This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] it all started with antivirus 2010 popups and webpage redir

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

:pullhair:

Hi,

ok, I am sure there is something going on here, the system is lagging badly, it was freezing completely, but now it hangs for almost 10 mins to open any web page, ie or firefox, or any program for that matter, it took 10 mins for HJT to open to be able to get a scan, I had a virus not long ago, the newest of the antivirus 2010 trojan, I did a clean with superantspyware 4.33 in safe mode, and ran trend micro after, it seemed to take care of the problem, but I think there are either reminants or something new, the disk cleanup keeps comming on and I have done it numerous times but it still shows up, the cpu's run from 1% to 100% and it keeps telling me I am low on disc space, I have removed alot of unused programs and the disc space was fine, now it seems to be back up again. and no one has downloaded anything, only web pages have been opened, and the updates have been done. so I'm guessing the virus scan has missed something or there might be something new.. I can find anything similar to my problem in the forum posts, so I am asking if someone can help please I hope this is enough info.
also there has been one blue screen of death come up (stack dump of physical memory) but I managed to stop it before it went. but it has been misbehaving and slow along with the disk cleanup tool constanly appearing.

Thankyou.
LFC

Also: would just like to say…that having just read something here in another topic about multiple posts on different sites , I would like to inform you that this log is posted on Tech Support Guys Forums and it was by suggestion within one of the tech notes From a tech at TSG to post on multiple sites and go with whom ever answered first, so that people arent waiting weeks for results and so that it doesnt over stress certain sites who are minimally staffed. so, could this rule be over looked please? as long as it stands clear that the member is aware that they are only to follow the one set of instructions of whom ever answers the post first, and in turn closes the post upon the other site so that its not taking away help from another member there?
and if its a nogo on the rule, then I guess this post will be closed by the mods.
otherwise..
Thankyou for your input and help.
Have a nice day.
")


syetem: MW XP Home
version 2002, service pack 3
pentium® 4CPU 2.40GHz
2.39 GHZ,512MB of RAM





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:43:57 PM, on 1/24/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\IOGear\ION\IoctlSvc.exe
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ca.rd.yahoo.com/customize/yco…..;//ca.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by SHAW Internet
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {49132671-36d0-4319-acbe-6fed9ae5715a} - C:\WINDOWS\system32\juvoguru.dll (file missing)
O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: (no name) - {5cb492ae-bc91-4a4f-a7f0-30f6c55728cc} - C:\WINDOWS\system32\fagesefa.dll (file missing)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [jowuzamaku] Rundll32.exe "C:\WINDOWS\system32\ronigofu.dll",s
O4 - HKLM\..\Run: [24f0ca60] rundll32.exe "C:\WINDOWS\system32\feyumaze.dll",b
O4 - HKLM\..\Run: [CPM27c3f9fc] Rundll32.exe "c:\windows\system32\wobupobu.dll",a
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [jowuzamaku] Rundll32.exe "C:\WINDOWS\system32\ronigofu.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [jowuzamaku] Rundll32.exe "C:\WINDOWS\system32\ronigofu.dll",s (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\TEIGAN\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/game…ts/y/at0_x.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com…..;/c381/chat.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/game…ts/y/it1_x.cab
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/game…ts/y/tt1_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/game…s/y/potc_x.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/…oUploader5.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary…r.cab56986.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/ho…vex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://bin.mcafee.com/molbin/shared/…6/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary…n.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-CA/…..;/GAME_UNO1.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/…toUploader.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/…Uploader55.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramewor…o.cab56649.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yaho…tocomplete.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary…t.cab56907.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01…l/MSNPUpld.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is…60/mcfscan.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\wejiwulo.dll c:\windows\system32\botapepe.dll c:\windows\system32\gafilumu.dll C:\WINDOWS\system32\lamisefi.dll ffzrka.dll c:\windows\system32\putevama.dll c:\windows\system32\wobupobu.dll cedyfe.dll c:\windows\system32\jahanane.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - (no file)
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - (no file)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Program Files\IOGear\ION\IoctlSvc.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe
O23 - Service: Retrospect Helper - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\rthlpsvc.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
O24 - Desktop Component 0: (no name) - file:///C:/Documents%20and%20Settings/tanja/My%20Documents/My%20Pictures/whatnots/my%20very%20own%20sigs/snags%20for%20tags/1more%20fantasy%20art/more/dragon.jpg
Hi lilfirecat69, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.


1st step

Please close both of your threads at TechGuy. Posting at multiple forums is frowned upon regardless of the advice given. Researching infections/logs can take considersble time in some cases. Multiple posting can still tie up multiple helpers just in research.

http://forums.techguy.org/malware-removal-…e-read-log.html

http://forums.techguy.org/malware-removal-…er-hanging.html



Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries




Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custon Scans/Fixes, copy and paste the following

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

No need for a Hijackthis log this time.

Please post back with
  • GMER log
  • both OTL logs
Hi, ok, the threads are closed on TSG. Now the problem I am having is, that I cant get Gmer to scan in normal mode, it keeps stackdumping, can I run this util in safe mode? also having dll errors at startup, but I believe they have to do with the super anti spyware quarintine,, I've written them down in case you want me to post them. and I also wrote down the error reporting log on the stack dump. please advise Thank you
Hi lilfirecat69, Yes try running GMER in safe mode. The dll errors, do they say something similar to unable find or load X dll? Thanks
yes all three say module not found.. as follows: RUNDLL: error loading c:\windows\system32\wobupobu.dll (all lower case) : error loading C:\WINDOWS\SYSTEM32\ronigofu.dll : error loading C:\WINDOWS\SYSTEM32\feyumaze.dll ok I will try to run Gmer when I get in from work this afternoon. Thankyou
Hi lilfirecat69, Thanks. I'll look for the logs later. If GMER will still not run even in safe mode, please proceed with the OTL scans. Thanks
I finally got Gmer scanning in safemode and went to save and she stackdumped again after 4 hrs of scanning lol oh well, the OTL scans ran ok though. here they are:
1st one:
OTL.Txt

OTL logfile created on: 1/27/2010 4:11:37 PM - Run 1
OTL by OldTimer - Version 3.1.26.0 Folder = C:\Documents and Settings\tanja\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 199.00 Mb Available Physical Memory | 39.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): c:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 0.20 Gb Free Space | 0.27% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DHGGS431
Current User Name: tanja
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\tanja\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe (Musicmatch, Inc.)
PRC - C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe (Musicmatch, Inc.)
PRC - C:\Program Files\Ahead\InCD\InCDsrv.exe (Nero AG)
PRC - C:\Program Files\Ahead\InCD\InCD.exe (Nero AG)
PRC - C:\Program Files\IOGear\ION\IoctlSvc.exe (Prolific Technology Inc.)
PRC - C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
PRC - C:\Program Files\Dantz\Retrospect\retrorun.exe (Dantz Development Corporation)
PRC - C:\WINDOWS\SYSTEM32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\SYSTEM32\LEXBCES.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\SYSTEM32\LEXPPS.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\SYSTEM32\cidaemon.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Logitech\QCDriver\LVComS.exe (Logitech Inc.)
PRC - C:\WINDOWS\SYSTEM32\CTsvcCDA.EXE (Creative Technology Ltd)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\tanja\Desktop\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (Imapi Helper) – C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe (Alex Feinman)
SRV - (InCDsrv) – C:\Program Files\Ahead\InCD\InCDsrv.exe (Nero AG)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (PLFlash DeviceIoControl Service) – C:\Program Files\IOGear\ION\IoctlSvc.exe (Prolific Technology Inc.)
SRV - (Retrospect Helper) – C:\Program Files\Dantz\Retrospect\rthlpsvc.exe (Dantz Development Corporation)
SRV - (RetroLauncher) – C:\Program Files\Dantz\Retrospect\retrorun.exe (Dantz Development Corporation)
SRV - (NVSvc) – C:\WINDOWS\SYSTEM32\nvsvc32.exe (NVIDIA Corporation)
SRV - (NetSvc) – C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation)
SRV - (LexBceS) – C:\WINDOWS\SYSTEM32\LEXBCES.EXE (Lexmark International, Inc.)
SRV - (TermService) – C:\WINDOWS\SYSTEM32\termsrv32.dll (Microsoft Corporation)
SRV - (Creative Service for CDROM Access) – C:\WINDOWS\SYSTEM32\CTsvcCDA.EXE (Creative Technology Ltd)


========== Driver Services (SafeList) ==========

DRV - (PxHelp20) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (fssfltr) – C:\WINDOWS\SYSTEM32\DRIVERS\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (amdagp) – C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (tmcomm) – C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys (Trend Micro Inc.)
DRV - (Secdrv) – C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (InCDfs) – C:\WINDOWS\SYSTEM32\DRIVERS\InCDfs.sys (Nero AG)
DRV - (InCDPass) – C:\WINDOWS\SYSTEM32\DRIVERS\InCDpass.sys (Nero AG)
DRV - (incdrm) – C:\WINDOWS\SYSTEM32\DRIVERS\InCDrm.sys (Nero AG)
DRV - (gameenum) – C:\WINDOWS\SYSTEM32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (iAimFP4) – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)
DRV - (iAimFP3) – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)
DRV - (iAimTV4) – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)
DRV - (iAimTV3) – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)
DRV - (iAimTV1) – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)
DRV - (iAimTV0) – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)
DRV - (iAimFP0) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)
DRV - (iAimFP1) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)
DRV - (iAimFP2) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)
DRV - (i81x) – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (Freedom) – C:\WINDOWS\freedom.backup.dat ()
DRV - (pfc) – C:\WINDOWS\SYSTEM32\DRIVERS\pfc.sys (Padus, Inc.)
DRV - (HSFHWBS2) – C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (nv) – C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (P16X) Creative SB Live! Series (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\P16X.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:\WINDOWS\SYSTEM32\DRIVERS\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\SYSTEM32\DRIVERS\ctoss2k.sys (Creative Technology Ltd.)
DRV - (mdmxsdk) – C:\WINDOWS\SYSTEM32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (E100B) Intel® – C:\WINDOWS\SYSTEM32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (ultra) – C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (sym_u3) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (Sparrow) – C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (ql1280) – C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (ql12160) – C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (Ptilink) – C:\WINDOWS\SYSTEM32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (mraid35x) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (dac2w2k) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (CmdIde) – C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (asc) – C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (LVBulk) – C:\WINDOWS\SYSTEM32\DRIVERS\LVBulk.sys (Logitech Inc.)
DRV - (QCDonner) Logitech QuickCam Express(PID_0840) – C:\WINDOWS\SYSTEM32\DRIVERS\lvcd.sys (Logitech Inc.)
DRV - (lusbaudio) – C:\WINDOWS\SYSTEM32\DRIVERS\LVSound2.sys (Logitech Inc.)
DRV - (LVVI500A) – C:\WINDOWS\SYSTEM32\DRIVERS\lvvi500a.sys (Tekom Technologies, Inc.)
DRV - (MODEMCSA) – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)
DRV - (ICAM5USB) Intel® – C:\WINDOWS\SYSTEM32\DRIVERS\Icam5USB.sys (Microsoft Corporation)
DRV - (mrtRate) – C:\WINDOWS\SYSTEM32\DRIVERS\MrtRate.sys (Marimba, Inc.)
DRV - (ScFBPNT3) – C:\WINDOWS\SYSTEM32\DRIVERS\ScFBPNT3.sys ()
DRV - (PfModNT) – C:\WINDOWS\SYSTEM32\PFMODNT.SYS (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ca.rd.yahoo.com/customize/ycomp/def…://ca.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:3.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/23 16:05:18 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/23 16:05:10 | 00,000,000 | —D | M]

[2008/11/01 10:49:18 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\Mozilla\Extensions
[2010/01/23 16:06:26 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\Mozilla\Firefox\Profiles\iz4ah2te.default\extensions
[2009/10/23 19:23:02 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\Mozilla\Firefox\Profiles\iz4ah2te.default\extensions\[removed]
[2010/01/23 22:02:08 | 00,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/03/03 21:06:21 | 00,000,423 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.igetnet.com
O1 - Hosts: 127.0.0.1 code.ignphrases.com
O1 - Hosts: 127.0.0.1 clear-search.com
O1 - Hosts: 127.0.0.1 r1.clrsch.com
O1 - Hosts: 127.0.0.1 sds.clrsch.com
O1 - Hosts: 127.0.0.1 status.clrsch.com
O1 - Hosts: 127.0.0.1 www.clrsch.com
O1 - Hosts: 127.0.0.1 clr-sch.com
O1 - Hosts: 127.0.0.1 sds-qckads.com
O1 - Hosts: 127.0.0.1 status.qckads.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {49132671-36d0-4319-acbe-6fed9ae5715a} - C:\WINDOWS\System32\juvoguru.dll File not found
O2 - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {5cb492ae-bc91-4a4f-a7f0-30f6c55728cc} - C:\WINDOWS\System32\fagesefa.dll File not found
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [24f0ca60] C:\WINDOWS\System32\feyumaze.DLL File not found
O4 - HKLM..\Run: [CPM27c3f9fc] C:\WINDOWS\System32\wobupobu.DLL File not found
O4 - HKLM..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe (Dell)
O4 - HKLM..\Run: [fssui] C:\Program Files\Windows Live\Family Safety\fsui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [jowuzamaku] C:\WINDOWS\System32\ronigofu.DLL File not found
O4 - HKLM..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVComS.exe (Logitech Inc.)
O4 - HKLM..\Run: [MimBoot] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mimboot.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\SYSTEM32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [NBJ] C:\Program Files\Ahead\Nero BackItUp\NBJ.exe (Ahead Software AG)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\SYSTEM32\Macromed\Flash\FlashUtil10c.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\tanja\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = _ [binary data]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideClock = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoManageMyComputerVerb = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuPinnedList = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoUserNameInStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartmenuLogoff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuSubFolders = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCommonGroups = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPrinterTabs = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAddPrinter = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPrinters = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetworkConnections = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetFolders = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoShellSearchButton = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarCustomize = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeAnimation = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeKeyboardNavigationIndicators = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThemesTab = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O8 - Extra context menu item: &Yahoo;! Search - C:\Program Files\Yahoo!\Common [2010/01/23 17:07:06 | 00,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &Dictionary; - C:\Program Files\Yahoo!\Common [2010/01/23 17:07:06 | 00,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &Maps; - C:\Program Files\Yahoo!\Common [2010/01/23 17:07:06 | 00,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &SMS; - C:\Program Files\Yahoo!\Common [2010/01/23 17:07:06 | 00,000,000 | —D | M]
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\TEIGAN\Start Menu\Programs\IMVU\Run IMVU.lnk ()
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: 21 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00000075-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/voxmsdec.CAB (Reg Error: Key error.)
O16 - DPF: {00000075-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/voxacm.CAB (Reg Error: Key error.)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (Reg Error: Key error.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {33363249-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/i263_32.cab (Reg Error: Key error.)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://bin.mcafee.com/molbin/shared/mcinsc…76/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo…otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…8175.5361689815 (Reg Error: Key error.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab (Reg Error: Key error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.4.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} http://download.mcafee.com/molbin/iss-loc/…360/mcfscan.cab (McFreeScan Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Backgammon http://download.games.yahoo.com/games/clients/y/at0_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Chat http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Cribbage http://download.games.yahoo.com/games/clients/y/it1_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Literati http://download.games.yahoo.com/games/clients/y/tt1_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Pool 2 http://download.games.yahoo.com/games/clients/y/potc_x.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\wejiwulo.dll) - C:\WINDOWS\System32\wejiwulo.dll File not found
O20 - AppInit_DLLs: (c:\windows\system32\botapepe.dll) - C:\WINDOWS\System32\botapepe.dll File not found
O20 - AppInit_DLLs: (c:\windows\system32\gafilumu.dll) - C:\WINDOWS\System32\gafilumu.dll File not found
O20 - AppInit_DLLs: (C:\WINDOWS\system32\lamisefi.dll) - C:\WINDOWS\System32\lamisefi.dll File not found
O20 - AppInit_DLLs: (ffzrka.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\putevama.dll) - C:\WINDOWS\System32\putevama.dll File not found
O20 - AppInit_DLLs: (c:\windows\system32\wobupobu.dll) - C:\WINDOWS\System32\wobupobu.dll File not found
O20 - AppInit_DLLs: (cedyfe.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\jahanane.dll) - C:\WINDOWS\System32\jahanane.dll File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - CLSID or File not found.
O22 - SharedTaskScheduler: {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - STS - Reg Error: Key error. File not found
O24 - Desktop Components:0 () - file:///C:/Documents%20and%20Settings/tanja/My%20Documents/My%20Pictures/whatnots/my%20very%20own%20sigs/snags%20for%20tags/1more%20fantasy%20art/more/dragon.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\tanja\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\tanja\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\SYSTEM32\IAS [2004/07/07 05:16:36 | 00,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\SYSTEM32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: TermService - C:\WINDOWS\SYSTEM32\termsrv32.dll (Microsoft Corporation)
NetSvcs: Ip6FwHlp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17173366603513856)

========== Files/Folders - Created Within 30 Days ==========

[2010/01/25 19:34:12 | 00,547,328 | —- | C] (OldTimer Tools) – C:\Documents and Settings\tanja\Desktop\OTL.exe
[2010/01/23 14:08:41 | 00,000,000 | —D | C] – C:\Documents and Settings\tanja\Application Data\vlc
[2010/01/23 14:02:58 | 00,000,000 | —D | C] – C:\Documents and Settings\tanja\My Documents\Graboid
[2010/01/23 13:19:52 | 00,000,000 | —D | C] – C:\Documents and Settings\tanja\Application Data\MozillaControl
[2010/01/23 13:19:48 | 00,000,000 | —D | C] – C:\Documents and Settings\tanja\Local Settings\Application Data\Graboid
[2010/01/23 13:18:56 | 00,000,000 | —D | C] – C:\Program Files\Mozilla ActiveX Control v1.7.12
[2010/01/23 13:17:26 | 00,000,000 | —D | C] – C:\Program Files\VideoLAN
[2010/01/23 13:16:52 | 00,000,000 | —D | C] – C:\Program Files\Graboid
[2010/01/12 13:15:34 | 00,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/01/12 13:15:34 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/01/12 13:15:34 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/01/12 13:10:22 | 00,471,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aclayers.dll
[2010/01/12 13:05:10 | 00,000,000 | —D | C] – C:\Program Files\Buddy Spy
[2009/11/06 19:37:01 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/11/06 19:32:08 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2008/11/21 13:52:02 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2008/11/01 11:19:15 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2007/08/06 12:15:57 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/05/08 16:30:14 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2007/05/08 16:08:07 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2006/12/16 19:38:32 | 00,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\tanja\Application Data\pcouffin.sys
[2006/07/01 14:46:19 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Help
[2006/07/01 14:46:19 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Help
[2006/07/01 09:48:47 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\ApplicationHistory
[2003/07/22 20:01:30 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2002/04/11 00:41:00 | 00,065,536 | —- | C] ( ) – C:\WINDOWS\System32\A3d.dll
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2099/01/01 12:00:00 | 00,098,304 | -HS- | M] () – C:\WINDOWS\System32\medilile.dll
[2010/01/27 16:27:00 | 00,000,412 | —- | M] () – C:\WINDOWS\tasks\Symantec NetDetect.job
[2010/01/27 16:25:00 | 00,000,424 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{2251EC52-B660-4E59-B002-5A66781184C0}.job
[2010/01/27 16:01:52 | 00,012,598 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/01/27 16:00:29 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/01/27 16:00:26 | 53,587,5584 | -HS- | M] () – C:\hiberfil.sys
[2010/01/27 16:00:26 | 00,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/01/26 22:48:09 | 14,942,208 | —- | M] () – C:\Documents and Settings\tanja\ntuser.dat
[2010/01/25 22:55:26 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\tanja\NTUSER.INI
[2010/01/25 22:43:55 | 02,096,656 | -H– | M] () – C:\Documents and Settings\tanja\Local Settings\Application Data\IconCache.db
[2010/01/25 21:21:25 | 00,169,467 | —- | M] () – C:\Documents and Settings\tanja\My Documents\error.JPG
[2010/01/25 20:44:15 | 53,590,4256 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2010/01/25 19:34:13 | 00,547,328 | —- | M] (OldTimer Tools) – C:\Documents and Settings\tanja\Desktop\OTL.exe
[2010/01/25 19:33:30 | 00,195,724 | —- | M] () – C:\Documents and Settings\tanja\My Documents\scrnsht maintenence instructions3.JPG
[2010/01/25 19:31:12 | 00,157,623 | —- | M] () – C:\Documents and Settings\tanja\My Documents\scrnsht maintenence instructions2.JPG
[2010/01/25 19:30:12 | 00,200,357 | —- | M] () – C:\Documents and Settings\tanja\My Documents\scrnsht maintenence instructions1.JPG
[2010/01/25 03:15:49 | 00,000,718 | —- | M] () – C:\WINDOWS\lexstat.ini
[2010/01/23 17:00:43 | 00,001,917 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/01/12 12:24:54 | 00,000,552 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/01/12 11:52:13 | 00,000,036 | —- | M] () – C:\Documents and Settings\tanja\Local Settings\Application Data\housecall.guid.cache
[2010/01/12 08:52:05 | 00,074,176 | —- | M] () – C:\Documents and Settings\tanja\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2099/01/01 12:00:00 | 00,127,777 | -HS- | C] () – C:\WINDOWS\System32\fiyobubi.dll
[2099/01/01 12:00:00 | 00,127,687 | -HS- | C] () – C:\WINDOWS\System32\vavefowi.dll
[2099/01/01 12:00:00 | 00,101,099 | -HS- | C] () – C:\WINDOWS\System32\gedekuye.dll
[2099/01/01 12:00:00 | 00,098,304 | -HS- | C] () – C:\WINDOWS\System32\medilile.dll
[2099/01/01 12:00:00 | 00,092,298 | —- | C] () – C:\WINDOWS\System32\bemevaja.dll
[2099/01/01 12:00:00 | 00,089,275 | -HS- | C] () – C:\WINDOWS\System32\bipehozo.dll
[2099/01/01 12:00:00 | 00,006,456 | -H– | C] () – C:\WINDOWS\System32\rowijoko
[2010/01/26 22:46:01 | 53,587,5584 | -HS- | C] () – C:\hiberfil.sys
[2010/01/25 21:21:24 | 00,169,467 | —- | C] () – C:\Documents and Settings\tanja\My Documents\error.JPG
[2010/01/25 19:33:30 | 00,195,724 | —- | C] () – C:\Documents and Settings\tanja\My Documents\scrnsht maintenence instructions3.JPG
[2010/01/25 19:31:12 | 00,157,623 | —- | C] () – C:\Documents and Settings\tanja\My Documents\scrnsht maintenence instructions2.JPG
[2010/01/25 19:30:12 | 00,200,357 | —- | C] () – C:\Documents and Settings\tanja\My Documents\scrnsht maintenence instructions1.JPG
[2010/01/24 13:42:27 | 00,001,599 | —- | C] () – C:\Remote Assistance.lnk
[2010/01/24 13:42:27 | 00,000,792 | —- | C] () – C:\Windows Media Player.lnk
[2010/01/12 12:24:54 | 00,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/01/12 11:52:13 | 00,000,036 | —- | C] () – C:\Documents and Settings\tanja\Local Settings\Application Data\housecall.guid.cache
[2010/01/04 16:24:39 | 14,942,208 | —- | C] () – C:\Documents and Settings\tanja\ntuser.dat
[2009/03/09 06:42:16 | 01,835,082 | -HS- | C] () – C:\WINDOWS\System32\ezamuyef.ini
[2009/03/06 15:47:11 | 01,835,082 | -HS- | C] () – C:\WINDOWS\System32\ototuyay.ini
[2009/03/06 15:46:52 | 00,122,880 | -HS- | C] () – C:\WINDOWS\System32\wggneh.dll
[2009/03/05 19:21:33 | 01,835,082 | -HS- | C] () – C:\WINDOWS\System32\irugokow.ini
[2009/03/04 20:35:10 | 01,829,247 | -HS- | C] () – C:\WINDOWS\System32\ifokogen.ini
[2009/03/04 08:44:48 | 01,829,247 | -HS- | C] () – C:\WINDOWS\System32\asefowep.ini
[2009/03/03 20:34:39 | 01,829,247 | -HS- | C] () – C:\WINDOWS\System32\uyokejeg.ini
[2009/01/18 13:30:22 | 01,753,139 | -HS- | C] () – C:\WINDOWS\System32\adoredey.ini
[2009/01/17 21:40:10 | 02,013,919 | -HS- | C] () – C:\WINDOWS\System32\owuyijem.ini
[2009/01/17 09:20:05 | 01,387,308 | -HS- | C] () – C:\WINDOWS\System32\osimetoz.ini
[2009/01/16 16:49:33 | 01,387,308 | -HS- | C] () – C:\WINDOWS\System32\alibojuf.ini
[2009/01/16 01:16:02 | 01,360,561 | -HS- | C] () – C:\WINDOWS\System32\oworilum.ini
[2009/01/15 13:15:49 | 01,360,561 | -HS- | C] () – C:\WINDOWS\System32\urihikat.ini
[2009/01/14 12:02:21 | 01,360,561 | -HS- | C] () – C:\WINDOWS\System32\ubehojap.ini
[2009/01/13 13:59:50 | 01,335,039 | -HS- | C] () – C:\WINDOWS\System32\upayusok.ini
[2009/01/12 17:24:22 | 01,257,961 | -HS- | C] () – C:\WINDOWS\System32\evanagiz.ini
[2009/01/11 11:04:33 | 01,257,961 | -HS- | C] () – C:\WINDOWS\System32\evipekuz.ini
[2009/01/10 17:36:28 | 01,245,697 | -HS- | C] () – C:\WINDOWS\System32\imulowak.ini
[2009/01/08 17:08:23 | 01,313,897 | -HS- | C] () – C:\WINDOWS\System32\odenehip.ini
[2009/01/05 15:57:09 | 01,313,897 | -HS- | C] () – C:\WINDOWS\System32\ajavemeb.ini
[2009/01/04 17:21:20 | 01,294,028 | -HS- | C] () – C:\WINDOWS\System32\ozohepib.ini
[2009/01/03 15:23:41 | 01,296,108 | -HS- | C] () – C:\WINDOWS\System32\avunojuk.ini
[2008/12/31 13:39:13 | 01,296,108 | -HS- | C] () – C:\WINDOWS\System32\uruholis.ini
[2008/12/31 01:39:11 | 01,296,108 | -HS- | C] () – C:\WINDOWS\System32\avayafot.ini
[2008/12/30 13:44:31 | 01,296,108 | -HS- | C] () – C:\WINDOWS\System32\aluginom.ini
[2008/12/27 23:07:25 | 01,296,108 | -HS- | C] () – C:\WINDOWS\System32\ibewodaz.ini
[2008/12/27 11:06:54 | 01,294,912 | -HS- | C] () – C:\WINDOWS\System32\atabofuy.ini
[2008/12/26 13:43:19 | 01,286,023 | -HS- | C] () – C:\WINDOWS\System32\atoyetit.ini
[2008/12/25 12:06:03 | 01,610,020 | -HS- | C] () – C:\WINDOWS\System32\oyemukul.ini
[2008/12/24 11:44:05 | 01,610,020 | -HS- | C] () – C:\WINDOWS\System32\inazikun.ini
[2008/12/23 23:27:18 | 01,610,020 | -HS- | C] () – C:\WINDOWS\System32\uzehiven.ini
[2008/12/22 17:04:02 | 01,610,020 | -HS- | C] () – C:\WINDOWS\System32\ikefiluh.ini
[2008/12/21 13:54:43 | 01,610,020 | -HS- | C] () – C:\WINDOWS\System32\elejobeg.ini
[2008/12/20 14:19:02 | 01,610,020 | -HS- | C] () – C:\WINDOWS\System32\ayavijel.ini
[2008/12/19 20:21:58 | 01,610,020 | -HS- | C] () – C:\WINDOWS\System32\uhafawep.ini
[2008/12/18 15:51:48 | 01,610,989 | -HS- | C] () – C:\WINDOWS\System32\ejurimey.ini
[2008/09/30 12:38:24 | 00,031,744 | -HS- | C] () – C:\WINDOWS\System32\muyipeve.dll
[2008/09/27 23:07:13 | 00,087,312 | —- | C] () – C:\WINDOWS\System32\zadowebi.dll
[2008/09/27 11:06:52 | 00,098,025 | -HS- | C] () – C:\WINDOWS\System32\kufubabe.dll
[2008/09/27 10:06:48 | 00,063,639 | -HS- | C] () – C:\WINDOWS\System32\giletisa.dll
[2008/09/25 10:59:28 | 00,063,685 | -HS- | C] () – C:\WINDOWS\System32\larihisu.dll
[2008/09/23 19:03:15 | 00,062,103 | -HS- | C] () – C:\WINDOWS\System32\hosezora.dll
[2008/09/20 14:17:19 | 00,097,931 | -HS- | C] () – C:\WINDOWS\System32\jeyiniyo.dll
[2008/09/19 20:21:24 | 00,087,146 | -HS- | C] () – C:\WINDOWS\System32\pewafahu.dll
[2008/09/17 16:35:48 | 00,089,835 | —- | C] () – C:\WINDOWS\System32\gikosiha.dll
[2008/07/25 22:00:00 | 00,103,205 | —- | C] () – C:\WINDOWS\System32\romabotu.dll
[2008/07/25 22:00:00 | 00,092,403 | —- | C] () – C:\WINDOWS\System32\kujonuva.dll
[2007/05/08 15:09:57 | 00,000,006 | —- | C] () – C:\Documents and Settings\tanja\Application Data\dm.ini
[2007/05/08 15:09:56 | 00,000,901 | —- | C] () – C:\Documents and Settings\tanja\Application Data\AdobeDLM.log
[2006/12/16 19:38:32 | 00,081,920 | —- | C] () – C:\Documents and Settings\tanja\Application Data\ezpinst.exe
[2006/12/16 19:38:32 | 00,007,176 | —- | C] () – C:\Documents and Settings\tanja\Application Data\pcouffin.cat
[2006/12/16 19:38:32 | 00,001,144 | —- | C] () – C:\Documents and Settings\tanja\Application Data\pcouffin.inf
[2006/12/16 19:38:32 | 00,000,055 | —- | C] () – C:\Documents and Settings\tanja\Application Data\pcouffin.log
[2006/07/16 16:10:18 | 00,000,260 | —- | C] () – C:\WINDOWS\_delis32.ini
[2006/07/01 09:48:47 | 00,000,137 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\fusioncache.dat
[2006/06/25 16:43:35 | 00,000,125 | -HS- | C] () – C:\Documents and Settings\tanja\Application Data\.zreglib
[2006/05/25 13:33:23 | 00,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/02/01 15:20:19 | 00,000,000 | —- | C] () – C:\WINDOWS\lgfwup.ini
[2006/02/01 15:00:25 | 00,040,960 | —- | C] () – C:\Program Files\Uninstall_CDS.exe
[2006/01/11 10:05:01 | 00,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/09/02 20:44:52 | 00,000,000 | —- | C] () – C:\WINDOWS\pcfriend.INI
[2005/08/26 19:25:53 | 00,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2005/06/17 14:48:02 | 00,032,397 | —- | C] () – C:\WINDOWS\SGTBox.INI
[2005/05/09 08:39:34 | 00,000,032 | —- | C] () – C:\WINDOWS\basefx.INI
[2005/01/31 13:07:13 | 00,000,000 | —- | C] () – C:\WINDOWS\QFN.ini
[2005/01/31 13:07:13 | 00,000,000 | —- | C] () – C:\WINDOWS\QDQICK.ini
[2005/01/26 13:04:37 | 00,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2004/11/24 01:53:06 | 00,155,648 | —- | C] () – C:\WINDOWS\System32\winupdak.dll
[2004/11/24 01:41:01 | 00,155,648 | —- | C] () – C:\WINDOWS\System32\akupd.dll
[2004/11/23 07:48:06 | 00,000,262 | —- | C] () – C:\WINDOWS\usta32.ini
[2004/11/07 17:33:10 | 00,000,005 | —- | C] () – C:\Documents and Settings\All Users\Application Data\DirectCDUserNameE.txt
[2004/10/02 17:47:43 | 00,000,035 | —- | C] () – C:\WINDOWS\A4W.INI
[2004/10/02 17:46:55 | 00,000,572 | —- | C] () – C:\WINDOWS\maxlink.ini
[2004/10/02 17:44:57 | 00,000,000 | —- | C] () – C:\WINDOWS\OP70.INI
[2004/10/02 17:43:46 | 00,001,472 | —- | C] () – C:\WINDOWS\pstudio.ini
[2004/10/02 17:43:46 | 00,000,028 | —- | C] () – C:\WINDOWS\album.ini
[2004/10/02 17:43:46 | 00,000,021 | —- | C] () – C:\WINDOWS\Ps_setup.ini
[2004/10/02 17:42:09 | 00,016,032 | —- | C] () – C:\WINDOWS\System32\drivers\ScFBPNT3.sys
[2004/10/02 17:05:50 | 00,000,718 | —- | C] () – C:\WINDOWS\lexstat.ini
[2004/10/02 17:05:49 | 00,163,840 | —- | C] () – C:\WINDOWS\System32\ldepcl32.dll
[2004/10/02 17:05:48 | 00,328,704 | —- | C] () – C:\WINDOWS\System32\dosfnt32.dll
[2004/09/18 18:42:25 | 00,000,129 | —- | C] () – C:\WINDOWS\CTWave32.ini
[2004/07/19 02:57:09 | 00,011,776 | —- | C] () – C:\WINDOWS\System32\ZPORT4AS.dll
[2004/07/05 13:54:08 | 00,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2004/07/04 17:25:26 | 00,364,544 | —- | C] () – C:\WINDOWS\System32\psCamDat.dll
[2004/06/20 12:37:34 | 00,000,028 | —- | C] () – C:\WINDOWS\System32\autoscan3.dll
[2004/05/24 00:25:24 | 00,000,035 | —- | C] () – C:\Program Files\Default.PLS
[2004/05/13 10:55:56 | 00,000,032 | —- | C] () – C:\WINDOWS\thxcfg.ini
[2004/04/29 12:49:49 | 00,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll
[2004/04/29 12:48:31 | 00,000,034 | —- | C] () – C:\WINDOWS\h263test.ini
[2004/04/29 11:54:16 | 00,524,288 | —- | C] () – C:\WINDOWS\System32\InetIPLA6.dll
[2004/04/29 11:54:16 | 00,516,096 | —- | C] () – C:\WINDOWS\System32\InetIPLM6.dll
[2004/04/29 11:54:16 | 00,512,000 | —- | C] () – C:\WINDOWS\System32\InetIPLP6.dll
[2004/04/29 11:54:16 | 00,503,808 | —- | C] () – C:\WINDOWS\System32\InetIPLPX.dll
[2004/04/29 11:54:16 | 00,495,616 | —- | C] () – C:\WINDOWS\System32\InetIPLM5.dll
[2004/04/29 11:54:16 | 00,491,520 | —- | C] () – C:\WINDOWS\System32\InetIPLP5.dll
[2004/04/29 11:54:16 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\InetIPL.dll
[2004/04/29 11:54:16 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\Cpuinf32.dll
[2004/02/20 22:50:14 | 00,000,032 | —- | C] () – C:\Program Files\Draw Joy Bib.dat
[2004/02/19 00:24:29 | 00,000,008 | —- | C] () – C:\WINDOWS\System32\mseggrpid.dll
[2004/01/24 17:10:30 | 00,000,103 | —- | C] () – C:\WINDOWS\CTRec.INI
[2003/12/11 17:51:07 | 00,004,294 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2003/12/03 16:07:00 | 00,000,128 | —- | C] () – C:\Documents and Settings\tanja\Local Settings\Application Data\fusioncache.dat
[2003/11/17 23:37:20 | 00,072,192 | —- | C] () – C:\WINDOWS\System32\zlib.dll
[2003/10/08 13:34:26 | 00,121,440 | —- | C] () – C:\WINDOWS\System32\MSDRMCtrl.dll
[2003/10/06 14:16:00 | 00,027,136 | —- | C] () – C:\WINDOWS\System32\nvcod.dll
[2003/09/15 09:10:43 | 00,061,678 | —- | C] () – C:\Documents and Settings\tanja\Application Data\PFP110JPR.{PB
[2003/09/15 09:10:43 | 00,012,358 | —- | C] () – C:\Documents and Settings\tanja\Application Data\PFP110JCM.{PB
[2003/09/03 08:44:52 | 00,000,070 | —- | C] () – C:\WINDOWS\400A3C1E.ini
[2003/09/03 07:28:42 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/09/02 07:06:42 | 00,000,170 | —- | C] () – C:\WINDOWS\GetServer.ini
[2003/08/14 22:09:09 | 00,114,176 | —- | C] () – C:\Documents and Settings\tanja\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2003/08/11 11:30:38 | 00,000,823 | —- | C] () – C:\WINDOWS\TSC.ini
[2003/08/11 11:30:37 | 00,071,749 | —- | C] () – C:\WINDOWS\HCExtOutput.dll
[2003/08/10 13:28:31 | 00,000,030 | —- | C] () – C:\WINDOWS\Morpheus.INI
[2003/08/10 12:23:06 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2003/08/10 12:22:26 | 00,000,021 | —- | C] () – C:\WINDOWS\CS_setup.ini
[2003/08/10 11:24:45 | 00,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2003/07/22 20:37:17 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/07/22 20:32:24 | 00,000,185 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/07/22 20:32:22 | 00,000,846 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/07/22 20:30:53 | 00,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2003/07/22 20:30:41 | 00,002,092 | —- | C] () – C:\WINDOWS\System32\P16X.ini
[2003/07/22 20:30:41 | 00,000,026 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2003/07/22 20:30:40 | 00,006,175 | —- | C] () – C:\WINDOWS\MIXDEF.INI
[2003/07/22 20:30:40 | 00,005,917 | —- | C] () – C:\WINDOWS\SBMIXDEF.INI
[2003/07/22 20:30:40 | 00,000,064 | —- | C] () – C:\WINDOWS\P16x.ini
[2003/07/22 20:30:14 | 00,000,245 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2003/07/22 20:26:34 | 00,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/07/22 20:14:40 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/07/22 20:02:48 | 00,000,480 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2003/07/08 13:41:48 | 00,047,616 | —- | C] () – C:\WINDOWS\System32\P16X.dll
[2002/12/19 21:12:54 | 00,015,360 | —- | C] () – C:\WINDOWS\System32\selm_isx.dll
[2002/12/05 16:51:00 | 00,059,392 | R— | C] () – C:\WINDOWS\streamhlp.dll
[2002/06/10 13:16:22 | 00,005,187 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[1999/08/11 23:00:00 | 01,708,032 | —- | C] () – C:\WINDOWS\System32\MSO97V.DLL
[1999/08/11 23:00:00 | 00,036,864 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1999/08/11 23:00:00 | 00,032,768 | —- | C] () – C:\WINDOWS\System32\MSORFS.DLL
[1999/08/10 16:02:20 | 00,116,736 | —- | C] () – C:\WINDOWS\System32\LFKODAK.DLL
[1999/08/10 16:02:16 | 00,343,040 | —- | C] () – C:\WINDOWS\System32\lffpx7.dll
[1999/07/23 13:46:48 | 00,000,116 | —- | C] () – C:\WINDOWS\AuHCcup1.ini
[1999/07/23 10:53:20 | 00,129,536 | —- | C] () – C:\WINDOWS\AuHCcup1.dll
[1979/12/31 22:00:00 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll

========== LOP Check ==========

[2009/06/25 09:41:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2006/04/02 11:12:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MipKukSoft
[2003/12/31 21:00:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NFS Underground Demo
[2008/05/20 19:35:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2010/01/23 17:03:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Retrospect
[2009/11/06 18:47:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/03/28 10:01:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2003/09/03 08:41:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Zero Knowledge
[2006/01/29 23:06:20 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\.bittorrent
[2006/04/19 01:51:30 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\.gaim
[2004/12/19 10:09:00 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\AVG7
[2006/06/25 17:29:53 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\Elaborate Bytes
[2006/12/16 19:25:16 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\GEAR DVD Standard Edition 7.01
[2010/01/23 16:29:56 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\HouseCall 6.6
[2004/09/24 00:14:41 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\Jasc
[2003/08/30 13:59:43 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\Kazaa Lite
[2004/02/29 11:59:14 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\Kontiki
[2006/04/02 11:14:02 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\Kybtec Software
[2006/04/02 11:14:04 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\MipKukSoft
[2008/11/01 11:36:58 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\Musicmatch
[2006/12/16 19:22:30 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\RelevantReach
[2006/06/25 16:44:56 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\SlySoft
[2006/12/16 19:42:07 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\Vso
[2003/09/03 08:43:44 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\Zero Knowledge
[2010/01/27 16:25:00 | 00,000,424 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{2251EC52-B660-4E59-B002-5A66781184C0}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2009/03/03 21:02:33 | 00,049,152 | —- | M] () – C:\3.exe
[2005/10/31 08:56:00 | 00,700,416 | —- | M] (LimeWire) – C:\StubInstaller.exe


< MD5 for: AGP440.SYS >
[2004/08/25 21:12:00 | 22,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/09/06 21:55:09 | 23,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/25 21:12:00 | 22,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2008/09/06 21:55:09 | 23,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 11:36:38 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2004/08/03 23:07:41 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[2004/08/03 23:07:41 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\SYSTEM32\DRIVERS\agp440.sys
[2001/08/17 11:58:00 | 00,025,472 | —- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF – C:\I386\AGP440.SYS

< MD5 for: ATAPI.SYS >
[2002/08/29 03:00:00 | 10,158,890 | —- | M] () .cab file – C:\I386\sp1.cab:atapi.sys
[2002/09/03 10:04:09 | 10,158,890 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2004/08/25 21:12:00 | 22,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/09/06 21:55:09 | 23,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/25 21:12:00 | 22,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2008/09/06 21:55:09 | 23,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2003/01/31 13:43:30 | 00,087,040 | —- | M] (Microsoft Corporation) MD5=3C33F5479520844A186C2D43ECFFD477 – C:\I386\atapi.sys
[2008/04/13 11:40:30 | 00,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2004/08/03 22:59:42 | 00,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/03 22:59:42 | 00,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\SYSTEM32\DRIVERS\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 17:11:53 | 00,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 17:11:53 | 00,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SYSTEM32\eventlog.dll
[2004/08/04 00:56:42 | 00,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2002/08/29 03:00:00 | 00,049,152 | —- | M] (Microsoft Corporation) MD5=BF3C8CF53C77B48206B39910B6D6CBCC – C:\I386\EVENTLOG.DLL

< MD5 for: NETLOGON.DLL >
[2008/04/13 17:12:01 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 17:12:01 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SYSTEM32\netlogon.dll
[2002/08/29 03:00:00 | 00,399,360 | —- | M] (Microsoft Corporation) MD5=3ADD563ED7A1C66E6F5E0F7A661AA96D – C:\I386\NETLOGON.DLL
[2004/08/04 00:56:44 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 00:56:44 | 00,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2002/08/29 03:00:00 | 00,174,592 | —- | M] (Microsoft Corporation) MD5=97418A5C642A5C748A28BD7CF6860B57 – C:\I386\SCECLI.DLL
[2008/04/13 17:12:05 | 00,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 17:12:05 | 00,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SYSTEM32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

========== Alternate Data Streams ==========

@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9AB338B9
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D37AE80B
< End of report >
here is the 2nd.. (also.. IE opens now but shuts down immediately… had to use firefox to post here)

Extras.Txt

OTL Extras logfile created on: 1/27/2010 4:11:38 PM - Run 1
OTL by OldTimer - Version 3.1.26.0 Folder = C:\Documents and Settings\tanja\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 199.00 Mb Available Physical Memory | 39.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): c:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 0.20 Gb Free Space | 0.27% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DHGGS431
Current User Name: tanja
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [MediaMonkey.1Play] – "C:\Program Files\MediaMonkey\MediaMonkey.exe" "%1" (Ventis Media Inc.)
Directory [MediaMonkey.2PlayNext] – "C:\Program Files\MediaMonkey\MediaMonkey.exe" /NEXT "%1" (Ventis Media Inc.)
Directory [MediaMonkey.3Enqueue] – "C:\Program Files\MediaMonkey\MediaMonkey.exe" /ADD "%1" (Ventis Media Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"65533:TCP" = 65533:TCP:*:Enabled:Services
"52344:TCP" = 52344:TCP:*:Enabled:Services
"7271:TCP" = 7271:TCP:*:Enabled:Services
"2479:TCP" = 2479:TCP:*:Enabled:Services
"3389:TCP" = 3389:TCP:*:Enabled:Remote Desktop
"3246:TCP" = 3246:TCP:*:Enabled:Services

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"65533:TCP" = 65533:TCP:*:Enabled:Services
"52344:TCP" = 52344:TCP:*:Enabled:Services
"7271:TCP" = 7271:TCP:*:Enabled:Services
"2479:TCP" = 2479:TCP:*:Enabled:Services
"3389:TCP" = 3389:TCP:*:Enabled:Remote Desktop
"3246:TCP" = 3246:TCP:*:Enabled:Services

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Yahoo!\Messenger\YPager.exe" = C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger – File not found
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server – (Yahoo! Inc.)
"C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe:*:Enabled:LimeWire: The most advanced file sharing program on the planet. – File not found
"C:\Program Files\WinMX\WinMX.exe" = C:\Program Files\WinMX\WinMX.exe:*:Enabled:WinMX Application – File not found
"C:\Program Files\Kazaa Lite K++\KazaaLite.kpp" = C:\Program Files\Kazaa Lite K++\KazaaLite.kpp:*:Disabled:KazaaLite – File not found
"C:\Program Files\Internet Explorer\iexplore.exe" = C:\Program Files\Internet Explorer\iexplore.exe:*:Disabled:Internet Explorer – (Microsoft Corporation)
"C:\Program Files\mIRC\mirc.exe" = C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC – File not found
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – File not found
"C:\Program Files\ZakFromAnotherPlanet\Yazak Chat\iexplore.exe" = C:\Program Files\ZakFromAnotherPlanet\Yazak Chat\iexplore.exe:*:Enabled:iexplore – (ZakFromAnotherPlanet)
"C:\Documents and Settings\phil\Local Settings\Temp\WZS6.tmp\AswApp.exe" = C:\Documents and Settings\phil\Local Settings\Temp\WZS6.tmp\AswApp.exe:*:Enabled:AswApp – File not found
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\StubInstaller.exe" = C:\StubInstaller.exe:*:Enabled:LimeWire swarmed installer – (LimeWire)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – (Lime Wire, LLC)
"C:\Program Files\ZakFromAnotherPlanet\Yazak Chat\yazak.exe" = C:\Program Files\ZakFromAnotherPlanet\Yazak Chat\yazak.exe:*:Enabled:yazak – File not found
"C:\WINDOWS\SYSTEM32\rtcshare.exe" = C:\WINDOWS\SYSTEM32\rtcshare.exe:*:Enabled:RTC App Sharing – (Microsoft Corporation)
"C:\Nexon\MapleStory\MapleStory.exe" = C:\Nexon\MapleStory\MapleStory.exe:*:Enabled:MapleStory – File not found
"C:\Documents and Settings\TEIGAN\My Documents\World of Warcraft\WoW-1.12.0-enUS-downloader.exe" = C:\Documents and Settings\TEIGAN\My Documents\World of Warcraft\WoW-1.12.0-enUS-downloader.exe:*:Enabled:Blizzard Downloader – File not found
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:Explorer – (Microsoft Corporation)
"C:\WINDOWS\system32\LEXPPS.EXE" = C:\WINDOWS\system32\LEXPPS.EXE:*:Enabled:LEXPPS.EXE – (Lexmark International, Inc.)
"C:\Program Files\Ahead\InCD\InCDsrv.exe" = C:\Program Files\Ahead\InCD\InCDsrv.exe:*:Enabled:InCDsrv – (Nero AG)
"C:\WINDOWS\SYSTEM32\CTsvcCDA.EXE" = C:\WINDOWS\SYSTEM32\CTsvcCDA.EXE:*:Enabled:CTsvcCDA – (Creative Technology Ltd)
"C:\Program Files\ewido anti-malware\ewidoctrl.exe" = C:\Program Files\ewido anti-malware\ewidoctrl.exe:*:Enabled:ewidoctrl – File not found
"C:\Program Files\QuickTime\qttask.exe" = C:\Program Files\QuickTime\qttask.exe:*:Enabled:qttask – File not found
"C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" = C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe:*:Enabled:PDVDServ – (Cyberlink Corp.)
"C:\Program Files\Common Files\Logitech\QCDriver\LVComS.exe" = C:\Program Files\Common Files\Logitech\QCDriver\LVComS.exe:*:Enabled:LVCOMS – (Logitech Inc.)
"C:\Program Files\Windows Live\Family Safety\fssui.exe" = C:\Program Files\Windows Live\Family Safety\fssui.exe:*:Enabled:fssui – File not found
"C:\Program Files\Ahead\InCD\InCD.exe" = C:\Program Files\Ahead\InCD\InCD.exe:*:Enabled:InCD – (Nero AG)
"C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mimboot.exe" = C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mimboot.exe:*:Enabled:mimboot – (Musicmatch, Inc.)
"C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe" = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe:*:Enabled:reader_sl – (Adobe Systems Incorporated)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{03CDDD00-BD57-4326-9480-4C74449AF597}" = PhotoStitch
"{093625E3-7B87-49D3-AA53-AD0FCFABAF49}" = Camera Window
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{139E303E-1050-497F-98B1-9AE87B15C463}" = Windows Live Family Safety
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = Multimedia Launcher
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 17
"{2D37F6AE-D201-4580-B91A-6BF9BB93ED2D}" = The Sims™ 2 Double Deluxe
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150100}" = J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{43DCF766-6838-4F9A-8C91-D92DA586DFA7}" = Microsoft Windows Journal Viewer
"{43FCA273-9534-40DB-B7C5-D7758875616A}" = Dell Support
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{49FC50FC-F965-40D9-89B4-CBFF80941033}" = Windows Movie Maker 2.0
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{586C47A4-6917-4332-B33F-EEC8D6841DF7}" = IOGear ION
"{5C74694C-A687-E3EB-FF18-B018D4A76ECD}" = Adobe Media Player
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{5FA4690C-1975-4F94-9A64-274F29BD9221}" = Microsoft Baseline Security Analyzer 1.2
"{64116298-93C5-401D-B06C-39D8E3338508}" = DAO
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68D60342-7686-45C9-B8EB-40EF843D0460}" = Dell Networking Guide
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73B69C5C-87D6-471E-B695-0BD736C4B644}" = Retrospect 6.5
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77E70C3C-DBB9-4C47-8663-1E1F81FEC623}" = Logitech QuickCam
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{81A34902-9D0B-4920-A25C-4CDC5D14B328}" = Jasc Paint Shop Pro 8
"{81D62C32-0984-11D3-86CD-00105AD33021}" = Caere Scan Manager 5.1
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{85D3CC30-8859-481A-9654-FD9B74310BEF}" = Musicmatch® Jukebox
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{9496E9E4-F20A-11D4-8EAA-00062973342B}" = Intel® Create & Share® Software
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96E16100-A77F-4B31-B9AD-FFBA040EE1BD}" = Sound Blaster Live!
"{98DF85D9-96C0-4F57-A92E-C3539477EF5E}" = DVDSentry
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AC76BA86-7AD7-1033-7B44-A70900000002}" = Adobe Reader 7.0.9
"{AD708DF0-9F04-4CB3-821A-85804A833B4D}" = ArcSoft Camera Suite
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{B87ED12E-A95F-45AC-89E7-02CFD5BD2353}" = StudioTax 2008
"{B97CF5C3-0487-11D8-A36E-0050BAE317E1}" = DVD Solution
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BEAD39CD-901D-4267-8B8B-EAA83CB4B70D}" = Pivot Stickfigure Animator
"{BEB03A1A-1EB6-48EB-9985-8B97315EE5C0}" = RemoteCapture 2.7.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}" = Canon Utilities ZoomBrowser EX
"{C777D229-86EC-4E42-AAC4-D44CF7EA4847}" = Canon Camera WIA Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEA5EF64-B694-4B79-9A2C-0FF738906A1D}" = DriverGuide Toolkit
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{DFC6573E-124D-4026-BFA4-B433C9D3FF21}" = ISO Recorder
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{EC905264-BCFE-423B-9C42-C3A106266790}" = Windows Rights Management client
"{EF0DD8B7-471C-463B-A298-6066C2FABAF5}" = File Viewer Utility 1.2
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AdobeESD" = Adobe Download Manager 2.2 (Remove Only)
"ArcSoft PhotoStudio 2000" = ArcSoft PhotoStudio 2000
"Buddy Spy_is1" = Buddy Spy 2.2.10
"CanoCraft CS-P 3.8" = Canon CanoCraft CS-P 3.8
"Canon ScanGear Toolbox CS" = Canon ScanGear Toolbox CS 2.2
"CleanUp!" = CleanUp!
"CNXT_MODEM_PCI_VEN_14F1&DEV_2702" = Conexant SmartHSFi V92 56K DF PCI Modem
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DVD Shrink_is1" = DVD Shrink 3.2
"EAX™ Unified (SHELL)" = EAX™ Unified (SHELL)
"ForeWord_is1" = ForeWord
"GTK 2.0" = GTK+ Runtime 2.6.9 rev a (remove only)
"HijackThis" = HijackThis 2.0.2
"ie8" = Windows Internet Explorer 8
"ImageDrive!UninstallKey" = ImageDrive (ahead software)
"InCD!UninstallKey" = InCD
"InstallShield_{03CDDD00-BD57-4326-9480-4C74449AF597}" = Canon Utilities PhotoStitch 3.1
"InstallShield_{093625E3-7B87-49D3-AA53-AD0FCFABAF49}" = Canon Camera Window for ZoomBrowser EX
"InstallShield_{586C47A4-6917-4332-B33F-EEC8D6841DF7}" = IOGear ION
"InstallShield_{69654736-1026-4728-A78E-BA45DF993BAE}" = LimeWire
"InstallShield_{BEB03A1A-1EB6-48EB-9985-8B97315EE5C0}" = Canon Utilities RemoteCapture 2.7
"InstallShield_{C777D229-86EC-4E42-AAC4-D44CF7EA4847}" = Canon Camera WIA Driver 6.0
"InstallShield_{EF0DD8B7-471C-463B-A298-6066C2FABAF5}" = Canon Utilities File Viewer Utility 1.2
"Lexmark Z600 Series" = Lexmark Z600 Series
"LimeWire" = LimeWire 4.16.6
"LiveReg" = LiveReg (Symantec Corporation)
"LiveUpdate" = LiveUpdate 1.80 (Symantec Corporation)
"MediaMonkey_is1" = MediaMonkey 3.1
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0.15)" = Mozilla Firefox (3.0.15)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero - Burning Rom!UninstallKey" = Nero OEM
"NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
"NVIDIA Display Driver" = NVIDIA Display Driver
"Panda ActiveScan" = Panda ActiveScan
"PhotoRecord" = Canon PhotoRecord
"PPTView97" = Microsoft PowerPoint Viewer 97
"PROSet" = Intel® PRO Network Adapters and Drivers
"Quicken 2002 New User Edition" = Quicken 2002 New User Edition
"SceneCaster" = SceneCaster
"slowuploadfrag" = Window Searching
"Soulbringer" = Soulbringer
"Trend Micro HouseCall 6.6" = HouseCall 6.6
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WinTools.net Professional" = WinTools.net Professional
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XviDDec" = Nic's XviD Decoder
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Photos Drag-Drop Uploader 1v4" = Yahoo! Photos Easy Upload Tool 1v4
"Yahoo! Photos Drag-Drop Uploader 1v7" = Yahoo! Photos Easy Upload Tool 1v7
"Yahoo! Search Defender" = Yahoo! Search Protection
"Yahoo! Software Update" = Yahoo! Software Update

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/11/2009 5:18:31 PM | Computer Name = DHGGS431 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 11/17/2009 8:35:41 PM | Computer Name = DHGGS431 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 11/27/2009 7:45:09 PM | Computer Name = DHGGS431 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module flash10c.ocx, version 10.0.32.18, fault address 0x0003da50.

Error - 11/27/2009 8:51:41 PM | Computer Name = DHGGS431 | Source = Application Hang | ID = 1002
Description = Hanging application mmjb.exe, version 10.0.4.33, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 11/27/2009 9:24:02 PM | Computer Name = DHGGS431 | Source = Application Hang | ID = 1002
Description = Hanging application LimeWire.exe, version 1.0.0.2, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 12/1/2009 1:42:00 PM | Computer Name = DHGGS431 | Source = Application Hang | ID = 1002
Description = Hanging application Paint Shop Pro.exe, version 8.0.0.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/2/2009 8:29:49 PM | Computer Name = DHGGS431 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/7/2009 11:52:05 PM | Computer Name = DHGGS431 | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/7/2009 11:52:05 PM | Computer Name = DHGGS431 | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/12/2009 3:50:52 AM | Computer Name = DHGGS431 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module unknown, version 0.0.0.0, fault address 0x0385023a.

[ OSession Events ]
Error - 10/19/2009 11:00:06 PM | Computer Name = DHGGS431 | Source = Microsoft Office 12 Sessions | ID = 7001
Description =

[ System Events ]
Error - 1/26/2010 1:41:33 AM | Computer Name = DHGGS431 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 1/26/2010 1:43:57 AM | Computer Name = DHGGS431 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 1/26/2010 1:47:18 AM | Computer Name = DHGGS431 | Source = Service Control Manager | ID = 7000
Description = The npkcrypt service failed to start due to the following error: %%2

Error - 1/26/2010 7:51:30 PM | Computer Name = DHGGS431 | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.101 for the Network Card with network
address 0007E974EC45 has been denied by the DHCP server 192.168.0.1 (The DHCP Server
sent a DHCPNACK message).

Error - 1/26/2010 7:53:37 PM | Computer Name = DHGGS431 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 1/26/2010 7:54:29 PM | Computer Name = DHGGS431 | Source = Service Control Manager | ID = 7001
Description = The Fax service depends on the Print Spooler service which failed
to start because of the following error: %%1068

Error - 1/26/2010 7:54:29 PM | Computer Name = DHGGS431 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Fips intelppm SASDIFSV SASKUTIL

Error - 1/27/2010 1:46:19 AM | Computer Name = DHGGS431 | Source = Service Control Manager | ID = 7000
Description = The npkcrypt service failed to start due to the following error: %%2

Error - 1/27/2010 2:27:35 PM | Computer Name = DHGGS431 | Source = Service Control Manager | ID = 7000
Description = The npkcrypt service failed to start due to the following error: %%2

Error - 1/27/2010 7:00:42 PM | Computer Name = DHGGS431 | Source = Service Control Manager | ID = 7000
Description = The npkcrypt service failed to start due to the following error: %%2


< End of report >
Hi lilfirecat69,

Let's deal with some of this malware first then we'll have a look at Internet Explorer. Are you experiencing any browser or search redirects? Did you recently install Windows XP Service Pack 3?

What are you using for an antivirus program?


LimeWire
You have LimeWire, a P2P/file sharing program installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing them. It's not the program itself that is the problem, but what can be downloaded with them, usually from an unknown source.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx

http://www.internetworldstats.com/articles…cles/art053.htm

I would recommend that you uninstall LimeWire, however that choice is up to you. If you choose to remove this program, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.



Sorry to have you so much this time, but with vundo you need to hit it as hard as you can as it has a habit of breeding like rabbits.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
O2 - BHO: (no name) - {49132671-36d0-4319-acbe-6fed9ae5715a} - C:\WINDOWS\System32\juvoguru.dll File not found
O2 - BHO: (no name) - {5cb492ae-bc91-4a4f-a7f0-30f6c55728cc} - C:\WINDOWS\System32\fagesefa.dll File not found
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [24f0ca60] C:\WINDOWS\System32\feyumaze.DLL File not found
O4 - HKLM..\Run: [CPM27c3f9fc] C:\WINDOWS\System32\wobupobu.DLL File not found
O4 - HKLM..\Run: [jowuzamaku] C:\WINDOWS\System32\ronigofu.DLL File not found
O20 - AppInit_DLLs: (C:\WINDOWS\system32\wejiwulo.dll) - C:\WINDOWS\System32\wejiwulo.dll File not found
O20 - AppInit_DLLs: (c:\windows\system32\botapepe.dll) - C:\WINDOWS\System32\botapepe.dll File not found
O20 - AppInit_DLLs: (c:\windows\system32\gafilumu.dll) - C:\WINDOWS\System32\gafilumu.dll File not found
O20 - AppInit_DLLs: (C:\WINDOWS\system32\lamisefi.dll) - C:\WINDOWS\System32\lamisefi.dll File not found
O20 - AppInit_DLLs: (ffzrka.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\putevama.dll) - C:\WINDOWS\System32\putevama.dll File not found
O20 - AppInit_DLLs: (c:\windows\system32\wobupobu.dll) - C:\WINDOWS\System32\wobupobu.dll File not found
O20 - AppInit_DLLs: (cedyfe.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\jahanane.dll) - C:\WINDOWS\System32\jahanane.dll File not found
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - CLSID or File not found.
O22 - SharedTaskScheduler: {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - STS - Reg Error: Key error. File not found
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2099/01/01 12:00:00 | 00,098,304 | -HS- | M] () – C:\WINDOWS\System32\medilile.dll
[2099/01/01 12:00:00 | 00,127,777 | -HS- | C] () – C:\WINDOWS\System32\fiyobubi.dll
[2099/01/01 12:00:00 | 00,127,687 | -HS- | C] () – C:\WINDOWS\System32\vavefowi.dll
[2099/01/01 12:00:00 | 00,101,099 | -HS- | C] () – C:\WINDOWS\System32\gedekuye.dll
[2099/01/01 12:00:00 | 00,098,304 | -HS- | C] () – C:\WINDOWS\System32\medilile.dll
[2099/01/01 12:00:00 | 00,092,298 | —- | C] () – C:\WINDOWS\System32\bemevaja.dll
[2099/01/01 12:00:00 | 00,089,275 | -HS- | C] () – C:\WINDOWS\System32\bipehozo.dll
[2099/01/01 12:00:00 | 00,006,456 | -H– | C] () – C:\WINDOWS\System32\rowijoko
[2009/03/09 06:42:16 | 01,835,082 | -HS- | C] () – C:\WINDOWS\System32\ezamuyef.ini
[2009/03/06 15:47:11 | 01,835,082 | -HS- | C] () – C:\WINDOWS\System32\ototuyay.ini
[2009/03/06 15:46:52 | 00,122,880 | -HS- | C] () – C:\WINDOWS\System32\wggneh.dll
[2009/03/05 19:21:33 | 01,835,082 | -HS- | C] () – C:\WINDOWS\System32\irugokow.ini
[2009/03/04 20:35:10 | 01,829,247 | -HS- | C] () – C:\WINDOWS\System32\ifokogen.ini
[2009/03/04 08:44:48 | 01,829,247 | -HS- | C] () – C:\WINDOWS\System32\asefowep.ini
[2009/03/03 20:34:39 | 01,829,247 | -HS- | C] () – C:\WINDOWS\System32\uyokejeg.ini
[2009/01/18 13:30:22 | 01,753,139 | -HS- | C] () – C:\WINDOWS\System32\adoredey.ini
[2009/01/17 21:40:10 | 02,013,919 | -HS- | C] () – C:\WINDOWS\System32\owuyijem.ini
[2009/01/17 09:20:05 | 01,387,308 | -HS- | C] () – C:\WINDOWS\System32\osimetoz.ini
[2009/01/16 16:49:33 | 01,387,308 | -HS- | C] () – C:\WINDOWS\System32\alibojuf.ini
[2009/01/16 01:16:02 | 01,360,561 | -HS- | C] () – C:\WINDOWS\System32\oworilum.ini
[2009/01/15 13:15:49 | 01,360,561 | -HS- | C] () – C:\WINDOWS\System32\urihikat.ini
[2009/01/14 12:02:21 | 01,360,561 | -HS- | C] () – C:\WINDOWS\System32\ubehojap.ini
[2009/01/13 13:59:50 | 01,335,039 | -HS- | C] () – C:\WINDOWS\System32\upayusok.ini
[2009/01/12 17:24:22 | 01,257,961 | -HS- | C] () – C:\WINDOWS\System32\evanagiz.ini
[2009/01/11 11:04:33 | 01,257,961 | -HS- | C] () – C:\WINDOWS\System32\evipekuz.ini
[2009/01/10 17:36:28 | 01,245,697 | -HS- | C] () – C:\WINDOWS\System32\imulowak.ini
[2009/01/08 17:08:23 | 01,313,897 | -HS- | C] () – C:\WINDOWS\System32\odenehip.ini
[2009/01/05 15:57:09 | 01,313,897 | -HS- | C] () – C:\WINDOWS\System32\ajavemeb.ini
[2009/01/04 17:21:20 | 01,294,028 | -HS- | C] () – C:\WINDOWS\System32\ozohepib.ini
[2009/01/03 15:23:41 | 01,296,108 | -HS- | C] () – C:\WINDOWS\System32\avunojuk.ini
[2008/12/31 13:39:13 | 01,296,108 | -HS- | C] () – C:\WINDOWS\System32\uruholis.ini
[2008/12/31 01:39:11 | 01,296,108 | -HS- | C] () – C:\WINDOWS\System32\avayafot.ini
[2008/12/30 13:44:31 | 01,296,108 | -HS- | C] () – C:\WINDOWS\System32\aluginom.ini
[2008/12/27 23:07:25 | 01,296,108 | -HS- | C] () – C:\WINDOWS\System32\ibewodaz.ini
[2008/12/27 11:06:54 | 01,294,912 | -HS- | C] () – C:\WINDOWS\System32\atabofuy.ini
[2008/12/26 13:43:19 | 01,286,023 | -HS- | C] () – C:\WINDOWS\System32\atoyetit.ini
[2008/12/25 12:06:03 | 01,610,020 | -HS- | C] () – C:\WINDOWS\System32\oyemukul.ini
[2008/12/24 11:44:05 | 01,610,020 | -HS- | C] () – C:\WINDOWS\System32\inazikun.ini
[2008/12/23 23:27:18 | 01,610,020 | -HS- | C] () – C:\WINDOWS\System32\uzehiven.ini
[2008/12/22 17:04:02 | 01,610,020 | -HS- | C] () – C:\WINDOWS\System32\ikefiluh.ini
[2008/12/21 13:54:43 | 01,610,020 | -HS- | C] () – C:\WINDOWS\System32\elejobeg.ini
[2008/12/20 14:19:02 | 01,610,020 | -HS- | C] () – C:\WINDOWS\System32\ayavijel.ini
[2008/12/19 20:21:58 | 01,610,020 | -HS- | C] () – C:\WINDOWS\System32\uhafawep.ini
[2008/12/18 15:51:48 | 01,610,989 | -HS- | C] () – C:\WINDOWS\System32\ejurimey.ini
[2008/09/30 12:38:24 | 00,031,744 | -HS- | C] () – C:\WINDOWS\System32\muyipeve.dll
[2008/09/27 23:07:13 | 00,087,312 | —- | C] () – C:\WINDOWS\System32\zadowebi.dll
[2008/09/27 11:06:52 | 00,098,025 | -HS- | C] () – C:\WINDOWS\System32\kufubabe.dll
[2008/09/27 10:06:48 | 00,063,639 | -HS- | C] () – C:\WINDOWS\System32\giletisa.dll
[2008/09/25 10:59:28 | 00,063,685 | -HS- | C] () – C:\WINDOWS\System32\larihisu.dll
[2008/09/23 19:03:15 | 00,062,103 | -HS- | C] () – C:\WINDOWS\System32\hosezora.dll
[2008/09/20 14:17:19 | 00,097,931 | -HS- | C] () – C:\WINDOWS\System32\jeyiniyo.dll
[2008/09/19 20:21:24 | 00,087,146 | -HS- | C] () – C:\WINDOWS\System32\pewafahu.dll
[2008/09/17 16:35:48 | 00,089,835 | —- | C] () – C:\WINDOWS\System32\gikosiha.dll
[2008/07/25 22:00:00 | 00,103,205 | —- | C] () – C:\WINDOWS\System32\romabotu.dll
[2008/07/25 22:00:00 | 00,092,403 | —- | C] () – C:\WINDOWS\System32\kujonuva.dll

:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
""=-

:Files

:Commands
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.


I need some information on a file. We will use Virustotal Please submit these files for analysis

To submit a file to virustotal, please click on this link

Http://www.virustotal.com

Use the browse button to navigate to this file


C:\3.exe


Scroll down a bit and click "send file", wait for the results and post them in your next reply.

Please note that sometimes the scans take a few minutes.



Next

Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediatly.


Please post back with
  • OTL fix log
  • VirusTotal results
  • MBAM log
  • new OTL scan log taken after all other steps.
  • do not paste anything into the Custom scan windows this time
  • please uncheck Lop and Purity
  • please note there will onl be an OTL.txt this time
How's the computer?

Thanks
HI Oldman :)

ok here are the present scans for you.. also I sent you a messege but you can disregard it, other than the info I passed along, yes I did recently update the service pack from the windows update,this comp is behind a router,but all I run is superantispyware on this comp at the moment , until I can store the files that need to be removed on the external hd I have, and then I plan to reformat it as there are a lot of duplicate files on here taking up a lot of memory from a system save a long time ago, along with the 3 user profiles that I want to remove and just have one user on this comp, and I definatly didnt want to be saving anything infected on the ext-hd either. which I'm glad this was done, :) in the past online scanners have been used on this comp, like kaspersky, panda, symantic, trend micro housecall, avg, spybot, bit defender among others. IE still wont open, it hourglasses a moment then nothing…but otherwise, everything seems to be acting alot better, the firefox still hung a moment when I opened it after the scans, but was way better than before we started the cleaning process. I do agree on the limewire but I will remove it once I have sorted out the mp3 files for my squid,otherwise I am forbidden from removing it at the moment :D


here are the current logs:
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

Hi Oldman960

yes I did just recently update from the windows auto update.


ok , it came up alright, so here is the OTL fix log file:

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{49132671-36d0-4319-acbe-6fed9ae5715a}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{49132671-36d0-4319-acbe-6fed9ae5715a}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5cb492ae-bc91-4a4f-a7f0-30f6c55728cc}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5cb492ae-bc91-4a4f-a7f0-30f6c55728cc}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\24f0ca60 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\CPM27c3f9fc deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\jowuzamaku deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\WINDOWS\system32\wejiwulo.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\botapepe.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\gafilumu.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\WINDOWS\system32\lamisefi.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:ffzrka.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\putevama.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\wobupobu.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:cedyfe.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\jahanane.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\SSODL deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\ not found.
C:\WINDOWS\msdownld.tmp folder deleted successfully.
C:\WINDOWS\SYSTEM32\medilile.dll moved successfully.
C:\WINDOWS\SYSTEM32\fiyobubi.dll moved successfully.
C:\WINDOWS\SYSTEM32\vavefowi.dll moved successfully.
C:\WINDOWS\SYSTEM32\gedekuye.dll moved successfully.
File C:\WINDOWS\System32\medilile.dll not found.
C:\WINDOWS\SYSTEM32\bemevaja.dll moved successfully.
C:\WINDOWS\SYSTEM32\bipehozo.dll moved successfully.
C:\WINDOWS\SYSTEM32\rowijoko moved successfully.
C:\WINDOWS\SYSTEM32\ezamuyef.ini moved successfully.
C:\WINDOWS\SYSTEM32\ototuyay.ini moved successfully.
C:\WINDOWS\SYSTEM32\wggneh.dll moved successfully.
C:\WINDOWS\SYSTEM32\irugokow.ini moved successfully.
C:\WINDOWS\SYSTEM32\ifokogen.ini moved successfully.
C:\WINDOWS\SYSTEM32\asefowep.ini moved successfully.
C:\WINDOWS\SYSTEM32\uyokejeg.ini moved successfully.
C:\WINDOWS\SYSTEM32\adoredey.ini moved successfully.
C:\WINDOWS\SYSTEM32\owuyijem.ini moved successfully.
C:\WINDOWS\SYSTEM32\osimetoz.ini moved successfully.
C:\WINDOWS\SYSTEM32\alibojuf.ini moved successfully.
C:\WINDOWS\SYSTEM32\oworilum.ini moved successfully.
C:\WINDOWS\SYSTEM32\urihikat.ini moved successfully.
C:\WINDOWS\SYSTEM32\ubehojap.ini moved successfully.
C:\WINDOWS\SYSTEM32\upayusok.ini moved successfully.
C:\WINDOWS\SYSTEM32\evanagiz.ini moved successfully.
C:\WINDOWS\SYSTEM32\evipekuz.ini moved successfully.
C:\WINDOWS\SYSTEM32\imulowak.ini moved successfully.
C:\WINDOWS\SYSTEM32\odenehip.ini moved successfully.
C:\WINDOWS\SYSTEM32\ajavemeb.ini moved successfully.
C:\WINDOWS\SYSTEM32\ozohepib.ini moved successfully.
C:\WINDOWS\SYSTEM32\avunojuk.ini moved successfully.
C:\WINDOWS\SYSTEM32\uruholis.ini moved successfully.
C:\WINDOWS\SYSTEM32\avayafot.ini moved successfully.
C:\WINDOWS\SYSTEM32\aluginom.ini moved successfully.
C:\WINDOWS\SYSTEM32\ibewodaz.ini moved successfully.
C:\WINDOWS\SYSTEM32\atabofuy.ini moved successfully.
C:\WINDOWS\SYSTEM32\atoyetit.ini moved successfully.
C:\WINDOWS\SYSTEM32\oyemukul.ini moved successfully.
C:\WINDOWS\SYSTEM32\inazikun.ini moved successfully.
C:\WINDOWS\SYSTEM32\uzehiven.ini moved successfully.
C:\WINDOWS\SYSTEM32\ikefiluh.ini moved successfully.
C:\WINDOWS\SYSTEM32\elejobeg.ini moved successfully.
C:\WINDOWS\SYSTEM32\ayavijel.ini moved successfully.
C:\WINDOWS\SYSTEM32\uhafawep.ini moved successfully.
C:\WINDOWS\SYSTEM32\ejurimey.ini moved successfully.
C:\WINDOWS\SYSTEM32\muyipeve.dll moved successfully.
C:\WINDOWS\SYSTEM32\zadowebi.dll moved successfully.
C:\WINDOWS\SYSTEM32\kufubabe.dll moved successfully.
C:\WINDOWS\SYSTEM32\giletisa.dll moved successfully.
C:\WINDOWS\SYSTEM32\larihisu.dll moved successfully.
C:\WINDOWS\SYSTEM32\hosezora.dll moved successfully.
C:\WINDOWS\SYSTEM32\jeyiniyo.dll moved successfully.
C:\WINDOWS\SYSTEM32\pewafahu.dll moved successfully.
C:\WINDOWS\SYSTEM32\gikosiha.dll moved successfully.
C:\WINDOWS\SYSTEM32\romabotu.dll moved successfully.
C:\WINDOWS\SYSTEM32\kujonuva.dll moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\ not found.
========== FILES ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes

User: HelpAssistant
->Temp folder emptied: 268 bytes
->Temporary Internet Files folder emptied: 603 bytes
->Java cache emptied: 100370587 bytes
->FireFox cache emptied: 50681756 bytes
->Google Chrome cache emptied: 916014 bytes

User: HelpAssistant.DHGGS431

User: HelpAssistant.DHGGS431.000
->Temp folder emptied: 7152161 bytes
->Temporary Internet Files folder emptied: 29675857 bytes
->Java cache emptied: 110890005 bytes
->FireFox cache emptied: 36603402 bytes
->Google Chrome cache emptied: 916014 bytes

User: LocalService
->Temp folder emptied: 480 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 66083 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: phil

User: tanja
->Temp folder emptied: 907910 bytes
->Temporary Internet Files folder emptied: 1618543 bytes
->Java cache emptied: 93374962 bytes
->FireFox cache emptied: 42786955 bytes

User: TEIGAN
->Temp folder emptied: 73302502 bytes
->Temporary Internet Files folder emptied: 47630940 bytes
->Java cache emptied: 179505491 bytes
->FireFox cache emptied: 51637581 bytes
->Google Chrome cache emptied: 6175278 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1139743 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 23949375 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 402 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 820.00 mb


OTL by OldTimer - Version 3.1.26.0 log created on 01282010_200021

Files\Folders moved on Reboot…
File move failed. C:\WINDOWS\temp\$$$dq3e scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\$67we.$ scheduled to be moved on reboot.

Registry entries deleted on Reboot…
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>


this is the virustotal scan:


File has already been analysed:
MD5: 6eae8504114ec7e1137564a04bb384ba
First received: 2009.05.12 10:22:08 UTC
Date: 2009.05.12 10:22:08 UTC [>261D]
Results: 25/38
Permalink: analisis/d155ceaeeff61ebbf64f1e8dda25a7189db2cd41c87088414f7af9ce317f0168-1242123728

Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.01.29 Trojan.Win32.Vundo!IK
AhnLab-V3 5.0.0.2 2010.01.28 Win-Trojan/Monder.49152.BA
AntiVir 7.9.1.154 2010.01.28 TR/Crypt.XPACK.Gen
Antiy-AVL 2.0.3.7 2010.01.28 Trojan/Win32.Monder.gen
Authentium 5.2.0.5 2010.01.29 W32/Vundo.C!Generic
Avast 4.8.1351.0 2010.01.28 Win32:MoPack
AVG 9.0.0.730 2010.01.28 Vundo.FV
BitDefender 7.2 2010.01.29 Gen:Trojan.Heur.Vundo.dyW@dClAnjk
CAT-QuickHeal 10.00 2010.01.29 Trojan.Agent.IRC
ClamAV 0.94.1 2010.01.29 -
Comodo 3742 2010.01.28 TrojWare.Win32.MonderB.Gen
DrWeb 5.0.1.12222 2010.01.29 Trojan.Virtumod.based.26
eSafe 7.0.17.0 2010.01.28 Win32.TRCrypt.XPACK
eTrust-Vet 35.2.7269 2010.01.29 Win32/Vundo!generic
F-Prot 4.5.1.85 2010.01.28 W32/Vundo.C!Generic
F-Secure 9.0.15370.0 2010.01.29 Trojan:W32/Vundo.gen!D
Fortinet 4.0.14.0 2010.01.28 W32/Vundo.W!tr
GData 19 2010.01.28 Gen:Trojan.Heur.Vundo.dyW@dClAnjk
Ikarus T3.1.1.80.0 2010.01.29 Trojan.Win32.Vundo
K7AntiVirus 7.10.959 2010.01.28 Trojan.Win32.Monder.bzea
McAfee 5875 2010.01.28 Vundo.gen.w
McAfee+Artemis 5875 2010.01.28 Vundo.gen.w
McAfee-GW-Edition 6.8.5 2010.01.28 Trojan.Crypt.XPACK.Gen
Microsoft 1.5406 2010.01.28 Worm:Win32/Vundo.A
NOD32 4815 2010.01.28 a variant of Win32/Adware.Virtumonde.NFD
nProtect 2009.1.8.0 2010.01.28 Trojan/W32.Monder.49152.AX
Panda 10.0.2.2 2010.01.28 -
PCTools 7.0.3.5 2010.01.29 HeurEngine.MaliciousPacker
Prevx 3.0 2010.01.29 High Risk Fraudulent Security Program
Rising 22.32.04.01 2010.01.29 Packer.Win32.Agent.GEN
Sophos 4.50.0 2010.01.29 Mal/Vundo-C
Sunbelt 3.2.1858.2 2010.01.29 Trojan.Win32.Vundo.Gen (v)
Symantec 20091.2.0.41 2010.01.29 Packed.Generic.217
TheHacker 6.5.0.9.168 2010.01.28 Trojan/Monder.bzea
TrendMicro 9.120.0.1004 2010.01.29 TROJ_VUNDO.SMZ
VBA32 3.12.12.1 2010.01.28 Trojan-Downloader.Exficale
ViRobot 2010.1.29.2161 2010.01.29 -
VirusBuster 5.0.21.0 2010.01.28 -
Additional information
File size: 49152 bytes
MD5 : 6eae8504114ec7e1137564a04bb384ba
SHA1 : 08d4b081ebd88bf587bef5538814f670c9b71e01
SHA256: d155ceaeeff61ebbf64f1e8dda25a7189db2cd41c87088414f7af9ce317f0168
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x105C
timedatestamp…..: 0x40658307 (Sat Mar 27 14:35:03 2004)
machinetype…….: 0x14C (Intel I386)

( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x3000 0x2800 6.48 16fd9babf58d5db1a6fe7af275596d73
0x4000 0x1000 0x600 0.23 75cab2e9195d27d99708dc87eccdfeb8
0x5000 0x3000 0x2400 7.98 838c598d538d458e9874bb59194c4ccb
0x8000 0x3000 0x2200 7.98 391d7653e8d36cc64b94655374daef48
0xB000 0x3000 0x2200 7.98 72e3e55d740110e470fd7eb81edda3d5
0xE000 0xF000 0x2600 7.98 08c2403029cde660833532bee0bca706

( 6 imports )

> advapi32.dll: RegQueryValueExW
> comctl32.dll: InitCommonControlsEx
> comdlg32.dll: PrintDlgExA
> gdi32.dll: Arc, SelectClipPath
> kernel32.dll: ExitProcess, GetModuleHandleW, GetSystemInfo
> user32.dll: DispatchMessageW, TranslateMessage, LoadIconA, GetSystemMetrics

( 0 exports )
TrID : File type identification
Win32 Executable Generic (38.5%)
Win32 Dynamic Link Library (generic) (34.2%)
Clipper DOS Executable (9.1%)
Generic Win/DOS Executable (9.0%)
DOS Executable Generic (9.0%)
ssdeep: 768:bBK9UYWng9/P7ioZC+chMJEIh1wklTEt7rjHe4hjt9kdldWnDxtwyh9uvUZ:bM9UJyP5ehMJ/EZjHnhjkdlJyh9uvUZ
Prevx Info: http://info.prevx.com/aboutprogramtext.asp…2022A00BEB193EF
PEiD : -
RDS : NSRL Reference Data Set

>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
malewarebytes scan:

Malwarebytes' Anti-Malware 1.44
Database version: 3655
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

1/28/2010 11:33:52 PM
mbam-log-2010-01-28 (23-33-52).txt

Scan type: Quick Scan
Objects scanned: 155048
Time elapsed: 16 minute(s), 15 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 26
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 10
Files Infected: 21

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{18cacf0e-72a4-4be1-aa42-dc2ecdb197f1} (Trojan.Banker) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{2850bdc7-2330-4e31-9fa0-88268846539a} (Adware.WhenU) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{18cacf0e-72a4-4be1-aa42-dc2ecdb197f1} (Trojan.Banker) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6825fac3-d7d2-4045-97a2-87df42cb6728} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{6825fac3-d7d2-4045-97a2-87df42cb6728} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8617ef97-58d3-49ca-9fd3-52ab6525c86b} (Rogue.SystemGuard) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\System Guard 2009 (Rogue.SpywareGuard) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\Documents and Settings\HelpAssistant\Application Data\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant\Application Data\FunWebProducts\Data (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant\Application Data\FunWebProducts\Data\TEIGAN (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant.DHGGS431.000\Application Data\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant.DHGGS431.000\Application Data\FunWebProducts\Data (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant.DHGGS431.000\Application Data\FunWebProducts\Data\TEIGAN (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\TEIGAN\Application Data\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\TEIGAN\Application Data\FunWebProducts\Data (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\TEIGAN\Application Data\FunWebProducts\Data\TEIGAN (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs (Rogue.SystemGuard) -> Quarantined and deleted successfully.

Files Infected:
C:\3.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant\Application Data\FunWebProducts\Data\TEIGAN\avatar.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant\Application Data\FunWebProducts\Data\TEIGAN\outfit.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant\Application Data\FunWebProducts\Data\TEIGAN\register.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant\Application Data\FunWebProducts\Data\TEIGAN\zbucks.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant.DHGGS431.000\Application Data\FunWebProducts\Data\TEIGAN\avatar.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant.DHGGS431.000\Application Data\FunWebProducts\Data\TEIGAN\outfit.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant.DHGGS431.000\Application Data\FunWebProducts\Data\TEIGAN\register.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant.DHGGS431.000\Application Data\FunWebProducts\Data\TEIGAN\zbucks.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\TEIGAN\Application Data\FunWebProducts\Data\TEIGAN\avatar.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\TEIGAN\Application Data\FunWebProducts\Data\TEIGAN\outfit.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\TEIGAN\Application Data\FunWebProducts\Data\TEIGAN\register.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\TEIGAN\Application Data\FunWebProducts\Data\TEIGAN\zbucks.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\c.cgm (Rogue.SystemGuard) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\wdoijfazvr.dll (Rogue.SystemGuard) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\track.sys (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\bb1.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\kcms.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\mseggrpid.dll (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\WINDOWS\hosts (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\IE.ico (Malware.Trace) -> Quarantined and deleted successfully.

>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

new OTL scan:

OTL logfile created on: 1/28/2010 11:47:05 PM - Run 2
OTL by OldTimer - Version 3.1.26.0 Folder = C:\Documents and Settings\tanja\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 217.00 Mb Available Physical Memory | 43.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): c:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 0.91 Gb Free Space | 1.22% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DHGGS431
Current User Name: tanja
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\tanja\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe (Musicmatch, Inc.)
PRC - C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe (Musicmatch, Inc.)
PRC - C:\Program Files\Ahead\InCD\InCDsrv.exe (Nero AG)
PRC - C:\Program Files\Ahead\InCD\InCD.exe (Nero AG)
PRC - C:\Program Files\IOGear\ION\IoctlSvc.exe (Prolific Technology Inc.)
PRC - C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
PRC - C:\Program Files\Dantz\Retrospect\retrorun.exe (Dantz Development Corporation)
PRC - C:\WINDOWS\SYSTEM32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\SYSTEM32\LEXBCES.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\SYSTEM32\LEXPPS.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\SYSTEM32\cidaemon.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Logitech\QCDriver\LVComS.exe (Logitech Inc.)
PRC - C:\WINDOWS\SYSTEM32\CTsvcCDA.EXE (Creative Technology Ltd)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\tanja\Desktop\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (Imapi Helper) – C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe (Alex Feinman)
SRV - (InCDsrv) – C:\Program Files\Ahead\InCD\InCDsrv.exe (Nero AG)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (PLFlash DeviceIoControl Service) – C:\Program Files\IOGear\ION\IoctlSvc.exe (Prolific Technology Inc.)
SRV - (Retrospect Helper) – C:\Program Files\Dantz\Retrospect\rthlpsvc.exe (Dantz Development Corporation)
SRV - (RetroLauncher) – C:\Program Files\Dantz\Retrospect\retrorun.exe (Dantz Development Corporation)
SRV - (NVSvc) – C:\WINDOWS\SYSTEM32\nvsvc32.exe (NVIDIA Corporation)
SRV - (NetSvc) – C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation)
SRV - (LexBceS) – C:\WINDOWS\SYSTEM32\LEXBCES.EXE (Lexmark International, Inc.)
SRV - (TermService) – C:\WINDOWS\SYSTEM32\termsrv32.dll (Microsoft Corporation)
SRV - (Creative Service for CDROM Access) – C:\WINDOWS\SYSTEM32\CTsvcCDA.EXE (Creative Technology Ltd)


========== Driver Services (SafeList) ==========

DRV - (PxHelp20) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (fssfltr) – C:\WINDOWS\SYSTEM32\DRIVERS\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (amdagp) – C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (tmcomm) – C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys (Trend Micro Inc.)
DRV - (Secdrv) – C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (InCDfs) – C:\WINDOWS\SYSTEM32\DRIVERS\InCDfs.sys (Nero AG)
DRV - (InCDPass) – C:\WINDOWS\SYSTEM32\DRIVERS\InCDpass.sys (Nero AG)
DRV - (incdrm) – C:\WINDOWS\SYSTEM32\DRIVERS\InCDrm.sys (Nero AG)
DRV - (gameenum) – C:\WINDOWS\SYSTEM32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (iAimFP4) – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)
DRV - (iAimFP3) – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)
DRV - (iAimTV4) – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)
DRV - (iAimTV3) – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)
DRV - (iAimTV1) – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)
DRV - (iAimTV0) – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)
DRV - (iAimFP0) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)
DRV - (iAimFP1) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)
DRV - (iAimFP2) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)
DRV - (i81x) – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (Freedom) – C:\WINDOWS\freedom.backup.dat ()
DRV - (pfc) – C:\WINDOWS\SYSTEM32\DRIVERS\pfc.sys (Padus, Inc.)
DRV - (HSFHWBS2) – C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (nv) – C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (P16X) Creative SB Live! Series (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\P16X.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:\WINDOWS\SYSTEM32\DRIVERS\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\SYSTEM32\DRIVERS\ctoss2k.sys (Creative Technology Ltd.)
DRV - (mdmxsdk) – C:\WINDOWS\SYSTEM32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (E100B) Intel® – C:\WINDOWS\SYSTEM32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (ultra) – C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (sym_u3) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (Sparrow) – C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (ql1280) – C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (ql12160) – C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (Ptilink) – C:\WINDOWS\SYSTEM32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (mraid35x) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (dac2w2k) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (CmdIde) – C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (asc) – C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (LVBulk) – C:\WINDOWS\SYSTEM32\DRIVERS\LVBulk.sys (Logitech Inc.)
DRV - (QCDonner) Logitech QuickCam Express(PID_0840) – C:\WINDOWS\SYSTEM32\DRIVERS\lvcd.sys (Logitech Inc.)
DRV - (lusbaudio) – C:\WINDOWS\SYSTEM32\DRIVERS\LVSound2.sys (Logitech Inc.)
DRV - (LVVI500A) – C:\WINDOWS\SYSTEM32\DRIVERS\lvvi500a.sys (Tekom Technologies, Inc.)
DRV - (MODEMCSA) – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)
DRV - (ICAM5USB) Intel® – C:\WINDOWS\SYSTEM32\DRIVERS\Icam5USB.sys (Microsoft Corporation)
DRV - (mrtRate) – C:\WINDOWS\SYSTEM32\DRIVERS\MrtRate.sys (Marimba, Inc.)
DRV - (ScFBPNT3) – C:\WINDOWS\SYSTEM32\DRIVERS\ScFBPNT3.sys ()
DRV - (PfModNT) – C:\WINDOWS\SYSTEM32\PFMODNT.SYS (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ca.rd.yahoo.com/customize/ycomp/def…://ca.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:3.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/23 16:05:18 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/23 16:05:10 | 00,000,000 | —D | M]

[2008/11/01 10:49:18 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\Mozilla\Extensions
[2010/01/28 19:58:02 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\Mozilla\Firefox\Profiles\iz4ah2te.default\extensions
[2009/10/23 19:23:02 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\Mozilla\Firefox\Profiles\iz4ah2te.default\extensions\[removed]
[2010/01/28 19:58:04 | 00,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/03/03 21:06:21 | 00,000,423 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.igetnet.com
O1 - Hosts: 127.0.0.1 code.ignphrases.com
O1 - Hosts: 127.0.0.1 clear-search.com
O1 - Hosts: 127.0.0.1 r1.clrsch.com
O1 - Hosts: 127.0.0.1 sds.clrsch.com
O1 - Hosts: 127.0.0.1 status.clrsch.com
O1 - Hosts: 127.0.0.1 www.clrsch.com
O1 - Hosts: 127.0.0.1 clr-sch.com
O1 - Hosts: 127.0.0.1 sds-qckads.com
O1 - Hosts: 127.0.0.1 status.qckads.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe (Dell)
O4 - HKLM..\Run: [fssui] C:\Program Files\Windows Live\Family Safety\fsui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVComS.exe (Logitech Inc.)
O4 - HKLM..\Run: [MimBoot] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mimboot.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\SYSTEM32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [NBJ] C:\Program Files\Ahead\Nero BackItUp\NBJ.exe (Ahead Software AG)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\tanja\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = _ [binary data]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideClock = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoManageMyComputerVerb = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuPinnedList = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoUserNameInStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartmenuLogoff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuSubFolders = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCommonGroups = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPrinterTabs = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAddPrinter = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPrinters = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetworkConnections = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetFolders = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoShellSearchButton = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarCustomize = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeAnimation = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeKeyboardNavigationIndicators = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThemesTab = 0
O8 - Extra context menu item: &Yahoo;! Search - C:\Program Files\Yahoo!\Common [2010/01/23 17:07:06 | 00,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &Dictionary; - C:\Program Files\Yahoo!\Common [2010/01/23 17:07:06 | 00,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &Maps; - C:\Program Files\Yahoo!\Common [2010/01/23 17:07:06 | 00,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &SMS; - C:\Program Files\Yahoo!\Common [2010/01/23 17:07:06 | 00,000,000 | —D | M]
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\TEIGAN\Start Menu\Programs\IMVU\Run IMVU.lnk ()
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: 21 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00000075-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/voxmsdec.CAB (Reg Error: Key error.)
O16 - DPF: {00000075-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/voxacm.CAB (Reg Error: Key error.)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (Reg Error: Key error.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {33363249-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/i263_32.cab (Reg Error: Key error.)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://bin.mcafee.com/molbin/shared/mcinsc…76/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo…otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…8175.5361689815 (Reg Error: Key error.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab (Reg Error: Key error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.4.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} http://download.mcafee.com/molbin/iss-loc/…360/mcfscan.cab (McFreeScan Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Backgammon http://download.games.yahoo.com/games/clients/y/at0_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Chat http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Cribbage http://download.games.yahoo.com/games/clients/y/it1_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Literati http://download.games.yahoo.com/games/clients/y/tt1_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Pool 2 http://download.games.yahoo.com/games/clients/y/potc_x.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop Components:0 () - file:///C:/Documents%20and%20Settings/tanja/My%20Documents/My%20Pictures/whatnots/my%20very%20own%20sigs/snags%20for%20tags/1more%20fantasy%20art/more/dragon.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\tanja\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\tanja\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/01/28 21:26:31 | 00,000,000 | —D | C] – C:\Documents and Settings\tanja\Application Data\Malwarebytes
[2010/01/28 21:26:24 | 00,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/28 21:26:22 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/01/28 21:26:21 | 00,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/01/28 21:26:21 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/01/28 21:24:40 | 05,115,824 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\tanja\Desktop\mbam-setup.exe
[2010/01/28 20:00:21 | 00,000,000 | —D | C] – C:\_OTL
[2010/01/25 19:34:12 | 00,547,328 | —- | C] (OldTimer Tools) – C:\Documents and Settings\tanja\Desktop\OTL.exe
[2010/01/23 14:08:41 | 00,000,000 | —D | C] – C:\Documents and Settings\tanja\Application Data\vlc
[2010/01/23 14:02:58 | 00,000,000 | —D | C] – C:\Documents and Settings\tanja\My Documents\Graboid
[2010/01/23 13:19:52 | 00,000,000 | —D | C] – C:\Documents and Settings\tanja\Application Data\MozillaControl
[2010/01/23 13:19:48 | 00,000,000 | —D | C] – C:\Documents and Settings\tanja\Local Settings\Application Data\Graboid
[2010/01/23 13:18:56 | 00,000,000 | —D | C] – C:\Program Files\Mozilla ActiveX Control v1.7.12
[2010/01/23 13:17:26 | 00,000,000 | —D | C] – C:\Program Files\VideoLAN
[2010/01/23 13:16:52 | 00,000,000 | —D | C] – C:\Program Files\Graboid
[2010/01/12 13:15:34 | 00,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/01/12 13:15:34 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/01/12 13:15:34 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/01/12 13:10:22 | 00,471,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aclayers.dll
[2010/01/12 13:05:10 | 00,000,000 | —D | C] – C:\Program Files\Buddy Spy
[2009/11/06 19:37:01 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/11/06 19:32:08 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2008/11/21 13:52:02 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2008/11/01 11:19:15 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2007/08/06 12:15:57 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/05/08 16:30:14 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2007/05/08 16:08:07 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2006/12/16 19:38:32 | 00,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\tanja\Application Data\pcouffin.sys
[2006/07/01 14:46:19 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Help
[2006/07/01 14:46:19 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Help
[2006/07/01 09:48:47 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\ApplicationHistory
[2003/07/22 20:01:30 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2002/04/11 00:41:00 | 00,065,536 | —- | C] ( ) – C:\WINDOWS\System32\A3d.dll

========== Files - Modified Within 30 Days ==========

[2010/01/29 00:02:00 | 00,000,412 | —- | M] () – C:\WINDOWS\tasks\Symantec NetDetect.job
[2010/01/29 00:00:00 | 00,000,424 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{2251EC52-B660-4E59-B002-5A66781184C0}.job
[2010/01/28 23:38:11 | 00,012,598 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/01/28 23:37:36 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/01/28 23:37:34 | 00,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/01/28 23:37:33 | 53,587,5584 | -HS- | M] () – C:\hiberfil.sys
[2010/01/28 23:36:42 | 14,942,208 | —- | M] () – C:\Documents and Settings\tanja\ntuser.dat
[2010/01/28 23:36:19 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\tanja\NTUSER.INI
[2010/01/28 21:26:27 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/28 21:24:46 | 05,115,824 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\tanja\Desktop\mbam-setup.exe
[2010/01/25 22:43:55 | 02,096,656 | -H– | M] () – C:\Documents and Settings\tanja\Local Settings\Application Data\IconCache.db
[2010/01/25 21:21:25 | 00,169,467 | —- | M] () – C:\Documents and Settings\tanja\My Documents\error.JPG
[2010/01/25 20:44:15 | 53,590,4256 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2010/01/25 19:34:13 | 00,547,328 | —- | M] (OldTimer Tools) – C:\Documents and Settings\tanja\Desktop\OTL.exe
[2010/01/25 19:33:30 | 00,195,724 | —- | M] () – C:\Documents and Settings\tanja\My Documents\scrnsht maintenence instructions3.JPG
[2010/01/25 19:31:12 | 00,157,623 | —- | M] () – C:\Documents and Settings\tanja\My Documents\scrnsht maintenence instructions2.JPG
[2010/01/25 19:30:12 | 00,200,357 | —- | M] () – C:\Documents and Settings\tanja\My Documents\scrnsht maintenence instructions1.JPG
[2010/01/25 03:15:49 | 00,000,718 | —- | M] () – C:\WINDOWS\lexstat.ini
[2010/01/23 17:00:43 | 00,001,917 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/01/12 12:24:54 | 00,000,552 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/01/12 11:52:13 | 00,000,036 | —- | M] () – C:\Documents and Settings\tanja\Local Settings\Application Data\housecall.guid.cache
[2010/01/12 08:52:05 | 00,074,176 | —- | M] () – C:\Documents and Settings\tanja\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/01/07 16:07:14 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/07 16:07:04 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys

========== Files Created - No Company Name ==========

[2010/01/28 21:26:27 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/26 22:46:01 | 53,587,5584 | -HS- | C] () – C:\hiberfil.sys
[2010/01/25 21:21:24 | 00,169,467 | —- | C] () – C:\Documents and Settings\tanja\My Documents\error.JPG
[2010/01/25 19:33:30 | 00,195,724 | —- | C] () – C:\Documents and Settings\tanja\My Documents\scrnsht maintenence instructions3.JPG
[2010/01/25 19:31:12 | 00,157,623 | —- | C] () – C:\Documents and Settings\tanja\My Documents\scrnsht maintenence instructions2.JPG
[2010/01/25 19:30:12 | 00,200,357 | —- | C] () – C:\Documents and Settings\tanja\My Documents\scrnsht maintenence instructions1.JPG
[2010/01/24 13:42:27 | 00,001,599 | —- | C] () – C:\Remote Assistance.lnk
[2010/01/24 13:42:27 | 00,000,792 | —- | C] () – C:\Windows Media Player.lnk
[2010/01/12 12:24:54 | 00,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/01/12 11:52:13 | 00,000,036 | —- | C] () – C:\Documents and Settings\tanja\Local Settings\Application Data\housecall.guid.cache
[2010/01/04 16:24:39 | 14,942,208 | —- | C] () – C:\Documents and Settings\tanja\ntuser.dat
[2007/05/08 15:09:57 | 00,000,006 | —- | C] () – C:\Documents and Settings\tanja\Application Data\dm.ini
[2007/05/08 15:09:56 | 00,000,901 | —- | C] () – C:\Documents and Settings\tanja\Application Data\AdobeDLM.log
[2006/12/16 19:38:32 | 00,081,920 | —- | C] () – C:\Documents and Settings\tanja\Application Data\ezpinst.exe
[2006/12/16 19:38:32 | 00,007,176 | —- | C] () – C:\Documents and Settings\tanja\Application Data\pcouffin.cat
[2006/12/16 19:38:32 | 00,001,144 | —- | C] () – C:\Documents and Settings\tanja\Application Data\pcouffin.inf
[2006/12/16 19:38:32 | 00,000,055 | —- | C] () – C:\Documents and Settings\tanja\Application Data\pcouffin.log
[2006/07/16 16:10:18 | 00,000,260 | —- | C] () – C:\WINDOWS\_delis32.ini
[2006/07/01 09:48:47 | 00,000,137 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\fusioncache.dat
[2006/06/25 16:43:35 | 00,000,125 | -HS- | C] () – C:\Documents and Settings\tanja\Application Data\.zreglib
[2006/05/25 13:33:23 | 00,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/02/01 15:20:19 | 00,000,000 | —- | C] () – C:\WINDOWS\lgfwup.ini
[2006/02/01 15:00:25 | 00,040,960 | —- | C] () – C:\Program Files\Uninstall_CDS.exe
[2006/01/11 10:05:01 | 00,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/09/02 20:44:52 | 00,000,000 | —- | C] () – C:\WINDOWS\pcfriend.INI
[2005/08/26 19:25:53 | 00,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2005/06/17 14:48:02 | 00,032,397 | —- | C] () – C:\WINDOWS\SGTBox.INI
[2005/05/09 08:39:34 | 00,000,032 | —- | C] () – C:\WINDOWS\basefx.INI
[2005/01/31 13:07:13 | 00,000,000 | —- | C] () – C:\WINDOWS\QFN.ini
[2005/01/31 13:07:13 | 00,000,000 | —- | C] () – C:\WINDOWS\QDQICK.ini
[2005/01/26 13:04:37 | 00,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2004/11/24 01:53:06 | 00,155,648 | —- | C] () – C:\WINDOWS\System32\winupdak.dll
[2004/11/24 01:41:01 | 00,155,648 | —- | C] () – C:\WINDOWS\System32\akupd.dll
[2004/11/23 07:48:06 | 00,000,262 | —- | C] () – C:\WINDOWS\usta32.ini
[2004/11/07 17:33:10 | 00,000,005 | —- | C] () – C:\Documents and Settings\All Users\Application Data\DirectCDUserNameE.txt
[2004/10/02 17:47:43 | 00,000,035 | —- | C] () – C:\WINDOWS\A4W.INI
[2004/10/02 17:46:55 | 00,000,572 | —- | C] () – C:\WINDOWS\maxlink.ini
[2004/10/02 17:44:57 | 00,000,000 | —- | C] () – C:\WINDOWS\OP70.INI
[2004/10/02 17:43:46 | 00,001,472 | —- | C] () – C:\WINDOWS\pstudio.ini
[2004/10/02 17:43:46 | 00,000,028 | —- | C] () – C:\WINDOWS\album.ini
[2004/10/02 17:43:46 | 00,000,021 | —- | C] () – C:\WINDOWS\Ps_setup.ini
[2004/10/02 17:42:09 | 00,016,032 | —- | C] () – C:\WINDOWS\System32\drivers\ScFBPNT3.sys
[2004/10/02 17:05:50 | 00,000,718 | —- | C] () – C:\WINDOWS\lexstat.ini
[2004/10/02 17:05:49 | 00,163,840 | —- | C] () – C:\WINDOWS\System32\ldepcl32.dll
[2004/10/02 17:05:48 | 00,328,704 | —- | C] () – C:\WINDOWS\System32\dosfnt32.dll
[2004/09/18 18:42:25 | 00,000,129 | —- | C] () – C:\WINDOWS\CTWave32.ini
[2004/07/19 02:57:09 | 00,011,776 | —- | C] () – C:\WINDOWS\System32\ZPORT4AS.dll
[2004/07/05 13:54:08 | 00,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2004/07/04 17:25:26 | 00,364,544 | —- | C] () – C:\WINDOWS\System32\psCamDat.dll
[2004/06/20 12:37:34 | 00,000,028 | —- | C] () – C:\WINDOWS\System32\autoscan3.dll
[2004/05/24 00:25:24 | 00,000,035 | —- | C] () – C:\Program Files\Default.PLS
[2004/05/13 10:55:56 | 00,000,032 | —- | C] () – C:\WINDOWS\thxcfg.ini
[2004/04/29 12:49:49 | 00,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll
[2004/04/29 12:48:31 | 00,000,034 | —- | C] () – C:\WINDOWS\h263test.ini
[2004/04/29 11:54:16 | 00,524,288 | —- | C] () – C:\WINDOWS\System32\InetIPLA6.dll
[2004/04/29 11:54:16 | 00,516,096 | —- | C] () – C:\WINDOWS\System32\InetIPLM6.dll
[2004/04/29 11:54:16 | 00,512,000 | —- | C] () – C:\WINDOWS\System32\InetIPLP6.dll
[2004/04/29 11:54:16 | 00,503,808 | —- | C] () – C:\WINDOWS\System32\InetIPLPX.dll
[2004/04/29 11:54:16 | 00,495,616 | —- | C] () – C:\WINDOWS\System32\InetIPLM5.dll
[2004/04/29 11:54:16 | 00,491,520 | —- | C] () – C:\WINDOWS\System32\InetIPLP5.dll
[2004/04/29 11:54:16 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\InetIPL.dll
[2004/04/29 11:54:16 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\Cpuinf32.dll
[2004/02/20 22:50:14 | 00,000,032 | —- | C] () – C:\Program Files\Draw Joy Bib.dat
[2004/01/24 17:10:30 | 00,000,103 | —- | C] () – C:\WINDOWS\CTRec.INI
[2003/12/11 17:51:07 | 00,004,294 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2003/12/03 16:07:00 | 00,000,128 | —- | C] () – C:\Documents and Settings\tanja\Local Settings\Application Data\fusioncache.dat
[2003/11/17 23:37:20 | 00,072,192 | —- | C] () – C:\WINDOWS\System32\zlib.dll
[2003/10/08 13:34:26 | 00,121,440 | —- | C] () – C:\WINDOWS\System32\MSDRMCtrl.dll
[2003/10/06 14:16:00 | 00,027,136 | —- | C] () – C:\WINDOWS\System32\nvcod.dll
[2003/09/15 09:10:43 | 00,061,678 | —- | C] () – C:\Documents and Settings\tanja\Application Data\PFP110JPR.{PB
[2003/09/15 09:10:43 | 00,012,358 | —- | C] () – C:\Documents and Settings\tanja\Application Data\PFP110JCM.{PB
[2003/09/03 08:44:52 | 00,000,070 | —- | C] () – C:\WINDOWS\400A3C1E.ini
[2003/09/03 07:28:42 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/09/02 07:06:42 | 00,000,170 | —- | C] () – C:\WINDOWS\GetServer.ini
[2003/08/14 22:09:09 | 00,114,176 | —- | C] () – C:\Documents and Settings\tanja\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2003/08/11 11:30:38 | 00,000,823 | —- | C] () – C:\WINDOWS\TSC.ini
[2003/08/11 11:30:37 | 00,071,749 | —- | C] () – C:\WINDOWS\HCExtOutput.dll
[2003/08/10 13:28:31 | 00,000,030 | —- | C] () – C:\WINDOWS\Morpheus.INI
[2003/08/10 12:23:06 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2003/08/10 12:22:26 | 00,000,021 | —- | C] () – C:\WINDOWS\CS_setup.ini
[2003/08/10 11:24:45 | 00,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2003/07/22 20:37:17 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/07/22 20:32:24 | 00,000,185 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/07/22 20:32:22 | 00,000,846 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/07/22 20:30:53 | 00,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2003/07/22 20:30:41 | 00,002,092 | —- | C] () – C:\WINDOWS\System32\P16X.ini
[2003/07/22 20:30:41 | 00,000,026 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2003/07/22 20:30:40 | 00,006,175 | —- | C] () – C:\WINDOWS\MIXDEF.INI
[2003/07/22 20:30:40 | 00,005,917 | —- | C] () – C:\WINDOWS\SBMIXDEF.INI
[2003/07/22 20:30:40 | 00,000,064 | —- | C] () – C:\WINDOWS\P16x.ini
[2003/07/22 20:30:14 | 00,000,245 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2003/07/22 20:26:34 | 00,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/07/22 20:14:40 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/07/22 20:02:48 | 00,000,480 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2003/07/08 13:41:48 | 00,047,616 | —- | C] () – C:\WINDOWS\System32\P16X.dll
[2002/12/19 21:12:54 | 00,015,360 | —- | C] () – C:\WINDOWS\System32\selm_isx.dll
[2002/12/05 16:51:00 | 00,059,392 | R— | C] () – C:\WINDOWS\streamhlp.dll
[2002/06/10 13:16:22 | 00,005,187 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[1999/08/11 23:00:00 | 01,708,032 | —- | C] () – C:\WINDOWS\System32\MSO97V.DLL
[1999/08/11 23:00:00 | 00,036,864 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1999/08/11 23:00:00 | 00,032,768 | —- | C] () – C:\WINDOWS\System32\MSORFS.DLL
[1999/08/10 16:02:20 | 00,116,736 | —- | C] () – C:\WINDOWS\System32\LFKODAK.DLL
[1999/08/10 16:02:16 | 00,343,040 | —- | C] () – C:\WINDOWS\System32\lffpx7.dll
[1999/07/23 13:46:48 | 00,000,116 | —- | C] () – C:\WINDOWS\AuHCcup1.ini
[1999/07/23 10:53:20 | 00,129,536 | —- | C] () – C:\WINDOWS\AuHCcup1.dll
[1979/12/31 22:00:00 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9AB338B9
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D37AE80B
< End of report >


Thanks again ")
Hi lilfirecat69,

That looks a lot better. Was Norton (Symantec) installed on this computer at one time?

Let's do a quick check of something, then continue.



Please download MBR.exe and save it to your desktop

  • Click your start button, click run
  • Copy and paste the following line in to the run box and click OK (don't mss the opening and closing "" marks)

    "%userprofile%\desktop\mbr.exe" -t>"%userprofile%\Desktop\mbr.txt"
A log will be produced, MBR.log on your desktop.

Please open this log in Notepad and post its contents in your next reply.
Hi Oldman960
the code when I first ran it, said there was no file associated with it ,but I tried it again and then it produced the log.

here is the mbr log.

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x82C325C8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x82c325c8
NDIS: Intel® PRO/100 VE Network Connection -> SendCompleteHandler -> 0x82312330
Warning: possible MBR rootkit infection !
copy of MBR has been found in sector 0x094FE9BD
malicious code @ sector 0x094FE9C0 !
PE file found in sector at 0x094FE9D6 !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.
Hi lilfirecat69,


Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield
  • Do not copy the word CODE , please note the script starts with the :
    :filefind
    atapi.*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt




Please read through the instructions to familarize youself with what to expect when the tool runs.

It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Link 1or Link 2 to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, before you save it to your desktop, rename Combofix to jgh.exe

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on ComboFix.exe (jgh.exe in your case) & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • combofix log
  • SytemLook log
How is the computer?

Thanks
Hi Oldman960 here is the first of the logs.. systemlook: SystemLook v1.0 by jpshortstuff (11.01.10) Log created at 12:02 on 29/01/2010 by tanja (Administrator - Elevation successful) ========== filefind ========== Searching for "atapi.*" C:\DELL\ATAPI.EXE –a— 28672 bytes [13:31 03/09/2002] [13:31 03/09/2002] 9C559E4CF8C3B2268818F1F6C6B1EE39 C:\I386\atapi.sys –a— 87040 bytes [03:24 31/07/2003] [20:43 31/01/2003] 3C33F5479520844A186C2D43ECFFD477 C:\WINDOWS\$NtServicePackUninstall$\atapi.sys —–c 95360 bytes [04:58 07/09/2008] [05:59 04/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51 C:\WINDOWS\ServicePackFiles\i386\atapi.sys —— 96512 bytes [05:59 04/08/2004] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674 C:\WINDOWS\SYSTEM32\DRIVERS\atapi.sys –a— 95360 bytes [16:27 03/09/2002] [05:59 04/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51 -=End Of File=- I have read through the instructions and I am off to disable the firewall, antispyware etc.. and download the combofix. back in a bit . LFC
Hi Oldman960

here is the combofix log:

ComboFix 10-01-29.02 - tanja 01/29/2010 13:24:45.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.286 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\jgh.exe
.
PEV Error: ProgramsFolder

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\desktop.ini
c:\documents and settings\tanja\My Documents\ZbThumbnail.info
C:\test.txt
c:\windows\BackUp
c:\windows\BackUp\090203.dat
c:\windows\box boat blue.ico
c:\windows\Downloaded Program Files\rave
c:\windows\Downloaded Program Files\rave\avirexe.vdm
c:\windows\Downloaded Program Files\rave\avirscr.vdm
c:\windows\Downloaded Program Files\rave\base.vdm
c:\windows\Downloaded Program Files\rave\daily.vdm
c:\windows\Downloaded Program Files\rave\daily.vdt
c:\windows\Downloaded Program Files\rave\filters.vdm
c:\windows\Downloaded Program Files\rave\kernel.vdk
c:\windows\Downloaded Program Files\rave\keyring.vdk
c:\windows\Downloaded Program Files\rave\mapi_vdm.vdm
c:\windows\Downloaded Program Files\rave\modules.vdk
c:\windows\Downloaded Program Files\rave\rav8def.vdm
c:\windows\Downloaded Program Files\rave\rufs.vdm
c:\windows\Downloaded Program Files\rave\rufsplg.vdm
c:\windows\Downloaded Program Files\rave\unarch.vdm
c:\windows\Downloaded Program Files\rave\unmail.vdm
c:\windows\Downloaded Program Files\rave\unpack.vdm
c:\windows\EventSystem.log
c:\windows\inform.dat
c:\windows\patch.exe
c:\windows\system\oeminfo.ini
c:\windows\system32\Data
c:\windows\system32\mx
c:\windows\system32\open.ico
c:\windows\system32\part_4Zip .RB0
c:\windows\system32\part_4Zip .z

.
original MBR restored successfully !
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_ISEXENG
——-\Legacy_ZESOFT


((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-29 )))))))))))))))))))))))))))))))
.

2010-01-29 04:26 . 2010-01-29 04:26 ——– d—–w- c:\documents and settings\tanja\Application Data\Malwarebytes
2010-01-29 04:26 . 2010-01-07 23:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-29 04:26 . 2010-01-29 04:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-29 04:26 . 2010-01-29 06:31 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-29 04:26 . 2010-01-07 23:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-29 03:00 . 2010-01-29 03:00 ——– d—–w- C:\_OTL
2010-01-26 04:35 . 2010-01-26 04:35 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2010-01-24 03:35 . 2009-06-07 01:04 34 —-a-w- c:\documents and settings\HelpAssistant.DHGGS431.000\jagex_runescape_preferences.dat
2010-01-24 00:37 . 2010-01-24 03:43 ——– d—–w- c:\documents and settings\HelpAssistant.DHGGS431.000\UserData
2010-01-24 00:37 . 2010-01-24 00:37 ——– d—–w- c:\documents and settings\HelpAssistant.DHGGS431.000\Tracing
2010-01-24 00:37 . 2010-01-24 03:43 ——– d—–w- c:\documents and settings\HelpAssistant.DHGGS431.000\Shared
2010-01-24 00:36 . 2010-01-24 03:43 ——– d—–w- c:\documents and settings\HelpAssistant.DHGGS431.000\PrivacIE
2010-01-24 00:36 . 2010-01-24 00:37 ——– d—–w- c:\documents and settings\HelpAssistant.DHGGS431.000\SecurityScans
2010-01-24 00:36 . 2010-01-24 00:36 ——– d—–w- c:\documents and settings\HelpAssistant.DHGGS431.000\null
2010-01-24 00:24 . 2010-01-24 03:35 ——– d—–w- c:\documents and settings\HelpAssistant.DHGGS431.000\Incomplete
2010-01-24 00:24 . 2010-01-24 03:35 ——– d—–w- c:\documents and settings\HelpAssistant.DHGGS431.000\IETldCache
2010-01-24 00:24 . 2010-01-24 00:24 ——– d—–w- c:\documents and settings\HelpAssistant.DHGGS431.000\jmeeting
2010-01-24 00:24 . 2010-01-24 00:24 ——– d—–w- c:\documents and settings\HelpAssistant.DHGGS431.000\IECompatCache
2010-01-24 00:23 . 2010-01-24 03:35 ——– d—–w- c:\documents and settings\HelpAssistant.DHGGS431.000\Contacts
2010-01-24 00:19 . 2010-01-24 03:21 ——– d—–w- c:\documents and settings\HelpAssistant.DHGGS431.000\.limewire
2010-01-24 00:19 . 2010-01-24 00:19 ——– d—–w- c:\documents and settings\HelpAssistant.DHGGS431.000\.housecall6.6
2010-01-24 00:18 . 2010-01-24 00:19 ——– d—–w- c:\documents and settings\HelpAssistant.DHGGS431.000\.housecall
2010-01-23 23:14 . 2010-01-23 23:14 ——– d—–w- c:\documents and settings\HelpAssistant.DHGGS431
2010-01-23 23:08 . 2010-01-23 23:08 ——– d—–w- c:\windows\system32\wbem\Repository
2010-01-23 21:08 . 2010-01-23 21:08 ——– d—–w- c:\documents and settings\tanja\Application Data\vlc
2010-01-23 20:19 . 2010-01-23 20:21 ——– d—–w- c:\documents and settings\tanja\Application Data\MozillaControl
2010-01-23 20:19 . 2010-01-23 22:55 ——– d—–w- c:\documents and settings\tanja\Local Settings\Application Data\Graboid
2010-01-23 20:18 . 2010-01-23 20:18 ——– d—–w- c:\program files\Mozilla ActiveX Control v1.7.12
2010-01-23 20:17 . 2010-01-23 20:17 ——– d—–w- c:\program files\VideoLAN
2010-01-23 20:16 . 2010-01-23 22:57 ——– d—–w- c:\program files\Graboid
2010-01-23 06:21 . 2009-06-07 01:04 34 —-a-w- c:\documents and settings\HelpAssistant\jagex_runescape_preferences.dat
2010-01-22 02:45 . 2010-01-23 23:29 ——– d—–w- c:\documents and settings\HelpAssistant\UserData
2010-01-22 02:45 . 2010-01-23 23:05 ——– d—–w- c:\documents and settings\HelpAssistant\Tracing
2010-01-22 02:44 . 2010-01-23 23:05 ——– d—–w- c:\documents and settings\HelpAssistant\Shared
2010-01-22 02:44 . 2010-01-22 02:44 ——– d—–w- c:\documents and settings\HelpAssistant\SecurityScans
2010-01-22 02:33 . 2010-01-23 23:29 ——– d—–w- c:\documents and settings\HelpAssistant\Incomplete
2010-01-22 02:33 . 2010-01-23 23:29 ——– d—–w- c:\documents and settings\HelpAssistant\IETldCache
2010-01-22 02:33 . 2010-01-23 23:29 ——– d—–w- c:\documents and settings\HelpAssistant\IECompatCache
2010-01-22 02:33 . 2010-01-23 23:05 ——– d—–w- c:\documents and settings\HelpAssistant\jmeeting
2010-01-22 02:32 . 2010-01-23 23:05 ——– d—–w- c:\documents and settings\HelpAssistant\Contacts
2010-01-22 02:30 . 2010-01-23 23:28 ——– d—–w- c:\documents and settings\HelpAssistant\.limewire
2010-01-22 02:30 . 2010-01-23 23:06 ——– d—–w- c:\documents and settings\HelpAssistant\.housecall6.6
2010-01-22 02:30 . 2010-01-23 23:06 ——– d—–w- c:\documents and settings\HelpAssistant\.housecall
2010-01-22 02:29 . 2010-01-23 23:06 ——– d-s—w- c:\documents and settings\HelpAssistant
2010-01-12 20:10 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2010-01-12 20:05 . 2010-01-12 20:05 ——– d—–w- c:\program files\Buddy Spy
2010-01-12 19:24 . 2010-01-12 19:24 552 —-a-w- c:\windows\system32\d3d8caps.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-24 06:37 . 2007-04-17 22:33 ——– d—–w- c:\program files\Google
2010-01-24 05:08 . 2009-01-18 21:30 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-01-24 00:03 . 2007-05-08 23:01 ——– d—–w- c:\documents and settings\All Users\Application Data\Retrospect
2010-01-23 23:29 . 2008-12-31 02:52 ——– d—–w- c:\documents and settings\tanja\Application Data\HouseCall 6.6
2010-01-20 18:21 . 2009-06-15 02:47 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-12 20:15 . 2004-06-27 21:27 ——– d—–w- c:\program files\Java
2010-01-12 20:13 . 2010-01-12 20:13 152576 —-a-w- c:\documents and settings\tanja\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-01-12 20:13 . 2010-01-12 20:13 79488 —-a-w- c:\documents and settings\tanja\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-12 15:52 . 2003-08-06 19:40 74176 —-a-w- c:\documents and settings\tanja\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-22 03:48 . 2009-12-22 03:48 ——– d—–w- c:\program files\EA GAMES
2009-12-21 19:14 . 2004-02-07 00:05 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-04 18:46 . 2009-12-04 18:46 ——– d—–w- c:\documents and settings\tanja\Application Data\DivX
2009-12-01 04:25 . 2007-04-07 03:38 ——– d—–w- c:\program files\Maxis
2009-11-21 15:51 . 2002-09-03 16:26 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-10 02:42 . 2005-10-03 03:22 74176 —-a-w- c:\documents and settings\TEIGAN\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2004-10-01 22:00 . 2006-02-01 22:00 40960 —-a-w- c:\program files\Uninstall_CDS.exe
2004-05-24 07:25 . 2004-05-24 07:25 35 —-a-w- c:\program files\Default.PLS
2004-02-23 23:12 . 2004-02-21 05:50 32 —-a-w- c:\program files\Draw Joy Bib.dat
2009-09-25 16:41 . 2009-09-25 16:41 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-06-02 1957888]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-01-12 2002160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DwlClient"="c:\program files\Common Files\Dell\EUSW\Support.exe" [2005-10-14 69632]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\System32\IME\PINTLGNT\ImScInst.exe" [2002-09-03 59392]
"PHIME2002ASync"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2002-09-03 455168]
"PHIME2002A"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2002-09-03 455168]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-12-09 32768]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2005-07-08 1397760]
"LVCOMS"="c:\program files\Common Files\Logitech\QCDriver\LVCOMS.EXE" [2001-09-24 98304]
"fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-08-06 647520]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~1\mimboot.exe" [2006-01-19 11776]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="c:\windows\System32\NVMCTRAY.DLL" [2003-10-06 49152]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-20 17:10 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL 7.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AOL 7.0 Tray Icon.lnk
backup=c:\windows\pss\AOL 7.0 Tray Icon.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^tanja^Start Menu^Programs^Startup^PalNetaware.lnk]
path=c:\documents and settings\tanja\Start Menu\Programs\Startup\PalNetaware.lnk
backup=c:\windows\pss\PalNetaware.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\diagent]
2002-04-03 06:01 135264 —-a-w- c:\program files\Creative\SBLive\Diagnostics\diagent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
2002-08-14 23:22 28672 —-a-r- c:\windows\SYSTEM32\DSentry.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMS]
2001-09-24 15:39 98304 —-a-w- c:\program files\Common Files\Logitech\QCDriver\LVComS.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
2001-07-09 18:50 155648 —-a-w- c:\windows\SYSTEM32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 18:50 155648 —-a-w- c:\windows\SYSTEM32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2003-10-06 21:16 5058560 —-a-w- c:\windows\SYSTEM32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2003-10-06 21:16 741376 —-a-w- c:\windows\SYSTEM32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QAGENT]
2001-08-01 17:30 94208 —-a-w- c:\program files\QUICKENW\qagent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\ZakFromAnotherPlanet\\Yazak Chat\\iexplore.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\SYSTEM32\\rtcshare.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Ahead\\InCD\\InCDsrv.exe"=
"c:\\WINDOWS\\SYSTEM32\\spoolsv.exe"=
"c:\\WINDOWS\\SYSTEM32\\CTsvcCDA.EXE"=
"c:\\Program Files\\CyberLink DVD Solution\\PowerDVD\\PDVDServ.exe"=
"c:\\Program Files\\Common Files\\Logitech\\QCDriver\\LVComS.exe"=
"c:\\Program Files\\Ahead\\InCD\\InCD.exe"=
"c:\\Program Files\\MUSICMATCH\\MUSICMATCH Jukebox\\mimboot.exe"=
"c:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\reader_sl.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
"7271:TCP"= 7271:TCP:Services
"2479:TCP"= 2479:TCP:Services
"3389:TCP"= 3389:TCP:Remote Desktop
"3246:TCP"= 3246:TCP:Services

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [12/22/2008 11:06 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/22/2008 11:05 AM 74480]
R2 fssfltr;FssFltr;c:\windows\SYSTEM32\DRIVERS\fssfltr_tdi.sys [6/14/2009 7:46 PM 54752]
R2 mrtRate;mrtRate;c:\windows\SYSTEM32\DRIVERS\MrtRate.sys [7/22/2003 8:32 PM 34712]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/22/2008 11:06 AM 7408]
S2 LTANMWUI;LTANMWUI;\??\c:\windows\system32\ltanmwui.vdw –> c:\windows\system32\ltanmwui.vdw [?]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 10:48 PM 704864]
S3 lc3pkt_2.1;LC3 Packet Driver;\??\c:\program files\@stake\LC4\lc3pkt.sys –> c:\program files\@stake\LC4\lc3pkt.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2010-01-29 c:\windows\Tasks\User_Feed_Synchronization-{2251EC52-B660-4E59-B002-5A66781184C0}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 10:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\TEIGAN\Start Menu\Programs\IMVU\Run IMVU.lnk
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: Yahoo! Chat - hxxp://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
FF - ProfilePath - c:\documents and settings\tanja\Application Data\Mozilla\Firefox\Profiles\iz4ah2te.default\
FF - plugin: c:\program files\SceneCaster\Version 3.11.16\NPSceneCaster.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{DE102568-9CF5-B799-4941-FCD55C07F15F} - (no file)
MSConfigStartUp-AdaptecDirectCD - c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
MSConfigStartUp-Amenfind - c:\progra~1\THEWAY~1\DEAD PLUS.exe
MSConfigStartUp-AVG_CC - c:\program files\Grisoft\AVG6\avgcc32.exe
MSConfigStartUp-BullsEye Network - c:\program files\BullsEye Network\bin\bargains.exe
MSConfigStartUp-DeskAd Service - c:\program files\DeskAd Service\DeskAdServ.exe
MSConfigStartUp-Freedom - c:\program files\Zero Knowledge\Freedom\Freedom.exe
MSConfigStartUp-Internet Optimizer - c:\program files\Internet Optimizer\optimize.exe
MSConfigStartUp-Iotn - c:\documents and settings\phil\Application Data\urod.exe
MSConfigStartUp-mmtask - c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\qttask.exe
MSConfigStartUp-SAHBundle - c:\docume~1\tanja\LOCALS~1\Temp\bundle.exe
MSConfigStartUp-salm - c:\temp\salm.exe
MSConfigStartUp-SpyHunter - c:\progra~1\THEWAY~1\DEAD PLUS.exe
MSConfigStartUp-SpySweeper - c:\program files\Webroot\Spy Sweeper\SpySweeper.exe
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre1.5.0_03\bin\jusched.exe
MSConfigStartUp-THGuard - c:\program files\TrojanHunter 3.8\THGuard.exe
MSConfigStartUp-Windows AdStatus - c:\program files\Windows AdStatus\WinStat.exe
MSConfigStartUp-Yahoo! Pager - c:\program files\Yahoo!\Messenger\ypager.exe
AddRemove-LiveUpdate - c:\program files\Symantec\LiveUpdate\LSETUP.EXE
AddRemove-slowuploadfrag - c:\progra~1\THEWAY~1\DEAD PLUS.exe
AddRemove-Soulbringer - c:\program files\Infogrames\Soulbringer\Uninst.isu
AddRemove-System Guard 2009 - c:\program files\System Guard 2009\uninstall.exe
AddRemove-WinTools.net Professional - c:\program files\WinTools\WinTools.net Professional\uninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-29 13:46
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DwlClient = c:\program files\Common Files\Dell\EUSW\Support.exe?l?e?s?\?D?e?l?l?\?E?U?S?W?\?S?u?p?p?o?r?t?.?e?x?e???x???x???????????????????x???x???????x???x???????????x???????????x???x??????????? ??????????????????????????????w????????????j??w????x???x??????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LTANMWUI]
"ImagePath"="\??\c:\windows\system32\ltanmwui.vdw"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(648)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(2088)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Ahead\InCD\InCDsrv.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\windows\System32\CTsvcCDA.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\System32\nvsvc32.exe
c:\program files\IOGear\ION\IoctlSvc.exe
c:\program files\Dantz\Retrospect\retrorun.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\MUSICM~1\MUSICM~1\MMDiag.exe
c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
.
**************************************************************************
.
Completion time: 2010-01-29 13:58:26 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-29 20:58

Pre-Run: 716,812,288 bytes free
Post-Run: 686,743,552 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

- - End Of File - - 875262B12267ACAB2F475530F72EF431

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI