This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help! I am infected but dont know what with

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL files
OTL logfile created on: 5/2/2011 6:48:45 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\meri\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 592.00 Mb Available Physical Memory | 58.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 413.69 Gb Free Space | 88.82% Space Free | Partition Type: NTFS

Computer Name: YOUR-845F836F3D | User Name: meri | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\meri\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\GamesBar\SearchEngineProtection.exe (Oberon Media )
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\SupportSoft\bin\sprtlisten.exe (SupportSoft, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\meri\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (GamesAppService) – C:\Program Files\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (sprtlisten) – C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe (SupportSoft, Inc.)
SRV - (SupportSoft RemoteAssist) – C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe (SupportSoft, Inc.)


========== Driver Services (SafeList) ==========

DRV - (MpKslcf5aed6f) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EB0F1EF3-DC3E-4640-A472-2910BAC289C4}\MpKslcf5aed6f.sys (Microsoft Corporation)
DRV - (X4HSEx) – C:\Program Files\Free Ride Games\X4HSEx.sys (Exent Technologies Ltd.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (senfilt) – C:\WINDOWS\system32\drivers\senfilt.sys (Creative Technology Ltd.)
DRV - (PhilCam8116) Logitech QuickCam Pro 3000 (08B0) – C:\WINDOWS\system32\drivers\CamDrO21.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.pogo.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.pogo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.pogo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..browser.startup.homepage: "http://www.facebook.com/"
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.81
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:3.3.3.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {de404f4c-3cde-4d74-a6fb-052d099c104c}:3.3.3.2
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}:2.2.0
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"


FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/12/09 07:39:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/09 17:54:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/04/30 06:07:47 | 000,000,000 | —D | M]

[2010/08/17 08:06:06 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\meri\Application Data\Mozilla\Extensions
[2010/08/17 08:06:06 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\meri\Application Data\Mozilla\Extensions\[removed]
[2011/05/01 12:03:29 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\extensions
[2010/06/27 06:34:10 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/26 09:49:38 | 000,000,000 | —D | M] (Zynga Community Toolbar) – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011/03/01 06:12:31 | 000,000,000 | —D | M] ("StumbleUpon") – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2011/03/26 09:49:34 | 000,000,000 | —D | M] (Messenger Plus Live US Community Toolbar) – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\extensions\{de404f4c-3cde-4d74-a6fb-052d099c104c}
[2011/03/26 09:49:33 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\extensions\[removed]
[2011/03/26 09:49:37 | 000,000,000 | —D | M] (Oberon GamesBar) – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\extensions\[removed]
[2011/02/13 08:28:34 | 000,001,919 | —- | M] () – C:\Documents and Settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\searchplugins\bing-zugo.xml
[2011/04/30 08:23:43 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/06 11:58:19 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\MERI\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\QT57T2B0.DEFAULT\EXTENSIONS\{8A9386B4-E958-4C4C-ADF4-8F26DB3E4829}
[2010/04/12 17:29:19 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/07/12 09:33:56 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2011/02/13 08:28:49 | 000,002,191 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
[2010/09/20 11:06:19 | 000,001,600 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\WebSearchober19934781.xml
[2011/04/28 05:27:18 | 000,001,600 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\WebSearchober2202375.xml
[2011/04/27 06:27:14 | 000,001,600 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\WebSearchober3372062.xml

O1 HOSTS File: ([2008/08/21 05:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll (Google Inc.)
O2 - BHO: (no name) - {CB0D163C-E9F4-4236-9496-0597E24B23A5} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4 - HKCU..\Run: [SearchEngineProtection] C:\Program Files\GamesBar\SearchEngineProtection.exe (Oberon Media )
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {000F1EA4-5E08-4564-A29B-29076F63A37A} http://launch.soe.com/plugin/web/SOEWebInstaller.cab (SOE Web Installer)
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1270808702234 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx2.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 [removed]
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\TPSvc: DllName - TPSvc.dll - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\meri\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\meri\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/12/02 19:11:59 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56590081070202880)

========== Files/Folders - Created Within 30 Days ==========

[2011/05/02 06:46:50 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\meri\Desktop\OTL.exe
[2011/05/01 12:05:36 | 000,000,000 | RH-D | C] – C:\Documents and Settings\meri\Recent
[2011/05/01 12:03:29 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Application Data\PriceGong
[2011/05/01 11:52:07 | 000,190,032 | —- | C] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/05/01 11:52:07 | 000,056,400 | —- | C] (trend_company_name) – C:\WINDOWS\System32\drivers\tmrkb.sys
[2011/05/01 11:52:07 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\log
[2011/05/01 11:47:52 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/05/01 11:47:52 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Start Menu\Programs\HiJackThis
[2011/05/01 08:38:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/04/28 05:28:30 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Start Menu\Programs\Pogo Games
[2011/04/27 06:29:25 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Application Data\MysteryStudio
[2011/04/27 06:27:08 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Application Data\Oberon Media
[2011/04/27 06:27:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\GamesBar
[2011/04/27 06:27:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\GamesBar
[2011/04/27 06:27:01 | 000,000,000 | —D | C] – C:\Program Files\GamesBar
[2011/04/26 08:06:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CanonIJ
[2011/04/26 08:05:55 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2011/04/26 08:05:53 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Application Data\Canon
[2011/04/20 07:27:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2011/04/02 08:16:59 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Application Data\Exent Technologies
[2011/04/02 08:11:03 | 000,000,000 | —D | C] – C:\Documents and Settings\meri\Start Menu\Programs\Free Ride Games
[2011/04/02 08:08:31 | 000,000,000 | —D | C] – C:\Program Files\Playalot Games
[2011/04/02 08:08:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Playalot Games
[2011/04/02 08:05:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Free Ride Games
[2011/04/02 08:05:23 | 000,053,314 | —- | C] (Exent Technologies Ltd.) – C:\WINDOWS\ExentInfo.exe
[2011/04/02 08:05:14 | 000,000,000 | —D | C] – C:\Program Files\Free Ride Games
[2011/04/02 08:05:10 | 000,000,000 | —D | C] – C:\Remote Programs
[2011/04/02 07:11:20 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\CanonIJMyPrinter
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/02 06:47:16 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\meri\Desktop\OTL.exe
[2011/05/02 06:42:50 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/05/02 06:34:29 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/05/02 06:29:35 | 000,012,598 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/05/02 06:29:20 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/02 06:29:17 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/02 06:14:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/01 12:54:45 | 000,002,349 | —- | M] () – C:\Documents and Settings\All Users\Desktop\InSpheration.lnk
[2011/05/01 12:43:16 | 000,002,345 | —- | M] () – C:\Documents and Settings\All Users\Desktop\WordSlinger.lnk
[2011/05/01 11:59:38 | 000,000,073 | —- | M] () – C:\WINDOWS\System32\-1
[2011/05/01 11:52:07 | 000,056,400 | —- | M] (trend_company_name) – C:\WINDOWS\System32\drivers\tmrkb.sys
[2011/05/01 11:52:06 | 000,190,032 | —- | M] (Trend Micro Inc.) – C:\WINDOWS\System32\drivers\tmcomm.sys
[2011/05/01 11:48:21 | 000,002,445 | —- | M] () – C:\Documents and Settings\meri\Desktop\HiJackThis.lnk
[2011/05/01 11:39:07 | 000,000,036 | —- | M] () – C:\Documents and Settings\meri\Local Settings\Application Data\housecall.guid.cache
[2011/05/01 08:51:21 | 000,002,032 | —- | M] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/04/28 09:33:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/04/28 05:28:30 | 000,001,861 | —- | M] () – C:\Documents and Settings\meri\Desktop\FREE Dream Day Honeymoon.lnk
[2011/04/16 03:23:33 | 000,330,688 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/16 03:06:38 | 000,435,688 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/04/16 03:06:38 | 000,068,584 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/04/12 04:41:25 | 000,000,000 | —- | M] () – C:\Documents and Settings\meri\My Documents\custom.dic
[2011/04/06 10:48:01 | 000,000,354 | —- | M] () – C:\Documents and Settings\meri\Desktop\Hausernet Decoy Entry Web Site.url
[2011/04/02 08:05:30 | 000,000,064 | —- | M] () – C:\WINDOWS\GPlrLanc.dat
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/01 11:59:38 | 000,000,073 | —- | C] () – C:\WINDOWS\System32\-1
[2011/05/01 11:47:52 | 000,002,445 | —- | C] () – C:\Documents and Settings\meri\Desktop\HiJackThis.lnk
[2011/05/01 11:39:07 | 000,000,036 | —- | C] () – C:\Documents and Settings\meri\Local Settings\Application Data\housecall.guid.cache
[2011/05/01 08:50:35 | 000,002,032 | —- | C] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/04/28 10:45:34 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/04/28 05:28:30 | 000,001,861 | —- | C] () – C:\Documents and Settings\meri\Desktop\FREE Dream Day Honeymoon.lnk
[2011/04/12 04:41:25 | 000,000,000 | —- | C] () – C:\Documents and Settings\meri\My Documents\custom.dic
[2011/04/02 08:05:30 | 000,000,064 | —- | C] () – C:\WINDOWS\GPlrLanc.dat
[2011/02/13 14:28:04 | 000,000,449 | —- | C] () – C:\Program Files\0213201113280473.bat
[2011/01/15 11:05:01 | 000,118,784 | —- | C] () – C:\WINDOWS\ShowBmp.exe
[2011/01/15 11:05:01 | 000,000,180 | —- | C] () – C:\WINDOWS\ap561.ini
[2011/01/15 11:05:00 | 000,014,385 | —- | C] () – C:\WINDOWS\Tw561a.ini
[2011/01/15 11:05:00 | 000,000,081 | —- | C] () – C:\WINDOWS\Setup8a.ini
[2010/09/28 08:40:10 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/09/20 11:34:28 | 000,000,015 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2010/05/02 07:57:20 | 000,000,030 | —- | C] () – C:\WINDOWS\iedit.INI
[2010/04/12 12:30:56 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/04/10 10:12:30 | 000,000,116 | —- | C] () – C:\WINDOWS\Ulead32.ini
[2010/04/10 10:04:43 | 000,000,387 | —- | C] () – C:\WINDOWS\lexstat.ini
[2010/04/10 10:04:40 | 000,000,092 | —- | C] () – C:\WINDOWS\dellstat.ini
[2010/04/08 15:44:22 | 000,000,007 | —- | C] () – C:\WINDOWS\System32\mkghj.dll
[2009/12/03 10:46:44 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2009/12/02 19:13:42 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/12/02 19:10:05 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/12/02 18:00:56 | 000,000,131 | —- | C] () – C:\WINDOWS\System32\Oeminfo.ini
[2009/12/02 18:00:54 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2009/12/02 18:00:54 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2009/12/02 18:00:54 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2009/12/02 18:00:54 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2009/12/02 18:00:54 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2009/12/02 18:00:50 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2009/12/02 18:00:49 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2009/12/02 18:00:49 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2009/12/02 18:00:49 | 000,435,688 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2009/12/02 18:00:49 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2009/12/02 18:00:49 | 000,068,584 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2009/12/02 18:00:49 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2009/12/02 18:00:49 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2009/12/02 18:00:49 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2009/12/02 18:00:49 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2009/12/02 18:00:44 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2009/12/02 18:00:44 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2009/12/02 11:06:25 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/12/02 11:05:49 | 000,330,688 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe

========== LOP Check ==========

[2010/04/10 10:05:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2011/04/01 16:18:58 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/04/26 08:06:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJ
[2011/04/01 18:06:35 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJEGV
[2011/04/01 18:01:32 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJEPPEX
[2011/04/02 07:11:20 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJMyPrinter
[2011/04/26 08:06:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2011/04/26 08:05:55 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2011/04/01 18:00:31 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJSolutionMenu
[2011/04/02 08:05:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Free Ride Games
[2011/04/02 10:55:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameHouse
[2010/10/20 06:58:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GAMEON
[2011/05/01 08:34:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GamesBar
[2010/08/09 09:51:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Merscom
[2010/06/27 06:30:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2011/01/09 05:24:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
[2011/04/28 05:28:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Oberon Media
[2010/04/08 15:55:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2010/04/23 06:20:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Qwest
[2011/04/20 07:27:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2011/05/01 11:38:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/01/11 08:14:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SugarGames
[2011/04/30 11:54:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/10/15 13:23:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2011/01/15 16:18:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2010/04/08 15:54:04 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\CallingID
[2011/04/26 08:05:55 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Canon
[2011/04/01 17:55:54 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Canon Easy-WebPrint EX
[2011/04/02 08:16:59 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Exent Technologies
[2010/06/23 06:33:02 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Facebook
[2011/02/13 11:17:04 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\GameHouse
[2010/11/16 08:50:10 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\LimeWire
[2010/08/09 09:51:00 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Merscom
[2011/04/28 04:56:26 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\MysteryStudio
[2011/04/28 05:28:48 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Oberon Media
[2010/11/05 11:18:55 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Post-it® Photo Organizer
[2011/05/01 12:03:29 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\PriceGong
[2011/04/13 15:38:38 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Sony Online Entertainment
[2011/04/27 04:47:05 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\StumbleUpon
[2010/10/16 04:39:38 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\TitanicMystery
[2010/05/02 07:57:09 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Ulead Systems
[2010/04/26 09:27:04 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\Unity
[2011/02/13 08:29:11 | 000,000,000 | —D | M] – C:\Documents and Settings\meri\Application Data\vmntemplate
[2011/05/02 06:34:29 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/12/02 19:11:59 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/04/08 14:48:22 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/04/08 15:50:23 | 000,000,170 | —- | M] () – C:\caEntitlementLog.txt
[2010/04/08 15:56:59 | 000,351,652 | —- | M] () – C:\caisslog.txt
[2009/12/02 19:11:59 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/04/09 03:29:30 | 000,004,828 | —- | M] () – C:\Facilitator.log
[2009/12/02 19:11:59 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/03/28 12:13:29 | 000,000,078 | —- | M] () – C:\lxcy.log
[2009/12/02 19:11:59 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/08/21 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/08/21 05:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/05/02 06:29:14 | 1598,029,824 | -HS- | M] () – C:\pagefile.sys
[2010/04/10 10:05:21 | 000,000,168 | —- | M] () – C:\setupfax.log

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/12/02 19:11:36 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2010/04/24 05:00:00 | 000,027,648 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD9W.DLL
[2010/04/24 05:00:00 | 000,070,656 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP9W.DLL
[2008/07/06 05:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 03:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2002/05/14 16:50:34 | 000,011,264 | —- | M] (BVRP Software) – C:\WINDOWS\system32\spool\prtprocs\w32x86\wfxprint2000.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2011/02/13 14:28:04 | 000,000,449 | —- | M] () – C:\Program Files\0213201113280473.bat

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/12/02 11:05:17 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/12/02 11:05:17 | 001,089,536 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/12/02 11:05:16 | 000,913,408 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/12/03 10:46:44 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >
[2009/12/02 19:14:36 | 000,000,000 | —- | M] () – C:\WINDOWS\system32\config\systemprofile\rpkdriverinst.log

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/08 14:48:50 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\meri\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/12/02 19:19:00 | 000,000,079 | —- | M] () – C:\Documents and Settings\meri\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/05/02 06:47:16 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\meri\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >
[2002/08/13 19:01:26 | 000,007,431 | —- | M] () – C:\WINDOWS\Tw561a.src
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-28 10:03:21

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 216 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D48FEB33
@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:AE8D8202
@Alternate Data Stream - 138 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:813B8EB6
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3B3A35EC
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:03392111

< End of report >
OTL Extras logfile created on: 5/2/2011 6:48:45 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\meri\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 592.00 Mb Available Physical Memory | 58.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 413.69 Gb Free Space | 88.82% Space Free | Partition Type: NTFS

Computer Name: YOUR-845F836F3D | User Name: meri | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\CA Personal Firewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiMalware]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"59160:TCP" = 59160:TCP:*:Enabled:Pando
"59160:UDP" = 59160:UDP:*:Enabled:Pando

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Pando Networks\Pando\Pando.exe" = C:\Program Files\Pando Networks\Pando\Pando.exe:*:Enabled:Pando – (Pando Networks)
"C:\WINDOWS\system32\lxcycoms.exe" = C:\WINDOWS\system32\lxcycoms.exe:*:Enabled:3400 Series Server


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00170409-78E1-11D2-B60F-006097C998E7}" = Microsoft Word 2000
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP250_series" = Canon MP250 series MP Drivers
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18B148B8-50B0-4DD9-B017-18713B782F85}" = WordSlinger
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216019FF}" = Java™ 6 Update 20
"{2B7BDADB-EC8C-4C54-B5DD-CE45A016D3A7}" = Free Ride Games Player
"{2D87E961-577B-492B-AD54-1368680FB9A7}" = Bing Maps 3D
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A3532ED-A121-4297-AA4F-70B60E4BD631}" = Playalot Games
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{56364334-9530-11D2-BFFC-00C04FA329AA}" = Microsoft Works 2000
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{693EF7BC-C5CA-43E6-AFA8-1F3FB63A8D92}" = Qwest Windows Live Toolbar Buttons
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-wildgames" = WildTangent Games App
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{77A776C4-D10F-416D-88F0-53F2D9DCD9B3}" = Microsoft Security Client
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112270203}" = Dream Day Wedding
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-118367707}" = FREE Dream Day Honeymoon
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{928B06E4-DDAA-476A-926A-641620326327}" = Microsoft Search Enhancement Pack
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser
"{A63E18AC-B504-4045-AFE6-A279BBABB988}" = Qwest QuickAssist Desktop Tools
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9E27FF5-6294-46A8-B8FD-77B1DECA3021}" = Wizard101
"{AB480DA0-7EE9-465D-9C12-4CDE65BF18FB}" = Pando
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.4
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6F65BE1-D11E-42EE-9389-84C124B905B4}" = InSpheration
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C96FF998-45BD-411E-9253-B7F2660FE280}" = Qwest Installer
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D271DAE0-8D68-4C97-8356-A126D48A1D8C}" = Ulead Photo Explorer 8.0
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F45298E5-0083-426F-A668-1A2C5F04B8A0}" = FaxTools
"{F48C6EA5-3B43-11D6-86A6-0050BA0259A2}" = ICatch (VI) PC Camera
"{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}" = Acrobat.com
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"amg-1912titanicmystery" = 1912 Titanic Mystery
"amg-3cardstodeadtime" = 3 Cards to Dead Time
"amg-affairbureau" = Affair Bureau
"amg-alohasolitaire" = Aloha Solitaire
"amg-autumnstreasuresthejadecoin" = Autumn's Treasures - The Jade Coin
"amg-biggestlittleadventure" = Biggest Little Adventure
"amg-chameleongems" = Chameleon Gems
"amg-fashionassistant" = Fashion Assistant
"amg-frankensteinthedismemberedbride" = FRANKENSTEIN - The Dismembered Bride
"amg-gamehousesolitairechallenge" = GameHouse Solitaire Challenge
"amg-hiddenmagic" = Hidden Magic
"amg-janeangeltemplarmystery" = Jane Angel - Templar Mystery
"amg-jewelcharm" = Jewel Charm
"amg-liongthelostamulets" = Liong - The Lost Amulets
"amg-mahjongginvestigationsundersuspicion" = Mahjongg Investigations - Under Suspicion
"amg-mysterylegendstmsleepyhollow" = Mystery Legends™ - Sleepy Hollow
"amg-nataliebrooksmysteryathillcresthigh" = Natalie Brooks - Mystery at Hillcrest High
"amg-puzzlesolitaire" = Puzzle Solitaire
"amg-strikeball3" = Strike Ball 3
"amg-sunsetstudioloveonthehighseas" = Sunset Studio - Love on the High Seas
"amg-supercollapsepuzzlegallery4" = Super Collapse! Puzzle Gallery 4
"amg-thelostcasesofsherlockholmes" = The Lost Cases of Sherlock Holmes
"amg-thetreasuresofmysteryisland" = The Treasures of Mystery Island
"amg-thetudors" = The Tudors
"Canon MP250 series User Registration" = Canon MP250 series User Registration
"CANONIJPLM100" = Canon Inkjet Printer/Scanner/Fax Extended Survey Program
"CanonMyPrinter" = Canon Utilities My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CCleaner" = CCleaner
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"exent_466550" = The Treasures of Montezuma
"exent_554750" = Cradle of Rome
"exent_605350" = Magic Encyclopedia
"exent_668050" = Farm Mania 2
"exent_695650" = Little Shop - Memories
"GamesBar" = GamesBar [removed]
"ie8" = Windows Internet Explorer 8
"Little Shop of Treasures 2" = Little Shop of Treasures 2
"Messenger Plus!" = Messenger Plus! 5
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"MP Navigator EX 3.0" = Canon MP Navigator EX 3.0
"MSNINST" = MSN
"mspheres_is1" = Magic Spheres v1.0
"Rainbow Web II" = Rainbow Web II
"UnityWebPlayer" = Unity Web Player
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WildTangent wildgames Master Uninstall" = WildTangent Games
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format Runtime
"WinLiveSuite_Wave3" = Windows Live Essentials
"Works2kSetup" = Microsoft Works 2000 Setup Launcher
"WT086164" = Monster Mash

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"SOE-Clone Wars" = Clone Wars
"SOE-Free Realms" = Free Realms
"Winamp Detect" = Winamp Detector Plug-in

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/29/2011 3:15:44 PM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.

Error - 4/29/2011 3:55:29 PM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.

Error - 4/29/2011 7:36:26 PM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.

Error - 4/29/2011 7:37:59 PM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.

Error - 4/29/2011 7:38:30 PM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.

Error - 4/30/2011 11:39:54 PM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.

Error - 5/1/2011 4:19:54 AM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.

Error - 5/1/2011 4:19:57 AM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.

Error - 5/1/2011 4:20:00 AM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2000 – Error 1706. No valid source could
be found for product Microsoft Word 2000. The Windows installer cannot continue.

Error - 5/1/2011 2:35:24 PM | Computer Name = YOUR-845F836F3D | Source = MsiInstaller | ID = 11722
Description = Product: STOPzilla – Message 1722. STOPzilla has canceled the removal
process!

[ System Events ]
Error - 5/1/2011 8:48:36 AM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 5/1/2011 11:35:55 AM | Computer Name = YOUR-845F836F3D | Source = Service Control Manager | ID = 7034
Description = The Windows User Mode Driver Framework service terminated unexpectedly.
It has done this 1 time(s).

Error - 5/1/2011 11:50:05 AM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 5/1/2011 11:50:05 AM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 5/1/2011 2:56:29 PM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 5/1/2011 2:56:29 PM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 5/1/2011 3:40:45 PM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 5/1/2011 3:40:45 PM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 5/2/2011 9:29:39 AM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 5/2/2011 9:29:39 AM | Computer Name = YOUR-845F836F3D | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.


< End of report >
here is my hijack this file

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:00:54 AM, on 5/2/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Gamesbar\SearchEngineProtection.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qwest.live.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pogo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Qwest
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll
O2 - BHO: (no name) - {CB0D163C-E9F4-4236-9496-0597E24B23A5} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [SearchEngineProtection] C:\Program Files\Gamesbar\SearchEngineProtection.exe
O4 - HKUS\S-1-5-19\..\Run: [Exetender] "C:\Program Files\Free Ride Games\GPlayer.exe" /runonstartup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Exetender] "C:\Program Files\Free Ride Games\GPlayer.exe" /runonstartup (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Exetender] "C:\Program Files\Free Ride Games\GPlayer.exe" /runonstartup (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Exetender] "C:\Program Files\Free Ride Games\GPlayer.exe" /runonstartup (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {000F1EA4-5E08-4564-A29B-29076F63A37A} (SOE Web Installer) - http://launch.soe.com/plugin/web/SOEWebInstaller.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1270808702234
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx2.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab
O20 - Winlogon Notify: TPSvc - TPSvc.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files\WildTangent Games\App\GamesAppService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: SupportSoft Listener Service (sprtlisten) - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\sprtlisten.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe

–
End of file - 7986 bytes
here is the last file u asked for . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_11-03-05.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 4/8/2010 2:48:25 PM System Uptime: 5/2/2011 6:29:02 AM (1 hours ago) . Motherboard: Dell Inc. | | 0RJ290 Processor: Intel® Pentium® D CPU 2.80GHz | Microprocessor | 2793/800mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 466 GiB total, 413.674 GiB free. D: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP335: 2/1/2011 4:10:32 PM - System Checkpoint RP336: 2/2/2011 4:14:09 PM - System Checkpoint RP337: 2/3/2011 5:10:47 PM - System Checkpoint RP338: 2/4/2011 6:10:47 PM - System Checkpoint RP339: 2/5/2011 7:02:21 PM - System Checkpoint RP340: 2/6/2011 7:08:28 PM - System Checkpoint RP341: 2/7/2011 8:05:46 PM - System Checkpoint RP342: 2/8/2011 8:01:45 PM - Software Distribution Service 3.0 RP343: 2/9/2011 8:14:08 PM - System Checkpoint RP344: 2/10/2011 8:17:43 PM - System Checkpoint RP345: 2/11/2011 9:15:51 PM - System Checkpoint RP346: 2/12/2011 9:16:55 PM - System Checkpoint RP347: 2/13/2011 4:05:47 AM - Microsoft OneCare Protection Checkpoint RP348: 2/13/2011 7:26:59 AM - Microsoft OneCare Protection Checkpoint RP349: 2/14/2011 8:35:27 AM - System Checkpoint RP350: 2/15/2011 9:00:38 AM - System Checkpoint RP351: 2/15/2011 5:51:02 PM - Installed InSpheration RP352: 2/16/2011 3:21:32 PM - Microsoft OneCare Protection Checkpoint RP353: 2/17/2011 5:06:54 AM - Microsoft OneCare Protection Checkpoint RP354: 2/18/2011 7:58:31 AM - System Checkpoint RP355: 2/19/2011 8:40:45 AM - System Checkpoint RP356: 2/20/2011 7:15:22 AM - before one care removed RP357: 2/20/2011 7:34:32 AM - Software Distribution Service 3.0 RP358: 2/21/2011 2:12:36 AM - Software Distribution Service 3.0 RP359: 2/21/2011 5:09:45 AM - Microsoft Antimalware Checkpoint RP360: 2/21/2011 7:32:33 AM - Software Distribution Service 3.0 RP361: 2/22/2011 7:32:46 AM - Software Distribution Service 3.0 RP362: 2/23/2011 7:32:47 AM - Software Distribution Service 3.0 RP363: 2/24/2011 8:10:08 AM - System Checkpoint RP364: 2/25/2011 5:47:15 AM - Software Distribution Service 3.0 RP365: 2/26/2011 9:22:08 AM - System Checkpoint RP366: 2/27/2011 5:04:21 AM - Software Distribution Service 3.0 RP367: 2/28/2011 2:03:07 AM - Software Distribution Service 3.0 RP368: 2/28/2011 1:12:36 PM - Software Distribution Service 3.0 RP369: 3/1/2011 2:08:34 PM - System Checkpoint RP370: 3/2/2011 4:49:08 AM - Software Distribution Service 3.0 RP371: 3/3/2011 5:17:21 AM - Software Distribution Service 3.0 RP372: 3/4/2011 5:11:52 AM - Software Distribution Service 3.0 RP373: 3/5/2011 6:03:51 AM - System Checkpoint RP374: 3/5/2011 6:05:58 AM - Software Distribution Service 3.0 RP375: 3/6/2011 6:42:35 AM - System Checkpoint RP376: 3/6/2011 6:59:35 AM - Software Distribution Service 3.0 RP377: 3/7/2011 2:11:57 AM - Software Distribution Service 3.0 RP378: 3/7/2011 4:49:43 AM - Microsoft Antimalware Checkpoint RP379: 3/8/2011 3:00:15 AM - Software Distribution Service 3.0 RP380: 3/8/2011 5:35:14 AM - Software Distribution Service 3.0 RP381: 3/9/2011 3:00:14 AM - Software Distribution Service 3.0 RP382: 3/9/2011 5:35:13 AM - Software Distribution Service 3.0 RP383: 3/10/2011 8:41:54 AM - System Checkpoint RP384: 3/10/2011 9:24:23 AM - Software Distribution Service 3.0 RP385: 3/11/2011 10:21:03 AM - System Checkpoint RP386: 3/12/2011 4:36:50 AM - Software Distribution Service 3.0 RP387: 3/13/2011 5:55:29 AM - Software Distribution Service 3.0 RP388: 3/14/2011 1:38:48 AM - Software Distribution Service 3.0 RP389: 3/15/2011 1:46:47 AM - System Checkpoint RP390: 3/15/2011 4:43:46 AM - Software Distribution Service 3.0 RP391: 3/15/2011 5:42:06 PM - Software Distribution Service 3.0 RP392: 3/16/2011 5:07:08 AM - Software Distribution Service 3.0 RP393: 3/17/2011 5:39:19 AM - Software Distribution Service 3.0 RP394: 3/18/2011 5:34:16 AM - Software Distribution Service 3.0 RP395: 3/19/2011 6:05:45 AM - System Checkpoint RP396: 3/19/2011 7:08:01 AM - Software Distribution Service 3.0 RP397: 3/20/2011 1:49:06 AM - Software Distribution Service 3.0 RP398: 3/21/2011 2:04:57 AM - System Checkpoint RP399: 3/21/2011 6:06:51 AM - Software Distribution Service 3.0 RP400: 3/22/2011 6:34:13 AM - System Checkpoint RP401: 3/23/2011 6:01:18 AM - Software Distribution Service 3.0 RP402: 3/23/2011 5:01:29 PM - Software Distribution Service 3.0 RP403: 3/24/2011 6:15:22 AM - Software Distribution Service 3.0 RP404: 3/25/2011 8:41:25 AM - System Checkpoint RP405: 3/25/2011 9:05:09 AM - Software Distribution Service 3.0 RP406: 3/26/2011 8:59:51 AM - Software Distribution Service 3.0 RP407: 3/27/2011 1:42:59 AM - Software Distribution Service 3.0 RP408: 3/27/2011 10:07:03 AM - Software Distribution Service 3.0 RP409: 3/28/2011 10:26:37 AM - Software Distribution Service 3.0 RP410: 3/28/2011 11:47:06 AM - Software Distribution Service 3.0 RP411: 3/29/2011 12:16:56 PM - System Checkpoint RP412: 3/29/2011 3:18:53 PM - Software Distribution Service 3.0 RP413: 3/30/2011 3:57:44 PM - System Checkpoint RP414: 3/31/2011 4:59:39 AM - Software Distribution Service 3.0 RP415: 4/1/2011 5:26:13 AM - Software Distribution Service 3.0 RP416: 4/2/2011 6:02:02 AM - System Checkpoint RP417: 4/2/2011 7:22:16 AM - Software Distribution Service 3.0 RP418: 4/2/2011 8:05:10 AM - Installed Free Ride Games Player RP419: 4/3/2011 2:08:57 AM - Software Distribution Service 3.0 RP420: 4/3/2011 11:38:09 AM - Software Distribution Service 3.0 RP421: 4/3/2011 1:34:36 PM - Removed InstallIQ Updater RP422: 4/4/2011 1:53:21 PM - System Checkpoint RP423: 4/4/2011 4:18:44 PM - Software Distribution Service 3.0 RP424: 4/5/2011 5:07:53 PM - System Checkpoint RP425: 4/6/2011 5:09:53 AM - Software Distribution Service 3.0 RP426: 4/7/2011 5:18:45 AM - Software Distribution Service 3.0 RP427: 4/8/2011 6:29:44 AM - Software Distribution Service 3.0 RP428: 4/9/2011 8:30:27 AM - System Checkpoint RP429: 4/10/2011 2:09:18 AM - Software Distribution Service 3.0 RP430: 4/11/2011 2:36:47 AM - System Checkpoint RP431: 4/12/2011 3:13:42 AM - Software Distribution Service 3.0 RP432: 4/13/2011 4:13:21 AM - System Checkpoint RP433: 4/13/2011 4:15:22 AM - Software Distribution Service 3.0 RP434: 4/14/2011 4:20:41 AM - Software Distribution Service 3.0 RP435: 4/15/2011 4:22:20 AM - Software Distribution Service 3.0 RP436: 4/16/2011 3:00:15 AM - Software Distribution Service 3.0 RP437: 4/16/2011 6:18:58 AM - Software Distribution Service 3.0 RP438: 4/17/2011 2:18:12 AM - Software Distribution Service 3.0 RP439: 4/18/2011 2:18:40 AM - System Checkpoint RP440: 4/18/2011 6:20:39 AM - Software Distribution Service 3.0 RP441: 4/19/2011 6:50:46 AM - Software Distribution Service 3.0 RP442: 4/19/2011 7:06:18 AM - Software Distribution Service 3.0 RP443: 4/20/2011 7:35:13 AM - Software Distribution Service 3.0 RP444: 4/21/2011 3:00:15 AM - Software Distribution Service 3.0 RP445: 4/22/2011 3:09:09 AM - System Checkpoint RP446: 4/22/2011 5:09:14 AM - Software Distribution Service 3.0 RP447: 4/23/2011 5:03:39 AM - Software Distribution Service 3.0 RP448: 4/24/2011 1:46:55 AM - Software Distribution Service 3.0 RP449: 4/25/2011 1:53:38 AM - System Checkpoint RP450: 4/25/2011 4:49:23 AM - Software Distribution Service 3.0 RP451: 4/26/2011 4:44:02 AM - Software Distribution Service 3.0 RP452: 4/27/2011 4:46:06 AM - Software Distribution Service 3.0 RP453: 4/28/2011 3:00:15 AM - Software Distribution Service 3.0 RP454: 4/28/2011 5:01:37 AM - Software Distribution Service 3.0 RP455: 4/29/2011 4:56:35 AM - Software Distribution Service 3.0 RP456: 4/30/2011 5:00:39 AM - Software Distribution Service 3.0 RP457: 5/1/2011 1:33:39 AM - Software Distribution Service 3.0 RP458: 5/1/2011 8:38:13 AM - Installed STOPzilla. Available with Windows Installer version 1.2 and later. RP459: 5/1/2011 11:38:04 AM - Removed STOPzilla. Available with Windows Installer version 1.2 and later. RP460: 5/1/2011 11:47:51 AM - Installed HiJackThis RP461: 5/2/2011 6:39:58 AM - Software Distribution Service 3.0 RP462: 5/2/2011 6:49:16 AM - OTL Restore Point . ==== Installed Programs ====================== . . 1912 Titanic Mystery 3 Cards to Dead Time Acrobat.com Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.4.4 Adobe Shockwave Player 11.5 Affair Bureau Aloha Solitaire Apple Application Support Apple Software Update Autumn's Treasures - The Jade Coin Biggest Little Adventure Bing Maps 3D Canon Easy-WebPrint EX Canon Inkjet Printer/Scanner/Fax Extended Survey Program Canon MP Navigator EX 3.0 Canon MP250 series MP Drivers Canon MP250 series User Registration Canon Utilities Easy-PhotoPrint EX Canon Utilities My Printer Canon Utilities Solution Menu CCleaner Chameleon Gems Clone Wars Cradle of Rome Dream Day Wedding Facebook Plug-In Farm Mania 2 Fashion Assistant FaxTools FRANKENSTEIN - The Dismembered Bride FREE Dream Day Honeymoon Free Realms Free Ride Games Player GameHouse Solitaire Challenge GamesBar 2.0.1.81 Google Toolbar for Internet Explorer Google Update Helper Hidden Magic HiJackThis Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows XP (KB2158563) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) ICatch (VI) PC Camera InSpheration Intel® Graphics Media Accelerator Driver Jane Angel - Templar Mystery Java Auto Updater Java™ 6 Update 20 Jewel Charm Liong - The Lost Amulets Little Shop - Memories Little Shop of Treasures 2 Magic Encyclopedia Magic Spheres v1.0 Mahjongg Investigations - Under Suspicion Messenger Plus! 5 Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Antimalware Microsoft Application Error Reporting Microsoft Choice Guard Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft Search Enhancement Pack Microsoft Security Client Microsoft Security Essentials Microsoft Silverlight Microsoft Sync Framework Runtime Native v1.0 (x86) Microsoft Sync Framework Services Native v1.0 (x86) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable - KB2467175 Microsoft Word 2000 Microsoft Works 2000 Microsoft Works 2000 Setup Launcher Monster Mash Mozilla Firefox (3.6.8) MSN MSVCRT MSXML 6.0 Parser Mystery Legends™ - Sleepy Hollow Natalie Brooks - Mystery at Hillcrest High OGA Notifier 2.0.0048.0 Pando Playalot Games Puzzle Solitaire QuickTime Qwest Installer Qwest QuickAssist Desktop Tools Qwest Windows Live Toolbar Buttons Rainbow Web II Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Windows Internet Explorer 8 (KB2183461) Security Update for Windows Internet Explorer 8 (KB2360131) Security Update for Windows Internet Explorer 8 (KB2416400) Security Update for Windows Internet Explorer 8 (KB2482017) Security Update for Windows Internet Explorer 8 (KB2497640) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player (KB979402) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2279986) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165-v2) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981957) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Security Update for Windows XP (KB982802) Segoe UI SoundMAX Strike Ball 3 Sunset Studio - Love on the High Seas Super Collapse! Puzzle Gallery 4 The Lost Cases of Sherlock Holmes The Treasures of Montezuma The Treasures of Mystery Island The Tudors Ulead Photo Explorer 8.0 Unity Web Player Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB980182) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB898461) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB961503) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Update Installer for WildTangent Games App WebFldrs XP WildTangent Games WildTangent Games App Winamp Winamp Detector Plug-in Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 8 Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live ID Sign-in Assistant Windows Live Messenger Windows Live Toolbar Windows Live Upload Tool Windows Media Format Runtime Wizard101 WordSlinger . ==== Event Viewer Messages From Past Week ======== . 5/1/2011 8:35:55 AM, error: Service Control Manager [7034] - The Windows User Mode Driver Framework service terminated unexpectedly. It has done this 1 time(s). 4/30/2011 1:41:40 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 4/25/2011 4:38:47 AM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory. 4/25/2011 4:38:47 AM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver. . ==== End Of File ===========================
Hi whiteroses35,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

I don't know what stopzilla found, but you've got some adware showing.

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
here is my log i did a scan yesterday with malware something cant remember which one now and it found some adware and removed some of it…so this might be different than my first log was….sure hope i did it right and i sure do appreciate the help i am soo lost on this stuff… :huh:



ComboFix 11-05-04.04 - meri 05/05/2011 6:10.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.591 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\meri\Application Data\PriceGong
c:\documents and settings\meri\WINDOWS
c:\windows\system32\config\systemprofile\Application Data\PriceGong
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\1.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\2229.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\5352.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\a.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\b.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\c.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\d.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\e.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\f.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\g.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\h.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\i.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\j.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\k.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\l.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\m.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\mru.xml
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\n.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\o.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\p.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\q.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\r.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\s.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\t.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\u.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\v.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\w.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\wlu.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\x.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\y.txt
c:\windows\system32\config\systemprofile\Application Data\PriceGong\Data\z.txt
c:\windows\XSxS
.
Infected copy of c:\windows\system32\drivers\disk.sys was found and disinfected
Restored copy from - Kitty had a snack :P
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_NPF
.
.
((((((((((((((((((((((((( Files Created from 2011-04-05 to 2011-05-05 )))))))))))))))))))))))))))))))
.
.
2011-05-05 02:48 . 2011-05-05 02:48 ——– d—–w- c:\windows\system32\config\systemprofile\Tracing
2011-05-05 02:24 . 2011-04-11 07:04 7071056 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C0E8585-BA05-4A91-BF43-04E1714847EB}\mpengine.dll
2011-05-05 02:15 . 2011-05-05 02:15 ——– d—–w- c:\program files\Microsoft Security Client
2011-05-05 02:09 . 2011-05-05 02:09 ——– d–h–w- c:\windows\system32\GroupPolicy
2011-05-04 19:30 . 2011-05-04 19:30 ——– d—–w- c:\documents and settings\meri\Application Data\Malwarebytes
2011-05-04 19:30 . 2010-12-21 01:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-04 19:30 . 2011-05-04 19:30 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-05-04 19:30 . 2011-05-04 19:30 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-05-04 19:30 . 2010-12-21 01:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-05-01 18:52 . 2011-05-01 18:52 56400 —-a-w- c:\windows\system32\drivers\tmrkb.sys
2011-05-01 18:52 . 2011-05-01 18:52 ——– d—–w- c:\documents and settings\meri\log
2011-05-01 18:52 . 2011-05-01 18:52 190032 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2011-05-01 18:47 . 2011-05-01 18:47 388096 —-a-r- c:\documents and settings\meri\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-05-01 18:47 . 2011-05-01 19:04 ——– d—–w- c:\program files\Trend Micro
2011-05-01 15:38 . 2011-05-01 18:38 ——– d—–w- c:\documents and settings\All Users\Application Data\STOPzilla!
2011-04-27 13:29 . 2011-04-28 11:56 ——– d—–w- c:\documents and settings\meri\Application Data\MysteryStudio
2011-04-27 13:27 . 2011-04-28 12:28 ——– d—–w- c:\documents and settings\meri\Application Data\Oberon Media
2011-04-27 13:27 . 2011-05-01 15:34 ——– d—–w- c:\documents and settings\All Users\Application Data\GamesBar
2011-04-27 13:27 . 2011-04-27 13:27 ——– d—–w- c:\program files\GamesBar
2011-04-27 12:02 . 2011-04-27 12:02 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\Canon Easy-WebPrint EX
2011-04-27 11:48 . 2011-04-27 11:48 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2011-04-27 11:48 . 2011-04-27 11:48 ——– d-sh–w- c:\windows\system32\config\systemprofile\PrivacIE
2011-04-27 11:48 . 2011-04-27 11:48 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\StumbleUpon
2011-04-26 15:06 . 2011-04-26 15:06 ——– d—–w- c:\documents and settings\All Users\Application Data\CanonIJ
2011-04-26 15:05 . 2011-04-26 15:05 ——– d—–w- c:\documents and settings\meri\Application Data\Canon
2011-04-20 14:27 . 2011-04-20 14:27 ——– d—–w- c:\documents and settings\All Users\Application Data\Sandlot Games
2011-04-14 10:39 . 2011-04-14 10:39 103864 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2011-04-14 10:39 . 2011-04-14 10:39 103864 —-a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-08 23:06 . 2009-08-18 19:30 564632 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\wlidui.dll
2011-03-08 23:06 . 2009-08-18 19:24 18328 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-03-07 05:33 . 2009-12-03 02:10 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37 . 2009-12-03 01:00 420864 —-a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2009-12-03 01:00 1857920 —-a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06 . 2009-12-03 01:00 916480 —-a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06 . 2009-12-03 01:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06 . 2009-12-03 01:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:41 . 2009-12-03 01:00 385024 —-a-w- c:\windows\system32\html.iec
2011-02-17 13:18 . 2009-12-03 01:00 455936 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2009-12-03 01:00 357888 —-a-w- c:\windows\system32\drivers\srv.sys
2011-02-17 12:32 . 2010-04-09 10:02 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56 . 2009-12-03 01:00 290432 —-a-w- c:\windows\system32\atmfd.dll
2011-02-13 21:28 . 2011-02-13 21:28 449 —-a-w- c:\program files\0213201113280473.bat
2011-02-13 15:34 . 2011-02-13 15:34 0 —-a-w- c:\windows\system32\ConduitEngine.tmp
2011-02-09 13:53 . 2009-12-03 01:00 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2009-12-03 01:00 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33 . 2009-12-03 01:00 978944 —-a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33 . 2009-12-03 01:00 974848 —-a-w- c:\windows\system32\mfc42u.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-04-10 39408]
"SearchEngineProtection"="c:\program files\Gamesbar\SearchEngineProtection.exe" [2010-12-29 591248]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Exetender"="c:\program files\Free Ride Games\GPlayer.exe" [2010-07-18 1774080]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10o_ActiveX.exe" [2011-04-12 235168]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Icatch(VI) SnapDetect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Icatch(VI) SnapDetect.lnk
backup=c:\windows\pss\Icatch(VI) SnapDetect.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=c:\windows\pss\Microsoft Works Calendar Reminders.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 06:07 932288 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-31 08:44 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC]
2010-11-30 20:20 997408 —-a-w- c:\program files\Microsoft Security Client\msseces.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-30 01:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 18:43 248040 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2010-04-10 13:19 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiMalware]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Pando Networks\\Pando\\Pando.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"59160:TCP"= 59160:TCP:Pando
"59160:UDP"= 59160:UDP:Pando
.
R1 MpKslf658e70f;MpKslf658e70f;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C0E8585-BA05-4A91-BF43-04E1714847EB}\MpKslf658e70f.sys [5/5/2011 6:17 AM 28752]
R2 sprtlisten;SupportSoft Listener Service;c:\program files\Common Files\SupportSoft\bin\sprtlisten.exe [1/8/2008 12:02 PM 1213728]
R2 X4HSEx;X4HSEx;c:\program files\Free Ride Games\X4HSEx.sys [4/2/2011 8:05 AM 56352]
S1 MpKsl1b92015b;MpKsl1b92015b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{61BC18C7-3CE2-4E2F-80BC-E2E106300FB5}\MpKsl1b92015b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{61BC18C7-3CE2-4E2F-80BC-E2E106300FB5}\MpKsl1b92015b.sys [?]
S1 MpKsl792e9c9e;MpKsl792e9c9e;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C0E8585-BA05-4A91-BF43-04E1714847EB}\MpKsl792e9c9e.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C0E8585-BA05-4A91-BF43-04E1714847EB}\MpKsl792e9c9e.sys [?]
S1 MpKsla2fccd1d;MpKsla2fccd1d;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C0E8585-BA05-4A91-BF43-04E1714847EB}\MpKsla2fccd1d.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C0E8585-BA05-4A91-BF43-04E1714847EB}\MpKsla2fccd1d.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [4/11/2010 5:44 AM 135664]
S3 GamesAppService;GamesAppService;c:\program files\WildTangent Games\App\GamesAppService.exe [10/12/2010 10:59 AM 206072]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [4/11/2010 5:44 AM 135664]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSLF658E70F
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
.
2011-05-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-11 12:44]
.
2011-05-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-11 12:44]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.pogo.com/
uInternet Settings,ProxyOverride =
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
FF - ProfilePath - c:\documents and settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: StumbleUpon: {AE93811A-5C9A-4d34-8462-F7B864FC4696} - %profile%\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
FF - Ext: Zynga Community Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - %profile%\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
FF - Ext: Messenger Plus Live US Community Toolbar: {de404f4c-3cde-4d74-a6fb-052d099c104c} - %profile%\extensions\{de404f4c-3cde-4d74-a6fb-052d099c104c}
FF - Ext: Oberon GamesBar: [removed] - %profile%\extensions\[removed]
FF - Ext: Conduit Engine : [removed] - %profile%\extensions\[removed]
FF - user.js: general.useragent.extra.brc -
.
- - - - ORPHANS REMOVED - - - -
.
Notify-TPSvc - TPSvc.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-05 06:17
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,07,c1,cc,6a,e9,bc,6f,4a,b0,a1,90,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,07,c1,cc,6a,e9,bc,6f,4a,b0,a1,90,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(608)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe
.
**************************************************************************
.
Completion time: 2011-05-05 06:20:49 - machine was rebooted
ComboFix-quarantined-files.txt 2011-05-05 13:20
.
Pre-Run: 443,921,891,328 bytes free
Post-Run: 444,003,495,936 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 971113C6A1E0DE6EF3A14726AD43861B
whiteroses35,

I'm betting things are running better now.

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
hi Tom…yes things are going much better this end….thanks for the help it is kewl u guys are here i would have been lost without some help here!! :wub: does this mean i am cured!? since it didnt find anything?? I sure hope so!! Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6507 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 5/6/2011 5:57:48 AM mbam-log-2011-05-06 (05-57-48).txt Scan type: Quick scan Objects scanned: 154896 Time elapsed: 5 minute(s), 20 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
whiteroses35,

It is definitely looking good.

Let's get an online scan to double-check things.

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
C:\Documents and Settings\meri\My Documents\My Downloads\MsgPlusLive-460.exe a variant of Win32/Adware.CiDHelp application C:\Documents and Settings\meri\My Documents\My Downloads\MsgPlusLive-484.exe a variant of Win32/MessengerPlus application C:\Documents and Settings\meri\My Documents\My Pando Packages\Pogo_Auto411fix_full.rar Win32/Packed.Themida.A trojan C:\Documents and Settings\meri\My Documents\My Pando Packages\from pando…grab bag of goodies\Fix's\Alcohol 120%\keymaker.exe probably a variant of Win32/Agent.CWORLZS trojan C:\Documents and Settings\meri\My Documents\My Pando Packages\Sunset Studio Deluxe\Sunset Studio Deluxe.exe probably a variant of Win32/Spy.Agent.MBMNASI trojan ok here is what it found….how do i get rid of them??? :huh:
Ah…. that explains how you got infected. You've been downloading programs at file sharing sites… including at least one piece of pirated software, and some infected ones.

Guaranteed way to mess up your system.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\Documents and Settings\meri\My Documents\My Downloads\MsgPlusLive-460.exe 
    C:\Documents and Settings\meri\My Documents\My Downloads\MsgPlusLive-484.exe 
    C:\Documents and Settings\meri\My Documents\My Pando Packages\Pogo_Auto411fix_full.rar 
    C:\Documents and Settings\meri\My Documents\My Pando Packages\from pando…grab bag of goodies\Fix's\Alcohol 120%\keymaker.exe 
    C:\Documents and Settings\meri\My Documents\My Pando Packages\Sunset Studio Deluxe\Sunset Studio Deluxe.exe
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
i downloaded them a long time ago tho…i have since been doing much better!! Here is the log it produced..it loaded some files to i dont know where…am i in trouble now?


ComboFix 11-05-04.04 - meri 05/06/2011 17:13:44.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.651 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\meri\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
FILE ::
"c:\documents and settings\meri\My Documents\My Downloads\MsgPlusLive-460.exe"
"c:\documents and settings\meri\My Documents\My Downloads\MsgPlusLive-484.exe"
"c:\documents and settings\meri\My Documents\My Pando Packages\from pando…grab bag of goodies\Fix's\Alcohol 120%\keymaker.exe"
"c:\documents and settings\meri\My Documents\My Pando Packages\Pogo_Auto411fix_full.rar"
"c:\documents and settings\meri\My Documents\My Pando Packages\Sunset Studio Deluxe\Sunset Studio Deluxe.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\meri\My Documents\My Downloads\MsgPlusLive-460.exe
c:\documents and settings\meri\My Documents\My Downloads\MsgPlusLive-484.exe
c:\documents and settings\meri\My Documents\My Pando Packages\from pando…grab bag of goodies\Fix's\Alcohol 120%\keymaker.exe
c:\documents and settings\meri\My Documents\My Pando Packages\Pogo_Auto411fix_full.rar
c:\documents and settings\meri\My Documents\My Pando Packages\Sunset Studio Deluxe\Sunset Studio Deluxe.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-04-07 to 2011-05-07 )))))))))))))))))))))))))))))))
.
.
2011-05-06 13:00 . 2011-04-11 07:04 7071056 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-05-06 13:00 . 2011-04-11 07:04 7071056 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D1927877-DCEC-4377-9077-27EDE012E7BE}\mpengine.dll
2011-05-05 02:48 . 2011-05-05 02:48 ——– d—–w- c:\windows\system32\config\systemprofile\Tracing
2011-05-05 02:15 . 2011-05-05 02:15 ——– d—–w- c:\program files\Microsoft Security Client
2011-05-05 02:09 . 2011-05-05 02:09 ——– d–h–w- c:\windows\system32\GroupPolicy
2011-05-04 19:30 . 2011-05-04 19:30 ——– d—–w- c:\documents and settings\meri\Application Data\Malwarebytes
2011-05-04 19:30 . 2010-12-21 01:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-04 19:30 . 2011-05-04 19:30 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-05-04 19:30 . 2011-05-04 19:30 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-05-04 19:30 . 2010-12-21 01:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-05-01 18:52 . 2011-05-01 18:52 56400 —-a-w- c:\windows\system32\drivers\tmrkb.sys
2011-05-01 18:52 . 2011-05-01 18:52 ——– d—–w- c:\documents and settings\meri\log
2011-05-01 18:52 . 2011-05-01 18:52 190032 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2011-05-01 18:47 . 2011-05-01 18:47 388096 —-a-r- c:\documents and settings\meri\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-05-01 18:47 . 2011-05-01 19:04 ——– d—–w- c:\program files\Trend Micro
2011-05-01 15:38 . 2011-05-01 18:38 ——– d—–w- c:\documents and settings\All Users\Application Data\STOPzilla!
2011-04-27 13:29 . 2011-04-28 11:56 ——– d—–w- c:\documents and settings\meri\Application Data\MysteryStudio
2011-04-27 13:27 . 2011-04-28 12:28 ——– d—–w- c:\documents and settings\meri\Application Data\Oberon Media
2011-04-27 13:27 . 2011-05-01 15:34 ——– d—–w- c:\documents and settings\All Users\Application Data\GamesBar
2011-04-27 13:27 . 2011-04-27 13:27 ——– d—–w- c:\program files\GamesBar
2011-04-27 12:02 . 2011-04-27 12:02 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\Canon Easy-WebPrint EX
2011-04-27 11:48 . 2011-04-27 11:48 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2011-04-27 11:48 . 2011-04-27 11:48 ——– d-sh–w- c:\windows\system32\config\systemprofile\PrivacIE
2011-04-27 11:48 . 2011-04-27 11:48 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\StumbleUpon
2011-04-26 15:06 . 2011-04-26 15:06 ——– d—–w- c:\documents and settings\All Users\Application Data\CanonIJ
2011-04-26 15:05 . 2011-04-26 15:05 ——– d—–w- c:\documents and settings\meri\Application Data\Canon
2011-04-20 14:27 . 2011-04-20 14:27 ——– d—–w- c:\documents and settings\All Users\Application Data\Sandlot Games
2011-04-14 10:39 . 2011-04-14 10:39 103864 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2011-04-14 10:39 . 2011-04-14 10:39 103864 —-a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-08 23:06 . 2009-08-18 19:30 564632 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\wlidui.dll
2011-03-08 23:06 . 2009-08-18 19:24 18328 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-03-07 05:33 . 2009-12-03 02:10 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37 . 2009-12-03 01:00 420864 —-a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2009-12-03 01:00 1857920 —-a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06 . 2009-12-03 01:00 916480 —-a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06 . 2009-12-03 01:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06 . 2009-12-03 01:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:41 . 2009-12-03 01:00 385024 —-a-w- c:\windows\system32\html.iec
2011-02-17 13:18 . 2009-12-03 01:00 455936 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2009-12-03 01:00 357888 —-a-w- c:\windows\system32\drivers\srv.sys
2011-02-17 12:32 . 2010-04-09 10:02 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56 . 2009-12-03 01:00 290432 —-a-w- c:\windows\system32\atmfd.dll
2011-02-13 21:28 . 2011-02-13 21:28 449 —-a-w- c:\program files\0213201113280473.bat
2011-02-13 15:34 . 2011-02-13 15:34 0 —-a-w- c:\windows\system32\ConduitEngine.tmp
2011-02-09 13:53 . 2009-12-03 01:00 270848 —-a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2009-12-03 01:00 186880 —-a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33 . 2009-12-03 01:00 978944 —-a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33 . 2009-12-03 01:00 974848 —-a-w- c:\windows\system32\mfc42u.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-05-05_13.17.28 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-05-07 00:20 . 2011-05-07 00:20 16384 c:\windows\Temp\Perflib_Perfdata_450.dat
- 2011-05-05 13:17 . 2011-05-05 13:17 16384 c:\windows\Temp\Perflib_Perfdata_450.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-04-10 39408]
"SearchEngineProtection"="c:\program files\Gamesbar\SearchEngineProtection.exe" [2010-12-29 591248]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Exetender"="c:\program files\Free Ride Games\GPlayer.exe" [2010-07-18 1774080]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10o_ActiveX.exe" [2011-04-12 235168]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Icatch(VI) SnapDetect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Icatch(VI) SnapDetect.lnk
backup=c:\windows\pss\Icatch(VI) SnapDetect.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=c:\windows\pss\Microsoft Works Calendar Reminders.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 06:07 932288 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-31 08:44 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC]
2010-11-30 20:20 997408 —-a-w- c:\program files\Microsoft Security Client\msseces.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-30 01:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 18:43 248040 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2010-04-10 13:19 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiMalware]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Pando Networks\\Pando\\Pando.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"59160:TCP"= 59160:TCP:Pando
"59160:UDP"= 59160:UDP:Pando
.
R1 MpKslb93ec907;MpKslb93ec907;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D1927877-DCEC-4377-9077-27EDE012E7BE}\MpKslb93ec907.sys [5/6/2011 5:20 PM 28752]
R2 sprtlisten;SupportSoft Listener Service;c:\program files\Common Files\SupportSoft\bin\sprtlisten.exe [1/8/2008 12:02 PM 1213728]
R2 X4HSEx;X4HSEx;c:\program files\Free Ride Games\X4HSEx.sys [4/2/2011 8:05 AM 56352]
S1 MpKsl1b92015b;MpKsl1b92015b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{61BC18C7-3CE2-4E2F-80BC-E2E106300FB5}\MpKsl1b92015b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{61BC18C7-3CE2-4E2F-80BC-E2E106300FB5}\MpKsl1b92015b.sys [?]
S1 MpKsl792e9c9e;MpKsl792e9c9e;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C0E8585-BA05-4A91-BF43-04E1714847EB}\MpKsl792e9c9e.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C0E8585-BA05-4A91-BF43-04E1714847EB}\MpKsl792e9c9e.sys [?]
S1 MpKsla2fccd1d;MpKsla2fccd1d;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C0E8585-BA05-4A91-BF43-04E1714847EB}\MpKsla2fccd1d.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C0E8585-BA05-4A91-BF43-04E1714847EB}\MpKsla2fccd1d.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [4/11/2010 5:44 AM 135664]
S3 CFcatchme;CFcatchme;\??\c:\docume~1\meri\LOCALS~1\Temp\CFcatchme.sys –> c:\docume~1\meri\LOCALS~1\Temp\CFcatchme.sys [?]
S3 GamesAppService;GamesAppService;c:\program files\WildTangent Games\App\GamesAppService.exe [10/12/2010 10:59 AM 206072]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [4/11/2010 5:44 AM 135664]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSLB93EC907
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
.
2011-05-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-11 12:44]
.
2011-05-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-11 12:44]
.
2011-05-07 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 19:26]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://forums.whatthetech.com/index.php?act=UserCP&CODE;=26
uInternet Settings,ProxyOverride =
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
FF - ProfilePath - c:\documents and settings\meri\Application Data\Mozilla\Firefox\Profiles\qt57t2b0.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: StumbleUpon: {AE93811A-5C9A-4d34-8462-F7B864FC4696} - %profile%\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
FF - Ext: Zynga Community Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - %profile%\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
FF - Ext: Messenger Plus Live US Community Toolbar: {de404f4c-3cde-4d74-a6fb-052d099c104c} - %profile%\extensions\{de404f4c-3cde-4d74-a6fb-052d099c104c}
FF - Ext: Oberon GamesBar: [removed] - %profile%\extensions\[removed]
FF - Ext: Conduit Engine : [removed] - %profile%\extensions\[removed]
FF - user.js: general.useragent.extra.brc -
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-06 17:20
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,07,c1,cc,6a,e9,bc,6f,4a,b0,a1,90,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,07,c1,cc,6a,e9,bc,6f,4a,b0,a1,90,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(676)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_179798c8\MSVCR80.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
.
**************************************************************************
.
Completion time: 2011-05-06 17:23:59 - machine was rebooted
ComboFix-quarantined-files.txt 2011-05-07 00:23
ComboFix2.txt 2011-05-05 13:20
.
Pre-Run: 443,877,675,008 bytes free
Post-Run: 443,828,768,768 bytes free
.
- - End Of File - - 83368BDA96500AE5E93F1CF57B3E39D7
whiteroses35,

am i in trouble now?


I don't think so. I think we've gotten everything.

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /Uninstall in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

  • Double click on OTL to run it.
  • Click on CleanUp!
  • When done, you will be prompted to restart your computer. Please restart your computer.

Please re-enable any security that was disabled.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
wow that was complicated sure am glad u was here with me!!! I did everything u said and will read the sections i got listed from u… thanks again for helping me and maybe some day i can learn as much as and help someone. Hope everything goes good for u and u have a wonderful time from ME

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI