29 13:05 . 2006-06-29 13:05 26112 c:\windows\system32\idndl.dll
+ 2007-08-13 23:36 . 2009-06-29 16:12 63488 c:\windows\system32\icardie.dll
+ 2006-10-11 01:26 . 2009-06-29 16:12 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2006-10-11 01:25 . 2007-08-13 23:01 48128 c:\windows\system32\dllcache\mshtmler.dll
+ 2006-10-11 01:25 . 2007-08-13 23:32 45568 c:\windows\system32\dllcache\mshta.exe
+ 2006-10-11 01:24 . 2007-08-13 23:44 40960 c:\windows\system32\dllcache\licmgr10.dll
+ 2006-10-11 01:23 . 2009-06-29 16:12 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2006-10-11 01:23 . 2007-08-13 23:39 92672 c:\windows\system32\dllcache\inseng.dll
+ 2006-10-11 01:23 . 2007-08-13 23:36 36352 c:\windows\system32\dllcache\imgutil.dll
+ 2006-10-11 01:23 . 2007-08-13 23:39 55296 c:\windows\system32\dllcache\iesetup.dll
+ 2006-10-11 01:23 . 2009-06-29 16:12 44544 c:\windows\system32\dllcache\iernonce.dll
+ 2006-10-11 01:23 . 2009-06-29 16:12 78336 c:\windows\system32\dllcache\ieencode.dll
+ 2006-10-11 01:23 . 2007-08-13 23:44 69120 c:\windows\system32\dllcache\iedw.exe
+ 2006-10-11 01:23 . 2009-06-29 11:07 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2006-10-11 01:23 . 2007-08-13 23:18 60416 c:\windows\system32\dllcache\hmmapi.dll
- 2005-06-22 10:29 . 2006-06-03 11:40 33792 c:\windows\system32\dllcache\custsat.dll
+ 2005-06-22 10:29 . 2007-08-13 23:54 33792 c:\windows\system32\dllcache\custsat.dll
+ 2006-10-11 01:22 . 2009-06-29 16:12 17408 c:\windows\system32\dllcache\corpol.dll
+ 2006-10-11 01:21 . 2007-08-13 23:39 71680 c:\windows\system32\dllcache\admparse.dll
+ 2006-10-11 01:21 . 2007-08-13 23:39 71680 c:\windows\system32\admparse.dll
+ 2009-08-10 07:47 . 2007-08-13 23:36 44544 c:\windows\ie7updates\KB972260-IE7\pngfilt.dll
+ 2009-08-10 07:47 . 2007-08-13 23:54 50688 c:\windows\ie7updates\KB972260-IE7\msfeedsbs.dll
+ 2009-08-10 07:47 . 2007-08-13 23:54 27136 c:\windows\ie7updates\KB972260-IE7\jsproxy.dll
+ 2009-08-10 07:47 . 2007-08-13 23:39 13312 c:\windows\ie7updates\KB972260-IE7\ieudinit.exe
+ 2009-08-10 07:47 . 2007-08-13 23:39 43008 c:\windows\ie7updates\KB972260-IE7\iernonce.dll
+ 2009-08-10 07:47 . 2009-06-26 16:18 81920 c:\windows\ie7updates\KB972260-IE7\ieencode.dll
+ 2009-08-10 07:47 . 2007-08-13 23:39 54784 c:\windows\ie7updates\KB972260-IE7\ie4uinit.exe
+ 2009-08-10 07:47 . 2007-08-13 23:36 61952 c:\windows\ie7updates\KB972260-IE7\icardie.dll
+ 2009-08-10 07:47 . 2007-08-13 23:42 17408 c:\windows\ie7updates\KB972260-IE7\corpol.dll
+ 2009-08-10 07:46 . 2004-08-04 12:00 37888 c:\windows\ie7\url.dll
+ 2009-08-10 07:46 . 2007-08-13 23:52 66048 c:\windows\ie7\spuninst\ieResetIcons.exe
+ 2009-08-10 07:46 . 2007-08-13 23:54 32960 c:\windows\ie7\spuninst\iecustom.dll
+ 2009-08-10 07:46 . 2009-06-26 16:18 39424 c:\windows\ie7\pngfilt.dll
+ 2009-08-10 07:46 . 2004-08-04 12:00 96256 c:\windows\ie7\occache.dll
+ 2009-08-10 07:46 . 2004-08-04 12:00 56832 c:\windows\ie7\mshtmler.dll
+ 2009-08-10 07:46 . 2004-08-04 12:00 29184 c:\windows\ie7\mshta.exe
+ 2009-08-10 07:46 . 2004-08-04 12:00 22016 c:\windows\ie7\licmgr10.dll
+ 2009-08-10 07:46 . 2009-06-26 16:18 16384 c:\windows\ie7\jsproxy.dll
+ 2009-08-10 07:46 . 2009-06-26 16:18 96256 c:\windows\ie7\inseng.dll
+ 2009-08-10 07:46 . 2004-08-04 12:00 35840 c:\windows\ie7\imgutil.dll
+ 2009-08-10 07:46 . 2004-08-04 12:00 93184 c:\windows\ie7\iexplore.exe
+ 2009-08-10 07:46 . 2004-08-04 12:00 62976 c:\windows\ie7\iesetup.dll
+ 2009-08-10 07:46 . 2004-08-04 12:00 48640 c:\windows\ie7\iernonce.dll
+ 2009-08-10 07:46 . 2009-06-22 11:38 18432 c:\windows\ie7\iedw.exe
+ 2009-08-10 07:46 . 2004-08-04 12:00 34304 c:\windows\ie7\ie4uinit.exe
+ 2009-08-10 07:46 . 2004-08-04 12:00 38912 c:\windows\ie7\hmmapi.dll
+ 2009-08-10 07:46 . 2009-06-26 16:18 55808 c:\windows\ie7\extmgr.dll
+ 2009-08-10 07:46 . 2006-06-03 11:40 33792 c:\windows\ie7\custsat.dll
+ 2009-08-10 07:46 . 2004-08-04 12:00 35328 c:\windows\ie7\corpol.dll
+ 2009-08-10 07:46 . 2004-08-04 12:00 99840 c:\windows\ie7\advpack.dll
+ 2009-08-10 07:46 . 2004-08-04 12:00 61440 c:\windows\ie7\admparse.dll
+ 2009-08-10 07:56 . 2009-08-10 07:56 8192 c:\windows\ERDNT\8-10-2009\Users\00000006\UsrClass.dat
+ 2009-08-10 07:56 . 2009-08-10 07:56 8192 c:\windows\ERDNT\8-10-2009\Users\00000002\UsrClass.dat
+ 2009-08-10 07:44 . 2006-07-14 15:51 121856 c:\windows\system32\xmllite.dll
+ 2007-08-13 23:45 . 2007-08-13 23:45 206336 c:\windows\system32\WinFXDocObj.exe
+ 2006-10-11 01:27 . 2009-06-29 16:12 233472 c:\windows\system32\webcheck.dll
+ 2006-10-11 01:27 . 2007-08-13 23:54 413696 c:\windows\system32\vbscript.dll
+ 2006-10-11 01:27 . 2009-06-29 16:12 105984 c:\windows\system32\url.dll
+ 2006-10-11 01:26 . 2009-06-29 16:12 102912 c:\windows\system32\occache.dll
+ 2006-10-11 01:25 . 2009-06-29 16:12 671232 c:\windows\system32\mstime.dll
+ 2006-10-11 01:25 . 2009-06-29 16:12 193024 c:\windows\system32\msrating.dll
+ 2006-10-11 01:25 . 2007-08-13 23:54 156160 c:\windows\system32\msls31.dll
+ 2006-10-11 01:25 . 2009-06-29 16:12 477696 c:\windows\system32\mshtmled.dll
+ 2007-08-13 23:54 . 2009-06-29 16:12 459264 c:\windows\system32\msfeeds.dll
+ 2006-10-11 01:23 . 2007-08-13 23:38 491520 c:\windows\system32\jscript.dll
+ 2007-08-13 23:54 . 2007-08-13 23:54 180736 c:\windows\system32\ieui.dll
+ 2007-08-13 23:34 . 2009-06-29 16:12 268288 c:\windows\system32\iertutil.dll
+ 2006-10-11 01:23 . 2007-08-13 23:54 191488 c:\windows\system32\iepeers.dll
+ 2006-10-11 01:23 . 2009-06-29 16:12 385024 c:\windows\system32\iedkcs32.dll
+ 2007-07-11 17:27 . 2009-06-29 16:12 380928 c:\windows\system32\ieapfltr.dll
+ 2006-10-11 01:23 . 2009-06-29 08:33 161792 c:\windows\system32\ieakui.dll
+ 2006-10-11 01:23 . 2009-06-29 16:12 230400 c:\windows\system32\ieaksie.dll
+ 2006-10-11 01:23 . 2009-06-29 16:12 153088 c:\windows\system32\ieakeng.dll
+ 2006-10-11 01:23 . 2009-06-29 16:12 133120 c:\windows\system32\extmgr.dll
+ 2006-10-11 01:23 . 2009-06-29 16:12 214528 c:\windows\system32\dxtrans.dll
+ 2006-10-11 01:23 . 2009-06-29 16:12 347136 c:\windows\system32\dxtmsft.dll
+ 2006-10-11 01:27 . 2009-06-29 16:12 827392 c:\windows\system32\dllcache\wininet.dll
+ 2006-10-11 01:27 . 2009-06-29 16:12 233472 c:\windows\system32\dllcache\webcheck.dll
+ 2006-10-11 01:27 . 2008-05-27 17:23 765952 c:\windows\system32\dllcache\vgx.dll
+ 2006-10-11 01:27 . 2007-08-13 23:54 413696 c:\windows\system32\dllcache\vbscript.dll
+ 2006-10-11 01:27 . 2009-06-29 16:12 105984 c:\windows\system32\dllcache\url.dll
+ 2006-10-11 01:26 . 2009-06-29 16:12 102912 c:\windows\system32\dllcache\occache.dll
+ 2006-10-11 01:25 . 2009-06-29 16:12 671232 c:\windows\system32\dllcache\mstime.dll
+ 2006-10-11 01:25 . 2009-06-29 16:12 193024 c:\windows\system32\dllcache\msrating.dll
+ 2006-10-11 01:25 . 2007-08-13 23:54 156160 c:\windows\system32\dllcache\msls31.dll
+ 2006-10-11 01:25 . 2009-06-29 16:12 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2006-10-11 01:23 . 2007-08-13 23:38 491520 c:\windows\system32\dllcache\jscript.dll
+ 2006-10-11 01:23 . 2009-06-29 08:35 634632 c:\windows\system32\dllcache\iexplore.exe
+ 2006-10-11 01:23 . 2007-08-13 23:54 191488 c:\windows\system32\dllcache\iepeers.dll
+ 2006-10-11 01:23 . 2009-06-29 16:12 385024 c:\windows\system32\dllcache\iedkcs32.dll
+ 2006-10-11 01:23 . 2009-06-29 08:33 161792 c:\windows\system32\dllcache\ieakui.dll
+ 2006-10-11 01:23 . 2009-06-29 16:12 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2006-10-11 01:23 . 2009-06-29 16:12 153088 c:\windows\system32\dllcache\ieakeng.dll
+ 2006-10-11 01:23 . 2009-06-29 16:12 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2006-10-11 01:23 . 2009-06-29 16:12 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2006-10-11 01:23 . 2009-06-29 16:12 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2006-10-11 01:21 . 2009-06-29 16:12 124928 c:\windows\system32\dllcache\advpack.dll
+ 2006-10-11 01:21 . 2009-06-29 16:12 124928 c:\windows\system32\advpack.dll
+ 2009-08-10 07:47 . 2007-08-13 23:54 818688 c:\windows\ie7updates\KB972260-IE7\wininet.dll
+ 2009-08-10 07:47 . 2007-08-13 23:54 231424 c:\windows\ie7updates\KB972260-IE7\webcheck.dll
+ 2009-08-10 07:47 . 2007-08-13 23:44 105984 c:\windows\ie7updates\KB972260-IE7\url.dll
+ 2009-08-10 07:47 . 2009-05-26 11:40 382840 c:\windows\ie7updates\KB972260-IE7\spuninst\updspapi.dll
+ 2009-08-10 07:47 . 2008-07-08 13:02 231288 c:\windows\ie7updates\KB972260-IE7\spuninst\spuninst.exe
+ 2009-08-10 07:47 . 2007-08-13 23:44 101376 c:\windows\ie7updates\KB972260-IE7\occache.dll
+ 2009-08-10 07:47 . 2007-08-13 23:54 670720 c:\windows\ie7updates\KB972260-IE7\mstime.dll
+ 2009-08-10 07:47 . 2007-08-13 23:44 192000 c:\windows\ie7updates\KB972260-IE7\msrating.dll
+ 2009-08-10 07:47 . 2007-08-13 23:54 475648 c:\windows\ie7updates\KB972260-IE7\mshtmled.dll
+ 2009-08-10 07:47 . 2007-08-13 23:54 458752 c:\windows\ie7updates\KB972260-IE7\msfeeds.dll
+ 2009-08-10 07:47 . 2007-08-13 23:43 622080 c:\windows\ie7updates\KB972260-IE7\iexplore.exe
+ 2009-08-10 07:47 . 2007-08-13 23:34 266752 c:\windows\ie7updates\KB972260-IE7\iertutil.dll
+ 2009-08-10 07:47 . 2007-08-13 23:39 382976 c:\windows\ie7updates\KB972260-IE7\iedkcs32.dll
+ 2009-08-10 07:47 . 2007-07-11 17:27 383488 c:\windows\ie7updates\KB972260-IE7\ieapfltr.dll
+ 2009-08-10 07:47 . 2007-08-13 22:56 161792 c:\windows\ie7updates\KB972260-IE7\ieakui.dll
+ 2009-08-10 07:47 . 2007-08-13 23:39 229376 c:\windows\ie7updates\KB972260-IE7\ieaksie.dll
+ 2009-08-10 07:47 . 2007-08-13 23:39 152064 c:\windows\ie7updates\KB972260-IE7\ieakeng.dll
+ 2009-08-10 07:47 . 2007-08-13 23:54 131584 c:\windows\ie7updates\KB972260-IE7\extmgr.dll
+ 2009-08-10 07:47 . 2007-08-13 23:35 214528 c:\windows\ie7updates\KB972260-IE7\dxtrans.dll
+ 2009-08-10 07:47 . 2007-08-13 23:35 346624 c:\windows\ie7updates\KB972260-IE7\dxtmsft.dll
+ 2009-08-10 07:47 . 2007-08-13 23:39 123904 c:\windows\ie7updates\KB972260-IE7\advpack.dll
+ 2009-08-10 22:21 . 2007-08-13 23:54 765952 c:\windows\ie7updates\KB938127-v2-IE7\vgx.dll
+ 2009-08-10 22:21 . 2007-03-06 01:23 371424 c:\windows\ie7updates\KB938127-v2-IE7\spuninst\updspapi.dll
+ 2009-08-10 22:21 . 2007-03-06 01:22 213216 c:\windows\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe
+ 2009-08-10 07:46 . 2009-06-26 16:18 659456 c:\windows\ie7\wininet.dll
+ 2009-08-10 07:46 . 2004-08-04 12:00 276480 c:\windows\ie7\webcheck.dll
+ 2009-08-10 07:46 . 2004-08-04 12:00 848384 c:\windows\ie7\vgx.dll
+ 2009-08-10 07:46 . 2007-12-18 14:40 417792 c:\windows\ie7\vbscript.dll
+ 2009-08-10 07:46 . 2009-06-26 16:18 616448 c:\windows\ie7\urlmon.dll
+ 2009-08-10 07:46 . 2006-09-06 22:43 371424 c:\windows\ie7\spuninst\updspapi.dll
+ 2009-08-10 07:46 . 2006-09-06 22:43 213216 c:\windows\ie7\spuninst\spuninst.exe
+ 2009-08-10 07:46 . 2009-06-26 16:18 532480 c:\windows\ie7\mstime.dll
+ 2009-08-10 07:46 . 2009-06-26 16:18 146432 c:\windows\ie7\msrating.dll
+ 2009-08-10 07:46 . 2004-08-04 12:00 146432 c:\windows\ie7\msls31.dll
+ 2009-08-10 07:46 . 2009-06-26 16:18 449024 c:\windows\ie7\mshtmled.dll
+ 2009-08-10 07:46 . 2007-12-18 14:40 450560 c:\windows\ie7\jscript.dll
+ 2009-08-10 07:46 . 2009-06-26 16:18 251392 c:\windows\ie7\iepeers.dll
+ 2009-08-10 07:46 . 2004-08-04 12:00 323584 c:\windows\ie7\iedkcs32.dll
+ 2009-08-10 07:46 . 2004-08-04 12:00 221184 c:\windows\ie7\ieakui.dll
+ 2009-08-10 07:46 . 2004-08-04 12:00 216576 c:\windows\ie7\ieaksie.dll
+ 2009-08-10 07:46 . 2004-08-04 12:00 139264 c:\windows\ie7\ieakeng.dll
+ 2009-08-10 07:46 . 2009-06-26 16:18 205312 c:\windows\ie7\dxtrans.dll
+ 2009-08-10 07:46 . 2009-06-26 16:18 357888 c:\windows\ie7\dxtmsft.dll
+ 2009-08-10 07:56 . 2009-08-10 07:56 241664 c:\windows\ERDNT\8-10-2009\Users\00000005\NTUSER.DAT
+ 2009-08-10 07:56 . 2009-08-10 07:56 253952 c:\windows\ERDNT\8-10-2009\Users\00000004\UsrClass.dat
+ 2009-08-10 07:56 . 2009-08-10 07:56 241664 c:\windows\ERDNT\8-10-2009\Users\00000001\NTUSER.DAT
+ 2009-08-10 07:56 . 2005-10-20 17:02 163328 c:\windows\ERDNT\8-10-2009\ERDNT.EXE
+ 2006-10-11 01:27 . 2009-06-29 16:12 1159680 c:\windows\system32\urlmon.dll
+ 2006-10-11 01:25 . 2009-07-20 00:03 3597824 c:\windows\system32\mshtml.dll
+ 2007-08-13 23:54 . 2009-07-19 13:32 6067200 c:\windows\system32\ieframe.dll
+ 2007-02-12 21:10 . 2009-06-29 08:33 2452872 c:\windows\system32\ieapfltr.dat
+ 2006-10-11 01:27 . 2009-06-29 16:12 1159680 c:\windows\system32\dllcache\urlmon.dll
+ 2006-10-11 01:25 . 2009-07-20 00:03 3597824 c:\windows\system32\dllcache\mshtml.dll
+ 2009-08-10 07:47 . 2007-08-13 23:54 1162240 c:\windows\ie7updates\KB972260-IE7\urlmon.dll
+ 2009-08-10 07:47 . 2007-08-13 23:54 3578368 c:\windows\ie7updates\KB972260-IE7\mshtml.dll
+ 2009-08-10 07:47 . 2007-08-13 23:54 6049280 c:\windows\ie7updates\KB972260-IE7\ieframe.dll
+ 2009-08-10 07:47 . 2007-02-12 21:10 2451312 c:\windows\ie7updates\KB972260-IE7\ieapfltr.dat
+ 2009-08-10 07:46 . 2009-07-18 16:20 3062272 c:\windows\ie7\mshtml.dll
+ 2009-08-10 07:56 . 2009-08-10 07:56 3960832 c:\windows\ERDNT\8-10-2009\Users\00000003\NTUSER.DAT
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-09 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TabletWizard"="c:\windows\help\SplshWrp.exe" [2004-08-04 16384]
"TabletTip"="c:\program files\Common Files\microsoft shared\ink\tabtip.exe" [2004-08-04 271872]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-12-16 169984]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 688218]
"HostManager"="c:\program files\Common Files\AOL\1229413987\EE\AOLHostManager.exe" [2004-11-03 125528]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-10-12 139264]
"Snippet"="c:\program files\Microsoft Experience Pack\Snipping Tool\SnippingTool.exe" [2005-02-25 68296]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 32768]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 602182]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-12-16 98304]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-12-16 1783808]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"SMSERIAL"="sm56hlpr.exe" - c:\windows\sm56hlpr.exe [2006-01-20 544768]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-12-27 413696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-12-15 384000]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\loginkey]
2004-08-04 12:00 47104 —-a-w- c:\program files\Common Files\Microsoft Shared\Ink\LoginKey.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\TabBtnWL]
2002-08-29 10:41 11776 —-a-w- c:\windows\system32\tabbtnwl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpgwlnotify]
2004-08-04 12:00 30208 —-a-w- c:\windows\system32\tpgwlnot.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1229413987\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [8/7/2009 6:29 PM 114768]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [12/16/2008 6:51 PM 141312]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8/7/2009 6:29 PM 20560]
R3 FinePnt;FinePoint Innovations HID Driver;c:\windows\system32\drivers\FpHidDrv.sys [12/16/2008 1:52 AM 18816]
R3 MSTabBtn;Tablet PC Buttons HID Driver;c:\windows\system32\drivers\MSTabBtn.sys [12/16/2008 1:52 AM 9600]
S3 el575nd5;3Com Megahertz 10/100 LAN CardBus PC Card Driver;c:\windows\system32\drivers\el575ND5.sys [12/16/2008 1:48 AM 69692]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [12/16/2008 7:41 PM 33752]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&Br;=GTW&Loc;=ENG_US&Sys;=PTB&M;=CX2724
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Crawler Search - tbr:iemenu
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\ctbr.dll
DPF: {C75BE5CC-7F80-458C-8B66-FAB86E3B13C3} - hxxp://images.fotki.com/activex/FotkiUploader.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\pe030i71.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p;=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p;=
FF - component: c:\program files\Crawler\firefox\components\xcomm.dll
FF - component: c:\program files\Crawler\firefox\components\xshared.dll
FF - component: c:\program files\Crawler\firefox\components\xsupport.dll
FF - component: c:\program files\Crawler\firefox\components\xwsg.dll
FF - plugin: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\pe030i71.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-10 17:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3720)
c:\windows\system32\WININET.dll
c:\program files\windows journal\nbmaptip.dll
c:\windows\IME\SPGRMR.DLL
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Common Files\Microsoft Shared\Ink\KeyboardSurrogate.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\system32\wisptis.exe
c:\windows\system32\tabbtnu.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Microsoft Shared\Ink\TCServer.exe
c:\program files\Google\Google Desktop Search\GoogleDesktopIndex.exe
c:\program files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\progra~1\COMMON~1\AOL\122941~1\EE\AOLServiceHost.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\windows\system32\wdfmgr.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
.
**************************************************************************
.
Completion time: 2009-08-10 17:45 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-10 22:45
ComboFix2.txt 2009-08-09 19:16

Pre-Run: 44,681,211,904 bytes free
Post-Run: 44,673,126,400 bytes free

371 — E O F — 2009-08-10 22:21
Hi,

Please do the following:

  • Go to Start >> My Computer > C:\
  • Then Navigate to the C:\Qoobox\Quarantine folder.
  • Find the archive zip file called "[4]-Submit_Date_Time.zip" ( Date and time will be close to this > 08/10/2009 17:28)
  • Simply go to This Channel and upload the submit.zip archive file to me.
  • Follow the instructions on that page to copy/paste/send the requested file.

Please let me know if the upload was successful

NEXT

Go Start > Run and copy/paste the following single-line command into the Run box and click OK:

cmd /c del /f/a/q "c:\windows\system32\wopimiga.exe" "c:\windows\system32\jiziveji.exe"



NEXT


Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report
I upload the file to bleepingcomputer.com. I have also attached the MBAM log, but I am unable to download Kap…its says that the "java applet failed go online to use the program". Malwarebytes' Anti-Malware 1.40 Database version: 2551 Windows 5.1.2600 Service Pack 2 8/10/2009 8:50:16 PM mbam-log-2009-08-10 (20-50-16).txt Scan type: Quick Scan Objects scanned: 94446 Time elapsed: 5 minute(s), 52 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 5 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{c48635ad-d6b5-3ee4-aaa2-540d5a173658} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{c48635ad-d6b5-3ee4-aaa2-540d5a173658} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{c48635ad-d6b5-3ee4-aaa2-540d5a173658} (Backdoor.Bot) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi,

The files found by MBAM indicate a "backdoorbot"

This type of infection allows hackers to remotely control your computer, steal critical system information and download and execute files without your knowledge.
If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Please read this: How Do I Handle Possible Identify Theft, Internet Fraud, and CC Fraud?


NEXT

Kaspersky can be a bit finicky to run - please check the following setting:

the Java Addon in IE is probably disabled.

Go to Tools > Internet Options > Advanced tab. Click Reset then OK and exit IE.

Re-open IE and ensure the Java add-ons are enabled.

[external image: Posted Image]


If Kaspersky still will not run, please do the following scan:

Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=6 # iexplore.exe=7.00.6000.16876 (vista_gdr.090625-2339) # OnlineScanner.ocx=1.0.0.5889 # api_version=3.0.2 # EOSSerial=e7ea34b642dc624f8b08e8510bc6e5f8 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2009-08-11 07:56:37 # local_time=2009-08-11 02:56:37 (-0600, Central Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=769 37 100 100 205175781250 # compatibility_mode=1793 22 0 4 482497457178750 # compatibility_mode=7937 61 100 100 205058970625000 # scanned=234273 # found=11 # cleaned=0 # scan_time=12110 C:\Documents and Settings\Owner\Desktop\SDFix.exe Win32/PrcView application 00000000000000000000000000000000 I C:\My Backup – 08-11-30 0946PM\Program Files\Mozilla Firefox\chrome\amba.jar Win32/Spy.Ursnif.A trojan 00000000000000000000000000000000 I C:\My Backup – 08-11-30 0946PM\Program Files\SelectRebates\SelectRebates.exe probably a variant of Win32/Genetik trojan 00000000000000000000000000000000 I C:\My Backup – 08-11-30 0946PM\Program Files\SelectRebates\SelectRebatesApi.exe probably a variant of Win32/Adware.SAHAgent application 00000000000000000000000000000000 I C:\My Backup – 08-11-30 0946PM\Program Files\SelectRebates\SelectRebatesUninstall.exe probably a variant of Win32/Genetik trojan 00000000000000000000000000000000 I C:\My Backup – 08-11-30 0946PM\WINDOWS\system32\aaGjmnmp.ini Win32/Adware.Virtumonde.NEO application 00000000000000000000000000000000 I C:\My Backup – 08-11-30 0946PM\WINDOWS\system32\aaGjmnmp.ini2 Win32/Adware.Virtumonde.NEO application 00000000000000000000000000000000 I C:\SDFix\apps\Process.exe Win32/PrcView application 00000000000000000000000000000000 I C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\GK2SVGE9\static[1].exe Win32/Spy.Zbot.JF trojan 00000000000000000000000000000000 I C:\_OTL\MovedFiles\08082009_160951\WINDOWS\System32\critical_warning.html Win32/TrojanDownloader.FakeAlert.ADG trojan 00000000000000000000000000000000 I C:\_OTL\MovedFiles\08082009_160951\WINDOWS\System32\drivers\etc\hosts Win32/Qhost trojan 00000000000000000000000000000000 I The computer is running better. :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI