This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] "Your system is infected" background, and a brows

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So I'd like to start off and save someone time, I used the otl fix in the other thread and it seems to have by and large fixed everything, though time will tell. As someone who is not at ALL computer savvy, this has been insanely frustrating for me. One thing that is not fixed is that malwarebytes and norton were deleted from my computer at some point and now when I try and download and reinstall it, the exe file continues to magically no longer be there once it gets to the "launch" portion of the instalation. I have no idea if this is all part of the same virus or if I just managed to royally screw myself in three different ways. I've also tried running trendmicro housecall, but when I click on the download I get a message about it not being a valid win32 application or something. Now that I've run that otl fix I can access system restore…should I just try this?
Hi,

Locate the two giles on your desktop

one is called otl.txt, the other is called extras.txt
open them (double click on them)

Navigate to this page in your browser and hit "add reply" - now go back to each open document one at a time. Highlight all the text by going to edit > select all > right click on the highlighted text and select "copy" now come back to the open window here > right click in the open window and select "paste" - do the same for the extras. text > press "add reply"


If you cannot see the documents on your desktop > search for OTL.txt with your windows search feature.
lol I'm not THAT lost….I can copy and paste! :P I guess my confusion lies in the fact that neither file exists on my computer (after running a search). I still have the OTL program on my computer, but that's it.
OK….took initiative and ran a scan (something I did not do earlier…I just ran the posted fix for the background issue).

otl.txt:

OTL logfile created on: 1/27/2010 9:55:11 AM - Run 1
OTL by OldTimer - Version 3.1.27.0 Folder = C:\Documents and Settings\HP_Administrator\My Documents
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.00 Mb Total Physical Memory | 481.00 Mb Available Physical Memory | 50.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 177.46 Gb Total Space | 141.75 Gb Free Space | 79.88% Space Free | Partition Type: NTFS
Drive D: | 8.83 Gb Total Space | 0.86 Gb Free Space | 9.76% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-4DACD0EA75
Current User Name: HP_Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/01/26 22:37:01 | 00,548,352 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\My Documents\OTL.exe
PRC - [2009/10/11 04:17:35 | 00,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009/09/29 14:44:22 | 00,068,384 | —- | M] () – C:\Program Files\Uniblue\RegistryBooster 2010\registrybooster.exe
PRC - [2009/04/08 16:22:58 | 00,345,480 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office14\OfficeSAS\OfficeSAS.exe
PRC - [2009/04/08 16:22:58 | 00,122,264 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office14\OfficeSAS\OfficeSASScheduler.exe
PRC - [2009/04/08 15:37:12 | 04,319,136 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\OSPPSVC.EXE
PRC - [2009/03/05 16:07:20 | 02,260,480 | RHS- | M] (Safer-Networking Ltd.) – C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2007/06/13 05:23:07 | 01,033,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/01/19 10:49:26 | 00,049,152 | —- | M] (Wireless Service) – C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
PRC - [2006/08/18 02:06:12 | 00,061,440 | —- | M] (Hewlett-Packard Company) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2006/05/09 17:50:00 | 00,131,139 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\nvsvc32.exe
PRC - [2006/04/07 03:51:18 | 01,073,152 | —- | M] (Digital Interactive Systems Corporation) – C:\Program Files\DISC\DISCover.exe
PRC - [2006/04/07 03:50:22 | 00,065,536 | —- | M] (Digital Interactive Systems Corporation, Inc.) – C:\Program Files\DISC\DISCUpdMgr.exe
PRC - [2006/04/07 03:50:22 | 00,057,344 | —- | M] (Digital Interactive Systems Corporation, Inc.) – C:\Program Files\DISC\DiscStreamHub.exe
PRC - [2006/03/10 17:22:57 | 00,048,280 | —- | M] (America Online, Inc.) – C:\Program Files\Common Files\AOL\1255985372\EE\aolsoftware.exe
PRC - [2005/11/10 23:03:52 | 00,036,975 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
PRC - [2005/08/03 02:19:16 | 00,058,880 | —- | M] (Microsoft) – C:\WINDOWS\arservice.exe
PRC - [2005/07/28 16:28:58 | 00,037,464 | —- | M] (America Online, Inc.) – C:\Program Files\America Online 9.0\waol.exe
PRC - [2005/07/28 16:28:53 | 00,054,872 | —- | M] (America Online, Inc.) – C:\Program Files\America Online 9.0\shellmon.exe
PRC - [2005/02/02 18:44:24 | 00,061,440 | —- | M] (Hewlett-Packard Company) – C:\hp\KBD\kbd.exe
PRC - [2004/10/20 08:40:04 | 00,010,328 | R— | M] (America Online) – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
PRC - [2004/10/15 15:54:14 | 00,100,016 | —- | M] (America Online, Inc) – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
PRC - [2004/10/15 15:54:12 | 00,046,768 | —- | M] (America Online Inc) – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
PRC - [1998/05/07 11:04:38 | 00,052,736 | —- | M] (Hewlett-Packard Company) – c:\WINDOWS\system\hpsysdrv.exe


========== Modules (SafeList) ==========

MOD - [2099/01/01 12:00:00 | 00,091,136 | -HS- | M] () – C:\WINDOWS\system32\nadusajo.dll
MOD - [2099/01/01 12:00:00 | 00,052,224 | -HS- | M] () – C:\WINDOWS\system32\moyebari.dll
MOD - [2010/01/26 22:37:01 | 00,548,352 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\My Documents\OTL.exe
MOD - [2006/08/25 10:45:55 | 01,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
MOD - [2005/07/28 16:28:39 | 00,006,144 | —- | M] (America Online, Inc.) – C:\Program Files\America Online 9.0\idleproc.dll
MOD - [2004/08/09 23:00:00 | 00,713,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\opengl32.dll
MOD - [2004/08/09 23:00:00 | 00,266,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\ddraw.dll
MOD - [2004/08/09 23:00:00 | 00,122,880 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\glu32.dll
MOD - [2004/08/09 23:00:00 | 00,008,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\dciman32.dll
MOD - [2003/08/12 20:17:04 | 00,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msvcr71.dll


========== Win32 Services (SafeList) ==========

SRV - [2009/10/11 04:17:35 | 00,153,376 | —- | M] (Sun Microsystems, Inc.) [Auto | Running] – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService)
SRV - [2009/04/25 18:18:48 | 33,480,048 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE – (Microsoft SharePoint Workspace Audit Service)
SRV - [2009/04/08 15:37:12 | 04,319,136 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\WINDOWS\system32\OSPPSVC.EXE – (osppsvc)
SRV - [2009/04/08 15:31:36 | 00,163,688 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose)
SRV - [2008/05/19 02:35:50 | 00,356,434 | —- | M] (Atheros Communications, Inc.) [On_Demand | Stopped] – C:\Program Files\D-Link\RangeBooster G WUA-2340\JSWUtil\jswpsapi.exe – (jswpsapi)
SRV - [2007/01/19 10:49:26 | 00,049,152 | —- | M] (Wireless Service) [Auto | Running] – C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe – (ANIWZCSdService)
SRV - [2006/08/18 02:06:12 | 00,061,440 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files\Common Files\LightScribe\LSSrvc.exe – (LightScribeService)
SRV - [2006/05/09 17:50:00 | 00,131,139 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\WINDOWS\system32\nvsvc32.exe – (NVSvc)
SRV - [2005/08/03 02:19:16 | 00,058,880 | —- | M] (Microsoft) [Auto | Running] – C:\WINDOWS\arservice.exe – (ARSVC)
SRV - [2004/10/22 13:24:18 | 00,073,728 | —- | M] (Macrovision Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe – (IDriverT)
SRV - [2004/10/20 08:40:04 | 00,010,328 | R— | M] (America Online) [Auto | Running] – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe – (AOL ACS)
SRV - [2004/10/15 15:54:14 | 00,100,016 | —- | M] (America Online, Inc) [Auto | Running] – C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe – (AOL TopSpeedMonitor)


========== Driver Services (SafeList) ==========

DRV - [2009/04/28 15:20:06 | 00,044,944 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\WINDOWS\System32\Drivers\PxHelp20.sys – (PxHelp20)
DRV - [2008/06/13 07:50:26 | 00,386,784 | —- | M] (D-Link Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\A5AGU.sys – (A5AGU)
DRV - [2008/02/12 17:05:00 | 00,057,440 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\jswscimd.sys – (JSWSCIMD)
DRV - [2007/11/13 05:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\secdrv.sys – (Secdrv)
DRV - [2007/05/12 15:39:32 | 00,028,195 | —- | M] (Alpha Networks Inc.) [Kernel | Auto | Running] – C:\WINDOWS\system32\ANIO.sys – (ANIO)
DRV - [2006/06/14 13:04:12 | 04,299,264 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006/05/09 17:50:00 | 03,535,680 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2006/03/03 17:31:04 | 00,013,056 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nvnetbus.sys – (nvnetbus)
DRV - [2006/03/03 17:31:02 | 00,034,176 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\NVENETFD.sys – (NVENETFD)
DRV - [2005/12/12 19:27:00 | 00,019,072 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\PS2.sys – (Ps2)
DRV - [2005/12/06 13:20:50 | 00,241,664 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSXHWBS2.sys – (HSXHWBS2)
DRV - [2005/12/06 13:20:42 | 00,670,208 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSX_CNXT.sys – (winachsx)
DRV - [2005/12/06 13:20:40 | 00,936,448 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSX_DP.sys – (HSX_DP)
DRV - [2005/10/05 17:57:08 | 00,012,544 | —- | M] (Conexant) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\mdmxsdk.sys – (mdmxsdk)
DRV - [2005/06/29 19:03:18 | 00,175,104 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ftsata2.sys – (ftsata2)
DRV - [2005/03/09 16:53:00 | 00,036,352 | —- | M] (Advanced Micro Devices) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AmdK8.sys – (AmdK8)
DRV - [2005/01/08 03:07:18 | 00,138,752 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Hdaudbus.sys – (HDAudBus)
DRV - [2004/08/09 23:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ptilink.sys – (Ptilink)
DRV - [2004/08/03 16:31:34 | 00,020,992 | —- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RTL8139.sys – (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2003/11/05 09:45:12 | 00,017,408 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\bb-run.sys – (bb-run)
DRV - [2003/01/10 15:13:04 | 00,033,588 | R— | M] (America Online, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\wanatw4.sys – (wanatw) WAN Miniport (ATW)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.aol.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.2
FF - prefs.js..extensions.enabledItems: {e001c731-5e37-4538-a5cb-8168736a2360}:0.9.9.0
FF - prefs.js..extensions.enabledItems: {F8A55C97-3DB6-4961-A81D-0DE0080E53CB}:0.8.6
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.6.5
FF - prefs.js..extensions.enabledItems: [removed]:3.0.4
FF - prefs.js..extensions.enabledItems: [removed]:1.3.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: SkipScreen@SkipScreen:0.3.20091214_AMO
FF - prefs.js..extensions.enabledItems: [removed]:0.7.1

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/05 22:45:43 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/25 11:38:05 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Netscape Browser 8.0.4.0\Extensions\\Components: C:\Program Files\Netscape\Netscape Browser\Components [2009/10/19 15:50:20 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Netscape Browser 8.0.4.0\Extensions\\Plugins: C:\Program Files\Netscape\Netscape Browser\Plugins [2010/01/25 11:38:05 | 00,000,000 | —D | M]

[2009/10/19 16:46:02 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Extensions
[2010/01/26 22:54:16 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\wp9g4vzn.default\extensions
[2009/11/20 10:01:26 | 00,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\wp9g4vzn.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/01/07 11:43:07 | 00,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\wp9g4vzn.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/01/26 22:54:12 | 00,000,000 | —D | M] (No name found) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\wp9g4vzn.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2009/11/07 16:50:10 | 00,000,000 | —D | M] (Download Manager Tweak) – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\wp9g4vzn.default\extensions\{F8A55C97-3DB6-4961-A81D-0DE0080E53CB}
[2010/01/07 11:43:04 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\wp9g4vzn.default\extensions\[removed]
[2010/01/07 11:43:07 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\wp9g4vzn.default\extensions\SkipScreen@SkipScreen
[2010/01/07 11:43:12 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\wp9g4vzn.default\extensions\[removed]
[2009/11/16 10:20:09 | 00,000,000 | —D | M] – C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\wp9g4vzn.default\extensions\[removed]
[2010/01/26 22:54:16 | 00,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/01/26 22:38:26 | 00,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (hpWebHelper Class) - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll (Hewlett-Packard)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [HPBootOp] C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [mohepamof] C:\WINDOWS\System32\nadusajo.DLL ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [UserFaultCheck] File not found
O4 - HKCU..\Run: [AOL Fast Start] C:\Program Files\America Online 9.0\AOL.EXE (America Online, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\RunOnce: [UniblueRegistryBooster] C:\Program Files\Uniblue\RegistryBooster 2010\launcher.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\OfficeSAS.lnk = C:\Program Files\Microsoft Office\Office14\OfficeSAS\OfficeSASScheduler.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\RD2010.lnk = C:\Program Files\Angle Interactive\RD2010\RDAssistant.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: S&end; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Linked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Linked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O15 - HKLM\..Trusted Domains: trymedia.com ([]http in Trusted sites)
O15 - HKLM\..Trusted Domains: trymedia.com ([]https in Trusted sites)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (moyebari.dll) - C:\WINDOWS\System32\moyebari.dll ()
O20 - AppInit_DLLs: (c:\windows\system32\nadusajo.dll) - C:\WINDOWS\system32\nadusajo.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O21 - SSODL: zipodinaf - {9d598e7a-9402-4769-bfae-90ce46311b52} - C:\WINDOWS\system32\nadusajo.dll ()
O22 - SharedTaskScheduler: {9d598e7a-9402-4769-bfae-90ce46311b52} - gahurihor - C:\WINDOWS\system32\nadusajo.dll ()
O24 - Desktop WallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/11/15 16:26:53 | 00,000,100 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/27 08:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/04/30 00:01:14 | 00,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/01/27 09:27:20 | 02,077,424 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\HP_Administrator\Desktop\WindowsXP-KB894391-x86-ENU.exe
[2010/01/27 09:26:02 | 00,000,000 | —D | C] – C:\ProgramData
[2010/01/27 09:26:02 | 00,000,000 | —D | C] – C:\Program Files\Angle Interactive
[2010/01/27 09:21:42 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\HPQ
[2010/01/26 23:14:41 | 00,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/01/26 23:14:41 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/01/26 23:12:10 | 16,409,960 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\HP_Administrator\My Documents\spybotsd162.exe
[2010/01/26 22:54:17 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\QuickScan
[2010/01/26 22:37:46 | 00,000,000 | —D | C] – C:\_OTL
[2010/01/26 22:36:51 | 00,548,352 | —- | C] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\My Documents\OTL.exe
[2010/01/25 11:39:34 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Apple Computer
[2010/01/25 11:37:22 | 00,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/01/25 11:37:19 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/01/25 11:36:49 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/01/25 11:36:34 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Apple
[2010/01/25 11:36:27 | 00,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/01/25 11:36:26 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2010/01/25 11:36:00 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Apple Computer
[2010/01/23 22:33:22 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Application Data\Malwarebytes
[2010/01/23 22:33:17 | 00,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/23 22:33:16 | 00,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/01/23 22:33:16 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/01/23 22:33:16 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/01/11 18:47:26 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Christmasfamily2009014
[2010/01/10 21:08:56 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\1newsprig2010
[2010/01/10 12:08:28 | 00,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2010/01/10 12:07:36 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Synchronization Services
[2010/01/10 12:07:07 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Sync Framework
[2010/01/10 12:07:07 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Microsoft
[2010/01/10 12:07:06 | 00,000,000 | —D | C] – C:\Program Files\Microsoft.NET
[2010/01/10 12:07:06 | 00,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2010/01/10 12:06:20 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio 8
[2010/01/10 12:03:30 | 00,000,000 | —D | C] – C:\WINDOWS\SHELLNEW
[2010/01/10 12:03:15 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Analysis Services
[2010/01/10 12:02:03 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft Help
[2010/01/10 12:01:53 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2010/01/10 12:01:53 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2010/01/10 12:01:39 | 00,000,000 | RH-D | C] – C:\MSOCache
[2010/01/10 11:44:27 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\Microsoft Office 2010
[2010/01/06 10:52:53 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\My Documents\house
[2010/01/05 22:49:11 | 00,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Yahoo!
[2010/01/03 20:18:04 | 00,000,000 | –SD | C] – C:\Documents and Settings\HP_Administrator\My Documents\My DVDs
[2010/01/03 20:17:52 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusb.dll
[2010/01/03 20:17:51 | 00,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusd.dll
[2010/01/03 20:17:51 | 00,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2009/10/21 02:07:57 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2006/11/15 15:39:37 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2006/11/15 15:39:37 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2006/11/15 15:39:36 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2006/02/19 13:28:56 | 00,012,288 | —- | C] (Hewlett-Packard Development Company, L.P.) – C:\WINDOWS\Fonts\RandFont.dll

========== Files - Modified Within 30 Days ==========

[2099/01/01 12:00:00 | 00,096,256 | -HS- | M] () – C:\WINDOWS\System32\vukuleyi.dll
[2099/01/01 12:00:00 | 00,095,232 | -HS- | M] () – C:\WINDOWS\System32\kidoyera.dll
[2099/01/01 12:00:00 | 00,092,160 | -HS- | M] () – C:\WINDOWS\System32\geyedeza.dll
[2099/01/01 12:00:00 | 00,091,648 | -HS- | M] () – C:\WINDOWS\System32\zusudupe.dll
[2099/01/01 12:00:00 | 00,091,136 | -HS- | M] () – C:\WINDOWS\System32\nadusajo.dll
[2099/01/01 12:00:00 | 00,061,440 | -HS- | M] () – C:\WINDOWS\System32\dubolaho.dll
[2099/01/01 12:00:00 | 00,052,224 | -HS- | M] () – C:\WINDOWS\System32\sojerire.dll
[2099/01/01 12:00:00 | 00,052,224 | -HS- | M] () – C:\WINDOWS\System32\moyebari.dll
[2099/01/01 12:00:00 | 00,052,224 | -HS- | M] () – C:\WINDOWS\System32\lurapaso.dll
[2099/01/01 12:00:00 | 00,052,224 | -HS- | M] () – C:\WINDOWS\System32\heredetu.dll
[2099/01/01 12:00:00 | 00,041,984 | -HS- | M] () – C:\WINDOWS\System32\wuvajepe.dll
[2099/01/01 12:00:00 | 00,041,984 | -HS- | M] () – C:\WINDOWS\System32\ligaduvu.dll
[2099/01/01 12:00:00 | 00,038,912 | -HS- | M] () – C:\WINDOWS\System32\zurufalo.dll
[2099/01/01 12:00:00 | 00,038,400 | -HS- | M] () – C:\WINDOWS\System32\piyojomi.dll
[2099/01/01 12:00:00 | 00,038,400 | -HS- | M] () – C:\WINDOWS\System32\lakutufo.dll
[2099/01/01 12:00:00 | 00,038,400 | -HS- | M] () – C:\WINDOWS\System32\bamawasi.dll
[2099/01/01 12:00:00 | 00,037,888 | -HS- | M] () – C:\WINDOWS\System32\pogudoma.dll
[2010/01/27 09:57:01 | 00,006,456 | -H– | M] () – C:\WINDOWS\System32\matutile
[2010/01/27 09:43:33 | 00,000,183 | —- | M] () – C:\WINDOWS\System\hpsysdrv.DAT
[2010/01/27 09:41:54 | 00,000,698 | —- | M] () – C:\WINDOWS\win.ini
[2010/01/27 09:38:00 | 00,043,531 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/01/27 09:37:56 | 00,000,007 | —- | M] () – C:\WINDOWS\System32\ANIWZCSUSERNAME{3D958CD7-89F5-4196-8C92-596D769E8388}
[2010/01/27 09:37:56 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/01/27 09:37:54 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/01/27 09:37:52 | 10,051,13344 | -HS- | M] () – C:\hiberfil.sys
[2010/01/27 09:36:47 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\HP_Administrator\ntuser.ini
[2010/01/27 09:36:46 | 03,145,728 | -H– | M] () – C:\Documents and Settings\HP_Administrator\NTUSER.DAT
[2010/01/27 09:27:21 | 02,077,424 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\HP_Administrator\Desktop\WindowsXP-KB894391-x86-ENU.exe
[2010/01/27 09:26:15 | 00,000,792 | —- | M] () – C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\RD2010.lnk
[2010/01/27 09:26:15 | 00,000,753 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Reg Defender 2010.lnk
[2010/01/27 09:00:00 | 00,000,316 | —- | M] () – C:\WINDOWS\tasks\pmxvkrhy.job
[2010/01/26 23:14:46 | 00,000,944 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Spybot - Search & Destroy.lnk
[2010/01/26 23:12:45 | 16,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\HP_Administrator\My Documents\spybotsd162.exe
[2010/01/26 22:40:07 | 00,000,007 | —- | M] () – C:\WINDOWS\System32\ANIWZCSUSERNAME
[2010/01/26 22:38:26 | 00,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2010/01/26 22:37:01 | 00,548,352 | —- | M] (OldTimer Tools) – C:\Documents and Settings\HP_Administrator\My Documents\OTL.exe
[2010/01/26 18:41:54 | 00,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/01/26 01:36:33 | 00,095,360 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\atapi.sys
[2010/01/23 03:01:08 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/01/22 23:58:48 | 00,445,700 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/01/22 23:58:47 | 00,525,184 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/01/22 23:58:47 | 00,072,780 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/01/22 23:19:17 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/01/15 11:43:40 | 00,095,232 | —- | M] () – C:\Documents and Settings\HP_Administrator\My Documents\SyllabusTemplateSPHHS2010.doc
[2010/01/15 11:10:43 | 00,016,384 | —- | M] () – C:\WKCONV.RTF
[2010/01/14 17:11:12 | 00,005,120 | —- | M] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/14 03:17:31 | 00,317,952 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/01/13 12:34:56 | 00,015,009 | —- | M] () – C:\Documents and Settings\HP_Administrator\My Documents\I could smell it in the air.docx
[2010/01/10 18:48:20 | 00,087,552 | —- | M] () – C:\Documents and Settings\HP_Administrator\My Documents\Janey.doc
[2010/01/10 12:11:09 | 00,000,915 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\OfficeSAS.lnk
[2010/01/07 16:07:14 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/07 16:07:04 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/01/05 14:27:11 | 00,051,038 | —- | M] () – C:\Documents and Settings\HP_Administrator\My Documents\scubadaily1.5.10.rtf

========== Files Created - No Company Name ==========

[2099/01/01 12:00:00 | 00,096,256 | -HS- | C] () – C:\WINDOWS\System32\vukuleyi.dll
[2099/01/01 12:00:00 | 00,095,232 | -HS- | C] () – C:\WINDOWS\System32\kidoyera.dll
[2099/01/01 12:00:00 | 00,092,160 | -HS- | C] () – C:\WINDOWS\System32\geyedeza.dll
[2099/01/01 12:00:00 | 00,091,648 | -HS- | C] () – C:\WINDOWS\System32\zusudupe.dll
[2099/01/01 12:00:00 | 00,091,136 | -HS- | C] () – C:\WINDOWS\System32\nadusajo.dll
[2099/01/01 12:00:00 | 00,061,440 | -HS- | C] () – C:\WINDOWS\System32\dubolaho.dll
[2099/01/01 12:00:00 | 00,052,224 | -HS- | C] () – C:\WINDOWS\System32\sojerire.dll
[2099/01/01 12:00:00 | 00,052,224 | -HS- | C] () – C:\WINDOWS\System32\moyebari.dll
[2099/01/01 12:00:00 | 00,052,224 | -HS- | C] () – C:\WINDOWS\System32\lurapaso.dll
[2099/01/01 12:00:00 | 00,052,224 | -HS- | C] () – C:\WINDOWS\System32\heredetu.dll
[2099/01/01 12:00:00 | 00,041,984 | -HS- | C] () – C:\WINDOWS\System32\wuvajepe.dll
[2099/01/01 12:00:00 | 00,041,984 | -HS- | C] () – C:\WINDOWS\System32\ligaduvu.dll
[2099/01/01 12:00:00 | 00,038,912 | -HS- | C] () – C:\WINDOWS\System32\zurufalo.dll
[2099/01/01 12:00:00 | 00,038,400 | -HS- | C] () – C:\WINDOWS\System32\piyojomi.dll
[2099/01/01 12:00:00 | 00,038,400 | -HS- | C] () – C:\WINDOWS\System32\lakutufo.dll
[2099/01/01 12:00:00 | 00,038,400 | -HS- | C] () – C:\WINDOWS\System32\bamawasi.dll
[2099/01/01 12:00:00 | 00,037,888 | -HS- | C] () – C:\WINDOWS\System32\pogudoma.dll
[2099/01/01 12:00:00 | 00,006,456 | -H– | C] () – C:\WINDOWS\System32\matutile
[2010/01/27 09:26:15 | 00,000,792 | —- | C] () – C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\RD2010.lnk
[2010/01/27 09:26:15 | 00,000,753 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Reg Defender 2010.lnk
[2010/01/26 23:14:46 | 00,000,944 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Spybot - Search & Destroy.lnk
[2010/01/25 13:58:28 | 00,000,316 | —- | C] () – C:\WINDOWS\tasks\pmxvkrhy.job
[2010/01/22 23:58:33 | 00,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/01/15 11:43:40 | 00,095,232 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\SyllabusTemplateSPHHS2010.doc
[2010/01/13 12:34:54 | 00,015,009 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\I could smell it in the air.docx
[2010/01/10 21:34:16 | 00,016,384 | —- | C] () – C:\WKCONV.RTF
[2010/01/10 18:48:18 | 00,087,552 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\Janey.doc
[2010/01/10 12:11:09 | 00,000,915 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\OfficeSAS.lnk
[2010/01/05 14:27:11 | 00,051,038 | —- | C] () – C:\Documents and Settings\HP_Administrator\My Documents\scubadaily1.5.10.rtf
[2009/10/20 14:48:04 | 00,000,145 | —- | C] () – C:\WINDOWS\game.INI
[2009/10/19 19:42:48 | 00,005,120 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/19 19:40:08 | 00,262,144 | —- | C] () – C:\WINDOWS\System32\wlanapp.dll
[2009/10/19 19:40:08 | 00,049,152 | —- | C] () – C:\WINDOWS\System32\JJAKEn.dll
[2009/10/19 19:07:44 | 00,000,136 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\fusioncache.dat
[2006/11/15 16:56:27 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/11/15 16:36:16 | 00,028,848 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2006/11/15 16:30:14 | 00,014,316 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2006/11/15 16:30:08 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2006/11/15 16:27:08 | 00,000,174 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2006/11/15 16:15:06 | 00,000,157 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/11/15 16:14:28 | 00,000,698 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.ini
[2006/11/15 16:09:46 | 00,000,708 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006/11/15 16:08:47 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2006/11/15 16:05:51 | 01,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/11/15 16:05:51 | 01,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/11/15 16:05:51 | 01,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/11/15 16:05:51 | 00,573,440 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/11/15 16:05:51 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/11/15 16:05:51 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/11/15 16:05:50 | 00,106,496 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/11/15 16:04:34 | 00,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2006/11/15 15:42:44 | 00,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2006/11/15 15:42:44 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2006/11/15 15:42:26 | 00,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2006/06/16 13:58:18 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/06 00:01:54 | 00,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/08/03 02:19:16 | 00,050,176 | —- | C] () – C:\WINDOWS\armcex.dll
[2004/09/16 22:24:26 | 03,375,104 | —- | C] () – C:\WINDOWS\System32\qt-mt331.dll
[2004/07/26 09:51:38 | 00,000,560 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
< End of report >


extras.txt:

OTL Extras logfile created on: 1/27/2010 9:55:11 AM - Run 1
OTL by OldTimer - Version 3.1.27.0 Folder = C:\Documents and Settings\HP_Administrator\My Documents
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.00 Mb Total Physical Memory | 481.00 Mb Available Physical Memory | 50.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 177.46 Gb Total Space | 141.75 Gb Free Space | 79.88% Space Free | Partition Type: NTFS
Drive D: | 8.83 Gb Total Space | 0.86 Gb Free Space | 9.76% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-4DACD0EA75
Current User Name: HP_Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP – (Hewlett-Packard)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\DISC\DISCover.exe" = C:\Program Files\DISC\DISCover.exe:*:Enabled:DISCover Drop & Play System – (Digital Interactive Systems Corporation)
"C:\Program Files\DISC\DiscStreamHub.exe" = C:\Program Files\DISC\DiscStreamHub.exe:*:Enabled:DISCover Stream Hub – (Digital Interactive Systems Corporation, Inc.)
"C:\Program Files\DISC\myFTP.exe" = C:\Program Files\DISC\myFTP.exe:*:Enabled:DISCover FTP – (Digital Interactive Systems Corporation, Inc.)
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe" = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP – (Hewlett-Packard)
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – File not found
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL – (America Online)
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL – (America Online)
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe" = C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon – (America Online, Inc)
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe" = C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed – (America Online Inc)
"C:\Program Files\Common Files\AOL\1255985372\EE\AOLServiceHost.exe" = C:\Program Files\Common Files\AOL\1255985372\EE\AOLServiceHost.exe:*:Enabled:AOL – (America Online, Inc.)
"C:\Program Files\Common Files\AOL\System Information\sinf.exe" = C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL – (America Online Inc.)
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe" = C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:*:Enabled:AOL – ()
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe" = C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:*:Enabled:AOL – (AOL Spyware Protection)
"C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe" = C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL – (Gteko Ltd.)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\Microsoft Office\Office14\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:Explorer – (Microsoft Corporation)
"C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" = C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe:*:Enabled:WZCSLDR2 – (Wireless Service)
"C:\Program Files\DISC\DISCUpdMgr.exe" = C:\Program Files\DISC\DISCUpdMgr.exe:*:Enabled:DiscUpdMgr – (Digital Interactive Systems Corporation, Inc.)
"C:\WINDOWS\system32\dwwin.exe" = C:\WINDOWS\system32\dwwin.exe:*:Enabled:dwwin – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{0A65A3BD-54B5-4d0d-B084-7688507813F5}" = SlideShow
"{0F7C2E47-089E-4d23-B9F7-39BE00100776}" = Toolbox
"{10140000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 14
"{10140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 14
"{10140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 14
"{10140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 14
"{10140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 14
"{10140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 14
"{10140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 14
"{10140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 14
"{10140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 14
"{10140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 14
"{10140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 14
"{10140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 14
"{10140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 14
"{10140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 14
"{10140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 14
"{10140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 14
"{10140000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 14
"{10140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 14
"{10140000-011A-0000-0000-0000000FF1CE}" = Microsoft Office Send-a-Smile
"{1341D838-719C-4A05-B50F-49420CA1B4BB}" = HP Boot Optimizer
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{15C0AF59-4877-49B6-B8C6-A61CE54515F5}" = cp_OnlineProjectsConfig
"{167F938F-5AD3-40e2-B05D-2B7C6F0FDE48}" = HP Deskjet D1500 Printer Driver 10.0 Rel .3
"{188CEE76-0503-4910-A845-E1DC45685DA0}" = RangeBooster G WUA-2340
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD Plus
"{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 17
"{27FA210E-9F51-4E63-9C88-BAC9CC71A75A}" = RD2010
"{2818095F-FB6C-42C8-827E-0A406CC9AFF5}" = Quicken 2006
"{2AEABBDC-89E6-4AE2-BF99-DA6D188D6F7C}" = LightScribe [removed]
"{2F58D60D-2BFD-4467-9B4D-64E7355C329D}" = Sonic_PrimoSDK
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{305468A6-DE2D-43ba-A168-2F45A97A89DA}" = DJ_SF_03_D1500_Software_Min
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{33BF0960-DBA3-4187-B6CC-C969FCFA2D25}" = SkinsHP1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36D620AD-EEBA-4973-BA86-0C9AE6396620}" = OptionalContentQFolder
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{41E776A5-9B12-416D-9A12-B4F7B044EBED}" = CP_Package_Basic1
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 2.1
"{4C590030-7469-453E-8589-D15DA9D03F52}" = ANIWZCS2 Service
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{5FDD0538-C67A-4F67-B3F8-09D1AAF04D99}" = muvee autoProducer unPlugged 2.0
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Sonic Express Labeler
"{6696D9A4-28A8-4F5A-8E9A-2E8974C8C39C}" = RandMap
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7B5CE976-C7A9-4E38-A7F3-6C8EF025DD8E}" = ANIO Service
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"{82081779-4175-4666-A457-AB711CD37EF0}" = cp_LightScribeConfig
"{829DAAD6-BB11-4BB7-921B-07FFB703F944}" = CP_Package_Variety3
"{82E55892-6FFD-403F-AA97-D726846768AA}" = CP_AtenaShokunin1Config
"{866A0078-DEA7-4348-9C9A-999AF2991EAA}" = SlideShowMusic
"{8A534F71-3202-4464-A422-B767295E67B9}" = CP_Package_Variety2
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{93E5A317-24EC-4744-812C-16FECFE86E6A}" = CP_Package_Variety1
"{A29800BA-0BF1-4E63-9F31-DF05A87F4104}" = InstantShareDevices
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-A70500000002}" = Adobe Reader 7.0.5
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{B2157760-AA3C-4E2E-BFE6-D20BC52495D9}" = cp_PosterPrintConfig
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6286A44-7505-471A-A72B-04EC2DB2F442}" = CueTour
"{B69CFE29-FD03-4E0A-87A7-6ED97F98E5B3}" = CP_Panorama1Config
"{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}" = HP Software Update
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1C6767D-B395-43CB-BF99-051B58B86DA6}" = PhotoGallery
"{C3FAA091-B278-44A7-BF48-190811C5F9F7}" = cp_UpdateProjectsConfig
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DAAD5187-62C5-4AD6-A526-803C18C4944D}" = HP Web Helper
"{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}" = HpSdpAppCoreApp
"{E63E34A7-E552-412B-9E40-FD6FC5227ABA}_is1" = Uniblue RegistryBooster 2010
"{ED2C557E-9C18-41FF-B58E-A05EEF0B3B5F}" = CP_CalendarTemplates1
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F80239D8-7811-4D5E-B033-0D0BBFE32920}" = HP DigitalMedia Archive
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FB4740B3-2530-452D-A825-F7AB246CA7DF}" = muvee autoProducer 5.0
"12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AOL Connectivity Services" = AOL Connectivity Services
"AOL Spyware Protection" = AOL Spyware Protection
"AOL Uninstaller" = AOL Uninstaller
"AOL YGP Screensaver" = AOL You've Got Pictures Screensaver
"AolCoach2_en" = AOL Coach Version 2.0(Build:20041026.5 en)
"AwayMode160" = Microsoft Away Mode
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200C14F1" = Data Fax SoftModem with SmartCP
"DISCover" = DISCover
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Photo & Imaging" = HP Photosmart Premier Software 6.5
"HP Photosmart for Media Center PC" = HP Photosmart for Media Center PC
"HPOOVClient-9972322 Uninstaller" = Updates from HP (remove only)
"Install WeatherBug" = Remove WeatherBug Installer
"InstallShield_{23012310-3E05-46A5-88A9-C6CBCABCAC79}" = Customer Experience Enhancement
"InstallShield_{8105684D-8CA6-440D-8F58-7E5FD67A499D}" = Easy Internet Sign-up
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.7)" = Mozilla Firefox (3.5.7)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Netscape Browser" = Netscape Browser (remove only)
"NVIDIA Drivers" = NVIDIA Drivers
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010 (Technical Preview)
"OfficeTrial" = Microsoft Office Standard Edition 2003 60 days trial
"PC-Doctor 5 for Windows" = PC-Doctor 5 for Windows
"Python 2.2.3" = Python 2.2.3
"pywin32-py2.2" = Python 2.2 pywin32 extensions (build 203)
"RealPlayer 6.0" = RealPlayer
"Rhapsody" = Rhapsody
"uTorrent" = µTorrent
"ViewpointMediaPlayer" = Viewpoint Media Player
"WIC" = Windows Imaging Component
"WildTangent CDA" = WildTangent Web Driver
"WildTangent hpmedia Master Uninstall" = My HP Games
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar for Internet Explorer
"Yahoo! Toolbar" = Yahoo! Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Media Player" = Move Media Player
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/27/2010 10:12:50 AM | Computer Name = YOUR-4DACD0EA75 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x02baf7a0.

Error - 1/27/2010 10:15:08 AM | Computer Name = YOUR-4DACD0EA75 | Source = Application Error | ID = 1004
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x02b7f7a0.

Error - 1/27/2010 10:19:51 AM | Computer Name = YOUR-4DACD0EA75 | Source = Application Error | ID = 1004
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x024cf7a0.

Error - 1/27/2010 10:19:56 AM | Computer Name = YOUR-4DACD0EA75 | Source = Application Error | ID = 1001
Description = Fault bucket 938191705.

Error - 1/27/2010 10:19:57 AM | Computer Name = YOUR-4DACD0EA75 | Source = Application Error | ID = 1004
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x02c1f7a0.

Error - 1/27/2010 10:21:06 AM | Computer Name = YOUR-4DACD0EA75 | Source = Application Error | ID = 1004
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x0254f7a0.

Error - 1/27/2010 10:26:15 AM | Computer Name = YOUR-4DACD0EA75 | Source = Application Error | ID = 1004
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x02b7f7a0.

Error - 1/27/2010 10:30:23 AM | Computer Name = YOUR-4DACD0EA75 | Source = Application Error | ID = 1004
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x02b7f7a0.

Error - 1/27/2010 10:35:39 AM | Computer Name = YOUR-4DACD0EA75 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x0267f7a0.

Error - 1/27/2010 10:38:00 AM | Computer Name = YOUR-4DACD0EA75 | Source = Application Error | ID = 1004
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x02b7f7a0.

[ System Events ]
Error - 1/27/2010 10:15:28 AM | Computer Name = YOUR-4DACD0EA75 | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 1/27/2010 10:15:28 AM | Computer Name = YOUR-4DACD0EA75 | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 1/27/2010 10:21:26 AM | Computer Name = YOUR-4DACD0EA75 | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 1/27/2010 10:21:26 AM | Computer Name = YOUR-4DACD0EA75 | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 1/27/2010 10:30:43 AM | Computer Name = YOUR-4DACD0EA75 | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 1/27/2010 10:30:43 AM | Computer Name = YOUR-4DACD0EA75 | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 1/27/2010 10:35:40 AM | Computer Name = YOUR-4DACD0EA75 | Source = Service Control Manager | ID = 7031
Description = The DCOM Server Process Launcher service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in 60000
milliseconds: Reboot the machine.

Error - 1/27/2010 10:35:40 AM | Computer Name = YOUR-4DACD0EA75 | Source = Service Control Manager | ID = 7034
Description = The Terminal Services service terminated unexpectedly. It has done
this 1 time(s).

Error - 1/27/2010 10:38:21 AM | Computer Name = YOUR-4DACD0EA75 | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 1/27/2010 10:38:21 AM | Computer Name = YOUR-4DACD0EA75 | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.


< End of report >

Aaaaand a new wrinkle….I'm getting a repeated message that says, "Data excecution prevention To help protect your computer, windows has closed this program name: generic host process for win32 services"
Hi, Thanks, sorry about my confusion, I should have realized you just ran a fix and not the program itself…now we can get back on track: The log from the fix will be located here: C:\_OTL\MovedFiles folder (mmddyyyy_hhmmss.log format - your date and time will be 27 Jan10 at the time you ran the scan). If you can locate that log and post it. I will look over the logs you have provided and get back to you with further instructions as soon as possible.
No problem! I was just laughing at how completely hopeless you must have thought I was if I needed that kind of direction :)

Here's what you asked for:

All processes killed
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\"Shell"|"explorer.exe" /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\"Userinit"|"C:\\WINDOWS\\system32\\Userinit.exe," /E : value set successfully!
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\\DisableTaskMgr deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\\DisableTaskMgr not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetActiveDesktop deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoActiveDesktopChanges deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSetActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoActiveDesktopChanges deleted successfully.
========== FILES ==========
File\Folder helper32.dll not found.
File\Folder winhelper86.dll not found.
C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk moved successfully.
C:\WINDOWS\system32\config\systemprofile\Desktop\Internet Security 2010.lnk moved successfully.
C:\WINDOWS\system32\config\systemprofile\Start Menu\Internet Security 2010.lnk moved successfully.
C:\WINDOWS\System32\winlogon32.exe moved successfully.
C:\WINDOWS\System32\smss32.exe moved successfully.
File/Folder C:\WINDOWS\System32\AVR10.exe not found.
C:\WINDOWS\System32\helper32.dll moved successfully.
File/Folder C:\WINDOWS\System32\winlogon32.exe not found.
File/Folder C:\WINDOWS\System32\smss32.exe not found.
C:\WINDOWS\System32\warning.html moved successfully.
C:\WINDOWS\system32\IS15.exe moved successfully.
File/Folder C:\WINDOWS\System32\winhelper86.dll not found.
File/Folder C:\trhh.exe not found.
File/Folder C:\sdigdvmg.exe not found.
File/Folder C:\wgqi.exe not found.
File/Folder C:\byyk.exe not found.
File/Folder C:\WINDOWS\lsass.exe not found.
File/Folder C:\WINDOWS\odbn0.exe not found.
File/Folder C:\WINDOWS\System32\sdra64.exe not found.
C:\WINDOWS\System32\41.exe moved successfully.
File/Folder C:\WINDOWS\System32\153.exe not found.
File/Folder C:\WINDOWS\System32\292.exe not found.
File/Folder C:\WINDOWS\System32\491.exe not found.
File/Folder C:\WINDOWS\System32\1869.exe not found.
File/Folder C:\WINDOWS\system32\2876.exe not found.
File/Folder C:\WINDOWS\System32\2995.exe not found.
File/Folder C:\WINDOWS\System32\3902.exe not found.
File/Folder C:\WINDOWS\System32\4827.exe not found.
File/Folder C:\WINDOWS\System32\5436.exe not found.
File/Folder C:\WINDOWS\System32\5447.exe not found.
C:\WINDOWS\System32\5705.exe moved successfully.
C:\WINDOWS\System32\6334.exe moved successfully.
File/Folder C:\WINDOWS\System32\7376.exe not found.
File/Folder C:\WINDOWS\System32\9961.exe not found.
C:\WINDOWS\System32\11478.exe moved successfully.
File/Folder C:\WINDOWS\System32\11538.exe not found.
File/Folder C:\WINDOWS\System32\11942.exe not found.
File/Folder C:\WINDOWS\System32\12382.exe not found.
File/Folder C:\WINDOWS\system32\12662.exe not found.
File/Folder C:\WINDOWS\System32\13931.exe not found.
File/Folder C:\WINDOWS\system32\14070.exe not found.
File/Folder C:\WINDOWS\System32\14604.exe not found.
File/Folder C:\WINDOWS\System32\14771.exe not found.
C:\WINDOWS\System32\15724.exe moved successfully.
File/Folder C:\WINDOWS\System32\16827.exe not found.
File/Folder C:\WINDOWS\System32\16944.exe not found.
File/Folder C:\WINDOWS\system32\17125.exe not found.
File/Folder C:\WINDOWS\System32\17421.exe not found.
C:\WINDOWS\System32\18467.exe moved successfully.
File/Folder C:\WINDOWS\System32\18716.exe not found.
C:\WINDOWS\System32\19169.exe moved successfully.
File/Folder C:\WINDOWS\System32\19718.exe not found.
File/Folder C:\WINDOWS\System32\19895.exe not found.
File/Folder C:\WINDOWS\system32\19905.exe not found.
File/Folder C:\WINDOWS\System32\19912.exe not found.
File/Folder C:\WINDOWS\system32\21386.exe not found.
File/Folder C:\WINDOWS\System32\21726.exe not found.
File/Folder C:\WINDOWS\system32\22934.exe not found.
File/Folder C:\WINDOWS\System32\23281.exe not found.
File/Folder C:\WINDOWS\system32\24242.exe not found.
C:\WINDOWS\System32\24464.exe moved successfully.
File/Folder C:\WINDOWS\system32\24478.exe not found.
File/Folder C:\WINDOWS\System32\26308.exe not found.
C:\WINDOWS\System32\26500.exe moved successfully.
C:\WINDOWS\System32\26962.exe moved successfully.
File/Folder C:\WINDOWS\system32\27213.exe not found.
File/Folder C:\WINDOWS\System32\28145.exe not found.
File/Folder C:\WINDOWS\system32\28466.exe not found.
C:\WINDOWS\System32\29358.exe moved successfully.
File/Folder C:\WINDOWS\System32\32391.exe not found.
File/Folder C:\WINDOWS\System32\32439.exe not found.
File/Folder C:\WINDOWS\system32\ndisdrv.sys not found.
File/Folder C:\s not found.
File/Folder C:\WINDOWS\system32\kbdsock.dll not found.
File/Folder C:\WINDOWS\system32\mshlps.dll not found.
File/Folder C:\WINDOWS\system32\drivers\kdrhkukb.sys not found.
File/Folder C:\Program Files\InternetSecurity2010 not found.
File/Folder C:\WINDOWS\System32\lowsec not found.
========== SERVICES/DRIVERS ==========
Error: No service named lmuytnv was found to stop!
Unable to stop service lmuytnv!
Error: No service named ndisdrv was found to stop!
Unable to stop service ndisdrv!
Error: No service named qvazdxe was found to stop!
Unable to stop service qvazdxe!
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32768 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: HP_Administrator
->Temp folder emptied: 1141699289 bytes
->Temporary Internet Files folder emptied: 5213568 bytes
->Java cache emptied: 58692922 bytes
->FireFox cache emptied: 98795548 bytes

User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 166929 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3490556 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 23972966 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 138665336 bytes
RecycleBin emptied: 786943276 bytes

Total Files Cleaned = 2,153.00 mb

Restore point Set: OTL Restore Point (64424509440)
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.1.27.0 log created on 01262010_223746

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…

  • Please reopen [external image: Posted Image] on your desktop.
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :OTL
    MOD - [2099/01/01 12:00:00 | 00,091,136 | -HS- | M] () – C:\WINDOWS\system32\nadusajo.dll
    MOD - [2099/01/01 12:00:00 | 00,052,224 | -HS- | M] () – C:\WINDOWS\system32\moyebari.dll
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
    O4 - HKLM..\Run: [mohepamof] C:\WINDOWS\System32\nadusajo.DLL ()
    O4 - HKLM..\Run: [UserFaultCheck] File not found
    O20 - AppInit_DLLs: (moyebari.dll) - C:\WINDOWS\System32\moyebari.dll ()
    O20 - AppInit_DLLs: (c:\windows\system32\nadusajo.dll) - C:\WINDOWS\system32\nadusajo.dll ()
    O21 - SSODL: zipodinaf - {9d598e7a-9402-4769-bfae-90ce46311b52} - C:\WINDOWS\system32\nadusajo.dll ()
    O22 - SharedTaskScheduler: {9d598e7a-9402-4769-bfae-90ce46311b52} - gahurihor - C:\WINDOWS\system32\nadusajo.dll ()
    [2099/01/01 12:00:00 | 00,096,256 | -HS- | M] () – C:\WINDOWS\System32\vukuleyi.dll
    [2099/01/01 12:00:00 | 00,095,232 | -HS- | M] () – C:\WINDOWS\System32\kidoyera.dll
    [2099/01/01 12:00:00 | 00,092,160 | -HS- | M] () – C:\WINDOWS\System32\geyedeza.dll
    [2099/01/01 12:00:00 | 00,091,648 | -HS- | M] () – C:\WINDOWS\System32\zusudupe.dll
    [2099/01/01 12:00:00 | 00,091,136 | -HS- | M] () – C:\WINDOWS\System32\nadusajo.dll
    [2099/01/01 12:00:00 | 00,061,440 | -HS- | M] () – C:\WINDOWS\System32\dubolaho.dll
    [2099/01/01 12:00:00 | 00,052,224 | -HS- | M] () – C:\WINDOWS\System32\sojerire.dll
    [2099/01/01 12:00:00 | 00,052,224 | -HS- | M] () – C:\WINDOWS\System32\moyebari.dll
    [2099/01/01 12:00:00 | 00,052,224 | -HS- | M] () – C:\WINDOWS\System32\lurapaso.dll
    [2099/01/01 12:00:00 | 00,052,224 | -HS- | M] () – C:\WINDOWS\System32\heredetu.dll
    [2099/01/01 12:00:00 | 00,041,984 | -HS- | M] () – C:\WINDOWS\System32\wuvajepe.dll
    [2099/01/01 12:00:00 | 00,041,984 | -HS- | M] () – C:\WINDOWS\System32\ligaduvu.dll
    [2099/01/01 12:00:00 | 00,038,912 | -HS- | M] () – C:\WINDOWS\System32\zurufalo.dll
    [2099/01/01 12:00:00 | 00,038,400 | -HS- | M] () – C:\WINDOWS\System32\piyojomi.dll
    [2099/01/01 12:00:00 | 00,038,400 | -HS- | M] () – C:\WINDOWS\System32\lakutufo.dll
    [2099/01/01 12:00:00 | 00,038,400 | -HS- | M] () – C:\WINDOWS\System32\bamawasi.dll
    [2099/01/01 12:00:00 | 00,037,888 | -HS- | M] () – C:\WINDOWS\System32\pogudoma.dll
    [2010/01/27 09:57:01 | 00,006,456 | -H– | M] () – C:\WINDOWS\System32\matutile
    [2010/01/27 09:00:00 | 00,000,316 | —- | M] () – C:\WINDOWS\tasks\pmxvkrhy.job
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]
  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
Here ya go

All processes killed
========== OTL ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\mohepamof deleted successfully.
C:\WINDOWS\system32\nadusajo.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\UserFaultCheck deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:moyebari.dll deleted successfully.
C:\WINDOWS\system32\moyebari.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\nadusajo.dll deleted successfully.
File C:\WINDOWS\system32\nadusajo.dll not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\zipodinaf deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9d598e7a-9402-4769-bfae-90ce46311b52}\ deleted successfully.
File C:\WINDOWS\system32\nadusajo.dll not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{9d598e7a-9402-4769-bfae-90ce46311b52} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9d598e7a-9402-4769-bfae-90ce46311b52}\ not found.
File C:\WINDOWS\system32\nadusajo.dll not found.
C:\WINDOWS\system32\vukuleyi.dll moved successfully.
C:\WINDOWS\system32\kidoyera.dll moved successfully.
C:\WINDOWS\system32\geyedeza.dll moved successfully.
C:\WINDOWS\system32\zusudupe.dll moved successfully.
File C:\WINDOWS\System32\nadusajo.dll not found.
C:\WINDOWS\system32\dubolaho.dll moved successfully.
C:\WINDOWS\system32\sojerire.dll moved successfully.
File C:\WINDOWS\System32\moyebari.dll not found.
C:\WINDOWS\system32\lurapaso.dll moved successfully.
C:\WINDOWS\system32\heredetu.dll moved successfully.
C:\WINDOWS\system32\wuvajepe.dll moved successfully.
C:\WINDOWS\system32\ligaduvu.dll moved successfully.
C:\WINDOWS\system32\zurufalo.dll moved successfully.
C:\WINDOWS\system32\piyojomi.dll moved successfully.
C:\WINDOWS\system32\lakutufo.dll moved successfully.
C:\WINDOWS\system32\bamawasi.dll moved successfully.
C:\WINDOWS\system32\pogudoma.dll moved successfully.
C:\WINDOWS\system32\matutile moved successfully.
C:\WINDOWS\tasks\pmxvkrhy.job moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

Hi,

Please do the following:

Download ComboFix from either of these locations:
Link 1
Link 2


VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
the log:

ComboFix 10-01-26.06 - HP_Administrator 01/27/2010 11:17:24.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.676 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Start Menu\Programs\Startup\OfficeSAS.lnk
c:\windows\kb913800.exe
D:\Autorun.inf

Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :P
.
((((((((((((((((((((((((( Files Created from 2009-12-27 to 2010-01-27 )))))))))))))))))))))))))))))))
.

2010-01-27 14:26 . 2010-01-27 14:26 ——– d—–w- C:\ProgramData
2010-01-27 14:26 . 2010-01-27 14:26 ——– d—–w- c:\program files\Angle Interactive
2010-01-27 14:21 . 2010-01-27 14:21 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\HPQ
2010-01-27 04:14 . 2010-01-27 04:28 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-01-27 04:14 . 2010-01-27 04:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-27 03:54 . 2010-01-27 03:58 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\QuickScan
2010-01-27 03:37 . 2010-01-27 03:37 ——– d—–w- C:\_OTL
2010-01-25 16:39 . 2010-01-25 16:39 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\Apple Computer
2010-01-25 16:37 . 2010-01-25 16:38 ——– d—–w- c:\program files\QuickTime
2010-01-25 16:37 . 2010-01-25 16:37 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-01-25 16:36 . 2010-01-25 16:36 ——– d—–w- c:\program files\Common Files\Apple
2010-01-25 16:36 . 2010-01-25 16:36 ——– d—–w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Apple
2010-01-25 16:36 . 2010-01-25 16:36 ——– d—–w- c:\program files\Apple Software Update
2010-01-25 16:36 . 2010-01-25 16:36 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2010-01-25 16:36 . 2010-01-25 16:36 ——– d—–w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Apple Computer
2010-01-24 03:33 . 2010-01-24 03:33 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\Malwarebytes
2010-01-24 03:33 . 2010-01-24 03:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-23 20:20 . 2010-01-23 20:20 ——– d—–w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Adobe
2010-01-23 04:58 . 2010-01-26 23:41 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-01-23 04:24 . 2010-01-23 04:24 ——– d-s—w- c:\windows\system32\config\systemprofile\UserData
2010-01-10 17:07 . 2010-01-10 17:07 ——– d—–w- c:\program files\Microsoft Synchronization Services
2010-01-10 17:07 . 2010-01-10 17:10 ——– d—–w- c:\documents and settings\All Users\Microsoft
2010-01-10 17:07 . 2010-01-10 17:07 ——– d—–w- c:\program files\Microsoft Sync Framework
2010-01-10 17:07 . 2010-01-10 17:07 ——– d—–w- c:\program files\Microsoft.NET
2010-01-10 17:07 . 2010-01-10 17:07 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition
2010-01-10 17:06 . 2010-01-10 17:06 ——– d—–w- c:\program files\Microsoft Visual Studio 8
2010-01-10 17:03 . 2010-01-10 17:08 ——– d—–w- c:\windows\SHELLNEW
2010-01-10 17:03 . 2010-01-10 17:03 ——– d—–w- c:\program files\Microsoft Analysis Services
2010-01-10 17:02 . 2010-01-10 17:02 ——– d—–w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Microsoft Help
2010-01-10 17:01 . 2010-01-10 17:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-10 17:01 . 2010-01-10 17:01 ——– d—–r- C:\MSOCache
2010-01-06 03:49 . 2010-01-06 03:49 ——– d—–w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Yahoo!
2010-01-04 01:17 . 2001-08-18 03:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2010-01-04 01:17 . 2004-08-04 05:56 159232 —-a-w- c:\windows\system32\ptpusd.dll
2010-01-04 01:17 . 2004-08-04 03:58 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2010-01-04 01:17 . 2004-08-04 03:58 15104 —-a-w- c:\windows\system32\dllcache\usbscan.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-26 06:36 . 2004-08-10 04:00 95360 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-01-20 10:54 . 2009-10-20 17:40 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\uTorrent
2010-01-11 22:33 . 2010-01-27 03:54 789320 —-a-w- c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\wp9g4vzn.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
2010-01-11 22:32 . 2010-01-27 03:54 698184 —-a-w- c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\wp9g4vzn.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
2010-01-10 17:13 . 2006-11-15 21:20 90040 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-10 17:08 . 2009-10-20 13:20 ——– d—–w- c:\program files\MSBuild
2010-01-10 14:46 . 2006-11-15 21:16 ——– d—–w- c:\documents and settings\All Users\Application Data\WildTangent
2009-12-22 05:35 . 2004-08-10 04:00 668672 —-a-w- c:\windows\system32\wininet.dll
2009-12-22 05:35 . 2004-08-10 04:00 81920 ——w- c:\windows\system32\ieencode.dll
2009-12-18 15:49 . 2009-12-18 15:45 153742 —-a-w- c:\windows\hphins26.dat
2009-12-18 15:49 . 2006-11-15 21:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Hewlett-Packard
2009-12-11 04:30 . 2009-12-11 03:58 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\Move Networks
2009-12-11 03:58 . 2009-12-11 03:58 127325 —-a-w- c:\documents and settings\HP_Administrator\Application Data\Move Networks\uninstall.exe
2009-12-11 03:58 . 2009-08-13 19:21 4187512 —-a-w- c:\documents and settings\HP_Administrator\Application Data\Move Networks\plugins\npqmp071505000011.dll
2009-12-11 03:56 . 2009-12-11 03:56 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\Sonic
2009-12-11 03:56 . 2009-12-11 03:56 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\Leadertech
2009-12-07 18:08 . 2006-11-15 20:50 ——– d—–w- c:\program files\Java
2009-12-07 18:07 . 2009-12-07 18:07 152576 —-a-w- c:\documents and settings\HP_Administrator\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-07 18:07 . 2009-12-07 18:07 79488 —-a-w- c:\documents and settings\HP_Administrator\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-21 16:36 . 2004-08-10 04:00 470528 —-a-w- c:\windows\AppPatch\aclayers.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
2009-04-08 21:05 739688 —-a-w- c:\progra~1\MICROS~2\Office14\URLREDIR.DLL

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"AOL Fast Start"="c:\program files\America Online 9.0\AOL.EXE" [2005-07-28 50776]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"UniblueRegistryBooster"="c:\program files\Uniblue\RegistryBooster 2010\launcher.exe" [2009-09-29 59184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 249856]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-09 7311360]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates From HP.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Updates From HP.lnk
backup=c:\windows\pss\Updates From HP.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
2004-10-18 21:42 79448 —-a-w- c:\progra~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
2004-10-20 13:40 34904 —-a-r- c:\program files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
2006-03-10 22:22 48280 —-a-w- c:\program files\Common Files\AOL\1255985372\EE\aolsoftware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-10-13 23:24 1694208 ——w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 04:08 417792 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 09:17 149280 —-a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2009-07-01 16:37 37888 —-a-w- c:\program files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1255985372\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"=
"c:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\ANI\\ANIWZCS2 Service\\WZCSLDR2.exe"=
"c:\\Program Files\\DISC\\DISCUpdMgr.exe"=
"c:\\WINDOWS\\system32\\dwwin.exe"=
"c:\\WINDOWS\\system32\\dllhost.exe"=
"c:\\WINDOWS\\ehome\\ehrecvr.exe"=

R2 osppsvc;Office Software Protection Platform;c:\windows\system32\OSPPSVC.EXE [4/8/2009 3:37 PM 4319136]
R3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\drivers\A5AGU.sys [10/19/2009 7:39 PM 386784]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [10/19/2009 7:39 PM 57440]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\D-Link\RangeBooster G WUA-2340\JSWUtil\jswpsapi.exe [10/19/2009 7:39 PM 356434]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [4/25/2009 6:18 PM 33480048]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=64&bd;=PAVILION&pf;=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=64&bd;=PAVILION&pf;=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=64&bd;=PAVILION&pf;=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=64&bd;=PAVILION&pf;=desktop
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=64&bd;=PAVILION&pf;=desktop
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: S&end; to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
Trusted Zone: trymedia.com
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\wp9g4vzn.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com/
FF - component: c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\wp9g4vzn.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
FF - plugin: c:\documents and settings\HP_Administrator\Application Data\Move Networks\plugins\npqmp071505000011.dll
FF - plugin: c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\wp9g4vzn.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: c:\documents and settings\HP_Administrator\Local Settings\Application Data\Yahoo!\BrowserPlus\2.4.21\Plugins\npybrowserplus_2.4.21.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-mohepamof - c:\windows\system32\nadusajo.dll
SharedTaskScheduler-{9d598e7a-9402-4769-bfae-90ce46311b52} - c:\windows\system32\nadusajo.dll
SSODL-zipodinaf-{9d598e7a-9402-4769-bfae-90ce46311b52} - c:\windows\system32\nadusajo.dll



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-27 11:23
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3900)
c:\progra~1\MICROS~2\Office14\1033\GrooveIntlResource.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Common Files\aolshare\aolshcpy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
c:\program files\Common Files\AOL\ACS\AOLAcsd.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\windows\arservice.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\program files\America Online 9.0\waol.exe
c:\program files\America Online 9.0\shellmon.exe
c:\program files\Uniblue\RegistryBooster 2010\registrybooster.exe
c:\program files\Uniblue\RegistryBooster 2010\registrybooster.exe
.
**************************************************************************
.
Completion time: 2010-01-27 11:29:06 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-27 16:29

Pre-Run: 152,196,071,424 bytes free
Post-Run: 152,145,649,664 bytes free

- - End Of File - - E31C4DAC61F5E27586DD3C1A8D0091CD

hi,

Please do the following:

  • Open your Malwarebytes' Anti-Malware program and select the update tab, select update now
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so.


NEXT


Using Internet Explorer or Firefox, visit Kaspersky Online Scanner:
1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.
    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
malwarebytes log:

Malwarebytes' Anti-Malware 1.44
Database version: 3646
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

1/27/2010 12:33:12 PM
mbam-log-2010-01-27 (12-33-12).txt

Scan type: Quick Scan
Objects scanned: 124185
Time elapsed: 4 minute(s), 15 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\VB and VBA Program Settings\RD2010 (Rogue.RegDefender) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\Angle Interactive\RD2010 (Rogue.RegDefender) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\Angle Interactive\RD2010\check.txt (Rogue.RegDefender) -> Quarantined and deleted successfully.


Kaspersky log:

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Wednesday, January 27, 2010
Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Wednesday, January 27, 2010 17:34:53
Records in database: 3377684
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Scan statistics:
Objects scanned: 104432
Threats found: 4
Infected objects found: 7
Suspicious objects found: 0
Scan duration: 03:17:52


File name / Threat / Threats count
C:\hp\bin\wbug\HPPavillion_Spring06.exe Infected: not-a-virus:AdWare.Win32.WeatherBug.a 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\atapi.sys.vir Infected: Rootkit.Win32.TDSS.y 1
C:\WINDOWS\system32\spool\prtprocs\w32x86\205.tmp Infected: Packed.Win32.TDSS.aa 1
C:\_OTL\MovedFiles\01262010_223746\C_WINDOWS\system32\smss32.exe Infected: Trojan-Downloader.Win32.FraudLoad.wxtw 1
C:\_OTL\MovedFiles\01262010_223746\C_WINDOWS\system32\winlogon32.exe Infected: Trojan-Downloader.Win32.FraudLoad.wxtw 1
D:\I386\APPS\APP13033\src\CompaqPresario_Spring06.exe Infected: not-a-virus:AdWare.Win32.WeatherBug.a 1
D:\I386\APPS\APP13033\src\HPPavillion_Spring06.exe Infected: not-a-virus:AdWare.Win32.WeatherBug.a 1

Selected area has been scanned.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI