OKAY here is OTL run again
(while this was happening my Security Essentials program window opened up to inform me that this history threat should be removed from my computer, so I clicked OK)
OTL logfile created on: 12/4/2011 12:40:05 PM - Run 4
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Brian\Desktop\VIRUS FIX
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
991.48 Mb Total Physical Memory | 564.52 Mb Available Physical Memory | 56.94% Memory free
2.34 Gb Paging File | 1.99 Gb Available in Paging File | 85.16% Paging File free
Paging file location(s): C:\pagefile.sys 1488 2976 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 131.37 Gb Free Space | 88.14% Space Free | Partition Type: NTFS
Computer Name: BRIANS | User Name: Brian | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Brian\Desktop\VIRUS FIX\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\ltmsg.exe (Agere Systems)
PRC - C:\Program Files\Visioneer OneTouch\OneTouchMon.exe (Visioneer Inc)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Adobe\Reader 9.0\Reader\ViewerPS.dll ()
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (MpKslef447c30) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{98D84950-D20A-4ABC-B0FC-50D96E5F24CA}\MpKslef447c30.sys (Microsoft Corporation)
DRV - (KMWDFILTER) – C:\WINDOWS\system32\drivers\KMWDFILTER.sys (Windows ® Codename Longhorn DDK provider)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (nvnforce) Service for NVIDIA® nForce™ – C:\WINDOWS\system32\drivers\nvapu.sys (NVIDIA Corporation)
DRV - (nvax) Service for NVIDIA® nForce™ – C:\WINDOWS\system32\drivers\nvax.sys (NVIDIA Corporation)
DRV - (ltmodem5) – C:\WINDOWS\system32\drivers\ltmdmnt.sys (Agere Systems)
DRV - (NVENET) – C:\WINDOWS\system32\drivers\NVENET.sys (NVIDIA Corporation)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (ppsio2) – C:\WINDOWS\System32\drivers\ppsio2.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
O1 HOSTS File: ([2003/07/16 15:29:34 | 000,000,734 | -H– | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [LTMSG] C:\WINDOWS\ltmsg.exe (Agere Systems)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [OneTouch Monitor] C:\Program Files\Visioneer OneTouch\OneTouchMon.exe (Visioneer Inc)
O4 - HKCU..\Run: [PPWebCap] C:\Program Files\ScanSoft\PaperPort\PPWEBCAP.EXE (Scansoft Inc.)
O4 - Startup: C:\Documents and Settings\Brian\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &ieSpell Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Check &Spelling - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Lookup on Merriam Webster - C:\Program Files\ieSpell\Merriam Webster.HTM ()
O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files\ieSpell\wikipedia.HTM ()
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {38AB0814-B09B-4378-9940-14A19638C3C2}
http://www.auctiva.com/Aurigma/ImageUploader57.cab (Auctiva Image Uploader Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/…b?1281530804562 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu…b?1281533633281 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{74154A94-5F2B-46A0-A274-CDAA7769E700}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (NVDESK32.DLL) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/11 07:36:55 | 000,000,000 | -H– | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/12/04 11:35:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Brian\Desktop\VIRUS FIX
[2011/12/03 11:22:48 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Brian\Recent
[2011/11/30 12:51:07 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Brian\Start Menu\Programs\System Fix
[2011/11/15 15:55:56 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Brian\My Documents\DudleyDix 55 stuff
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/04 12:44:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{2DD1C23A-87F8-45BF-96AB-C10466627E93}.job
[2011/12/04 12:30:22 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/12/04 12:25:04 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/04 12:25:03 | 1039,716,352 | -HS- | M] () – C:\hiberfil.sys
[2011/12/04 10:43:32 | 000,111,872 | —- | M] () – C:\WINDOWS\System32\drivers\TrueSight.sys
[2011/12/03 11:21:55 | 000,013,646 | -H– | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/11/30 12:51:32 | 000,000,416 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\IBGAOVNqVpnBcv
[2011/11/30 12:51:09 | 000,000,312 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcv
[2011/11/30 12:51:09 | 000,000,216 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcvr
[2011/11/30 12:44:04 | 000,445,312 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\vMttfGqwJXmmgo.exe
[2011/11/29 13:14:46 | 000,000,077 | -H– | M] () – C:\WINDOWS\mydebug.ini
[2011/11/25 11:11:06 | 000,263,214 | -H– | M] () – C:\Documents and Settings\Brian\Desktop\Hydrogen Peroxide Cancer Treatment - Alternative Cancer Treatments.mht
[2011/11/24 13:03:02 | 000,000,284 | -H– | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/24 00:27:43 | 000,414,368 | -H– | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/11/23 14:58:51 | 000,054,017 | -H– | M] () – C:\Documents and Settings\Brian\Desktop\A47-aft-deck-7.jpg
[2011/11/09 22:51:57 | 000,001,374 | -H– | M] () – C:\WINDOWS\imsins.BAK
[2011/11/09 17:34:04 | 000,292,513 | -H– | M] () – C:\Documents and Settings\Brian\My Documents\NorCore plastic honeycomb.pdf
[2011/11/06 09:47:05 | 000,311,604 | -H– | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/11/06 09:47:05 | 000,039,992 | -H– | M] () – C:\WINDOWS\System32\perfc009.dat
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/04 11:30:53 | 1039,716,352 | -HS- | C] () – C:\hiberfil.sys
[2011/12/04 08:47:57 | 000,111,872 | —- | C] () – C:\WINDOWS\System32\drivers\TrueSight.sys
[2011/11/30 12:51:09 | 000,000,312 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcv
[2011/11/30 12:51:09 | 000,000,216 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcvr
[2011/11/30 12:51:03 | 000,000,416 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\IBGAOVNqVpnBcv
[2011/11/30 12:47:08 | 000,445,312 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\vMttfGqwJXmmgo.exe
[2011/11/25 11:11:06 | 000,263,214 | -H– | C] () – C:\Documents and Settings\Brian\Desktop\Hydrogen Peroxide Cancer Treatment - Alternative Cancer Treatments.mht
[2011/11/23 17:06:48 | 000,054,017 | -H– | C] () – C:\Documents and Settings\Brian\Desktop\A47-aft-deck-7.jpg
[2011/11/09 17:34:04 | 000,292,513 | -H– | C] () – C:\Documents and Settings\Brian\My Documents\NorCore plastic honeycomb.pdf
[2011/07/13 18:13:34 | 000,000,077 | -H– | C] () – C:\WINDOWS\mydebug.ini
[2010/12/14 09:58:02 | 000,023,200 | -H– | C] () – C:\WINDOWS\System32\drivers\ppsio2.sys
[2010/12/14 09:52:34 | 000,000,090 | -H– | C] () – C:\WINDOWS\calera.ini
[2010/09/13 16:26:58 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/09/11 16:47:33 | 000,006,656 | -H– | C] () – C:\Documents and Settings\Brian\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/25 19:33:07 | 000,001,456 | -H– | C] () – C:\WINDOWS\MAXLINK.INI
[2010/08/25 19:33:00 | 000,269,312 | -H– | C] () – C:\WINDOWS\System32\FPXIG.DLL
[2010/08/25 19:33:00 | 000,068,096 | -H– | C] () – C:\WINDOWS\System32\IGFPX32P.DLL
[2010/08/25 19:33:00 | 000,065,024 | -H– | C] () – C:\WINDOWS\System32\JPEGACC.DLL
[2010/08/25 19:32:40 | 000,101,376 | -H– | C] () – C:\WINDOWS\System32\WELSOF32.DLL
[2010/08/17 20:58:39 | 000,000,664 | -H– | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/08/11 08:09:31 | 000,004,569 | -H– | C] () – C:\WINDOWS\System32\secupd.dat
[2010/08/11 07:41:07 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/08/11 07:34:53 | 000,021,640 | -H– | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/08/11 03:31:43 | 000,004,161 | -H– | C] () – C:\WINDOWS\ODBCINST.INI
[2010/08/11 03:30:24 | 000,119,744 | -H– | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2003/07/16 15:54:55 | 000,004,594 | -H– | C] () – C:\WINDOWS\System32\oembios.dat
[2003/07/16 15:54:54 | 013,107,200 | -H– | C] () – C:\WINDOWS\System32\oembios.bin
[2003/07/16 15:41:25 | 000,311,604 | -H– | C] () – C:\WINDOWS\System32\perfh009.dat
[2003/07/16 15:41:25 | 000,272,128 | -H– | C] () – C:\WINDOWS\System32\perfi009.dat
[2003/07/16 15:41:23 | 000,028,626 | -H– | C] () – C:\WINDOWS\System32\perfd009.dat
[2003/07/16 15:41:21 | 000,039,992 | -H– | C] () – C:\WINDOWS\System32\perfc009.dat
[2003/07/16 15:39:07 | 000,000,741 | -H– | C] () – C:\WINDOWS\System32\noise.dat
[2003/07/16 15:33:50 | 000,673,088 | -H– | C] () – C:\WINDOWS\System32\mlang.dat
[2003/07/16 15:33:39 | 000,046,258 | -H– | C] () – C:\WINDOWS\System32\mib.bin
[2003/07/16 15:27:41 | 000,218,003 | -H– | C] () – C:\WINDOWS\System32\dssec.dat
[2003/07/16 15:26:37 | 000,001,804 | -H– | C] () – C:\WINDOWS\System32\dcache.bin
[2002/03/31 13:03:00 | 000,001,024 | -H– | C] () – C:\WINDOWS\System32\drivers\jedih2rx.bin
[2002/03/31 13:03:00 | 000,000,122 | -H– | C] () – C:\WINDOWS\System32\drivers\ramsed.bin
========== Custom Scans ==========
< :Services >
< >
< :OTL >
< [2011/11/30 12:51:32 | 000,000,416 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\IBGAOVNqVpnBcv >
Invalid Switch: 30 12:51:32 | 000,000,416 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\IBGAOVNqVpnBcv
< [2011/11/30 12:51:09 | 000,000,831 | -H– | M] () – C:\Documents and Settings\Brian\Desktop\System Fix.lnk >
Invalid Switch: 30 12:51:09 | 000,000,831 | -H– | M] () – C:\Documents and Settings\Brian\Desktop\System Fix.lnk
< [2011/11/30 12:51:09 | 000,000,312 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcv >
Invalid Switch: 30 12:51:09 | 000,000,312 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcv
< [2011/11/30 12:51:09 | 000,000,216 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcvr >
Invalid Switch: 30 12:51:09 | 000,000,216 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcvr
< [2011/11/30 12:50:56 | 000,352,256 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\IBGAOVNqVpnBcv.exe >
Invalid Switch: 30 12:50:56 | 000,352,256 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\IBGAOVNqVpnBcv.exe
< [2011/11/30 12:55:05 | 000,000,849 | -H– | C] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk >
Invalid Switch: 30 12:55:05 | 000,000,849 | -H– | C] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk
< >
< :Commands >
< [purity] >
< [Reboot] >
< >
< End of report >