This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected Netbook with Virus

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

All processes killed ========== PROCESSES ========== ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E38FA08E-F56A-4169-ABF5-5C71E3C153A1}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E38FA08E-F56A-4169-ABF5-5C71E3C153A1}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\gameboxchrome\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{494D4E3B-FA53-4487-8AF6-3F50FE1167A9}\ deleted successfully. File {494D4E3B-FA53-4487-8AF6-3F50FE1167A9} - File not found not found. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== C:\32788R22FWJFW\N_ folder moved successfully. C:\32788R22FWJFW\License folder moved successfully. C:\32788R22FWJFW\EN-US folder moved successfully. C:\32788R22FWJFW folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Guest ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: JM ->Temp folder emptied: 467156 bytes ->Temporary Internet Files folder emptied: 12438006 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Google Chrome cache emptied: 90063257 bytes ->Flash cache emptied: 791 bytes User: John Hurst ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: NetworkService ->Temp folder emptied: 2484 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 2326 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 955 bytes Total Files Cleaned = 98.00 mb OTL by OldTimer - Version 3.2.22.3 log created on 04132011_192828 Files\Folders moved on Reboot… File\Folder C:\Documents and Settings\JM\Local Settings\Temp\~DF56A3.tmp not found! File\Folder C:\Documents and Settings\JM\Local Settings\Temp\~DF56B5.tmp not found! File\Folder C:\Documents and Settings\JM\Local Settings\Temp\~DF574E.tmp not found! File\Folder C:\Documents and Settings\JM\Local Settings\Temp\~DF5768.tmp not found! File\Folder C:\Documents and Settings\JM\Local Settings\Temp\~DF5883.tmp not found! File\Folder C:\Documents and Settings\JM\Local Settings\Temp\~DF5896.tmp not found! C:\Documents and Settings\JM\Local Settings\Temporary Internet Files\Content.IE5\RDJQUR0D\like[1].htm moved successfully. C:\Documents and Settings\JM\Local Settings\Temporary Internet Files\Content.IE5\EYT3JH2Y\iframe[1].htm moved successfully. C:\Documents and Settings\JM\Local Settings\Temporary Internet Files\Content.IE5\0PIMQD2A\index[4].htm moved successfully. C:\Documents and Settings\JM\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. File\Folder C:\WINDOWS\temp\_avast5_\Webshlock.txt not found! Registry entries deleted on Reboot…
Good evening Ken5454..included below is the second OTL scan that you had requested.

Unfortunately the computer continues to run slow. Any additional thoughts?

OTL logfile created on: 4/13/2011 7:40:27 PM - Run 4
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Virus Scan\OTL
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 616.00 Mb Available Physical Memory | 61.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 143.04 Gb Total Space | 68.09 Gb Free Space | 47.60% Space Free | Partition Type: NTFS

Computer Name: SAMSUNG120 | User Name: JM | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Virus Scan\OTL\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\NCH Software\Components\mp3el\mp3enc.exe ()
PRC - C:\Program Files\NCH Swift Sound\BroadWave\broadwave.exe (NCH Software)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Virus Scan\OTL\OTL.exe (OldTimer Tools)
MOD - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll (RealNetworks, Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (gusvc) – File not found
SRV - (AppMgmt) – File not found
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (BroadWaveService) – C:\Program Files\NCH Swift Sound\BroadWave\broadwave.exe (NCH Software)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (VMC326) – C:\WINDOWS\system32\drivers\VMC326.sys (Vimicro Corporation)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (AR5416) – C:\WINDOWS\system32\drivers\athw.sys (Atheros Communications, Inc.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (SUEPD) – C:\WINDOWS\system32\drivers\SUE_PD.sys (Samsung)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (DOSMEMIO) – C:\WINDOWS\system32\MEMIO.SYS ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…N&bmod;=SMSN
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaulturl: "http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch⁡=14542"
FF - prefs.js..browser.search.order.1: "Google"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {D5493C6A-FD62-4255-AA85-AB7E7D0F0001}:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}:[removed]
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..keyword.URL: "http://search.search-star.net/?sid=10101045100&s;="

FF - user.js..browser.search.selectedEngine: "Google"
FF - user.js..browser.search.order.1: "Google"
FF - user.js..keyword.URL: "http://search.search-star.net/?sid=10101045100&s;="

FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/01/12 17:32:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/03 18:54:43 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/03 18:54:43 | 000,000,000 | —D | M]

[2009/12/27 15:49:24 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\JM\Application Data\Mozilla\Extensions
[2011/04/06 19:18:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\JM\Application Data\Mozilla\Firefox\Profiles\qip023fr.default\extensions
[2010/06/02 00:44:50 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\JM\Application Data\Mozilla\Firefox\Profiles\qip023fr.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/08/03 13:56:37 | 000,000,000 | —D | M] (myBabylon English Toolbar) – C:\Documents and Settings\JM\Application Data\Mozilla\Firefox\Profiles\qip023fr.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}
[2010/04/12 14:01:34 | 000,002,456 | —- | M] () – C:\Documents and Settings\JM\Application Data\Mozilla\Firefox\Profiles\qip023fr.default\searchplugins\iMeshWebSearch.xml
[2011/04/06 19:18:14 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/11/08 21:20:32 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/05/20 16:51:53 | 000,000,000 | —D | M] (BarQuery) – C:\Program Files\Mozilla Firefox\extensions\{D5493C6A-FD62-4255-AA85-AB7E7D0F0001}
[2011/01/12 17:32:43 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2010/11/08 21:20:17 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/11/08 21:20:17 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/08/03 13:56:29 | 000,002,226 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
[2009/09/21 11:24:16 | 000,001,329 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\crawlersrch.xml
[2010/04/12 14:01:34 | 000,002,456 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\iMeshWebSearch.xml

O1 HOSTS File: ([2011/04/12 20:00:19 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - File not found
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No CLSID value found.
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [BatteryLifeExtender] C:\Program Files\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe (Samsung Electronics. Co. Ltd.)
O4 - HKCU..\Run: [swg] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\JM\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Send to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\JM\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\JM\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/05/13 20:47:07 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/04/12 20:00:02 | 000,000,000 | —D | C] – C:\_OTL
[2011/04/12 19:54:59 | 000,000,000 | —D | C] – C:\Documents and Settings\JM\Desktop\erunt
[2011/04/08 16:11:50 | 000,000,000 | —D | C] – C:\Program Files\Windows Defender
[2011/04/08 10:11:41 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2011/04/06 18:57:54 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/04/06 18:11:08 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2011/04/06 17:47:12 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/04/06 17:47:12 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/04/06 17:47:12 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/04/06 17:47:12 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/04/06 17:43:04 | 000,000,000 | —D | C] – C:\Qoobox
[2011/03/30 17:50:03 | 000,000,000 | —D | C] – C:\Documents and Settings\JM\Local Settings\Application Data\Z-Systems
[2011/03/30 17:48:45 | 000,000,000 | —D | C] – C:\Documents and Settings\JM\Application Data\Z-Systems
[2011/03/30 17:48:27 | 000,000,000 | —D | C] – C:\Documents and Settings\JM\My Documents\Z-Maestro Parts
[2011/03/30 17:48:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Z-Maestro Parts
[2011/03/30 17:46:01 | 000,000,000 | —D | C] – C:\Program Files\Z-Maestro
[2011/03/27 08:47:19 | 000,000,000 | —D | C] – C:\Documents and Settings\JM\Local Settings\Application Data\MediaMonkey
[2011/03/27 08:47:16 | 000,000,000 | —D | C] – C:\Program Files\MediaMonkey
[2009/12/26 11:23:16 | 000,800,544 | —- | C] (Sun Microsystems, Inc.) – C:\Program Files\JavaSetup6u17-rv.exe

========== Files - Modified Within 30 Days ==========

[2011/04/13 19:59:00 | 000,000,432 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{F89E5EF8-7ACA-4DBF-954D-55BFE72ABEE9}.job
[2011/04/13 19:58:39 | 000,002,497 | —- | M] () – C:\Documents and Settings\JM\Desktop\Microsoft Office Word 2003.lnk
[2011/04/13 19:40:00 | 000,000,998 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2871473685-3360655730-2245385684-1005UA.job
[2011/04/13 19:35:31 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/04/13 19:32:08 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/04/13 19:31:59 | 1063,702,528 | -HS- | M] () – C:\hiberfil.sys
[2011/04/13 19:26:25 | 000,000,272 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2871473685-3360655730-2245385684-1006.job
[2011/04/13 19:26:24 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2871473685-3360655730-2245385684-1006.job
[2011/04/13 19:22:00 | 000,000,966 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2871473685-3360655730-2245385684-1006UA.job
[2011/04/13 19:21:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/04/13 17:52:29 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/04/13 07:22:00 | 000,000,914 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2871473685-3360655730-2245385684-1006Core.job
[2011/04/12 20:40:00 | 000,000,946 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2871473685-3360655730-2245385684-1005Core.job
[2011/04/12 20:00:19 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2011/04/12 19:54:10 | 000,513,320 | —- | M] () – C:\Documents and Settings\JM\Desktop\erunt.zip
[2011/04/09 16:33:19 | 000,453,632 | —- | M] () – C:\Documents and Settings\JM\Desktop\CKScanner.exe
[2011/04/08 16:09:46 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/04/08 10:12:49 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2011/04/07 10:42:05 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/04/06 21:50:28 | 000,001,984 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/04/05 08:36:12 | 000,012,138 | -HS- | M] () – C:\Documents and Settings\JM\Local Settings\Application Data\j638u7q3443b5j
[2011/04/05 08:36:12 | 000,012,138 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\j638u7q3443b5j
[2011/03/30 17:39:00 | 000,000,292 | —- | M] () – C:\WINDOWS\tasks\wavepadDowngrade.job
[2011/03/22 17:39:00 | 000,000,292 | —- | M] () – C:\WINDOWS\tasks\wavepadShakeIcon.job
[2011/03/16 16:10:16 | 000,077,532 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat

========== Files Created - No Company Name ==========

[2011/04/12 19:53:54 | 000,513,320 | —- | C] () – C:\Documents and Settings\JM\Desktop\erunt.zip
[2011/04/09 16:33:10 | 000,453,632 | —- | C] () – C:\Documents and Settings\JM\Desktop\CKScanner.exe
[2011/04/08 16:15:34 | 000,000,330 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/04/07 10:34:28 | 1063,702,528 | -HS- | C] () – C:\hiberfil.sys
[2011/04/06 17:47:12 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/04/06 17:47:12 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/04/06 17:47:12 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/04/06 17:47:12 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/04/06 17:47:12 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/04/03 19:38:21 | 000,012,138 | -HS- | C] () – C:\Documents and Settings\JM\Local Settings\Application Data\j638u7q3443b5j
[2011/04/03 19:38:21 | 000,012,138 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\j638u7q3443b5j
[2011/03/16 17:04:29 | 000,000,292 | —- | C] () – C:\WINDOWS\tasks\wavepadShakeIcon.job
[2011/01/12 18:12:39 | 000,000,633 | —- | C] () – C:\Documents and Settings\JM\Application Data\ClipExtractor-YouTube-Clip-ExtractorFlvConverterDefaultSettings.xml
[2010/12/20 21:47:10 | 000,667,978 | —- | C] () – C:\WINDOWS\unins000.exe
[2010/12/20 21:47:10 | 000,001,647 | —- | C] () – C:\WINDOWS\unins000.dat
[2010/09/23 22:48:59 | 000,522,328 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/08/17 01:35:06 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/07/27 11:10:43 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2010/07/25 13:28:37 | 000,000,789 | —- | C] () – C:\WINDOWS\hegames.ini
[2010/04/06 22:13:07 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2010/03/23 21:30:57 | 000,000,064 | —- | C] () – C:\WINDOWS\GPlrLanc.dat
[2010/03/14 18:47:12 | 000,001,984 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/03/04 19:21:05 | 000,050,630 | —- | C] () – C:\Documents and Settings\JM\Application Data\speech.wav
[2009/12/27 15:49:16 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/12/26 21:17:53 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2009/12/26 21:16:24 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\pxhpinst.exe
[2009/12/26 15:28:04 | 000,077,532 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/12/26 15:02:47 | 000,144,896 | —- | C] () – C:\Documents and Settings\JM\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/26 02:00:22 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/12/26 01:19:06 | 000,001,520 | —- | C] () – C:\WINDOWS\System32\John Hurst_KBD.ini
[2009/12/25 17:21:14 | 000,001,520 | —- | C] () – C:\WINDOWS\System32\JM_KBD.ini
[2009/12/25 16:11:32 | 000,000,048 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/10/05 19:46:46 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2009/05/13 21:18:21 | 000,307,200 | —- | C] () – C:\WINDOWS\SetDisplayResolution.exe
[2009/05/13 20:59:17 | 000,000,002 | —- | C] () – C:\WINDOWS\HotFixList.ini
[2009/05/13 20:59:11 | 000,001,522 | —- | C] () – C:\WINDOWS\System32\MagicKBD.INI
[2009/05/13 20:59:11 | 000,001,520 | —- | C] () – C:\WINDOWS\System32\Owner_KBD.ini
[2009/05/13 20:59:09 | 000,003,425 | —- | C] () – C:\WINDOWS\System32\KBDR.INI
[2009/05/13 20:59:09 | 000,002,741 | —- | C] () – C:\WINDOWS\System32\KBDD.INI
[2009/05/13 20:59:09 | 000,002,699 | —- | C] () – C:\WINDOWS\System32\KBDO.INI
[2009/05/13 20:59:09 | 000,002,699 | —- | C] () – C:\WINDOWS\System32\KBDC.INI
[2009/05/13 20:59:09 | 000,002,606 | —- | C] () – C:\WINDOWS\System32\KBDB.INI
[2009/05/13 20:59:09 | 000,002,236 | —- | C] () – C:\WINDOWS\System32\KBDQ.INI
[2009/05/13 20:59:09 | 000,001,956 | —- | C] () – C:\WINDOWS\System32\KBDE.INI
[2009/05/13 20:59:09 | 000,001,885 | —- | C] () – C:\WINDOWS\System32\KBDP.INI
[2009/05/13 20:59:09 | 000,001,857 | —- | C] () – C:\WINDOWS\System32\KBDUU.INI
[2009/05/13 20:59:09 | 000,001,835 | —- | C] () – C:\WINDOWS\System32\KBDG.INI
[2009/05/13 20:59:09 | 000,001,835 | —- | C] () – C:\WINDOWS\System32\KBDA.INI
[2009/05/13 20:59:09 | 000,001,834 | —- | C] () – C:\WINDOWS\System32\KBDU.INI
[2009/05/13 20:59:09 | 000,001,819 | —- | C] () – C:\WINDOWS\System32\KBDN.INI
[2009/05/13 20:59:09 | 000,001,699 | —- | C] () – C:\WINDOWS\System32\KBDT.INI
[2009/05/13 20:59:09 | 000,001,697 | —- | C] () – C:\WINDOWS\System32\KBDV.INI
[2009/05/13 20:59:09 | 000,001,522 | —- | C] () – C:\WINDOWS\System32\KBDS.INI
[2009/05/13 20:59:09 | 000,001,476 | —- | C] () – C:\WINDOWS\System32\KBDF.INI
[2009/05/13 20:57:52 | 000,000,135 | R— | C] () – C:\WINDOWS\System32\lngEng.ini
[2009/05/13 20:57:52 | 000,000,117 | —- | C] () – C:\WINDOWS\System32\lngKor.ini
[2009/05/13 20:53:57 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2009/05/13 20:51:15 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\drivers\Marker.exe
[2009/05/13 20:51:14 | 000,004,300 | —- | C] () – C:\WINDOWS\System32\MEMIO.SYS
[2009/05/13 20:49:25 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/05/13 20:44:44 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/05/13 18:57:57 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2009/05/13 18:57:17 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2009/05/13 18:57:16 | 000,444,596 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2009/05/13 18:57:16 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2009/05/13 18:57:16 | 000,072,306 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2009/05/13 18:57:16 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2009/05/13 18:57:15 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2009/05/13 18:57:15 | 000,004,486 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2009/05/13 18:57:15 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2009/05/13 18:57:13 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2009/05/13 18:57:13 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2009/05/13 18:57:09 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2009/05/13 18:57:07 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2009/05/13 13:39:07 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/05/13 13:37:54 | 000,352,976 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/23 18:40:06 | 002,854,976 | —- | C] () – C:\WINDOWS\System32\btwicons.dll
[2007/02/26 19:49:12 | 006,139,774 | —- | C] () – C:\WINDOWS\imagine digital freedom.dat
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/11/14 14:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 990 bytes -> C:\Program Files\WindowsUpdate:jUwsjxIR6OIzKGKUKuispnC92of
@Alternate Data Stream - 828 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:35E5AF34
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:453190EC
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:D1B5B4F1
@Alternate Data Stream - 1134 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:nBlALKTo5W826T0tCQ4f6WP9
@Alternate Data Stream - 1132 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:aIF2EwvJ6jviacDEypJ2H
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:5804A24D
@Alternate Data Stream - 1016 bytes -> C:\Program Files\WindowsUpdate:ZCgaypncyLSHfArnOH4DgoH66QzV

< End of report >
Thank you for your assistance and patience. I have sharded your knowledge with my son in an effort to prevent malicious downloads. I'll monitor the speed and post in the Windows forum in the event we continue to have problems. Regards, jhurst
Your very welcome


Open OTL and click on Clean Up and it will remove programs we used to clean your system along with there backups


  • How did I get infected in the first place ?
    Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • WhattheTech
  • Grinler BleepingComputer
  • GeeksTo Go
  • Dslreports





Safe Surfn
Ken

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI