This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

iexplorer or yoog virus maybe?

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please help, would you kindly? My sister had an infected PC for the past 3 years and completly ignored it and got another brand new PC. Well I've come back to attempt revive this old PC from the dead.

I'm pretty sure got the virus was from downloading from limewire. I think its in the form of iexplorer or yoogg search or both because they won't go away no matter what I do. The most noticeable effect is my extemely slow PC speed. 5X slower and some programs can take an entire minute to just to start when before it would take 4 seconds.

Thank you very much in advance! I installed HiJackThis and here's what I got:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:33:11 AM, on 2/5/2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\b3duZXI\command.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Documents and Settings\Owner\Desktop\HiJackThis!\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie8
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: adsoftinc - {094bb94a-c86d-fb3e-d158-285dd3da1e41} - C:\WINDOWS\system32\nsn159.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [GetPack24] "C:\Program Files\GetPack\GetPack24.exe"
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://comcast.oberon-media.com/online2/di…sh.1.0.0.80.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O18 - Filter hijack: text/html - {1b1ccad0-b527-418f-a58d-046e891361bb} - C:\WINDOWS\system32\msziptools.dll
O20 - AppInit_DLLs: yighkw.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\b3duZXI\command.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (file missing)
O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (file missing)
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 7962 bytes
Hi,

:welcome:

My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
As I'm still in training at What The Tech, all my posts needs to be checked by an expert first. This may cause a delay, but I will do my best to keep it as short as possible.
Thanks alot for your assitance NoodleTech. Also, I would like to mention that along with slow speed, I have frequent errors and crashes. Also in the past I had alot of Popup ads. I believe a year ago, I used Mcafee to remove any viruses and I'm assuming it removed the Popup virus because I don't see them anymore. I STILL have slow speed, frequent errors, and crashes so I think some kind of virus is still there. Again, thanks for your help :3
Hi xadavid,

I will do my best to take care of the problems you mentioned.
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

Scan With RootKitUnHooker

  • Please choose one link and download Rootkit Unhooker and save it to your desktop.
    Link 1
    Link 2
    Link 3
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"


===================================================

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
===================================================

In your next post, please post the following logs:
  • OTL log
  • Rootkit Unhooker Log
  • MBRCheck log
Hey NoodleTech, I got a little problem here.
I downloaded OTL and MBRcheck however, RootkitUnHooker would not start.

When I tried to run RootkitUnHooker, an error message popped up saying:

Sorry, but unhandled exception has occured
Program will be terminated
Exception code: 0xC0000005
Instruction adress: 0x7C81043B
Attempt to read at adress: 0xC360C3E9

Error log generatedm please report to developers




I do have the logs for OTL and MBRcheck though. I also have a log called "Extras.txt" but I did not post it.


The OTL log:

Computer Name: OWNER-35B7587FB | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\Desktop\OTL!\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\WINDOWS\b3duZXI\command.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\Desktop\OTL!\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Network Monitor) – File not found
SRV - (McSysmon) – File not found
SRV - (McShield) – File not found
SRV - (AppMgmt) – File not found
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (cmdService) – C:\WINDOWS\b3duZXI\command.exe ()


========== Driver Services (SafeList) ==========

DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (m4301a) – C:\WINDOWS\system32\drivers\m4301A.sys (ALinx Corporation)
DRV - (BCMModem) – C:\WINDOWS\system32\drivers\BCMDM.sys (BCM)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2004/08/04 04:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (adsoftinc) - {094bb94a-c86d-fb3e-d158-285dd3da1e41} - C:\WINDOWS\system32\nsn159.dll ()
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [Aim6] C:\Program Files\AIM6\aim6.exe (AOL LLC)
O4 - HKCU..\Run: [GetPack24] File not found
O4 - HKCU..\Run: [Search Protection] File not found
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll (Sun Microsystems, Inc.)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} http://comcast.oberon-media.com/online2/di…sh.1.0.0.80.cab (CPlayFirstDinerDashControl Object)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.popcap.com/games/popcaploader_v6.cab (PopCapLoader Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.15.1
O20 - AppInit_DLLs: (yighkw.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O29 - HKLM SecurityProviders - (msansspc.dll) - File not found
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\fccyaYOI) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/14 00:33:11 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{806c1688-0ba3-11dd-912e-0007e99f3b82}\Shell - "" = AutoRun
O33 - MountPoints2\{806c1688-0ba3-11dd-912e-0007e99f3b82}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{806c1688-0ba3-11dd-912e-0007e99f3b82}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{85906fe2-30d0-11e0-9214-0007e99f3b82}\Shell - "" = AutoRun
O33 - MountPoints2\{85906fe2-30d0-11e0-9214-0007e99f3b82}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{85906fe2-30d0-11e0-9214-0007e99f3b82}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.dvsd - C:\WINDOWS\System32\Dvc.dll (Adaptec)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2011/02/05 15:04:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\RootKit
[2011/02/05 14:58:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\OTL!
[2011/02/05 11:58:52 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2011/02/05 03:12:00 | 000,000,000 | —D | C] – C:\WINDOWS\ServicePackFiles
[2011/02/05 03:10:35 | 000,000,000 | —D | C] – C:\WINDOWS\ie8updates
[2011/02/05 03:09:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Mario Forever 5.01
[2011/02/05 03:08:59 | 000,000,000 | —D | C] – C:\Program Files\softendo.com
[2011/02/05 01:06:45 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedvtool.dll
[2011/02/05 00:39:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\HiJackThis!
[2011/02/04 20:09:34 | 000,025,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbprint.sys
[2011/02/04 19:27:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Norton
[2011/02/04 19:27:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Norton
[2011/02/04 18:46:35 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Owner\PrivacIE
[2011/02/04 17:06:11 | 000,021,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidserv.dll
[2011/02/04 16:56:01 | 000,014,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kbdhid.sys
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\*.tmp files -> C:\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/02/05 12:05:57 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/02/05 11:59:46 | 000,409,562 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/02/05 11:59:45 | 000,064,576 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/02/05 11:54:40 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/02/05 11:54:34 | 000,360,936 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/05 03:18:05 | 000,000,020 | —- | M] () – C:\WINDOWS\mafosav.INI
[2011/02/04 20:17:21 | 000,002,497 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Microsoft Office Word 2003.lnk
[2011/02/04 19:33:52 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/02/04 19:31:18 | 000,000,825 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Norton Installation Files.lnk
[2011/02/04 16:54:29 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\*.tmp files -> C:\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/02/05 03:18:05 | 000,000,020 | —- | C] () – C:\WINDOWS\mafosav.INI
[2011/02/04 19:27:35 | 000,000,825 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Norton Installation Files.lnk
[2009/01/06 09:55:50 | 000,687,104 | —- | C] () – C:\WINDOWS\System32\nsn159.dll
[2008/12/06 01:20:41 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2008/12/03 21:49:02 | 000,114,688 | —- | C] () – C:\WINDOWS\System32\etmxbhcg.dll
[2008/11/12 23:06:25 | 000,687,592 | —- | C] () – C:\WINDOWS\System32\atmtd.dll._
[2008/11/12 23:06:25 | 000,687,592 | —- | C] () – C:\WINDOWS\System32\atmtd.dll
[2008/11/11 21:52:31 | 000,881,870 | -HS- | C] () – C:\WINDOWS\System32\IOYayccf.ini2
[2008/11/11 21:52:30 | 000,881,870 | -HS- | C] () – C:\WINDOWS\System32\IOYayccf.ini
[2008/09/29 13:14:03 | 000,000,197 | —- | C] () – C:\WINDOWS\Wininit.ini
[2006/12/03 01:38:50 | 000,001,759 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/05/09 16:20:44 | 000,000,028 | —- | C] () – C:\WINDOWS\atid.ini
[2006/02/18 14:17:21 | 000,000,000 | —- | C] () – C:\WINDOWS\ka.ini
[2005/12/25 23:17:09 | 000,000,470 | —- | C] () – C:\WINDOWS\System32\Dext536.ini
[2005/12/25 23:17:08 | 000,049,152 | —- | C] () – C:\WINDOWS\unC326C.dll
[2005/11/02 21:43:11 | 000,046,512 | —- | C] () – C:\WINDOWS\System32\EPSN.DLL
[2005/11/02 21:43:11 | 000,012,126 | —- | C] () – C:\WINDOWS\System32\PIXPCZ.DLL
[2005/11/02 21:43:11 | 000,011,934 | —- | C] () – C:\WINDOWS\System32\PIXPNR.DLL
[2005/11/02 21:42:54 | 000,000,008 | —- | C] () – C:\WINDOWS\pstudio.ini
[2005/08/24 14:36:43 | 000,000,000 | —- | C] () – C:\WINDOWS\Setup32.INI
[2005/08/14 18:06:22 | 000,036,352 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/08/14 02:08:52 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/08/13 17:22:44 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2003/01/07 14:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI

========== LOP Check ==========

[2007/04/05 16:13:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2007/04/04 11:56:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2008/09/29 13:13:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/09/29 13:46:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2006/05/09 16:24:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\acccore
[2008/12/05 23:59:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\gadcom
[2007/04/05 16:13:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PlayFirst
[2007/04/13 11:08:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Reno 911 Paintball
[2008/12/05 23:59:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Twain
[2007/03/08 19:39:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Viewpoint
[2006/06/28 22:59:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Walgreens

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2005/08/14 01:41:05 | 004,815,360 | —- | M] () – C:\9521846.exe
[2006/08/27 13:20:15 | 002,855,080 | —- | M] () – C:\aawsepersonal.exe
[2006/09/02 14:29:42 | 000,712,448 | —- | M] () – C:\ar505enu.bin
[2005/08/14 00:33:11 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2005/08/14 00:26:30 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2007/05/22 22:26:56 | 000,039,625 | —- | M] () – C:\c scale.rm
[2005/08/14 00:33:11 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/04/09 00:00:12 | 023,510,720 | —- | M] (Microsoft Corporation) – C:\dotnetfx.exe
[2005/08/24 12:19:50 | 000,000,081 | —- | M] () – C:\DVDPATH.TXT
[2006/05/14 18:10:31 | 003,972,069 | —- | M] () – C:\DVDtoiPod.zip
[2006/06/16 23:53:18 | 000,000,062 | —- | M] () – C:\hurlPNM.ra
[2005/08/14 00:33:11 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/08/04 14:11:16 | 000,001,075 | -H– | M] () – C:\IPH.PH
[2005/09/22 18:18:00 | 000,001,128 | —- | M] () – C:\joystick.inf
[2007/01/07 22:04:50 | 000,036,864 | —- | M] () – C:\LEC02Literalequations.doc
[2007/05/15 19:06:12 | 003,098,056 | —- | M] (Lime Wire LLC) – C:\LimeWireWin.exe
[2008/10/12 23:09:52 | 000,000,478 | —- | M] () – C:\LOG167.log
[2008/12/15 02:47:09 | 000,000,478 | —- | M] () – C:\LOG1C.log
[2008/12/15 04:29:23 | 000,000,478 | —- | M] () – C:\LOG2E.log
[2008/10/22 07:01:37 | 000,000,478 | —- | M] () – C:\LOG3.log
[2008/04/21 06:14:54 | 000,000,478 | —- | M] () – C:\LOG9.log
[2008/04/16 02:55:27 | 000,000,478 | —- | M] () – C:\LOGA.log
[2005/08/14 00:33:11 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 04:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 04:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2011/02/05 11:54:32 | 399,187,968 | -HS- | M] () – C:\pagefile.sys
[2007/04/08 23:57:40 | 004,894,789 | —- | M] () – C:\PaintDotNet_3_05_BetaNews.zip
[2007/04/08 23:52:54 | 000,027,696 | —- | M] () – C:\Photoshop_CS3_Full.3653665.TPB.torrent
[2005/10/31 07:56:00 | 000,700,416 | —- | M] (LimeWire) – C:\StubInstaller.exe
[2005/12/25 16:46:01 | 000,304,898 | —- | M] () – C:\USBDetectorHelper.txt
[2006/07/28 20:18:26 | 000,697,418 | —- | M] () – C:\WebPayTableVersion2006updated.pdf
[6 C:\*.tmp files -> C:\*.tmp -> ]

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2005/08/14 00:32:29 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2003/06/18 16:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2007/12/11 20:56:20 | 000,001,546 | -H– | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2005/08/13 17:19:31 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/08/13 17:19:31 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/08/13 17:19:31 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2005/08/14 00:33:22 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2007/02/02 15:06:48 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/08/14 00:37:52 | 000,000,079 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2007/04/02 13:18:22 | 000,328,464 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Owner\Desktop\Paint.EXE

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >
[2008/09/29 13:01:12 | 067,110,184 | —- | M] (Apple Inc.) – C:\Documents and Settings\Owner\My Documents\iTunes8Setup.exe

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2005/08/14 00:37:52 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Owner\Favorites\Desktop.ini
[2006/05/09 16:23:39 | 000,001,519 | —- | M] () – C:\Documents and Settings\Owner\Favorites\Free AOL & Unlimited Internet.lnk

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2011/02/05 12:00:36 | 000,540,672 | —- | M] () – C:\Documents and Settings\Owner\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-02-05 20:14:28

========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Owner\Desktop\Paint.EXE:SummaryInformation

< End of report >






The MBRcheck:

MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows XP Home Edition
Windows Information: Service Pack 2 (build 2600)
Logical Drives Mask: 0x0000001d

Kernel Drivers (total 120):
0x804D7000 \WINDOWS\system32\ntoskrnl.exe
0x806EC000 \WINDOWS\system32\hal.dll
0xF97C6000 \WINDOWS\system32\KDCOM.DLL
0xF96D6000 \WINDOWS\system32\BOOTVID.dll
0xF9277000 ACPI.sys
0xF97C8000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF9266000 pci.sys
0xF92C6000 isapnp.sys
0xF988E000 PCIIde.sys
0xF9546000 \WINDOWS\System32\Drivers\PCIIDEX.SYS
0xF97CA000 intelide.sys
0xF92D6000 MountMgr.sys
0xF9247000 ftdisk.sys
0xF954E000 PartMgr.sys
0xF92E6000 VolSnap.sys
0xF922F000 atapi.sys
0xF92F6000 disk.sys
0xF9306000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF920F000 fltMgr.sys
0xF91FD000 sr.sys
0xF91E6000 KSecDD.sys
0xF91D3000 WudfPf.sys
0xF9146000 Ntfs.sys
0xF9119000 NDIS.sys
0xF90FE000 Mup.sys
0xF9496000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xF8D54000 \SystemRoot\system32\DRIVERS\ialmnt5.sys
0xF8D40000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xF95DE000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xF8D1D000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF95E6000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xF8C48000 \SystemRoot\system32\DRIVERS\BCMDM.sys
0xF8C25000 \SystemRoot\system32\DRIVERS\ks.sys
0xF95EE000 \SystemRoot\System32\Drivers\Modem.SYS
0xF8C02000 \SystemRoot\system32\DRIVERS\e100b325.sys
0xF95F6000 \SystemRoot\system32\DRIVERS\fdc.sys
0xF94A6000 \SystemRoot\system32\DRIVERS\serial.sys
0xF976E000 \SystemRoot\system32\DRIVERS\serenum.sys
0xF8BEE000 \SystemRoot\system32\DRIVERS\parport.sys
0xF94B6000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xF94C6000 \SystemRoot\system32\DRIVERS\redbook.sys
0xF9772000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys
0xF94D6000 \SystemRoot\system32\DRIVERS\imapi.sys
0xF8B82000 \SystemRoot\system32\drivers\smwdm.sys
0xF98D5000 \SystemRoot\system32\drivers\SENSUPGD.SYS
0xF8B5E000 \SystemRoot\system32\drivers\portcls.sys
0xF94E6000 \SystemRoot\system32\drivers\drmk.sys
0xF97F6000 \SystemRoot\system32\DRIVERS\serscan.sys
0xF98D6000 \SystemRoot\system32\DRIVERS\audstub.sys
0xF94F6000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xF977E000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xF8B47000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xF9506000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xF9516000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF95FE000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xF8B36000 \SystemRoot\system32\DRIVERS\psched.sys
0xF9526000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xF960E000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF9616000 \SystemRoot\system32\DRIVERS\raspti.sys
0xF9536000 \SystemRoot\system32\DRIVERS\termdd.sys
0xF961E000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xF9626000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xF97F8000 \SystemRoot\system32\DRIVERS\swenum.sys
0xF8ADD000 \SystemRoot\system32\DRIVERS\update.sys
0xF978E000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xF9336000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xF0A0D000 \SystemRoot\system32\drivers\ialmsbw.sys
0xF095B000 \SystemRoot\system32\drivers\ialmkchw.sys
0xF9366000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF9800000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xF9746000 \SystemRoot\system32\drivers\MODEMCSA.sys
0xF9646000 \SystemRoot\system32\DRIVERS\flpydisk.sys
0xF9802000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xF9939000 \SystemRoot\System32\Drivers\Null.SYS
0xF9804000 \SystemRoot\System32\Drivers\Beep.SYS
0xF9656000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xF965E000 \SystemRoot\System32\drivers\vga.sys
0xF9806000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF9808000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xF9666000 \SystemRoot\System32\Drivers\Msfs.SYS
0xF966E000 \SystemRoot\System32\Drivers\Npfs.SYS
0xF8D7C000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xF0771000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xF0719000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xF06F1000 \SystemRoot\system32\DRIVERS\netbt.sys
0xF06CF000 \SystemRoot\System32\drivers\afd.sys
0xF93B6000 \SystemRoot\system32\DRIVERS\netbios.sys
0xF06A4000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xF0635000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xF0602000 \SystemRoot\system32\drivers\mfehidk.sys
0xF05E1000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xF93C6000 \SystemRoot\System32\Drivers\Fips.SYS
0xF93D6000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xF967E000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0xF975E000 \SystemRoot\system32\DRIVERS\hidusb.sys
0xF9416000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0xF9762000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0xF976A000 \SystemRoot\system32\DRIVERS\mouhid.sys
0xEFDAF000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xEF36A000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xF9886000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xF8AB0000 \SystemRoot\System32\drivers\Dxapi.sys
0xF969E000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xF9902000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF01F000 \SystemRoot\System32\ialmdnt5.dll
0xBF012000 \SystemRoot\System32\ialmrnt5.dll
0xBF038000 \SystemRoot\System32\ialmdev5.DLL
0xBF060000 \SystemRoot\System32\ialmdd5.DLL
0xEF323000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xEF0AB000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xF986E000 \SystemRoot\System32\Drivers\ParVdm.SYS
0xEF096000 \SystemRoot\system32\drivers\wdmaud.sys
0xF097D000 \SystemRoot\system32\drivers\sysaudio.sys
0xEED46000 \SystemRoot\system32\DRIVERS\srv.sys
0xEE855000 \SystemRoot\System32\Drivers\HTTP.sys
0xEE3A7000 \SystemRoot\System32\Drivers\Fastfat.SYS
0xEE2DC000 \SystemRoot\system32\drivers\kmixer.sys
0x7C900000 \WINDOWS\system32\ntdll.dll

Processes (total 39):
0 System Idle Process
4 System
556 C:\WINDOWS\system32\smss.exe
604 csrss.exe
628 C:\WINDOWS\system32\winlogon.exe
672 C:\WINDOWS\system32\services.exe
684 C:\WINDOWS\system32\lsass.exe
844 C:\WINDOWS\system32\svchost.exe
916 svchost.exe
1008 C:\WINDOWS\system32\svchost.exe
1044 C:\WINDOWS\system32\svchost.exe
1148 svchost.exe
1300 svchost.exe
1476 C:\WINDOWS\system32\spoolsv.exe
1560 svchost.exe
1632 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
1780 C:\WINDOWS\explorer.exe
1808 C:\WINDOWS\b3duZXI\command.exe
1864 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
2024 C:\WINDOWS\system32\svchost.exe
120 C:\Program Files\Viewpoint\Common\ViewpointService.exe
208 C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
1284 C:\WINDOWS\system32\hkcmd.exe
1320 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
1348 C:\Program Files\iTunes\iTunesHelper.exe
1388 C:\Program Files\Messenger\msmsgs.exe
1436 C:\WINDOWS\system32\ctfmon.exe
1848 C:\Program Files\Internet Explorer\iexplore.exe
252 C:\WINDOWS\system32\wscntfy.exe
2068 alg.exe
2572 C:\Program Files\iPod\bin\iPodService.exe
3204 C:\Program Files\Internet Explorer\iexplore.exe
3880 C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
3020 C:\WINDOWS\system32\wuauclt.exe
3484 C:\Documents and Settings\Owner\Desktop\OTL!\OTL.exe
1896 C:\Documents and Settings\Owner\Desktop\RootKit\RKUnhookerLE.EXE
2548 C:\WINDOWS\NOTEPAD.EXE
176 C:\WINDOWS\NOTEPAD.EXE
392 C:\Documents and Settings\Owner\Desktop\MBRChEcK!\MBRCheck.exe

\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)

PhysicalDrive0 Model Number: WDCWD200EB-11CPF0, Rev: 06.04G06

Size Device Name MBR Status
——————————————–
18 GB \\.\PhysicalDrive0 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A


Done!
Hi xadavid,

Don't worry about RKU, we'll try a different scanner in a minute.

First, run OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTL
    PRC - C:\WINDOWS\b3duZXI\command.exe ()
    SRV - (cmdService) – C:\WINDOWS\b3duZXI\command.exe ()
    O2 - BHO: (adsoftinc) - {094bb94a-c86d-fb3e-d158-285dd3da1e41} - C:\WINDOWS\system32\nsn159.dll ()
    O4 - HKCU..\Run: [GetPack24] File not found
    O20 - AppInit_DLLs: (yighkw.dll) - File not found
    O20 - Winlogon\Notify\WgaLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
    O29 - HKLM SecurityProviders - (msansspc.dll) - File not found
    O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\fccyaYOI) - File not found
    [2008/11/12 23:06:25 | 000,687,592 | —- | C] () – C:\WINDOWS\System32\atmtd.dll._
    [2008/11/12 23:06:25 | 000,687,592 | —- | C] () – C:\WINDOWS\System32\atmtd.dll
    [2008/11/11 21:52:31 | 000,881,870 | -HS- | C] () – C:\WINDOWS\System32\IOYayccf.ini2
    [2008/11/11 21:52:30 | 000,881,870 | -HS- | C] () – C:\WINDOWS\System32\IOYayccf.ini
    
    :Files
    yighkw.dll /s
    C:\WINDOWS\system32\msziptools.dll
    C:\Program Files\GetPack\GetPack24.exe
    C:\WINDOWS\b3duZXI
    
    :Commands
    [createrestorepoint]
    [purity]
    [emptytemp]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
===================================================

Please go to: VirusTotal
  • [external image: Posted Image]
  • Click the Browse button and search for the following file: C:\WINDOWS\System32\etmxbhcg.dll
  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

Repeat the process for the following files:
C:\WINDOWS\atid.ini
C:\WINDOWS\ka.ini
C:\WINDOWS\unC326C.dll
C:\WINDOWS\Wininit.ini

Please post the results in your next reply.

===================================================

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

In your next post, please post the following:
  • OTL Log
  • VirusTotal Results
  • GMER Log
Hey NoodleTech, sorry I haven't answered sooner. I wasn't quite sure how I was supposed to post the VirusTotal results, but I just copy and pasted everything I thought was important. I scanned all the files except for " C:\WINDOWS\ka.ini ". It wouldn't scan and whenever I clicked on Send File, it would just take me back to the previous page. Other than that, I got everything else, so here it is. OTL Log: All processes killed ========== OTL ========== No active process named command.exe was found! Service cmdService stopped successfully! Service cmdService deleted successfully! C:\WINDOWS\b3duZXI\command.exe moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{094bb94a-c86d-fb3e-d158-285dd3da1e41}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{094bb94a-c86d-fb3e-d158-285dd3da1e41}\ deleted successfully. C:\WINDOWS\system32\nsn159.dll moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\GetPack24 deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:yighkw.dll deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders:msansspc.dll deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages:C:\WINDOWS\system32\fccyaYOI deleted successfully. C:\WINDOWS\system32\atmtd.dll._ moved successfully. C:\WINDOWS\system32\atmtd.dll moved successfully. C:\WINDOWS\system32\IOYayccf.ini2 moved successfully. C:\WINDOWS\system32\IOYayccf.ini moved successfully. ========== FILES ========== File\Folder yighkw.dll not found. File\Folder C:\WINDOWS\system32\msziptools.dll not found. File\Folder C:\Program Files\GetPack\GetPack24.exe not found. C:\WINDOWS\b3duZXI folder moved successfully. ========== COMMANDS ========== Restore point Set: OTL Restore Point (0) [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 210398 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Guest ->Temp folder emptied: 4802699 bytes ->Temporary Internet Files folder emptied: 8614737 bytes ->Flash cache emptied: 592 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 357854 bytes ->Flash cache emptied: 772 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 145426983 bytes User: Owner ->Temp folder emptied: 54789991 bytes ->Temporary Internet Files folder emptied: 146594244 bytes ->Java cache emptied: 6770240 bytes ->Flash cache emptied: 13513045 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2142714 bytes %systemroot%\System32 .tmp files removed: 3244192 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 16478603 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 9240442 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 37297 bytes RecycleBin emptied: 6387049 bytes Total Files Cleaned = 399.00 mb OTL by OldTimer - Version 3.2.20.6 log created on 02072011_204805 Files\Folders moved on Reboot… File\Folder C:\Documents and Settings\Owner\Local Settings\Temp\~DF1840.tmp not found! File\Folder C:\Documents and Settings\Owner\Local Settings\Temp\~DFA2E.tmp not found! File\Folder C:\Documents and Settings\Owner\Local Settings\Temp\~DFCBDC.tmp not found! C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\M181DK7Q\like[1].htm moved successfully. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\LO9QZJHX\index[3].htm moved successfully. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\AG3GV11S\iframe[1].htm moved successfully. Registry entries deleted on Reboot… VirusTotal Files: File name: etmxbhcg.dll Submission date: 2011-02-09 01:09:26 (UTC) Current status: queued (#83) queued (#83) analysing finished Result: 35/ 43 (81.4%) VT Community not reviewed Safety score: - Compact Print results Antivirus Version Last Update Result AhnLab-V3 2011.02.06.00 2011.02.06 Win-Trojan/Xema.variant AntiVir 7.11.2.104 2011.02.08 TR/Vundo.114688AL Antiy-AVL 2.0.3.7 2011.01.28 Trojan/Win32.Genome.gen Avast 4.8.1351.0 2011.02.08 Win32:Adware-gen Avast5 5.0.677.0 2011.02.08 Win32:Adware-gen AVG 10.0.0.1190 2011.02.09 Agent.ARFK BitDefender 7.2 2011.02.09 Application.Generic.205060 CAT-QuickHeal 11.00 2011.02.08 Trojan.Agent.ATV ClamAV 0.96.4.0 2011.02.09 - Commtouch 5.2.11.5 2011.02.08 - Comodo 7622 2011.02.08 TrojWare.Win32.Vundo.114688AL0 DrWeb 5.0.2.03300 2011.02.09 Trojan.Click1.4399 Emsisoft 5.1.0.2 2011.02.08 Trojan.Win32.Genome!IK eSafe 7.0.17.0 2011.02.08 - eTrust-Vet 36.1.8147 2011.02.08 Win32/Vundo.BOI F-Prot 4.6.2.117 2011.02.04 - F-Secure 9.0.16160.0 2011.02.09 Application.Generic.205060 Fortinet 4.2.254.0 2011.02.08 - GData 21 2011.02.09 Application.Generic.205060 Ikarus T3.1.1.97.0 2011.02.08 Trojan.Win32.Genome Jiangmin 13.0.900 2011.02.08 Trojan/Genome.upg K7AntiVirus 9.81.3788 2011.02.08 - Kaspersky 7.0.0.125 2011.02.09 Trojan.Win32.Genome.awob McAfee 5.400.0.1158 2011.02.09 Spyware-JuanSearch McAfee-GW-Edition 2010.1C 2011.02.08 Spyware-JuanSearch Microsoft 1.6502 2011.02.08 Trojan:Win32/Vundo.gen!AL NOD32 5857 2011.02.08 Win32/Adware.SuperJuan Norman 6.07.03 2011.02.08 W32/Virtumonde.BSCO nProtect 2011-01-27.01 2011.02.02 - Panda 10.0.3.5 2011.02.08 Adware/Antivirus2009ARY PCTools 7.0.3.5 2011.02.08 Downloader.MisleadApp Prevx 3.0 2011.02.09 High Risk Fraudulent Security Program Rising 23.44.01.06 2011.02.08 Trojan.Win32.Generic.1273D59E Sophos 4.61.0 2011.02.09 Troj/Virtum-Gen SUPERAntiSpyware 4.40.0.1006 2011.02.09 Adware.Vundo Variant Symantec 20101.3.0.103 2011.02.09 Downloader.MisleadApp TheHacker 6.7.0.1.126 2011.02.08 Trojan/Genome.dxjz TrendMicro 9.200.0.1012 2011.02.08 TROJ_VUNDO.AEC TrendMicro-HouseCall 9.200.0.1012 2011.02.09 TROJ_VUNDO.AEC VBA32 3.12.14.3 2011.02.08 Win32.Adware.SuperJuan VIPRE 8354 2011.02.09 Trojan.Win32.Generic!BT ViRobot 2011.2.8.4299 2011.02.08 - VirusBuster 13.6.189.0 2011.02.08 Trojan.Vundo!n1R72R0vmDM Additional informationShow all MD5 : d73856b5cbb897893b0299dbc8bfbed9 SHA1 : 85e5594a44f2753cd91d594d345febdcc8587229 SHA256: 5982f5d82bebce562d06bb0ac5b63b7fc86384fdb6251550e59603b4627a75d8 File name: atid.ini Submission date: 2011-02-09 01:19:46 (UTC) Current status: queued queued analysing finished Result: 0/ 43 (0.0%) VT Community not reviewed Safety score: - Compact Print results Antivirus Version Last Update Result AhnLab-V3 2011.02.06.00 2011.02.06 - AntiVir 7.11.2.104 2011.02.08 - Antiy-AVL 2.0.3.7 2011.01.28 - Avast 4.8.1351.0 2011.02.08 - Avast5 5.0.677.0 2011.02.08 - AVG 10.0.0.1190 2011.02.09 - BitDefender 7.2 2011.02.09 - CAT-QuickHeal 11.00 2011.02.08 - ClamAV 0.96.4.0 2011.02.09 - Commtouch 5.2.11.5 2011.02.08 - Comodo 7622 2011.02.08 - DrWeb 5.0.2.03300 2011.02.09 - Emsisoft 5.1.0.2 2011.02.08 - eSafe 7.0.17.0 2011.02.08 - eTrust-Vet 36.1.8147 2011.02.08 - F-Prot 4.6.2.117 2011.02.04 - F-Secure 9.0.16160.0 2011.02.09 - Fortinet 4.2.254.0 2011.02.08 - GData 21 2011.02.09 - Ikarus T3.1.1.97.0 2011.02.08 - Jiangmin 13.0.900 2011.02.08 - K7AntiVirus 9.81.3788 2011.02.08 - Kaspersky 7.0.0.125 2011.02.09 - McAfee 5.400.0.1158 2011.02.09 - McAfee-GW-Edition 2010.1C 2011.02.08 - Microsoft 1.6502 2011.02.08 - NOD32 5857 2011.02.08 - Norman 6.07.03 2011.02.08 - nProtect 2011-01-27.01 2011.02.02 - Panda 10.0.3.5 2011.02.08 - PCTools 7.0.3.5 2011.02.08 - Prevx 3.0 2011.02.09 - Rising 23.44.01.06 2011.02.08 - Sophos 4.61.0 2011.02.09 - SUPERAntiSpyware 4.40.0.1006 2011.02.09 - Symantec 20101.3.0.103 2011.02.09 - TheHacker 6.7.0.1.126 2011.02.08 - TrendMicro 9.200.0.1012 2011.02.08 - TrendMicro-HouseCall 9.200.0.1012 2011.02.09 - VBA32 3.12.14.3 2011.02.08 - VIPRE 8354 2011.02.09 - ViRobot 2011.2.8.4299 2011.02.08 - VirusBuster 13.6.189.0 2011.02.08 - Additional informationShow all MD5 : f5adba722cef83d6c026442aa7281d29 SHA1 : 86a149f459ed9140f61f2591f71ee7af4b992704 SHA256: ea9bb8a118ded507dad25425bfacaf4b3acf49bc3577b41306a6f5ef2539be32 File name: Wininit.ini Submission date: 2011-02-09 01:34:57 (UTC) Current status: queued queued analysing finished Result: 0/ 43 (0.0%) VT Community not reviewed Safety score: - Compact Print results Antivirus Version Last Update Result AhnLab-V3 2011.02.06.00 2011.02.06 - AntiVir 7.11.2.104 2011.02.08 - Antiy-AVL 2.0.3.7 2011.01.28 - Avast 4.8.1351.0 2011.02.08 - Avast5 5.0.677.0 2011.02.08 - AVG 10.0.0.1190 2011.02.09 - BitDefender 7.2 2011.02.09 - CAT-QuickHeal 11.00 2011.02.08 - ClamAV 0.96.4.0 2011.02.09 - Commtouch 5.2.11.5 2011.02.08 - Comodo 7622 2011.02.08 - DrWeb 5.0.2.03300 2011.02.09 - Emsisoft 5.1.0.2 2011.02.09 - eSafe 7.0.17.0 2011.02.08 - eTrust-Vet 36.1.8147 2011.02.08 - F-Prot 4.6.2.117 2011.02.04 - F-Secure 9.0.16160.0 2011.02.09 - Fortinet 4.2.254.0 2011.02.08 - GData 21 2011.02.09 - Ikarus T3.1.1.97.0 2011.02.08 - Jiangmin 13.0.900 2011.02.08 - K7AntiVirus 9.81.3788 2011.02.08 - Kaspersky 7.0.0.125 2011.02.09 - McAfee 5.400.0.1158 2011.02.09 - McAfee-GW-Edition 2010.1C 2011.02.08 - Microsoft 1.6502 2011.02.08 - NOD32 5857 2011.02.08 - Norman 6.07.03 2011.02.08 - nProtect 2011-01-27.01 2011.02.02 - Panda 10.0.3.5 2011.02.08 - PCTools 7.0.3.5 2011.02.08 - Prevx 3.0 2011.02.09 - Rising 23.44.01.06 2011.02.08 - Sophos 4.61.0 2011.02.09 - SUPERAntiSpyware 4.40.0.1006 2011.02.09 - Symantec 20101.3.0.103 2011.02.09 - TheHacker 6.7.0.1.126 2011.02.08 - TrendMicro 9.200.0.1012 2011.02.08 - TrendMicro-HouseCall 9.200.0.1012 2011.02.09 - VBA32 3.12.14.3 2011.02.08 - VIPRE 8354 2011.02.09 - ViRobot 2011.2.8.4299 2011.02.08 - VirusBuster 13.6.189.0 2011.02.08 - Additional informationShow all MD5 : a815dcb3764c6494e79e685e7297d94c SHA1 : e2402fe1247e371e416eab0d5b60a0716412387c SHA256: 45ac7abad22a16114fd43af64a1dd71b259ab553777931e56ef568fd1382b609 File name: unC326C.dll Submission date: 2011-02-09 01:24:21 (UTC) Current status: finished Result: 0 /43 (0.0%) VT Community not reviewed Safety score: - Compact Print results Antivirus Version Last Update Result AhnLab-V3 2011.02.06.00 2011.02.06 - AntiVir 7.11.2.104 2011.02.08 - Antiy-AVL 2.0.3.7 2011.01.28 - Avast 4.8.1351.0 2011.02.08 - Avast5 5.0.677.0 2011.02.08 - AVG 10.0.0.1190 2011.02.09 - BitDefender 7.2 2011.02.09 - CAT-QuickHeal 11.00 2011.02.08 - ClamAV 0.96.4.0 2011.02.09 - Commtouch 5.2.11.5 2011.02.08 - Comodo 7622 2011.02.08 - DrWeb 5.0.2.03300 2011.02.09 - Emsisoft 5.1.0.2 2011.02.08 - eSafe 7.0.17.0 2011.02.08 - eTrust-Vet 36.1.8147 2011.02.08 - F-Prot 4.6.2.117 2011.02.04 - F-Secure 9.0.16160.0 2011.02.09 - Fortinet 4.2.254.0 2011.02.08 - GData 21 2011.02.09 - Ikarus T3.1.1.97.0 2011.02.08 - Jiangmin 13.0.900 2011.02.08 - K7AntiVirus 9.81.3788 2011.02.08 - Kaspersky 7.0.0.125 2011.02.09 - McAfee 5.400.0.1158 2011.02.09 - McAfee-GW-Edition 2010.1C 2011.02.08 - Microsoft 1.6502 2011.02.08 - NOD32 5857 2011.02.08 - Norman 6.07.03 2011.02.08 - nProtect 2011-01-27.01 2011.02.02 - Panda 10.0.3.5 2011.02.08 - PCTools 7.0.3.5 2011.02.08 - Prevx 3.0 2011.02.09 - Rising 23.44.01.06 2011.02.08 - Sophos 4.61.0 2011.02.09 - SUPERAntiSpyware 4.40.0.1006 2011.02.09 - Symantec 20101.3.0.103 2011.02.09 - TheHacker 6.7.0.1.126 2011.02.08 - TrendMicro 9.200.0.1012 2011.02.08 - TrendMicro-HouseCall 9.200.0.1012 2011.02.09 - VBA32 3.12.14.3 2011.02.08 - VIPRE 8354 2011.02.09 - ViRobot 2011.2.8.4299 2011.02.08 - VirusBuster 13.6.189.0 2011.02.08 - Additional informationShow all MD5 : 69b49f5a171581eb5f222b5c7d725907 SHA1 : 63a3e76163a3af6dcb833933743320e7935db0f3 SHA256: 297250848834d6ee61a7fb0127dd7e83c15f92e83dfa70f874e89da23a20d141

Attachments:

Hi xadavid,

Don't worry about the file not scanning in VirusTotal.

Please do the following:

Run OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :Files
    C:\WINDOWS\System32\etmxbhcg.dll
    
    :Commands
    [createrestorepoint]
    [purity]
    [emptytemp]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
===================================================

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.

Also please describe how your computer behaves at the moment.
Hey NoodleTech. Well my system still feels about the same. Sluggish still and I haven't really noticed a big difference, but maybe I haven't noticed? :o Anyway, I ran OTL and Malawarebytes and here's what I got. OTL LOG: All processes killed ========== FILES ========== File\Folder C:\WINDOWS\System32\etmxbhcg.dll not found. ========== COMMANDS ========== Restore point Set: OTL Restore Point (0) [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Guest ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 0 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Owner ->Temp folder emptied: 1830587 bytes ->Temporary Internet Files folder emptied: 14677408 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 577 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 16.00 mb OTL by OldTimer - Version 3.2.20.6 log created on 02082011_184924 Files\Folders moved on Reboot… File\Folder C:\Documents and Settings\Owner\Local Settings\Temp\~DF319E.tmp not found! File\Folder C:\Documents and Settings\Owner\Local Settings\Temp\~DF3D7A.tmp not found! C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\V611SG77\ads[6].htm moved successfully. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\PN29USQK\like[1].htm moved successfully. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\HI2PEFTI\ads[6].htm moved successfully. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\HI2PEFTI\iframe[1].htm moved successfully. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\3QSHK4BR\ads[8].htm moved successfully. C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\3QSHK4BR\index[3].htm moved successfully. Registry entries deleted on Reboot… Malawarebytes Results: Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5725 Windows 5.1.2600 Service Pack 2 Internet Explorer 8.0.6001.18702 2/8/2011 7:17:16 PM mbam-log-2011-02-08 (19-17-16).txt Scan type: Quick scan Objects scanned: 155843 Time elapsed: 6 minute(s), 55 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 17 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 5 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A63E645F-13BD-45ED-B15F-6E8C1BD57279} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} (Rogue.WinAntiVirus) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920} (Trojan.Downloader) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A394E835-C8D6-4B4B-884B-D2709059F3BE} (Trojan.Network.Monitor) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mwcjwkluwb (Adware.AdRotator) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\GetPack (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTW ARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DPS (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iCheck (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR (Trojan.DNSChanger) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Network Monitor (Trojan.Service) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\documents and settings\Owner\application data\gadcom (Trojan.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\system32\config\systemprofile\application data\gadcom (Trojan.Agent) -> Quarantined and deleted successfully. c:\documents and settings\localservice\application data\NetMon (Trojan.NetMon) -> Quarantined and deleted successfully. c:\documents and settings\Owner\application data\Twain (Trojan.Matcash) -> Quarantined and deleted successfully. c:\program files\network monitor (Trojan.DNSChanger) -> Quarantined and deleted successfully. Files Infected: c:\WINDOWS\system32\mwcjwkluwb.exe (Adware.AdRotator) -> Quarantined and deleted successfully. c:\documents and settings\localservice\application data\NetMon\domains.txt (Trojan.NetMon) -> Quarantined and deleted successfully. c:\documents and settings\localservice\application data\NetMon\log.txt (Trojan.NetMon) -> Quarantined and deleted successfully.
Hi xadavid,

Please read through the instructions to familiarize yourself with what to expect when the tool runs.

It is vitally important that combofix is renamed before it has even started to download

Please download ComboFix from Link 1or Link 2 to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, before you save it to your desktop, rename Combofix to jgh.exe

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on ComboFix.exe (jgh.exe in your case) & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • combofix log
How is the computer?

Thanks
Hey NoodleTech, just want to say thanks for all your help so far!

I ran Combofix and everything like you said however, my computer is still running more or less the same.
Here's the log:

ComboFix 11-02-11.01 - Owner 02/10/2011 23:10:18.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.254.127 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\jgh.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\9521846.exe
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\accessories\cup.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\accessories\customer_cup.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\accessories\heart.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\accessories\menu_down.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\accessories\menu_up.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\accessories\plates.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\accessories\ticket.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\accessories\tray.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\audio\music\mainmenumusic.ogg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\audio\sfx\sfx_bring_check_1_snd.ogg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\audio\sfx\sfx_deliver_food_1_snd.ogg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\audio\sfx\sfx_deliver_order_1_snd.ogg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\audio\sfx\sfx_diner.ogg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\audio\sfx\sfx_dish_dropoff_1_snd.ogg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\audio\sfx\sfx_food_ready_1_snd.ogg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\audio\sfx\sfx_gain_heart_1.ogg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\audio\sfx\sfx_get_drinks_1_snd.ogg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\audio\sfx\sfx_party_arrive_1_snd.ogg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\audio\sfx\sfx_pencil_write_2.ogg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\audio\sfx\sfx_pickup_food_1_snd.ogg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\audio\sfx\sfx_rollover_1.ogg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\audio\sfx\sfx_seat_people_snd.ogg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\backgrounds\choosedifficulty.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\backgrounds\credits.jpg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\backgrounds\flo_lose.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\backgrounds\flo_win.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\backgrounds\help1.jpg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\backgrounds\help2.jpg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\backgrounds\highscores.jpg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\backgrounds\levelintro.jpg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\backgrounds\levelintro_mask.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\backgrounds\levelover.jpg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\backgrounds\levelover_mask.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\backgrounds\mainmenu.jpg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\backgrounds\popup.jpg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\backgrounds\popup_mask.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\backgrounds\upgradegrid.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\backgrounds\upgradetitle.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\backgrounds\upsell.jpg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\arrowleft_blue.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\arrowleft_yellow.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\arrowright_blue.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\arrowright_yellow.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\back_blue.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\back_yellow.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\backchalk.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\backchalkup.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\backtomenu_blue.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\backtomenu_yellow.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\cancel.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\cancelup.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\career.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\career_over.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\close.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\closeup.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\continue.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\continueover.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\credits_blue.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\credits_yellow.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\download_blue.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\download_yellow.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\easy.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\easy_over.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\endlessshift.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\endlessshift_over.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\hard.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\hard_over.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\help.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\help_over.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\highscores.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\highscores_over.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\instructions_blue.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\instructions_yellow.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\letsplay.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\letsplayover.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\medium.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\medium_over.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\moreinfo.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\moreinfoup.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\off.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\off_on.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\on.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\on_on.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\pause.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\pauseover.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\quit.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\quitgame.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\quitgameover.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\quitover.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\resumegame.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\resumegameover.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\submit.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\submitup.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\tryagain.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\tryagainover.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\upgrade_over.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\upgrade_up.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\viewglobal.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\viewglobalup.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\viewhighscore.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\viewhighscoreon.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\viewlocal.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\buttons\viewlocalup.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\comics\webcomic.jpg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\config\career.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\config\customer.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\config\endless.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\config\global.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\config\powerups.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\cook\cook.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\cook\cook.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\cook\stove.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\cursor\arrow.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\cursor\click.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\cursor\click2.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\cursor\grab.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\cursor\open.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\old_male\anim.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\old_male\blue\anim.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\old_male\blue\anim.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\old_male\blue\sit_legs.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\old_male\green\anim.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\old_male\green\anim.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\old_male\green\sit_legs.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\old_male\purple\anim.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\old_male\purple\anim.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\old_male\purple\sit_legs.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\old_male\red\anim.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\old_male\red\anim.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\old_male\red\sit_legs.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\old_male\yellow\anim.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\old_male\yellow\anim.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\old_male\yellow\sit_legs.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\young_female\anim.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\young_female\blue\anim.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\young_female\blue\anim.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\young_female\blue\sit_legs.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\young_female\green\anim.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\young_female\green\anim.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\young_female\green\sit_legs.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\young_female\purple\anim.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\young_female\purple\anim.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\young_female\purple\sit_legs.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\young_female\red\anim.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\young_female\red\anim.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\young_female\red\sit_legs.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\young_female\yellow\anim.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\young_female\yellow\anim.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\customers\young_female\yellow\sit_legs.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\flo\idle.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\flo\idle.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\flo\lower.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\flo\lower.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\flo\upper.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\flo\upper.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\fonts\arial.mvec
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\fonts\komikaaxis.mvec
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\furniture\chair.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\furniture\chair.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\furniture\dirt2top.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\furniture\dirt4top.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\furniture\dishcart.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\furniture\dishcart.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\furniture\drinkstation_off.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\furniture\drinkstation_on1.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\furniture\drinkstation_on2.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\furniture\ticketstation.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\furniture\ticketstation.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\hiscore\arrowdown.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\hiscore\arrowdownon.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\hiscore\arrowleft.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\hiscore\arrowlefton.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\hiscore\arrowright.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\hiscore\arrowrighton.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\hiscore\arrowup.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\hiscore\arrowupon.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\hiscore\p1icon.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\hiscore\textedit.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\hiscore\title.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\layouts\endless_1_1.txt
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\layouts\endless_1_1_a.txt
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\layouts\endless_1_1_b.txt
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\layouts\endless_1_1_c.txt
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\layouts\endless_1_2.txt
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\layouts\endless_1_2_a.txt
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\layouts\endless_1_2_b.txt
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\layouts\endless_1_2_c.txt
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\layouts\endless_1_2_d.txt
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\layouts\endless_1_3.txt
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\layouts\endless_1_3_a.txt
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\layouts\endless_1_3_b.txt
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\layouts\endless_1_3_c.txt
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\layouts\endless_1_3_d.txt
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\layouts\fifth_level_diner.txt
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\layouts\first_level_diner.txt
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\layouts\fourth_level_diner.txt
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\layouts\second_level_diner.txt
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\playfirst_logo.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\restaurants\diner\background.jpg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\restaurants\diner\food\food1.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\restaurants\diner\food\food1.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\restaurants\diner\food\food2.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\restaurants\diner\food\food2.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\restaurants\diner\food\food3.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\restaurants\diner\food\food3.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\restaurants\diner\frames\upgrade_0001.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\restaurants\diner\tables\2top.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\restaurants\diner\tables\2top.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\restaurants\diner\tables\4top.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\restaurants\diner\tables\4top.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\restaurants\diner\upgrades.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\restaurants\tableshadow.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\choosedifficulty.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\chooseplayer.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\chooserestaurant.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\credits.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\game.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\gothighscore.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\help.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\help2.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\hiscore.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\hiscoreinfo.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\hiscoresubmit.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\levelintro.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\levelover.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\loading.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\mainloop.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\mainmenu.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\ok.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\pause.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\style.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\tutorialintro.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\upgrade.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\upsell.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\webcomic.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\scripts\yesno.lua
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\splash\aol_logo.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\splash\gamelabsplash.jpg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\splash\playfirst_logo.jpg
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\strings.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\angersmoke.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\angersmoke.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\chairflags.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\chairflags.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\check.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\checkmark.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\clock.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\closed.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\closingtime.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\coinflip.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\coinflip.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\dollar.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\doodles\coffee.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\doodles\tables.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\doodles\wallpaper.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\expert.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\expertscore.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\foodpoof.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\foodpoof.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\fork_timer.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\goalcompleted.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\heartgrow.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\heartgrow.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\jar.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\jar.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\level.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\level_career.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\score.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\sound.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\staroff.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\staron.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\tablenumber.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\tablenumberup.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\traynumber.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\tutorial_character.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\tutorialarrow.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\tutorialbox.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\upgradeanim.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\upgradeanim.xml
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\upgrades\drinks.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\upgrades\maitred.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\upgrades\oven.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\upgrades\select.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\upgrades\shoes.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\upgrades\stereo.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\assets\ui\upgrades\table.png
c:\windows\Downloaded Program Files\DinerDash.1.0.0.80\dinerdash.exe
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\expert
c:\windows\expert\XSNCR.INI
c:\windows\wiaserviv.log

.
((((((((((((((((((((((((( Files Created from 2011-01-11 to 2011-02-11 )))))))))))))))))))))))))))))))
.

2011-02-09 02:11 . 2011-02-09 02:11 ——– d—–w- c:\documents and settings\Owner\Application Data\Malwarebytes
2011-02-09 02:11 . 2010-12-21 02:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-09 02:11 . 2011-02-09 02:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-02-09 02:11 . 2010-12-21 02:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-02-09 02:11 . 2011-02-09 02:11 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-02-08 04:48 . 2011-02-08 04:48 ——– d—–w- C:\_OTL
2011-02-08 04:46 . 2011-02-08 04:46 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2011-02-08 04:45 . 2011-02-08 04:45 ——– d—–w- C:\c8d930e8f03ad7600d
2011-02-08 04:44 . 2011-02-08 04:48 ——– d—–w- C:\f144264f88f72288e88f
2011-02-05 11:12 . 2011-02-05 11:12 ——– d—–w- c:\windows\ServicePackFiles
2011-02-05 11:10 . 2011-02-05 20:03 ——– d—–w- c:\windows\ie8updates
2011-02-05 11:08 . 2011-02-09 03:30 ——– d—–w- c:\program files\softendo.com
2011-02-05 09:06 . 2010-05-06 10:41 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2011-02-05 09:06 . 2010-05-06 10:41 743424 -c—-w- c:\windows\system32\dllcache\iedvtool.dll
2011-02-05 09:06 . 2010-05-06 10:41 247808 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2011-02-05 04:09 . 2004-08-04 07:01 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2011-02-05 04:09 . 2004-08-04 07:01 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2011-02-05 03:27 . 2011-02-05 03:31 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2011-02-05 02:46 . 2011-02-05 02:46 ——– d-sh–w- c:\documents and settings\Owner\PrivacIE
2011-02-05 01:06 . 2004-08-04 08:56 21504 -c–a-w- c:\windows\system32\dllcache\hidserv.dll
2011-02-05 01:06 . 2004-08-04 08:56 21504 —-a-w- c:\windows\system32\hidserv.dll
2011-02-05 00:56 . 2004-08-04 06:58 14848 -c–a-w- c:\windows\system32\dllcache\kbdhid.sys
2011-02-05 00:56 . 2004-08-04 06:58 14848 —-a-w- c:\windows\system32\drivers\kbdhid.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-03-06 50528]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2002-12-04 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2002-12-04 114688]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-11 289576]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-04-05 171448]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Common Files\\AOL\\1147220571\\ee\\aim6.exe"=
"c:\\Program Files\\Common Files\\AOL\\1147220571\\ee\\aolsoftware.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\StubInstaller.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

S3 m4301a;Linksys Wireless-B USB Network Adapter v4.0 Driver;c:\windows\system32\drivers\m4301A.sys [8/14/2005 12:40 AM 83552]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2/8/2011 6:11 PM 38224]
S3 Normandy;Normandy SR2; [x]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 11:32 128512 —-a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder

2008-09-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} - hxxp://comcast.oberon-media.com/online2/diner_dash/DinerDash.1.0.0.80.cab
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Search Protection - c:\program files\Yahoo!\Search Protection\SearchProtection.exe
SafeBoot-mcmscsvc
SafeBoot-MCODS



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-10 23:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-299502267-2147131803-1801674531-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:a7,08,5e,6e,6c,84,71,70,ad,5b,92,07,ac,93,c4,99,ba,fd,bd,f2,db,b2,9a,
69,3d,f3,99,aa,53,21,af,cd,db,a9,b0,93,4e,cb,72,59,b4,96,35,39,ae,97,11,14,\
"??"=hex:63,bf,32,ef,66,28,e1,6a,a1,b6,b8,a1,09,9b,f3,73

[HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\Clients\R a s ötdwAssignDefault ÿsUsage: Remotej
ÿvs ÌÌÌinÌÌÌlö9söt, dwU‹ì ÿTUsage:…ötdwU‹ìNumberOfRÌÌÌs: dwRÌÌÌs Ì̃øxr=.\èuöN u m b e r O f R i n gös ]
"EnableForRas?,???????m????›U?????"=dword:00000000
"EnableForRoutin??"=dword:00000000
.
Completion time: 2011-02-10 23:24:45
ComboFix-quarantined-files.txt 2011-02-11 07:24

Pre-Run: 1,689,575,424 bytes free
Post-Run: 1,661,419,520 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - ADFB466B362037D984A97550D8C09B99
Next, create this batch file.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad.
Do Not copy the word CODE

@echo off
reg query "HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000" /s > result.txt
start result.txt
del %0

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "look.bat"
  • Click save

You will have a new file on your desktop called look.bat

Double click look.bat to run it. A when it's done a notepad called result.txt will open. Please post it's contents.
Hey NoodleTech, I ran notepad and here are the results that popped up: ! REG.EXE VERSION 3.0 HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000 AttachedTo REG_SZ COM3 FriendlyName REG_SZ BCM V.90 56K Modem UINumber REG_DWORD 0x1 LoggingPath REG_SZ C:\WINDOWS\ModemLog_BCM V.90 56K Modem.txt DeviceType REG_BINARY 02 PortConfigDialog REG_SZ serialui.dll AdvancedSettings REG_SZ msports.dll,SerialDisplayAdvancedSettings Manufacturer REG_SZ BCM Model REG_SZ BCM V.90 56K Modem EnumPropPages32 REG_SZ modemui.dll,ModemPropPagesProvider ID REG_BINARY D1280400 PermanentGuid REG_BINARY EA12A7B6C1F90E43AC94CA7982B06D25 ConfigDialog REG_SZ modemui.dll PortSubClass REG_BINARY 02 CodecType REG_BINARY 15 VoiceEnumerator REG_SZ serwave.vxd VoiceProfile REG_BINARY 23230102 ForwardDelay REG_BINARY 8813 SpeakerPhoneSpecs REG_BINARY FF00000001000000FF00000001000000 CallerIDPrivate REG_SZ P CallerIDOutSide REG_SZ O VariableTerminator REG_SZ AbortPlay REG_SZ TerminatePlay REG_SZ TerminateRecord REG_SZ Properties REG_BINARY C0010000FF000000FF000000070000000F000000F703000000100E00C0DA0000 InactivityScale REG_BINARY 0A000000 Reset REG_SZ AT&F InfPath REG_SZ mdmbcmsm.inf InfSection REG_SZ BCM4211_PCI.Modem InfSectionExt REG_SZ .NT ProviderName REG_SZ Microsoft DriverDateData REG_BINARY 008062C5C001C101 DriverDate REG_SZ 7-1-2001 DriverVersion REG_SZ 5.1.2535.0 MatchingDeviceId REG_SZ pci\ven_14e4&dev_4212&subsys_000214e4 DriverDesc REG_SZ BCM V.90 56K Modem ResponsesKeyName REG_SZ BCM V.90 56K Modem::BCM::Microsoft Default REG_BINARY 3C000000000000000000000001000000D3010000 DCB REG_BINARY 1C00000000C201001520000000000A000A0008000011130000000000 MSCurrentCountry REG_DWORD 0xb5 CountryList REG_BINARY 000407090A0F1416191B202526272B2D2E313335373C3D46494F50515253545758596168696C737B 7E7F8284858788898A8B8C989C9FA0A5A6A9AEB4B5B7B8BBBC LastCloseTime REG_BINARY 88367E3A ModemProfile REG_BINARY 00B50000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 0000000000000000000AE33520A00002B0D0A08034602060E5F328A000030460849A046000A111300 07000203286B0101071B0F5F072F02230000FF00001E0005000A0A06008100002B0D0A08034602060 E5F328A000030460849A046000A11130007000203286B0101071B0F5F072F02230000FF00001E0005 000A0A060081000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000000000000000000000000000002F460 0000F940000 CheckedForCountrySelect REG_DWORD 0x1 HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\Answer 1 REG_SZ ATA HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\Clients HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\Clients\Ras EnableForRas REG_DWORD 0x0 EnableForRouting REG_DWORD 0x0 HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\Clients\Ras????????t????›?????????????,??ì????????????????›???s??????NumberOfRin?s EnableForRas?,???????m????›U????? REG_DWORD 0x0 EnableForRoutin?? REG_DWORD 0x0 HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\CloseHandset 1 REG_SZ at+vls=0 2 REG_SZ at+fclass=0 HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\EnableCallerID 1 REG_SZ at+vcid=1 HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\EnableDistinctiveRing 1 REG_SZ at+vdr=1,10 HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\Fax HardwareFlowControl REG_SZ 1 SetupCommand REG_SZ ATS7=60&K3 HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\Fax\Class1 HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\Fax\Class1\AdaptiveAnswer ModemResponseFaxDetect REG_SZ FAX ModemResponseDataConnect REG_SZ CONNECT ModemResponseDataDetect REG_SZ DATA ModemResponseFaxConnect REG_SZ CONNECT HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\Fax\Class1\AdaptiveAnswer\AnswerCommand 1 REG_SZ AT 2 REG_SZ AT &F S0=0 E0 V1 S95=0 &D2 3 REG_SZ AT L1 M1 &K3 4 REG_SZ AT X4 5 REG_SZ AT+FCLASS=1 6 REG_SZ AT+FAA=1 7 REG_SZ ATA HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\Fax\Class2 HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\Fax\Class2\AdaptiveAnswer ModemResponseFaxDetect REG_SZ FAX ModemResponseDataConnect REG_SZ CONNECT ModemResponseFaxConnect REG_SZ CONNECT ModemResponseDataDetect REG_SZ DATA HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\Fax\Class2\AdaptiveAnswer\AnswerCommand 1 REG_SZ AT 2 REG_SZ AT &F S0=0 E0 V1 S95=0 &D2 3 REG_SZ AT L1 M1 &K3 4 REG_SZ AT X4 5 REG_SZ AT+FCLASS=2 6 REG_SZ AT+FAA=1 7 REG_SZ ATA HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\Fax\Class2_0 HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\Fax\Class2_0\AdaptiveAnswer ModemResponseFaxDetect REG_SZ FAX ModemResponseDataConnect REG_SZ CONNECT ModemResponseDataDetect REG_SZ DATA ModemResponseFaxConnect REG_SZ CONNECT HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\Fax\Class2_0\AdaptiveAnswer\AnswerCommand 1 REG_SZ AT 2 REG_SZ AT &F S0=0 E0 V1 S95=0 &D2 3 REG_SZ AT L1 M1 &K3 4 REG_SZ AT X4 5 REG_SZ AT+FCLASS=2.0 6 REG_SZ AT+FAA=1 7 REG_SZ ATA HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\GenerateDigit 1 REG_SZ at+vts= HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\HandsetSetPlayFormat 1 REG_SZ at+fclass=8 2 REG_SZ at+vsm=128 HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\HandsetSetRecordFormat 1 REG_SZ at+fclass=8 2 REG_SZ at+vsm=128 HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\Hangup 1 REG_SZ ATH HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\Init 1 REG_SZ AT 2 REG_SZ AT &F E0 V1 &D2 &C1 S95=47 S0=0 HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\LineSetPlayFormat 1 REG_SZ at+fclass=8 2 REG_SZ at+vsm=128,8000,128,0 HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\LineSetRecordFormat 1 REG_SZ at+fclass=8 2 REG_SZ at+vsm=128,8000,128,0 HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\Monitor 1 REG_SZ ATS0=0 2 REG_SZ None HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\OpenHandset 1 REG_SZ at+fclass=8 2 REG_SZ at+vls=3 HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\Settings Prefix REG_SZ AT Terminator REG_SZ DialPrefix REG_SZ D DialSuffix REG_SZ ; SpeakerVolume_Low REG_SZ L0 SpeakerVolume_Med REG_SZ L2 SpeakerVolume_High REG_SZ L3 SpeakerMode_Off REG_SZ M0 SpeakerMode_Dial REG_SZ M1 SpeakerMode_On REG_SZ M2 SpeakerMode_Setup REG_SZ M3 FlowControl_Off REG_SZ &K0 FlowControl_Hard REG_SZ &K3 FlowControl_Soft REG_SZ &K4 ErrorControl_On REG_SZ \N3 ErrorControl_Off REG_SZ \N0 ErrorControl_Forced REG_SZ \N2 Compression_On REG_SZ %C3 Compression_Off REG_SZ %C0 Modulation_CCITT REG_SZ B0 Modulation_Bell REG_SZ B1 SpeedNegotiation_Off REG_SZ N0\J1 SpeedNegotiation_On REG_SZ N1\J1 Pulse REG_SZ P Tone REG_SZ T Blind_Off REG_SZ X4 Blind_On REG_SZ X3 CallSetupFailTimer REG_SZ S7=<#> InactivityTimeout REG_SZ S30=<#> HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\StartPlay 1 REG_SZ at+fclass=8 2 REG_SZ at+vsd=128,0 3 REG_SZ at+vtx HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\StartRecord 1 REG_SZ at+fclass=8 2 REG_SZ at+vsd=128,50 3 REG_SZ at+vrx HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\StopPlay 1 REG_SZ None 2 REG_SZ NoResponse HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\StopRecord 1 REG_SZ None 2 REG_SZ NoResponse HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\VoiceAnswer 1 REG_SZ at+fclass=8 2 REG_SZ at+vls=3 HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\VoiceDialNumberSetup 1 REG_SZ at+fclass=8 2 REG_SZ at+vls=0 3 REG_SZ at+vrn=10 4 REG_SZ at+vra=0 HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\VoiceToDataAnswer 1 REG_SZ at+fclass=0 2 REG_SZ ata HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\WaveDriver WaveHardwareID REG_SZ HALFDUPLEX XformModule REG_SZ umdmxfrm.dll XformID REG_BINARY 0400 BaudRate REG_BINARY 00C20100 WaveDevices REG_BINARY 0100 WaveInstance REG_DWORD 0x0 HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\WaveDriver\Enumerated Started REG_DWORD 0x1
Hi xadavid,

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 23.
  • Scroll down to where it says "The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • In the pull down menu next to Platform select Windows
  • Check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement"
  • Click Continue
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u23-windows-i586-p.exe to install the newest version.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are three options in the window to clear the cache - Leave all 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.
===================================================

I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.
===================================================

Update Adobe Reader
Earlier versions of Adobe Reader have known security flaws so it is recommended that you update your copy
  • Go to Start > Control Panel > Add/Remove Programs
  • Remove ALL instances of Adobe Reader
  • Re-boot your computer as required.
  • Once ALL versions of Adobe Reader have been uninstalled, visit: <> and download the latest version of Adobe Reader
Alternative Option: after uninstalling Adobe Reader, you could try installing Foxit Reader from >here< Foxit Reader has fewer add-ons therefore loads more quickly.
Hey NoodleTech, I updated Java and Adobe Reader. Also, when I did the Esat scan, I couldn't find the details tab but instead I just saved it to a txt file. Here's what I got: C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4144.0.4\setup.exe probably a variant of Win32/Agent.HZHBURL trojan C:\Documents and Settings\Owner\My Documents\My Stuff\Install_AIM.exe Win32/Adware.WBug.A application C:\_OTL\MovedFiles\02072011_204805\C_WINDOWS\b3duZXI\command.exe Win32/Adware.CommAd application C:\_OTL\MovedFiles\02072011_204805\C_WINDOWS\system32\IOYayccf.ini Win32/Adware.Virtumonde.NEO application C:\_OTL\MovedFiles\02072011_204805\C_WINDOWS\system32\IOYayccf.ini2 Win32/Adware.Virtumonde.NEO application C:\_OTL\MovedFiles\02072011_204805\C_WINDOWS\system32\nsn159.dll a variant of Win32/Adware.GooochiBiz application C:\_OTL\MovedFiles\02082011_175659\C_WINDOWS\System32\etmxbhcg.dll Win32/Adware.SuperJuan application

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI