HI Oldman
ok here are the present scans for you.. also I sent you a messege but you can disregard it, other than the info I passed along, yes I did recently update the service pack from the windows update,this comp is behind a router,but all I run is superantispyware on this comp at the moment , until I can store the files that need to be removed on the external hd I have, and then I plan to reformat it as there are a lot of duplicate files on here taking up a lot of memory from a system save a long time ago, along with the 3 user profiles that I want to remove and just have one user on this comp, and I definatly didnt want to be saving anything infected on the ext-hd either. which I'm glad this was done,

in the past online scanners have been used on this comp, like kaspersky, panda, symantic, trend micro housecall, avg, spybot, bit defender among others. IE still wont open, it hourglasses a moment then nothing…but otherwise, everything seems to be acting alot better, the firefox still hung a moment when I opened it after the scans, but was way better than before we started the cleaning process. I do agree on the limewire but I will remove it once I have sorted out the mp3 files for my squid,otherwise I am forbidden from removing it at the moment
here are the current logs:
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
Hi Oldman960
yes I did just recently update from the windows auto update.
ok , it came up alright, so here is the OTL fix log file:
All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{49132671-36d0-4319-acbe-6fed9ae5715a}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{49132671-36d0-4319-acbe-6fed9ae5715a}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5cb492ae-bc91-4a4f-a7f0-30f6c55728cc}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5cb492ae-bc91-4a4f-a7f0-30f6c55728cc}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\24f0ca60 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\CPM27c3f9fc deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\jowuzamaku deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\WINDOWS\system32\wejiwulo.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\botapepe.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\gafilumu.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\WINDOWS\system32\lamisefi.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:ffzrka.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\putevama.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\wobupobu.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:cedyfe.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\jahanane.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\SSODL deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\ not found.
C:\WINDOWS\msdownld.tmp folder deleted successfully.
C:\WINDOWS\SYSTEM32\medilile.dll moved successfully.
C:\WINDOWS\SYSTEM32\fiyobubi.dll moved successfully.
C:\WINDOWS\SYSTEM32\vavefowi.dll moved successfully.
C:\WINDOWS\SYSTEM32\gedekuye.dll moved successfully.
File C:\WINDOWS\System32\medilile.dll not found.
C:\WINDOWS\SYSTEM32\bemevaja.dll moved successfully.
C:\WINDOWS\SYSTEM32\bipehozo.dll moved successfully.
C:\WINDOWS\SYSTEM32\rowijoko moved successfully.
C:\WINDOWS\SYSTEM32\ezamuyef.ini moved successfully.
C:\WINDOWS\SYSTEM32\ototuyay.ini moved successfully.
C:\WINDOWS\SYSTEM32\wggneh.dll moved successfully.
C:\WINDOWS\SYSTEM32\irugokow.ini moved successfully.
C:\WINDOWS\SYSTEM32\ifokogen.ini moved successfully.
C:\WINDOWS\SYSTEM32\asefowep.ini moved successfully.
C:\WINDOWS\SYSTEM32\uyokejeg.ini moved successfully.
C:\WINDOWS\SYSTEM32\adoredey.ini moved successfully.
C:\WINDOWS\SYSTEM32\owuyijem.ini moved successfully.
C:\WINDOWS\SYSTEM32\osimetoz.ini moved successfully.
C:\WINDOWS\SYSTEM32\alibojuf.ini moved successfully.
C:\WINDOWS\SYSTEM32\oworilum.ini moved successfully.
C:\WINDOWS\SYSTEM32\urihikat.ini moved successfully.
C:\WINDOWS\SYSTEM32\ubehojap.ini moved successfully.
C:\WINDOWS\SYSTEM32\upayusok.ini moved successfully.
C:\WINDOWS\SYSTEM32\evanagiz.ini moved successfully.
C:\WINDOWS\SYSTEM32\evipekuz.ini moved successfully.
C:\WINDOWS\SYSTEM32\imulowak.ini moved successfully.
C:\WINDOWS\SYSTEM32\odenehip.ini moved successfully.
C:\WINDOWS\SYSTEM32\ajavemeb.ini moved successfully.
C:\WINDOWS\SYSTEM32\ozohepib.ini moved successfully.
C:\WINDOWS\SYSTEM32\avunojuk.ini moved successfully.
C:\WINDOWS\SYSTEM32\uruholis.ini moved successfully.
C:\WINDOWS\SYSTEM32\avayafot.ini moved successfully.
C:\WINDOWS\SYSTEM32\aluginom.ini moved successfully.
C:\WINDOWS\SYSTEM32\ibewodaz.ini moved successfully.
C:\WINDOWS\SYSTEM32\atabofuy.ini moved successfully.
C:\WINDOWS\SYSTEM32\atoyetit.ini moved successfully.
C:\WINDOWS\SYSTEM32\oyemukul.ini moved successfully.
C:\WINDOWS\SYSTEM32\inazikun.ini moved successfully.
C:\WINDOWS\SYSTEM32\uzehiven.ini moved successfully.
C:\WINDOWS\SYSTEM32\ikefiluh.ini moved successfully.
C:\WINDOWS\SYSTEM32\elejobeg.ini moved successfully.
C:\WINDOWS\SYSTEM32\ayavijel.ini moved successfully.
C:\WINDOWS\SYSTEM32\uhafawep.ini moved successfully.
C:\WINDOWS\SYSTEM32\ejurimey.ini moved successfully.
C:\WINDOWS\SYSTEM32\muyipeve.dll moved successfully.
C:\WINDOWS\SYSTEM32\zadowebi.dll moved successfully.
C:\WINDOWS\SYSTEM32\kufubabe.dll moved successfully.
C:\WINDOWS\SYSTEM32\giletisa.dll moved successfully.
C:\WINDOWS\SYSTEM32\larihisu.dll moved successfully.
C:\WINDOWS\SYSTEM32\hosezora.dll moved successfully.
C:\WINDOWS\SYSTEM32\jeyiniyo.dll moved successfully.
C:\WINDOWS\SYSTEM32\pewafahu.dll moved successfully.
C:\WINDOWS\SYSTEM32\gikosiha.dll moved successfully.
C:\WINDOWS\SYSTEM32\romabotu.dll moved successfully.
C:\WINDOWS\SYSTEM32\kujonuva.dll moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\ not found.
========== FILES ==========
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes
User: HelpAssistant
->Temp folder emptied: 268 bytes
->Temporary Internet Files folder emptied: 603 bytes
->Java cache emptied: 100370587 bytes
->FireFox cache emptied: 50681756 bytes
->Google Chrome cache emptied: 916014 bytes
User: HelpAssistant.DHGGS431
User: HelpAssistant.DHGGS431.000
->Temp folder emptied: 7152161 bytes
->Temporary Internet Files folder emptied: 29675857 bytes
->Java cache emptied: 110890005 bytes
->FireFox cache emptied: 36603402 bytes
->Google Chrome cache emptied: 916014 bytes
User: LocalService
->Temp folder emptied: 480 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 66083 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: phil
User: tanja
->Temp folder emptied: 907910 bytes
->Temporary Internet Files folder emptied: 1618543 bytes
->Java cache emptied: 93374962 bytes
->FireFox cache emptied: 42786955 bytes
User: TEIGAN
->Temp folder emptied: 73302502 bytes
->Temporary Internet Files folder emptied: 47630940 bytes
->Java cache emptied: 179505491 bytes
->FireFox cache emptied: 51637581 bytes
->Google Chrome cache emptied: 6175278 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1139743 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 23949375 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 402 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 820.00 mb
OTL by OldTimer - Version 3.1.26.0 log created on 01282010_200021
Files\Folders moved on Reboot…
File move failed. C:\WINDOWS\temp\$$$dq3e scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\$67we.$ scheduled to be moved on reboot.
Registry entries deleted on Reboot…
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
this is the virustotal scan:
File has already been analysed:
MD5: 6eae8504114ec7e1137564a04bb384ba
First received: 2009.05.12 10:22:08 UTC
Date: 2009.05.12 10:22:08 UTC [>261D]
Results: 25/38
Permalink: analisis/d155ceaeeff61ebbf64f1e8dda25a7189db2cd41c87088414f7af9ce317f0168-1242123728
Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.01.29 Trojan.Win32.Vundo!IK
AhnLab-V3 5.0.0.2 2010.01.28 Win-Trojan/Monder.49152.BA
AntiVir 7.9.1.154 2010.01.28 TR/Crypt.XPACK.Gen
Antiy-AVL 2.0.3.7 2010.01.28 Trojan/Win32.Monder.gen
Authentium 5.2.0.5 2010.01.29 W32/Vundo.C!Generic
Avast 4.8.1351.0 2010.01.28 Win32:MoPack
AVG 9.0.0.730 2010.01.28 Vundo.FV
BitDefender 7.2 2010.01.29 Gen:Trojan.Heur.Vundo.dyW@dClAnjk
CAT-QuickHeal 10.00 2010.01.29 Trojan.Agent.IRC
ClamAV 0.94.1 2010.01.29 -
Comodo 3742 2010.01.28 TrojWare.Win32.MonderB.Gen
DrWeb 5.0.1.12222 2010.01.29 Trojan.Virtumod.based.26
eSafe 7.0.17.0 2010.01.28 Win32.TRCrypt.XPACK
eTrust-Vet 35.2.7269 2010.01.29 Win32/Vundo!generic
F-Prot 4.5.1.85 2010.01.28 W32/Vundo.C!Generic
F-Secure 9.0.15370.0 2010.01.29 Trojan:W32/Vundo.gen!D
Fortinet 4.0.14.0 2010.01.28 W32/Vundo.W!tr
GData 19 2010.01.28 Gen:Trojan.Heur.Vundo.dyW@dClAnjk
Ikarus T3.1.1.80.0 2010.01.29 Trojan.Win32.Vundo
K7AntiVirus 7.10.959 2010.01.28 Trojan.Win32.Monder.bzea
McAfee 5875 2010.01.28 Vundo.gen.w
McAfee+Artemis 5875 2010.01.28 Vundo.gen.w
McAfee-GW-Edition 6.8.5 2010.01.28 Trojan.Crypt.XPACK.Gen
Microsoft 1.5406 2010.01.28 Worm:Win32/Vundo.A
NOD32 4815 2010.01.28 a variant of Win32/Adware.Virtumonde.NFD
nProtect 2009.1.8.0 2010.01.28 Trojan/W32.Monder.49152.AX
Panda 10.0.2.2 2010.01.28 -
PCTools 7.0.3.5 2010.01.29 HeurEngine.MaliciousPacker
Prevx 3.0 2010.01.29 High Risk Fraudulent Security Program
Rising 22.32.04.01 2010.01.29 Packer.Win32.Agent.GEN
Sophos 4.50.0 2010.01.29 Mal/Vundo-C
Sunbelt 3.2.1858.2 2010.01.29 Trojan.Win32.Vundo.Gen (v)
Symantec 20091.2.0.41 2010.01.29 Packed.Generic.217
TheHacker 6.5.0.9.168 2010.01.28 Trojan/Monder.bzea
TrendMicro 9.120.0.1004 2010.01.29 TROJ_VUNDO.SMZ
VBA32 3.12.12.1 2010.01.28 Trojan-Downloader.Exficale
ViRobot 2010.1.29.2161 2010.01.29 -
VirusBuster 5.0.21.0 2010.01.28 -
Additional information
File size: 49152 bytes
MD5 : 6eae8504114ec7e1137564a04bb384ba
SHA1 : 08d4b081ebd88bf587bef5538814f670c9b71e01
SHA256: d155ceaeeff61ebbf64f1e8dda25a7189db2cd41c87088414f7af9ce317f0168
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x105C
timedatestamp…..: 0x40658307 (Sat Mar 27 14:35:03 2004)
machinetype…….: 0x14C (Intel I386)
( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x3000 0x2800 6.48 16fd9babf58d5db1a6fe7af275596d73
0x4000 0x1000 0x600 0.23 75cab2e9195d27d99708dc87eccdfeb8
0x5000 0x3000 0x2400 7.98 838c598d538d458e9874bb59194c4ccb
0x8000 0x3000 0x2200 7.98 391d7653e8d36cc64b94655374daef48
0xB000 0x3000 0x2200 7.98 72e3e55d740110e470fd7eb81edda3d5
0xE000 0xF000 0x2600 7.98 08c2403029cde660833532bee0bca706
( 6 imports )
> advapi32.dll: RegQueryValueExW
> comctl32.dll: InitCommonControlsEx
> comdlg32.dll: PrintDlgExA
> gdi32.dll: Arc, SelectClipPath
> kernel32.dll: ExitProcess, GetModuleHandleW, GetSystemInfo
> user32.dll: DispatchMessageW, TranslateMessage, LoadIconA, GetSystemMetrics
( 0 exports )
TrID : File type identification
Win32 Executable Generic (38.5%)
Win32 Dynamic Link Library (generic) (34.2%)
Clipper DOS Executable (9.1%)
Generic Win/DOS Executable (9.0%)
DOS Executable Generic (9.0%)
ssdeep: 768:bBK9UYWng9/P7ioZC+chMJEIh1wklTEt7rjHe4hjt9kdldWnDxtwyh9uvUZ:bM9UJyP5ehMJ/EZjHnhjkdlJyh9uvUZ
Prevx Info:
http://info.prevx.com/aboutprogramtext.asp…2022A00BEB193EF
PEiD : -
RDS : NSRL Reference Data Set
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
malewarebytes scan:
Malwarebytes' Anti-Malware 1.44
Database version: 3655
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
1/28/2010 11:33:52 PM
mbam-log-2010-01-28 (23-33-52).txt
Scan type: Quick Scan
Objects scanned: 155048
Time elapsed: 16 minute(s), 15 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 26
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 10
Files Infected: 21
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{18cacf0e-72a4-4be1-aa42-dc2ecdb197f1} (Trojan.Banker) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{2850bdc7-2330-4e31-9fa0-88268846539a} (Adware.WhenU) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{18cacf0e-72a4-4be1-aa42-dc2ecdb197f1} (Trojan.Banker) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6825fac3-d7d2-4045-97a2-87df42cb6728} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{6825fac3-d7d2-4045-97a2-87df42cb6728} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8617ef97-58d3-49ca-9fd3-52ab6525c86b} (Rogue.SystemGuard) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\System Guard 2009 (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
C:\Documents and Settings\HelpAssistant\Application Data\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant\Application Data\FunWebProducts\Data (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant\Application Data\FunWebProducts\Data\TEIGAN (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant.DHGGS431.000\Application Data\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant.DHGGS431.000\Application Data\FunWebProducts\Data (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant.DHGGS431.000\Application Data\FunWebProducts\Data\TEIGAN (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\TEIGAN\Application Data\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\TEIGAN\Application Data\FunWebProducts\Data (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\TEIGAN\Application Data\FunWebProducts\Data\TEIGAN (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs (Rogue.SystemGuard) -> Quarantined and deleted successfully.
Files Infected:
C:\3.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant\Application Data\FunWebProducts\Data\TEIGAN\avatar.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant\Application Data\FunWebProducts\Data\TEIGAN\outfit.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant\Application Data\FunWebProducts\Data\TEIGAN\register.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant\Application Data\FunWebProducts\Data\TEIGAN\zbucks.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant.DHGGS431.000\Application Data\FunWebProducts\Data\TEIGAN\avatar.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant.DHGGS431.000\Application Data\FunWebProducts\Data\TEIGAN\outfit.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant.DHGGS431.000\Application Data\FunWebProducts\Data\TEIGAN\register.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant.DHGGS431.000\Application Data\FunWebProducts\Data\TEIGAN\zbucks.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\TEIGAN\Application Data\FunWebProducts\Data\TEIGAN\avatar.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\TEIGAN\Application Data\FunWebProducts\Data\TEIGAN\outfit.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\TEIGAN\Application Data\FunWebProducts\Data\TEIGAN\register.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\TEIGAN\Application Data\FunWebProducts\Data\TEIGAN\zbucks.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\c.cgm (Rogue.SystemGuard) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\wdoijfazvr.dll (Rogue.SystemGuard) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\track.sys (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\bb1.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\kcms.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\mseggrpid.dll (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\WINDOWS\hosts (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\IE.ico (Malware.Trace) -> Quarantined and deleted successfully.
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
new OTL scan:
OTL logfile created on: 1/28/2010 11:47:05 PM - Run 2
OTL by OldTimer - Version 3.1.26.0 Folder = C:\Documents and Settings\tanja\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
511.00 Mb Total Physical Memory | 217.00 Mb Available Physical Memory | 43.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): c:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 0.91 Gb Free Space | 1.22% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DHGGS431
Current User Name: tanja
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\tanja\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe (Musicmatch, Inc.)
PRC - C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe (Musicmatch, Inc.)
PRC - C:\Program Files\Ahead\InCD\InCDsrv.exe (Nero AG)
PRC - C:\Program Files\Ahead\InCD\InCD.exe (Nero AG)
PRC - C:\Program Files\IOGear\ION\IoctlSvc.exe (Prolific Technology Inc.)
PRC - C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
PRC - C:\Program Files\Dantz\Retrospect\retrorun.exe (Dantz Development Corporation)
PRC - C:\WINDOWS\SYSTEM32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\SYSTEM32\LEXBCES.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\SYSTEM32\LEXPPS.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\SYSTEM32\cidaemon.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Logitech\QCDriver\LVComS.exe (Logitech Inc.)
PRC - C:\WINDOWS\SYSTEM32\CTsvcCDA.EXE (Creative Technology Ltd)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\tanja\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (Imapi Helper) – C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe (Alex Feinman)
SRV - (InCDsrv) – C:\Program Files\Ahead\InCD\InCDsrv.exe (Nero AG)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (PLFlash DeviceIoControl Service) – C:\Program Files\IOGear\ION\IoctlSvc.exe (Prolific Technology Inc.)
SRV - (Retrospect Helper) – C:\Program Files\Dantz\Retrospect\rthlpsvc.exe (Dantz Development Corporation)
SRV - (RetroLauncher) – C:\Program Files\Dantz\Retrospect\retrorun.exe (Dantz Development Corporation)
SRV - (NVSvc) – C:\WINDOWS\SYSTEM32\nvsvc32.exe (NVIDIA Corporation)
SRV - (NetSvc) – C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation)
SRV - (LexBceS) – C:\WINDOWS\SYSTEM32\LEXBCES.EXE (Lexmark International, Inc.)
SRV - (TermService) – C:\WINDOWS\SYSTEM32\termsrv32.dll (Microsoft Corporation)
SRV - (Creative Service for CDROM Access) – C:\WINDOWS\SYSTEM32\CTsvcCDA.EXE (Creative Technology Ltd)
========== Driver Services (SafeList) ==========
DRV - (PxHelp20) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (fssfltr) – C:\WINDOWS\SYSTEM32\DRIVERS\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (amdagp) – C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (tmcomm) – C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys (Trend Micro Inc.)
DRV - (Secdrv) – C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (InCDfs) – C:\WINDOWS\SYSTEM32\DRIVERS\InCDfs.sys (Nero AG)
DRV - (InCDPass) – C:\WINDOWS\SYSTEM32\DRIVERS\InCDpass.sys (Nero AG)
DRV - (incdrm) – C:\WINDOWS\SYSTEM32\DRIVERS\InCDrm.sys (Nero AG)
DRV - (gameenum) – C:\WINDOWS\SYSTEM32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (iAimFP4) – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)
DRV - (iAimFP3) – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)
DRV - (iAimTV4) – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)
DRV - (iAimTV3) – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)
DRV - (iAimTV1) – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)
DRV - (iAimTV0) – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)
DRV - (iAimFP0) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)
DRV - (iAimFP1) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)
DRV - (iAimFP2) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)
DRV - (i81x) – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (Freedom) – C:\WINDOWS\freedom.backup.dat ()
DRV - (pfc) – C:\WINDOWS\SYSTEM32\DRIVERS\pfc.sys (Padus, Inc.)
DRV - (HSFHWBS2) – C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (nv) – C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (P16X) Creative SB Live! Series (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\P16X.sys (Creative Technology Ltd.)
DRV - (ctsfm2k) – C:\WINDOWS\SYSTEM32\DRIVERS\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\SYSTEM32\DRIVERS\ctoss2k.sys (Creative Technology Ltd.)
DRV - (mdmxsdk) – C:\WINDOWS\SYSTEM32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (E100B) Intel® – C:\WINDOWS\SYSTEM32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (ultra) – C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (sym_u3) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (Sparrow) – C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (ql1280) – C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (ql12160) – C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (Ptilink) – C:\WINDOWS\SYSTEM32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (mraid35x) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (dac2w2k) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (CmdIde) – C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (asc) – C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (LVBulk) – C:\WINDOWS\SYSTEM32\DRIVERS\LVBulk.sys (Logitech Inc.)
DRV - (QCDonner) Logitech QuickCam Express(PID_0840) – C:\WINDOWS\SYSTEM32\DRIVERS\lvcd.sys (Logitech Inc.)
DRV - (lusbaudio) – C:\WINDOWS\SYSTEM32\DRIVERS\LVSound2.sys (Logitech Inc.)
DRV - (LVVI500A) – C:\WINDOWS\SYSTEM32\DRIVERS\lvvi500a.sys (Tekom Technologies, Inc.)
DRV - (MODEMCSA) – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)
DRV - (ICAM5USB) Intel® – C:\WINDOWS\SYSTEM32\DRIVERS\Icam5USB.sys (Microsoft Corporation)
DRV - (mrtRate) – C:\WINDOWS\SYSTEM32\DRIVERS\MrtRate.sys (Marimba, Inc.)
DRV - (ScFBPNT3) – C:\WINDOWS\SYSTEM32\DRIVERS\ScFBPNT3.sys ()
DRV - (PfModNT) – C:\WINDOWS\SYSTEM32\PFMODNT.SYS (Creative Technology Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://search.live.com/sphome.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://ca.rd.yahoo.com/customize/ycomp/def…://ca.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:3.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/23 16:05:18 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/23 16:05:10 | 00,000,000 | —D | M]
[2008/11/01 10:49:18 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\Mozilla\Extensions
[2010/01/28 19:58:02 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\Mozilla\Firefox\Profiles\iz4ah2te.default\extensions
[2009/10/23 19:23:02 | 00,000,000 | —D | M] – C:\Documents and Settings\tanja\Application Data\Mozilla\Firefox\Profiles\iz4ah2te.default\extensions\[removed]
[2010/01/28 19:58:04 | 00,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2009/03/03 21:06:21 | 00,000,423 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.igetnet.com
O1 - Hosts: 127.0.0.1 code.ignphrases.com
O1 - Hosts: 127.0.0.1 clear-search.com
O1 - Hosts: 127.0.0.1 r1.clrsch.com
O1 - Hosts: 127.0.0.1 sds.clrsch.com
O1 - Hosts: 127.0.0.1 status.clrsch.com
O1 - Hosts: 127.0.0.1 www.clrsch.com
O1 - Hosts: 127.0.0.1 clr-sch.com
O1 - Hosts: 127.0.0.1 sds-qckads.com
O1 - Hosts: 127.0.0.1 status.qckads.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe (Dell)
O4 - HKLM..\Run: [fssui] C:\Program Files\Windows Live\Family Safety\fsui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVComS.exe (Logitech Inc.)
O4 - HKLM..\Run: [MimBoot] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mimboot.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\SYSTEM32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (Yahoo! Inc)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [NBJ] C:\Program Files\Ahead\Nero BackItUp\NBJ.exe (Ahead Software AG)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\tanja\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = _ [binary data]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideClock = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoManageMyComputerVerb = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuPinnedList = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoUserNameInStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartmenuLogoff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuSubFolders = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCommonGroups = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPrinterTabs = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAddPrinter = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPrinters = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetworkConnections = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetFolders = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewContextMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFileMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoShellSearchButton = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoToolbarCustomize = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeAnimation = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeKeyboardNavigationIndicators = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThemesTab = 0
O8 - Extra context menu item: &Yahoo;! Search - C:\Program Files\Yahoo!\Common [2010/01/23 17:07:06 | 00,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &Dictionary; - C:\Program Files\Yahoo!\Common [2010/01/23 17:07:06 | 00,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &Maps; - C:\Program Files\Yahoo!\Common [2010/01/23 17:07:06 | 00,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &SMS; - C:\Program Files\Yahoo!\Common [2010/01/23 17:07:06 | 00,000,000 | —D | M]
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\TEIGAN\Start Menu\Programs\IMVU\Run IMVU.lnk ()
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: 21 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00000075-0000-0010-8000-00AA00389B71}
http://codecs.microsoft.com/codecs/i386/voxmsdec.CAB (Reg Error: Key error.)
O16 - DPF: {00000075-9980-0010-8000-00AA00389B71}
http://codecs.microsoft.com/codecs/i386/voxacm.CAB (Reg Error: Key error.)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (Reg Error: Key error.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {33363249-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/i263_32.cab (Reg Error: Key error.)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://bin.mcafee.com/molbin/shared/mcinsc…76/mcinsctl.cab (Reg Error: Key error.)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo…otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F}
http://v4.windowsupdate.microsoft.com/CAB/…8175.5361689815 (Reg Error: Key error.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab (Reg Error: Key error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.4.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147}
http://gfx1.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6}
http://download.mcafee.com/molbin/iss-loc/…360/mcfscan.cab (McFreeScan Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Backgammon
http://download.games.yahoo.com/games/clients/y/at0_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Chat http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Cribbage http://download.games.yahoo.com/games/clients/y/it1_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Literati
http://download.games.yahoo.com/games/clients/y/tt1_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Pool 2
http://download.games.yahoo.com/games/clients/y/potc_x.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop Components:0 () - file:///C:/Documents%20and%20Settings/tanja/My%20Documents/My%20Pictures/whatnots/my%20very%20own%20sigs/snags%20for%20tags/1more%20fantasy%20art/more/dragon.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\tanja\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\tanja\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/01/28 21:26:31 | 00,000,000 | —D | C] – C:\Documents and Settings\tanja\Application Data\Malwarebytes
[2010/01/28 21:26:24 | 00,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/28 21:26:22 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/01/28 21:26:21 | 00,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/01/28 21:26:21 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/01/28 21:24:40 | 05,115,824 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\tanja\Desktop\mbam-setup.exe
[2010/01/28 20:00:21 | 00,000,000 | —D | C] – C:\_OTL
[2010/01/25 19:34:12 | 00,547,328 | —- | C] (OldTimer Tools) – C:\Documents and Settings\tanja\Desktop\OTL.exe
[2010/01/23 14:08:41 | 00,000,000 | —D | C] – C:\Documents and Settings\tanja\Application Data\vlc
[2010/01/23 14:02:58 | 00,000,000 | —D | C] – C:\Documents and Settings\tanja\My Documents\Graboid
[2010/01/23 13:19:52 | 00,000,000 | —D | C] – C:\Documents and Settings\tanja\Application Data\MozillaControl
[2010/01/23 13:19:48 | 00,000,000 | —D | C] – C:\Documents and Settings\tanja\Local Settings\Application Data\Graboid
[2010/01/23 13:18:56 | 00,000,000 | —D | C] – C:\Program Files\Mozilla ActiveX Control v1.7.12
[2010/01/23 13:17:26 | 00,000,000 | —D | C] – C:\Program Files\VideoLAN
[2010/01/23 13:16:52 | 00,000,000 | —D | C] – C:\Program Files\Graboid
[2010/01/12 13:15:34 | 00,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/01/12 13:15:34 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/01/12 13:15:34 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/01/12 13:10:22 | 00,471,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aclayers.dll
[2010/01/12 13:05:10 | 00,000,000 | —D | C] – C:\Program Files\Buddy Spy
[2009/11/06 19:37:01 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/11/06 19:32:08 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2008/11/21 13:52:02 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2008/11/01 11:19:15 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2007/08/06 12:15:57 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/05/08 16:30:14 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2007/05/08 16:08:07 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2006/12/16 19:38:32 | 00,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\tanja\Application Data\pcouffin.sys
[2006/07/01 14:46:19 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Help
[2006/07/01 14:46:19 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Help
[2006/07/01 09:48:47 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\ApplicationHistory
[2003/07/22 20:01:30 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2002/04/11 00:41:00 | 00,065,536 | —- | C] ( ) – C:\WINDOWS\System32\A3d.dll
========== Files - Modified Within 30 Days ==========
[2010/01/29 00:02:00 | 00,000,412 | —- | M] () – C:\WINDOWS\tasks\Symantec NetDetect.job
[2010/01/29 00:00:00 | 00,000,424 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{2251EC52-B660-4E59-B002-5A66781184C0}.job
[2010/01/28 23:38:11 | 00,012,598 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/01/28 23:37:36 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/01/28 23:37:34 | 00,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/01/28 23:37:33 | 53,587,5584 | -HS- | M] () – C:\hiberfil.sys
[2010/01/28 23:36:42 | 14,942,208 | —- | M] () – C:\Documents and Settings\tanja\ntuser.dat
[2010/01/28 23:36:19 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\tanja\NTUSER.INI
[2010/01/28 21:26:27 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/28 21:24:46 | 05,115,824 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\tanja\Desktop\mbam-setup.exe
[2010/01/25 22:43:55 | 02,096,656 | -H– | M] () – C:\Documents and Settings\tanja\Local Settings\Application Data\IconCache.db
[2010/01/25 21:21:25 | 00,169,467 | —- | M] () – C:\Documents and Settings\tanja\My Documents\error.JPG
[2010/01/25 20:44:15 | 53,590,4256 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2010/01/25 19:34:13 | 00,547,328 | —- | M] (OldTimer Tools) – C:\Documents and Settings\tanja\Desktop\OTL.exe
[2010/01/25 19:33:30 | 00,195,724 | —- | M] () – C:\Documents and Settings\tanja\My Documents\scrnsht maintenence instructions3.JPG
[2010/01/25 19:31:12 | 00,157,623 | —- | M] () – C:\Documents and Settings\tanja\My Documents\scrnsht maintenence instructions2.JPG
[2010/01/25 19:30:12 | 00,200,357 | —- | M] () – C:\Documents and Settings\tanja\My Documents\scrnsht maintenence instructions1.JPG
[2010/01/25 03:15:49 | 00,000,718 | —- | M] () – C:\WINDOWS\lexstat.ini
[2010/01/23 17:00:43 | 00,001,917 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/01/12 12:24:54 | 00,000,552 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/01/12 11:52:13 | 00,000,036 | —- | M] () – C:\Documents and Settings\tanja\Local Settings\Application Data\housecall.guid.cache
[2010/01/12 08:52:05 | 00,074,176 | —- | M] () – C:\Documents and Settings\tanja\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/01/07 16:07:14 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/07 16:07:04 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
========== Files Created - No Company Name ==========
[2010/01/28 21:26:27 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/26 22:46:01 | 53,587,5584 | -HS- | C] () – C:\hiberfil.sys
[2010/01/25 21:21:24 | 00,169,467 | —- | C] () – C:\Documents and Settings\tanja\My Documents\error.JPG
[2010/01/25 19:33:30 | 00,195,724 | —- | C] () – C:\Documents and Settings\tanja\My Documents\scrnsht maintenence instructions3.JPG
[2010/01/25 19:31:12 | 00,157,623 | —- | C] () – C:\Documents and Settings\tanja\My Documents\scrnsht maintenence instructions2.JPG
[2010/01/25 19:30:12 | 00,200,357 | —- | C] () – C:\Documents and Settings\tanja\My Documents\scrnsht maintenence instructions1.JPG
[2010/01/24 13:42:27 | 00,001,599 | —- | C] () – C:\Remote Assistance.lnk
[2010/01/24 13:42:27 | 00,000,792 | —- | C] () – C:\Windows Media Player.lnk
[2010/01/12 12:24:54 | 00,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/01/12 11:52:13 | 00,000,036 | —- | C] () – C:\Documents and Settings\tanja\Local Settings\Application Data\housecall.guid.cache
[2010/01/04 16:24:39 | 14,942,208 | —- | C] () – C:\Documents and Settings\tanja\ntuser.dat
[2007/05/08 15:09:57 | 00,000,006 | —- | C] () – C:\Documents and Settings\tanja\Application Data\dm.ini
[2007/05/08 15:09:56 | 00,000,901 | —- | C] () – C:\Documents and Settings\tanja\Application Data\AdobeDLM.log
[2006/12/16 19:38:32 | 00,081,920 | —- | C] () – C:\Documents and Settings\tanja\Application Data\ezpinst.exe
[2006/12/16 19:38:32 | 00,007,176 | —- | C] () – C:\Documents and Settings\tanja\Application Data\pcouffin.cat
[2006/12/16 19:38:32 | 00,001,144 | —- | C] () – C:\Documents and Settings\tanja\Application Data\pcouffin.inf
[2006/12/16 19:38:32 | 00,000,055 | —- | C] () – C:\Documents and Settings\tanja\Application Data\pcouffin.log
[2006/07/16 16:10:18 | 00,000,260 | —- | C] () – C:\WINDOWS\_delis32.ini
[2006/07/01 09:48:47 | 00,000,137 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\fusioncache.dat
[2006/06/25 16:43:35 | 00,000,125 | -HS- | C] () – C:\Documents and Settings\tanja\Application Data\.zreglib
[2006/05/25 13:33:23 | 00,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/02/01 15:20:19 | 00,000,000 | —- | C] () – C:\WINDOWS\lgfwup.ini
[2006/02/01 15:00:25 | 00,040,960 | —- | C] () – C:\Program Files\Uninstall_CDS.exe
[2006/01/11 10:05:01 | 00,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/09/02 20:44:52 | 00,000,000 | —- | C] () – C:\WINDOWS\pcfriend.INI
[2005/08/26 19:25:53 | 00,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2005/06/17 14:48:02 | 00,032,397 | —- | C] () – C:\WINDOWS\SGTBox.INI
[2005/05/09 08:39:34 | 00,000,032 | —- | C] () – C:\WINDOWS\basefx.INI
[2005/01/31 13:07:13 | 00,000,000 | —- | C] () – C:\WINDOWS\QFN.ini
[2005/01/31 13:07:13 | 00,000,000 | —- | C] () – C:\WINDOWS\QDQICK.ini
[2005/01/26 13:04:37 | 00,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2004/11/24 01:53:06 | 00,155,648 | —- | C] () – C:\WINDOWS\System32\winupdak.dll
[2004/11/24 01:41:01 | 00,155,648 | —- | C] () – C:\WINDOWS\System32\akupd.dll
[2004/11/23 07:48:06 | 00,000,262 | —- | C] () – C:\WINDOWS\usta32.ini
[2004/11/07 17:33:10 | 00,000,005 | —- | C] () – C:\Documents and Settings\All Users\Application Data\DirectCDUserNameE.txt
[2004/10/02 17:47:43 | 00,000,035 | —- | C] () – C:\WINDOWS\A4W.INI
[2004/10/02 17:46:55 | 00,000,572 | —- | C] () – C:\WINDOWS\maxlink.ini
[2004/10/02 17:44:57 | 00,000,000 | —- | C] () – C:\WINDOWS\OP70.INI
[2004/10/02 17:43:46 | 00,001,472 | —- | C] () – C:\WINDOWS\pstudio.ini
[2004/10/02 17:43:46 | 00,000,028 | —- | C] () – C:\WINDOWS\album.ini
[2004/10/02 17:43:46 | 00,000,021 | —- | C] () – C:\WINDOWS\Ps_setup.ini
[2004/10/02 17:42:09 | 00,016,032 | —- | C] () – C:\WINDOWS\System32\drivers\ScFBPNT3.sys
[2004/10/02 17:05:50 | 00,000,718 | —- | C] () – C:\WINDOWS\lexstat.ini
[2004/10/02 17:05:49 | 00,163,840 | —- | C] () – C:\WINDOWS\System32\ldepcl32.dll
[2004/10/02 17:05:48 | 00,328,704 | —- | C] () – C:\WINDOWS\System32\dosfnt32.dll
[2004/09/18 18:42:25 | 00,000,129 | —- | C] () – C:\WINDOWS\CTWave32.ini
[2004/07/19 02:57:09 | 00,011,776 | —- | C] () – C:\WINDOWS\System32\ZPORT4AS.dll
[2004/07/05 13:54:08 | 00,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2004/07/04 17:25:26 | 00,364,544 | —- | C] () – C:\WINDOWS\System32\psCamDat.dll
[2004/06/20 12:37:34 | 00,000,028 | —- | C] () – C:\WINDOWS\System32\autoscan3.dll
[2004/05/24 00:25:24 | 00,000,035 | —- | C] () – C:\Program Files\Default.PLS
[2004/05/13 10:55:56 | 00,000,032 | —- | C] () – C:\WINDOWS\thxcfg.ini
[2004/04/29 12:49:49 | 00,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll
[2004/04/29 12:48:31 | 00,000,034 | —- | C] () – C:\WINDOWS\h263test.ini
[2004/04/29 11:54:16 | 00,524,288 | —- | C] () – C:\WINDOWS\System32\InetIPLA6.dll
[2004/04/29 11:54:16 | 00,516,096 | —- | C] () – C:\WINDOWS\System32\InetIPLM6.dll
[2004/04/29 11:54:16 | 00,512,000 | —- | C] () – C:\WINDOWS\System32\InetIPLP6.dll
[2004/04/29 11:54:16 | 00,503,808 | —- | C] () – C:\WINDOWS\System32\InetIPLPX.dll
[2004/04/29 11:54:16 | 00,495,616 | —- | C] () – C:\WINDOWS\System32\InetIPLM5.dll
[2004/04/29 11:54:16 | 00,491,520 | —- | C] () – C:\WINDOWS\System32\InetIPLP5.dll
[2004/04/29 11:54:16 | 00,020,480 | —- | C] () – C:\WINDOWS\System32\InetIPL.dll
[2004/04/29 11:54:16 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\Cpuinf32.dll
[2004/02/20 22:50:14 | 00,000,032 | —- | C] () – C:\Program Files\Draw Joy Bib.dat
[2004/01/24 17:10:30 | 00,000,103 | —- | C] () – C:\WINDOWS\CTRec.INI
[2003/12/11 17:51:07 | 00,004,294 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2003/12/03 16:07:00 | 00,000,128 | —- | C] () – C:\Documents and Settings\tanja\Local Settings\Application Data\fusioncache.dat
[2003/11/17 23:37:20 | 00,072,192 | —- | C] () – C:\WINDOWS\System32\zlib.dll
[2003/10/08 13:34:26 | 00,121,440 | —- | C] () – C:\WINDOWS\System32\MSDRMCtrl.dll
[2003/10/06 14:16:00 | 00,027,136 | —- | C] () – C:\WINDOWS\System32\nvcod.dll
[2003/09/15 09:10:43 | 00,061,678 | —- | C] () – C:\Documents and Settings\tanja\Application Data\PFP110JPR.{PB
[2003/09/15 09:10:43 | 00,012,358 | —- | C] () – C:\Documents and Settings\tanja\Application Data\PFP110JCM.{PB
[2003/09/03 08:44:52 | 00,000,070 | —- | C] () – C:\WINDOWS\400A3C1E.ini
[2003/09/03 07:28:42 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/09/02 07:06:42 | 00,000,170 | —- | C] () – C:\WINDOWS\GetServer.ini
[2003/08/14 22:09:09 | 00,114,176 | —- | C] () – C:\Documents and Settings\tanja\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2003/08/11 11:30:38 | 00,000,823 | —- | C] () – C:\WINDOWS\TSC.ini
[2003/08/11 11:30:37 | 00,071,749 | —- | C] () – C:\WINDOWS\HCExtOutput.dll
[2003/08/10 13:28:31 | 00,000,030 | —- | C] () – C:\WINDOWS\Morpheus.INI
[2003/08/10 12:23:06 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2003/08/10 12:22:26 | 00,000,021 | —- | C] () – C:\WINDOWS\CS_setup.ini
[2003/08/10 11:24:45 | 00,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2003/07/22 20:37:17 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/07/22 20:32:24 | 00,000,185 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/07/22 20:32:22 | 00,000,846 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/07/22 20:30:53 | 00,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2003/07/22 20:30:41 | 00,002,092 | —- | C] () – C:\WINDOWS\System32\P16X.ini
[2003/07/22 20:30:41 | 00,000,026 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2003/07/22 20:30:40 | 00,006,175 | —- | C] () – C:\WINDOWS\MIXDEF.INI
[2003/07/22 20:30:40 | 00,005,917 | —- | C] () – C:\WINDOWS\SBMIXDEF.INI
[2003/07/22 20:30:40 | 00,000,064 | —- | C] () – C:\WINDOWS\P16x.ini
[2003/07/22 20:30:14 | 00,000,245 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2003/07/22 20:26:34 | 00,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/07/22 20:14:40 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/07/22 20:02:48 | 00,000,480 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2003/07/08 13:41:48 | 00,047,616 | —- | C] () – C:\WINDOWS\System32\P16X.dll
[2002/12/19 21:12:54 | 00,015,360 | —- | C] () – C:\WINDOWS\System32\selm_isx.dll
[2002/12/05 16:51:00 | 00,059,392 | R— | C] () – C:\WINDOWS\streamhlp.dll
[2002/06/10 13:16:22 | 00,005,187 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[1999/08/11 23:00:00 | 01,708,032 | —- | C] () – C:\WINDOWS\System32\MSO97V.DLL
[1999/08/11 23:00:00 | 00,036,864 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1999/08/11 23:00:00 | 00,032,768 | —- | C] () – C:\WINDOWS\System32\MSORFS.DLL
[1999/08/10 16:02:20 | 00,116,736 | —- | C] () – C:\WINDOWS\System32\LFKODAK.DLL
[1999/08/10 16:02:16 | 00,343,040 | —- | C] () – C:\WINDOWS\System32\lffpx7.dll
[1999/07/23 13:46:48 | 00,000,116 | —- | C] () – C:\WINDOWS\AuHCcup1.ini
[1999/07/23 10:53:20 | 00,129,536 | —- | C] () – C:\WINDOWS\AuHCcup1.dll
[1979/12/31 22:00:00 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:9AB338B9
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D37AE80B
< End of report >
Thanks again ")