This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infected with AntiVirus XP 2010 rogue program

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Hi lucella31,

I was under the impression that you could launch exes in safe mode on the infected account. You said exehelper.com ran successfully on your mother account?

Please clarify what the account names are.


Let's try this, in your mother's account rename dds to dds.bat If that doesn't work try dds.pif


Using your account submit this file for analysis.

We need some file informantion
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path, one at a time if more than file is listed, into the "Suspicious files to scan" box on the top of the page:

    C:\WINDOWS\system32\userinit.exe

  • Click on the Upload button
  • Please ensure the scan is complete and the results saved before submitting the next.
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.
OK, to clarify…my mother's name is Cookie and my name is Amber.

I still can access the internet and launch programs under my account.
I cannot do that under Cookie (the infected account).

Under Cookie's account, I was able to change the DDS extension to .bat and open it, but I did not get two reports (Attach and DDS). I'm sending you what I did get.
For some reason my name shows up in the log below, even though I was under Cookie's account.

***The VirScan results your requested follow the DDS report.***

FYI: I have been transferring info through a flash drive from the PC to my laptop so as not to be on the internet and risk further infection.


DDS (Ver_09-06-26.01) - NTFSx86 MINIMAL
Run by [removed] at 17:31:39.62 on Thu 02/11/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1013.748 [GMT -8:00]

AV: PC-cillin Internet Security - Virus Protection *On-access scanning enabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: PC-cillin Internet Security - Firewall *enabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\Documents and Settings\Amber\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=0080318
uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
mSearchAssistant = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: ALOT Toolbar: {5aa2ba46-9913-4dc7-9620-69ab0fa17ae7} - c:\program files\alot\bin\alot.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: IEHlprObj Class: {8ca5ed52-f3fb-4414-a105-2e3491156990} - c:\program files\iwin games\iWinGamesHookIE.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: iWin Toolbar: {ce0c2586-da36-452b-acdb-320d9bcb19bf} - c:\program files\iwin\tbiWi0.dll
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: iWin Toolbar: {ce0c2586-da36-452b-acdb-320d9bcb19bf} - c:\program files\iwin\tbiWi0.dll
TB: ALOT Toolbar: {5aa2ba46-9913-4dc7-9620-69ab0fa17ae7} - c:\program files\alot\bin\alot.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1210395665609
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://zone.msn.com/bingame/popcaploader_v10.cab
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL

================= FIREFOX ===================

FF - ProfilePath -
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

S2 datunidr;DellAutomatedPCTuneUp UniDriver;c:\windows\system32\drivers\datunidr.sys [2007-8-23 5376]
S2 iWinTrusted;iWinTrusted;c:\program files\iwin games\iWinTrusted.exe [2009-6-4 78104]
S2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512]
S2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\trendm~1\intern~1\Tmntsrv.exe [2007-11-8 345696]
S2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\trendm~1\intern~1\TmPfw.exe [2007-11-8 923216]
S2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2007-11-8 36368]
S2 tmproxy;Trend Micro Proxy Service;c:\progra~1\trendm~1\intern~1\tmproxy.exe [2007-11-8 566872]
S3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2007-11-8 280392]

=============== Created Last 30 ================

2010-02-09 16:27 –d—– c:\docume~1\amber\applic~1\Malwarebytes
2010-02-09 16:27 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-09 16:27 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-09 16:27 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-02-09 16:27 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-02-06 08:38 –d—– c:\docume~1\alluse~1\applic~1\MSNDynFiles
2010-01-13 05:28 471,552 ——– c:\windows\system32\dllcache\aclayers.dll

==================== Find3M ====================

2009-12-31 08:50 353,792 a——- c:\windows\system32\drivers\srv.sys
2009-12-31 08:50 353,792 ——– c:\windows\system32\dllcache\srv.sys
2009-12-31 07:33 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe
2009-12-31 07:33 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe
2009-12-18 05:05 634,648 ——– c:\windows\system32\dllcache\iexplore.exe
2009-12-18 05:04 161,792 ——– c:\windows\system32\dllcache\ieakui.dll
2009-12-16 10:43 343,040 a——- c:\windows\system32\mspaint.exe
2009-12-16 10:43 343,040 ——– c:\windows\system32\dllcache\mspaint.exe
2009-12-13 23:08 33,280 a——- c:\windows\system32\csrsrv.dll
2009-12-13 23:08 33,280 ——– c:\windows\system32\dllcache\csrsrv.dll
2009-12-08 01:23 474,112 ——– c:\windows\system32\dllcache\shlwapi.dll
2009-12-04 10:22 455,424 ——– c:\windows\system32\dllcache\mrxsmb.sys
2009-11-27 09:11 1,291,776 a——- c:\windows\system32\quartz.dll
2009-11-27 09:11 17,920 a——- c:\windows\system32\msyuv.dll
2009-11-27 09:11 1,291,776 ——– c:\windows\system32\dllcache\quartz.dll
2009-11-27 09:11 17,920 ——– c:\windows\system32\dllcache\msyuv.dll
2009-11-27 08:07 28,672 a——- c:\windows\system32\msvidc32.dll
2009-11-27 08:07 8,704 a——- c:\windows\system32\tsbyuv.dll
2009-11-27 08:07 28,672 ——– c:\windows\system32\dllcache\msvidc32.dll
2009-11-27 08:07 8,704 ——– c:\windows\system32\dllcache\tsbyuv.dll
2009-11-27 08:07 84,992 a——- c:\windows\system32\avifil32.dll
2009-11-27 08:07 48,128 a——- c:\windows\system32\iyuv_32.dll
2009-11-27 08:07 11,264 a——- c:\windows\system32\msrle32.dll
2009-11-27 08:07 84,992 ——– c:\windows\system32\dllcache\avifil32.dll
2009-11-27 08:07 48,128 ——– c:\windows\system32\dllcache\iyuv_32.dll
2009-11-27 08:07 11,264 ——– c:\windows\system32\dllcache\msrle32.dll
2009-11-21 07:51 471,552 a——- c:\windows\apppatch\aclayers.dll
2008-08-18 19:12 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008081820080819\index.dat

============= FINISH: 17:31:54.06 ===============


VirSCAN program run under my account, Amber, as IE was unable to run under Cookie.

VirSCAN.org Scanned Report :
Scanned time : 2010/02/13 05:58:22 (PST)
Scanner results: 3% Scanner(s) (1/36) found malware!
File Name : userinit.exe
File Size : 26112 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : a93aee1928a9d7ce3e16d24ec7380f89
SHA1 : 513f8bdf67a5a9e09803cfb61f590b39f2683853
Online report : http://virscan.org/report/aff38b9835b3d38f…af5a778a46.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20100213013640 2010-02-13 4.87 -
AhnLab V3 2010.02.14.00 2010.02.14 2010-02-14 1.11 -
AntiVir 8.2.1.170 7.10.4.45 2010-02-12 0.34 -
Antiy 2.0.18 20100213.3845580 2010-02-13 0.12 -
Arcavir 2009 201002101845 2010-02-10 0.03 -
Authentium 5.1.1 201002130803 2010-02-13 1.27 -
AVAST! 4.7.4 100213-0 2010-02-13 0.01 -
AVG 8.5.720 271.1.1/2660 2010-02-01 0.23 -
BitDefender 7.81008.5041831 7.30361 2010-02-13 5.13 -
ClamAV 0.95.3 10388 2010-02-13 0.01 W32.Virut-82
Comodo 3.13.579 3409 2010-02-13 0.92 -
CP Secure 1.3.0.5 2010.02.13 2010-02-13 0.04 -
Dr.Web 5.0.1.12222 2010.02.13 2010-02-13 5.26 -
F-Prot 4.4.4.56 20100212 2010-02-12 1.26 -
F-Secure 7.02.73807 2010.02.13.08 2010-02-13 9.90 -
Fortinet 11.491- 11.491 2010-02-13 0.17 -
GData 19.10480/19.752 20100213 2010-02-13 6.17 -
ViRobot 20100213 2010.02.13 2010-02-13 0.41 -
Ikarus T3.1.01.80 2010.02.13.75184 2010-02-13 4.45 -
JiangMin 13.0.900 2010.02.08 2010-02-08 5.72 -
Kaspersky 5.5.10 2010.02.13 2010-02-13 0.11 -
KingSoft 2009.2.5.15 2010.2.13.7 2010-02-13 0.58 -
McAfee 5.3.00 5890 2010-02-12 3.52 -
Microsoft 1.5406 2010.02.13 2010-02-13 6.72 -
Norman 6.01.09 6.01.00 2010-02-10 4.01 -
Panda 9.05.01 2010.02.12 2010-02-12 2.29 -
Trend Micro 9.120-1004 6.846.05 2010-02-13 0.00 -
Quick Heal 10.00 2010.02.12 2010-02-12 1.39 -
Rising 20.0 22.34.01.03 2010-02-09 1.02 -
Sophos 3.04.1 4.50 2010-02-13 3.21 -
Sunbelt 3.9.2400.2 5675 2010-02-12 2.81 -
Symantec 1.3.0.24 20100211.002 2010-02-11 0.00 -
nProtect 20100213.01 7209349 2010-02-13 4.29 -
The Hacker [removed] v00191 2010-02-13 0.36 -
VBA32 3.12.12.2 20100211.2255 2010-02-11 2.80 -
VirusBuster 4.5.11.10 10.119.53/2013571 2010-02-13 2.34 -
Hi Hi lucella31,

The DDS log was an old one ran in safe mode from the Amber account.

Run by [removed] at 17:31:39.62 on Thu 02/11/2010

I don't like the Clam detection. It may be a false positive but warrants further investigation.

Let's check a few more files.

We need some file informantion
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path, one at a time if more than file is listed, into the "Suspicious files to scan" box on the top of the page:


    c:\windows\system32\svchost.exe
    c:\windows\explorer.exe
    c:\windows\system32\ctfmon.exe
    c:\windows\system32\spoolsv.exe


  • Click on the Upload button
  • Please ensure the scan is complete and the results saved before submitting the next.
  • Ensure ach is clearly identified as to which file the results belong to.
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.
Hello oldman960, Oh, my mistake. I forgot DDS is disposable and is only supposed to be run once, so I probably should have deleted it and downloaded it again, right? I'm going to check the files you requested on VirScan now…. lucella31
I accidentally closed Notepad with the VirScan results from the four files so I must run them again. No malware was detected in all 4 files. In the meantime, I deleted all DDS files and downloaded a new one and ran it. Here are the two logs from the Amber account. Cookie's account still will not let me run DDS with .exe, .bat., .com, or .pif. DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 14:03:16.78 on Mon 02/15/2010 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1013.347 [GMT -8:00] AV: PC-cillin Internet Security - Virus Protection *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5} FW: PC-cillin Internet Security - Firewall *enabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Canon\BJCard\Bjmcmng.exe C:\Program Files\iWin Games\iWinTrusted.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Java\jre6\bin\jucheck.exe C:\WINDOWS\system32\msiexec.exe C:\Documents and Settings\Amber\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uSearch Page = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=0080318 uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us mSearchAssistant = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: ALOT Toolbar: {5aa2ba46-9913-4dc7-9620-69ab0fa17ae7} - c:\program files\alot\bin\alot.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: IEHlprObj Class: {8ca5ed52-f3fb-4414-a105-2e3491156990} - c:\program files\iwin games\iWinGamesHookIE.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll BHO: iWin Toolbar: {ce0c2586-da36-452b-acdb-320d9bcb19bf} - c:\program files\iwin\tbiWi1.dll BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: iWin Toolbar: {ce0c2586-da36-452b-acdb-320d9bcb19bf} - c:\program files\iwin\tbiWi1.dll TB: ALOT Toolbar: {5aa2ba46-9913-4dc7-9620-69ab0fa17ae7} - c:\program files\alot\bin\alot.dll TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1210395665609 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://zone.msn.com/bingame/popcaploader_v10.cab Notify: igfxcui - igfxdev.dll AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\amber\applic~1\mozilla\firefox\profiles\8j2hwweq.default\ FF - component: c:\documents and settings\amber\application data\mozilla\firefox\profiles\8j2hwweq.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R2 datunidr;DellAutomatedPCTuneUp UniDriver;c:\windows\system32\drivers\datunidr.sys [2007-8-23 5376] R2 iWinTrusted;iWinTrusted;c:\program files\iwin games\iWinTrusted.exe [2009-6-4 78104] R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512] R2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\trendm~1\intern~1\Tmntsrv.exe [2007-11-8 345696] R2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\trendm~1\intern~1\TmPfw.exe [2007-11-8 923216] R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2007-11-8 36368] R2 tmproxy;Trend Micro Proxy Service;c:\progra~1\trendm~1\intern~1\tmproxy.exe [2007-11-8 566872] R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2007-11-8 280392] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-15 135664] =============== Created Last 30 ================ 2010-02-14 10:42 –d-h— c:\windows\PIF 2010-02-09 16:27 –d—– c:\docume~1\amber\applic~1\Malwarebytes 2010-02-09 16:27 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-02-09 16:27 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-02-09 16:27 19,160 a——- c:\windows\system32\drivers\mbam.sys 2010-02-09 16:27 –d—– c:\program files\Malwarebytes' Anti-Malware 2010-02-06 08:38 –d—– c:\docume~1\alluse~1\applic~1\MSNDynFiles ==================== Find3M ==================== 2009-12-31 08:50 353,792 a——- c:\windows\system32\drivers\srv.sys 2009-12-31 08:50 353,792 ——– c:\windows\system32\dllcache\srv.sys 2009-12-31 07:33 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe 2009-12-31 07:33 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe 2009-12-18 05:05 634,648 ——– c:\windows\system32\dllcache\iexplore.exe 2009-12-18 05:04 161,792 ——– c:\windows\system32\dllcache\ieakui.dll 2009-12-16 10:43 343,040 a——- c:\windows\system32\mspaint.exe 2009-12-16 10:43 343,040 ——– c:\windows\system32\dllcache\mspaint.exe 2009-12-13 23:08 33,280 a——- c:\windows\system32\csrsrv.dll 2009-12-13 23:08 33,280 ——– c:\windows\system32\dllcache\csrsrv.dll 2009-12-08 01:23 474,112 ——– c:\windows\system32\dllcache\shlwapi.dll 2009-12-04 10:22 455,424 ——– c:\windows\system32\dllcache\mrxsmb.sys 2009-11-27 09:11 1,291,776 a——- c:\windows\system32\quartz.dll 2009-11-27 09:11 17,920 a——- c:\windows\system32\msyuv.dll 2009-11-27 09:11 1,291,776 ——– c:\windows\system32\dllcache\quartz.dll 2009-11-27 09:11 17,920 ——– c:\windows\system32\dllcache\msyuv.dll 2009-11-27 08:07 28,672 a——- c:\windows\system32\msvidc32.dll 2009-11-27 08:07 8,704 a——- c:\windows\system32\tsbyuv.dll 2009-11-27 08:07 28,672 ——– c:\windows\system32\dllcache\msvidc32.dll 2009-11-27 08:07 8,704 ——– c:\windows\system32\dllcache\tsbyuv.dll 2009-11-27 08:07 84,992 a——- c:\windows\system32\avifil32.dll 2009-11-27 08:07 48,128 a——- c:\windows\system32\iyuv_32.dll 2009-11-27 08:07 11,264 a——- c:\windows\system32\msrle32.dll 2009-11-27 08:07 84,992 ——– c:\windows\system32\dllcache\avifil32.dll 2009-11-27 08:07 48,128 ——– c:\windows\system32\dllcache\iyuv_32.dll 2009-11-27 08:07 11,264 ——– c:\windows\system32\dllcache\msrle32.dll 2009-11-21 07:51 471,552 a——- c:\windows\apppatch\aclayers.dll 2009-11-21 07:51 471,552 ——– c:\windows\system32\dllcache\aclayers.dll 2008-08-18 19:12 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008081820080819\index.dat ============= FINISH: 14:03:30.17 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume2 Install Date: 3/22/2008 9:36:48 AM System Uptime: 2/15/2010 12:39:57 PM (2 hours ago) Motherboard: Dell Inc. | | 0RY007 Processor: Intel® Core™2 Duo CPU E4500 @ 2.20GHz | Socket 775 | 2194/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 295 GiB total, 273.763 GiB free. D: is CDROM () E: is Removable F: is Removable G: is Removable H: is Removable I: is Removable ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP307: 11/11/2009 5:38:54 AM - System Checkpoint RP308: 11/12/2009 4:09:02 AM - Software Distribution Service 3.0 RP309: 11/13/2009 1:59:51 PM - System Checkpoint RP310: 11/16/2009 5:40:30 AM - System Checkpoint RP311: 11/17/2009 1:54:05 PM - System Checkpoint RP312: 11/21/2009 10:03:16 AM - System Checkpoint RP313: 11/22/2009 11:16:57 AM - System Checkpoint RP314: 11/24/2009 7:56:55 AM - System Checkpoint RP315: 11/24/2009 7:51:21 AM - System Checkpoint RP316: 11/25/2009 8:32:40 AM - System Checkpoint RP317: 11/25/2009 7:36:01 PM - Software Distribution Service 3.0 RP318: 11/27/2009 6:04:18 AM - System Checkpoint RP319: 11/28/2009 7:45:33 AM - System Checkpoint RP320: 11/29/2009 9:08:03 AM - System Checkpoint RP321: 11/30/2009 9:59:45 AM - System Checkpoint RP322: 12/1/2009 7:50:55 PM - Software Distribution Service 3.0 RP323: 12/3/2009 4:41:40 AM - System Checkpoint RP324: 12/4/2009 6:59:45 AM - System Checkpoint RP325: 12/5/2009 8:06:05 AM - System Checkpoint RP326: 12/7/2009 5:19:11 AM - System Checkpoint RP327: 12/8/2009 5:38:05 AM - System Checkpoint RP328: 12/9/2009 7:09:37 AM - Software Distribution Service 3.0 RP329: 12/10/2009 8:59:15 AM - System Checkpoint RP330: 12/11/2009 9:11:34 AM - System Checkpoint RP331: 12/12/2009 9:33:58 AM - System Checkpoint RP332: 12/13/2009 11:30:55 AM - System Checkpoint RP333: 12/14/2009 11:46:08 AM - System Checkpoint RP334: 12/15/2009 4:46:01 PM - System Checkpoint RP335: 12/16/2009 4:56:39 PM - System Checkpoint RP336: 12/17/2009 6:04:16 PM - System Checkpoint RP337: 12/19/2009 7:10:17 AM - System Checkpoint RP338: 12/19/2009 8:20:05 PM - Software Distribution Service 3.0 RP339: 12/22/2009 6:01:24 AM - System Checkpoint RP340: 12/23/2009 8:00:27 AM - System Checkpoint RP341: 12/24/2009 8:05:56 AM - System Checkpoint RP342: 12/25/2009 10:01:46 AM - System Checkpoint RP343: 12/26/2009 10:24:54 AM - System Checkpoint RP344: 12/29/2009 5:07:11 PM - System Checkpoint RP345: 12/30/2009 5:46:06 PM - System Checkpoint RP346: 1/1/2010 6:37:17 AM - System Checkpoint RP347: 1/2/2010 8:37:09 AM - System Checkpoint RP348: 1/4/2010 5:16:11 AM - System Checkpoint RP349: 1/5/2010 5:34:42 AM - System Checkpoint RP350: 1/6/2010 6:00:50 AM - System Checkpoint RP351: 1/8/2010 4:13:48 AM - System Checkpoint RP352: 1/9/2010 1:19:20 PM - System Checkpoint RP353: 1/11/2010 5:36:08 AM - System Checkpoint RP354: 1/12/2010 6:19:38 AM - System Checkpoint RP355: 1/13/2010 6:47:36 PM - Software Distribution Service 3.0 RP356: 1/16/2010 5:37:08 AM - System Checkpoint RP357: 1/17/2010 6:00:59 AM - System Checkpoint RP358: 1/18/2010 6:02:13 AM - System Checkpoint RP359: 1/19/2010 8:42:41 AM - System Checkpoint RP360: 1/20/2010 1:51:42 PM - System Checkpoint RP361: 1/21/2010 2:29:37 PM - System Checkpoint RP362: 1/22/2010 4:07:42 PM - System Checkpoint RP363: 1/22/2010 7:30:11 PM - Software Distribution Service 3.0 RP364: 1/24/2010 6:10:30 AM - System Checkpoint RP365: 1/26/2010 5:19:31 AM - System Checkpoint RP366: 1/27/2010 5:21:07 AM - System Checkpoint RP367: 1/28/2010 5:27:15 AM - System Checkpoint RP368: 1/29/2010 5:36:03 AM - System Checkpoint RP369: 1/30/2010 5:02:43 PM - System Checkpoint RP370: 2/1/2010 5:00:53 AM - System Checkpoint RP371: 2/2/2010 5:49:01 AM - System Checkpoint RP372: 2/3/2010 8:44:43 AM - System Checkpoint RP373: 2/5/2010 6:01:19 AM - System Checkpoint RP374: 2/6/2010 6:59:44 AM - System Checkpoint RP375: 2/7/2010 8:31:48 AM - System Checkpoint RP376: 2/8/2010 9:29:15 AM - System Checkpoint RP377: 2/10/2010 9:19:37 PM - Software Distribution Service 3.0 RP378: 2/11/2010 5:38:07 PM - Software Distribution Service 3.0 RP379: 2/14/2010 1:13:39 PM - System Checkpoint RP380: 2/15/2010 1:18:55 PM - System Checkpoint ==== Installed Programs ====================== Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742) Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 8.1.2 Adobe Reader 8.1.2 Security Update 1 (KB403742) Adobe Shockwave Player 11.5 Alchemy Deluxe 1.51p ALOT Toolbar Aveyond Lord of Twilight (remove only) Bejeweled Twist 1.0 Browser Address Error Redirector Canon i470D Canon MP Navigator EX 1.0 Canon MX310 series Canon MX310 series User Registration Canon My Printer Canon Utilities Easy-PhotoPrint EX Canon Utilities Solution Menu Compatibility Pack for the 2007 Office system Conexant D850 56K V.9x DFVc Modem Dell Automated PC TuneUp Dell DataSafe Online Dell Driver Reset Tool Dell Support Center Dell System Restore Digital Line Detect DIGOpt DIGReqEx DinerTown Tycoon (remove only) DING! Documentation & Support Launcher Dynomite Deluxe 2.71 Enchanted Fairy Friends Secret of the Fairy Queen (remove only) ERUNT 1.1j Faerie Solitaire (remove only) Games, Music, & Photos Launcher Google Desktop Google Toolbar for Internet Explorer Google Update Helper High Definition Audio Driver Package - KB835221 HijackThis 2.0.2 Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) InstallMgr Intel® Graphics Media Accelerator Driver Intel® PRO Network Connections Drivers Internet Service Offers Launcher iWin Games (remove only) iWin Toolbar J2SE Runtime Environment 5.0 Update 6 Java™ 6 Update 13 Java™ 6 Update 7 Lost in Reefs (remove only) Malwarebytes' Anti-Malware Masque Slots featuring WMS Gaming II Memory Card Utility Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB953297) Microsoft Default Manager Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Office Word Viewer 2003 Microsoft Plus! Digital Media Edition Installer Microsoft Plus! Photo Story 2 LE Microsoft Search Enhancement Pack Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Works Modem Diagnostic Tool Mortimer Beckett And The Secrets Of Spooky Manor Mozilla Firefox (3.5.7) MSN MSN Messenger 6.1 MSN Toolbar MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 6.0 Parser (KB933579) Mystery P.I. - Lost in Los Angeles Mystery PI The Vegas Heist 1.00 NetWaiting Norton Security Scan OGA Notifier 2.0.0048.0 OpenOffice.org 3.0 PowerDVD Presto! PageManager 7.15.16 QualxServ Service Agreement RealArcade Realtek High Definition Audio Driver Roxio Creator Audio Roxio Creator BDAV Plugin Roxio Creator Copy Roxio Creator Data Roxio Creator DE Roxio Creator Tools Roxio Drag-to-Disc Roxio Express Labeler Roxio MyDVD DE Roxio Update Manager ScanSoft OmniPage SE 4 SearchAssist Security Update for CAPICOM (KB931906) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 7 (KB972260) Security Update for Windows Internet Explorer 7 (KB974455) Security Update for Windows Internet Explorer 7 (KB976325) Security Update for Windows Internet Explorer 7 (KB978207) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978706) Sonic Activation Module Stellarium 0.10.1 Trend Micro PC-cillin Internet Security 14 Update for Windows Internet Explorer 7 (KB976749) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) VLC media player 1.0.1 WebFldrs XP Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Media Format Runtime Windows Media Player 10 Windows XP Service Pack 3 WinRAR archiver ==== Event Viewer Messages From Past Week ======== 2/9/2010 6:05:47 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 2/9/2010 6:00:09 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 2/9/2010 5:56:17 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Fips intelppm tmtdi 2/9/2010 5:56:17 PM, error: Service Control Manager [7001] - The Trend Micro Proxy Service service depends on the Trend Micro TDI Driver service which failed to start because of the following error: A device attached to the system is not functioning. 2/9/2010 5:49:48 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip tmtdi 2/9/2010 5:49:48 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. 2/9/2010 5:49:48 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 2/9/2010 5:49:48 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 2/9/2010 5:49:48 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 2/9/2010 5:48:52 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 2/10/2010 9:15:36 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: iaStor 2/10/2010 9:15:31 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume. ==== End Of File ===========================
Here are the VirScan results from the 4 files!

VirSCAN.org Scanned Report :
Scanned time : 2010/02/11 23:07:00 (PST)
Scanner results: Scanners did not find malware!
File Name : svchost.exe
File Size : 14336 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 27c6d03bcdb8cfeb96b716f3d8be3e18
SHA1 : 49083ae3725a0488e0a8fbbe1335c745f70c4667
Online report : http://virscan.org/report/c9d67cd4c83d5ccc…0dc0874462.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20100212010812 2010-02-12 34.73 -
AhnLab V3 2010.02.12.04 2010.02.12 2010-02-12 2.71 -
AntiVir 8.2.1.160 7.10.4.41 2010-02-11 0.37 -
Antiy 2.0.18 20100212.3842788 2010-02-12 0.12 -
Arcavir 2009 201002101845 2010-02-10 0.03 -
Authentium 5.1.1 201002120142 2010-02-12 1.27 -
AVAST! 4.7.4 100211-1 2010-02-11 0.00 -
AVG 8.5.720 271.1.1/2660 2010-02-01 0.22 -
BitDefender 7.81008.5035152 7.30339 2010-02-12 5.15 -
ClamAV 0.95.3 10384 2010-02-12 0.01 -
Comodo 3.13.579 3409 2010-02-12 0.91 -
CP Secure 1.3.0.5 2010.02.11 2010-02-11 0.04 -
Dr.Web 5.0.1.12222 2010.02.12 2010-02-12 5.38 -
F-Prot 4.4.4.56 20100212 2010-02-12 1.25 -
F-Secure 7.02.73807 2010.02.12.02 2010-02-12 9.81 -
Fortinet 11.487- 11.487 2010-02-11 0.59 -
GData 19.10459/19.745 20100212 2010-02-12 10.24 -
ViRobot 20100212 2010.02.12 2010-02-12 0.66 -
Ikarus T3.1.01.80 2010.02.12.75171 2010-02-12 4.69 -
JiangMin 13.0.900 2010.02.08 2010-02-08 40.12 -
Kaspersky 5.5.10 2010.02.12 2010-02-12 0.07 -
KingSoft 2009.2.5.15 2010.2.12.7 2010-02-12 0.62 -
McAfee 5.3.00 5889 2010-02-11 3.57 -
Microsoft 1.5406 2010.02.12 2010-02-12 7.05 -
Norman 6.01.09 6.01.00 2010-02-10 2.01 -
Panda 9.05.01 2010.02.09 2010-02-09 13.91 -
Trend Micro 9.120-1004 6.844.02 2010-02-11 0.03 -
Quick Heal 10.00 2010.02.11 2010-02-11 1.39 -
Rising 20.0 22.34.01.03 2010-02-09 1.41 -
Sophos 3.04.1 4.50 2010-02-12 3.65 -
Sunbelt 3.9.2398.2 5671 2010-02-11 4.93 -
Symantec 1.3.0.24 20100211.002 2010-02-11 0.00 -
nProtect 20100212.03 7203210 2010-02-12 16.73 -
The Hacker [removed] v00190 2010-02-11 3.27 -
VBA32 3.12.12.2 20100210.2233 2010-02-10 2.59 -
VirusBuster 4.5.11.10 10.119.51/2011380 2010-02-11 2.35 -


********************************************************

VirSCAN.org Scanned Report :
Scanned time : 2010/02/11 13:57:38 (PST)
Scanner results: Scanners did not find malware!
File Name : explorer.exe
File Size : 1033728 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 12896823fb95bfb3dc9b46bcaedc9923
SHA1 : 9d2bf84874abc5b6e9a2744b7865c193c08d362f
Online report : http://virscan.org/report/ee4fe7f8042b5787…ca53b9bd27.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20100212010812 2010-02-12 4.21 -
AhnLab V3 2010.02.12.00 2010.02.12 2010-02-12 1.03 -
AntiVir 8.2.1.160 7.10.4.41 2010-02-11 0.24 -
Antiy 2.0.18 20100211.3837291 2010-02-11 0.12 -
Arcavir 2009 201002101845 2010-02-10 0.07 -
Authentium 5.1.1 201002112035 2010-02-11 2.27 -
AVAST! 4.7.4 100211-0 2010-02-11 0.05 -
AVG 8.5.720 271.1.1/2660 2010-02-01 0.22 -
BitDefender 7.81008.5035082 7.30333 2010-02-12 5.09 -
ClamAV 0.95.3 10380 2010-02-11 0.17 -
Comodo 3.13.579 3409 2010-02-11 0.90 -
CP Secure 1.3.0.5 2010.02.11 2010-02-11 0.11 -
Dr.Web 5.0.1.12222 2010.02.12 2010-02-12 5.44 -
F-Prot 4.4.4.56 20100211 2010-02-11 2.19 -
F-Secure 7.02.73807 2010.02.11.11 2010-02-11 9.67 -
Fortinet 11.485- 11.485 2010-02-11 0.24 -
GData 19.10448/19.744 20100211 2010-02-11 5.93 -
ViRobot 20100211 2010.02.11 2010-02-11 0.41 -
Ikarus T3.1.01.80 2010.02.11.75166 2010-02-11 4.46 -
JiangMin 13.0.900 2010.02.08 2010-02-08 4.67 -
Kaspersky 5.5.10 2010.02.11 2010-02-11 0.07 -
KingSoft 2009.2.5.15 2010.2.11.7 2010-02-11 0.54 -
McAfee 5.3.00 5889 2010-02-11 3.55 -
Microsoft 1.5406 2010.02.11 2010-02-11 6.52 -
Norman 6.01.09 6.01.00 2010-02-10 4.01 -
Panda 9.05.01 2010.02.09 2010-02-09 2.07 -
Trend Micro 9.120-1004 6.842.04 2010-02-11 0.04 -
Quick Heal 10.00 2010.02.11 2010-02-11 1.60 -
Rising 20.0 22.34.01.03 2010-02-09 1.01 -
Sophos 3.04.1 4.50 2010-02-12 3.19 -
Sunbelt 3.9.2398.2 5671 2010-02-11 2.61 -
Symantec 1.3.0.24 20100211.002 2010-02-11 0.08 -
nProtect 20100212.01 7200620 2010-02-12 4.31 -
The Hacker [removed] v00189 2010-02-11 0.39 -
VBA32 3.12.12.2 20100210.2233 2010-02-10 2.63 -
VirusBuster 4.5.11.10 10.119.51/2011380 2010-02-11 2.65 -


********************************************************

VirSCAN.org Scanned Report :
Scanned time : 2010/02/09 03:23:25 (PST)
Scanner results: Scanners did not find malware!
File Name : ctfmon.exe
File Size : 15360 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 5f1d5f88303d4a4dbc8e5f97ba967cc3
SHA1 : 99cb7370f16773c8e2d0c86fe805ec638ab126e9
Online report : http://virscan.org/report/27118c0dec677acc…137cf734bb.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20100209060126 2010-02-09 4.84 -
AhnLab V3 2010.02.08.00 2010.02.08 2010-02-08 1.10 -
AntiVir 8.2.1.160 7.10.3.255 2010-02-09 0.52 -
Antiy 2.0.18 20100201.3785967 2010-02-01 0.02 -
Arcavir 2009 201002082340 2010-02-08 0.03 -
Authentium 5.1.1 201002090722 2010-02-09 1.29 -
AVAST! 4.7.4 100208-2 2010-02-08 0.01 -
AVG 8.5.720 271.1.1/2660 2010-02-01 5.18 -
BitDefender 7.81008.5034635 7.30298 2010-02-09 5.18 -
ClamAV 0.95.3 10368 2010-02-09 0.01 -
Comodo 3.13.579 3409 2010-02-09 0.92 -
CP Secure 1.3.0.5 2010.02.09 2010-02-09 0.04 -
Dr.Web 5.0.1.12222 2010.02.09 2010-02-09 5.36 -
F-Prot 4.4.4.56 20100208 2010-02-08 1.30 -
F-Secure 7.02.73807 2010.02.09.03 2010-02-09 0.15 -
Fortinet 11.475- 11.475 2010-02-09 0.24 -
GData 19.10404/19.740 20100209 2010-02-09 7.67 -
ViRobot 20100208 2010.02.08 2010-02-08 0.68 -
Ikarus T3.1.01.80 2010.02.09.75144 2010-02-09 4.48 -
JiangMin 13.0.900 2010.02.08 2010-02-08 9.30 -
Kaspersky 5.5.10 2010.02.09 2010-02-09 0.12 -
KingSoft 2009.2.5.15 2010.2.9.15 2010-02-09 0.56 -
McAfee 5.3.00 5886 2010-02-08 3.74 -
Microsoft 1.5406 2010.02.09 2010-02-09 7.05 -
Norman 6.01.09 6.01.00 2010-02-08 8.01 -
Panda 9.05.01 2010.02.08 2010-02-08 2.10 -
Trend Micro 9.120-1004 6.836.05 2010-02-09 0.03 -
Quick Heal 10.00 2010.02.09 2010-02-09 1.35 -
Rising 20.0 22.34.01.01 2010-02-09 1.27 -
Sophos 3.04.1 4.50 2010-02-09 3.13 -
Sunbelt 3.9.2398.2 5666 2010-02-08 3.03 -
Symantec 1.3.0.24 20100201.009 2010-02-01 0.00 -
nProtect 20100207.01 7182772 2010-02-07 4.71 -
The Hacker [removed] v00185 2010-02-09 0.41 -
VBA32 3.12.12.1 20100207.2056 2010-02-07 2.69 -
VirusBuster 4.5.11.10 10.119.45/2024198 2010-02-08 2.39 -

********************************************************

VirSCAN.org Scanned Report :
Scanned time : 2010/02/04 01:43:17 (PST)
Scanner results: Scanners did not find malware!
File Name : spoolsv.exe
File Size : 57856 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : d8e14a61acc1d4a6cd0d38aebac7fa3b
SHA1 : 0e5d1a09a103eae3bd693c7a1c7531fde2e2402b
Online report : http://virscan.org/report/4a7dbbdac216c441…3c989bc73e.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20100204033159 2010-02-04 8.30 -
AhnLab V3 2010.02.04.01 2010.02.04 2010-02-04 1.39 -
AntiVir 8.2.1.158 7.10.3.193 2010-02-04 0.07 -
Antiy 2.0.18 20100201.3785967 2010-02-01 0.02 -
Arcavir 2009 201002031750 2010-02-03 0.04 -
Authentium 5.1.1 201002040129 2010-02-04 1.28 -
AVAST! 4.7.4 100204-0 2010-02-04 0.01 -
AVG 8.5.720 271.1.1/2660 2010-02-01 0.23 -
BitDefender 7.81008.5009158 7.30208 2010-02-04 5.12 -
ClamAV 0.95.3 10352 2010-02-03 0.02 -
Comodo 3.13.579 3409 2010-02-04 0.90 -
CP Secure 1.3.0.5 2010.02.04 2010-02-04 0.10 -
Dr.Web 5.0.1.12222 2010.02.04 2010-02-04 5.17 -
F-Prot 4.4.4.56 20100204 2010-02-04 1.25 -
F-Secure 7.02.73807 2010.02.04.08 2010-02-04 0.15 -
Fortinet 11.455- 11.455 2010-02-03 1.27 -
GData 19.10289/19.725 20100204 2010-02-04 7.87 -
ViRobot 20100203 2010.02.03 2010-02-03 3.55 -
Ikarus T3.1.01.80 2010.02.04.75112 2010-02-04 5.71 -
JiangMin 13.0.900 2010.02.04 2010-02-04 14.32 -
Kaspersky 5.5.10 2010.02.04 2010-02-04 0.07 -
KingSoft 2009.2.5.15 2010.2.4.16 2010-02-04 0.91 -
McAfee 5.3.00 5881 2010-02-03 3.49 -
Microsoft 1.5406 2010.02.04 2010-02-04 12.62 -
Norman 6.01.09 6.01.00 2010-01-16 4.00 -
Panda 9.05.01 2010.02.03 2010-02-03 8.94 -
Trend Micro 9.120-1004 6.822.02 2010-02-03 0.04 -
Quick Heal 10.00 2010.02.04 2010-02-04 1.35 -
Rising 20.0 22.33.03.04 2010-02-04 0.58 -
Sophos 3.04.1 4.50 2010-02-04 3.00 -
Sunbelt 3.9.2398.2 5655 2010-02-03 5.28 -
Symantec 1.3.0.24 20100201.009 2010-02-01 0.03 -
nProtect 20100203.01 7137481 2010-02-03 8.54 -
The Hacker [removed] v00180 2010-02-04 0.83 -
VBA32 3.12.12.1 20100202.2221 2010-02-02 3.54 -
VirusBuster 4.5.11.10 10.119.37/2027780 2010-02-04 3.64 -
Hi lucella31,

Under Cookie's account, I was able to change the DDS extension to .bat and open it, but I did not get two reports (Attach and DDS).

I thought you were successful in running it but posted the wrong log.

The VirScan results would seem to indicate the the lone detection on userinit.exe
was a false positive.

When you started to clean this computer, did you use the Amber account?
Hello oldman960, Yes, when I started to clean this computer using SAFE MODE, I was in my account (Amber) because I thought it didn't matter which account I was in. I just clicked on the first name in the list. I figured whatever's wrong would infect all accounts. Each time you've told me to run something in normal mode, I try to run it on my mother's account, but now it seems only hers is infected. I can use mine to surf the internet, and I even launched and played a game from the desktop last night. As for the DDS report, yes, I was able to change the extension to .bat on my mother's account and run it, but I think that ended up being a copy of the old DDS program/report from my account because a previous message from you stated that I had sent you a report dated 2/11. What should I do now? Is there anything I should try to do in SAFE MODE under Cookie's account? I have always used mine in this mode. Thanks for all your patience and time thus far. :thumbup:
UPDATE: In Cookie's account in SAFE MODE, all .exe programs still cannot be run directly when clicked on. However, when the pop-up window opens and asks which program I want to use to open it, I manually searched for the HiJackThis program, clicked on it, clicked Open, and I was able to run HJT and save a log from it. It seems I might be able to do this for other programs hopefully. I tried DDS again, in SAFE MODE, with the same procedure I just outlined, but it still wouldn't open, even when changing the extension. I notice that DDS is run in the CMD screen, so maybe that's the problem? I am running a quick scan in MBAM now under Cookie's account in normal mode (by manually choosing the program), the first time I have done so, and so far it has detected an infected object. I go to work soon, and I know that the rule is to NOT post any log unless asked, but I will post the MBAM log if I don't hear from you in the next hour, so that you will have something to work with if you do get the chance to look at it. ….MBAM finished and found 3 infections. I will wait and check back throughout the next hour to see if you've replied. Thanks oldman960!
Hello oldman960,

GOOD NEWS! :woot:

The computer in my mother's account is working FINE!
After running MBAM, deleting the 3 infections, and restarting the computer, the desktop icons are working again. All the system tray icons have been restored, and I finally was able to run DDS without changing the extension!

I am posting the MBAM log and the two DDS logs which are from my mother's account in normal mode.
Right now my mother is checking her e-mail (in which she clicks on the MSN butterfly icon on her desktop, not IE or FIrefox) because I just want to test it and see if she runs into any other problems. So far so good! After using her email account, I told her to shut down completely as I will wait to hear from you.
I'm hoping we are very close to the ALL CLEAN! :D

MBAM Log:

Malwarebytes' Anti-Malware 1.44
Database version: 3723
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

2/16/2010 5:51:39 AM
mbam-log-2010-02-16 (05-51-39).txt

Scan type: Quick Scan
Objects scanned: 131994
Time elapsed: 4 minute(s), 7 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\secfile (Trojan.Fakealert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CLASSES_ROOT\.exe\(default) (Hijacked.exeFile) -> Bad: (secfile) Good: (exefile) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

*******************************************************************

DDS Log:


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 5:55:46.96 on Tue 02/16/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1013.366 [GMT -8:00]

AV: PC-cillin Internet Security - Virus Protection *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: PC-cillin Internet Security - Firewall *enabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Southwest Airlines\Ding\Ding.exe
svchost.exe
C:\Program Files\Canon\BJCard\Bjmcmng.exe
C:\Program Files\iWin Games\iWinTrusted.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\Program Files\MSN\MSNCoreFiles\msn.exe
C:\Documents and Settings\Cookie\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://home.alot.com/?client_id=3B798D1001C9B861005A7559&install;_time=08-04-2009:08:47&src;_id=11076&camp;_id=14&tb;_version=2.4.2.399
uSearch Page = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
uDefault_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=0080318
uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=0080318
uInternet Settings,ProxyServer = http=
mSearchAssistant = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
uURLSearchHooks: iWin Toolbar: {ce0c2586-da36-452b-acdb-320d9bcb19bf} - c:\program files\iwin\tbiWi1.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: ALOT Toolbar: {5aa2ba46-9913-4dc7-9620-69ab0fa17ae7} - c:\program files\alot\bin\alot.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: IEHlprObj Class: {8ca5ed52-f3fb-4414-a105-2e3491156990} - c:\program files\iwin games\iWinGamesHookIE.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: iWin Toolbar: {ce0c2586-da36-452b-acdb-320d9bcb19bf} - c:\program files\iwin\tbiWi1.dll
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: iWin Toolbar: {ce0c2586-da36-452b-acdb-320d9bcb19bf} - c:\program files\iwin\tbiWi1.dll
TB: ALOT Toolbar: {5aa2ba46-9913-4dc7-9620-69ab0fa17ae7} - c:\program files\alot\bin\alot.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
uRun: [OE_OEM] "c:\program files\trend micro\internet security 14\tmas_oe\TMAS_OEMon.exe"
uRun: [DellAutomatedPCTuneUp] "c:\program files\dellautomatedpctuneup\PTAgnt.exe" /startup
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background
uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockwave 11\SwHelper_1150596.exe -Update -1150596 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; GTB6; .NET CLR 1.1.4322; MSN 9.0;MSN 9.1;MSN 9.6; MSNbMSNI; MSNmen-us; MSNcOTH)" -"http://www.freeworldgroup.com/games3/vines/index.html"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\cookie\startm~1\programs\startup\ding!.lnk - c:\program files\southwest airlines\ding\Ding.exe
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1210395665609
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://zone.msn.com/bingame/popcaploader_v10.cab
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\cookie\applic~1\mozilla\firefox\profiles\l6l76x0t.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=SOLTDF&q;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=SOLTDF&q;=
FF - component: c:\documents and settings\cookie\application data\mozilla\firefox\profiles\l6l76x0t.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R2 datunidr;DellAutomatedPCTuneUp UniDriver;c:\windows\system32\drivers\datunidr.sys [2007-8-23 5376]
R2 iWinTrusted;iWinTrusted;c:\program files\iwin games\iWinTrusted.exe [2009-6-4 78104]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512]
R2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\trendm~1\intern~1\Tmntsrv.exe [2007-11-8 345696]
R2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\trendm~1\intern~1\TmPfw.exe [2007-11-8 923216]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2007-11-8 36368]
R2 tmproxy;Trend Micro Proxy Service;c:\progra~1\trendm~1\intern~1\tmproxy.exe [2007-11-8 566872]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2007-11-8 280392]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-15 135664]

=============== Created Last 30 ================

2010-02-16 05:24 –d—– c:\docume~1\cookie\applic~1\Malwarebytes
2010-02-14 10:42 –d-h— c:\windows\PIF
2010-02-09 16:27 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-09 16:27 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-09 16:27 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-02-09 16:27 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-02-06 08:38 –d—– c:\docume~1\alluse~1\applic~1\MSNDynFiles

==================== Find3M ====================

2010-02-09 11:46 5,970 a——- c:\docume~1\cookie\applic~1\wklnhst.dat
2009-12-31 08:50 353,792 a——- c:\windows\system32\drivers\srv.sys
2009-12-31 08:50 353,792 ——– c:\windows\system32\dllcache\srv.sys
2009-12-31 07:33 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe
2009-12-31 07:33 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe
2009-12-18 05:05 634,648 ——– c:\windows\system32\dllcache\iexplore.exe
2009-12-18 05:04 161,792 ——– c:\windows\system32\dllcache\ieakui.dll
2009-12-16 10:43 343,040 a——- c:\windows\system32\mspaint.exe
2009-12-16 10:43 343,040 ——– c:\windows\system32\dllcache\mspaint.exe
2009-12-13 23:08 33,280 a——- c:\windows\system32\csrsrv.dll
2009-12-13 23:08 33,280 ——– c:\windows\system32\dllcache\csrsrv.dll
2009-12-08 01:23 474,112 ——– c:\windows\system32\dllcache\shlwapi.dll
2009-12-04 10:22 455,424 ——– c:\windows\system32\dllcache\mrxsmb.sys
2009-11-27 09:11 1,291,776 a——- c:\windows\system32\quartz.dll
2009-11-27 09:11 17,920 a——- c:\windows\system32\msyuv.dll
2009-11-27 09:11 1,291,776 ——– c:\windows\system32\dllcache\quartz.dll
2009-11-27 09:11 17,920 ——– c:\windows\system32\dllcache\msyuv.dll
2009-11-27 08:07 28,672 a——- c:\windows\system32\msvidc32.dll
2009-11-27 08:07 8,704 a——- c:\windows\system32\tsbyuv.dll
2009-11-27 08:07 28,672 ——– c:\windows\system32\dllcache\msvidc32.dll
2009-11-27 08:07 8,704 ——– c:\windows\system32\dllcache\tsbyuv.dll
2009-11-27 08:07 84,992 a——- c:\windows\system32\avifil32.dll
2009-11-27 08:07 48,128 a——- c:\windows\system32\iyuv_32.dll
2009-11-27 08:07 11,264 a——- c:\windows\system32\msrle32.dll
2009-11-27 08:07 84,992 ——– c:\windows\system32\dllcache\avifil32.dll
2009-11-27 08:07 48,128 ——– c:\windows\system32\dllcache\iyuv_32.dll
2009-11-27 08:07 11,264 ——– c:\windows\system32\dllcache\msrle32.dll
2009-11-21 07:51 471,552 a——- c:\windows\apppatch\aclayers.dll
2009-11-21 07:51 471,552 ——– c:\windows\system32\dllcache\aclayers.dll
2008-08-18 19:12 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008081820080819\index.dat

============= FINISH: 5:56:44.53 ===============


ATTACH log:


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 3/22/2008 9:36:48 AM
System Uptime: 2/16/2010 5:53:20 AM (0 hours ago)

Motherboard: Dell Inc. | | 0RY007
Processor: Intel® Core™2 Duo CPU E4500 @ 2.20GHz | Socket 775 | 1184/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 295 GiB total, 273.832 GiB free.
D: is CDROM ()
E: is Removable
F: is Removable
G: is Removable
H: is Removable
I: is Removable

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP307: 11/11/2009 5:38:54 AM - System Checkpoint
RP308: 11/12/2009 4:09:02 AM - Software Distribution Service 3.0
RP309: 11/13/2009 1:59:51 PM - System Checkpoint
RP310: 11/16/2009 5:40:30 AM - System Checkpoint
RP311: 11/17/2009 1:54:05 PM - System Checkpoint
RP312: 11/21/2009 10:03:16 AM - System Checkpoint
RP313: 11/22/2009 11:16:57 AM - System Checkpoint
RP314: 11/24/2009 7:56:55 AM - System Checkpoint
RP315: 11/24/2009 7:51:21 AM - System Checkpoint
RP316: 11/25/2009 8:32:40 AM - System Checkpoint
RP317: 11/25/2009 7:36:01 PM - Software Distribution Service 3.0
RP318: 11/27/2009 6:04:18 AM - System Checkpoint
RP319: 11/28/2009 7:45:33 AM - System Checkpoint
RP320: 11/29/2009 9:08:03 AM - System Checkpoint
RP321: 11/30/2009 9:59:45 AM - System Checkpoint
RP322: 12/1/2009 7:50:55 PM - Software Distribution Service 3.0
RP323: 12/3/2009 4:41:40 AM - System Checkpoint
RP324: 12/4/2009 6:59:45 AM - System Checkpoint
RP325: 12/5/2009 8:06:05 AM - System Checkpoint
RP326: 12/7/2009 5:19:11 AM - System Checkpoint
RP327: 12/8/2009 5:38:05 AM - System Checkpoint
RP328: 12/9/2009 7:09:37 AM - Software Distribution Service 3.0
RP329: 12/10/2009 8:59:15 AM - System Checkpoint
RP330: 12/11/2009 9:11:34 AM - System Checkpoint
RP331: 12/12/2009 9:33:58 AM - System Checkpoint
RP332: 12/13/2009 11:30:55 AM - System Checkpoint
RP333: 12/14/2009 11:46:08 AM - System Checkpoint
RP334: 12/15/2009 4:46:01 PM - System Checkpoint
RP335: 12/16/2009 4:56:39 PM - System Checkpoint
RP336: 12/17/2009 6:04:16 PM - System Checkpoint
RP337: 12/19/2009 7:10:17 AM - System Checkpoint
RP338: 12/19/2009 8:20:05 PM - Software Distribution Service 3.0
RP339: 12/22/2009 6:01:24 AM - System Checkpoint
RP340: 12/23/2009 8:00:27 AM - System Checkpoint
RP341: 12/24/2009 8:05:56 AM - System Checkpoint
RP342: 12/25/2009 10:01:46 AM - System Checkpoint
RP343: 12/26/2009 10:24:54 AM - System Checkpoint
RP344: 12/29/2009 5:07:11 PM - System Checkpoint
RP345: 12/30/2009 5:46:06 PM - System Checkpoint
RP346: 1/1/2010 6:37:17 AM - System Checkpoint
RP347: 1/2/2010 8:37:09 AM - System Checkpoint
RP348: 1/4/2010 5:16:11 AM - System Checkpoint
RP349: 1/5/2010 5:34:42 AM - System Checkpoint
RP350: 1/6/2010 6:00:50 AM - System Checkpoint
RP351: 1/8/2010 4:13:48 AM - System Checkpoint
RP352: 1/9/2010 1:19:20 PM - System Checkpoint
RP353: 1/11/2010 5:36:08 AM - System Checkpoint
RP354: 1/12/2010 6:19:38 AM - System Checkpoint
RP355: 1/13/2010 6:47:36 PM - Software Distribution Service 3.0
RP356: 1/16/2010 5:37:08 AM - System Checkpoint
RP357: 1/17/2010 6:00:59 AM - System Checkpoint
RP358: 1/18/2010 6:02:13 AM - System Checkpoint
RP359: 1/19/2010 8:42:41 AM - System Checkpoint
RP360: 1/20/2010 1:51:42 PM - System Checkpoint
RP361: 1/21/2010 2:29:37 PM - System Checkpoint
RP362: 1/22/2010 4:07:42 PM - System Checkpoint
RP363: 1/22/2010 7:30:11 PM - Software Distribution Service 3.0
RP364: 1/24/2010 6:10:30 AM - System Checkpoint
RP365: 1/26/2010 5:19:31 AM - System Checkpoint
RP366: 1/27/2010 5:21:07 AM - System Checkpoint
RP367: 1/28/2010 5:27:15 AM - System Checkpoint
RP368: 1/29/2010 5:36:03 AM - System Checkpoint
RP369: 1/30/2010 5:02:43 PM - System Checkpoint
RP370: 2/1/2010 5:00:53 AM - System Checkpoint
RP371: 2/2/2010 5:49:01 AM - System Checkpoint
RP372: 2/3/2010 8:44:43 AM - System Checkpoint
RP373: 2/5/2010 6:01:19 AM - System Checkpoint
RP374: 2/6/2010 6:59:44 AM - System Checkpoint
RP375: 2/7/2010 8:31:48 AM - System Checkpoint
RP376: 2/8/2010 9:29:15 AM - System Checkpoint
RP377: 2/10/2010 9:19:37 PM - Software Distribution Service 3.0
RP378: 2/11/2010 5:38:07 PM - Software Distribution Service 3.0
RP379: 2/14/2010 1:13:39 PM - System Checkpoint
RP380: 2/15/2010 1:18:55 PM - System Checkpoint

==== Installed Programs ======================

Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.1.2
Adobe Reader 8.1.2 Security Update 1 (KB403742)
Adobe Shockwave Player 11.5
Alchemy Deluxe 1.51p
ALOT Toolbar
Aveyond Lord of Twilight (remove only)
Bejeweled Twist 1.0
Browser Address Error Redirector
Canon i470D
Canon MP Navigator EX 1.0
Canon MX310 series
Canon MX310 series User Registration
Canon My Printer
Canon Utilities Easy-PhotoPrint EX
Canon Utilities Solution Menu
Compatibility Pack for the 2007 Office system
Conexant D850 56K V.9x DFVc Modem
Dell Automated PC TuneUp
Dell DataSafe Online
Dell Driver Reset Tool
Dell Support Center
Dell System Restore
Digital Line Detect
DIGOpt
DIGReqEx
DinerTown Tycoon (remove only)
DING!
Documentation & Support Launcher
Dynomite Deluxe 2.71
Enchanted Fairy Friends Secret of the Fairy Queen (remove only)
ERUNT 1.1j
Faerie Solitaire (remove only)
Games, Music, & Photos Launcher
Google Desktop
Google Toolbar for Internet Explorer
Google Update Helper
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
InstallMgr
Intel® Graphics Media Accelerator Driver
Intel® PRO Network Connections Drivers
Internet Service Offers Launcher
iWin Games (remove only)
iWin Toolbar
J2SE Runtime Environment 5.0 Update 6
Java™ 6 Update 13
Java™ 6 Update 7
Lost in Reefs (remove only)
Malwarebytes' Anti-Malware
Masque Slots featuring WMS Gaming II
Memory Card Utility
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft Default Manager
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Word Viewer 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Search Enhancement Pack
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Modem Diagnostic Tool
Mortimer Beckett And The Secrets Of Spooky Manor
Mozilla Firefox (3.5.7)
MSN
MSN Messenger 6.1
MSN Toolbar
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6.0 Parser (KB933579)
Mystery P.I. - Lost in Los Angeles
Mystery PI The Vegas Heist 1.00
NetWaiting
Norton Security Scan
OGA Notifier 2.0.0048.0
OpenOffice.org 3.0
PowerDVD
Presto! PageManager 7.15.16
QualxServ Service Agreement
RealArcade
Realtek High Definition Audio Driver
Roxio Creator Audio
Roxio Creator BDAV Plugin
Roxio Creator Copy
Roxio Creator Data
Roxio Creator DE
Roxio Creator Tools
Roxio Drag-to-Disc
Roxio Express Labeler
Roxio MyDVD DE
Roxio Update Manager
ScanSoft OmniPage SE 4
SearchAssist
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978706)
Sonic Activation Module
Stellarium 0.10.1
Trend Micro PC-cillin Internet Security 14
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VLC media player 1.0.1
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player 10
Windows XP Service Pack 3
WinRAR archiver

==== Event Viewer Messages From Past Week ========

2/9/2010 5:49:48 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip tmtdi
2/9/2010 5:49:48 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
2/9/2010 5:49:48 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/9/2010 5:49:48 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/9/2010 5:49:48 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
2/9/2010 5:48:52 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
2/10/2010 9:15:36 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: iaStor
2/10/2010 9:15:31 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume.
2/10/2010 9:14:35 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
2/10/2010 7:46:31 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
2/10/2010 6:53:44 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Fips intelppm tmtdi
2/10/2010 6:53:44 PM, error: Service Control Manager [7001] - The Trend Micro Proxy Service service depends on the Trend Micro TDI Driver service which failed to start because of the following error: A device attached to the system is not functioning.

==== End Of File ===========================
Hi lucella31

Good news.

This crud usually travels with friends. We'll work from your mother's account. Are you experiencing any browser or search redirects?


Delete the copy of GMER you have
Go HERE to get a new randomly named copy.

Scroll down to the Download section and click Download EXE. Save it to your desktop.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Double click on the file you downloaded. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER will not run in normal windows, please run it in safe mode. B sure to use the cookie account.

Please post the GMER log.
Hello oldman960, I heard from my mother and she said everything worked fine while in her email. She was sending/receiving emails with no problem for about 3 hours. I did not ask her to do anything else but check her email, so I am not sure about any browser redirects. I will check that when I get home, but I prefer to use Firefox instead of IE, which is what I'm gonna have her use from this point forward. I will log in to this site and download GMER and perform the requested actions and then post the log for you. Probably will be in about 4 hours or so. B) Thanks oldman960! :banana2:
Hello oldman960, I'm having trouble with GMER. :( First time I ran it (under the Cookie account), walked away from it for about 15 min, came back and appeared to be frozen as a blue screen appeared (no, not a BSOD). Shut off PC, restarted, logged in under Cookie, and downloaded a new GMER file and ran it. Ran for about 1 1/2 hours. Been in front of the computer the whole time to check if it finished. Appeared to finish when no more files were seen at the bottom of the screen, but there was nothing to prompt me that is was done and asking what I'd like to do. I was torn between the OK and SAVE buttons, so I clicked SAVE in order to not lose the report. Nothing happened. Computer froze. Opened Task Manager and the CPU Usage was at 100% and showed GMER as Not Responding. I had nothing else open but the GMER window. Tried to end two processes (SeaPort - may be a game, and explorer) to lower the CPU usage, but didn't help. What kind of prompt or "ending" should I look for when GMER is finished scanning? I will scan again, but will have to wait until late tonight when I return from school. Or unless you request otherwise… Thanks. :wacko:
Hi lucella31,

The browser redirect could happen with either Internet Explorer of FireFox.

GMER doesn't seem to want to run. Let's do this instead. Please use the cookie account.

Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custon Scans/Fixes, copy and paste the following bold text


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Next

Please download MBR.exe and save it to your desktop

Next

Click your start button, click run. Copy and paste the following line into the run box (including the " " marks)and click ok


"%userprofile%\desktop\mbr.exe" -t>"%userprofile%\Desktop\mbr.txt"


A notepad named mbr.log should appear on your desktop. Please post it's contents.

Please post back with
  • Both OTL logs
  • mbr.log
Thanks
Hello oldman960,

Thank goodness there are alternative programs! ^_^

I successfully ran the MBR and OTL programs.
Here are the MBR and the OTL Logfile (1 of 2 files).
Due to its length and to make it easier for reading, the OTL Extras Logfile is posted in the next reply following this one.

MBR Log:

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK

********************************************************************************
************************************************

OTL Logfile

OTL logfile created on: 2/17/2010 5:40:10 AM - Run 1
OTL by OldTimer - Version 3.1.28.0 Folder = C:\Documents and Settings\Cookie\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,013.00 Mb Total Physical Memory | 629.00 Mb Available Physical Memory | 62.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 294.73 Gb Total Space | 273.72 Gb Free Space | 92.87% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 3.72 Gb Total Space | 1.38 Gb Free Space | 36.98% Space Free | Partition Type: FAT32

Computer Name: MAMASPC
Current User Name: Cookie
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Cookie\Desktop\erunt_setup DLd as OTL.exe (OldTimer Tools)
PRC - C:\Program Files\iWin Games\iWinTrusted.exe (iWin Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe (Gteko Ltd.)
PRC - C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Sonic Solutions)
PRC - C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe (Trend Micro Inc.)
PRC - C:\Program Files\Southwest Airlines\Ding\Ding.exe (Southwest Airlines)
PRC - C:\Program Files\Canon\BJCard\Bjmcmng.exe (CANON INC.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Cookie\Desktop\erunt_setup DLd as OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (gupdate) Google Update Service (gupdate) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (iWinTrusted) – C:\Program Files\iWin Games\iWinTrusted.exe (iWin Inc.)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (gusvc) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (PcCtlCom) – C:\Program Files\Trend Micro\Internet Security 14\PcCtlCom.exe (Trend Micro Inc.)
SRV - (GoogleDesktopManager) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (Tmntsrv) – C:\Program Files\Trend Micro\Internet Security 14\Tmntsrv.exe (Trend Micro Inc.)
SRV - (DellAMBrokerService) – C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe ()
SRV - (tmproxy) – C:\Program Files\Trend Micro\Internet Security 14\tmproxy.exe (Trend Micro Inc.)
SRV - (TmPfw) – C:\Program Files\Trend Micro\Internet Security 14\TmPfw.exe (Trend Micro Inc.)
SRV - (RoxMediaDB9) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Sonic Solutions)
SRV - (RoxWatch9) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Sonic Solutions)
SRV - (stllssvr) – C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (MicroVision Development, Inc.)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (aspnet_state) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Bjmcmng) – C:\Program Files\Canon\BJCard\Bjmcmng.exe (CANON INC.)


========== Driver Services (SafeList) ==========

DRV - (tmxpflt) – C:\WINDOWS\system32\drivers\tmxpflt.sys (Trend Micro Inc.)
DRV - (tmpreflt) – C:\WINDOWS\system32\drivers\tmpreflt.sys (Trend Micro Inc.)
DRV - (vsapint) – C:\WINDOWS\system32\drivers\vsapint.sys (Trend Micro Inc.)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (datunidr) – C:\WINDOWS\system32\drivers\datunidr.sys (Gteko Ltd.)
DRV - (e1express) Intel® – C:\WINDOWS\system32\drivers\e1e5132.sys (Intel Corporation)
DRV - (iaStor) – C:\WINDOWS\system32\drivers\iaStor.sys (Intel Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (tmcfw) – C:\WINDOWS\system32\drivers\TM_CFW.sys (Trend Micro Inc.)
DRV - (tmtdi) – C:\WINDOWS\system32\drivers\tmtdi.sys (Trend Micro Inc.)
DRV - (PTproct) – C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys (Gteko Ltd.)
DRV - (DLADResM) – C:\WINDOWS\system32\DLA\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) – C:\WINDOWS\system32\DLA\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Roxio)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Roxio)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Roxio)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Roxio)
DRV - (DRVNDDM) – C:\WINDOWS\system32\drivers\DRVNDDM.SYS (Roxio)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Roxio)
DRV - (DLARTL_M) – C:\WINDOWS\system32\drivers\DLARTL_M.SYS (Roxio)
DRV - (PxHelp20) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (DRVMCDB) – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (mdmxsdk) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
DRV - (FilterService) – C:\WINDOWS\system32\drivers\bjhid.sys (Canon.inc)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (MODEMCSA) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (E100B) Intel® – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=0080318
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/hws/sb/dell-usuk/en/…html?channel=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=0080318

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=0080318
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/hws/sb/dell-usuk/en/…html?channel=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.alot.com/?client_id=3B798D1001…rsion=2.4.2.399
IE - HKCU\..\URLSearchHook: {ce0c2586-da36-452b-acdb-320d9bcb19bf} - C:\Program Files\iWin\tbiWi1.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://search.live.com/results.aspx?FORM=SOLTDF&q;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..keyword.URL: "http://search.live.com/results.aspx?FORM=SOLTDF&q;="

FF - HKLM\software\mozilla\Firefox\Extensions\\{98e34367-8df7-42b4-837b-20b892ff0847}: C:\Program Files\iWin Games\firefox\ [2009/06/18 17:30:08 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/09 17:54:57 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/14 16:45:06 | 000,000,000 | —D | M]

[2009/05/09 07:56:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\Mozilla\Extensions
[2010/01/08 16:34:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\Mozilla\Firefox\Profiles\l6l76x0t.default\extensions
[2009/12/05 14:12:56 | 000,001,633 | —- | M] () – C:\Documents and Settings\Cookie\Application Data\Mozilla\Firefox\Profiles\l6l76x0t.default\searchplugins\live-search.xml
[2010/02/16 18:06:52 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2004/08/04 03:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (ALOT Toolbar) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll (Miva)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (IEHlprObj Class) - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\Program Files\iWin Games\iWinGamesHookIE.dll (iWin Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (iWin Toolbar) - {ce0c2586-da36-452b-acdb-320d9bcb19bf} - C:\Program Files\iWin\tbiWi1.dll (Conduit Ltd.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (ALOT Toolbar) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll (Miva)
O3 - HKLM\..\Toolbar: (iWin Toolbar) - {ce0c2586-da36-452b-acdb-320d9bcb19bf} - C:\Program Files\iWin\tbiWi1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (iWin Toolbar) - {CE0C2586-DA36-452B-ACDB-320D9BCB19BF} - C:\Program Files\iWin\tbiWi1.dll (Conduit Ltd.)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [DellAutomatedPCTuneUp] C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [OE_OEM] C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe (Trend Micro Inc.)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\WINDOWS\System32\Adobe\Shockwave 11\SwHelper_1150596.exe -Update -1150596 -Mozilla\4.0 ( File not found
O4 - Startup: C:\Documents and Settings\Cookie\Start Menu\Programs\Startup\DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe (Southwest Airlines)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: //@install.mar@ ([]msni in My Computer)
O15 - HKCU\..Trusted Domains: //@mail.mar@ ([]msn in Local intranet)
O15 - HKCU\..Trusted Domains: //@mail.mar@ ([]msni in Local intranet)
O15 - HKCU\..Trusted Domains: //@mail.mar@/ ([]msn in Local intranet)
O15 - HKCU\..Trusted Domains: //@signup.mar@ ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: //@signup.mar@/ ([]msn in My Computer)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1210395665609 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://zone.msn.com/bingame/popcaploader_v10.cab (PopCapLoader Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Cookie\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Cookie\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 15:15:00 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2004/08/11 15:02:12 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

========== Files/Folders - Created Within 30 Days ==========

[2010/02/17 05:38:02 | 000,549,376 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Cookie\Desktop\erunt_setup DLd as OTL.exe
[2010/02/16 05:24:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Cookie\Application Data\Malwarebytes
[2010/02/16 05:19:23 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/02/15 14:00:11 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2010/02/14 10:42:19 | 000,000,000 | -H-D | C] – C:\WINDOWS\PIF
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-TW
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-HK
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\tr-TR
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\sv-SE
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\pt-BR
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nl-NL
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nb-NO
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ko-KR
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\it-IT
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\he-IL
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fr-FR
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fi-FI
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\es-ES
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\el-GR
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\de-DE
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\da-DK
[2010/02/11 17:38:13 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ar-SA
[2010/02/11 17:14:41 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/02/09 17:54:31 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2010/02/09 16:27:44 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/02/09 16:27:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/02/09 16:27:42 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/02/09 16:27:42 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/02/09 16:19:10 | 005,061,512 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Cookie\Desktop\fluffy.exe
[2010/02/06 08:38:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MSNDynFiles
[2008/08/18 19:12:28 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2008/04/02 19:13:06 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2008/03/17 19:24:35 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Roxio
[2004/08/11 15:20:16 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2004/08/11 15:06:56 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/02/17 05:31:02 | 000,549,376 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Cookie\Desktop\erunt_setup DLd as OTL.exe
[2010/02/17 05:27:56 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/02/17 05:27:40 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2010/02/17 05:27:39 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/02/17 05:27:36 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/02/17 05:27:34 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/02/17 05:27:33 | 1062,387,712 | -HS- | M] () – C:\hiberfil.sys
[2010/02/17 05:05:05 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/02/16 18:15:56 | 004,194,304 | -H– | M] () – C:\Documents and Settings\Cookie\NTUSER.DAT
[2010/02/16 18:15:56 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Cookie\ntuser.ini
[2010/02/16 18:13:35 | 000,293,376 | —- | M] () – C:\Documents and Settings\Cookie\Desktop\rue0v3z3.exe
[2010/02/15 17:49:03 | 000,000,560 | —- | M] () – C:\WINDOWS\tasks\Norton Security Scan for Cookie.job
[2010/02/15 15:12:18 | 000,000,089 | —- | M] () – C:\WINDOWS\popcinfot.dat
[2010/02/15 14:32:09 | 000,000,027 | —- | M] () – C:\WINDOWS\popcinfo.dat
[2010/02/15 13:59:51 | 000,359,929 | —- | M] () – C:\Documents and Settings\Cookie\Desktop\dds.scr
[2010/02/15 12:53:20 | 000,000,009 | —- | M] () – C:\WINDOWS\System32\Class14
[2010/02/15 12:53:20 | 000,000,005 | —- | M] () – C:\WINDOWS\System32\Band4
[2010/02/10 21:22:33 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/02/10 06:49:28 | 000,015,004 | -HS- | M] () – C:\Documents and Settings\Cookie\Local Settings\Application Data\g52C
[2010/02/09 18:14:35 | 000,000,901 | —- | M] () – C:\Documents and Settings\Cookie\Desktop\Shortcut (2) to HijackThis Log 02-09-10.lnk
[2010/02/09 18:13:37 | 000,000,901 | —- | M] () – C:\Documents and Settings\Cookie\Desktop\Shortcut to HijackThis Log 02-09-10.lnk
[2010/02/09 18:04:07 | 000,001,734 | —- | M] () – C:\Documents and Settings\Cookie\Desktop\HiJackThis.lnk
[2010/02/09 17:52:52 | 000,000,477 | —- | M] () – C:\WINDOWS\win.ini
[2010/02/09 17:52:52 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/02/09 17:52:52 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/02/09 16:27:47 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/09 16:21:49 | 004,770,096 | -H– | M] () – C:\Documents and Settings\Cookie\Local Settings\Application Data\IconCache.db
[2010/02/09 16:19:19 | 005,061,512 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Cookie\Desktop\fluffy.exe
[2010/02/09 11:46:02 | 000,005,970 | —- | M] () – C:\Documents and Settings\Cookie\Application Data\wklnhst.dat
[2010/01/24 05:53:00 | 003,456,282 | —- | M] () – C:\Documents and Settings\Cookie\My Documents\ELVIS_seatplan.pdf
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/02/16 18:13:35 | 000,293,376 | —- | C] () – C:\Documents and Settings\Cookie\Desktop\rue0v3z3.exe
[2010/02/16 05:19:16 | 1062,387,712 | -HS- | C] () – C:\hiberfil.sys
[2010/02/15 14:01:54 | 000,359,929 | —- | C] () – C:\Documents and Settings\Cookie\Desktop\dds.scr
[2010/02/15 14:00:07 | 000,000,886 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/02/15 14:00:07 | 000,000,882 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/02/11 17:38:15 | 000,000,236 | —- | C] () – C:\WINDOWS\tasks\OGALogon.job
[2010/02/09 18:14:35 | 000,000,901 | —- | C] () – C:\Documents and Settings\Cookie\Desktop\Shortcut (2) to HijackThis Log 02-09-10.lnk
[2010/02/09 18:13:37 | 000,000,901 | —- | C] () – C:\Documents and Settings\Cookie\Desktop\Shortcut to HijackThis Log 02-09-10.lnk
[2010/02/09 18:04:07 | 000,001,734 | —- | C] () – C:\Documents and Settings\Cookie\Desktop\HiJackThis.lnk
[2010/02/09 16:27:47 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/09 15:09:50 | 000,015,004 | -HS- | C] () – C:\Documents and Settings\Cookie\Local Settings\Application Data\g52C
[2010/01/24 05:52:59 | 003,456,282 | —- | C] () – C:\Documents and Settings\Cookie\My Documents\ELVIS_seatplan.pdf
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2008/08/24 15:06:56 | 000,005,632 | —- | C] () – C:\Documents and Settings\Cookie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/08/17 06:29:56 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2008/07/03 13:35:25 | 000,005,970 | —- | C] () – C:\Documents and Settings\Cookie\Application Data\wklnhst.dat
[2008/06/15 12:19:48 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\pmsbfn32.dll
[2008/06/15 12:16:12 | 000,000,412 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2008/04/04 05:31:18 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\CNMVS4y.DLL
[2008/03/22 08:28:41 | 000,101,376 | —- | C] () – C:\WINDOWS\System32\hpgt34.dll
[2008/03/17 19:24:50 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/03/17 19:15:39 | 000,056,056 | —- | C] () – C:\WINDOWS\System32\DLAAPI_W.DLL
[2008/03/17 19:15:39 | 000,000,120 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/03/17 18:48:46 | 000,876,544 | —- | C] () – C:\WINDOWS\System32\TEACico2.dll
[2008/03/17 18:48:37 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4820.dll
[2008/03/17 18:47:06 | 000,001,119 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2006/11/07 02:25:58 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2006/09/16 20:36:50 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/16 20:36:50 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2004/08/11 15:24:19 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/11 15:11:31 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini

========== LOP Check ==========

[2008/06/15 12:11:44 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2008/08/16 19:52:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IM
[2008/08/16 19:51:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IncrediMail
[2009/04/08 06:41:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iWin Games
[2008/05/24 14:03:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Masque
[2008/03/22 10:46:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN Messenger 6.1.0207
[2010/02/16 05:54:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSNDynFiles
[2009/06/21 18:18:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2008/04/01 05:43:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2008/11/16 13:17:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2008/06/15 12:16:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2009/07/31 15:25:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SpinTop Games
[2008/03/17 19:19:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2010/02/15 17:48:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/12/15 16:28:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\alot
[2009/06/19 05:53:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\Aveyond 3
[2008/06/16 09:37:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\Canon
[2009/03/27 08:14:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\Fabulous Finds
[2009/06/18 18:03:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\Faerie Solitaire
[2008/05/24 14:13:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\Masque
[2008/07/09 18:30:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\MSNInstaller
[2009/06/21 18:18:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\PlayFirst
[2009/07/30 17:50:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\PopCapv1001
[2009/03/24 06:20:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\PopCapv1002
[2008/06/15 12:16:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\ScanSoft
[2008/08/28 09:14:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\Southwest Airlines
[2009/02/05 18:33:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\Stellarium
[2008/07/03 13:35:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\Template
[2010/02/17 05:27:40 | 000,000,236 | —- | M] () – C:\WINDOWS\Tasks\OGALogon.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/04 03:00:00 | 018,738,937 | —- | M] () .cab file – C:\i386\sp2.cab:AGP440.sys
[2004/08/04 03:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/08/18 18:55:44 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/08/18 18:55:44 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 10:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 10:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/03 21:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\i386\AGP440.SYS
[2004/08/03 21:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 03:00:00 | 018,738,937 | —- | M] () .cab file – C:\i386\sp2.cab:atapi.sys
[2004/08/04 03:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/08/18 18:55:44 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/08/18 18:55:44 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2006/08/28 00:02:10 | 000,095,872 | —- | M] (Microsoft Corporation) MD5=40CAACE7F2E7668148A1D45CF91E1131 – C:\i386\atapi.sys
[2006/08/27 19:02:10 | 000,095,872 | —- | M] (Microsoft Corporation) MD5=40CAACE7F2E7668148A1D45CF91E1131 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2006/08/27 19:02:10 | 000,095,872 | —- | M] (Microsoft Corporation) MD5=40CAACE7F2E7668148A1D45CF91E1131 – C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\atapi.sys
[2006/08/27 19:02:10 | 000,095,872 | —- | M] (Microsoft Corporation) MD5=40CAACE7F2E7668148A1D45CF91E1131 – C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 16:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 16:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 03:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\i386\eventlog.dll
[2004/08/04 03:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: IASTOR.SYS >
[2007/07/19 16:26:24 | 000,304,920 | —- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 – C:\drivers\storage\R158515\iastor.sys
[2007/07/19 16:26:24 | 000,304,920 | —- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 – C:\i386\iastor.sys
[2007/07/19 16:26:24 | 000,304,920 | —- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 – C:\WINDOWS\system32\drivers\iastor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/13 16:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 16:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 03:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\i386\netlogon.dll
[2004/08/04 03:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 03:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\i386\scecli.dll
[2004/08/04 03:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2004/08/11 15:06:14 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/08/11 15:06:14 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/08/11 15:06:14 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav

========== Alternate Data Streams ==========

@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:37C5B4CA
@Alternate Data Stream - 140 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7198E1D2
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C9D9AD33
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D3932BB3
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E39052E1
< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI