This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] PC Antispyware 2010

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I am new to this forum. I am hopeing that you can help. I found this PC Anitspyware 2010 on my computer. I tried using Malwarebytes' Anti-malware to get rid of it but the file won't open. I follow your directions to get you the following information. I am pulling my hair out. I really don't want to wipe the drive and start over. I think I got everything. Thank you in advance for any help you can give me. :pullhair:



DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 10:24:27.84 on Sat 08/29/2009
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.522 [GMT -4:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Protection System *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\braviax.exe
svchost.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\PC_Antispyware2010\PC_Antispyware2010.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Documents and Settings\Noah\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client;=dell
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
mDefault_Search_URL = hxxp://www.google.com/ie
mSearch Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uSearchAssistant = hxxp://www.google.com
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com
uURLSearchHooks: H - No File
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: c:\windows\system32\tajf83ikdmf.dll: {bf56a325-23f2-42ad-f4e4-00aac39caa53} - c:\windows\system32\tajf83ikdmf.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [braviax] braviax.exe
uPolicies-explorer: NoFolderOptions = 1 (0x1)
uPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
uPolicies-system: DisableRegistryTools = 1 (0x1)
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_02\bin\ssv.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: musicmatch.com\online
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://javadl-esd.sun.com/update/1.6.0/jinstall-6-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: avgrsstarter - avgrsstx.dll
AppInit_DLLs: cru629.dat
STS: c:\windows\system32\tajf83ikdmf.dll: {bf56a325-23f2-42ad-f4e4-00aac39caa53} - c:\windows\system32\tajf83ikdmf.dll

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-2-16 335240]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-2-16 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-2-16 108552]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S4 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-2-16 908056]
S4 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-2-16 297752]
S4 SMS_v3_2_0;SMS_v3_2_0;c:\program files\rosetta stone\sms v3.2.0hs\wrapper.exe [2007-7-12 204800]

============== File Associations ===============

scrfile="%1" %*

=============== Created Last 30 ================

2009-08-29 08:02 19,089 a——- c:\windows\system32\lazateq._sy
2009-08-29 08:01 6,144 a——- c:\windows\cru629.dat
2009-08-28 21:15 19,359 a——- c:\windows\ucalozanen.db
2009-08-28 21:15 18,991 a——- c:\docume~1\noah\applic~1\wobog.exe
2009-08-28 21:15 17,284 a——- c:\windows\dabyroj._dl
2009-08-28 21:15 17,178 a——- c:\docume~1\noah\applic~1\jacype.dat
2009-08-28 21:15 17,173 a——- c:\docume~1\alluse~1\applic~1\muniwa.bat
2009-08-28 21:15 16,517 a——- c:\docume~1\noah\applic~1\ubypy.bin
2009-08-28 21:15 16,089 a——- c:\windows\system32\ibir.ban
2009-08-28 21:15 15,533 a——- c:\docume~1\alluse~1\applic~1\osov.bin
2009-08-28 21:15 15,462 a——- c:\docume~1\alluse~1\applic~1\ipaci.bat
2009-08-28 21:15 15,321 a——- c:\windows\system32\ruvyqulywi._dl
2009-08-28 21:15 14,426 a——- c:\program files\common files\ydeg.scr
2009-08-28 21:15 14,374 a——- c:\windows\system32\xewogy._dl
2009-08-28 21:15 13,880 a——- c:\program files\common files\ryjiloqy.bin
2009-08-28 21:15 13,359 a——- c:\docume~1\noah\applic~1\vyvor.vbs
2009-08-28 21:15 13,154 a——- c:\program files\common files\keha.reg
2009-08-28 21:15 10,858 a——- c:\program files\common files\myly.bat
2009-08-28 21:15 10,281 a——- c:\windows\feno.com
2009-08-28 21:15 10,232 a——- c:\program files\common files\omewirodo.dat
2009-08-28 21:15 –d—– c:\program files\PC_Antispyware2010
2009-08-28 21:05 42,496 a——- C:\dvrdiqbe.exe
2009-08-28 15:14 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-28 15:14 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-08-28 15:14 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-08-28 15:14 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-28 14:56 18,323 a——- c:\windows\ceduqahov.scr
2009-08-28 14:56 16,900 a——- c:\windows\system32\okiqi.sys
2009-08-28 14:56 15,818 a——- c:\docume~1\alluse~1\applic~1\xymu.dll
2009-08-28 14:56 15,269 a——- c:\docume~1\noah\applic~1\ohowy.sys
2009-08-28 14:56 13,668 a——- c:\docume~1\alluse~1\applic~1\ifotita.scr
2009-08-28 14:56 12,165 a——- c:\program files\common files\notok.reg
2009-08-28 14:56 12,111 a——- c:\windows\ibebepif.com
2009-08-28 14:56 11,246 a——- c:\windows\bexop.lib
2009-08-28 14:56 13,230 a——- c:\windows\system32\uhigo.com
2009-08-28 14:56 11,726 a——- c:\windows\tupep.ban
2009-08-27 18:51 19,443 a——- c:\windows\ecajoliza.lib
2009-08-27 18:51 18,598 a——- c:\windows\bufy.reg
2009-08-27 18:51 18,048 a——- c:\windows\qexezi.dll
2009-08-27 18:51 17,055 a——- c:\windows\kutaji.scr
2009-08-27 18:51 13,968 a——- c:\windows\system32\leku._dl
2009-08-27 18:51 11,864 a——- c:\windows\lewyb._sy
2009-08-27 18:51 11,435 a——- c:\program files\common files\bufumybe.dll
2009-08-27 18:51 11,186 a——- c:\windows\system32\vofokyru.lib
2009-08-27 18:51 10,857 a——- c:\windows\cinypylo.vbs
2009-08-26 12:59 –d—– c:\docume~1\noah\applic~1\MalwareRemovalBot
2009-08-22 07:52 31,232 a——- c:\windows\system32\wingenocx.dll
2009-08-22 07:40 19,249 a——- c:\docume~1\alluse~1\applic~1\afycolizi.dll
2009-08-22 07:40 18,542 a——- c:\windows\tazecyliru.bat
2009-08-22 07:40 18,427 a——- c:\windows\ezumiwibe.exe
2009-08-22 07:40 17,753 a——- c:\windows\system32\atybiped.com
2009-08-22 07:40 17,582 a——- c:\windows\system32\usiji.db
2009-08-22 07:40 16,613 a——- c:\windows\pyzimopuqi.com
2009-08-22 07:40 15,645 a——- c:\windows\jovajir.dat
2009-08-22 07:40 14,958 a——- c:\windows\ladabuf._dl
2009-08-22 07:40 14,565 a——- c:\program files\common files\kanymi.bat
2009-08-22 07:40 13,678 a——- c:\windows\delo.sys
2009-08-22 07:40 13,382 a——- c:\windows\rogyj.dll
2009-08-22 07:40 11,111 a——- c:\docume~1\noah\applic~1\kuqoni.dll
2009-08-22 07:40 10,787 a——- c:\windows\akefa.bin
2009-08-22 07:40 10,696 a——- c:\program files\common files\acyfurohe.pif
2009-08-22 07:40 10,509 a——- c:\windows\vini.inf
2009-08-22 07:40 348,674 a——- c:\windows\system32\_scui.cpl
2009-08-22 07:32 6,144 a——- c:\windows\system32\cru629.dat
2009-08-22 07:32 11,264 a——- c:\windows\braviax.exe
2009-08-22 07:30 15,000 a——- c:\windows\system32\tajf83ikdmf.dll
2009-08-22 07:30 10,752 a——- C:\yihw.exe
2009-08-22 07:30 2 a–sh— C:\-462040451
2009-08-22 07:30 189,791 a——- c:\windows\system32\wisdstr.exe
2009-08-22 07:29 29,184 a——- c:\windows\system32\dllcache\beep.sys
2009-08-22 07:29 11,264 a——- c:\windows\system32\braviax.exe
2009-08-22 07:29 77,312 a——- c:\windows\system32\~.exe
2009-08-20 20:53 –d—– c:\docume~1\alluse~1\applic~1\Blizzard Entertainment
2009-08-18 08:34 –d—– c:\program files\GodsWar Online
2009-08-17 09:31 –d—– c:\program files\DNA
2009-08-17 09:31 –d—– c:\docume~1\noah\applic~1\DNA
2009-08-12 12:06 128,512 ——– c:\windows\system32\dllcache\dhtmled.ocx
2009-08-12 12:06 1,315,328 ——– c:\windows\system32\dllcache\msoe.dll
2009-08-09 09:46 1,089,593 ——– c:\windows\system32\dllcache\ntprint.cat
2009-08-08 13:53 –d—– c:\windows\system32\XPSViewer
2009-08-08 13:52 1,676,288 ——– c:\windows\system32\xpssvcs.dll
2009-08-08 13:52 1,676,288 ——– c:\windows\system32\dllcache\xpssvcs.dll
2009-08-08 13:52 597,504 ——– c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-08 13:52 575,488 ——– c:\windows\system32\xpsshhdr.dll
2009-08-08 13:52 575,488 ——– c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-08 13:52 117,760 ——– c:\windows\system32\prntvpt.dll
2009-08-08 13:52 89,088 ——– c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-08 13:52 –d—– C:\ca9890ad2b50aea30f5751
2009-08-08 12:58 993,792 a——- c:\documents and settings\noah\WLL.exe

==================== Find3M ====================

2009-08-28 14:56 12,338 a——- c:\program files\common files\ywak._sy
2009-08-28 14:51 335,240 a——- c:\windows\system32\drivers\avgldx86.sys
2009-08-28 14:51 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-08-27 18:51 12,671 a——- c:\program files\common files\iqudakoti._sy
2009-08-22 07:29 29,184 a——- c:\windows\system32\drivers\beep.sys
2009-08-20 14:59 34 a——- c:\documents and settings\noah\jagex_runescape_preferences.dat
2009-08-11 16:38 8,456 a——- c:\windows\system32\KGyGaAvL.sys
2009-08-05 05:01 204,800 a——- c:\windows\system32\dllcache\mswebdvd.dll
2009-08-05 05:01 204,800 ——– c:\windows\system32\mswebdvd.dll
2009-07-19 09:33 3,597,824 a——- c:\windows\system32\dllcache\mshtml.dll
2009-07-19 09:32 6,067,200 ——– c:\windows\system32\dllcache\ieframe.dll
2009-07-17 15:01 58,880 a——- c:\windows\system32\atl.dll
2009-07-17 15:01 58,880 ——– c:\windows\system32\dllcache\atl.dll
2009-07-13 10:08 286,720 ——– c:\windows\system32\wmpdxm.dll
2009-07-13 10:08 286,720 ——– c:\windows\system32\dllcache\wmpdxm.dll
2009-07-13 10:08 5,537,792 ——– c:\windows\system32\dllcache\wmp.dll
2009-06-29 07:07 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe
2009-06-29 07:07 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe
2009-06-29 04:35 634,632 a——- c:\windows\system32\dllcache\iexplore.exe
2009-06-29 04:33 2,452,872 ——– c:\windows\system32\dllcache\ieapfltr.dat
2009-06-29 04:33 161,792 ——– c:\windows\system32\dllcache\ieakui.dll
2009-06-16 10:36 119,808 ——– c:\windows\system32\t2embed.dll
2009-06-16 10:36 119,808 ——– c:\windows\system32\dllcache\t2embed.dll
2009-06-16 10:36 81,920 ——– c:\windows\system32\fontsub.dll
2009-06-16 10:36 81,920 ——– c:\windows\system32\dllcache\fontsub.dll
2009-06-12 08:31 80,896 ——– c:\windows\system32\tlntsess.exe
2009-06-12 08:31 80,896 ——– c:\windows\system32\dllcache\tlntsess.exe
2009-06-12 08:31 76,288 ——– c:\windows\system32\telnet.exe
2009-06-12 08:31 76,288 ——– c:\windows\system32\dllcache\telnet.exe
2009-06-10 10:13 84,992 ——– c:\windows\system32\dllcache\avifil32.dll
2009-06-10 10:13 84,992 ——– c:\windows\system32\avifil32.dll
2009-06-10 09:19 2,066,432 ——– c:\windows\system32\mstscax.dll
2009-06-10 09:19 2,066,432 ——– c:\windows\system32\dllcache\mstscax.dll
2009-06-10 02:14 132,096 ——– c:\windows\system32\wkssvc.dll
2009-06-10 02:14 132,096 ——– c:\windows\system32\dllcache\wkssvc.dll
2009-06-03 15:09 1,291,264 a——- c:\windows\system32\quartz.dll
2009-06-03 15:09 1,291,264 ——– c:\windows\system32\dllcache\quartz.dll
2007-02-21 07:41 32 ac—r– c:\documents and settings\all users\hash.dat
2008-10-02 10:39 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008100220081003\index.dat

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-07-30.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 3/16/2006 2:43:14 PM
System Uptime: 8/29/2009 10:08:42 AM (0 hours ago)

Motherboard: Dell Inc. | | 0WG261
Processor: Intel® Pentium® 4 CPU 3.00GHz | Microprocessor | 2992/800mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 70 GiB total, 33.385 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Packet Scheduler Miniport
Device ID: ROOT\MS_PSCHEDMP\0002
Manufacturer: Microsoft
Name: Linksys Wireless-G PCI Adapter - Packet Scheduler Miniport
PNP Device ID: ROOT\MS_PSCHEDMP\0002
Service: PSched

==== System Restore Points ===================

No restore point in system.

==== Installed Programs ======================

Adobe Acrobat - Reader 6.0.2 Update
Adobe Flash Player ActiveX
Adobe Reader 6.0.1
Age of Empires III
Amazon MP3 Downloader 1.0.3
AOLIcon
Apple Software Update
ATI Control Panel
ATI Display Driver
AVG Free 8.5
Blender (remove only)
Canon Camera Access Library
Canon Camera Support Core Library
Canon G.726 WMP-Decoder
Canon MovieEdit Task for ZoomBrowser EX
Canon RAW Image Task for ZoomBrowser EX
Canon Utilities CameraWindow
Canon Utilities CameraWindow DC
Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
Canon Utilities EOS Utility
Canon Utilities MyCamera
Canon Utilities MyCamera DC
Canon Utilities PhotoStitch
Canon Utilities RemoteCapture Task for ZoomBrowser EX
Canon Utilities ZoomBrowser EX
Canon ZoomBrowser EX Memory Card Utility
Character Builder
Conexant D850 56K V.9x DFVc Modem
Corel Paint Shop Pro X
Corel Photo Album 6
Dell CinePlayer
Dell Digital Jukebox Driver
Dell Driver Reset Tool
Dell System Restore
DellSupport
Digital Content Portal
Digital Line Detect
DNA
EarthLink setup files
EducateU
ELIcon
ESPNMotion
Game Console - WildGames
GameShadow
Get High Speed Internet!
GodsWar Online
Google
Google Desktop
Google Earth
Google Toolbar for Internet Explorer
Harry Potter II
High Definition Audio Driver Package - KB835221
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Intel® PRO Network Connections Drivers
Intel® PROSet for Wired Connections
iTunes
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 9
Java 2 Runtime Environment, SE v1.4.2_03
Java™ 6 Update 2
Learn2 Player (Uninstall Only)
Malwarebytes' Anti-Malware
MCU
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Modem Helper
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
Musicmatch for Windows Media Player
Musicmatch® Jukebox
NetWaiting
NetZeroInstallers
QuickTime
RealPlayer Basic
Roblox for Noah
Rosetta Stone 2.2.1.0Asms
Roxio DLA
Roxio MyDVD LE
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Silent Hunter III
Skype™ 4.0
Sonic Activation Module
Sonic Encoders
Sonic Update Manager
Star Defender 2 Free Trial
Storywizard
Student Management System v3.2.0hs
The Sims Complete Collection
Time to Ride
Type to Learn 3 Home
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB973815)
Update Rollup 2 for Windows XP Media Center Edition 2005
URL Assistant
Viewpoint Media Player
WebCyberCoach 3.2 Dell
WebFldrs XP
WildTangent Games
WildTangent Web Driver
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
Windows XP Media Center Edition 2005 KB908246
Windows XP Media Center Edition 2005 KB908250
Windows XP Service Pack 3
Wizard101
WordPerfect Office 12
World of Warcraft
Xfire (remove only)

==== Event Viewer Messages From Past Week ========

8/28/2009 7:01:31 AM, error: Dhcp [1002] - The IP address lease 192.168.2.3 for the Network Card with network address 00123FCDD080 has been denied by the DHCP server 192.168.2.1 (The DHCP Server sent a DHCPNACK message).
8/27/2009 7:08:22 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
8/27/2009 7:05:39 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
8/27/2009 6:44:12 AM, information: Windows File Protection [64001] - File replacement was attempted on the protected system file nls302en.lex. This file was restored to the original version to maintain system stability. The file version of the bad file is 0.0.0.1, the version of the system file is 0.0.0.1.
8/26/2009 12:56:38 PM, error: Service Control Manager [7023] - The System Restore Service service terminated with the following error: The system cannot find the file specified.
8/26/2009 12:56:38 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the AVG Free8 E-mail Scanner service to connect.
8/26/2009 12:56:38 PM, error: Service Control Manager [7000] - The AVG Free8 E-mail Scanner service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
8/26/2009 12:55:27 PM, error: SRService [104] - The System Restore initialization process failed.
8/26/2009 1:24:12 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AvgLdx86 AvgMfx86 AvgTdiX Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip WS2IFSL
8/26/2009 1:24:12 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
8/26/2009 1:24:12 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/26/2009 1:24:12 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/26/2009 1:24:12 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
8/26/2009 1:23:25 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
8/26/2009 1:23:24 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
8/26/2009 1:23:12 PM, error: sfsync02 [12] -

==== End Of File ===========================

============= FINISH: 10:25:26.98 ===============

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-07-30.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 3/16/2006 2:43:14 PM
System Uptime: 8/29/2009 10:08:42 AM (0 hours ago)

Motherboard: Dell Inc. | | 0WG261
Processor: Intel® Pentium® 4 CPU 3.00GHz | Microprocessor | 2992/800mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 70 GiB total, 33.385 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Packet Scheduler Miniport
Device ID: ROOT\MS_PSCHEDMP\0002
Manufacturer: Microsoft
Name: Linksys Wireless-G PCI Adapter - Packet Scheduler Miniport
PNP Device ID: ROOT\MS_PSCHEDMP\0002
Service: PSched

==== System Restore Points ===================

No restore point in system.

==== Installed Programs ======================

Adobe Acrobat - Reader 6.0.2 Update
Adobe Flash Player ActiveX
Adobe Reader 6.0.1
Age of Empires III
Amazon MP3 Downloader 1.0.3
AOLIcon
Apple Software Update
ATI Control Panel
ATI Display Driver
AVG Free 8.5
Blender (remove only)
Canon Camera Access Library
Canon Camera Support Core Library
Canon G.726 WMP-Decoder
Canon MovieEdit Task for ZoomBrowser EX
Canon RAW Image Task for ZoomBrowser EX
Canon Utilities CameraWindow
Canon Utilities CameraWindow DC
Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
Canon Utilities EOS Utility
Canon Utilities MyCamera
Canon Utilities MyCamera DC
Canon Utilities PhotoStitch
Canon Utilities RemoteCapture Task for ZoomBrowser EX
Canon Utilities ZoomBrowser EX
Canon ZoomBrowser EX Memory Card Utility
Character Builder
Conexant D850 56K V.9x DFVc Modem
Corel Paint Shop Pro X
Corel Photo Album 6
Dell CinePlayer
Dell Digital Jukebox Driver
Dell Driver Reset Tool
Dell System Restore
DellSupport
Digital Content Portal
Digital Line Detect
DNA
EarthLink setup files
EducateU
ELIcon
ESPNMotion
Game Console - WildGames
GameShadow
Get High Speed Internet!
GodsWar Online
Google
Google Desktop
Google Earth
Google Toolbar for Internet Explorer
Harry Potter II
High Definition Audio Driver Package - KB835221
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Intel® PRO Network Connections Drivers
Intel® PROSet for Wired Connections
iTunes
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 9
Java 2 Runtime Environment, SE v1.4.2_03
Java™ 6 Update 2
Learn2 Player (Uninstall Only)
Malwarebytes' Anti-Malware
MCU
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Modem Helper
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
Musicmatch for Windows Media Player
Musicmatch® Jukebox
NetWaiting
NetZeroInstallers
QuickTime
RealPlayer Basic
Roblox for Noah
Rosetta Stone 2.2.1.0Asms
Roxio DLA
Roxio MyDVD LE
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Silent Hunter III
Skype™ 4.0
Sonic Activation Module
Sonic Encoders
Sonic Update Manager
Star Defender 2 Free Trial
Storywizard
Student Management System v3.2.0hs
The Sims Complete Collection
Time to Ride
Type to Learn 3 Home
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB973815)
Update Rollup 2 for Windows XP Media Center Edition 2005
URL Assistant
Viewpoint Media Player
WebCyberCoach 3.2 Dell
WebFldrs XP
WildTangent Games
WildTangent Web Driver
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
Windows XP Media Center Edition 2005 KB908246
Windows XP Media Center Edition 2005 KB908250
Windows XP Service Pack 3
Wizard101
WordPerfect Office 12
World of Warcraft
Xfire (remove only)

==== Event Viewer Messages From Past Week ========

8/28/2009 7:01:31 AM, error: Dhcp [1002] - The IP address lease 192.168.2.3 for the Network Card with network address 00123FCDD080 has been denied by the DHCP server 192.168.2.1 (The DHCP Server sent a DHCPNACK message).
8/27/2009 7:08:22 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
8/27/2009 7:05:39 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
8/27/2009 6:44:12 AM, information: Windows File Protection [64001] - File replacement was attempted on the protected system file nls302en.lex. This file was restored to the original version to maintain system stability. The file version of the bad file is 0.0.0.1, the version of the system file is 0.0.0.1.
8/26/2009 12:56:38 PM, error: Service Control Manager [7023] - The System Restore Service service terminated with the following error: The system cannot find the file specified.
8/26/2009 12:56:38 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the AVG Free8 E-mail Scanner service to connect.
8/26/2009 12:56:38 PM, error: Service Control Manager [7000] - The AVG Free8 E-mail Scanner service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
8/26/2009 12:55:27 PM, error: SRService [104] - The System Restore initialization process failed.
8/26/2009 1:24:12 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AvgLdx86 AvgMfx86 AvgTdiX Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip WS2IFSL
8/26/2009 1:24:12 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
8/26/2009 1:24:12 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/26/2009 1:24:12 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/26/2009 1:24:12 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
8/26/2009 1:23:25 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
8/26/2009 1:23:24 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
8/26/2009 1:23:12 PM, error: sfsync02 [12] -

==== End Of File ===========================

Attachments:

Hi,

This can be a nasty one.

Lets see if this works if not don't worry I have a lot more tricks up my sleeve.

Download and Run Win32KDiag

Please download Win32Diag from one of the links below and save it to your desktop.

Link 1
Link 2
Link 3

  • Double-click on Win32Diag.exe to run it. If you are using Windows Vista, please right-click and select Run As Administrator
  • A black command prompt window shall appear.
  • It will now begin to scan. This may take a while, please be paitent until the scan is complete.
  • Once it's done, in the black screen it will say "Finished! Press any key to exit…. Press any key to exit.
  • A log file called Win32KDiag.txt will be created on your desktop.
  • Please copy and paste the contents of that log file here in your next reply please.


Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

    [external image: Posted Image]

    [external image: Posted Image]

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    ———————————————————–

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      ———————————————————–

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    ———————————————————–

  • Double click on combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\Combo-Fix.txt"
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**
I follow your instructions to the letter. It works so far. Here are the results from the 2 downloads


Log file is located at: C:\Documents and Settings\Noah\Desktop\Win32kDiag.txt

WARNING: Could not get backup privileges!

Searching 'C:\WINDOWS'…





Finished!



ComboFix 09-08-29.01 - Noah 08/29/2009 22:40.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.730 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\Noah\LOCALS~1\Temp\csrss.exe
c:\docume~1\Noah\LOCALS~1\Temp\lsass.exe
c:\docume~1\Noah\LOCALS~1\Temp\services.exe
c:\docume~1\Noah\LOCALS~1\Temp\taskmgr.exe
c:\documents and settings\All Users\Application Data\afycolizi.dll
c:\documents and settings\All Users\Application Data\anuhyl.inf
c:\documents and settings\All Users\Application Data\holaq.lib
c:\documents and settings\All Users\Application Data\ifotita.scr
c:\documents and settings\All Users\Application Data\ipaci.bat
c:\documents and settings\All Users\Application Data\jawovure.dl
c:\documents and settings\All Users\Application Data\liwaxic.lib
c:\documents and settings\All Users\Application Data\muniwa.bat
c:\documents and settings\All Users\Application Data\osov.bin
c:\documents and settings\All Users\Application Data\ubyfaby._sy
c:\documents and settings\All Users\Application Data\volukitor.ban
c:\documents and settings\All Users\Application Data\xipyxurim.inf
c:\documents and settings\All Users\Application Data\xymu.dll
c:\documents and settings\All Users\Application Data\ysarofuty.lib
c:\documents and settings\All Users\Documents\apuqufaboq.bin
c:\documents and settings\All Users\Documents\gobihy.sys
c:\documents and settings\All Users\Documents\hozaq.pif
c:\documents and settings\All Users\Documents\orik.vbs
c:\documents and settings\All Users\Documents\pagoge.scr
c:\documents and settings\All Users\Documents\ukyhigeto.exe
c:\documents and settings\All Users\Documents\ulog.inf
c:\documents and settings\Noah\Application Data\ahiqymu._sy
c:\documents and settings\Noah\Application Data\kuqoni.dll
c:\documents and settings\Noah\Application Data\Microsoft\Internet Explorer\Quick Launch\PC_Antispyware2010.lnk
c:\documents and settings\Noah\Application Data\mogu._dl
c:\documents and settings\Noah\Application Data\ohowy.sys
c:\documents and settings\Noah\Application Data\ubypy.bin
c:\documents and settings\Noah\Application Data\vytipap.ban
c:\documents and settings\Noah\Application Data\vyvor.vbs
c:\documents and settings\Noah\Application Data\wobog.exe
c:\documents and settings\Noah\Application Data\xazowi.vbs
c:\documents and settings\Noah\Application Data\xuwodufi._sy
c:\documents and settings\Noah\Application Data\ywumezux.inf
c:\documents and settings\Noah\Cookies\aheqejyhaq.dll
c:\documents and settings\Noah\Cookies\jyfukupe.com
c:\documents and settings\Noah\Cookies\odibe.reg
c:\documents and settings\Noah\Cookies\qebukur.bin
c:\documents and settings\Noah\Cookies\zekylifi.vbs
c:\documents and settings\Noah\Desktop\PC_Antispyware2010.lnk
c:\documents and settings\Noah\Local Settings\Application Data\acixyfi.ban
c:\documents and settings\Noah\Local Settings\Application Data\agyqegum.dll
c:\documents and settings\Noah\Local Settings\Application Data\azuqidubec.bat
c:\documents and settings\Noah\Local Settings\Application Data\humiga.inf
c:\documents and settings\Noah\Local Settings\Application Data\lydyvu.com
c:\documents and settings\Noah\Local Settings\Application Data\myfa.dll
c:\documents and settings\Noah\Local Settings\Application Data\palepacyku.scr
c:\documents and settings\Noah\Local Settings\Application Data\qakutupo.dll
c:\documents and settings\Noah\Local Settings\Application Data\sodacim._dl
c:\documents and settings\Noah\Local Settings\Application Data\tady.ban
c:\documents and settings\Noah\Local Settings\Application Data\uloz._dl
c:\documents and settings\Noah\Local Settings\Application Data\vumozuf.inf
c:\documents and settings\Noah\Local Settings\Application Data\wahokubopo.ban
c:\documents and settings\Noah\Local Settings\Application Data\xetekaby.exe
c:\documents and settings\Noah\Local Settings\Application Data\ycyjihexo.exe
c:\documents and settings\Noah\Local Settings\Temporary Internet Files\cobojagodu.com
c:\documents and settings\Noah\Local Settings\Temporary Internet Files\mufi.dll
c:\documents and settings\Noah\Local Settings\Temporary Internet Files\nagub.dll
c:\documents and settings\Noah\Local Settings\Temporary Internet Files\ozimuqiko.scr
c:\documents and settings\Noah\Local Settings\Temporary Internet Files\qodysymo.com
c:\documents and settings\Noah\Local Settings\Temporary Internet Files\ubybylifum.bin
c:\documents and settings\Noah\Start Menu\Programs\PC_Antispyware2010
c:\documents and settings\Noah\Start Menu\Programs\PC_Antispyware2010\PC_Antispyware2010.lnk
c:\documents and settings\Noah\Start Menu\Programs\PC_Antispyware2010\Uninstall.lnk
c:\program files\Common Files\acyfurohe.pif
c:\program files\Common Files\arotohet.dl
c:\program files\Common Files\bufumybe.dll
c:\program files\Common Files\hocazexeje.scr
c:\program files\Common Files\jitizo._dl
c:\program files\Common Files\kanymi.bat
c:\program files\Common Files\keha.reg
c:\program files\Common Files\myly.bat
c:\program files\Common Files\notok.reg
c:\program files\Common Files\ryjiloqy.bin
c:\program files\Common Files\sikozad.pif
c:\program files\Common Files\wuzafy.inf
c:\program files\Common Files\ydeg.scr
c:\program files\PC_Antispyware2010
c:\program files\PC_Antispyware2010\AVEngn.dll
c:\program files\PC_Antispyware2010\data\daily.cvd
c:\program files\PC_Antispyware2010\htmlayout.dll
c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcm80.dll
c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcp80.dll
c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcr80.dll
c:\program files\PC_Antispyware2010\PC_Antispyware2010.cfg
c:\program files\PC_Antispyware2010\PC_Antispyware2010.exe
c:\program files\PC_Antispyware2010\pthreadVC2.dll
c:\program files\PC_Antispyware2010\Uninstall.exe
c:\program files\PC_Antispyware2010\wscui.cpl
c:\windows\akefa.bin
c:\windows\braviax.exe
c:\windows\bufy.reg
c:\windows\ceduqahov.scr
c:\windows\cinypylo.vbs
c:\windows\cru629.dat
c:\windows\dabyroj._dl
c:\windows\delo.sys
c:\windows\ezumiwibe.exe
c:\windows\Fonts\WPHV07NB.TTF
c:\windows\fydiv.vbs
c:\windows\Installer\4adc4.msi
c:\windows\Installer\8b39dc.msi
c:\windows\kb913800.exe
c:\windows\kutaji.scr
c:\windows\ladabuf._dl
c:\windows\qexezi.dll
c:\windows\rogyj.dll
c:\windows\system32\_scui.cpl
c:\windows\system32\~.exe
c:\windows\system32\braviax.exe
c:\windows\system32\cru629.dat
c:\windows\system32\dllcache\beep.sys
c:\windows\system32\drivers\UACmnmyxidwqp.sys
c:\windows\system32\ibir.ban
c:\windows\system32\leku._dl
c:\windows\system32\okiqi.sys
c:\windows\system32\ruvyqulywi._dl
c:\windows\system32\tajf83ikdmf.dll
c:\windows\system32\UACbwuyfvalkl.dll
c:\windows\system32\UACdyqmehqofr.dat
c:\windows\system32\uacinit.dll
c:\windows\system32\UACmylvrbjerr.dll
c:\windows\system32\UACqfulkyxmbc.dll
c:\windows\system32\UACsngkdpkbbv.dll
c:\windows\system32\wisdstr.exe
c:\windows\system32\xewogy._dl
c:\windows\tazecyliru.bat
c:\windows\tupep.ban
c:\windows\uwosu.exe
c:\windows\vini.inf
c:\windows\xiwu.dl
C:\yihw.exe
c:\recycler\S-1-5-21-448695876-2246867838-327816092-1006 . . . . failed to delete

Infected copy of c:\windows\system32\drivers\beep.sys was found and disinfected
Restored copy from - c:\i386\beep.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_UACd.sys
——-\Legacy_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-30 )))))))))))))))))))))))))))))))
.

2009-08-29 15:45 . 2009-08-29 15:45 13010 —-a-w- c:\windows\feqapiru.com
2009-08-29 15:45 . 2009-08-29 15:45 12789 —-a-w- c:\windows\ucur.com
2009-08-29 12:44 . 2009-08-29 12:44 ——– d—–w- c:\program files\ERUNT
2009-08-29 01:15 . 2009-08-29 01:15 10281 —-a-w- c:\windows\feno.com
2009-08-29 01:15 . 2009-08-29 01:15 10232 —-a-w- c:\program files\Common Files\omewirodo.dat
2009-08-29 01:05 . 2009-08-29 01:05 42496 —-a-w- C:\dvrdiqbe.exe
2009-08-28 18:56 . 2009-08-28 18:56 12111 —-a-w- c:\windows\ibebepif.com
2009-08-28 18:56 . 2009-08-28 18:56 13230 —-a-w- c:\windows\system32\uhigo.com
2009-08-27 11:15 . 2009-08-27 11:15 ——– d—–w- c:\documents and settings\Administrator\Application Data\AdobeUM
2009-08-27 11:15 . 2009-08-27 11:15 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2009-08-26 16:59 . 2009-08-26 16:59 ——– d—–w- c:\documents and settings\Noah\Application Data\MalwareRemovalBot
2009-08-22 11:52 . 2009-08-22 15:42 31232 —-a-w- c:\windows\system32\wingenocx.dll
2009-08-22 11:40 . 2009-08-22 11:40 17753 —-a-w- c:\windows\system32\atybiped.com
2009-08-22 11:40 . 2009-08-22 11:40 16613 —-a-w- c:\windows\pyzimopuqi.com
2009-08-22 11:40 . 2009-08-22 11:40 15645 —-a-w- c:\windows\jovajir.dat
2009-08-22 11:33 . 2009-08-22 11:33 19968 —-a-w- c:\windows\system32\UACouoiemlqrx.dll
2009-08-21 00:53 . 2009-08-21 00:53 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment
2009-08-18 12:34 . 2009-08-19 15:06 ——– d—–w- c:\program files\GodsWar Online
2009-08-17 13:31 . 2009-08-17 13:31 ——– d—–w- c:\documents and settings\Noah\Local Settings\Application Data\DNA
2009-08-17 13:31 . 2009-08-26 16:54 ——– d—–w- c:\documents and settings\Noah\Application Data\DNA
2009-08-17 13:31 . 2009-08-26 16:53 ——– d—–w- c:\program files\DNA
2009-08-12 16:06 . 2009-07-10 13:27 1315328 ——w- c:\windows\system32\dllcache\msoe.dll
2009-08-09 00:08 . 2009-08-09 00:08 888984 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-08-08 18:01 . 2009-08-08 18:10 ——– d—–w- c:\documents and settings\Noah\Local Settings\Application Data\Wizards_of_the_Coast
2009-08-08 17:53 . 2009-08-08 17:53 ——– d—–w- c:\windows\system32\XPSViewer
2009-08-08 17:53 . 2009-08-08 17:53 ——– d—–w- c:\program files\MSBuild
2009-08-08 17:53 . 2009-08-08 17:53 ——– d—–w- c:\program files\Reference Assemblies
2009-08-08 17:52 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-08 17:52 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-08-08 17:52 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-08 17:52 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-08-08 17:52 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-08 17:52 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-08-08 17:52 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-08 17:52 . 2009-08-08 17:52 ——– d—–w- C:\ca9890ad2b50aea30f5751
2009-08-08 16:58 . 2009-02-07 21:51 993792 —-a-w- c:\documents and settings\Noah\WLL.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-30 02:19 . 2009-02-17 00:11 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-08-29 15:45 . 2009-08-29 15:45 16236 —-a-w- c:\documents and settings\All Users\Application Data\huwek.dat
2009-08-29 01:15 . 2009-08-29 01:15 17178 —-a-w- c:\documents and settings\Noah\Application Data\jacype.dat
2009-08-28 18:56 . 2009-08-28 18:56 12338 —-a-w- c:\program files\Common Files\ywak._sy
2009-08-27 22:51 . 2009-08-27 22:51 12671 —-a-w- c:\program files\Common Files\iqudakoti._sy
2009-08-27 10:27 . 2006-03-09 04:45 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-26 16:42 . 2009-02-22 15:58 ——– d—–w- c:\documents and settings\Noah\Application Data\skypePM
2009-08-26 16:42 . 2009-02-22 15:55 ——– d—–w- c:\documents and settings\Noah\Application Data\Skype
2009-08-21 00:53 . 2009-03-24 19:03 ——– d—–w- c:\program files\World of Warcraft
2009-08-20 18:59 . 2008-07-03 20:39 34 —-a-w- c:\documents and settings\Noah\jagex_runescape_preferences.dat
2009-08-11 20:38 . 2006-06-08 23:34 8456 —-a-w- c:\windows\system32\KGyGaAvL.sys
2009-08-11 20:38 . 2006-06-08 23:34 152 –sh–r- c:\windows\system32\589C2B60CB.sys
2009-08-09 12:50 . 2008-07-16 10:38 ——– d—–w- c:\documents and settings\All Users\Application Data\WildTangent
2009-08-09 12:50 . 2008-07-16 10:36 ——– d—–w- c:\program files\WildGames
2009-08-08 17:58 . 2006-04-22 21:10 44056 —-a-w- c:\documents and settings\Noah\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-08 17:34 . 2007-11-23 17:06 ——– d—–w- c:\program files\Wizards of the Coast
2009-08-05 09:01 . 2005-08-16 10:18 204800 ——w- c:\windows\system32\mswebdvd.dll
2009-07-31 23:11 . 2009-01-22 15:20 ——– d—–w- c:\documents and settings\Noah\Application Data\Story Wizard
2009-07-25 11:19 . 2007-12-25 12:36 524 —-a-w- c:\windows\eReg.dat
2009-07-17 19:01 . 2005-08-16 10:18 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-13 14:08 . 2005-08-16 10:19 286720 ——w- c:\windows\system32\wmpdxm.dll
2009-07-07 14:10 . 2009-07-07 14:10 8854 -c–a-r- c:\documents and settings\Noah\Application Data\Microsoft\Installer\{D98C9637-93DA-44DB-B73A-B11A1192AB26}\NewShortcut1_D98C963793DA44DBB73AB11A1192AB26.exe
2009-07-07 14:10 . 2009-07-07 14:10 45056 -c–a-r- c:\documents and settings\Noah\Application Data\Microsoft\Installer\{D98C9637-93DA-44DB-B73A-B11A1192AB26}\GameShadow.exe1_D9316813509243FDA4C292F72F483E61.exe
2009-07-07 14:10 . 2009-07-07 14:10 45056 -c–a-r- c:\documents and settings\Noah\Application Data\Microsoft\Installer\{D98C9637-93DA-44DB-B73A-B11A1192AB26}\GameShadow.exe_D9316813509243FDA4C292F72F483E61.exe
2009-07-07 14:10 . 2009-07-07 14:10 40960 -c–a-r- c:\documents and settings\Noah\Application Data\Microsoft\Installer\{D98C9637-93DA-44DB-B73A-B11A1192AB26}\GSDR.exe_D9316813509243FDA4C292F72F483E61.exe
2009-07-07 14:10 . 2009-07-07 14:10 10134 -c–a-r- c:\documents and settings\Noah\Application Data\Microsoft\Installer\{D98C9637-93DA-44DB-B73A-B11A1192AB26}\ARPPRODUCTICON.exe
2009-07-07 14:10 . 2009-07-07 14:10 ——– d—–w- c:\program files\GameShadow
2009-06-29 16:12 . 2005-08-16 10:18 827392 —-a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2005-08-16 10:18 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2005-08-16 10:18 17408 —-a-w- c:\windows\system32\corpol.dll
2009-06-16 14:36 . 2005-08-16 10:18 119808 ——w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2005-08-16 10:18 81920 ——w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2005-08-16 10:18 80896 ——w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2005-08-16 10:18 76288 ——w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2005-08-16 10:18 84992 ——w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2005-08-16 10:37 2066432 ——w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2005-08-16 10:18 132096 ——w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2005-08-16 10:18 1291264 —-a-w- c:\windows\system32\quartz.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-18 68856]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Noah^Start Menu^Programs^Startup^Registration Silent Hunter III.LNK]
path=c:\documents and settings\Noah\Start Menu\Programs\Startup\Registration Silent Hunter III.LNK
backup=c:\windows\pss\Registration Silent Hunter III.LNKStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Noah^Start Menu^Programs^Startup^Start SMS Service.lnk]
path=c:\documents and settings\Noah\Start Menu\Programs\Startup\Start SMS Service.lnk
backup=c:\windows\pss\Start SMS Service.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Noah^Start Menu^Programs^Startup^Xfire.lnk]
path=c:\documents and settings\Noah\Start Menu\Programs\Startup\Xfire.lnk
backup=c:\windows\pss\Xfire.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"UserAccess7"=2 (0x2)
"SMS_v3_2_0"=2 (0x2)
"NetSvc"=3 (0x3)
"iPod Service"=3 (0x3)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"gusvc"=3 (0x3)
"DSBrokerService"=3 (0x3)
"CCALib8"=2 (0x2)
"avg8wd"=2 (0x2)
"avg8emc"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Java\\jre1.5.0_11\\bin\\java.exe"=
"c:\\Program Files\\Rosetta Stone\\SMS v3.2.0hs\\server.exe"=
"c:\\Program Files\\Rosetta Stone\\SMS v3.2.0hs\\admin.exe"=
"c:\\Program Files\\Rosetta Stone\\RS2.2.1.0Asms\\Rosetta Stone.exe"=
"c:\\Program Files\\Rosetta Stone\\RS2.2.1.0Asms\\Discover.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

S4 SMS_v3_2_0;SMS_v3_2_0;c:\program files\Rosetta Stone\SMS v3.2.0hs\wrapper.exe [7/12/2007 3:42 PM 204800]
.
Contents of the 'Scheduled Tasks' folder

2009-08-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-07-25 17:15]
.
- - - - ORPHANS REMOVED - - - -

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKLM-Run-PC Antispyware 2010 - c:\program files\PC_Antispyware2010\PC_Antispyware2010.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
mStart Page = hxxp://www.google.com
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: musicmatch.com\online
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-29 22:49
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(1388)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
.
———————— Other Running Processes ————————
.
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-08-30 22:54 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-30 02:54

Pre-Run: 36,068,052,992 bytes free
Post-Run: 37,715,341,312 bytes free

337 — E O F — 2009-08-28 19:38


thanks ever so much. You are the greatest. I will be telling everyone about you. Thanks again :woot:
Not done yet,

1) CFScript

Open notepad and copy/paste the text in the quotebox below into it:

http://forums.whatthetech.com/PC_Antispyware_2010_t106549.html

Collect::
c:\windows\feqapiru.com
c:\windows\ucur.com
c:\windows\feno.com
c:\program files\Common Files\omewirodo.dat
C:\dvrdiqbe.exe
c:\windows\ibebepif.com
c:\windows\system32\uhigo.com
c:\windows\system32\wingenocx.dll
c:\windows\system32\atybiped.com
c:\windows\pyzimopuqi.com
c:\windows\jovajir.dat
c:\windows\system32\UACouoiemlqrx.dll

File::
c:\program files\Common Files\ywak._sy
c:\program files\Common Files\iqudakoti._sy

Folder::
c:\documents and settings\Noah\Application Data\MalwareRemovalBot

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\DNA\\btdna.exe"=-


Save this as CFScript.txt


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you. Post that log in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.

2) OTL

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

In your reply I would like to see copied and pasted,

1) ComboFix log
2) OTListIt.txt
3) Extras.txt
I'm Back. Here is the info.

1. ComboFix Log

ComboFix 09-08-30.01 - Noah 08/30/2009 21:30.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.630 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Noah\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

FILE ::
"c:\program files\Common Files\iqudakoti._sy"
"c:\program files\Common Files\ywak._sy"

file zipped: c:\program files\Common Files\omewirodo.dat
file zipped: c:\windows\feno.com
file zipped: c:\windows\feqapiru.com
file zipped: c:\windows\ibebepif.com
file zipped: c:\windows\jovajir.dat
file zipped: c:\windows\pyzimopuqi.com
file zipped: c:\windows\system32\atybiped.com
file zipped: c:\windows\system32\uhigo.com
file zipped: c:\windows\ucur.com
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Common Files\iqudakoti._sy
c:\program files\Common Files\omewirodo.dat
c:\program files\Common Files\ywak._sy
c:\windows\feno.com
c:\windows\feqapiru.com
c:\windows\ibebepif.com
c:\windows\jovajir.dat
c:\windows\pyzimopuqi.com
c:\windows\system32\atybiped.com
c:\windows\system32\uhigo.com
c:\windows\ucur.com

.
((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-31 )))))))))))))))))))))))))))))))
.

2009-08-30 13:18 . 2009-08-30 14:16 ——– d–h–w- C:\$AVG8.VAULT$
2009-08-30 03:55 . 2009-07-24 13:55 1090816 —-a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-08-30 03:54 . 2009-08-30 03:54 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-08-30 03:54 . 2009-08-30 03:54 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-30 03:54 . 2009-08-30 03:54 335240 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-30 03:54 . 2009-08-30 03:54 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-30 03:53 . 2009-08-30 22:25 ——– d—–w- c:\windows\system32\drivers\Avg
2009-08-30 03:53 . 2009-08-30 03:55 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-08-30 03:46 . 2009-08-30 03:46 ——– d—–w- c:\documents and settings\Noah\Application Data\AVG8
2009-08-30 03:02 . 2009-08-30 03:02 ——– d—–w- c:\documents and settings\Noah\Application Data\Malwarebytes
2009-08-30 03:02 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-30 03:02 . 2009-08-30 03:02 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-30 03:02 . 2009-08-30 03:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-30 03:02 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-29 12:44 . 2009-08-29 12:44 ——– d—–w- c:\program files\ERUNT
2009-08-27 11:15 . 2009-08-27 11:15 ——– d—–w- c:\documents and settings\Administrator\Application Data\AdobeUM
2009-08-27 11:15 . 2009-08-27 11:15 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2009-08-21 00:53 . 2009-08-21 00:53 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment
2009-08-18 12:34 . 2009-08-19 15:06 ——– d—–w- c:\program files\GodsWar Online
2009-08-17 13:31 . 2009-08-17 13:31 ——– d—–w- c:\documents and settings\Noah\Local Settings\Application Data\DNA
2009-08-17 13:31 . 2009-08-26 16:54 ——– d—–w- c:\documents and settings\Noah\Application Data\DNA
2009-08-17 13:31 . 2009-08-26 16:53 ——– d—–w- c:\program files\DNA
2009-08-12 16:06 . 2009-07-10 13:27 1315328 ——w- c:\windows\system32\dllcache\msoe.dll
2009-08-09 00:08 . 2009-08-09 00:08 888984 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-08-08 18:01 . 2009-08-08 18:10 ——– d—–w- c:\documents and settings\Noah\Local Settings\Application Data\Wizards_of_the_Coast
2009-08-08 17:53 . 2009-08-08 17:53 ——– d—–w- c:\windows\system32\XPSViewer
2009-08-08 17:53 . 2009-08-08 17:53 ——– d—–w- c:\program files\MSBuild
2009-08-08 17:53 . 2009-08-08 17:53 ——– d—–w- c:\program files\Reference Assemblies
2009-08-08 17:52 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-08 17:52 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-08-08 17:52 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-08 17:52 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-08-08 17:52 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-08 17:52 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-08-08 17:52 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-08 17:52 . 2009-08-08 17:52 ——– d—–w- C:\ca9890ad2b50aea30f5751
2009-08-08 16:58 . 2009-02-07 21:51 993792 —-a-w- c:\documents and settings\Noah\WLL.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-30 23:08 . 2006-06-08 23:34 152 –sh–r- c:\windows\system32\589C2B60CB.sys
2009-08-30 23:08 . 2006-06-08 23:34 8352 —-a-w- c:\windows\system32\KGyGaAvL.sys
2009-08-30 03:53 . 2009-02-17 00:11 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-08-29 15:45 . 2009-08-29 15:45 16236 —-a-w- c:\documents and settings\All Users\Application Data\huwek.dat
2009-08-29 01:15 . 2009-08-29 01:15 17178 —-a-w- c:\documents and settings\Noah\Application Data\jacype.dat
2009-08-27 10:27 . 2006-03-09 04:45 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-26 16:42 . 2009-02-22 15:58 ——– d—–w- c:\documents and settings\Noah\Application Data\skypePM
2009-08-26 16:42 . 2009-02-22 15:55 ——– d—–w- c:\documents and settings\Noah\Application Data\Skype
2009-08-21 00:53 . 2009-03-24 19:03 ——– d—–w- c:\program files\World of Warcraft
2009-08-20 18:59 . 2008-07-03 20:39 34 —-a-w- c:\documents and settings\Noah\jagex_runescape_preferences.dat
2009-08-09 12:50 . 2008-07-16 10:38 ——– d—–w- c:\documents and settings\All Users\Application Data\WildTangent
2009-08-09 12:50 . 2008-07-16 10:36 ——– d—–w- c:\program files\WildGames
2009-08-08 17:58 . 2006-04-22 21:10 44056 —-a-w- c:\documents and settings\Noah\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-08 17:34 . 2007-11-23 17:06 ——– d—–w- c:\program files\Wizards of the Coast
2009-08-05 09:01 . 2005-08-16 10:18 204800 ——w- c:\windows\system32\mswebdvd.dll
2009-07-31 23:11 . 2009-01-22 15:20 ——– d—–w- c:\documents and settings\Noah\Application Data\Story Wizard
2009-07-25 11:19 . 2007-12-25 12:36 524 —-a-w- c:\windows\eReg.dat
2009-07-17 19:01 . 2005-08-16 10:18 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-13 14:08 . 2005-08-16 10:19 286720 ——w- c:\windows\system32\wmpdxm.dll
2009-07-07 14:10 . 2009-07-07 14:10 8854 -c–a-r- c:\documents and settings\Noah\Application Data\Microsoft\Installer\{D98C9637-93DA-44DB-B73A-B11A1192AB26}\NewShortcut1_D98C963793DA44DBB73AB11A1192AB26.exe
2009-07-07 14:10 . 2009-07-07 14:10 45056 -c–a-r- c:\documents and settings\Noah\Application Data\Microsoft\Installer\{D98C9637-93DA-44DB-B73A-B11A1192AB26}\GameShadow.exe1_D9316813509243FDA4C292F72F483E61.exe
2009-07-07 14:10 . 2009-07-07 14:10 45056 -c–a-r- c:\documents and settings\Noah\Application Data\Microsoft\Installer\{D98C9637-93DA-44DB-B73A-B11A1192AB26}\GameShadow.exe_D9316813509243FDA4C292F72F483E61.exe
2009-07-07 14:10 . 2009-07-07 14:10 40960 -c–a-r- c:\documents and settings\Noah\Application Data\Microsoft\Installer\{D98C9637-93DA-44DB-B73A-B11A1192AB26}\GSDR.exe_D9316813509243FDA4C292F72F483E61.exe
2009-07-07 14:10 . 2009-07-07 14:10 10134 -c–a-r- c:\documents and settings\Noah\Application Data\Microsoft\Installer\{D98C9637-93DA-44DB-B73A-B11A1192AB26}\ARPPRODUCTICON.exe
2009-07-07 14:10 . 2009-07-07 14:10 ——– d—–w- c:\program files\GameShadow
2009-06-29 16:12 . 2005-08-16 10:18 827392 ——w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2005-08-16 10:18 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2005-08-16 10:18 17408 —-a-w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2005-08-16 10:18 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2005-08-16 10:18 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2005-08-16 10:18 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2005-08-16 10:18 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2005-08-16 10:18 730112 ——w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2005-08-16 10:18 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2005-08-16 10:18 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2005-08-16 10:18 119808 ——w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2005-08-16 10:18 81920 ——w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2005-08-16 10:18 80896 ——w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2005-08-16 10:18 76288 ——w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2005-08-16 10:18 84992 ——w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2005-08-16 10:37 2066432 ——w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2005-08-16 10:18 132096 ——w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2005-08-16 10:18 1291264 —-a-w- c:\windows\system32\quartz.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-08-30_02.49.14 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-05-30 18:36 . 2008-07-08 13:02 17272 c:\windows\system32\spmsg.dll
- 2006-05-30 18:36 . 2009-05-26 11:40 17272 c:\windows\system32\spmsg.dll
+ 2009-06-25 08:25 . 2009-06-25 08:25 54272 c:\windows\system32\dllcache\wdigest.dll
- 2009-02-03 19:59 . 2009-02-03 19:59 56832 c:\windows\system32\dllcache\secur32.dll
+ 2009-02-03 19:59 . 2009-06-25 08:25 56832 c:\windows\system32\dllcache\secur32.dll
+ 2009-06-24 11:18 . 2009-06-24 11:18 92928 c:\windows\system32\dllcache\ksecdd.sys
+ 2008-12-05 06:54 . 2009-06-25 08:25 147456 c:\windows\system32\dllcache\schannel.dll
+ 2009-06-25 08:25 . 2009-06-25 08:25 136192 c:\windows\system32\dllcache\msv1_0.dll
+ 2009-04-16 23:49 . 2009-06-25 08:25 730112 c:\windows\system32\dllcache\lsasrv.dll
+ 2009-06-25 08:25 . 2009-06-25 08:25 301568 c:\windows\system32\dllcache\kerberos.dll
+ 2006-05-17 15:23 . 2008-03-20 22:06 1480232 c:\windows\system32\LegitCheckControl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 13:55 1090816 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-18 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-30 2007832]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-30 03:54 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Noah^Start Menu^Programs^Startup^Registration Silent Hunter III.LNK]
path=c:\documents and settings\Noah\Start Menu\Programs\Startup\Registration Silent Hunter III.LNK
backup=c:\windows\pss\Registration Silent Hunter III.LNKStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Noah^Start Menu^Programs^Startup^Start SMS Service.lnk]
path=c:\documents and settings\Noah\Start Menu\Programs\Startup\Start SMS Service.lnk
backup=c:\windows\pss\Start SMS Service.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Noah^Start Menu^Programs^Startup^Xfire.lnk]
path=c:\documents and settings\Noah\Start Menu\Programs\Startup\Xfire.lnk
backup=c:\windows\pss\Xfire.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"UserAccess7"=2 (0x2)
"SMS_v3_2_0"=2 (0x2)
"NetSvc"=3 (0x3)
"iPod Service"=3 (0x3)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"gusvc"=3 (0x3)
"DSBrokerService"=3 (0x3)
"CCALib8"=2 (0x2)
"avg8wd"=2 (0x2)
"avg8emc"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Java\\jre1.5.0_11\\bin\\java.exe"=
"c:\\Program Files\\Rosetta Stone\\SMS v3.2.0hs\\server.exe"=
"c:\\Program Files\\Rosetta Stone\\SMS v3.2.0hs\\admin.exe"=
"c:\\Program Files\\Rosetta Stone\\RS2.2.1.0Asms\\Rosetta Stone.exe"=
"c:\\Program Files\\Rosetta Stone\\RS2.2.1.0Asms\\Discover.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/29/2009 11:54 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8/29/2009 11:54 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [8/29/2009 11:53 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/29/2009 11:53 PM 297752]
S4 SMS_v3_2_0;SMS_v3_2_0;c:\program files\Rosetta Stone\SMS v3.2.0hs\wrapper.exe [7/12/2007 3:42 PM 204800]
.
Contents of the 'Scheduled Tasks' folder

2009-08-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-07-25 17:15]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.google.com
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: musicmatch.com\online
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-30 21:34
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-08-31 21:36
ComboFix-quarantined-files.txt 2009-08-31 01:36
ComboFix2.txt 2009-08-30 02:54

Pre-Run: 31,073,828,864 bytes free
Post-Run: 31,212,924,928 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

239 — E O F — 2009-08-31 00:27
Upload was successful

2. OTListlt.txt

OTL logfile created on: 8/30/2009 9:43:33 PM - Run 1
OTL by OldTimer - Version 3.0.10.7 Folder = C:\Documents and Settings\Noah\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.07 Mb Total Physical Memory | 548.07 Mb Available Physical Memory | 53.62% Memory free
2.40 Gb Paging File | 2.09 Gb Available in Paging File | 87.14% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.79 Gb Total Space | 29.10 Gb Free Space | 41.69% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JACKIEANDNOAH
Current User Name: Noah
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\System32\wscntfy.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Noah\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Disabled | Stopped]) – C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (CCALib8 [Disabled | Stopped]) – C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DSBrokerService [Disabled | Stopped]) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (ehRecvr [Auto | Running]) – C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [Auto | Running]) – C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gusvc [Disabled | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [Disabled | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (McrdSvc [Auto | Running]) – C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
SRV - (MHN [On_Demand | Stopped]) – C:\WINDOWS\System32\mhn.dll (Microsoft Corporation)
SRV - (NetSvc [Disabled | Stopped]) – C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe (Intel® Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (SMS_v3_2_0 [Disabled | Stopped]) – C:\Program Files\Rosetta Stone\SMS v3.2.0hs\wrapper.exe ()
SRV - (UMWdf [On_Demand | Stopped]) – C:\WINDOWS\System32\wdfmgr.exe (Microsoft Corporation)
SRV - (UserAccess7 [Disabled | Stopped]) – C:\WINDOWS\System32\UAService7.exe ()

========== Driver Services (SafeList) ==========

DRV - (AliIde [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (ASCTRM [Auto | Running]) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (catchme [On_Demand | Running]) – File not found
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (DLABOIOM [Auto | Running]) – C:\WINDOWS\System32\DLA\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLACDBHM [System | Running]) – C:\WINDOWS\System32\Drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLADResN [Auto | Running]) – C:\WINDOWS\System32\DLA\DLADResN.SYS (Sonic Solutions)
DRV - (DLAIFS_M [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLAOPIOM [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLARTL_N [System | Running]) – C:\WINDOWS\System32\Drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (DLAUDFAM [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M [Auto | Running]) – C:\WINDOWS\System32\DLA\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DRVMCDB [Boot | Running]) – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (DRVNDDM [Auto | Running]) – C:\WINDOWS\System32\Drivers\DRVNDDM.SYS (Sonic Solutions)
DRV - (DSproct [On_Demand | Stopped]) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (dsunidrv [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (E100B [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (HSFHWBS2 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSF_DP [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (MODEMCSA [On_Demand | Running]) – C:\WINDOWS\System32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (RT2500 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\RT2500.sys (Ralink Technology Inc.)
DRV - (Secdrv [Auto | Running]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sfdrv01 [Boot | Running]) – C:\WINDOWS\System32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfhlp02 [Boot | Running]) – C:\WINDOWS\System32\drivers\sfhlp02.sys (Protection Technology)
DRV - (sfsync02 [Boot | Running]) – C:\WINDOWS\System32\drivers\sfsync02.sys (Protection Technology)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (STHDA [On_Demand | Running]) – C:\WINDOWS\System32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.google.com/ig/dell?hl=en&client=dell
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.com/ig/dell?hl=en&client=dell

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/08/08 13:54:49 | 00,000,000 | —D | M]


O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O15 - HKLM\..Trusted Domains: 2 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://javadl-esd.sun.com/update/1.6.0/jin…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 06:43:04 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/08/30 21:42:55 | 00,514,048 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Noah\Desktop\OTL.exe
[2009/08/30 21:37:16 | 00,000,000 | —D | C] – C:\WINDOWS\temp
[2009/08/30 21:23:39 | 00,000,209 | —- | C] () – C:\Boot.bak
[2009/08/30 21:23:34 | 00,260,272 | —- | C] () – C:\cmldr
[2009/08/30 21:23:31 | 00,000,000 | RHSD | C] – C:\cmdcons
[2009/08/30 21:22:28 | 00,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2009/08/30 21:15:37 | 03,188,306 | R— | C] () – C:\Documents and Settings\Noah\Desktop\ComboFix.exe
[2009/08/30 18:23:53 | 00,000,000 | —D | C] – C:\Documents and Settings\Noah\Desktop\Wishes
[2009/08/30 09:18:06 | 00,000,000 | -H-D | C] – C:\$AVG8.VAULT$
[2009/08/29 23:54:10 | 00,108,552 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/08/29 23:54:10 | 00,011,952 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/08/29 23:54:10 | 00,001,507 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/08/29 23:54:04 | 00,335,240 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/08/29 23:54:02 | 00,027,784 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/08/29 23:53:49 | 40,319,333 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/08/29 23:53:48 | 00,073,369 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/08/29 23:53:46 | 00,463,779 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/08/29 23:53:44 | 06,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/08/29 23:53:44 | 00,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2009/08/29 23:53:43 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/08/29 23:46:49 | 00,000,000 | —D | C] – C:\Documents and Settings\Noah\Application Data\AVG8
[2009/08/29 23:02:26 | 00,000,000 | —D | C] – C:\Documents and Settings\Noah\Application Data\Malwarebytes
[2009/08/29 23:02:25 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/29 23:02:23 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/08/29 23:02:21 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/08/29 23:02:21 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/08/29 23:02:21 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/08/29 23:01:58 | 03,942,048 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Noah\Desktop\mbam-setup.exe
[2009/08/29 22:53:41 | 01,614,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\sfcfiles.dll
[2009/08/29 22:53:41 | 00,574,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntfs.sys
[2009/08/29 22:53:41 | 00,435,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntmssvc.dll
[2009/08/29 22:53:41 | 00,253,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\es.dll
[2009/08/29 22:53:41 | 00,249,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\tapisrv.dll
[2009/08/29 22:53:41 | 00,245,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mswsock.dll
[2009/08/29 22:53:41 | 00,198,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\netman.dll
[2009/08/29 22:53:41 | 00,192,512 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\schedsvc.dll
[2009/08/29 22:53:41 | 00,185,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\upnphost.dll
[2009/08/29 22:53:41 | 00,171,008 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\srsvc.dll
[2009/08/29 22:53:41 | 00,167,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\appmgmts.dll
[2009/08/29 22:53:41 | 00,142,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\aec.sys
[2009/08/29 22:53:41 | 00,135,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\shsvcs.dll
[2009/08/29 22:53:41 | 00,129,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\xmlprov.dll
[2009/08/29 22:53:41 | 00,088,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\rasauto.dll
[2009/08/29 22:53:41 | 00,077,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\browser.dll
[2009/08/29 22:53:41 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ssdpsrv.dll
[2009/08/29 22:53:41 | 00,062,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\cryptsvc.dll
[2009/08/29 22:53:41 | 00,059,904 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\regsvc.dll
[2009/08/29 22:53:41 | 00,025,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\MsPMSNSv.dll
[2009/08/29 22:53:41 | 00,019,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\linkinfo.dll
[2009/08/29 22:53:41 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wscntfy.exe
[2009/08/29 22:53:40 | 03,597,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mshtml.dll
[2009/08/29 22:53:40 | 02,145,280 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntoskrnl.exe
[2009/08/29 22:53:40 | 02,023,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntkrnlpa.exe
[2009/08/29 22:53:40 | 01,033,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\explorer.exe
[2009/08/29 22:53:40 | 00,989,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\kernel32.dll
[2009/08/29 22:53:40 | 00,927,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mfc40u.dll
[2009/08/29 22:53:40 | 00,827,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wininet.dll
[2009/08/29 22:53:40 | 00,792,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\comres.dll
[2009/08/29 22:53:40 | 00,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\comctl32.dll
[2009/08/29 22:53:40 | 00,578,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\user32.dll
[2009/08/29 22:53:40 | 00,507,904 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\winlogon.exe
[2009/08/29 22:53:40 | 00,409,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\qmgr.dll
[2009/08/29 22:53:40 | 00,407,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\netlogon.dll
[2009/08/29 22:53:40 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\rpcss.dll
[2009/08/29 22:53:40 | 00,361,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\tcpip.sys
[2009/08/29 22:53:40 | 00,295,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\termsrv.dll
[2009/08/29 22:53:40 | 00,182,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ndis.sys
[2009/08/29 22:53:40 | 00,181,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\scecli.dll
[2009/08/29 22:53:40 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\services.exe
[2009/08/29 22:53:40 | 00,110,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\imm32.dll
[2009/08/29 22:53:40 | 00,082,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ws2_32.dll
[2009/08/29 22:53:40 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\spoolsv.exe
[2009/08/29 22:53:40 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\eventlog.dll
[2009/08/29 22:53:40 | 00,051,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wuauclt.exe
[2009/08/29 22:53:40 | 00,036,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ip6fw.sys
[2009/08/29 22:53:40 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\msgsvc.dll
[2009/08/29 22:53:40 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\userinit.exe
[2009/08/29 22:53:40 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\kbdclass.sys
[2009/08/29 22:53:40 | 00,022,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\lpk.dll
[2009/08/29 22:53:40 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\powrprof.dll
[2009/08/29 22:53:40 | 00,015,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ctfmon.exe
[2009/08/29 22:53:40 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\svchost.exe
[2009/08/29 22:53:40 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\asyncmac.sys
[2009/08/29 22:53:40 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\lsass.exe
[2009/08/29 22:53:40 | 00,011,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\acpiec.sys
[2009/08/29 22:53:40 | 00,005,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\sfc.dll
[2009/08/29 22:53:40 | 00,004,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\beep.sys
[2009/08/29 22:53:40 | 00,002,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\null.sys
[2009/08/29 22:53:40 | 00,000,000 | —D | C] – C:\WINDOWS\System32\dllcache\cache
[2009/08/29 22:27:19 | 00,229,376 | —- | C] () – C:\WINDOWS\PEV.exe
[2009/08/29 22:27:19 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/08/29 22:27:19 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/08/29 22:27:19 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/08/29 22:27:19 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/08/29 22:27:19 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/08/29 22:27:19 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/08/29 22:26:23 | 00,000,000 | —D | C] – C:\Qoobox
[2009/08/29 11:45:50 | 00,016,236 | —- | C] () – C:\Documents and Settings\All Users\Application Data\huwek.dat
[2009/08/29 08:45:02 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/08/29 08:44:40 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/08/29 08:02:45 | 00,019,089 | —- | C] () – C:\WINDOWS\System32\lazateq._sy
[2009/08/28 21:15:47 | 00,019,775 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ygoxazyzez.db
[2009/08/28 21:15:47 | 00,019,359 | —- | C] () – C:\WINDOWS\ucalozanen.db
[2009/08/28 21:15:47 | 00,017,178 | —- | C] () – C:\Documents and Settings\Noah\Application Data\jacype.dat
[2009/08/28 20:33:40 | 10,717,96224 | -HS- | C] () – C:\hiberfil.sys
[2009/08/28 14:56:48 | 00,015,200 | —- | C] () – C:\Documents and Settings\All Users\Application Data\munivujydy.db
[2009/08/28 14:56:48 | 00,011,246 | —- | C] () – C:\WINDOWS\bexop.lib
[2009/08/27 18:51:19 | 00,019,443 | —- | C] () – C:\WINDOWS\ecajoliza.lib
[2009/08/27 18:51:19 | 00,017,889 | —- | C] () – C:\Documents and Settings\Noah\Local Settings\Application Data\suvenidoly.db
[2009/08/27 18:51:19 | 00,016,719 | —- | C] () – C:\Documents and Settings\All Users\Documents\hede._sy
[2009/08/27 18:51:19 | 00,015,166 | —- | C] () – C:\Documents and Settings\All Users\Documents\gokywewyl.lib
[2009/08/27 18:51:19 | 00,011,864 | —- | C] () – C:\WINDOWS\lewyb._sy
[2009/08/27 18:51:19 | 00,011,186 | —- | C] () – C:\WINDOWS\System32\vofokyru.lib
[2009/08/27 13:48:43 | 03,942,048 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Noah\My Documents\mbam-setup.exe
[2009/08/22 07:40:42 | 00,017,582 | —- | C] () – C:\WINDOWS\System32\usiji.db
[2009/08/22 07:40:42 | 00,011,728 | —- | C] () – C:\Documents and Settings\Noah\Local Settings\Application Data\ugic.lib
[2009/08/22 07:30:03 | 00,000,002 | -HS- | C] () – C:\-462040451
[2009/08/20 20:53:05 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Blizzard Entertainment
[2009/08/18 08:36:40 | 00,000,712 | —- | C] () – C:\Documents and Settings\Noah\Desktop\GodsWar Online.lnk
[2009/08/18 08:34:46 | 00,000,000 | —D | C] – C:\Program Files\GodsWar Online
[2009/08/18 07:48:58 | 15,939,0500 | —- | C] (Skyunion(IGG), Joyconnect Studio ) – C:\Documents and Settings\Noah\Desktop\gw_setup_1.0.242.exe
[2009/08/17 09:31:45 | 00,000,000 | —D | C] – C:\Documents and Settings\Noah\Local Settings\Application Data\DNA
[2009/08/17 09:31:44 | 00,000,000 | —D | C] – C:\Program Files\DNA
[2009/08/17 09:31:44 | 00,000,000 | —D | C] – C:\Documents and Settings\Noah\Application Data\DNA
[2009/08/12 12:06:30 | 00,128,512 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dhtmled.ocx
[2009/08/12 12:06:17 | 01,315,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msoe.dll
[2009/08/09 09:46:04 | 01,089,593 | —- | C] () – C:\WINDOWS\System32\dllcache\ntprint.cat
[2009/08/08 14:01:49 | 00,000,000 | —D | C] – C:\Documents and Settings\Noah\Local Settings\Application Data\Wizards_of_the_Coast
[2009/08/08 13:53:30 | 00,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2009/08/08 13:53:24 | 00,000,000 | —D | C] – C:\Program Files\MSBuild
[2009/08/08 13:53:13 | 00,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2009/08/08 13:52:12 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2009/08/08 13:52:12 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2009/08/08 13:52:12 | 00,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2009/08/08 13:52:12 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsshhdr.dll
[2009/08/08 13:52:12 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2009/08/08 13:52:12 | 00,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2009/08/08 13:52:12 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2009/08/08 13:52:11 | 00,000,000 | —D | C] – C:\ca9890ad2b50aea30f5751
[2009/08/08 13:34:30 | 00,002,111 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Character Builder.lnk
[2009/08/08 13:34:19 | 00,000,000 | —D | C] – C:\Documents and Settings\Noah\My Documents\ddi
[2009/08/08 13:16:04 | 00,000,000 | —D | C] – C:\Documents and Settings\Noah\Desktop\WotC Games
[2007/09/22 14:12:20 | 00,000,254 | —- | C] () – C:\WINDOWS\System32\SunData.ini
[2007/09/22 14:09:35 | 00,000,128 | —- | C] () – C:\WINDOWS\TTL3.ini
[2007/09/07 17:40:30 | 00,000,032 | —- | C] () – C:\WINDOWS\CD_Start.INI
[2007/08/01 07:09:43 | 00,000,079 | —- | C] () – C:\WINDOWS\pccillin.ini
[2007/02/28 16:27:08 | 00,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/08/05 12:16:19 | 00,000,000 | —- | C] () – C:\WINDOWS\ka.ini
[2006/06/08 19:34:30 | 00,000,152 | RHS- | C] () – C:\WINDOWS\System32\589C2B60CB.sys
[2006/06/08 19:34:29 | 00,008,352 | —- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/03/09 00:59:00 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/03/09 00:55:34 | 00,000,126 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/03/09 00:23:48 | 00,000,200 | —- | C] () – C:\WINDOWS\System32\dlbcplc.ini
[2006/03/09 00:22:54 | 00,000,392 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/11/10 10:56:34 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/16 06:37:24 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/08/16 06:18:43 | 00,000,477 | —- | C] () – C:\WINDOWS\win.ini
[2005/08/16 06:18:41 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2005/08/05 16:01:54 | 00,239,104 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[1997/06/14 04:56:08 | 00,056,832 | —- | C] () – C:\WINDOWS\System32\iyvu9_32.dll

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/08/30 21:42:56 | 00,514,048 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Noah\Desktop\OTL.exe
[2009/08/30 21:36:39 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/08/30 21:34:39 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/08/30 21:23:39 | 00,000,279 | RHS- | M] () – C:\boot.ini
[2009/08/30 21:15:37 | 03,188,306 | R— | M] () – C:\Documents and Settings\Noah\Desktop\ComboFix.exe
[2009/08/30 21:10:08 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/08/30 21:09:31 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/08/30 21:09:29 | 10,717,96224 | -HS- | M] () – C:\hiberfil.sys
[2009/08/30 19:08:01 | 00,008,352 | —- | M] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2009/08/30 19:08:01 | 00,000,152 | RHS- | M] () – C:\WINDOWS\System32\589C2B60CB.sys
[2009/08/30 18:24:51 | 40,319,333 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/08/29 23:54:10 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/08/29 23:54:10 | 00,011,952 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/08/29 23:54:10 | 00,001,507 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/08/29 23:54:04 | 00,335,240 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/08/29 23:54:02 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/08/29 23:53:49 | 00,073,369 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/08/29 23:53:48 | 00,463,779 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/08/29 23:53:46 | 06,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/08/29 23:02:25 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/29 23:01:58 | 03,942,048 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Noah\Desktop\mbam-setup.exe
[2009/08/29 22:48:57 | 00,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/08/29 11:54:09 | 04,815,128 | -H– | M] () – C:\Documents and Settings\Noah\Local Settings\Application Data\IconCache.db
[2009/08/29 11:45:50 | 00,016,236 | —- | M] () – C:\Documents and Settings\All Users\Application Data\huwek.dat
[2009/08/29 10:08:00 | 00,000,477 | —- | M] () – C:\WINDOWS\win.ini
[2009/08/29 10:08:00 | 00,000,209 | —- | M] () – C:\Boot.bak
[2009/08/29 09:11:26 | 00,014,848 | —- | M] () – C:\Documents and Settings\Noah\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/29 08:02:45 | 00,019,089 | —- | M] () – C:\WINDOWS\System32\lazateq._sy
[2009/08/28 21:15:47 | 00,019,775 | —- | M] () – C:\Documents and Settings\All Users\Application Data\ygoxazyzez.db
[2009/08/28 21:15:47 | 00,019,359 | —- | M] () – C:\WINDOWS\ucalozanen.db
[2009/08/28 21:15:47 | 00,017,178 | —- | M] () – C:\Documents and Settings\Noah\Application Data\jacype.dat
[2009/08/28 21:05:37 | 00,000,002 | -HS- | M] () – C:\-462040451
[2009/08/28 15:38:54 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/08/28 14:56:48 | 00,015,200 | —- | M] () – C:\Documents and Settings\All Users\Application Data\munivujydy.db
[2009/08/28 14:56:48 | 00,011,246 | —- | M] () – C:\WINDOWS\bexop.lib
[2009/08/27 18:51:19 | 00,019,443 | —- | M] () – C:\WINDOWS\ecajoliza.lib
[2009/08/27 18:51:19 | 00,017,889 | —- | M] () – C:\Documents and Settings\Noah\Local Settings\Application Data\suvenidoly.db
[2009/08/27 18:51:19 | 00,016,719 | —- | M] () – C:\Documents and Settings\All Users\Documents\hede._sy
[2009/08/27 18:51:19 | 00,015,166 | —- | M] () – C:\Documents and Settings\All Users\Documents\gokywewyl.lib
[2009/08/27 18:51:19 | 00,011,864 | —- | M] () – C:\WINDOWS\lewyb._sy
[2009/08/27 18:51:19 | 00,011,186 | —- | M] () – C:\WINDOWS\System32\vofokyru.lib
[2009/08/26 13:19:00 | 03,942,048 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Noah\My Documents\mbam-setup.exe
[2009/08/23 03:09:13 | 00,229,376 | —- | M] () – C:\WINDOWS\PEV.exe
[2009/08/22 07:40:42 | 00,017,582 | —- | M] () – C:\WINDOWS\System32\usiji.db
[2009/08/22 07:40:42 | 00,011,728 | —- | M] () – C:\Documents and Settings\Noah\Local Settings\Application Data\ugic.lib
[2009/08/20 17:03:04 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/08/18 08:36:40 | 00,000,712 | —- | M] () – C:\Documents and Settings\Noah\Desktop\GodsWar Online.lnk
[2009/08/18 08:33:24 | 15,939,0500 | —- | M] (Skyunion(IGG), Joyconnect Studio ) – C:\Documents and Settings\Noah\Desktop\gw_setup_1.0.242.exe
[2009/08/08 20:06:36 | 00,503,304 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/08/08 20:06:36 | 00,442,466 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/08/08 20:06:36 | 00,071,732 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/08/08 13:58:03 | 00,044,056 | —- | M] () – C:\Documents and Settings\Noah\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/08/08 13:57:18 | 00,197,752 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/08/08 13:34:30 | 00,002,111 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Character Builder.lnk
[2009/08/05 05:01:48 | 00,204,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mswebdvd.dll
[2009/08/05 05:01:48 | 00,204,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mswebdvd.dll
[2009/08/03 13:36:28 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/08/03 13:36:06 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys

========== LOP Check ==========

[2009/08/29 23:53:43 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/12/25 12:37:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Age of Empires 3
[2009/08/29 23:55:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/03/24 14:51:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Blizzard
[2009/08/20 20:53:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Blizzard Entertainment
[2008/01/26 14:45:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Dell
[2005/08/16 22:54:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DIGStream
[2006/11/15 08:56:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2008/09/09 08:55:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Roblox
[2008/08/21 16:20:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RobloxDownloads
[2007/02/28 15:43:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/03/09 00:48:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/08/09 08:50:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2008/11/13 14:23:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ZoomBrowser
[2009/08/29 23:46:49 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Noah\Application Data
[2009/03/20 10:29:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Noah\Application Data\Blender Foundation
[2009/03/02 20:12:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Noah\Application Data\CameraWindowDC
[2009/03/02 20:09:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Noah\Application Data\CANON INC
[2007/08/09 11:16:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Noah\Application Data\Corel
[2006/06/08 19:34:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Noah\Application Data\Corel Photo Album
[2009/08/26 12:54:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Noah\Application Data\DNA
[2008/01/18 12:43:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Noah\Application Data\Leadertech
[2008/09/09 08:08:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Noah\Application Data\ROBLOX
[2009/07/31 19:11:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Noah\Application Data\Story Wizard
[2009/06/16 13:05:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Noah\Application Data\WildTangent
[2008/10/09 18:44:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Noah\Application Data\Xfire
[2007/11/22 16:22:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Noah\Application Data\yoclient
[2009/03/02 20:14:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Noah\Application Data\ZoomBrowser EX
[2009/08/20 17:03:04 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004/08/10 07:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/08/30 21:36:39 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:325064EA
< End of report >

3. Extras.txt

OTL Extras logfile created on: 8/30/2009 9:43:33 PM - Run 1
OTL by OldTimer - Version 3.0.10.7 Folder = C:\Documents and Settings\Noah\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.07 Mb Total Physical Memory | 548.07 Mb Available Physical Memory | 53.62% Memory free
2.40 Gb Paging File | 2.09 Gb Available in Paging File | 87.14% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.79 Gb Total Space | 29.10 Gb Free Space | 41.69% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JACKIEANDNOAH
Current User Name: Noah
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – File not found
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – File not found
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL – File not found
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger – (Microsoft Corporation)
"C:\WINDOWS\system32\java.exe" = C:\WINDOWS\system32\java.exe:*:Enabled:Java™ 2 Platform Standard Edition binary – (Sun Microsystems, Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Java\jre1.5.0_11\bin\java.exe" = C:\Program Files\Java\jre1.5.0_11\bin\java.exe:*:Enabled:Java Runtime Environment – (Sun Microsystems, Inc.)
"C:\Program Files\Rosetta Stone\SMS v3.2.0hs\server.exe" = C:\Program Files\Rosetta Stone\SMS v3.2.0hs\server.exe:*:Enabled:SMS Server v3.2.0hs – ()
"C:\Program Files\Rosetta Stone\SMS v3.2.0hs\admin.exe" = C:\Program Files\Rosetta Stone\SMS v3.2.0hs\admin.exe:*:Enabled:SMS Admin v3.2.0hs – ()
"C:\Program Files\Rosetta Stone\RS2.2.1.0Asms\Rosetta Stone.exe" = C:\Program Files\Rosetta Stone\RS2.2.1.0Asms\Rosetta Stone.exe:*:Enabled:Rosetta Stone Application – (Macromedia, Inc.)
"C:\Program Files\Rosetta Stone\RS2.2.1.0Asms\Discover.exe" = C:\Program Files\Rosetta Stone\RS2.2.1.0Asms\Discover.exe:*:Enabled:Rosetta Stone SMS Discovery Tool – (Fairfield Language Technologies)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Program Files\World of Warcraft\Launcher.exe" = C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher – (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\BackgroundDownloader.exe" = C:\Program Files\World of Warcraft\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader – (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe:*:Enabled:Blizzard Downloader – (Blizzard Entertainment)
"C:\Program Files\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe" = C:\Program Files\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe:*:Enabled:Blizzard Downloader – (Blizzard Entertainment)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype – (Skype Technologies S.A.)
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio RecordNow Data
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Roxio DLA
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1A15507A-8551-4626-915D-3D5FA095CC1B}" = Corel Paint Shop Pro X
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Roxio MyDVD LE
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skype™ 4.0
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{352310C3-E46B-42D3-8F32-54721FDD72D9}" = NetZeroInstallers
"{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}" = Google Earth
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{43CAC9A1-1993-4F65-9096-7C9AFC2BBF54}" = Dell CinePlayer
"{4667B940-BB01-428B-986E-A0CC46497BF7}" = ELIcon
"{492724FC-3B26-46B4-824F-3CE2722D9AA0}" = Apple Software Update
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}" = Sonic Activation Module
"{626C034B-50B8-47BD-AF93-EEFD0FA78FF4}" = Character Builder
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{682A2953-FF3B-42DE-B80A-D711FF94B1C8}" = Rosetta Stone 2.2.1.0Asms
"{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}" = Digital Content Portal
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{728278A1-0BB7-45E4-AC5E-91D7C0FD1EDE}" = EarthLink setup files
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{7A3F0566-5E05-4919-9C98-456F6B5CF831}" = Get High Speed Internet!
"{7BF68B83-5057-4D4B-0093-28285EEB9EE3}" = Harry Potter II
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{83F793B5-8BBF-42FD-A8A6-868CB3E2AAEA}" = Intel® PROSet for Wired Connections
"{85D3CC30-8859-481A-9654-FD9B74310BEF}" = Musicmatch® Jukebox
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A9B8148-DDD7-448F-BD6C-358386D32354}" = Corel Photo Album 6
"{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}" = QuickTime
"{9720C029-0C2C-4D1E-9DE0-E89971C4C8C7}" = Silent Hunter III
"{974C05A0-C76C-4724-A9A2-11D5D1355729}" = iTunes
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A683A2C0-821C-486F-858C-FA634DB5E864}" = EducateU
"{A698E8D4-46A3-48E7-89B3-FB3A7E914F66}" = Time to Ride
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio RecordNow Audio
"{AC76BA86-0000-0000-0000-6028747ADE01}" = Adobe Acrobat - Reader 6.0.2 Update
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio RecordNow Copy
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C51CD33D-D7A0-4328-A802-3CD9DA437208}" = Type to Learn 3 Home
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{D98C9637-93DA-44DB-B73A-B11A1192AB26}" = GameShadow
"{DF6A589A-7A1A-430C-9FF2-A0BDB42669DC}" = Google
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E93E5EF6-D361-481E-849D-F16EF5C78EBC}" = Musicmatch for Windows Media Player
"{F2527115-B8BF-4FDB-B5DA-5AADFB7C13E1}" = The Sims Complete Collection
"{F3DE47C0-1128-45C5-9494-EDC3086519DA}" = Storywizard
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3
"ATI Display Driver" = ATI Display Driver
"AVG8Uninstall" = AVG Free 8.5
"CAL" = Canon Camera Access Library
"CameraWindowDC" = Canon Utilities CameraWindow DC
"CameraWindowDVC5" = Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
"CameraWindowLauncher" = Canon Utilities CameraWindow
"Canon G.726 WMP-Decoder" = Canon G.726 WMP-Decoder
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"CSCLIB" = Canon Camera Support Core Library
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"EmeraldQFE2" = Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
"EOS Utility" = Canon Utilities EOS Utility
"ESPNMotion" = ESPNMotion
"Game Console - WildGames" = Game Console - WildGames
"GodsWar Online_is1" = GodsWar Online
"Google Desktop" = Google Desktop
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{682A2953-FF3B-42DE-B80A-D711FF94B1C8}" = Rosetta Stone 2.2.1.0Asms
"InstallShield_{70F8B183-99EB-4304-BA35-080E2DFFD2A3}" = Age of Empires III
"InstallShield_{9720C029-0C2C-4D1E-9DE0-E89971C4C8C7}" = Silent Hunter III
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"MyCamera" = Canon Utilities MyCamera
"MyCameraDC" = Canon Utilities MyCamera DC
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PhotoStitch" = Canon Utilities PhotoStitch
"PROSet" = Intel® PRO Network Connections Drivers
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RealPlayer 6.0" = RealPlayer Basic
"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
"StreetPlugin" = Learn2 Player (Uninstall Only)
"Student Management System v3.2.0hs" = Student Management System v3.2.0hs
"ViewpointMediaPlayer" = Viewpoint Media Player
"WebCyberCoach_wtrb" = WebCyberCoach 3.2 Dell
"WildTangent CDA" = WildTangent Web Driver
"WildTangent wildgames Master Uninstall" = WildTangent Games
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"World of Warcraft" = World of Warcraft
"Xfire" = Xfire (remove only)
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{373B1718-8CC5-4567-8EE2-9033AD08A680}" = Roblox for Noah
"BitTorrent DNA" = DNA

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/11/2009 7:39:10 AM | Computer Name = JACKIEANDNOAH | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16876, faulting
module unknown, version 0.0.0.0, fault address 0x60b47930.

Error - 8/11/2009 1:57:15 PM | Computer Name = JACKIEANDNOAH | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16876, faulting
module flash9f.ocx, version 9.0.124.0, fault address 0x00194cf1.

Error - 8/13/2009 9:11:33 AM | Computer Name = JACKIEANDNOAH | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16876, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 8/17/2009 10:17:54 AM | Computer Name = JACKIEANDNOAH | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16876, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 8/27/2009 6:24:41 AM | Computer Name = JACKIEANDNOAH | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16876, faulting
module unknown, version 0.0.0.0, fault address 0x10003973.

Error - 8/27/2009 6:46:50 AM | Computer Name = JACKIEANDNOAH | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16876, faulting
module unknown, version 0.0.0.0, fault address 0x10003973.

Error - 8/27/2009 7:09:45 AM | Computer Name = JACKIEANDNOAH | Source = MsiInstaller | ID = 1008
Description = The installation of C:\WINDOWS\Installer\4a6427.msi is not permitted
due to an error in software restriction policy processing. The object cannot be
trusted.

Error - 8/27/2009 7:09:51 AM | Computer Name = JACKIEANDNOAH | Source = MsiInstaller | ID = 1008
Description = The installation of C:\WINDOWS\Installer\4a6427.msi is not permitted
due to an error in software restriction policy processing. The object cannot be
trusted.

Error - 8/27/2009 6:43:01 PM | Computer Name = JACKIEANDNOAH | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16876, faulting
module unknown, version 0.0.0.0, fault address 0x10003973.

Error - 8/28/2009 6:59:18 AM | Computer Name = JACKIEANDNOAH | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16876, faulting
module unknown, version 0.0.0.0, fault address 0x10003973.

[ System Events ]
Error - 8/29/2009 10:49:07 PM | Computer Name = JACKIEANDNOAH | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2

Error - 8/29/2009 10:49:11 PM | Computer Name = JACKIEANDNOAH | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the PEVSystemStart service
to connect.

Error - 8/29/2009 11:44:33 PM | Computer Name = JACKIEANDNOAH | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 8/29/2009 11:44:39 PM | Computer Name = JACKIEANDNOAH | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2

Error - 8/30/2009 6:23:28 PM | Computer Name = JACKIEANDNOAH | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service iPod Service
with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}

Error - 8/30/2009 8:17:13 PM | Computer Name = JACKIEANDNOAH | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service gusvc with
arguments "" in order to run the server: {89DAE4CD-9F17-4980-902A-99BA84A8F5C8}

Error - 8/30/2009 9:30:02 PM | Computer Name = JACKIEANDNOAH | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the PEVSystemStart service
to connect.

Error - 8/30/2009 9:34:34 PM | Computer Name = JACKIEANDNOAH | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the PEVSystemStart service
to connect.

Error - 8/30/2009 9:34:35 PM | Computer Name = JACKIEANDNOAH | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the PEVSystemStart service
to connect.

Error - 8/30/2009 9:43:39 PM | Computer Name = JACKIEANDNOAH | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service gusvc with
arguments "" in order to run the server: {89DAE4CD-9F17-4980-902A-99BA84A8F5C8}


< End of report >
What's next? Thanks again for your help.
Hi,

Lets continue.

Go to start and then run and appwiz.cpl.

This will take you to Add or Remove programs.

Uninstall the following.

Viewpoint Media Player
BitTorrent DNA


1) OTL

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    [2009/08/22 07:40:42 | 00,017,582 | —- | C] () – C:\WINDOWS\System32\usiji.db
    [2009/08/22 07:40:42 | 00,011,728 | —- | C] () – C:\Documents and Settings\Noah\Local Settings\Application Data\ugic.lib
    [2009/08/28 14:56:48 | 00,015,200 | —- | C] () – C:\Documents and Settings\All Users\Application Data\munivujydy.db
    [2009/08/28 14:56:48 | 00,011,246 | —- | C] () – C:\WINDOWS\bexop.lib
    [2009/08/27 18:51:19 | 00,019,443 | —- | C] () – C:\WINDOWS\ecajoliza.lib
    [2009/08/27 18:51:19 | 00,017,889 | —- | C] () – C:\Documents and Settings\Noah\Local Settings\Application Data\suvenidoly.db
    [2009/08/27 18:51:19 | 00,016,719 | —- | C] () – C:\Documents and Settings\All Users\Documents\hede._sy
    [2009/08/27 18:51:19 | 00,015,166 | —- | C] () – C:\Documents and Settings\All Users\Documents\gokywewyl.lib
    [2009/08/27 18:51:19 | 00,011,864 | —- | C] () – C:\WINDOWS\lewyb._sy
    [2009/08/27 18:51:19 | 00,011,186 | —- | C] () – C:\WINDOWS\System32\vofokyru.lib
    [2009/08/29 08:02:45 | 00,019,089 | —- | M] () – C:\WINDOWS\System32\lazateq._sy
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done

2) Malwarebytes

[external image: Posted Image] Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.

3) JavaRa

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

4) Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply

In your reply I would like to see copied and pasted,

1) OTL fix log
2) Malwarebytes scan
3) Kaspersky scan
I follow your last instructions and the reports are as follows: All processes killed ========== OTL ========== File C:\WINDOWS\System32\usiji.db not found. File C:\Documents and Settings\Noah\Local Settings\Application Data\ugic.lib not found. File C:\Documents and Settings\All Users\Application Data\munivujydy.db not found. File C:\WINDOWS\bexop.lib not found. File C:\WINDOWS\ecajoliza.lib not found. File C:\Documents and Settings\Noah\Local Settings\Application Data\suvenidoly.db not found. File C:\Documents and Settings\All Users\Documents\hede._sy not found. File C:\Documents and Settings\All Users\Documents\gokywewyl.lib not found. File C:\WINDOWS\lewyb._sy not found. File C:\WINDOWS\System32\vofokyru.lib not found. File C:\WINDOWS\System32\lazateq._sy not found. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 33170 bytes User: Noah ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 811157 bytes ->Java cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes Windows Temp folder emptied: 452 bytes RecycleBin emptied: 135078 bytes Total Files Cleaned = 0.97 mb OTL by OldTimer - Version 3.0.10.7 log created on 08312009_082411 Files\Folders moved on Reboot… Registry entries deleted on Reboot… ———————————————————————————————————————— Malwarebytes' Anti-Malware 1.40 Database version: 2714 Windows 5.1.2600 Service Pack 3 8/31/2009 8:35:17 AM mbam-log-2009-08-31 (08-35-17).txt Scan type: Quick Scan Objects scanned: 98364 Time elapsed: 4 minute(s), 16 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Monday, August 31, 2009 Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Monday, August 31, 2009 15:37:29 Records in database: 2731869 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Objects scanned: 113913 Threats found: 1 Infected objects found: 1 Suspicious objects found: 0 Scan duration: 01:33:27 File name / Threat / Threats count C:\Qoobox\Quarantine\C\WINDOWS\system32\~.exe.vir Infected: Packed.Win32.Krap.x 1 Selected area has been scanned. Anything more I need to do?
How are things running now? I need you post back and let me know

Now for the good news,

Congratulations your logs appear clean!! :thumbsup:

Clean up

Follow these steps to uninstall Combofix and tools used in the removal of malware
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    [external image: Posted Image]


  • Download OTC to your desktop and run it
  • Click Yes to beginning the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.

Browsers

Just because your computer came loaded with Internet Explorer doesn't mean that you have to use it, there are other free alternatives, FIREFOX and OPERA, both are free to use and are more secure than IE.

If you are using firefox you can stay more secure by adding NoScript and WOT (Web Of Trust)

NoScript stops Java scripts from starting on a web page unless you give permission for them, and WOT (Web Of Trust) has a comprehensive list of ratings for different websites allowing you to easily see if a website that you are about to go to has a bad reputation; in fact it will warn you to check if you are sure that you want to continue to a bad website.
  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.

Additional Security Measures

Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

SpywareBlaster- SpywareBlaster will add a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

You should have a good anti spyware program - We recommend MalwareBytes Anti-Malware and SUPERAntiSpyware

MVPS Hosts file The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer

Winpatrol Download and install the free version of Winpatrol. WinPatrol takes snapshot of your critical system resources and alerts you to any changes that may occur without your knowledge.

Spring Cleaning

TFC - Temp File Cleaner by OldTimer - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders

Auslogics Disc Defrag or JKDefrag - Two good disc defragmenters for you to choose from.

Also, please read this great article, Preventing Malware - Tools and Practices for Safe Computing
Everything is working so much better. Thank you for all your help. I am sure I will be posting again at some point. I have several computers that I work with. You made a very hard problem so easy and the directions were very clear and easy to follow. You guys & gals are great. Thanks again and I will be sure to tell my friends about you. :woot: :yeah:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI