I believe i have a major problem
i cannot reboot to regular desktop
when i reboot, it comes to a black screen with a window asking me to enter password with my user name (never set one up)
then, it comes to my regular desktop without the icon and bottom bar, telling me that Userinit Logon App is not loading due to failure.
what should i do.
In addition, whe i turn the computer off and restart it while pressing F8, it will let me restart in safe mode but it restart back in the mode with all the option.
I can not do anything to that computer.
I don't know what i did but i got it to load to my desktop with all the icons and lots of pop up windows
1)Data Execution Prevention-Microsoft Windows- To help protect your computer, Windows has closed this program-WMI
2)Generic Host Process for Win 32 Services
And it kept on loading up internet Ex with lots of blank page tap
I don't know but it's back to square 1
no icons on desktop no start button nothing
help
Hello,
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.
I will post back shortly with instructions.
Double click DDS icon to run the tool (may take up to 3 minutes to run)
When done, DDS.txt will open.
After a few moments, attach.txt will open in a second window.
Save both reports to your desktop.
—————————————————
Post the contents of the DDS.txt report in your next reply
Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
—————————————————
Please include the contents of the following in your next reply:
DDS.txt
Please attach the second file; Attach.txt. To attach a file, do the following:
Under the reply panel is the Attachments Panel.
Browse for the attachment file you want to upload, then click the green Upload button.
Once it has uploaded, click the Manage Current Attachments drop down box.
Click on to insert the attachment into your post
Please post both DDS logs in your next reply.
–Next–
We Need to check for Rootkits with RootRepeal
Please download RootRepeal one of these locations and save it to your desktop Here Here Here
Open [external image: Posted Image] on your desktop.
Click the [external image: Posted Image] tab.
Click the [external image: Posted Image] button.
Check just these boxes:
[external image: Posted Image]
Push Ok
Check the box for your main system drive (Usually C:, and press Ok.
Allow RootRepeal to run a scan of your system. This may take some time.
Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your post.
Logs to post in your next reply:
1. DDS logs.
2. RootRepeal log.
3. Any updates on the symptoms. Thank you.
We need to access the internet to download the tools we will be using and if this is an infection we don't want to risk infecting other
computers by transferring files from each other.
Can you please elaborate on why you can't get online? Is it because you can't open your browser? Internet explorer, Mozilla firefox or any browser you use?
Let's try this, open Task Manager by pressing ctrl,alt,del at the same time or right click on the bar that you see on the bottom of your screen, near the clock then select (left click) Task Manager.
In Task Manager, click the Options button
check mark Allways on Top
This will keep Taskmanager from disappearing when you click on anything else.
Using your left mouse button, click on the top blue portion of Task Manager and slide it down to the lower part of your screen so these instructions are visible.
In Task Manager
click file
click New Task(Run…)
type the following line into the open: field iexplore.exe
click ok
–Next–
Try to download the tools mentioned above, you must download it to your desktop, run it, then post the logs please. Also, post any other problems your computer is having.
hey, the reason why i can't get online because there is nohting on the desktop, all i see is blue screen
i tried pressing ctrl, alt, and delete but it says task manager has been disable by your administrion. i never recall disabling it.
hey, i was searchingn through this site and came up with
download a blank disk (hiren bootcd wintools 1.2) and i install it
now I see blue screen with icons:
my computer,my network places, 7-zip file manager, bootcd wintools, clear temp. cmd. command prompt, network, task manager procexp, windows explorer, and the bar on the bottom.
i have decided to wait cuz i don't wnat to mess thing up again. thanks
Please refrain from installing/uninstalling any applications unless advised and don't run any other scanning tools other than those I'll instruct you to use.
If you have any questions, please feel free to ask before proceeding with the advised fixes. Thank you.
Double click the Network icon on the desktop.
Your network adapter should be detected, drivers installed and configured for a connection.
Once the network connection has been established, a connection icon should be located near the clock in the notification area.
There should be a minimized program on the taskbar named Hiren's BootCD WinTools - click it to bring up the interface (or click Start>Programs>BootCD WinTools or double click the Hiren's BootCD Wintools icon on the desktop).
Once saved, close all other windows then double click the program to run it.
When completed, a log will open.
Save the log to the desktop using File>Save as, then post the log in a reply.
*Please do not restart the computer, nor do any other browsing or run any other programs, until I've responded with further instructions. Running from the bootable cd is like God mode, and anything you do could be irreversible.
DDS_BootCD_Version (Ver_09-10-04.01) - NTFSx86
Run at 19:46:49.21 on Sat 10/24/2009
Internet Explorer: 7.0.5730.13
============== Pseudo HJT Report ===============
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\drivers\smss.exe
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: c:\windows\system32\nkdac.dll: {a2234b15-23f2-42ad-f4e4-00aac39c0004} - c:\windows\system32\nkdac.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: c:\windows\system32\nkdac.dll: {a2234b15-23f2-42ad-f4e4-00aac39c0004} - c:\windows\system32\nkdac.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {37B85A29-692B-4205-9CAD-2626E4993404} - No File
TB: {55FAF0F2-44D4-425F-B5F5-6B275B621EAB} - No File
TB: BearShare MediaBar: {d3dee18f-db64-4beb-9ff1-e1f0a5033e4a} - c:\program files\bearshare applications\bearshare mediabar\MediaBar.dll
TB: {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - No File
S-1-5-21-2052111302-287218729-839522115-1004_Run: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
S-1-5-21-2052111302-287218729-839522115-1004_Run: [PhotoShow Deluxe Media Manager] c:\progra~1\ahead\neroph~1\data\xtras\mssysmgr.exe
S-1-5-21-2052111302-287218729-839522115-1004_Run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
S-1-5-21-2052111302-287218729-839522115-1004_Run: [Microsoft Windows logon process] c:\documents and settings\ho\application data\microsoft\windows\winlogon.exe
S-1-5-21-2052111302-287218729-839522115-1004_Run: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
S-1-5-21-2052111302-287218729-839522115-1004_Run: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
S-1-5-21-2052111302-287218729-839522115-1004_Run: [PopRock] c:\docume~1\ho\locals~1\temp\b.exe
S-1-5-21-2052111302-287218729-839522115-1004_Run: [Advanced Virus Remover] c:\program files\advancedvirusremover\PAVRM.exe
S-1-5-21-2052111302-287218729-839522115-1004_Run: [mserv] c:\documents and settings\ho\application data\seres.exe
S-1-5-21-2052111302-287218729-839522115-1004_Run: [svchost] c:\documents and settings\ho\application data\svcst.exe
S-1-5-21-2052111302-287218729-839522115-1004_Run: [calc] rundll32.exe c:\docume~1\ho\ntuser.dll,_IWMPEvents@0
S-1-5-21-2052111302-287218729-839522115-1004_Run: [Login Software 2009] c:\docume~1\ho\locals~1\temp\hnjyc4xur.exe
S-1-5-21-2052111302-287218729-839522115-1004_Run: [Yjafosi8kdf98winmdkmnkmfnwe] c:\docume~1\ho\locals~1\temp\install.exe
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [Cpqset] c:\program files\hpq\default settings\cpqset.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [eabconfg.cpl] c:\program files\hpq\quick launch buttons\EabServr.exe /Start
mRun: [hpWirelessAssistant] c:\program files\hpq\hp wireless assistant\HP Wireless Assistant.exe
mRun: [Home Theater SchSvr] "c:\program files\common files\intervideo\schsvr\SchSvr.exe"
mRun: [WINREMOTE] "c:\program files\intervideo\common\bin\WinRemote.exe"
mRun: [HelpCenter4.1] c:\program files\fastaccessdsl\helpcenter43\bin\sprtcmd.exe /P HelpCenter4.1
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [AutoTBar] AUTOTBAR.EXE
mRun: [lsdefrag] c:\docume~1\ho\locals~1\temp\erwcxsonam.tmp
mRun: [winupdate.exe] c:\windows\system32\winupdate.exe
mRun: [calc] rundll32.exe c:\windows\system32\calc.dll,_IWMPEvents@0
mRun: [Antivirus Pro 2010] "c:\program files\antiviruspro_2010\AntivirusPro_2010.exe" /hide
mRun: [csrs32] c:\windows\system32\csrs32.exe
mRun: [wozuwajus] Rundll32.exe "c:\windows\system32\menukabu.dll",a
mRun: [24867128] c:\docume~1\alluse~1\applic~1\24867128\24867128.exe
mRun: [87481937] c:\documents and settings\all users\application data\87481937\87481937.exe
mRunOnce: [ÑN@] d14e4000
StartupFolder: c:\documents and settings\ho\start menu\programs\startup\scandisk.dll
StartupFolder: c:\docume~1\ho\startm~1\programs\startup\scandisk.lnk - x:\i386\system32\rundll32.exe
S-1-5-21-2052111302-287218729-839522115-1004_Policies-explorer: NoSetActiveDesktop = 1 (0x1)
S-1-5-21-2052111302-287218729-839522115-1004_Policies-explorer: NoActiveDesktopChanges = 1 (0x1)
S-1-5-21-2052111302-287218729-839522115-1004_Policies-explorer: NoFolderOptions = 1 (0x1)
S-1-5-21-2052111302-287218729-839522115-1004_Policies-explorer: ForceClassicControlPanel = 1 (0x1)
S-1-5-21-2052111302-287218729-839522115-1004_Policies-system: = 0
S-1-5-21-2052111302-287218729-839522115-1004_Policies-system: DisableRegistryTools = 1 (0x1)
S-1-5-21-2052111302-287218729-839522115-1004_Policies-system: DisableTaskMgr = 1 (0x1)
S-1-5-21-2052111302-287218729-839522115-1004_Policies-system: EnableProfileQuota = 1 (0x1)
mPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {4788DE0A-3552-49EA-AC8C-233DA52523B9} - hxxp://www.blackberry.com/devicesoftware/AxLoader.cab
DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://go.divx.com/plugin/DivXBrowserPlugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://dl8-cdn-03.sun.com/s/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab?e=1227915938027&h=22dd0f8fd97925f6c81aef61de761c6d/&filename=jinstall-6u10-windows-i586-jc.cab
DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} - hxxp://ak.imgag.com/imgag/cp/install/Crusher.cab
DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: AtiExtEvent - Ati2evxx.dll
Notify: WRNotifier - WRLogonNTF.dll
AppInit_DLLs: c:\windows\system32\kbdnet.dll,kinotava.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: lebimupij - {9405df1d-5653-427b-9a9b-d3db82a9d6b3} - c:\windows\system32\menukabu.dll
STS: c:\windows\system32\nkdac.dll: {a2234b15-23f2-42ad-f4e4-00aac39c0004} - c:\windows\system32\nkdac.dll
STS: mujuzedij: {9405df1d-5653-427b-9a9b-d3db82a9d6b3} - c:\windows\system32\menukabu.dll
============= SERVICES / DRIVERS ===============
BtwSrv; c:\windows\system32\svchost.exe -k netsvcs; c:\windows\system32\BtwSrv.dll
daqdrv; \??\c:\windows\system32\daqdrv.sys
DVC; System32\Drivers\DVC.sys
fastnetsrv; c:\windows\temp\VRT9.tmp
HSFHWATI; system32\DRIVERS\HSFHWATI.sys
Ias; c:\windows\system32\svchost.exe -k netsvcs; c:\windows\system32\Iasex.dll
Iprip; c:\windows\system32\svchost.exe -k netsvcs; c:\windows\system32\Ipripv32.dll
Net_Login; c:\windows\svchust.exe
{059694F4-2A3B-4576-9A9D-D5F8537B580B}; [x]
{0A5A05BC-95C7-4BC8-917F-7CCE4CA4099B}; [x]
{0AB55F11-1B86-4578-A789-2EE85786663B}; [x]
{5405CEB4-759D-424F-AD6A-A15AE9C595B9}; [x]
=============== Created Last 30 ================
2009-10-22 03:21 0 a——- c:\windows\system32\4F.tmp
2009-10-22 03:14 0 a——- c:\windows\system32\4E.tmp
2009-10-22 03:13 0 a——- c:\windows\system32\4D.tmp
2009-10-22 03:11 0 a——- c:\windows\system32\4C.tmp
2009-10-22 03:09 0 a——- c:\windows\system32\4B.tmp
2009-10-22 03:08 0 a——- c:\windows\system32\4A.tmp
2009-10-22 02:58 0 a——- c:\windows\system32\49.tmp
2009-10-22 02:58 0 a——- c:\windows\system32\48.tmp
2009-10-22 02:57 0 a——- c:\windows\system32\47.tmp
2009-10-22 01:27 88,576 a——- c:\windows\system32\42.tmp
2009-10-22 01:27 46,080 a——- c:\windows\system32\41.tmp
2009-10-22 01:27 1 a——- c:\windows\system32\40.tmp
2009-10-22 01:24 152 a——- c:\windows\system32\3E.tmp
2009-10-22 00:56 88,576 a——- c:\windows\system32\3B.tmp
2009-10-22 00:56 46,080 a——- c:\windows\system32\3A.tmp
2009-10-22 00:56 1 a——- c:\windows\system32\36.tmp
2009-10-22 00:51 152 a——- c:\windows\system32\34.tmp
2009-10-22 00:51 88,576 a——- c:\windows\system32\33.tmp
2009-10-22 00:51 46,080 a——- c:\windows\system32\29.tmp
2009-10-22 00:51 1 a——- c:\windows\system32\26.tmp
2009-10-22 00:48 152 a——- c:\windows\system32\25.tmp
2009-10-22 00:39 98 a——- C:\kjderkic108.bat
2009-10-22 00:31 0 a——- c:\windows\SC.INS
2009-10-22 00:31 0 a——- c:\windows\sc.exe
2009-10-22 00:31 –d—– c:\program files\Protection System
2009-10-22 00:28 –d—– c:\documents and settings\all users\application data\87481937
2009-10-21 20:27 0 a——- c:\windows\system32\39.tmp
2009-10-21 20:27 0 a——- c:\windows\system32\38.tmp
2009-10-21 20:23 0 a——- c:\windows\system32\37.tmp
2009-10-21 20:18 0 a——- c:\windows\system32\35.tmp
2009-10-21 20:14 88,576 a——- c:\windows\system32\32.tmp
2009-10-21 20:14 46,080 a——- c:\windows\system32\31.tmp
2009-10-21 20:14 1 a——- c:\windows\system32\30.tmp
2009-10-21 20:14 152 a——- c:\windows\system32\2F.tmp
2009-10-21 20:13 88,576 a——- c:\windows\system32\2A.tmp
2009-10-21 20:13 152 a——- c:\windows\system32\27.tmp
2009-10-21 20:13 1 a——- c:\windows\system32\28.tmp
2009-10-21 20:10 88,576 a——- c:\windows\system32\24.tmp
2009-10-21 20:10 46,080 a——- c:\windows\system32\23.tmp
2009-10-21 20:09 1 a——- c:\windows\system32\22.tmp
2009-10-21 20:09 152 a——- c:\windows\system32\21.tmp
2009-10-21 20:09 88,576 a——- c:\windows\system32\20.tmp
2009-10-21 20:09 46,080 a——- c:\windows\system32\1F.tmp
2009-10-21 20:09 1 a——- c:\windows\system32\1E.tmp
2009-10-21 20:09 152 a——- c:\windows\system32\1C.tmp
2009-10-21 19:57 64,144 a——- c:\windows\sv1.exe
2009-10-21 19:56 74,752 a——- c:\windows\rundll22.exe
2009-10-21 19:56 88,576 a——- c:\windows\system32\2E.tmp
2009-10-21 19:56 46,080 a——- c:\windows\system32\2D.tmp
2009-10-21 19:56 1 a——- c:\windows\system32\2C.tmp
2009-10-21 19:56 152 a——- c:\windows\system32\2B.tmp
2009-10-21 19:33 88,576 a——- c:\windows\system32\1D.tmp
2009-10-21 19:33 1 a——- c:\windows\system32\1B.tmp
2009-10-21 19:33 152 a——- c:\windows\system32\19.tmp
2009-10-21 19:26 88,576 a——- c:\windows\system32\1A.tmp
2009-10-21 19:26 1 a——- c:\windows\system32\18.tmp
2009-10-21 19:26 152 a——- c:\windows\system32\12.tmp
2009-10-21 17:34 –d—– c:\documents and settings\all users\application data\24867128
2009-10-21 17:33 88,576 a——- c:\windows\system32\15.tmp
2009-10-21 17:33 1 a——- c:\windows\system32\F.tmp
2009-10-21 17:33 152 a——- c:\windows\system32\D.tmp
2009-10-21 17:33 0 a——- c:\windows\system32\AVR09.exe
2009-10-21 17:28 88,576 a——- c:\windows\system32\E.tmp
2009-10-21 17:28 152 a——- c:\windows\system32\4.tmp
2009-10-21 17:28 1 a——- c:\windows\system32\C.tmp
2009-10-21 16:55 152 a——- c:\windows\system32\api.reg
2009-10-21 16:55 40,960 a——- c:\windows\system32\csrs32.exe
2009-10-21 16:55 40,960 a——- c:\windows\sv3.exe
2009-10-21 16:55 307,168 a——- c:\windows\sv2.exe
2009-10-21 16:54 33,280 a——- c:\windows\svchust.exe
2009-10-21 16:53 1,168,384 a——- c:\windows\svchost.exe
2009-10-21 16:53 600,026 a——- c:\windows\isvchost.exe
2009-10-21 16:53 88,576 a——- c:\windows\system32\B.tmp
2009-10-21 16:53 46,080 a——- c:\windows\system32\7.tmp
2009-10-21 16:53 152 a——- c:\windows\system32\5.tmp
2009-10-21 16:53 1 a——- c:\windows\system32\6.tmp
2009-10-21 16:52 102,688 a——- c:\windows\9129837.exe
2009-10-21 04:29 88,576 a——- c:\windows\system32\17.tmp
2009-10-21 04:29 52 a——- c:\windows\system32\16.tmp
2009-10-21 04:28 88,576 a——- c:\windows\system32\14.tmp
2009-10-21 04:28 52 a——- c:\windows\system32\13.tmp
2009-10-21 04:26 88,576 a——- c:\windows\system32\11.tmp
2009-10-21 04:26 52 a——- c:\windows\system32\10.tmp
2009-10-21 03:55 17,487 a——- c:\windows\yjuveqahy.pif
2009-10-21 03:55 16,916 a——- c:\documents and settings\all users\application data\gyqosamoda.sys
2009-10-21 03:55 16,509 a——- c:\windows\vojod.ban
2009-10-21 03:55 16,361 a——- c:\windows\system32\kadanileh.ban
2009-10-21 03:55 16,097 a——- c:\documents and settings\all users\application data\womeqy.scr
2009-10-21 03:55 15,913 a——- c:\documents and settings\all users\application data\bosuxajil.bin
2009-10-21 03:55 15,753 a——- c:\windows\ydehonap.scr
2009-10-21 03:55 12,847 a——- c:\windows\selybyvyqo.sys
2009-10-21 03:55 12,560 a——- c:\documents and settings\ho\application data\sacar.exe
2009-10-21 03:55 12,351 a——- c:\documents and settings\all users\application data\yqyq.scr
2009-10-21 03:55 12,016 a——- c:\windows\system32\gewuxifac.inf
2009-10-21 03:55 11,783 a——- c:\windows\qolineru.dll
2009-10-21 03:55 10,679 a——- c:\windows\ninonyqu.exe
2009-10-21 03:54 168,448 a——- c:\windows\system32\_scui.cpl
2009-10-21 03:52 357,340 a——- c:\documents and settings\ho\application data\lizkavd.exe
2009-10-21 03:52 47,104 a——- c:\windows\system32\winupdate.exe
2009-10-21 03:52 15,000 a——- c:\windows\system32\nkdac.dll
2009-10-21 03:51 65,536 a——- c:\documents and settings\ho\application data\svcst.exe
2009-10-21 03:51 65,536 a——- c:\documents and settings\ho\application data\seres.exe
2009-10-21 03:51 119,808 a——- c:\windows\system32\~.exe
2009-10-21 03:50 88,576 a——- c:\windows\system32\3.tmp
2009-10-21 03:50 52 a——- c:\windows\system32\2.tmp
2009-10-21 02:58 0 a——- c:\windows\system32\26500.exe
2009-10-21 02:37 0 a——- c:\windows\system32\6334.exe
2009-10-21 02:17 0 a——- c:\windows\system32\18467.exe
2009-10-21 01:58 –d—– c:\documents and settings\all users\application data\78773133
2009-10-21 01:57 0 a——- c:\windows\system32\A.tmp
2009-10-21 01:57 0 a——- c:\windows\system32\41.exe
2009-10-21 01:57 88,576 a——- c:\windows\system32\9.tmp
2009-10-21 01:57 –d—– c:\documents and settings\ho\application data\Logs
2009-10-21 01:57 52 a——- c:\windows\system32\8.tmp
2009-10-21 01:56 22,528 a——- c:\windows\system32\winhelper.dll
2009-10-21 01:56 77 a——- c:\windows\system32\uses32.dat
2009-10-21 01:47 831 a——- c:\windows\system32\critical_warning.html
2009-10-21 01:44 15,000 a——- c:\windows\system32\x40b8kodc.dll
2009-10-21 01:42 360,064 a——- c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL
2009-10-21 01:42 162,304 a——- c:\windows\msb.exe
2009-10-21 01:41 162,304 a——- c:\windows\msa.exe
2009-10-21 01:40 36,942 a——- c:\windows\system32\net.net
==================== Find3M ====================
2009-10-22 03:11 13,312 a——- c:\windows\system32\locator.exe
2009-10-22 03:00 13,312 a——- c:\windows\system32\netdde.exe
2009-10-22 01:42 13,312 a——- c:\windows\system32\clipsrv.exe
2009-10-21 01:42 360,064 a——- c:\windows\system32\drivers\TCPIP.SYS
2008-07-08 15:53 47,360 a——- c:\documents and settings\ho\application data\pcouffin.sys
2006-10-08 16:36 21 a—h— c:\documents and settings\all users\application data\emopts.dat.old.dat
2006-03-17 11:00 262,144 a——- c:\documents and settings\all users\ntuser.dat
2007-04-16 15:52 23,552 a–sh— c:\windows\system32\calc.dll
2009-07-21 01:57 3,006,439 a–sh— c:\windows\system32\fagometo.exe
2009-07-21 17:34 54,272 a–sh— c:\windows\system32\jitabine.dll
2009-07-21 17:34 54,272 a–sh— c:\windows\system32\kifupiza.dll
2009-07-21 17:34 54,272 a–sh— c:\windows\system32\kinotava.dll
2009-07-21 01:57 47,104 a–sh— c:\windows\system32\lijuhidi.exe
2009-07-21 17:34 91,648 a–sh— c:\windows\system32\menukabu.dll
2009-07-21 17:34 54,272 a–sh— c:\windows\system32\mimadove.dll
2009-07-21 01:57 3,006,927 a–sh— c:\windows\system32\nobiyaki.exe
2009-07-21 17:34 39,424 a–sh— c:\windows\system32\varayihe.dll
2009-07-21 01:57 39,424 a–sh— c:\windows\system32\yavafike.dll
2009-07-21 17:34 1,011,308 a–sh— c:\windows\system32\yupohote.exe
2009-06-12 15:08 16,384 a–sh— c:\windows\temp\cookies\index.dat
2009-06-12 15:08 32,768 a–sh— c:\windows\temp\history\history.ie5\index.dat
2009-06-12 15:08 32,768 a–sh— c:\windows\temp\temporary internet files\content.ie5\index.dat
==== Installed Programs ======================
1600
1600_Help
1600Trb
32 Bit HP CIO Components Installer
4500_Help
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 6.0.1
AiO_Scan
AiOSoftware
Athlon 64 Processor Driver
ATI - Software Uninstall Utility
ATI Control Panel
ATI Display Driver
AutoUpdate
BearFlix
BearShare
BPD_HPSU
bpd_scan
BPDSoftware
BPDSoftware_Ini
Broadcom 802.11 Wireless LAN Adapter
BufferChm
Compaq Presario r4000 User Guides
Conexant AC-Link Audio
Data Fax SoftModem with SmartCP
DeviceDiscovery
DeviceManagementQFolder
DivX
DivX Player
DocMgr
DocProc
DocProcQFolder
DVC5.0 Driver
DVD Decrypter (Remove Only)
DVD Shrink 3.2
DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5.0.4.5 Be
ESSBrwr
ESSCDBK
ESScore
ESSgui
ESSini
ESSPCD
ESSPDock
ESSSONIC
ESSTOOLS
essvatgt
eSupportQFolder
FastAccess® DSL Help Center 4.3
Fax
GPBaseService
HijackThis 2.0.2
Home Theater
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
HP Document Manager 1.0
HP Help and Support
HP Image Zone Express
HP Image Zone Plus 4.8.5
HP Imaging Device Functions 10.0
HP Officejet J4500 Series
HP Pavillion zv6000 User Guides
HP Photosmart Essential 2.5
HP PSC & OfficeJet 4.7
HP Solution Center 10.0
HP Update
HP Wireless Assistant 1.01 A3
HPProductAssistant
InterActual Player
InterVideo Home Theater
InterVideo WinDVD
iTunes
J4500
Java™ 6 Update 10
kgcbaby
kgcbase
kgchday
kgchlwn
kgcinvt
kgckids
kgcmove
kgcvday
Kodak EasyShare software
KSU
LimeWire 5.2.13
Lotus NotesSQL 3.01 driver
Lotus SmartSuite - English
Malwarebytes' Anti-Malware
MarketResearch
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
muvee autoProducer 4.0 - SE
Nero PhotoShow Elite
Nero Suite
netbrdg
Notifier
OCR Software by I.R.I.S. 10.0
OfotoXMI
ProductContext
PSSWCORE
Quick Launch Buttons 5.10 B3
QuickTime
Readme
REALTEK Gigabit and Fast Ethernet NIC Driver
RipIt4Me
Samsung Camcorder USB-D03 Capture Driver
Scan
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944338)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB947864)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB948881)
SFR
SHASTA
SKIN0001
SKINXSDK
Sonic Audio Module
Sonic Copy Module
Sonic Data Module
Sonic Express Labeler
Sonic MyDVD Plus
Sonic Update Manager
staticcr
Status
Synaptics Pointing Device Driver
Texas Instruments PCIxx21/x515 drivers.
TIxx21
Toolbox
tooltips
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
UserGuides
VideoToolkit01
VPRINTOL
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB883667
Windows XP Hotfix - KB884575
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885464
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885855
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888239
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB892559
WIRELESS
============= FINISH: 19:47:19.78 ===============
hey inzanity i have downloaded and save log on desktop but when i tried to post it computer shutdown
i restarted everything and was able to save. but when i tried to post it again i have to retype my password and username about 5 times cuz it kept on going back and forth
so i started a new topic (continued for inzanity) can you conuite from there thanks
DDS_BootCD_Version (Ver_09-10-04.01) - NTFSx86
Run at 19:46:49.21 on Sat 10/24/2009
Internet Explorer: 7.0.5730.13
============== Pseudo HJT Report ===============
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\drivers\smss.exe
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: c:\windows\system32\nkdac.dll: {a2234b15-23f2-42ad-f4e4-00aac39c0004} - c:\windows\system32\nkdac.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: c:\windows\system32\nkdac.dll: {a2234b15-23f2-42ad-f4e4-00aac39c0004} - c:\windows\system32\nkdac.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {37B85A29-692B-4205-9CAD-2626E4993404} - No File
TB: {55FAF0F2-44D4-425F-B5F5-6B275B621EAB} - No File
TB: BearShare MediaBar: {d3dee18f-db64-4beb-9ff1-e1f0a5033e4a} - c:\program files\bearshare applications\bearshare mediabar\MediaBar.dll
TB: {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - No File
S-1-5-21-2052111302-287218729-839522115-1004_Run: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
S-1-5-21-2052111302-287218729-839522115-1004_Run: [PhotoShow Deluxe Media Manager] c:\progra~1\ahead\neroph~1\data\xtras\mssysmgr.exe
S-1-5-21-2052111302-287218729-839522115-1004_Run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
S-1-5-21-2052111302-287218729-839522115-1004_Run: [Microsoft Windows logon process] c:\documents and settings\ho\application data\microsoft\windows\winlogon.exe
S-1-5-21-2052111302-287218729-839522115-1004_Run: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
S-1-5-21-2052111302-287218729-839522115-1004_Run: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
S-1-5-21-2052111302-287218729-839522115-1004_Run: [PopRock] c:\docume~1\ho\locals~1\temp\b.exe
S-1-5-21-2052111302-287218729-839522115-1004_Run: [Advanced Virus Remover] c:\program files\advancedvirusremover\PAVRM.exe
S-1-5-21-2052111302-287218729-839522115-1004_Run: [mserv] c:\documents and settings\ho\application data\seres.exe
S-1-5-21-2052111302-287218729-839522115-1004_Run: [svchost] c:\documents and settings\ho\application data\svcst.exe
S-1-5-21-2052111302-287218729-839522115-1004_Run: [calc] rundll32.exe c:\docume~1\ho\ntuser.dll,_IWMPEvents@0
S-1-5-21-2052111302-287218729-839522115-1004_Run: [Login Software 2009] c:\docume~1\ho\locals~1\temp\hnjyc4xur.exe
S-1-5-21-2052111302-287218729-839522115-1004_Run: [Yjafosi8kdf98winmdkmnkmfnwe] c:\docume~1\ho\locals~1\temp\install.exe
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [Cpqset] c:\program files\hpq\default settings\cpqset.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [eabconfg.cpl] c:\program files\hpq\quick launch buttons\EabServr.exe /Start
mRun: [hpWirelessAssistant] c:\program files\hpq\hp wireless assistant\HP Wireless Assistant.exe
mRun: [Home Theater SchSvr] "c:\program files\common files\intervideo\schsvr\SchSvr.exe"
mRun: [WINREMOTE] "c:\program files\intervideo\common\bin\WinRemote.exe"
mRun: [HelpCenter4.1] c:\program files\fastaccessdsl\helpcenter43\bin\sprtcmd.exe /P HelpCenter4.1
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [AutoTBar] AUTOTBAR.EXE
mRun: [lsdefrag] c:\docume~1\ho\locals~1\temp\erwcxsonam.tmp
mRun: [winupdate.exe] c:\windows\system32\winupdate.exe
mRun: [calc] rundll32.exe c:\windows\system32\calc.dll,_IWMPEvents@0
mRun: [Antivirus Pro 2010] "c:\program files\antiviruspro_2010\AntivirusPro_2010.exe" /hide
mRun: [csrs32] c:\windows\system32\csrs32.exe
mRun: [wozuwajus] Rundll32.exe "c:\windows\system32\menukabu.dll",a
mRun: [24867128] c:\docume~1\alluse~1\applic~1\24867128\24867128.exe
mRun: [87481937] c:\documents and settings\all users\application data\87481937\87481937.exe
mRunOnce: [ÑN@] d14e4000
StartupFolder: c:\documents and settings\ho\start menu\programs\startup\scandisk.dll
StartupFolder: c:\docume~1\ho\startm~1\programs\startup\scandisk.lnk - x:\i386\system32\rundll32.exe
S-1-5-21-2052111302-287218729-839522115-1004_Policies-explorer: NoSetActiveDesktop = 1 (0x1)
S-1-5-21-2052111302-287218729-839522115-1004_Policies-explorer: NoActiveDesktopChanges = 1 (0x1)
S-1-5-21-2052111302-287218729-839522115-1004_Policies-explorer: NoFolderOptions = 1 (0x1)
S-1-5-21-2052111302-287218729-839522115-1004_Policies-explorer: ForceClassicControlPanel = 1 (0x1)
S-1-5-21-2052111302-287218729-839522115-1004_Policies-system: = 0
S-1-5-21-2052111302-287218729-839522115-1004_Policies-system: DisableRegistryTools = 1 (0x1)
S-1-5-21-2052111302-287218729-839522115-1004_Policies-system: DisableTaskMgr = 1 (0x1)
S-1-5-21-2052111302-287218729-839522115-1004_Policies-system: EnableProfileQuota = 1 (0x1)
mPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {4788DE0A-3552-49EA-AC8C-233DA52523B9} - hxxp://www.blackberry.com/devicesoftware/AxLoader.cab
DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://go.divx.com/plugin/DivXBrowserPlugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://dl8-cdn-03.sun.com/s/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab?e=1227915938027&h=22dd0f8fd97925f6c81aef61de761c6d/&filename=jinstall-6u10-windows-i586-jc.cab
DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} - hxxp://ak.imgag.com/imgag/cp/install/Crusher.cab
DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: AtiExtEvent - Ati2evxx.dll
Notify: WRNotifier - WRLogonNTF.dll
AppInit_DLLs: c:\windows\system32\kbdnet.dll,kinotava.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: lebimupij - {9405df1d-5653-427b-9a9b-d3db82a9d6b3} - c:\windows\system32\menukabu.dll
STS: c:\windows\system32\nkdac.dll: {a2234b15-23f2-42ad-f4e4-00aac39c0004} - c:\windows\system32\nkdac.dll
STS: mujuzedij: {9405df1d-5653-427b-9a9b-d3db82a9d6b3} - c:\windows\system32\menukabu.dll
============= SERVICES / DRIVERS ===============
BtwSrv; c:\windows\system32\svchost.exe -k netsvcs; c:\windows\system32\BtwSrv.dll
daqdrv; \??\c:\windows\system32\daqdrv.sys
DVC; System32\Drivers\DVC.sys
fastnetsrv; c:\windows\temp\VRT9.tmp
HSFHWATI; system32\DRIVERS\HSFHWATI.sys
Ias; c:\windows\system32\svchost.exe -k netsvcs; c:\windows\system32\Iasex.dll
Iprip; c:\windows\system32\svchost.exe -k netsvcs; c:\windows\system32\Ipripv32.dll
Net_Login; c:\windows\svchust.exe
{059694F4-2A3B-4576-9A9D-D5F8537B580B}; [x]
{0A5A05BC-95C7-4BC8-917F-7CCE4CA4099B}; [x]
{0AB55F11-1B86-4578-A789-2EE85786663B}; [x]
{5405CEB4-759D-424F-AD6A-A15AE9C595B9}; [x]
=============== Created Last 30 ================
2009-10-22 03:21 0 a——- c:\windows\system32\4F.tmp
2009-10-22 03:14 0 a——- c:\windows\system32\4E.tmp
2009-10-22 03:13 0 a——- c:\windows\system32\4D.tmp
2009-10-22 03:11 0 a——- c:\windows\system32\4C.tmp
2009-10-22 03:09 0 a——- c:\windows\system32\4B.tmp
2009-10-22 03:08 0 a——- c:\windows\system32\4A.tmp
2009-10-22 02:58 0 a——- c:\windows\system32\49.tmp
2009-10-22 02:58 0 a——- c:\windows\system32\48.tmp
2009-10-22 02:57 0 a——- c:\windows\system32\47.tmp
2009-10-22 01:27 88,576 a——- c:\windows\system32\42.tmp
2009-10-22 01:27 46,080 a——- c:\windows\system32\41.tmp
2009-10-22 01:27 1 a——- c:\windows\system32\40.tmp
2009-10-22 01:24 152 a——- c:\windows\system32\3E.tmp
2009-10-22 00:56 88,576 a——- c:\windows\system32\3B.tmp
2009-10-22 00:56 46,080 a——- c:\windows\system32\3A.tmp
2009-10-22 00:56 1 a——- c:\windows\system32\36.tmp
2009-10-22 00:51 152 a——- c:\windows\system32\34.tmp
2009-10-22 00:51 88,576 a——- c:\windows\system32\33.tmp
2009-10-22 00:51 46,080 a——- c:\windows\system32\29.tmp
2009-10-22 00:51 1 a——- c:\windows\system32\26.tmp
2009-10-22 00:48 152 a——- c:\windows\system32\25.tmp
2009-10-22 00:39 98 a——- C:\kjderkic108.bat
2009-10-22 00:31 0 a——- c:\windows\SC.INS
2009-10-22 00:31 0 a——- c:\windows\sc.exe
2009-10-22 00:31 –d—– c:\program files\Protection System
2009-10-22 00:28 –d—– c:\documents and settings\all users\application data\87481937
2009-10-21 20:27 0 a——- c:\windows\system32\39.tmp
2009-10-21 20:27 0 a——- c:\windows\system32\38.tmp
2009-10-21 20:23 0 a——- c:\windows\system32\37.tmp
2009-10-21 20:18 0 a——- c:\windows\system32\35.tmp
2009-10-21 20:14 88,576 a——- c:\windows\system32\32.tmp
2009-10-21 20:14 46,080 a——- c:\windows\system32\31.tmp
2009-10-21 20:14 1 a——- c:\windows\system32\30.tmp
2009-10-21 20:14 152 a——- c:\windows\system32\2F.tmp
2009-10-21 20:13 88,576 a——- c:\windows\system32\2A.tmp
2009-10-21 20:13 152 a——- c:\windows\system32\27.tmp
2009-10-21 20:13 1 a——- c:\windows\system32\28.tmp
2009-10-21 20:10 88,576 a——- c:\windows\system32\24.tmp
2009-10-21 20:10 46,080 a——- c:\windows\system32\23.tmp
2009-10-21 20:09 1 a——- c:\windows\system32\22.tmp
2009-10-21 20:09 152 a——- c:\windows\system32\21.tmp
2009-10-21 20:09 88,576 a——- c:\windows\system32\20.tmp
2009-10-21 20:09 46,080 a——- c:\windows\system32\1F.tmp
2009-10-21 20:09 1 a——- c:\windows\system32\1E.tmp
2009-10-21 20:09 152 a——- c:\windows\system32\1C.tmp
2009-10-21 19:57 64,144 a——- c:\windows\sv1.exe
2009-10-21 19:56 74,752 a——- c:\windows\rundll22.exe
2009-10-21 19:56 88,576 a——- c:\windows\system32\2E.tmp
2009-10-21 19:56 46,080 a——- c:\windows\system32\2D.tmp
2009-10-21 19:56 1 a——- c:\windows\system32\2C.tmp
2009-10-21 19:56 152 a——- c:\windows\system32\2B.tmp
2009-10-21 19:33 88,576 a——- c:\windows\system32\1D.tmp
2009-10-21 19:33 1 a——- c:\windows\system32\1B.tmp
2009-10-21 19:33 152 a——- c:\windows\system32\19.tmp
2009-10-21 19:26 88,576 a——- c:\windows\system32\1A.tmp
2009-10-21 19:26 1 a——- c:\windows\system32\18.tmp
2009-10-21 19:26 152 a——- c:\windows\system32\12.tmp
2009-10-21 17:34 –d—– c:\documents and settings\all users\application data\24867128
2009-10-21 17:33 88,576 a——- c:\windows\system32\15.tmp
2009-10-21 17:33 1 a——- c:\windows\system32\F.tmp
2009-10-21 17:33 152 a——- c:\windows\system32\D.tmp
2009-10-21 17:33 0 a——- c:\windows\system32\AVR09.exe
2009-10-21 17:28 88,576 a——- c:\windows\system32\E.tmp
2009-10-21 17:28 152 a——- c:\windows\system32\4.tmp
2009-10-21 17:28 1 a——- c:\windows\system32\C.tmp
2009-10-21 16:55 152 a——- c:\windows\system32\api.reg
2009-10-21 16:55 40,960 a——- c:\windows\system32\csrs32.exe
2009-10-21 16:55 40,960 a——- c:\windows\sv3.exe
2009-10-21 16:55 307,168 a——- c:\windows\sv2.exe
2009-10-21 16:54 33,280 a——- c:\windows\svchust.exe
2009-10-21 16:53 1,168,384 a——- c:\windows\svchost.exe
2009-10-21 16:53 600,026 a——- c:\windows\isvchost.exe
2009-10-21 16:53 88,576 a——- c:\windows\system32\B.tmp
2009-10-21 16:53 46,080 a——- c:\windows\system32\7.tmp
2009-10-21 16:53 152 a——- c:\windows\system32\5.tmp
2009-10-21 16:53 1 a——- c:\windows\system32\6.tmp
2009-10-21 16:52 102,688 a——- c:\windows\9129837.exe
2009-10-21 04:29 88,576 a——- c:\windows\system32\17.tmp
2009-10-21 04:29 52 a——- c:\windows\system32\16.tmp
2009-10-21 04:28 88,576 a——- c:\windows\system32\14.tmp
2009-10-21 04:28 52 a——- c:\windows\system32\13.tmp
2009-10-21 04:26 88,576 a——- c:\windows\system32\11.tmp
2009-10-21 04:26 52 a——- c:\windows\system32\10.tmp
2009-10-21 03:55 17,487 a——- c:\windows\yjuveqahy.pif
2009-10-21 03:55 16,916 a——- c:\documents and settings\all users\application data\gyqosamoda.sys
2009-10-21 03:55 16,509 a——- c:\windows\vojod.ban
2009-10-21 03:55 16,361 a——- c:\windows\system32\kadanileh.ban
2009-10-21 03:55 16,097 a——- c:\documents and settings\all users\application data\womeqy.scr
2009-10-21 03:55 15,913 a——- c:\documents and settings\all users\application data\bosuxajil.bin
2009-10-21 03:55 15,753 a——- c:\windows\ydehonap.scr
2009-10-21 03:55 12,847 a——- c:\windows\selybyvyqo.sys
2009-10-21 03:55 12,560 a——- c:\documents and settings\ho\application data\sacar.exe
2009-10-21 03:55 12,351 a——- c:\documents and settings\all users\application data\yqyq.scr
2009-10-21 03:55 12,016 a——- c:\windows\system32\gewuxifac.inf
2009-10-21 03:55 11,783 a——- c:\windows\qolineru.dll
2009-10-21 03:55 10,679 a——- c:\windows\ninonyqu.exe
2009-10-21 03:54 168,448 a——- c:\windows\system32\_scui.cpl
2009-10-21 03:52 357,340 a——- c:\documents and settings\ho\application data\lizkavd.exe
2009-10-21 03:52 47,104 a——- c:\windows\system32\winupdate.exe
2009-10-21 03:52 15,000 a——- c:\windows\system32\nkdac.dll
2009-10-21 03:51 65,536 a——- c:\documents and settings\ho\application data\svcst.exe
2009-10-21 03:51 65,536 a——- c:\documents and settings\ho\application data\seres.exe
2009-10-21 03:51 119,808 a——- c:\windows\system32\~.exe
2009-10-21 03:50 88,576 a——- c:\windows\system32\3.tmp
2009-10-21 03:50 52 a——- c:\windows\system32\2.tmp
2009-10-21 02:58 0 a——- c:\windows\system32\26500.exe
2009-10-21 02:37 0 a——- c:\windows\system32\6334.exe
2009-10-21 02:17 0 a——- c:\windows\system32\18467.exe
2009-10-21 01:58 –d—– c:\documents and settings\all users\application data\78773133
2009-10-21 01:57 0 a——- c:\windows\system32\A.tmp
2009-10-21 01:57 0 a——- c:\windows\system32\41.exe
2009-10-21 01:57 88,576 a——- c:\windows\system32\9.tmp
2009-10-21 01:57 –d—– c:\documents and settings\ho\application data\Logs
2009-10-21 01:57 52 a——- c:\windows\system32\8.tmp
2009-10-21 01:56 22,528 a——- c:\windows\system32\winhelper.dll
2009-10-21 01:56 77 a——- c:\windows\system32\uses32.dat
2009-10-21 01:47 831 a——- c:\windows\system32\critical_warning.html
2009-10-21 01:44 15,000 a——- c:\windows\system32\x40b8kodc.dll
2009-10-21 01:42 360,064 a——- c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL
2009-10-21 01:42 162,304 a——- c:\windows\msb.exe
2009-10-21 01:41 162,304 a——- c:\windows\msa.exe
2009-10-21 01:40 36,942 a——- c:\windows\system32\net.net
==================== Find3M ====================
2009-10-22 03:11 13,312 a——- c:\windows\system32\locator.exe
2009-10-22 03:00 13,312 a——- c:\windows\system32\netdde.exe
2009-10-22 01:42 13,312 a——- c:\windows\system32\clipsrv.exe
2009-10-21 01:42 360,064 a——- c:\windows\system32\drivers\TCPIP.SYS
2008-07-08 15:53 47,360 a——- c:\documents and settings\ho\application data\pcouffin.sys
2006-10-08 16:36 21 a—h— c:\documents and settings\all users\application data\emopts.dat.old.dat
2006-03-17 11:00 262,144 a——- c:\documents and settings\all users\ntuser.dat
2007-04-16 15:52 23,552 a–sh— c:\windows\system32\calc.dll
2009-07-21 01:57 3,006,439 a–sh— c:\windows\system32\fagometo.exe
2009-07-21 17:34 54,272 a–sh— c:\windows\system32\jitabine.dll
2009-07-21 17:34 54,272 a–sh— c:\windows\system32\kifupiza.dll
2009-07-21 17:34 54,272 a–sh— c:\windows\system32\kinotava.dll
2009-07-21 01:57 47,104 a–sh— c:\windows\system32\lijuhidi.exe
2009-07-21 17:34 91,648 a–sh— c:\windows\system32\menukabu.dll
2009-07-21 17:34 54,272 a–sh— c:\windows\system32\mimadove.dll
2009-07-21 01:57 3,006,927 a–sh— c:\windows\system32\nobiyaki.exe
2009-07-21 17:34 39,424 a–sh— c:\windows\system32\varayihe.dll
2009-07-21 01:57 39,424 a–sh— c:\windows\system32\yavafike.dll
2009-07-21 17:34 1,011,308 a–sh— c:\windows\system32\yupohote.exe
2009-06-12 15:08 16,384 a–sh— c:\windows\temp\cookies\index.dat
2009-06-12 15:08 32,768 a–sh— c:\windows\temp\history\history.ie5\index.dat
2009-06-12 15:08 32,768 a–sh— c:\windows\temp\temporary internet files\content.ie5\index.dat
==== Installed Programs ======================
1600
1600_Help
1600Trb
32 Bit HP CIO Components Installer
4500_Help
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 6.0.1
AiO_Scan
AiOSoftware
Athlon 64 Processor Driver
ATI - Software Uninstall Utility
ATI Control Panel
ATI Display Driver
AutoUpdate
BearFlix
BearShare
BPD_HPSU
bpd_scan
BPDSoftware
BPDSoftware_Ini
Broadcom 802.11 Wireless LAN Adapter
BufferChm
Compaq Presario r4000 User Guides
Conexant AC-Link Audio
Data Fax SoftModem with SmartCP
DeviceDiscovery
DeviceManagementQFolder
DivX
DivX Player
DocMgr
DocProc
DocProcQFolder
DVC5.0 Driver
DVD Decrypter (Remove Only)
DVD Shrink 3.2
DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5.0.4.5 Be
ESSBrwr
ESSCDBK
ESScore
ESSgui
ESSini
ESSPCD
ESSPDock
ESSSONIC
ESSTOOLS
essvatgt
eSupportQFolder
FastAccess® DSL Help Center 4.3
Fax
GPBaseService
HijackThis 2.0.2
Home Theater
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
HP Document Manager 1.0
HP Help and Support
HP Image Zone Express
HP Image Zone Plus 4.8.5
HP Imaging Device Functions 10.0
HP Officejet J4500 Series
HP Pavillion zv6000 User Guides
HP Photosmart Essential 2.5
HP PSC & OfficeJet 4.7
HP Solution Center 10.0
HP Update
HP Wireless Assistant 1.01 A3
HPProductAssistant
InterActual Player
InterVideo Home Theater
InterVideo WinDVD
iTunes
J4500
Java™ 6 Update 10
kgcbaby
kgcbase
kgchday
kgchlwn
kgcinvt
kgckids
kgcmove
kgcvday
Kodak EasyShare software
KSU
LimeWire 5.2.13
Lotus NotesSQL 3.01 driver
Lotus SmartSuite - English
Malwarebytes' Anti-Malware
MarketResearch
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
muvee autoProducer 4.0 - SE
Nero PhotoShow Elite
Nero Suite
netbrdg
Notifier
OCR Software by I.R.I.S. 10.0
OfotoXMI
ProductContext
PSSWCORE
Quick Launch Buttons 5.10 B3
QuickTime
Readme
REALTEK Gigabit and Fast Ethernet NIC Driver
RipIt4Me
Samsung Camcorder USB-D03 Capture Driver
Scan
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944338)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB947864)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB948881)
SFR
SHASTA
SKIN0001
SKINXSDK
Sonic Audio Module
Sonic Copy Module
Sonic Data Module
Sonic Express Labeler
Sonic MyDVD Plus
Sonic Update Manager
staticcr
Status
Synaptics Pointing Device Driver
Texas Instruments PCIxx21/x515 drivers.
TIxx21
Toolbox
tooltips
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
UserGuides
VideoToolkit01
VPRINTOL
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB883667
Windows XP Hotfix - KB884575
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885464
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885855
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888239
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB892559
WIRELESS
============= FINISH: 19:47:19.78 ===============
You did afterwards though, so since this post a duplicate of the link above, I will close this topic. Please continue to follow the instructions from Inzanity and post in that topic and do not start a new topic.