This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] your system is infected wallpaper

33 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please re-run exeHelper before proceeding with running ComboFix.

Running ComboFix
Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
I re-ran exeHelper but when i tried to save ComboFix file to desktop i received error message:

Error Copying File or Folder
Cannot copy ComboFix(1): Access is denied.

Make sure the disk is not full or write-protected and that the file is not currently in use.
Running ComboFix
Please do the following:

Download Combofix from either of the links below. You must rename it to combo.com before saving it.
Save it to your desktop. Change the save as file type to "all files"

**Note: In the event you already have Combofix, delete it, this is a new version that I need you to download.
It is important that it is saved and renamed following this process directly to your desktop**


  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".

Link 1
Link 2

———————————————————–


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link] to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • NOTE: If ComboFix asks to install the Recovery Console, please ALLOW it to do so.

    ———————————————————–

  • Double click on the renamed ComboFix.exe & follow the prompts. When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.
Delete your copy of exeHelper.

Run exeHelper
Please download exeHelper to your desktop.
Double-click on explorer.exe to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of explorerlog.txt (Will be created in the directory where you ran explorer.exe, and should open at the end of the scan)
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

OTS Scan
Download OTS to your Desktop
  • Double-click on OTS.exe to start the program. Make sure you close all other programs.
  • Now click the Run Scan button on the toolbar. Make sure not to use the PC while the program is running or it will freeze.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
The last line is < End of Report >, so make sure that is the last line in the attached report.

Make sure you attach the report in your reply. If it is too big to upload, then zip the text file and upload it that way.

Please make sure you include the following items in your next post:
1. The log that was produced after running explorer.exe.
2. The log that was produced after running OTS.
3. An update on how your computer is currently running.
exeHelper by Raktor
Build 20091122
Run at 13:49:39 on 12/03/09
Now searching…
Checking for numerical processes…
Checking for sysguard processes…
Checking for bad processes…
Killed process winupdate86.exe
Checking for bad files…
Deleting file C:\WINDOWS\system32\41.exe
Deleting file C:\WINDOWS\system32\critical_warning.html
Deleting file C:\WINDOWS\system32\winupdate86.exe
Checking for bad registry entries…
Removing HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Advanced Virus Remover
Deleting file C:\Program Files\AdvancedVirusRemover\AVR.exe
Error deleting C:\Program Files\AdvancedVirusRemover\AVR.exe - Set for removal on reboot - PLEASE REBOOT
Removing HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\winupdate86.exe
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–

exeHelper by Raktor
Build 20091122
Run at 10:08:20 on 12/04/09
Now searching…
Checking for numerical processes…
Checking for sysguard processes…
Checking for bad processes…
Checking for bad files…
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–

exeHelper by Raktor
Build 20091204
Run at 12:04:23 on 12/04/09
Now searching…
Checking for numerical processes…
Checking for sysguard processes…
Checking for bad processes…
Checking for bad files…
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–



📎OTS.Txt

My computer is running better, the red circle, the startup error message, the logon.exe error and the desktop "your system is infected" wallpaper message has disapeared. But, I still cannot change any of the setting for the desktop wallpaper and now there a lot of pop-ups and my clock changed to army time and i cannot change it back.
Running OTS Fix
Start OTS Copy/Paste the information inside the codebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

[Kill All Processes]
[Unregister Dlls]
[Modules - Safe List]
YY -> tefiwizu.dll -> C:\WINDOWS\SYSTEM32\tefiwizu.dll
YY -> kosagiti.dll -> C:\WINDOWS\SYSTEM32\kosagiti.dll
[Registry - Safe List]
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> 
YN -> HKEY_CURRENT_USER\: URLSearchHooks\\"" [HKLM] -> Reg Error: Key error. [Reg Error: Value error.]
YN -> HKEY_CURRENT_USER\: URLSearchHooks\\"{00A6FAF6-072E-44cf-8957-5838F569A31D}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> HKEY_CURRENT_USER\: URLSearchHooks\\"{3192b808-ec27-4332-b6c6-97f82692cad5}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {3192b808-ec27-4332-b6c6-97f82692cad5} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> {6022635F-7197-4CED-B066-5E46D0A696A0} [HKLM] -> Reg Error: Key error. [Reg Error: Value error.]
YN -> {C06B1E9D-AC66-42E1-9992-71147245A3F7} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> {e21c1631-27ba-4527-815a-39ace2fb4914} [HKLM] -> Reg Error: Key error. [Reg Error: Value error.]
YN -> {F8C5B5C9-3AC5-4C8C-A984-1C4B71C2E69B} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar
YN -> "{07B18EA9-A523-4961-B6BB-170DE4475CCA}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> "{3192b808-ec27-4332-b6c6-97f82692cad5}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
YN -> ShellBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{3192B808-EC27-4332-B6C6-97F82692CAD5}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YY -> "jidopijen" -> C:\WINDOWS\System32\tefiwizu.DLL [Rundll32.exe "c:\windows\system32\tefiwizu.dll",a]
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\
YN -> {669B269B-0D4E-41FB-A3D8-FD67CA94F646}:Exec [HKLM] -> [Button: ComcastHSI]
YN -> {8828075D-D097-4055-AA02-2DBFA9D85E8A}:Exec [HKLM] -> [Button: Support]
YN -> {97809617-3937-4F84-B335-9BB05EF1A8D4}:Exec [HKLM] -> [Button: Help]
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\
YN -> CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> [Reg Error: Value error.]
YN -> CmdMapping\\"{669B269B-0D4E-41FB-A3D8-FD67CA94F646}" [HKLM] -> [ComcastHSI]
YN -> CmdMapping\\"{8828075D-D097-4055-AA02-2DBFA9D85E8A}" [HKLM] -> [Support]
YN -> CmdMapping\\"{97809617-3937-4F84-B335-9BB05EF1A8D4}" [HKLM] -> [Help]
YN -> CmdMapping\\"{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}" [HKLM] -> [Reg Error: Key error.]
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls
YY -> kosagiti.dll -> C:\WINDOWS\System32\kosagiti.dll
YY -> c:\windows\system32\tefiwizu.dll -> C:\WINDOWS\SYSTEM32\tefiwizu.dll
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
YN -> jkhfd -> Reg Error: Value error.
YN -> ssqPfcde -> 
< SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
YY -> "{d236e6e8-ade7-48e9-bc46-9f000b385c58}" [HKLM] -> C:\WINDOWS\SYSTEM32\tefiwizu.dll [gehahetif]
YN -> "{1a309fd0-8200-4ac7-94e2-2927ed48df52}" [HKLM] -> Reg Error: Key error. [hakorumit]
< SharedTaskScheduler [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
YY -> "{d236e6e8-ade7-48e9-bc46-9f000b385c58}" [HKLM] -> C:\WINDOWS\SYSTEM32\tefiwizu.dll [mujuzedij]
< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders
*SecurityProviders* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders
YN ->  digeste.dll -> 
< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders
< LSA Authentication Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages
*LSA Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages
YN -> C:\WINDOWS\system32\awtsPJBT -> 
< LSA Authentication Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
YN -> "C:\Documents and Settings\JERN\Local Settings\Temp\n.exn" -> C:\Documents and Settings\JERN\Local Settings\Temp\n.exn [C:\Documents and Settings\JERN\Local Settings\Temp\n.exn:*:Enabled:n]
YN -> "C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe" -> C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe:*:Enabled:Kodak Software Updater]
YN -> "C:\Program Files\LimeWire\LimeWire.exe" -> C:\Program Files\LimeWire\LimeWire.exe [C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire]
YN -> "C:\WINDOWS\SYSTEM32\winupdate86.exe" -> C:\WINDOWS\System32\winupdate86.exe [C:\WINDOWS\SYSTEM32\winupdate86.exe:*:Enabled:winupdate86]
YY -> "C:\WINDOWS\Temp\rdl32E.tmp.exe" -> C:\WINDOWS\Temp\rdl32E.tmp.exe [C:\WINDOWS\Temp\rdl32E.tmp.exe:*:Enabled:rdl32E.tmp]
[Files/Folders - Created Within 30 Days]
NY ->  828be51ece8d9c1b7c7ec5 -> C:\828be51ece8d9c1b7c7ec5
NY ->  Conduit -> C:\Program Files\Conduit
NY ->  Conduit -> C:\Documents and Settings\JERN\Local Settings\Application Data\Conduit
NY ->  CommentsBar_-_Social_Comments -> C:\Documents and Settings\JERN\Local Settings\Application Data\CommentsBar_-_Social_Comments
NY ->  2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY ->  12 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
[Files/Folders - Modified Within 30 Days]
NY ->  bunazuto -> C:\WINDOWS\System32\bunazuto
NY ->  User_Feed_Synchronization-{7C9E5EF1-6217-432C-8F62-C78A0787AA55}.job -> C:\WINDOWS\tasks\User_Feed_Synchronization-{7C9E5EF1-6217-432C-8F62-C78A0787AA55}.job
NY ->  iqsacgyb.job -> C:\WINDOWS\tasks\iqsacgyb.job
NY ->  icknfiop.job -> C:\WINDOWS\tasks\icknfiop.job
NY ->  tmp.reg -> C:\WINDOWS\System32\tmp.reg
NY ->  4827.exe -> C:\WINDOWS\System32\4827.exe
NY ->  11942.exe -> C:\WINDOWS\System32\11942.exe
NY ->  2995.exe -> C:\WINDOWS\System32\2995.exe
NY ->  491.exe -> C:\WINDOWS\System32\491.exe
NY ->  9961.exe -> C:\WINDOWS\System32\9961.exe
NY ->  16827.exe -> C:\WINDOWS\System32\16827.exe
NY ->  23281.exe -> C:\WINDOWS\System32\23281.exe
NY ->  28145.exe -> C:\WINDOWS\System32\28145.exe
NY ->  5705.exe -> C:\WINDOWS\System32\5705.exe
NY ->  24464.exe -> C:\WINDOWS\System32\24464.exe
NY ->  26962.exe -> C:\WINDOWS\System32\26962.exe
NY ->  29358.exe -> C:\WINDOWS\System32\29358.exe
NY ->  11478.exe -> C:\WINDOWS\System32\11478.exe
NY ->  15724.exe -> C:\WINDOWS\System32\15724.exe
NY ->  19169.exe -> C:\WINDOWS\System32\19169.exe
NY ->  26500.exe -> C:\WINDOWS\System32\26500.exe
NY ->  6334.exe -> C:\WINDOWS\System32\6334.exe
NY ->  18467.exe -> C:\WINDOWS\System32\18467.exe
NY ->  5436.exe -> C:\WINDOWS\System32\5436.exe
NY ->  winlogon86.exe -> C:\WINDOWS\System32\winlogon86.exe
NY ->  33 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp
NY ->  33 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp
NY ->  33 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp
NY ->  280 C:\Documents and Settings\JERN\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\JERN\Local Settings\Temp\*.tmp
NY ->  280 C:\Documents and Settings\JERN\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\JERN\Local Settings\Temp\*.tmp
NY ->  280 C:\Documents and Settings\JERN\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\JERN\Local Settings\Temp\*.tmp
NY ->  2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY ->  12 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
[Files - No Company Name]
NY ->  tmp.reg -> C:\WINDOWS\System32\tmp.reg
NY ->  iqsacgyb.job -> C:\WINDOWS\tasks\iqsacgyb.job
NY ->  5436.exe -> C:\WINDOWS\System32\5436.exe
NY ->  4827.exe -> C:\WINDOWS\System32\4827.exe
NY ->  11942.exe -> C:\WINDOWS\System32\11942.exe
NY ->  2995.exe -> C:\WINDOWS\System32\2995.exe
NY ->  491.exe -> C:\WINDOWS\System32\491.exe
NY ->  9961.exe -> C:\WINDOWS\System32\9961.exe
NY ->  16827.exe -> C:\WINDOWS\System32\16827.exe
NY ->  23281.exe -> C:\WINDOWS\System32\23281.exe
NY ->  28145.exe -> C:\WINDOWS\System32\28145.exe
NY ->  5705.exe -> C:\WINDOWS\System32\5705.exe
NY ->  24464.exe -> C:\WINDOWS\System32\24464.exe
NY ->  26962.exe -> C:\WINDOWS\System32\26962.exe
NY ->  29358.exe -> C:\WINDOWS\System32\29358.exe
NY ->  11478.exe -> C:\WINDOWS\System32\11478.exe
NY ->  15724.exe -> C:\WINDOWS\System32\15724.exe
NY ->  19169.exe -> C:\WINDOWS\System32\19169.exe
NY ->  26500.exe -> C:\WINDOWS\System32\26500.exe
NY ->  6334.exe -> C:\WINDOWS\System32\6334.exe
NY ->  18467.exe -> C:\WINDOWS\System32\18467.exe
NY ->  winlogon86.exe -> C:\WINDOWS\System32\winlogon86.exe
NY ->  tefiwizu.dll -> C:\WINDOWS\System32\tefiwizu.dll
NY ->  ripeyoji.dll -> C:\WINDOWS\System32\ripeyoji.dll
NY ->  giwasora.dll -> C:\WINDOWS\System32\giwasora.dll
NY ->  wubedige.dll -> C:\WINDOWS\System32\wubedige.dll
NY ->  kogonubo.dll -> C:\WINDOWS\System32\kogonubo.dll
NY ->  fibanana.dll -> C:\WINDOWS\System32\fibanana.dll
NY ->  sezulono.dll -> C:\WINDOWS\System32\sezulono.dll
NY ->  wolayuga.dll -> C:\WINDOWS\System32\wolayuga.dll
NY ->  relereni.dll -> C:\WINDOWS\System32\relereni.dll
NY ->  kosagiti.dll -> C:\WINDOWS\System32\kosagiti.dll
NY ->  kobitaka.dll -> C:\WINDOWS\System32\kobitaka.dll
NY ->  dorulelo.dll -> C:\WINDOWS\System32\dorulelo.dll
NY ->  tukideka.dll -> C:\WINDOWS\System32\tukideka.dll
NY ->  TBJPstwa.ini2 -> C:\WINDOWS\System32\TBJPstwa.ini2
NY ->  TBJPstwa.ini -> C:\WINDOWS\System32\TBJPstwa.ini
NY ->  eKRsYcdd.ini2 -> C:\WINDOWS\System32\eKRsYcdd.ini2
NY ->  eKRsYcdd.ini -> C:\WINDOWS\System32\eKRsYcdd.ini
NY ->  TtCIOXyb.ini2 -> C:\WINDOWS\System32\TtCIOXyb.ini2
NY ->  TtCIOXyb.ini -> C:\WINDOWS\System32\TtCIOXyb.ini
NY ->  dfhkj.ini2 -> C:\WINDOWS\System32\dfhkj.ini2
[Empty Temp Folders]
[Start Explorer]
[Reboot]

The fix should only take a very short time. When the fix is completed a message box will popup either telling you that it is finished, or that a reboot is needed to complete the fix. If the fix is complete, click the Ok button and Notepad will open with a log of actions taken during the fix. Post that log back here in your next reply.

If a reboot is required, click the "Yes" button to reboot the machine. After the reboot, OTS will finish moving any files that could not be moved during the fix and NotePad will open with the final results at that time. Post that log back here in your next reply.

Running ComboFix
If you have any versions of ComboFix saved on your computer I need for you to go ahead and delete those and download a fresh copy from the links provided below.
Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the following items in your next post:
1. The log that was produced after running OTS.
2. The log that was produced after running ComboFix.
3. Any issues you are still experiencing.
All Processes Killed
[Modules - Safe List]
DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\tefiwizu.dll
DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\kosagiti.dll
Releasing module c:\windows\system32\tefiwizu.dll
C:\WINDOWS\SYSTEM32\tefiwizu.dll moved successfully.
Releasing module C:\WINDOWS\system32\kosagiti.dll
C:\WINDOWS\SYSTEM32\kosagiti.dll moved successfully.
[Registry - Safe List]
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{00A6FAF6-072E-44cf-8957-5838F569A31D} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{3192b808-ec27-4332-b6c6-97f82692cad5} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3192b808-ec27-4332-b6c6-97f82692cad5}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3192b808-ec27-4332-b6c6-97f82692cad5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3192b808-ec27-4332-b6c6-97f82692cad5}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6022635F-7197-4CED-B066-5E46D0A696A0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6022635F-7197-4CED-B066-5E46D0A696A0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C06B1E9D-AC66-42E1-9992-71147245A3F7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C06B1E9D-AC66-42E1-9992-71147245A3F7}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e21c1631-27ba-4527-815a-39ace2fb4914}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e21c1631-27ba-4527-815a-39ace2fb4914}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F8C5B5C9-3AC5-4C8C-A984-1C4B71C2E69B}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F8C5B5C9-3AC5-4C8C-A984-1C4B71C2E69B}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\{07B18EA9-A523-4961-B6BB-170DE4475CCA} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\{3192b808-ec27-4332-b6c6-97f82692cad5} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3192b808-ec27-4332-b6c6-97f82692cad5}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{3192B808-EC27-4332-B6C6-97F82692CAD5} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3192B808-EC27-4332-B6C6-97F82692CAD5}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\jidopijen deleted successfully.
File C:\WINDOWS\System32\tefiwizu.DLL not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{669B269B-0D4E-41FB-A3D8-FD67CA94F646}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{669B269B-0D4E-41FB-A3D8-FD67CA94F646}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{669B269B-0D4E-41FB-A3D8-FD67CA94F646}:Exec\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{8828075D-D097-4055-AA02-2DBFA9D85E8A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8828075D-D097-4055-AA02-2DBFA9D85E8A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8828075D-D097-4055-AA02-2DBFA9D85E8A}:Exec\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{97809617-3937-4F84-B335-9BB05EF1A8D4}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97809617-3937-4F84-B335-9BB05EF1A8D4}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97809617-3937-4F84-B335-9BB05EF1A8D4}:Exec\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{669B269B-0D4E-41FB-A3D8-FD67CA94F646} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{669B269B-0D4E-41FB-A3D8-FD67CA94F646}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{8828075D-D097-4055-AA02-2DBFA9D85E8A} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8828075D-D097-4055-AA02-2DBFA9D85E8A}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{97809617-3937-4F84-B335-9BB05EF1A8D4} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97809617-3937-4F84-B335-9BB05EF1A8D4}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:kosagiti.dll deleted successfully.
File C:\WINDOWS\System32\kosagiti.dll not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\tefiwizu.dll deleted successfully.
File C:\WINDOWS\SYSTEM32\tefiwizu.dll not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkhfd\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqPfcde\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\gehahetif deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d236e6e8-ade7-48e9-bc46-9f000b385c58}\ deleted successfully.
File C:\WINDOWS\SYSTEM32\tefiwizu.dll not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\hakorumit deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1a309fd0-8200-4ac7-94e2-2927ed48df52}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{d236e6e8-ade7-48e9-bc46-9f000b385c58} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d236e6e8-ade7-48e9-bc46-9f000b385c58}\ deleted successfully.
File C:\WINDOWS\SYSTEM32\tefiwizu.dll not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders: digeste.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages:C:\WINDOWS\system32\awtsPJBT deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Documents and Settings\JERN\Local Settings\Temp\n.exn deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\LimeWire\LimeWire.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\SYSTEM32\winupdate86.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\Temp\rdl32E.tmp.exe deleted successfully.
C:\WINDOWS\Temp\rdl32E.tmp.exe moved successfully.
[Files/Folders - Created Within 30 Days]
C:\828be51ece8d9c1b7c7ec5 folder moved successfully.
C:\Program Files\Conduit\Community Alerts folder moved successfully.
C:\Program Files\Conduit folder moved successfully.
C:\Documents and Settings\JERN\Local Settings\Application Data\Conduit\Community Alerts\Log folder moved successfully.
C:\Documents and Settings\JERN\Local Settings\Application Data\Conduit\Community Alerts\LanguagePacks folder moved successfully.
C:\Documents and Settings\JERN\Local Settings\Application Data\Conduit\Community Alerts\Feeds folder moved successfully.
C:\Documents and Settings\JERN\Local Settings\Application Data\Conduit\Community Alerts folder moved successfully.
C:\Documents and Settings\JERN\Local Settings\Application Data\Conduit folder moved successfully.
C:\Documents and Settings\JERN\Local Settings\Application Data\CommentsBar_-_Social_Comments\UserDefinedItems folder moved successfully.
C:\Documents and Settings\JERN\Local Settings\Application Data\CommentsBar_-_Social_Comments\SearchInNewTab folder moved successfully.
C:\Documents and Settings\JERN\Local Settings\Application Data\CommentsBar_-_Social_Comments\RadioPlayer\Skins folder moved successfully.
C:\Documents and Settings\JERN\Local Settings\Application Data\CommentsBar_-_Social_Comments\RadioPlayer folder moved successfully.
C:\Documents and Settings\JERN\Local Settings\Application Data\CommentsBar_-_Social_Comments\MyStuffComponents folder moved successfully.
C:\Documents and Settings\JERN\Local Settings\Application Data\CommentsBar_-_Social_Comments\Logs folder moved successfully.
C:\Documents and Settings\JERN\Local Settings\Application Data\CommentsBar_-_Social_Comments\ExternalComponent folder moved successfully.
C:\Documents and Settings\JERN\Local Settings\Application Data\CommentsBar_-_Social_Comments\EmailNotifier folder moved successfully.
C:\Documents and Settings\JERN\Local Settings\Application Data\CommentsBar_-_Social_Comments\CacheIcons folder moved successfully.
C:\Documents and Settings\JERN\Local Settings\Application Data\CommentsBar_-_Social_Comments folder moved successfully.
C:\WINDOWS\002782_.tmp deleted successfully.
C:\WINDOWS\msdownld.tmp folder deleted successfully.
C:\WINDOWS\System32\CONFIG.TMP deleted successfully.
C:\WINDOWS\System32\dfhkj.tmp deleted successfully.
C:\WINDOWS\System32\feretizi.dll.tmp deleted successfully.
C:\WINDOWS\System32\huhibimi.dll.tmp deleted successfully.
C:\WINDOWS\System32\mcrh.tmp deleted successfully.
C:\WINDOWS\System32\puyudupu.dll.tmp deleted successfully.
C:\WINDOWS\System32\SETD9.tmp deleted successfully.
C:\WINDOWS\System32\SETE5.tmp deleted successfully.
C:\WINDOWS\System32\SETEE.tmp deleted successfully.
C:\WINDOWS\System32\SETEF.tmp deleted successfully.
C:\WINDOWS\System32\SETF0.tmp deleted successfully.
C:\WINDOWS\System32\SETF3.tmp deleted successfully.
[Files/Folders - Modified Within 30 Days]
C:\WINDOWS\System32\bunazuto moved successfully.
C:\WINDOWS\tasks\User_Feed_Synchronization-{7C9E5EF1-6217-432C-8F62-C78A0787AA55}.job moved successfully.
C:\WINDOWS\tasks\iqsacgyb.job moved successfully.
C:\WINDOWS\tasks\icknfiop.job moved successfully.
C:\WINDOWS\System32\tmp.reg moved successfully.
C:\WINDOWS\System32\4827.exe moved successfully.
C:\WINDOWS\System32\11942.exe moved successfully.
C:\WINDOWS\System32\2995.exe moved successfully.
C:\WINDOWS\System32\491.exe moved successfully.
C:\WINDOWS\System32\9961.exe moved successfully.
C:\WINDOWS\System32\16827.exe moved successfully.
C:\WINDOWS\System32\23281.exe moved successfully.
C:\WINDOWS\System32\28145.exe moved successfully.
C:\WINDOWS\System32\5705.exe moved successfully.
C:\WINDOWS\System32\24464.exe moved successfully.
C:\WINDOWS\System32\26962.exe moved successfully.
C:\WINDOWS\System32\29358.exe moved successfully.
C:\WINDOWS\System32\11478.exe moved successfully.
C:\WINDOWS\System32\15724.exe moved successfully.
C:\WINDOWS\System32\19169.exe moved successfully.
C:\WINDOWS\System32\26500.exe moved successfully.
C:\WINDOWS\System32\6334.exe moved successfully.
C:\WINDOWS\System32\18467.exe moved successfully.
C:\WINDOWS\System32\5436.exe moved successfully.
C:\WINDOWS\System32\winlogon86.exe moved successfully.
C:\WINDOWS\Temp\Cab169.tmp deleted successfully.
C:\WINDOWS\Temp\Cab182.tmp deleted successfully.
C:\WINDOWS\Temp\Cab286.tmp deleted successfully.
C:\WINDOWS\Temp\Cab337.tmp deleted successfully.
C:\WINDOWS\Temp\Cab3C2.tmp deleted successfully.
C:\WINDOWS\Temp\Cab3C5.tmp deleted successfully.
C:\WINDOWS\Temp\KWI1DA.tmp folder deleted successfully.
C:\WINDOWS\Temp\mca71.tmp folder deleted successfully.
C:\WINDOWS\Temp\mca72.tmp folder deleted successfully.
C:\WINDOWS\Temp\mca73.tmp\avvclean.dat deleted successfully.
C:\WINDOWS\Temp\mca73.tmp\avvnames.dat deleted successfully.
C:\WINDOWS\Temp\mca73.tmp\avvscan.dat deleted successfully.
C:\WINDOWS\Temp\mca73.tmp\gdeltaavv.ini deleted successfully.
C:\WINDOWS\Temp\mca73.tmp\mferuntime.dat deleted successfully.
C:\WINDOWS\Temp\mca73.tmp folder deleted successfully.
C:\WINDOWS\Temp\mca74.tmp\config.dat deleted successfully.
C:\WINDOWS\Temp\mca74.tmp\mc5300up.001 deleted successfully.
C:\WINDOWS\Temp\mca74.tmp\mcscan32.dll deleted successfully.
C:\WINDOWS\Temp\mca74.tmp\signlic.txt deleted successfully.
C:\WINDOWS\Temp\mca74.tmp folder deleted successfully.
C:\WINDOWS\Temp\mca75.tmp folder deleted successfully.
C:\WINDOWS\Temp\mca76.tmp\avvclean.dat deleted successfully.
C:\WINDOWS\Temp\mca76.tmp\avvnames.dat deleted successfully.
C:\WINDOWS\Temp\mca76.tmp\avvscan.dat deleted successfully.
C:\WINDOWS\Temp\mca76.tmp\gdeltaavv.ini deleted successfully.
C:\WINDOWS\Temp\mca76.tmp folder deleted successfully.
C:\WINDOWS\Temp\rdl15.tmp deleted successfully.
C:\WINDOWS\Temp\rdl16.tmp deleted successfully.
C:\WINDOWS\Temp\rdl32E.tmp deleted successfully.
C:\WINDOWS\Temp\rdl55.tmp deleted successfully.
C:\WINDOWS\Temp\si2F1.tmp deleted successfully.
C:\WINDOWS\Temp\si37.tmp deleted successfully.
C:\WINDOWS\Temp\si43.tmp deleted successfully.
C:\WINDOWS\Temp\siE.tmp deleted successfully.
C:\WINDOWS\Temp\Tar16A.tmp deleted successfully.
C:\WINDOWS\Temp\Tar183.tmp deleted successfully.
C:\WINDOWS\Temp\Tar287.tmp deleted successfully.
C:\WINDOWS\Temp\Tar338.tmp deleted successfully.
C:\WINDOWS\Temp\Tar3C6.tmp deleted successfully.
C:\WINDOWS\Temp\TFR4CC.tmp deleted successfully.
C:\WINDOWS\Temp\tmp10D.tmp deleted successfully.
C:\WINDOWS\Temp\tmp70.tmp deleted successfully.
C:\WINDOWS\Temp\UPD77.tmp\updclean.dat deleted successfully.
C:\WINDOWS\Temp\UPD77.tmp\updnames.dat deleted successfully.
C:\WINDOWS\Temp\UPD77.tmp\updscan.dat deleted successfully.
C:\WINDOWS\Temp\UPD77.tmp folder deleted successfully.
C:\WINDOWS\Temp\UPD7B.tmp\updscan.dat deleted successfully.
C:\WINDOWS\Temp\UPD7B.tmp folder deleted successfully.
C:\WINDOWS\Temp\zg9tyd2n.TMP deleted successfully.
C:\WINDOWS\Temp\~nsu.tmp folder deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\12F.tmp folder deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\130.tmp\XP.mac deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\130.tmp folder deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\AB.tmp\Assoc.cmd deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\AB.tmp\dds.cmd deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\AB.tmp\DDS.txt deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\AB.tmp\edS.exe deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\AB.tmp\etPathS.exe deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\AB.tmp\evP.exe deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\AB.tmp\ffdefstr.dll deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\AB.tmp\MSClsid.exe deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\AB.tmp\MSGB.pif deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\AB.tmp\notifykeysB.com deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\AB.tmp\osidDDS.pif deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\AB.tmp\OSProp.pif deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\AB.tmp\Policies.exe deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\AB.tmp\RegX64.cmd deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\AB.tmp\Screentxt deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\AB.tmp\StartUp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\AB.tmp\svclist.dat deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\AB.tmp\SvcWhtDDS.dll deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\AB.tmp\SvcWhtDDSVista.dll deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\AB.tmp\SvcWhtDDSW7.dll deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\AB.tmp\wregS.exe deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\AB.tmp\XP.mac deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\AB.tmp folder deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\Acr329.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DCA960DB.TMP deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO10.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO12.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO13.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO15.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO18.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO19.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO1A.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO1B.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO1C.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO1D.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO1F.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO21.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO24.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO25.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO26.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO27.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO28.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO29.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO2A.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO2B.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO2C.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO2D.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO2E.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO2F.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO30.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO31.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO32.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO33.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO34.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO35.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO36.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO37.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO38.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO39.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO3A.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO3B.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO3C.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO3D.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO3E.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO3F.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO40.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO41.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO42.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO43.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO44.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO45.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO46.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO47.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO48.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO49.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO4A.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO4B.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO4C.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO4D.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO4E.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO4F.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO50.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO51.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO52.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO53.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO54.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO55.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO56.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO57.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO58.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO59.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO5A.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO5B.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO5C.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO5D.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO5E.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO5F.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO60.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO61.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO62.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO63.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO64.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO65.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO66.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO67.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO68.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO69.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO6A.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO6B.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO6C.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO6D.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO6E.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO6F.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO70.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO71.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO72.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO73.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO74.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO75.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO76.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO77.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO78.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO79.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO7A.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO7B.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO7C.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO7D.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO7E.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO7F.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO80.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO81.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO82.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO83.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO84.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO85.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO86.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO87.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO88.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO89.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO8A.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO8B.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO8C.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO8D.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO8E.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO8F.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO91.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO95.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\DIO96.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\jar_cache5062164204611841584.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\jar_cache5861376124862564097.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\jar_cache8013622719038988216.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR10.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR11.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR13.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR14.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR15.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR16.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR17.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR18.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR19.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR1A.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR1B.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR1C.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR1D.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR1E.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR1F.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR20.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR21.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR22.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR23.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR24.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR25.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR26.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR27.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR28.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR29.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR2A.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR2B.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR2C.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR2D.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR2E.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR2F.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR30.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR31.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR32.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR33.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR34.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR35.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR36.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR37.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR38.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR39.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR3A.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR3B.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR3C.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR3D.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR3E.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR3F.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR40.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR41.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR42.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR43.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR44.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR45.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR46.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR47.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR48.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR49.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR4A.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR4B.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR4C.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR4D.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR4E.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR4F.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR50.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR51.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR52.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR53.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR54.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR55.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR56.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR57.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR58.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR59.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR5A.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR5B.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR5C.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR5D.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR5E.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR5F.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR60.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR61.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR62.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR63.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR64.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR65.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR66.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR67.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR68.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR69.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR6A.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR6B.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR6C.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR6D.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR6E.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR6F.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR70.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR71.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR72.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR73.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR74.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR75.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR76.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR77.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR78.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR79.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR7A.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR7B.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MAR7C.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MARE.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\MARF.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\nsm6B.tmp\tbinstimp.dll deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\nsm6B.tmp folder deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\nsq6D.tmp folder deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\nst75.tmp folder deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\pcf8.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\pcf9.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\Saf224.tmp\Amtrak_W34.pdf deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\Saf224.tmp folder deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\tmp82.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\ycp68.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\ycp69.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DF1765.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DF29D5.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DF3CBB.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DF4A38.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DF56A5.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DF6444.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DF6C92.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DF70C2.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DF765F.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DF8300.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DF8DAA.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DF8E01.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DF93F5.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DF9A50.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DF9BCD.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DFA081.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DFA425.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DFACDB.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DFB9C9.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DFC20F.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DFC211.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DFD12D.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DFD7CD.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DFDB26.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DFDFBF.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DFE8A6.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DFE8BE.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~DFE920.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~WRC0000.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~WRF0001.tmp deleted successfully.
C:\Documents and Settings\JERN\Local Settings\Temp\~WRS0000.tmp deleted successfully.
[Files - No Company Name]
File C:\WINDOWS\System32\tmp.reg not found!
File C:\WINDOWS\tasks\iqsacgyb.job not found!
File C:\WINDOWS\System32\5436.exe not found!
File C:\WINDOWS\System32\4827.exe not found!
File C:\WINDOWS\System32\11942.exe not found!
File C:\WINDOWS\System32\2995.exe not found!
File C:\WINDOWS\System32\491.exe not found!
File C:\WINDOWS\System32\9961.exe not found!
File C:\WINDOWS\System32\16827.exe not found!
File C:\WINDOWS\System32\23281.exe not found!
File C:\WINDOWS\System32\28145.exe not found!
File C:\WINDOWS\System32\5705.exe not found!
File C:\WINDOWS\System32\24464.exe not found!
File C:\WINDOWS\System32\26962.exe not found!
File C:\WINDOWS\System32\29358.exe not found!
File C:\WINDOWS\System32\11478.exe not found!
File C:\WINDOWS\System32\15724.exe not found!
File C:\WINDOWS\System32\19169.exe not found!
File C:\WINDOWS\System32\26500.exe not found!
File C:\WINDOWS\System32\6334.exe not found!
File C:\WINDOWS\System32\18467.exe not found!
File C:\WINDOWS\System32\winlogon86.exe not found!
File C:\WINDOWS\System32\tefiwizu.dll not found!
DllUnregisterServer procedure not found in C:\WINDOWS\System32\ripeyoji.dll
C:\WINDOWS\System32\ripeyoji.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\System32\giwasora.dll
C:\WINDOWS\System32\giwasora.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\System32\wubedige.dll
C:\WINDOWS\System32\wubedige.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\System32\kogonubo.dll
C:\WINDOWS\System32\kogonubo.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\System32\fibanana.dll
C:\WINDOWS\System32\fibanana.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\System32\sezulono.dll
C:\WINDOWS\System32\sezulono.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\System32\wolayuga.dll
C:\WINDOWS\System32\wolayuga.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\System32\relereni.dll
C:\WINDOWS\System32\relereni.dll moved successfully.
File C:\WINDOWS\System32\kosagiti.dll not found!
DllUnregisterServer procedure not found in C:\WINDOWS\System32\kobitaka.dll
C:\WINDOWS\System32\kobitaka.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\System32\dorulelo.dll
C:\WINDOWS\System32\dorulelo.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\System32\tukideka.dll
C:\WINDOWS\System32\tukideka.dll moved successfully.
C:\WINDOWS\System32\TBJPstwa.ini2 moved successfully.
C:\WINDOWS\System32\TBJPstwa.ini moved successfully.
C:\WINDOWS\System32\eKRsYcdd.ini2 moved successfully.
C:\WINDOWS\System32\eKRsYcdd.ini moved successfully.
C:\WINDOWS\System32\TtCIOXyb.ini2 moved successfully.
C:\WINDOWS\System32\TtCIOXyb.ini moved successfully.
C:\WINDOWS\System32\dfhkj.ini2 moved successfully.
[Empty Temp Folders]


User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: JERN
->Temp folder emptied: 146107139 bytes
->Temporary Internet Files folder emptied: 40622618 bytes
->Java cache emptied: 44744355 bytes
->Apple Safari cache emptied: 187701328 bytes

User: KAYLA
->Temp folder emptied: 9653034 bytes
->Temporary Internet Files folder emptied: 232702722 bytes
->Java cache emptied: 215072 bytes

User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NATALIE
->Temp folder emptied: 2111904726 bytes
->Temporary Internet Files folder emptied: 125345137 bytes
->Java cache emptied: 283809 bytes

User: NetworkService
->Temp folder emptied: 41116 bytes
->Temporary Internet Files folder emptied: 168593720 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
Windows Temp folder emptied: 40201689 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 23951130 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 53262 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = -1108.85 mb

< End of fix log >
OTS by OldTimer - Version 3.1.8.4 fix logfile created on 12042009_163521

Files\Folders moved on Reboot…
File move failed. C:\WINDOWS\temp\hlktmp scheduled to be moved on reboot.
File\Folder C:\WINDOWS\temp\mcmsc_Gsaa1swZ7kHsXY3 not found!
C:\WINDOWS\temp\mcmsc_QPgiImFi5Ut1oEI moved successfully.

Registry entries deleted on Reboot…


ComboFix 09-12-04.02 - JERN 12/04/2009 17:03.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.168 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\JERN\Application Data\FunWebProducts
c:\documents and settings\JERN\Application Data\FunWebProducts\Data\JERN\avatar.dat
c:\documents and settings\JERN\Application Data\FunWebProducts\Data\JERN\outfit.dat
c:\documents and settings\JERN\Application Data\FunWebProducts\Data\JERN\register.dat
c:\documents and settings\JERN\Application Data\FunWebProducts\Data\JERN\zbucks.dat
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\AutoRun.inf
c:\windows\system32\bszip.dll
c:\windows\SYSTEM32\dfhkj.bak2
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
c:\windows\wiaserviv.log

.
((((((((((((((((((((((((( Files Created from 2009-11-05 to 2009-12-05 )))))))))))))))))))))))))))))))
.

2009-12-05 00:35 . 2009-12-05 00:35 ——– d—–w- C:\_OTS
2009-12-04 00:32 . 2009-12-04 00:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-04 00:32 . 2009-12-04 00:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-04 00:32 . 2009-12-04 00:13 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-04 00:19 . 2009-12-04 00:19 ——– d—–w- c:\documents and settings\JERN\Application Data\Malwarebytes
2009-12-04 00:13 . 2009-12-04 03:42 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-03 03:16 . 2009-12-03 03:17 ——– d—–w- c:\program files\ERUNT
2009-12-02 03:31 . 2009-12-02 03:31 ——– d—–w- c:\windows\system32\drivers\NSS
2009-12-02 03:31 . 2009-12-02 03:31 ——– d—–w- c:\program files\Norton Security Scan
2009-12-02 03:31 . 2009-12-02 03:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2009-12-02 03:30 . 2009-12-02 03:30 ——– d—–w- c:\program files\NortonInstaller
2009-12-02 03:30 . 2009-12-02 03:30 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-12-01 00:48 . 2009-12-01 00:48 22528 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{AA8B1B0E-B143-2755-083D-307523617344}-winhelper86.dll
2009-12-01 00:48 . 2009-12-01 00:48 52224 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{FACCB2B2-66E3-E697-4E4F-7EAD9E5A17E2}-kosagiti.dll
2009-12-01 00:48 . 2009-12-01 00:48 93184 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{467D38FC-6AAE-9666-145D-3B5D1F18322F}-lehebofi.dll
2009-12-01 00:48 . 2009-12-01 00:48 18944 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{4AB47B73-553D-99FC-4320-A32D28F3F314}-winupdate86.exe
2009-11-30 23:41 . 2009-11-03 04:42 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-11-30 23:28 . 2009-11-30 23:31 ——– d—–w- c:\program files\Microsoft Security Essentials
2009-11-30 23:28 . 2009-08-07 03:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2009-11-30 23:28 . 2009-08-07 03:23 215920 —-a-w- c:\windows\system32\muweb.dll
2009-11-30 22:50 . 2009-11-30 22:57 ——– d—–w- c:\program files\Angle Interactive
2009-11-30 22:50 . 2009-11-30 22:50 ——– d—–w- C:\ProgramData
2009-11-29 23:32 . 2009-11-29 23:32 ——– d—–w- c:\program files\Common Files\Scanner
2009-11-29 23:32 . 2009-11-29 23:37 ——– d—–w- c:\program files\CA Yahoo! Anti-Spy
2009-11-29 19:59 . 2004-08-04 10:00 5632 —-a-w- c:\windows\system32\dllcache\smimsgif.dll
2009-11-29 19:59 . 2004-08-04 10:00 5632 —-a-w- c:\windows\system32\dllcache\smierrsy.dll
2009-11-29 19:59 . 2004-08-04 10:00 15872 —-a-w- c:\windows\system32\dllcache\smierrsm.dll
2009-11-29 19:59 . 2004-08-04 10:00 10240 —-a-w- c:\windows\system32\wbem\snmpstup.dll
2009-11-29 19:59 . 2004-08-04 10:00 10240 —-a-w- c:\windows\system32\dllcache\snmpstup.dll
2009-11-12 00:23 . 2009-11-12 00:23 1408800 —-a-w- c:\documents and settings\JERN\Application Data\Move Networks\MoveMediaPlayerWin_071505000011.exe
2009-11-06 23:44 . 2009-11-06 23:44 152576 —-a-w- c:\documents and settings\JERN\Application Data\Sun\Java\jre1.6.0_17\lzma.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-04 23:00 . 2005-05-25 02:22 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-12-02 03:31 . 2005-05-25 02:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-12-01 01:26 . 2008-05-24 03:48 ——– d—–w- c:\program files\Windows Live Safety Center
2009-11-30 22:02 . 2005-08-02 03:55 11094 —-a-w- c:\documents and settings\JERN\Application Data\wklnhst.dat
2009-11-30 05:12 . 2008-05-08 16:40 ——– d—–w- c:\program files\Windows Media Connect 2
2009-11-29 23:31 . 2006-09-29 04:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-11-29 23:30 . 2006-09-29 04:30 ——– d—–w- c:\documents and settings\All Users\Application Data\yahoo!
2009-11-29 23:30 . 2006-09-29 04:29 ——– d—–w- c:\program files\Yahoo!
2009-11-29 23:30 . 2006-09-29 04:50 ——– d–h–r- c:\documents and settings\JERN\Application Data\yahoo!
2009-11-29 23:09 . 2005-06-06 03:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Kodak
2009-11-29 20:09 . 2005-06-06 03:48 ——– d—–w- c:\program files\Kodak
2009-11-20 01:29 . 2008-03-10 04:57 ——– d—–w- c:\program files\McAfee
2009-11-12 00:23 . 2009-10-01 20:46 127325 —-a-w- c:\documents and settings\JERN\Application Data\Move Networks\uninstall.exe
2009-11-12 00:23 . 2009-04-02 19:54 ——– d—–w- c:\documents and settings\JERN\Application Data\Move Networks
2009-11-12 00:23 . 2009-08-13 19:21 4187512 —-a-w- c:\documents and settings\JERN\Application Data\Move Networks\plugins\npqmp071505000011.dll
2009-11-11 01:32 . 2009-10-11 19:48 55792 —ha-w- c:\windows\system32\mlfcache.dat
2009-11-06 23:48 . 2005-05-25 02:09 ——– d—–w- c:\program files\Java
2009-10-30 22:59 . 2005-08-19 13:42 85648 -c–a-w- c:\documents and settings\JERN\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-30 22:58 . 2009-10-30 22:39 ——– d—–w- c:\program files\Web Publish
2009-10-30 22:41 . 2005-05-25 02:10 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-10-30 22:41 . 2009-10-30 22:12 ——– d—–w- c:\program files\Common Files\Broderbund
2009-10-30 22:41 . 2009-10-30 22:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Broderbund
2009-10-30 22:12 . 2009-10-30 22:12 ——– d—–w- c:\documents and settings\All Users\Application Data\Broderbund Software
2009-10-30 22:11 . 2009-10-30 22:11 ——– d—–w- c:\program files\Broderbund
2009-10-19 22:44 . 2009-05-31 20:54 ——– d—–w- c:\program files\PokerStars
2009-10-15 19:06 . 2009-06-05 21:29 ——– d—–w- c:\documents and settings\JERN\Application Data\ZoomBrowser EX
2009-10-15 18:58 . 2009-06-05 21:32 ——– d—–w- c:\documents and settings\JERN\Application Data\CameraWindowDC
2009-10-11 12:17 . 2009-02-23 04:23 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-10-01 20:46 . 2009-08-03 21:48 4187512 —-a-w- c:\documents and settings\JERN\Application Data\Move Networks\plugins\npqmp071505000010.dll
2009-10-01 20:46 . 2009-10-01 20:45 1407680 —-a-w- c:\documents and settings\JERN\Application Data\Move Networks\MoveMediaPlayerWin_071505000010.exe
2009-09-16 17:22 . 2008-03-10 04:58 40552 —-a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-09-16 17:22 . 2008-03-10 04:58 35272 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2009-09-16 17:22 . 2008-03-10 04:58 79816 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-09-16 17:22 . 2008-03-10 04:58 214664 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2009-09-16 17:22 . 2008-03-10 04:58 34248 —-a-w- c:\windows\system32\drivers\mferkdk.sys
2009-09-11 14:18 . 2004-08-04 10:00 136192 —-a-w- c:\windows\system32\msv1_0.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER" [X]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb12.exe" [2004-12-14 176128]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2009-09-14 1048392]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-4 258048]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-4 53248]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\67524439319544509788515526783771

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Intel\\Modem Event Monitor\\IntelMEM.exe"=
"c:\\Program Files\\McAfee.com\\Agent\\mcagent.exe"=
"c:\\Program Files\\DellSupport\\DSAgnt.exe"=
"c:\\Program Files\\McAfee\\VirusScan\\mcsysmon.exe"=

S3 dump_wmimmc;dump_wmimmc;\??\c:\nexon\MapleStory\GameGuard\dump_wmimmc.sys –> c:\nexon\MapleStory\GameGuard\dump_wmimmc.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2009-08-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:34]

2008-09-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2008-03-10 19:22]

2009-11-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2008-03-10 19:22]

2009-12-05 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2009-07-03 01:36]

2009-12-04 c:\windows\Tasks\Norton Security Scan for JERN.job
- c:\program files\Norton Security Scan\Engine\2.3.0.44\Nss.exe [2009-12-02 03:58]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mWindow Title = Microsoft Internet Explorer presented by Comcast
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office10\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe
.
.
——- File Associations ——-
.
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-jidopijen - c:\windows\system32\tefiwizu.dll
SharedTaskScheduler-{d236e6e8-ade7-48e9-bc46-9f000b385c58} - c:\windows\system32\tefiwizu.dll
SSODL-gehahetif-{d236e6e8-ade7-48e9-bc46-9f000b385c58} - c:\windows\system32\tefiwizu.dll
AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-04 17:21
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(4072)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Essentials\MsMpEng.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\program files\Real\RealPlayer\RealPlay.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\windows\system32\HPZipm12.exe
c:\windows\System32\snmp.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\HP\Digital Imaging\bin\hpqgalry.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Yahoo!\Messenger\ymsgr_tray.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-12-04 17:44 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-05 01:44

Pre-Run: 51,569,438,720 bytes free
Post-Run: 51,328,126,976 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 16C937FF499A92CCE955931999B2D32D



Wow you're awsome!!! Things seem back to normal, except as i'm typing it is going super slow and my clock is still in army time.

Can i delete everything you had me install? and can i turn my virus protection back on?
You seem to have signs of McAfee, Microsoft Security Essential and Norton running on your computer. Did your subscription recently expire to Norton and/or McAfee? It is never advisable to run more than one Anti-Virus or Firewall program. Please make sure you let me know what your current situation is regarding the above programs in your next reply.

Wow you're awsome!!! Things seem back to normal, except as i'm typing it is going super slow and my clock is still in army time.

Can i delete everything you had me install? and can i turn my virus protection back on?

We still have a little bit of work to do. For the time being leave the programs that I had you install. We will remove those once we get you all cleaned up.

For your clock issue:
1. Click Start > Settings > Control Panel
2. Double-Click Regional and Language Options
3. Click the Time tab
4. Click the Customize button
5. Choose HH:mm:ss
6. Click Apply
7. Click OK

Please Note: In order for this change to take affect it may be necessary for your computer to be rebooted.

Malwarebytes' Anti-Malware

I see that you have Malwarebytes' Anti-Malware installed on your computer could you please do a scan using these settings:

  • Open Malwarebytes' Anti-Malware
  • Select the Update tab
  • Click Check for Updates
  • After the update have been completed, Select the Scanner tab.
  • Select Perform quick scan, then click on Scan
  • Leave the default options as it is and click on Start Scan
  • When done, you will be prompted. Click OK, then click on Show Results
  • Checked (ticked) all items and click on Remove Selected
  • After it has removed the items, Notepad will open. Please post this log in your next reply. You can also find the log in the Logs tab. The bottom most log is the latest
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

*Note
It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Please make sure you include the following items in your next post:
1. An answer to my question in regards to your security program situation.
2. The log that was produced after running MalwareBytes' Anti-Malware
3. The log that was produced after running ESET Online Scan.
My primary virus protection is McAfee. but earlier in the week when these problems began,( I felt my McAfee failed me) I downloaded Microsoft security essential first and then Norton. That was before i found you! I was planning on uninstalling them. Malwarebytes' Anti-Malware 1.42 Database version: 3302 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 12/5/2009 5:35:19 PM mbam-log-2009-12-05 (17-35-19).txt Scan type: Quick Scan Objects scanned: 125142 Time elapsed: 8 minute(s), 51 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 3 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 6 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{d2a2595c-4fe4-4315-aa9b-19dbd6271b71} (Adware.PriceGong) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Program Files\MyWaySA (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files\MyWaySA\SrchAsDe (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files\MyWaySA\SrchAsDe\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files\Angle Interactive\RD2010 (Rogue.RegDefender) -> Quarantined and deleted successfully. C:\Documents and Settings\JERN\Application Data\PriceGong (Adware.PriceGong) -> Quarantined and deleted successfully. C:\Documents and Settings\JERN\Application Data\PriceGong\Data (Adware.PriceGong) -> Quarantined and deleted successfully. Files Infected: C:\Program Files\Angle Interactive\RD2010\Uninstall.exe (Rogue.RegDefender) -> Quarantined and deleted successfully. C:\Documents and Settings\JERN\Desktop\explorer.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\dfhkj.bak2.vir Win32/Adware.Virtumonde.NEO application C:\_OTS\MovedFiles\12042009_163521\C_WINDOWS\SYSTEM32\dfhkj.ini2 Win32/Adware.Virtumonde.NEO application C:\_OTS\MovedFiles\12042009_163521\C_WINDOWS\SYSTEM32\dorulelo.dll a variant of Win32/Kryptik.BGQ trojan C:\_OTS\MovedFiles\12042009_163521\C_WINDOWS\SYSTEM32\eKRsYcdd.ini Win32/Adware.Virtumonde.NEO application C:\_OTS\MovedFiles\12042009_163521\C_WINDOWS\SYSTEM32\eKRsYcdd.ini2 Win32/Adware.Virtumonde.NEO application C:\_OTS\MovedFiles\12042009_163521\C_WINDOWS\SYSTEM32\fibanana.dll a variant of Win32/Adware.Virtumonde.NGJ application C:\_OTS\MovedFiles\12042009_163521\C_WINDOWS\SYSTEM32\giwasora.dll a variant of Win32/Adware.Virtumonde.NGJ application C:\_OTS\MovedFiles\12042009_163521\C_WINDOWS\SYSTEM32\kobitaka.dll a variant of Win32/Kryptik.BGQ trojan C:\_OTS\MovedFiles\12042009_163521\C_WINDOWS\SYSTEM32\kogonubo.dll a variant of Win32/KillAV.NGT trojan C:\_OTS\MovedFiles\12042009_163521\C_WINDOWS\SYSTEM32\kosagiti.dll a variant of Win32/Kryptik.BGQ trojan C:\_OTS\MovedFiles\12042009_163521\C_WINDOWS\SYSTEM32\relereni.dll a variant of Win32/KillAV.NGT trojan C:\_OTS\MovedFiles\12042009_163521\C_WINDOWS\SYSTEM32\sezulono.dll a variant of Win32/KillAV.NGT trojan C:\_OTS\MovedFiles\12042009_163521\C_WINDOWS\SYSTEM32\TBJPstwa.ini Win32/Adware.Virtumonde.NEO application C:\_OTS\MovedFiles\12042009_163521\C_WINDOWS\SYSTEM32\TBJPstwa.ini2 Win32/Adware.Virtumonde.NEO application C:\_OTS\MovedFiles\12042009_163521\C_WINDOWS\SYSTEM32\TtCIOXyb.ini Win32/Adware.Virtumonde.NEO application C:\_OTS\MovedFiles\12042009_163521\C_WINDOWS\SYSTEM32\TtCIOXyb.ini2 Win32/Adware.Virtumonde.NEO application C:\_OTS\MovedFiles\12042009_163521\C_WINDOWS\SYSTEM32\tukideka.dll a variant of Win32/Kryptik.BGQ trojan C:\_OTS\MovedFiles\12042009_163521\C_WINDOWS\SYSTEM32\winlogon86.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\_OTS\MovedFiles\12042009_163521\C_WINDOWS\SYSTEM32\wolayuga.dll a variant of Win32/KillAV.NGT trojan C:\_OTS\MovedFiles\12042009_163521\C_WINDOWS\SYSTEM32\wubedige.dll a variant of Win32/KillAV.NGT trojan C:\_OTS\MovedFiles\12042009_163521\C_WINDOWS\Temp\rdl32E.tmp.exe Win32/TrojanDownloader.FakeAlert.AED trojan

My primary virus protection is McAfee. but earlier in the week when these problems began,( I felt my McAfee failed me) I downloaded Microsoft security essential first and then Norton. That was before i found you! I was planning on uninstalling them.

Now would be the appropriate time to remove those that you do not plan on keeping. If you are going to uninstall Norton please make sure you use this tool below:

Remove Norton Tool

ONLY if you don't have an active subscription, use below link to uninstall Norton.

Please click HERE and follow the instructions to download and run the Norton Removal Tool for your own version.

It is strongly recommended that you run only one anti-virus program at a time. Having more than one anti-virus program active in memory uses additional resources and can result in program conflicts and false virus alerts.

Update Adobe Reader
Earlier versions of Adobe Reader have known security flaws so it is recommended that you update your copy
  • Go to Start > Control Panel > Add/Remove Programs
  • Remove ALL instances of Adobe Reader
  • Re-boot your computer as required.
  • Once ALL versions of Adobe Reader have been uninstalled, visit: <> and download the latest version of Adobe Reader
Alternative Option: after uninstalling Adobe Reader, you could try installing Foxit Reader from >here< Foxit Reader has fewer add-ons therefore loads more quickly.

Java Outdated
You currently have the latest version of Java; however, you have older version still installed on your computer. Older versions can have vulnerabilities that malware can use to infect your system.
  • Now go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name. EXCEPT Java™ 6 Update 17
  • Click the Remove or Change/Remove button for the following versions:
    • J2SE Runtime Environment 5.0 Update 3
    • Java 2 Runtime Environment, SE v1.4.2_03
    • Java™ 6 Update 7
  • Repeat as many times as necessary to remove each Java version.
    • Go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window

    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.
Clean-Up Time
The following will implement some cleanup procedures as well as reset System Restore points:
[external image: Posted Image]
Click Start > Run and copy/paste the following bolded text into the Run box and click OK: ComboFix /Uninstall

OTS Clean-Up
  • Make sure you have an Internet Connection.
  • Double-click OTS.exe to run it. (Vista users, please right click on OTS.exe and select "Run as an Administrator")
  • Click on the CleanUp! button
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTS to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You should be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.
Any remaining logs are tools that are still on your computer can be deleted at this time.

All Clean Speech

===> Make sure you've re-enabled any Security Programs that we may have disabled during the malware removal process. <===

Below I have included a number of recommendations for how to protect your computer against malware infections.
  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at: http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.
  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.
  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.
  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE
  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from Here
    • If you choose to use Firefox, I highly recommend this add-on to keep your PC even more secure.
      • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.

Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
The Norton I downloaded is the Norton Security Scan which is not an option on the list of removal tools.

I followed your instructions to uninstall ComboFix (copy/paste) but received error message:

Windows cannot find 'ComboFix'. Make sure you typed the name correctly,….
According to this link Norton can be uninstalled via Add/Remove Programs.
Click Start > Settings > Control Panel.
Click Add or Remove Programs.
Click Norton Security Scan, and then click Remove.
yes, i copy/pasted exactly without quotes but same thing. I dont even have it on my desktop, I guess it's gone. Everything is looking good. Thank you so much for all your hard work!!!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI