This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

"Defense" Center

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

It has routinely popped up over the last three weeks. It claims to be a virus protection program, but is obviously a fake. I have repeatedly used the virus removal system on Geekstogo.com but it hasn't removed it. I followed the guide on here, and the program is still visible, and does not appear to have been removed.. I *cannot* get rid of it. I have tried twice to do a Malware Malbytes Quick Scan tonight and both times the computer has randomly shut down while I have done it. Here's my OTL log.
It won't let me add more than one log per upload, which is incredibly annoying.

Here's Hijack This.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 00:15:28, on 7/21/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\DOCUME~1\brenda\LOCALS~1\Temp\MSDERUN.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\DOCUME~1\brenda\LOCALS~1\Temp\wscsvc32.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Defense Center\defcnt.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\DOCUME~1\brenda\LOCALS~1\Temp\MSDERUN.EXE
C:\DOCUME~1\brenda\LOCALS~1\Temp\MSDERUN.EXE
C:\WINDOWS\system32\msiexec.exe
C:\DOCUME~1\brenda\LOCALS~1\Temp\MSDERUN.EXE
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://ca.search.yahoo.com/search?fr=mcafee&p=%s
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Encarta Web Companion - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Program Files\Common Files\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [Skace] rundll32.exe "C:\WINDOWS\ebadodexa.dll",Startup
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (rootkit-scan)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\brenda\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Bluwiyunolifeta] rundll32.exe "C:\WINDOWS\matmca.dll",Startup
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Defense Center] "C:\Program Files\Defense Center\defcnt.exe" -noscan
O4 - HKUS\S-1-5-18\..\Run: [Bluwiyunolifeta] rundll32.exe "C:\WINDOWS\matmca.dll",Startup (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msosrvay] C:\Documents and Settings\NetworkService\Application Data\dhipxullu\cyicebatssd.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [exjphxgy] C:\Documents and Settings\NetworkService\Local Settings\Application Data\wjqfmrucm\vpkfitatssd.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [fctlgfdo] C:\Documents and Settings\NetworkService\Local Settings\Application Data\auslracnc\nisqdcftssd.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [yhlkdfxf] C:\Documents and Settings\NetworkService\Local Settings\Application Data\camthnopy\mwagbiftssd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Bluwiyunolifeta] rundll32.exe "C:\WINDOWS\matmca.dll",Startup (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mโ€ฆ01/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdatโ€ฆb?1174581583656
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intelยฎ Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe

โ€“
End of file - 9276 bytes
Here's my DDS scan log and txt file. I don't know how to zip up the other part so I'm not really sure what to do hereโ€ฆ.. Edit - this goddamn virus is *also* shutting down/restarting my computer at random And my task/menu bar - which is supposed to be at the bottom of the screen, has now vanished. I am continually getting popups saying I'm infected and I need to buy this stupid effing virus software. Will someone *please* give me a hand? Edit 2 - Also tried to run GMER, and it froze my computer entirely. Still waiting for helpโ€ฆโ€ฆโ€ฆ. Edit *3* Finally got Malware to go through a complete scan. It's removed a lot of the problem, but it said it couldn't get rid of all the infected files. So I have a feeling this will be back. :( Here's my MBAM log.
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

โ€ขRefrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
โ€ขIf you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
โ€ขEven if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
โ€ขPlease reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post
โ€ขPlease be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
โ€ขThis may cause a delay in response time, but I will do my best to keep it as short as possible.
โ€ขI will reply back shortly with instructions.
Hello Lard please do the following

Re-Scanning with DDS
Please re-run DDS by sUBs.
Make sure to pay attention to the directions below:
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
  • Post the contents of the DDS.txt & Attach.txt reports in your next reply.


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scanโ€ฆclick on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following โ€ฆ
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<โ€” ROOKIT" entries


If GMER won't run try with devices unchecked.If still no go try in safe mode.



In your next reply please post the following.
  • Both DDS logs
  • GMER log
DDS.txt DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 13:27:28.64 on Thu 07/22/2010 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_17 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.276 [GMT -4:00] AV: Defense Center *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe C:\WINDOWS\system32\IoctlSvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\Explorer.EXE C:\WINDOWS\stsystra.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Logitech\Video\LogiTray.exe C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe C:\Program Files\Dell Support\DSAgnt.exe C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe C:\Program Files\Logitech\MouseWare\system\em_exec.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\WINDOWS\system32\dlcccoms.exe C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe C:\Documents and Settings\brenda\My Documents\Downloads\utorrent.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\Documents and Settings\brenda\My Documents\Downloads\dds.scr ============== Pseudo HJT Report =============== uSearchURL,(Default) = hxxp://ca.search.yahoo.com/search?fr=mcafee&p=%s BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Encarta Web Companion: {147d6308-0614-4112-89b1-31402f9b82c4} - c:\program files\common files\microsoft shared\encarta web companion\ENCWCBAR.DLL TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - uRun: [LogitechSoftwareUpdate] "c:\program files\logitech\video\ManifestEngine.exe" boot uRun: [DellSupport] "c:\program files\dell support\DSAgnt.exe" /startup uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Google Update] "c:\documents and settings\brenda\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [LVCOMSX] c:\windows\system32\LVCOMSX.EXE mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [LogitechVideoTray] c:\program files\logitech\video\LogiTray.exe mRun: [LogitechVideoRepair] c:\program files\logitech\video\ISStart.exe mRun: [Logitech Utility] Logi_MwX.Exe mRun: [dlccmon.exe] "c:\program files\dell photo aio printer 924\dlccmon.exe" mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe" mRun: [DLCCCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLCCtime.dll,_RunDLLEntry@16 mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup mRun: [Skace] rundll32.exe "c:\windows\ebadodexa.dll",Startup mRun: [Malwarebytes Anti-Malware (rootkit-scan)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray dRun: [msosrvay] c:\documents and settings\networkservice\application data\dhipxullu\cyicebatssd.exe dRun: [exjphxgy] c:\documents and settings\networkservice\local settings\application data\wjqfmrucm\vpkfitatssd.exe dRun: [fctlgfdo] c:\documents and settings\networkservice\local settings\application data\auslracnc\nisqdcftssd.exe dRun: [yhlkdfxf] c:\documents and settings\networkservice\local settings\application data\camthnopy\mwagbiftssd.exe StartupFolder: c:\docume~1\brenda\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\documents and settings\brenda\start menu\programs\startup\PowerReg Scheduler V3.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1174581583656 DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\brenda\applic~1\mozilla\firefox\profiles\keut6kc5.default\ FF - plugin: c:\documents and settings\brenda\application data\mozilla\plugins\npgoogletalk.dll FF - plugin: c:\documents and settings\brenda\application data\mozilla\plugins\npgtpo3dautoplugin.dll FF - plugin: c:\documents and settings\brenda\local settings\application data\google\update\1.2.183.29\npGoogleOneClick8.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - HiddenExtension: XULRunner: {C99CDA04-C018-42E3-8FD8-8E7F094E84DA} - c:\documents and settings\brenda\local settings\application data\{C99CDA04-C018-42E3-8FD8-8E7F094E84DA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} โ€”- FIREFOX POLICIES โ€”- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xnโ€“mgbaam7a8h", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xnโ€“mgberp4a5d4ar", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xnโ€“p1ai", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xnโ€“mgbayh7gpa", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1"); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\dddsk.sys [2010-5-7 22312] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-7-2 304464] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-7-2 20952] S3 {5FFDCCE4-1EF9-4D46-B064384B644E621B};{5FFDCCE4-1EF9-4D46-B064384B644E621B};c:\windows\temp\16E.tmp [2010-7-14 39040] S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2006-12-19 34248] S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2006-12-19 40552] S3 PhilCam8116_XP;Logitech QuickCam Pro 3000(PID_08B1);c:\windows\system32\drivers\CamDrL20.sys [2006-1-11 245760] S4 kcwdjux;kcwdjux;c:\windows\system32\drivers\jfci.sys [2010-7-3 54016] S4 kmydr;kmydr;c:\windows\system32\drivers\ctkpuv.sys [2010-7-3 54016] S4 ocgmpj;ocgmpj;c:\windows\system32\drivers\brmv.sys [2010-7-3 54016] =============== Created Last 30 ================ 2010-07-21 06:54 281,104 aโ€”โ€”- c:\windows\system32\wpcap.dll 2010-07-21 06:54 100,880 aโ€”โ€”- c:\windows\system32\Packet.dll 2010-07-21 06:54 50,704 aโ€”โ€”- c:\windows\system32\drivers\npf.sys 2010-07-21 03:45 0 aโ€”โ€”- c:\windows\aguzazowemu.dll 2010-07-21 03:15 0 aโ€”โ€”- c:\windows\amorokowucafoju.dll 2010-07-21 02:10 0 aโ€”โ€”- c:\windows\anolavarowi.dll 2010-07-21 02:01 0 aโ€”โ€”- c:\windows\ewibejuy.dll 2010-07-21 00:08 0 aโ€”โ€”- c:\windows\ucaharus.dll 2010-07-21 00:00 0 aโ€”โ€”- c:\windows\egacozis.dll 2010-07-20 22:54 0 aโ€”โ€”- c:\windows\acejidif.dll 2010-07-20 21:45 116 aโ€”โ€”- c:\windows\system32\fjhdyfhsn.bat 2010-07-20 21:45 365 aโ€”โ€”- c:\windows\.js 2010-07-20 21:18 0 aโ€”โ€”- c:\windows\ebelejacoyusi.dll 2010-07-20 19:16 0 aโ€”โ€”- c:\windows\orirokonibu.dll 2010-07-20 17:14 0 aโ€”โ€”- c:\windows\umizixocigezo.dll 2010-07-20 15:12 0 aโ€”โ€”- c:\windows\ibogepukogibux.dll 2010-07-20 13:10 0 aโ€”โ€”- c:\windows\awetaduxotoy.dll 2010-07-20 11:08 0 aโ€”โ€”- c:\windows\arisivik.dll 2010-07-20 09:07 0 aโ€”โ€”- c:\windows\odawuvur.dll 2010-07-20 07:04 0 aโ€”โ€”- c:\windows\acecaxozabocu.dll 2010-07-20 05:02 0 aโ€”โ€”- c:\windows\iwihikilugo.dll 2010-07-20 03:00 0 aโ€”โ€”- c:\windows\ajagafeyuzubiz.dll 2010-07-20 00:58 0 aโ€”โ€”- c:\windows\ehegejimijigoki.dll 2010-07-19 22:56 0 aโ€”โ€”- c:\windows\ixeludos.dll 2010-07-19 20:54 0 aโ€”โ€”- c:\windows\ahanodijipatax.dll 2010-07-19 18:52 0 aโ€”โ€”- c:\windows\ugoqevoyoxajijoh.dll 2010-07-19 16:50 0 aโ€”โ€”- c:\windows\ajacoden.dll 2010-07-19 14:48 0 aโ€”โ€”- c:\windows\efesuket.dll 2010-07-19 12:46 0 aโ€”โ€”- c:\windows\afurifaduf.dll 2010-07-19 10:45 0 aโ€”โ€”- c:\windows\utukoxaxeda.dll 2010-07-19 08:42 0 aโ€”โ€”- c:\windows\apuvikikikodu.dll 2010-07-19 06:40 0 aโ€”โ€”- c:\windows\imafideluj.dll 2010-07-19 04:38 0 aโ€”โ€”- c:\windows\elolipizuluf.dll 2010-07-19 02:36 0 aโ€”โ€”- c:\windows\uwowilulokuzox.dll 2010-07-19 00:35 0 aโ€”โ€”- c:\windows\omegunewucobuh.dll 2010-07-18 23:16 0 aโ€”โ€”- c:\windows\etiniyaw.dll 2010-07-18 22:24 0 aโ€”โ€”- c:\windows\okufabizagovagif.dll 2010-07-18 20:23 0 aโ€”โ€”- c:\windows\usebizebufisaw.dll 2010-07-18 18:20 0 aโ€”โ€”- c:\windows\ikenulamolimarig.dll 2010-07-18 16:18 0 aโ€”โ€”- c:\windows\acimavabow.dll 2010-07-18 14:16 0 aโ€”โ€”- c:\windows\ecezezuq.dll 2010-07-18 12:14 0 aโ€”โ€”- c:\windows\oxitefac.dll 2010-07-18 10:13 0 aโ€”โ€”- c:\windows\ivecoroj.dll 2010-07-18 08:10 0 aโ€”โ€”- c:\windows\iresuwul.dll 2010-07-18 06:08 0 aโ€”โ€”- c:\windows\okabefovahubimu.dll 2010-07-18 04:07 0 aโ€”โ€”- c:\windows\oliresoxiwuv.dll 2010-07-18 02:04 0 aโ€”โ€”- c:\windows\ugodunujanecatev.dll 2010-07-18 00:02 0 aโ€”โ€”- c:\windows\ogejezoweqoharus.dll 2010-07-17 22:00 0 aโ€”โ€”- c:\windows\ucuqaluxoc.dll 2010-07-17 19:58 0 aโ€”โ€”- c:\windows\opiriwesozomufa.dll 2010-07-17 17:56 0 aโ€”โ€”- c:\windows\atojihumevixipa.dll 2010-07-17 15:55 0 aโ€”โ€”- c:\windows\agepexomino.dll 2010-07-17 13:52 0 aโ€”โ€”- c:\windows\ecuxuwib.dll 2010-07-17 11:50 0 aโ€”โ€”- c:\windows\isalilun.dll 2010-07-17 09:48 0 aโ€”โ€”- c:\windows\egorozececisuwaq.dll 2010-07-17 07:46 0 aโ€”โ€”- c:\windows\uzezisijihafew.dll 2010-07-17 05:45 0 aโ€”โ€”- c:\windows\ukolesoqaxala.dll 2010-07-17 03:42 0 aโ€”โ€”- c:\windows\ikemeroko.dll 2010-07-17 01:40 0 aโ€”โ€”- c:\windows\uwiyimaxeqayofi.dll 2010-07-16 23:39 0 aโ€”โ€”- c:\windows\ewinotudokawas.dll 2010-07-16 21:37 0 aโ€”โ€”- c:\windows\aguziwawazu.dll 2010-07-16 19:34 0 aโ€”โ€”- c:\windows\olehozazohecewew.dll 2010-07-16 17:32 0 aโ€”โ€”- c:\windows\ugejilil.dll 2010-07-16 15:30 0 aโ€”โ€”- c:\windows\eyagelewizuteroy.dll 2010-07-16 13:29 0 aโ€”โ€”- c:\windows\awotazet.dll 2010-07-16 11:26 0 aโ€”โ€”- c:\windows\uwekifasocu.dll 2010-07-16 09:24 0 aโ€”โ€”- c:\windows\ogaqemeji.dll 2010-07-16 07:22 0 aโ€”โ€”- c:\windows\azukowucafo.dll 2010-07-16 05:21 0 aโ€”โ€”- c:\windows\ivohufaj.dll 2010-07-16 03:18 0 aโ€”โ€”- c:\windows\iwurulat.dll 2010-07-16 01:16 0 aโ€”โ€”- c:\windows\uyekolak.dll 2010-07-15 23:15 0 aโ€”โ€”- c:\windows\itibelixibugojud.dll 2010-07-15 21:12 0 aโ€”โ€”- c:\windows\oduxosokaradewil.dll 2010-07-15 19:11 0 aโ€”โ€”- c:\windows\ijolifasufoli.dll 2010-07-15 17:09 0 aโ€”โ€”- c:\windows\eqarowigesifefe.dll 2010-07-15 15:07 0 aโ€”โ€”- c:\windows\ivozifulo.dll 2010-07-15 13:05 0 aโ€”โ€”- c:\windows\ulesetube.dll 2010-07-15 12:31 0 aโ€”โ€”- c:\windows\oqejucohotuceja.dll 2010-07-15 10:28 0 aโ€”โ€”- c:\windows\igecedojodohuj.dll 2010-07-15 08:26 0 aโ€”โ€”- c:\windows\uwuhepayukay.dll 2010-07-15 06:25 0 aโ€”โ€”- c:\windows\epanodijip.dll 2010-07-15 04:22 0 aโ€”โ€”- c:\windows\onugududibot.dll 2010-07-15 02:21 0 aโ€”โ€”- c:\windows\utodegexino.dll 2010-07-15 01:36 0 aโ€”โ€”- c:\windows\ucezefijoc.dll 2010-07-14 23:34 0 aโ€”โ€”- c:\windows\eceyevev.dll 2010-07-14 21:54 0 aโ€”โ€”- c:\windows\agihujojulowuni.dll 2010-07-14 19:52 0 aโ€”โ€”- c:\windows\ipidagak.dll 2010-07-14 18:18 0 aโ€”โ€”- c:\windows\iwigucoruwuya.dll 2010-07-14 16:16 0 aโ€”โ€”- c:\windows\amepapoxulodi.dll 2010-07-14 02:59 0 aโ€”โ€”- c:\windows\evecejaqape.dll 2010-07-14 00:57 0 aโ€”โ€”- c:\windows\obayanac.dll 2010-07-13 22:55 0 aโ€”โ€”- c:\windows\uqebacax.dll 2010-07-13 21:34 0 aโ€”โ€”- c:\windows\iyefuxuz.dll 2010-07-13 21:05 0 aโ€”โ€”- c:\windows\ecoduyev.dll 2010-07-13 20:26 664 aโ€”โ€”- c:\windows\system32\d3d9caps.dat 2010-07-13 20:26 552 aโ€”โ€”- c:\windows\system32\d3d8caps.dat 2010-07-13 19:00 0 aโ€”โ€”- c:\windows\uvejuduli.dll 2010-07-13 16:58 0 aโ€”โ€”- c:\windows\uceqavivamebope.dll 2010-07-13 14:56 0 aโ€”โ€”- c:\windows\ocehivafecujof.dll 2010-07-13 12:54 0 aโ€”โ€”- c:\windows\upisuleb.dll 2010-07-13 10:53 0 aโ€”โ€”- c:\windows\afepukogibuxidet.dll 2010-07-13 08:50 0 aโ€”โ€”- c:\windows\ubexaxay.dll 2010-07-13 06:48 0 aโ€”โ€”- c:\windows\inuruwokuqisalut.dll 2010-07-13 04:46 0 aโ€”โ€”- c:\windows\eqinokecikotad.dll 2010-07-13 02:45 0 aโ€”โ€”- c:\windows\avovopebasu.dll 2010-07-13 00:42 0 aโ€”โ€”- c:\windows\izudinir.dll 2010-07-12 22:40 0 aโ€”โ€”- c:\windows\ozuboqaxuwibiqo.dll 2010-07-12 14:07 0 aโ€”โ€”- c:\windows\icuxebux.dll 2010-07-12 12:05 0 aโ€”โ€”- c:\windows\izebohoj.dll 2010-07-12 03:49 0 aโ€”โ€”- c:\windows\ugijimij.dll 2010-07-12 01:47 0 aโ€”โ€”- c:\windows\ozovokoxa.dll 2010-07-11 22:41 0 aโ€”โ€”- c:\windows\ivowefokibo.dll 2010-07-11 20:38 0 aโ€”โ€”- c:\windows\ibuhoyopogic.dll 2010-07-11 18:37 0 aโ€”โ€”- c:\windows\uqunoguq.dll 2010-07-11 16:34 0 aโ€”โ€”- c:\windows\abukabad.dll 2010-07-11 14:32 0 aโ€”โ€”- c:\windows\udakizaxifiv.dll 2010-07-11 12:30 0 aโ€”โ€”- c:\windows\etexebod.dll 2010-07-11 10:28 0 aโ€”โ€”- c:\windows\egoqehisuketo.dll 2010-07-11 08:26 0 aโ€”โ€”- c:\windows\ocowagurin.dll 2010-07-11 06:24 0 aโ€”โ€”- c:\windows\omoziyemamerihes.dll 2010-07-11 04:22 0 aโ€”โ€”- c:\windows\erepasuyaxukow.dll 2010-07-11 02:20 0 aโ€”โ€”- c:\windows\avojegigududibot.dll 2010-07-11 00:18 0 aโ€”โ€”- c:\windows\awazimimimesu.dll 2010-07-10 22:16 0 aโ€”โ€”- c:\windows\orimewobeyitame.dll 2010-07-10 20:14 0 aโ€”โ€”- c:\windows\otavubeqovuzi.dll 2010-07-10 18:12 0 aโ€”โ€”- c:\windows\upofomoh.dll 2010-07-10 16:11 0 aโ€”โ€”- c:\windows\ifacuyaj.dll 2010-07-10 14:09 0 aโ€”โ€”- c:\windows\igiyayidad.dll 2010-07-10 12:07 0 aโ€”โ€”- c:\windows\atawogep.dll 2010-07-10 10:04 0 aโ€”โ€”- c:\windows\epogiyelovawub.dll 2010-07-10 08:02 0 aโ€”โ€”- c:\windows\ohihemofivutamu.dll 2010-07-10 06:00 0 aโ€”โ€”- c:\windows\ezijower.dll 2010-07-10 03:58 0 aโ€”โ€”- c:\windows\unacohuvilit.dll 2010-07-10 02:15 0 aโ€”โ€”- c:\windows\enitiwuvubomure.dll 2010-07-10 00:29 0 aโ€”โ€”- c:\windows\efuquvetidacir.dll 2010-07-09 23:42 0 aโ€”โ€”- c:\windows\oxanotud.dll 2010-07-03 05:56 54,016 aโ€”โ€”- c:\windows\system32\drivers\ctkpuv.sys 2010-07-03 02:16 54,016 aโ€”โ€”- c:\windows\system32\drivers\brmv.sys 2010-07-03 00:55 54,016 aโ€”โ€”- c:\windows\system32\drivers\jfci.sys 2010-07-02 23:29 38,224 aโ€”โ€”- c:\windows\system32\drivers\mbamswissarmy.sys 2010-07-02 23:29 20,952 aโ€”โ€”- c:\windows\system32\drivers\mbam.sys 2010-07-02 23:29 โ€“dโ€”โ€“ c:\program files\Malwarebytes' Anti-Malware 2010-07-01 15:01 -cdโ€”โ€“ c:\docume~1\alluse~1\applic~1\{C4C0E335-EDDF-46A0-A57D-F3802AE44275} 2010-07-01 14:58 โ€“dโ€”โ€“ c:\windows\system32\XPSViewer 2010-07-01 14:55 117,760 โ€”โ€”โ€“ c:\windows\system32\prntvpt.dll 2010-07-01 14:55 597,504 โ€”โ€”โ€“ c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2010-07-01 14:55 89,088 โ€”โ€”โ€“ c:\windows\system32\dllcache\filterpipelineprintproc.dll 2010-07-01 14:55 575,488 โ€”โ€”โ€“ c:\windows\system32\xpsshhdr.dll 2010-07-01 14:55 575,488 โ€”โ€”โ€“ c:\windows\system32\dllcache\xpsshhdr.dll 2010-07-01 14:55 1,676,288 โ€”โ€”โ€“ c:\windows\system32\xpssvcs.dll 2010-07-01 14:55 1,676,288 โ€”โ€”โ€“ c:\windows\system32\dllcache\xpssvcs.dll 2010-07-01 14:54 โ€“dโ€”โ€“ c:\windows\SxsCaPendDel 2010-07-01 14:28 โ€“d-hrโ€“ C:\AHCache 2010-07-01 13:39 โ€“dโ€”โ€“ c:\program files\uTorrent 2010-07-01 13:27 โ€“dโ€”โ€“ c:\docume~1\brenda\applic~1\Uniblue ==================== Find3M ==================== 2010-06-12 06:49 722,416 aโ€”โ€”- c:\windows\system32\drivers\sptd.sys 2010-05-12 23:46 18,499,623 aโ€”โ€”- C:\vlc-1.0.5-win32.exe 2008-04-02 12:32 4,337,664 aโ€”โ€”- c:\program files\mplayerc.exe 2009-09-03 12:34 4,184 aโ€“shโ€” c:\windows\system32\KGyGaAvL.sys 2008-10-02 11:35 32,768 aโ€“shโ€” c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008100220081003\index.dat ============= FINISH: 13:29:16.65 =============== Attach.txt UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume3 Install Date: 1/9/2006 10:14:06 AM System Uptime: 7/21/2010 11:02:19 PM (14 hours ago) Motherboard: Dell Inc. | | 0KF623 Processor: Intelยฎ Pentiumยฎ 4 CPU 3.20GHz | Microprocessor | 3192/800mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 146 GiB total, 107.16 GiB free. D: is CDROM () E: is FIXED (NTFS) - 112 GiB total, 33.861 GiB free. F: is FIXED (FAT32) - 931 GiB total, 122.958 GiB free. ==== Disabled Device Manager Items ============= Class GUID: {4D36E96C-E325-11CE-BFC1-08002BE10318} Description: Microsoft Kernel DLS Synthesizer Device ID: SW\{8C07DD50-7A8D-11D2-8F8C-00C04FBF8FEF}\DMUSIC Manufacturer: Microsoft Name: Microsoft Kernel DLS Synthesizer PNP Device ID: SW\{8C07DD50-7A8D-11D2-8F8C-00C04FBF8FEF}\DMUSIC Service: DMusic ==== System Restore Points =================== RP1382: 7/12/2010 1:23:19 PM - System Checkpoint RP1383: 7/14/2010 5:57:03 PM - System Checkpoint RP1384: 7/16/2010 10:11:03 AM - System Checkpoint RP1385: 7/18/2010 11:36:57 PM - System Checkpoint RP1386: 7/20/2010 12:08:26 AM - System Checkpoint RP1387: 7/20/2010 11:08:07 PM - OTL Restore Point RP1388: 7/21/2010 12:14:01 AM - Installed HiJackThis RP1389: 7/22/2010 2:29:47 AM - System Checkpoint ==== Installed Programs ====================== ยตTorrent Acrobat.com Active@ UNERASER Demo Adobe AIR Adobe Flash Player 10 Plugin Adobe Flash Player ActiveX Adobe Reader 7.1.0 Auslogics Disk Defrag Canon MP140 series Canon Utilities Easy-LayoutPrint Canon Utilities Easy-PhotoPrint Compatibility Pack for the 2007 Office system Conexant D850 56K V.9x DFVc Modem Critical Update for Windows Media Player 11 (KB959772) Data Lifeguard Diagnostic for Windows Dell Driver Reset Tool Dell Photo AIO Printer 924 Dell Support 3.2.1 Dell System Restore Digital Line Detect EasyCleaner ERUNT 1.1j ESET Online Scanner v3 ffdshow [rev 1723] [2007-12-24] Finding Nemo FinePixViewer Ver.4.1 FreeUndelete GoldWave v5.55 Google Talk Plugin High Definition Audio Driver Package - KB835221 HiJackThis Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Format SDK (KB902344) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB954708) Image Resizer Powertoy for Windows XP Intelยฎ Graphics Media Accelerator Driver Intelยฎ PRO Network Connections Drivers Intelยฎ PROSet for Wired Connections Internet Explorer Default Page Javaโ„ข 6 Update 17 Javaโ„ข 6 Update 7 Junk Mail filter update LG USB Modem driver Logitech Desktop Messenger Logitech MouseWare 9.79 Logitech QuickCam Logitechยฎ Camera Driver Macromedia Shockwave Player Magic ISO Maker v5.5 (build 0261) Malwarebytes' Anti-Malware MCU Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Choice Guard Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Encarta Premium 2006 DVD Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Professional Edition 2003 Microsoft Plus! Digital Media Edition Installer Microsoft Plus! Photo Story 2 LE Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Text-to-Speech Engine 4.0 (English) Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 MicroStaff WINASPI Modem Helper Mozilla Firefox (3.6.7) MSN MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) Nero 8 NetWaiting NVIDIA Drivers Personal License Update Wizard for Windows Media Player Revo Uninstaller 1.83 Security Update for CAPICOM (KB931906) Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Switch Sound File Converter TVersity Codec Pack 1.2 Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) VLC media player 1.0.3 VueScan WebCyberCoach 3.2 Dell WebFldrs XP Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Mail Windows Live Messenger Windows Live Photo Gallery Windows Live Sign-in Assistant Windows Live Sync Windows Live Upload Tool Windows Media Connect Windows Media Format 11 runtime Windows Media Player 10 Windows Media Player 11 Windows XP Service Pack 3 WinRAR archiver WordPerfect Office 12 ==== Event Viewer Messages From Past Week ======== 7/21/2010 2:10:16 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the HTTP SSL service to connect. 7/21/2010 2:10:16 AM, error: Service Control Manager [7001] - The Windows Media Player Network Sharing Service service depends on the HTTP SSL service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion. 7/21/2010 2:10:16 AM, error: Service Control Manager [7000] - The HTTP SSL service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 7/21/2010 2:07:28 AM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service dlcc_device with arguments "" in order to run the server: {323CE21C-A448-40AA-BA74-7FCF1E441069} 7/20/2010 10:54:36 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Java Quick Starter service to connect. 7/20/2010 10:54:36 PM, error: Service Control Manager [7000] - The Java Quick Starter service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 7/20/2010 10:51:28 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the AudioSrv service. 7/20/2010 10:51:28 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect. 7/20/2010 10:51:28 PM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 7/18/2010 11:14:54 PM, error: Service Control Manager [7023] - The Automatic Updates service terminated with the following error: The specified module could not be found. 7/18/2010 11:14:07 PM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory. 7/18/2010 11:14:07 PM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver. ==== End Of File =========================== I'm putting these up first in case GMER crashes the computer again. Edit - I *cannot* run Gmer on my computer. I have tried twice, following the instructions you gave me, and both times it completely locks up and freezes the computer.
Things have taken a turn for the worse, and I'm *extremely* displeased about them. I tried running GMER in safe mode, following the instructions you provided. I did it three times but at no time did a log ever come up when a scan was finished. Then, this morning, I tried going into regular mode and scanning with GMER. Once again, my computer froze and I had to restart. Only now, it won't boot. (I am typing from my PS3 with a USB KB). It starts up, and then just goes into a black screen and hangs. So. GMER has seemingly butchered my computer and I am unable to use it when I am supposed to be signing up for courses. Not pleased at all. How, exactly, do I fix this? I would appreciate a prompt response. Edit-it won't boot in safe mode either. Congratulations, you've sucessfully killed my computer. Edit - A prompt response is not letting me languish in computer limbo for six hours.
Hello Lard,sorry to hear that things have gotten worse and also for the delay.

The instructions i provided to you for GMER are for diagnostic purposes only, and the tool should not have deleted anything from your system.

Have you tried selecting Last known good configuration

Last Known Good Configuration

Start the computer by using the last known good configuration. To start the computer by using the last known good configuration, follow these steps:

  • Restart your computer.
  • As the computer starts to boot-up, Tap the F8 KEY repeatedly,
  • This will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll to Last Known Good Configuration
  • Then press the Enter Key on your Keyboard
  • Go into your usual account


Do you have your Windows XP disc handy? If not, would you be able to borrow one from a friend?

If you need to have access to your P.C. right away, then your fastest option at this point would be to either perform a reformat and reinstall, or bring your machine into a local computer repair shop, and have them fix your computer for you.
Last known good configuration doesnt work. Do not have an XP disc. What you're saying is I am totally notgood. How nice you can just wash your hands of it.
Lard,
I know it can be very frustrating trying to remove todays types of infections, we do it many times every day.
Many of todays infections are MBR (Master Boot Record) RootKit infections and when trying to remove that type of infection can require the owners Windows CD to repair the MBR.

Congratulations, you've sucessfully killed my computer. Edit - A prompt response is not letting me languish in computer limbo for six hours.

We didn't infect your computer, you did.
We have no idea where on the net you might have visited, what was downloaded, what you might have clicked on or maybe just opening an email.

We don't know what tools or fixes you've already used / tried or files removed.

mowman has followed the standard diagnostics procedures we all use. Nothing he has had you do would remove anything.


Using foul language or bashing any volunteers here won't be tolerated.

The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI