This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Start menu wiped out ? Icons gone, cant alt + control + delete

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have no idea what my father did but my whole desktop is gone, start menu is blank and when i alt control and delete it says disabled by admin. I am in safe mode right now and can find some of those files from my other user name. i will post what i can. Thanks


OTL logfile created on: 11/14/2011 9:23:13 PM - Run 2
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Administrator.BASEMENT\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 72.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS.0 | %ProgramFiles% = C:\Program Files
Drive C: | 147.14 Gb Total Space | 98.28 Gb Free Space | 66.79% Space Free | Partition Type: NTFS
Drive D: | 5.52 Gb Total Space | 2.57 Gb Free Space | 46.65% Space Free | Partition Type: NTFS
Drive E: | 242.60 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: BASEMENT | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Documents and Settings\Administrator.BASEMENT\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\WINDOWS.0\explorer.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Administrator.BASEMENT\Desktop\NoLop.exe (PunkTools)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Administrator.BASEMENT\Desktop\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – C:\WINDOWS.0\System32\appmgmts.dll File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (HPSLPSVC) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\HPSLPSVC32.DLL (Hewlett-Packard Co.)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (hpqcxs08) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (hpqddsvc) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (wuauserv) – C:\WINDOWS\system32\wuauserv.dll (Microsoft Corporation)
SRV - (WANMiniportService) WAN Miniport (ATW) – C:\WINDOWS.0\wanmpsvc.exe (America Online, Inc.)


========== Driver Services (SafeList) ==========

DRV - (Lbd) – C:\WINDOWS.0\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (NPF) WinPcap Packet Driver (NPF) – C:\WINDOWS.0\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (MBAMSwissArmy) – C:\WINDOWS.0\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (Tcpip6) – C:\WINDOWS.0\system32\drivers\tcpip6.sys (Microsoft Corporation)
DRV - (NwlnkIpx) – C:\WINDOWS.0\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (nm) – C:\WINDOWS.0\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS.0\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (Cdralw2k) – C:\WINDOWS.0\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) – C:\WINDOWS.0\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (SymEvent) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (cdudf_xp) – C:\WINDOWS.0\System32\drivers\Cdudf_xp.sys (Sonic Solutions)
DRV - (dvd_2K) – C:\WINDOWS.0\System32\drivers\dvd_2k.sys (Sonic Solutions)
DRV - (DVDVRRdr_xp) – C:\WINDOWS.0\System32\drivers\DVDVRRdr_xp.sys (Windows ® 2000 DDK provider)
DRV - (UDFReadr) – C:\WINDOWS.0\System32\drivers\Udfreadr.sys (Sonic Solutions)
DRV - (mmc_2K) – C:\WINDOWS.0\System32\drivers\mmc_2k.sys (Sonic Solutions)
DRV - (pwd_2k) – C:\WINDOWS.0\System32\drivers\Pwd_2k.sys (Sonic Solutions)
DRV - (SYMTDI) – C:\WINDOWS.0\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS.0\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (AFS2K) – C:\WINDOWS.0\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS.0\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ltmodem5) – C:\WINDOWS.0\system32\drivers\ltmdmnt.sys (LT)
DRV - (ALCXSENS) – C:\WINDOWS.0\system32\drivers\ALCXSENS.SYS (Sensaura)
DRV - (viasraid) – C:\WINDOWS.0\System32\DRIVERS\viasraid.sys (VIA Technologies inc,.ltd)
DRV - (psa805) Aurilium Sound Agent 2 (WDM) – C:\WINDOWS.0\system32\drivers\psa805.sys (QSound Labs, Inc.)
DRV - (viaagp1) – C:\WINDOWS.0\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (QsndEnum) – C:\WINDOWS.0\system32\drivers\QsndEnum.sys (QSound Labs, Inc.)
DRV - (NwlnkNb) – C:\WINDOWS.0\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS.0\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS.0\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (ViaIde) – C:\WINDOWS.0\System32\DRIVERS\viaidexp.sys (VIA Technologies, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS.0\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A8 D6 F8 0D 12 82 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.0

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/10/09 11:22:50 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/05/18 11:07:29 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/21 08:08:31 | 000,000,000 | -H-D | M]

[2010/11/11 21:24:44 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.BASEMENT\Application Data\Mozilla\Extensions
[2010/11/11 21:24:44 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.BASEMENT\Application Data\Mozilla\Firefox\Profiles\y4fw1cy4.default\extensions
[2010/11/11 21:24:50 | 000,000,000 | -H-D | M] (No name found) – C:\Documents and Settings\Administrator.BASEMENT\Application Data\Mozilla\Firefox\Profiles\y4fw1cy4.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/11/11 21:24:49 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.BASEMENT\Application Data\Mozilla\Firefox\Profiles\y4fw1cy4.default\extensions\staged-xpis
[2006/09/27 19:21:40 | 000,000,000 | -H-D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/18 11:06:13 | 000,000,000 | -H-D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]

O1 HOSTS File: ([2008/08/26 08:42:00 | 000,259,167 | RH– | M]) - C:\WINDOWS.0\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 9024 more lines…
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Shareaza Web Download Hook) - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\CreativesFiles\RazaWebHook32.dll (Shareaza Development Team)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2 - BHO: (AOL Toolbar Launcher) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1168712829\ee\AOLSoftware.exe (AOL Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS.0\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www2.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-24-0.cab (EPUImageControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://picture.vzw.com/activex/VerizonWire…loadControl.cab (Verizon Wireless Media Upload)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} https://www.secure-session.com/include/XUpload.ocx (Persits Software XUpload)
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} http://216.249.24.62/code/iPIX-ImageWell-ipix.cab (iPIX Media Send Class)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS.0\explorer.exe (Microsoft Corporation)
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/10/10 21:32:03 | 000,000,000 | -H– | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS.0\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/11/14 20:37:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.BASEMENT\Local Settings\Application Data\Adobe
[2011/11/14 20:36:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.BASEMENT\Application Data\Malwarebytes
[2011/11/14 15:35:40 | 000,494,592 | -H– | C] (Rec0ver Inc) – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\WNicVIllUbjiXg.exe
[5 C:\WINDOWS.0\System32\*.tmp files -> C:\WINDOWS.0\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/14 21:15:57 | 000,000,486 | —- | M] () – C:\WINDOWS.0\tasks\Ad-Aware Update (Weekly).job
[2011/11/14 21:15:43 | 000,002,048 | –S- | M] () – C:\WINDOWS.0\bootstat.dat
[2011/11/14 20:42:16 | 000,000,899 | -HS- | M] () – C:\boot.ini
[2011/11/14 20:34:13 | 000,001,374 | -H– | M] () – C:\WINDOWS.0\System32\wpa.dbl
[2011/11/14 15:33:19 | 000,069,530 | -H– | M] () – C:\VETlog.dmp
[2011/11/14 15:31:36 | 000,494,592 | -H– | M] (Rec0ver Inc) – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\WNicVIllUbjiXg.exe
[2011/11/13 09:46:00 | 000,000,064 | -H– | M] () – C:\WINDOWS.0\System32\rp_stats.dat
[2011/11/13 09:46:00 | 000,000,044 | -H– | M] () – C:\WINDOWS.0\System32\rp_rules.dat
[2011/11/10 02:00:11 | 000,000,338 | -H– | M] () – C:\WINDOWS.0\tasks\AdobeAAMUpdater-1.0-BASEMENT-Tom.job
[5 C:\WINDOWS.0\System32\*.tmp files -> C:\WINDOWS.0\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/17 10:24:58 | 000,000,010 | -H– | C] () – C:\WINDOWS.0\msoffice.ini
[2010/04/08 22:30:03 | 000,009,916 | -HS- | C] () – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\6e6301sD6p
[2009/12/15 14:06:50 | 000,044,544 | -H– | C] () – C:\WINDOWS.0\System32\GIF89.DLL
[2009/11/26 08:37:08 | 000,323,584 | -H– | C] () – C:\WINDOWS.0\System32\FoxImager.dll
[2008/10/06 11:29:11 | 000,065,536 | -H– | C] () – C:\WINDOWS.0\System32\HPPLVS.dll
[2008/03/13 02:01:49 | 000,003,413 | -H– | C] () – C:\WINDOWS.0\System32\MRT.INI
[2007/12/11 14:43:44 | 000,012,288 | -H– | C] () – C:\WINDOWS.0\System32\DivXWMPExtType.dll
[2007/10/15 09:53:34 | 000,000,722 | -H– | C] () – C:\WINDOWS.0\wininit.ini
[2007/08/05 22:05:34 | 000,005,252 | -H– | C] () – C:\WINDOWS.0\CDPlayer.ini
[2007/08/05 22:04:53 | 000,000,503 | -H– | C] () – C:\WINDOWS.0\CDRip.INI
[2007/08/05 22:04:21 | 000,151,040 | -H– | C] () – C:\WINDOWS.0\System32\wimadll.dll
[2007/07/26 11:01:50 | 000,114,688 | -H– | C] () – C:\WINDOWS.0\System32\hppatusg01.dll
[2007/04/22 19:15:29 | 003,596,288 | -H– | C] () – C:\WINDOWS.0\System32\qt-dx331.dll
[2007/02/15 22:53:03 | 000,000,147 | -H– | C] () – C:\WINDOWS.0\bizpub32.INI
[2007/02/03 10:19:55 | 000,000,003 | -H– | C] () – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\DragToDiscUserNameF.txt
[2007/02/03 08:09:30 | 000,000,926 | -H– | C] () – C:\WINDOWS.0\CDRipper.ini
[2007/01/13 13:25:07 | 000,000,030 | -H– | C] () – C:\WINDOWS.0\atid.ini
[2006/11/16 13:25:12 | 000,000,754 | -H– | C] () – C:\WINDOWS.0\WORDPAD.INI
[2006/10/16 00:08:20 | 000,001,759 | -H– | C] () – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\QTSBandwidthCache
[2006/10/12 01:23:14 | 000,002,473 | -H– | C] () – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\hpzinstall.log
[2006/10/11 23:34:50 | 000,000,061 | -H– | C] () – C:\WINDOWS.0\smscfg.ini
[2006/10/11 23:27:54 | 000,363,520 | -H– | C] () – C:\WINDOWS.0\System32\psisdecd.dll
[2006/10/11 16:20:03 | 000,004,249 | -H– | C] () – C:\WINDOWS.0\ODBCINST.INI
[2004/09/17 16:37:42 | 000,069,632 | -H– | C] () – C:\WINDOWS.0\System32\vuins32.dll
[2004/02/09 18:18:18 | 000,155,648 | -H– | C] () – C:\WINDOWS.0\System32\RTLCPAPI.dll
[2003/10/31 16:28:25 | 000,000,312 | -H– | C] () – C:\WINDOWS.0\System32\OEMINFO.INI
[2003/03/08 23:31:04 | 000,561,152 | -H– | C] () – C:\WINDOWS.0\System32\hpotscl.dll

========== LOP Check ==========

[2007/07/16 14:55:53 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.BASEMENT\Application Data\Viewpoint
[2007/07/16 18:30:01 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\cake link byte time
[2011/02/22 13:45:09 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\regid.1986-12.com.adobe
[2007/01/22 00:36:28 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Viewpoint
[2011/11/14 21:15:57 | 000,000,486 | —- | M] () – C:\WINDOWS.0\Tasks\Ad-Aware Update (Weekly).job
[2009/01/27 23:26:20 | 000,000,338 | -H– | M] () – C:\WINDOWS.0\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1224905129.job

< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:43:43 PM, on 11/14/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS.0\System32\smss.exe
C:\WINDOWS.0\system32\winlogon.exe
C:\WINDOWS.0\system32\services.exe
C:\WINDOWS.0\system32\lsass.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS.0\Explorer.exe
C:\Documents and Settings\Administrator.BASEMENT\Desktop\NoLop.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS.0\system32\ctfmon.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Administrator.BASEMENT\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\CreativesFiles\RazaWebHook32.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1168712829\ee\AOLSoftware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS.0\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS.0\system32\Macromed\Flash\FlashUtil10q_ActiveX.exe -update activex
O4 - HKUS\S-1-5-21-1415427462-1084713858-833570676-500\..\Run: [ctfmon.exe] C:\WINDOWS.0\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-1415427462-1084713858-833570676-500\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS.0\system32\Macromed\Flash\FlashUtil10q_ActiveX.exe -update activex (User '?')
O4 - HKUS\S-1-5-18\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.1b\AOL.EXE" -b (User '?')
O4 - HKUS\.DEFAULT\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.1b\AOL.EXE" -b (User 'Default user')
O4 - .DEFAULT User Startup: Organize.lnk = ? (User 'Default user')
O4 - .DEFAULT User Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.0\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.0\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows.0\system32\nwprovau.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-24-0.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://picture.vzw.com/activex/VerizonWire…loadControl.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - https://www.secure-session.com/include/XUpload.ocx
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.62/code/iPIX-ImageWell-ipix.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS.0\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS.0\System32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS.0\wanmpsvc.exe

–
End of file - 8348 bytes

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, v6rs97

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.
Hi,

Please download Unhide.exe to your desktop:
  • Double-click on the Unhide.exe icon on your desktop and allow the program to run.
  • This program will remove the hidden attributes from all the files on your system.
  • Note: If you had purposely hidden any files, then you will need to hide them again after this tool has run.
===================================================

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

On your next reply please post :
GMER log
Report on system behavior


Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI