This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Tried Everything, Nothing Works

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I noticed my computer start to slow down and become incapable of performing many tasks, including browsing the internet and playing media files. I have Spybot Search and Destroy. It found three viruses, which I got rid of. The problem with my computer persists. I downloaded Ad Aware and deleted dozens of malware. The problem is still here, and I don't know what to do.

I am using a Dell XPS which I purchased new a few years ago. It runs Windows XP and I have both IE (the latest one) and Firefox (the latest one) both of which work at a snail's pace.

I defragged my system and have 16% of my hard drive free. I deleted all unneccesary files and programs. I really do not want to reformat, so I am hoping I can find some other solution. Here is my Hijack This! log file, and I have included a description in greater detail of my problems after it:

Logfile of HijackThis v1.99.1
Scan saved at 8:15:45 PM, on 6/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Common Files\AOL\1147441616\ee\AOLSoftware.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\D-Link\AirPlus G Wireless Adapter Utility\AirPlus.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\M-Audio MobilePre\MPTask.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
c:\programfiles\Winamp\winamp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.brandonmdennis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1147441616\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: D-Link AirPlus G Wireless Utility.lnk = ?
O4 - Global Startup: D-Link REG Utility.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: M-Audio MobilePre Control Panel Launcher.lnk = C:\Program Files\M-Audio MobilePre\MPTask.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01CA75F1-054B-4A63-9221-C6926369EC52} (HS_live Control) - http://install.homestead.com/~site/Install…ive/HS_live.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {5AA5A569-F96F-4628-A528-8B3698F558BB} (HS_live Control) - http://install.homestead.com/~site/Install…ive/HS_live.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1128709406296
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup161.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MobilePre Installer (MobilePreInstallerService) - M-Audio - C:\Program Files\M-Audio MobilePre\Install\MPInst.exe

I make animated movies for distrobution on the internet using Adobe Premiere Pro and programs like Fraps to record footage. The reason this system slowdown is so critical is because I cannot record smooth footage with my computer hitching and hiccuping all over the place. I have to open up the Windows Task Manager, wait for the CPU Usage meter to drop down to between 2-6% before I start recording. Then I only have about 10 seconds where I can record before my computer starts to hitch up. After I save the file, I have to wait 2 or 3 minutes for the CPU Usage meter to drop down to between 2-6% again.

Most of the time, however, my CPU Usage is at 100%, even when I am not running any programs and I have turned off all background applications. The greatest CPU hogs are: svchost.exe and system idle process. The greatest Mem Usage hogs are explorer.exe, svchost.exe.

It is so bad that I cannot watch streaming media or any videos I have saved to my computer. When I type text into an internet field, it takes a good 30 seconds for the entirety of what I have typed to appear. Also, my internal fan runs on high from the moment I turn my computer on until I turn it off. The outside plastic case is hot to the touch–not so much that it burns, but it is uncomfortable. I have tried proping it up off the table and placing fans behind and below it, and it still doesnt help.

Thanks for the help. Sorry for the spelling errors, but I am not about to wait thirty minutes for Word to load so I can spell check, heh.
Hello oxhorn and Welcome to TomCoyote,

Please do the following:

Also I do not see a firewall application installed. Perhaps you have a hardware firewall but a combination of both a software firewall and a hardware firewall is better. Just be sure there are no conflicts. Please do not rely solely on the Windows XP firewall. Using a software firewall other than the XP firewall will allow you to give/deny access for applications that want to go online. Select one of these, or another of your choice:
Please test your firewall and make sure it is working properly.
Test Firewall


======
Please download AVG Anti-Spyware from HERE
and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition files.
  • On the main screen
    • select the icon "Update"
    • then select the "Update now" link.
    • Next select the "Start Update" button,
    the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select ""Quarantine".".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found
    "
If you are having problems with the updater, you can use this link to manually update AVG Anti-spyware.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
______________________________

Close AVG Anti-Spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting
    your computer and continually tapping the F8 key until a menu appears.
    Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or
    programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • AVG Anti-Spyware will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it to a text file on your system (make sure to remember where
    you saved that file, this is important).
  • Close AVG Anti-Spyware and reboot your system back into Normal Mode.
======
Deckard’s System Scanner

Download
Deckard's System Scanner (DSS)
to your Desktop. Note: You must be logged onto an account with administrator privileges.
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt to your post. in your reply
Please post(reply) with the logs from the AVG anti-spyware and the Deckard’s System Scanner.
Thank you Susan!

I was relying solely on Windows Firewall previously. I downloaded and installed COMODO and tested it. Both the Simple Probe and the Port Scan came back ok. COMODO keeps freaking out with GoogleDesktop. I think things are ok, but should I uninstall GoogleDesktop?

I downloaded and installed the AVG Anti-Spyware. I also updated it. I rebooted in safe mode to run it, but when I tried to run it I got the following message: “connection to service failed. Please reinstall AVG Anti-Spyware 7.5”. I thought that I might have needed an internet connection, so I rebooted in safe mode with networking but got the same message. So I uninstalled it, reinstalled it in safe mode and installed the updates in safe mode, but I got the same message.

So I ran the program in normal mode. It took nearly 5 hours to do a full system scan. It found 41 objects (94 traces), and I clicked “Apply all actions”. I then clicked on Reports but I saw the message “No reports available” even though I had chosen “automatically generate report after every scan” in the settings and followed your other directions precisely.

I downloaded and ran Deckard’s System Scanner. Here are the logs, first MAIN then EXTRA:

Deckard's System Scanner v20070603.47
Run by [removed] on 2007-06-04 at 16:23:40
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

Successfully created a Deckard's System Scanner Restore Point.


– Last 5 Restore Point(s) –
59: 2007-06-04 21:24:18 UTC - RP953 - Deckard's System Scanner Restore Point
58: 2007-06-04 07:01:45 UTC - RP952 - System Checkpoint
57: 2007-06-03 06:21:31 UTC - RP951 - System Checkpoint
56: 2007-05-29 23:13:08 UTC - RP950 - System Checkpoint
55: 2007-05-28 22:44:54 UTC - RP949 - System Checkpoint


– First Restore Point –
1: 2007-03-17 18:37:07 UTC - RP895 - System Checkpoint


Backed up registry hives.

Performed disk cleanup.


– HijackThis (run as Oxhorn.exe) ———————————————-

Logfile of HijackThis v1.99.1
Scan saved at 4:42:34 PM, on 6/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\D-Link\AirPlus G Wireless Adapter Utility\AirPlus.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Documents and Settings\Oxhorn\Local Settings\Temporary Internet Files\Content.IE5\TOY7MC2N\dss[1].exe
C:\PROGRA~1\HIJACK~1\Oxhorn.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.brandonmdennis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1147441616\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: D-Link AirPlus G Wireless Utility.lnk = ?
O4 - Global Startup: D-Link REG Utility.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: M-Audio MobilePre Control Panel Launcher.lnk = C:\Program Files\M-Audio MobilePre\MPTask.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01CA75F1-054B-4A63-9221-C6926369EC52} (HS_live Control) - http://install.homestead.com/~site/Install…ive/HS_live.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {5AA5A569-F96F-4628-A528-8B3698F558BB} (HS_live Control) - http://install.homestead.com/~site/Install…ive/HS_live.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1128709406296
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup161.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MobilePre Installer (MobilePreInstallerService) - M-Audio - C:\Program Files\M-Audio MobilePre\Install\MPInst.exe


– HijackThis Fixed Entries (C:\PROGRA~1\HIJACK~1\backups\) ——————–

backup-20060818-180105-655 O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
backup-20060818-180105-875 O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
backup-20060818-180105-958 O2 - BHO: (no name) - {202a961f-23ae-42b1-9505-ffe3c818d717} - C:\Program Files\Media-Codec\isaddon.dll (file missing)
backup-20060819-164035-103 O4 - HKCU\..\Run: [7f243775.exe] C:\Documents and Settings\Oxhorn\Local Settings\Application Data\7f243775.exe
backup-20060819-164035-871 O4 - HKLM\..\Run: [7f243775.exe] C:\WINDOWS\system32\7f243775.exe

– File Associations ———————————————————–

.bat - batfile - DefaultIcon - C:\WINDOWS\System32\shell32.dll,-153
.hlp - hlpfile - DefaultIcon - C:\WINDOWS\hh.exe,0
.inf - inffile - DefaultIcon - C:\WINDOWS\System32\shell32.dll,-151
.ini - inifile - DefaultIcon - C:\WINDOWS\System32\shell32.dll,-151
.reg - regfile - DefaultIcon - C:\WINDOWS\regedit.exe,1
.txt - txtfile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,-152


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R1 APPDRV - c:\windows\system32\drivers\appdrv.sys
I tried again with AVG Anti-Spyware and was this time able to generate a repot. Nothing was found, however: ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 4:09:10 AM 6/5/2007 + Scan result: Nothing found. ::Report end
Have you noticed any difference since you ran the virus scans?

PCPitStop

Please register (it's free, don't worry) with PCPitStop and run the full tests here.
When the tests are complete, a results page will pop up. Click "Share these results with TechExpress" on the left-hand side. Then copy the URL provided and post (reply) with it here for me.

Deckard's Association File Tool (DAFT)

Please download Deckard's Association File Tool (DAFT) and save it to your desktop:
  • Double-click the daft.exe icon. Read the disclaimer and click OK.
  • Click on the Scan button.
  • If it finds faulty file associations, they will appear in red beside a checkbox. If this occurs, just place a tick in the boxes in question.
  • Click the Fix button.
  • Re-scan and save a logfile. By default, it will save as daft.txt.

Post the contents of that logfile with your next post
.

You should print these instructions or save these to a text file. Follow these instructions carefully.

Download Dr.Web CureIt to the desktop -> ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

Restart your computer to the safe mode:
  • Restart your computer
  • Start tapping the F8 key when the computer restarts.
  • When the start menu opens, choose Safe mode
  • Press Enter. The computer then begins to start in Safe mode.

Run a scan with Dr.Web CureIt
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, you should now mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found [external image: Posted Image]
  • If so, click it and then click the next icon right below and select Move incurable
    [external image: Posted Image]
  • After the scan, in the menu, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot the computer in Normal Mode,
  • Post the Cure-it report and a fresh HijackThis log and the DAFT report
http://users.telenet.be/bluepatchy/miekiem…mages/check.gif
Thanks again for all the help. No, I haven’t really noticed a difference in my computer’s performance yet. My fan is still spinning at top speed, and my CPU is still maxed at 100%. Here is the pit stop report:

http://www.pcpitstop.com/techexpress.asp?id=F0YDHW8HYFVS60SW

Here are the results from the DAFT log:

DAFT Log saved on 2007-06-05 16:38:46
———————————————————————–
All associations okay!

And, after nearly ten hours of checking, here is the Dr.Web report:

gdnUS2218.exe;C:\Deckard\System Scanner\backup\WINDOWS\Downloaded Program Files;Trojan.DownLoader.based;Deleted.;
setup.exe;C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\3869.9.20;Probably BACKDOOR.Trojan;Incurable.Moved.;
inst.exe;C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\3899.1.16;Probably BACKDOOR.Trojan;Incurable.Moved.;
inst.exe;C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\3999.1.4;Probably BACKDOOR.Trojan;Incurable.Moved.;
inst.exe;C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\SUDS\CACHE\4024.2.4;Probably BACKDOOR.Trojan;Incurable.Moved.;
inst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\AIMSUD338;Probably BACKDOOR.Trojan;Incurable.Moved.;
inst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\SUD4024;Probably BACKDOOR.Trojan;Incurable.Moved.;
setup.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install_2.0.7.1;Probably BACKDOOR.Trojan;Incurable.Moved.;
GTDownDE_87.ocx;C:\I386;Adware.Gdown;Incurable.Moved.;
aolsetup.exe;C:\Program Files\AIM6\services\softwareUpdate\ver2_13_13_7;Probably BACKDOOR.Trojan;Incurable.Moved.;
A0110742.exe;C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP969;Trojan.DownLoader.based;Deleted.;

And here is my new HijackThis! Log:

Logfile of HijackThis v1.99.1
Scan saved at 6:44:40 AM, on 6/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.brandonmdennis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01CA75F1-054B-4A63-9221-C6926369EC52} (HS_live Control) - http://install.homestead.com/~site/Install…ive/HS_live.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {5AA5A569-F96F-4628-A528-8B3698F558BB} (HS_live Control) - http://install.homestead.com/~site/Install…ive/HS_live.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1128709406296
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup161.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MobilePre Installer (MobilePreInstallerService) - M-Audio - C:\Program Files\M-Audio MobilePre\Install\MPInst.exe

*heads to bed*
My problems persist. For the first ten or so minutes after letting my computer rest for hours, it works just fine. But then it starts to lag and hitch up. If I play a media file, like .wmv, I get about 1/3rd of the way through it, and then all I hear is audio while the video jumps all around. When I open IE or firefox, my CPU Usage skyrockets to 100% and stays there until I stop browsing. When I record footage and save new media files to my hard drive, my CPU Usage again skyrockets to 100% and stays there for five minutes or so, even after I shut off my recording software. If I alt+tab or switch to a minimized window, my CPU Usage again jumps to 100%. It is so bad that I can't browse the internet or even open folders on my desktop without my computer taking three or four minutes to process. Right now the text I am typing in this field is slowly being added, letter by letter. I stopped typing minutes ago, but this paragraph is continuing to write long after I stopped typing. My CPU Usage will eventually go down to 1-2%, but as soon as I open IE, a new folder or any file, it shoots to 100%. PF Usage stays at 350 MB and never moves.
Dr.WebCureit found backdoors– you should read this.
When should I re-format? How should I reinstall?

======
Combofix by sUBs
  • Download this file - combofix.exe
  • Double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

======
Uninstall Manager

Let's see if we can find out what it got installed with.
  • Open HijackThis
  • Click on the configure button on the bottom right
  • Click on the tab "Misc Tools"
  • Click on the Box that says "Uninstall Manager"
  • Click on the button "Save list"
  • Copy and past the List from notepad into your post
======
MWAV Scan
Please download MWAV to a convenient location.
This scan only produces a report, it doesn't clean your system. I will analyze the report and recommend a course of action depending on the results.
This scan might take around 3+ hours to finish when set to scan everything.

Double-click on mwav.exe.
Put a check next to the below items before scanning:
  • Memory
  • Startup Folders
  • Drive - All Local Drives
  • Folder - then click "browse" to change the directory to C: (default is C:\Windows)
  • Registry
  • System Folders
  • Services
  • Include Sub-Directory
  • Scan All Files
Please make sure ALL of these are checked, then press the Scan button. This typically will take hours to complete.

**NOTE*** Sometimes MWav will pause and it appears to be finished, but it isn't done. Just let it run until it says it's complete.

On the bottom portion of the window, you will see the lower panel where MWav is listing "infected items", please highlight everything in that lower panel and copy them by holding CTRL + C then paste it here. The whole log will be extremely BIG so there is no way to post the log. I just need the infected items list.



Please post the ComboFix log, the uninstall list, the report from MWAV, and a new hijackthis log.
Here is the log from ComboFix:

"Oxhorn" - 2007-06-09 7:33:30 Service Pack 2 NTFS
ComboFix 07-06-3B - Running from: "C:\Documents and Settings\Oxhorn\Desktop\"


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\CC2 Demo\Bitmaps\Desktop_.ini
C:\CC2 Demo\Bitmaps\Tiles\Crayons\Desktop_.ini
C:\CC2 Demo\Bitmaps\Tiles\Desktop_.ini
C:\CC2 Demo\Desktop_.ini
C:\CC2 Demo\Examples\Characters\Desktop_.ini
C:\CC2 Demo\Examples\Cities\Desktop_.ini
C:\CC2 Demo\Examples\Desktop_.ini
C:\CC2 Demo\Examples\Dioramas\Desktop_.ini
C:\CC2 Demo\Examples\Dungeons\Desktop_.ini
C:\CC2 Demo\Examples\Maps\Desktop_.ini
C:\CC2 Demo\Guide\Desktop_.ini
C:\CC2 Demo\Symbols\Cities\Desktop_.ini
C:\CC2 Demo\Symbols\Cities\House Styles\Desktop_.ini
C:\CC2 Demo\Symbols\Desktop_.ini
C:\CC2 Demo\Symbols\Dungeons\Desktop_.ini
C:\CC2 Demo\Symbols\Maps\Desktop_.ini
C:\CC2 Demo\Symbols\Maps\Filled\Desktop_.ini
C:\CC2 Demo\System\Desktop_.ini
C:\CC2 Demo\Templates\Battletech\Desktop_.ini
C:\CC2 Demo\Templates\Cities\Desktop_.ini
C:\CC2 Demo\Templates\Desktop_.ini
C:\CC2 Demo\Templates\Dungeons\Desktop_.ini
C:\CC2 Demo\Templates\Maps\Desktop_.ini
C:\CC2 Demo\Templates\Other\Desktop_.ini
C:\DELL\CONTACT\Desktop_.ini
C:\DELL\Contracts\Consumer\Desktop_.ini
C:\DELL\Contracts\Desktop_.ini
C:\DELL\Contracts\Systems\Desktop_.ini
C:\DELL\Desktop_.ini
C:\DELL\DOCS\Desktop_.ini
C:\DELL\DOCS\MANUAL\Desktop_.ini
C:\DELL\drivers\Desktop_.ini
C:\DELL\drivers\R90275\Desktop_.ini
C:\DELL\MEDIAEXE\Desktop_.ini
C:\DELL\MEDIAEXE\MEDIA\Desktop_.ini
C:\DELL\Utilities\Desktop_.ini
C:\DELL\Utilities\Driver Reset Tool\Desktop_.ini
C:\DELL\Utilities\DSR\Desktop_.ini
C:\Documents and Settings\All Users\Documents\Adobe PDF\Desktop_.ini
C:\Documents and Settings\All Users\Documents\Adobe PDF\Extras\Desktop_.ini
C:\Documents and Settings\All Users\Documents\Adobe PDF\Settings\Desktop_.ini
C:\Documents and Settings\All Users\Documents\Config\Desktop_.ini
C:\Documents and Settings\All Users\Documents\Fonts\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Music\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Music\My Playlists\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Music\Sample Music\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\07872F\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\04ADD0\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Pictures\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\2006-11-07\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\2006-11-10\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\2006-11-29\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\2006-11-30\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\2006-12-05\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\2006-12-22\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Videos\Desktop_.ini
C:\Documents and Settings\All Users\Documents\Softwrap\Desktop_.ini
C:\Documents and Settings\All Users\Documents\Softwrap\ULEADGA520040406003\Desktop_.ini
C:\DRIVERS\AUDIO\Desktop_.ini
C:\DRIVERS\AUDIO\ONBOARD\Desktop_.ini
C:\DRIVERS\Desktop_.ini
C:\DRIVERS\MODEM\Desktop_.ini
C:\DRIVERS\MOUSE\Desktop_.ini
C:\DRIVERS\MOUSE\ONBOARD\Desktop_.ini
C:\DRIVERS\NETWORK\Desktop_.ini
C:\DRIVERS\NETWORK\ONBOARD\Desktop_.ini
C:\DRIVERS\New Folder\Desktop_.ini
C:\DRIVERS\VIDEO\Desktop_.ini
C:\DRIVERS\VIDEO\ONBOARD\B_17996\Desktop_.ini
C:\DRIVERS\VIDEO\ONBOARD\Desktop_.ini
C:\Fraps\Desktop_.ini
C:\Fraps\HELP\Desktop_.ini
C:\Fraps\Vids\Desktop_.ini
C:\hosts\Desktop_.ini
C:\I386\$OEM$\$1\Desktop_.ini
C:\I386\$OEM$\$1\DRIVERS\Desktop_.ini
C:\I386\$OEM$\Desktop_.ini
C:\I386\ASMS\1\DEFAULT\Desktop_.ini
C:\I386\ASMS\1\Desktop_.ini
C:\I386\ASMS\10\Desktop_.ini
C:\I386\ASMS\10\MSFT\Desktop_.ini
C:\I386\ASMS\10\POLICY\Desktop_.ini
C:\I386\ASMS\10\POLICY\MSFT\Desktop_.ini
C:\I386\ASMS\1000\Desktop_.ini
C:\I386\ASMS\1000\MSFT\Desktop_.ini
C:\I386\ASMS\2\DEFAULT\Desktop_.ini
C:\I386\ASMS\2\Desktop_.ini
C:\I386\ASMS\5100\Desktop_.ini
C:\I386\ASMS\5100\MSFT\Desktop_.ini
C:\I386\ASMS\52\Desktop_.ini
C:\I386\ASMS\52\MSFT\Desktop_.ini
C:\I386\ASMS\52\POLICY\Desktop_.ini
C:\I386\ASMS\52\POLICY\MSFT\Desktop_.ini
C:\I386\ASMS\60\Desktop_.ini
C:\I386\ASMS\60\MSFT\Desktop_.ini
C:\I386\ASMS\60\POLICY\60\COMCTL\Desktop_.ini
C:\I386\ASMS\60\POLICY\60\Desktop_.ini
C:\I386\ASMS\60\POLICY\Desktop_.ini
C:\I386\ASMS\6000\Desktop_.ini
C:\I386\ASMS\6000\MSFT\Desktop_.ini
C:\I386\ASMS\6000\MSFT\VCRTL\Desktop_.ini
C:\I386\ASMS\70\Desktop_.ini
C:\I386\ASMS\70\MSFT\Desktop_.ini
C:\I386\ASMS\70\POLICY\Desktop_.ini
C:\I386\ASMS\70\POLICY\MSFT\Desktop_.ini
C:\I386\ASMS\70\POLICY\MSFT\MSWINCRT\Desktop_.ini
C:\I386\ASMS\7000\Desktop_.ini
C:\I386\ASMS\7000\MSFT\Desktop_.ini
C:\I386\ASMS\Desktop_.ini
C:\I386\COMPDATA\Desktop_.ini
C:\I386\Desktop_.ini
C:\I386\DRW\1033\Desktop_.ini
C:\I386\DRW\Desktop_.ini
C:\I386\LANG\Desktop_.ini
C:\I386\WINNTUPG\Desktop_.ini
C:\I386\WINNTUPG\ENTINF\Desktop_.ini
C:\I386\WINNTUPG\MS\Desktop_.ini
C:\I386\WINNTUPG\MS\MODEMSHR\Desktop_.ini
C:\I386\WINNTUPG\MS\SNA\Desktop_.ini
C:\I386\WINNTUPG\OEM\Desktop_.ini
C:\I386\WINNTUPG\OEM\DIGI\ASYNC\Desktop_.ini
C:\I386\WINNTUPG\OEM\DIGI\Desktop_.ini
C:\I386\WINNTUPG\OEM\DIGI\ISDN\BRI\Desktop_.ini
C:\I386\WINNTUPG\OEM\DIGI\ISDN\Desktop_.ini
C:\I386\WINNTUPG\OEM\DIGI\ISDN\PRI\Desktop_.ini
C:\I386\WINNTUPG\OEM\DIGI\REALPORT\Desktop_.ini
C:\I386\WINNTUPG\OEM\EICON\Desktop_.ini
C:\I386\WINNTUPG\OEM\EQN\Desktop_.ini
C:\I386\WINNTUPG\OEM\SPX\Desktop_.ini
C:\I386\WINNTUPG\OEM\SPX\MPS\Desktop_.ini
C:\I386\WINNTUPG\OEM\TIGERJET\Desktop_.ini
C:\I386\WINNTUPG\PERINF\Desktop_.ini
C:\I386\WINNTUPG\SRVINF\Desktop_.ini
C:\ie-spyad\adult\Desktop_.ini
C:\ie-spyad\choice\Desktop_.ini
C:\ie-spyad\Desktop_.ini
C:\ie-spyad\old\Desktop_.ini
C:\KPCMS\CMSCP\Desktop_.ini
C:\KPCMS\Desktop_.ini
C:\My Documents\Desktop_.ini
C:\My Downloads\Desktop_.ini
C:\Mythic\Atlantis\anims\Desktop_.ini
C:\Mythic\Atlantis\charman\Desktop_.ini
C:\Mythic\Atlantis\data\albion\Desktop_.ini
C:\Mythic\Atlantis\data\atlantis\Desktop_.ini
C:\Mythic\Atlantis\data\Desktop_.ini
C:\Mythic\Atlantis\data\hibernia\Desktop_.ini
C:\Mythic\Atlantis\data\loading\Desktop_.ini
C:\Mythic\Atlantis\data\midgard\Desktop_.ini
C:\Mythic\Atlantis\data\skin1\Desktop_.ini
C:\Mythic\Atlantis\data\skin2\Desktop_.ini
C:\Mythic\Atlantis\Desktop_.ini
C:\Mythic\Atlantis\effects\caustic\Desktop_.ini
C:\Mythic\Atlantis\effects\Desktop_.ini
C:\Mythic\Atlantis\figures\Desktop_.ini
C:\Mythic\Atlantis\figures\fig3\Desktop_.ini
C:\Mythic\Atlantis\figures\mskins\Desktop_.ini
C:\Mythic\Atlantis\figures\skins\Desktop_.ini
C:\Mythic\Atlantis\fonts\Desktop_.ini
C:\Mythic\Atlantis\frontiers\Desktop_.ini
C:\Mythic\Atlantis\frontiers\items\Desktop_.ini
C:\Mythic\Atlantis\frontiers\nifs\Desktop_.ini
C:\Mythic\Atlantis\frontiers\sounds\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\terraintex\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\textures\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone163\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone164\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone167\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone168\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone169\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone170\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone171\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone172\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone173\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone174\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone175\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone176\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone177\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone178\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone233\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone234\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone235\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone236\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone237\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone238\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone239\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone240\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone241\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone242\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone244\Desktop_.ini
C:\Mythic\Atlantis\frontiers\zones\zone254\Desktop_.ini
C:\Mythic\Atlantis\icons\Desktop_.ini
C:\Mythic\Atlantis\insignia\Desktop_.ini
C:\Mythic\Atlantis\items\Desktop_.ini
C:\Mythic\Atlantis\items\pskins\Desktop_.ini
C:\Mythic\Atlantis\light\Desktop_.ini
C:\Mythic\Atlantis\miles\6.5\Desktop_.ini
C:\Mythic\Atlantis\miles\Desktop_.ini
C:\Mythic\Atlantis\newtowns\Desktop_.ini
C:\Mythic\Atlantis\newtowns\zones\Desktop_.ini
C:\Mythic\Atlantis\newtowns\zones\nifs\Desktop_.ini
C:\Mythic\Atlantis\nifs\Desktop_.ini
C:\Mythic\Atlantis\phousing\data\albion\Desktop_.ini
C:\Mythic\Atlantis\phousing\data\atlantis\Desktop_.ini
C:\Mythic\Atlantis\phousing\data\Desktop_.ini
C:\Mythic\Atlantis\phousing\data\hibernia\Desktop_.ini
C:\Mythic\Atlantis\phousing\data\loading\Desktop_.ini
C:\Mythic\Atlantis\phousing\data\midgard\Desktop_.ini
C:\Mythic\Atlantis\phousing\data\skin1\Desktop_.ini
C:\Mythic\Atlantis\phousing\data\skin2\Desktop_.ini
C:\Mythic\Atlantis\phousing\Desktop_.ini
C:\Mythic\Atlantis\phousing\effects\Desktop_.ini
C:\Mythic\Atlantis\phousing\nifs\Desktop_.ini
C:\Mythic\Atlantis\phousing\textures\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone013\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone016\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone017\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone018\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone020\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone064\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone114\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone117\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone118\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone119\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone121\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone122\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone213\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone215\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone217\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone218\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone219\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone225\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone260\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone261\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone262\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone266\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone267\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone268\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone272\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone273\Desktop_.ini
C:\Mythic\Atlantis\phousing\zones\zone274\Desktop_.ini
C:\Mythic\Atlantis\pregame\Desktop_.ini
C:\Mythic\Atlantis\sounds\Desktop_.ini
C:\Mythic\Atlantis\stylemap\Desktop_.ini
C:\Mythic\Atlantis\tutorial\Desktop_.ini
C:\Mythic\Atlantis\tutorial\sounds\Desktop_.ini
C:\Mythic\Atlantis\tutorial\zones\Desktop_.ini
C:\Mythic\Atlantis\tutorial\zones\nifs\Desktop_.ini
C:\Mythic\Atlantis\tutorial\zones\terraintex\Desktop_.ini
C:\Mythic\Atlantis\tutorial\zones\zone027\Desktop_.ini
C:\Mythic\Atlantis\tutorial\zones\zone028\Desktop_.ini
C:\Mythic\Atlantis\tutorial\zones\zone029\Desktop_.ini
C:\Mythic\Atlantis\ui\albion\Desktop_.ini
C:\Mythic\Atlantis\ui\atlantis\Desktop_.ini
C:\Mythic\Atlantis\ui\classic\Desktop_.ini
C:\Mythic\Atlantis\ui\Desktop_.ini
C:\Mythic\Atlantis\ui\fonts\Desktop_.ini
C:\Mythic\Atlantis\ui\hibernia\Desktop_.ini
C:\Mythic\Atlantis\ui\isles\Desktop_.ini
C:\Mythic\Atlantis\ui\maps\Desktop_.ini
C:\Mythic\Atlantis\ui\midgard\Desktop_.ini
C:\Mythic\Atlantis\ui\minimal\Desktop_.ini
C:\Mythic\Atlantis\water\Desktop_.ini
C:\Mythic\Atlantis\zones\Desktop_.ini
C:\Mythic\Atlantis\zones\Dnifs\Desktop_.ini
C:\Mythic\Atlantis\zones\Nifs\Desktop_.ini
C:\Mythic\Desktop_.ini
C:\WINDOWS\system32\drivers\fad.sys


((((((((((((((((((((((((( Files Created from 2007-05-09 to 2007-06-09 )))))))))))))))))))))))))))))))


2007-06-05 17:39 d——– C:\DOCUME~1\Oxhorn\DoctorWeb
2007-06-05 15:56 73,728 –a—— C:\WINDOWS\SYSTEM32\dlbcpwr.dll
2007-06-05 15:56 57,344 –a—— C:\WINDOWS\SYSTEM32\dlbccinf.dll
2007-06-05 15:56 49,152 –a—— C:\WINDOWS\SYSTEM32\dlbccoin.dll
2007-06-05 15:56 40,960 –a—— C:\WINDOWS\SYSTEM32\dlbcvs.dll
2007-06-05 15:56 311,296 –a—— C:\WINDOWS\SYSTEM32\LEXBCES.EXE
2007-06-05 15:56 201,216 –a—— C:\WINDOWS\SYSTEM32\LEXP2P32.DLL
2007-06-05 15:56 197,120 –a—— C:\WINDOWS\SYSTEM32\LEX2KUSB.DLL
2007-06-05 15:56 192,512 –a—— C:\WINDOWS\SYSTEM32\lexlmpm.dll
2007-06-05 15:56 174,592 –a—— C:\WINDOWS\SYSTEM32\LEXPPS.EXE
2007-06-05 15:56 147,456 –a—— C:\WINDOWS\SYSTEM32\LEXBCE.DLL
2007-06-05 15:56 d——– C:\Program Files\Dell 720
2007-06-05 15:54 d——– C:\Dell720
2007-06-04 19:22 d——– C:\Program Files\CONEXANT
2007-06-04 16:22 d——– C:\Deckard
2007-06-04 08:31 d–hs—- C:\WINDOWS\CSC
2007-06-04 06:34 10,872 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-06-04 06:18 d——– C:\DOCUME~1\Oxhorn\APPLIC~1\Comodo
2007-06-04 06:18 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Comodo
2007-06-04 06:11 d——– C:\Program Files\Comodo
2007-06-03 22:14 d——– C:\WINDOWS\SYSTEM32\ActiveScan
2007-06-02 19:21 d——– C:\Program Files\Common Files\Blizzard Entertainment
2007-05-12 22:23 561,152 –a—— C:\WINDOWS\SYSTEM32\AltST.dll
2007-05-12 22:23 491,520 –a—— C:\WINDOWS\SYSTEM32\imagx4.dll
2007-05-12 22:23 421,888 –a—— C:\WINDOWS\SYSTEM32\imagr4.dll
2007-05-12 22:23 38,912 –a—— C:\WINDOWS\SYSTEM32\picn20.dll
2007-05-12 22:23 372,736 –a—— C:\WINDOWS\SYSTEM32\ShellExtension.dll
2007-05-12 22:23 250,736 –a—— C:\WINDOWS\SYSTEM32\ImagXpr4.dll
2007-05-12 22:17 1,040,384 –a—— C:\WINDOWS\SYSTEM32\libgfl190.dll
2007-05-12 16:03 339,968 –a—— C:\WINDOWS\SYSTEM32\WDBtnMgr.exe


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-07 18:38:41 ——– d—–w C:\DOCUME~1\Oxhorn\APPLIC~1\Skype
2007-06-05 02:44:15 ——– d—–w C:\Program Files\SpywareGuard
2007-06-04 23:46:55 ——– d—–w C:\DOCUME~1\Oxhorn\APPLIC~1\Jasc Software Inc
2007-06-04 23:40:42 ——– d—–w C:\Program Files\ConTEXT
2007-06-04 23:34:00 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-06-04 23:32:23 ——– d—–w C:\Program Files\Game Extractor
2007-06-04 23:31:59 ——– d—–w C:\Program Files\LimeWire
2007-06-04 23:31:23 ——– d—–w C:\Program Files\GlobalSCAPE
2007-06-04 23:24:41 ——– d—–w C:\Program Files\NCH Swift Sound
2007-06-04 23:24:15 ——– d—–w C:\Program Files\JPEG Imager
2007-06-04 23:23:57 ——– d—–w C:\Program Files\Abacast
2007-06-04 23:22:47 ——– d—–w C:\Program Files\Game Cam
2007-06-04 23:06:11 ——– d–h–w C:\DOCUME~1\Oxhorn\APPLIC~1\Gtek
2007-06-04 07:15:02 ——– d—–w C:\Program Files\M-Audio MobilePre
2007-05-15 22:18:29 ——– d—–w C:\DOCUME~1\Oxhorn\APPLIC~1\AdobeUM
2007-05-08 23:59:28 96,256 —-a-w C:\WINDOWS\system32\drivers\sptd9469.sys
2007-05-05 15:58:18 ——– d—–w C:\DOCUME~1\Oxhorn\APPLIC~1\Greyfirst
2007-05-05 15:58:12 ——– d—–w C:\Program Files\Celtx
2007-05-01 20:44:34 ——– d—–w C:\Program Files\DivX
2007-05-01 10:45:18 ——– d—–w C:\DOCUME~1\Oxhorn\APPLIC~1\Dr. DivX 2.0 OSS
2007-04-19 19:22:30 ——– d—–w C:\Program Files\MediaJoin
2007-04-19 19:22:00 ——– d—–w C:\DOCUME~1\Oxhorn\APPLIC~1\Seven Zip
2007-04-18 16:12:23 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-17 03:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-17 03:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 03:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 03:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 03:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 03:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 03:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 03:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-04-17 03:44:20 271,224 —-a-w C:\WINDOWS\system32\mucltui.dll
2007-04-17 03:44:18 208,248 —-a-w C:\WINDOWS\system32\muweb.dll
2007-04-16 13:25:56 ——– d—–w C:\DOCUME~1\Oxhorn\APPLIC~1\Syntrillium
2007-03-27 07:55:57 524,288 —-a-w C:\WINDOWS\system32\DivXsm.exe
2007-03-27 07:55:48 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2007-03-27 07:55:31 129,784 ——w C:\WINDOWS\system32\pxafs.dll
2007-03-27 07:55:31 118,520 ——w C:\WINDOWS\system32\pxinsi64.exe
2007-03-27 07:55:31 116,472 ——w C:\WINDOWS\system32\pxcpyi64.exe
2007-03-27 07:55:23 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
2007-03-27 07:55:23 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
2007-03-27 07:49:07 73,728 —-a-w C:\WINDOWS\system32\dpl100.dll
2007-03-27 07:49:07 196,608 —-a-w C:\WINDOWS\system32\dtu100.dll
2007-03-27 07:49:05 53,248 —-a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-03-27 07:49:03 593,920 —-a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-03-27 07:49:02 57,344 —-a-w C:\WINDOWS\system32\dpv11.dll
2007-03-27 07:49:02 344,064 —-a-w C:\WINDOWS\system32\dpus11.dll
2007-03-27 07:49:02 294,912 —-a-w C:\WINDOWS\system32\dpu11.dll
2007-03-27 07:49:02 294,912 —-a-w C:\WINDOWS\system32\dpu10.dll
2007-03-27 07:48:59 823,296 —-a-w C:\WINDOWS\system32\divx_xx07.dll
2007-03-27 07:48:58 823,296 —-a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-03-27 07:48:58 802,816 —-a-w C:\WINDOWS\system32\divx_xx11.dll
2007-03-27 07:48:58 639,066 —-a-w C:\WINDOWS\system32\DivX.dll
2007-03-19 15:27:56 552 —-a-w C:\WINDOWS\system32\d3d8caps.dat
2007-03-18 06:13:19 107,136 —-a-w C:\DOCUME~1\Oxhorn\APPLIC~1\GDIPFONTCACHEV1.DAT
2007-03-17 13:43:01 292,864 —-a-w C:\WINDOWS\system32\winsrv.dll
2005-06-14 15:31:30 10,856 –sha-w C:\WINDOWS\SYSTEM32\KGyGaAvL.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{22BF413B-C6D2-4d91-82A9-A0F997BA588C}=C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL [2007-02-09 16:58]
{4A368E80-174F-4872-96B5-0B27DDD11DB2}=C:\Program Files\SpywareGuard\dlprotect.dll [2003-08-02 23:24]
{53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 02:04]
{5CA3D70E-1895-11CF-8E15-001234567890}=C:\WINDOWS\system32\dla\tfswshx.dll [2004-11-16 02:05]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2007-06-04 06:11]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-05-30 07:30]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"=0 (0x0)
"NoColorChoice"=0 (0x0)
"NoSizeChoice"=0 (0x0)
"NoDispScrSavPage"=0 (0x0)
"NoDispCPL"=0 (0x0)
"NoVisualStyleChoice"=0 (0x0)
"NoDispSettingsPage"=0 (0x0)
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktopChanges"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSaveSettings"=0 (0x0)
"NoThemesTab"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 07:29]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^D-Link AirPlus G Wireless Utility.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\D-Link AirPlus G Wireless Utility.lnk
backup=C:\WINDOWS\pss\D-Link AirPlus G Wireless Utility.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^D-Link REG Utility.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\D-Link REG Utility.lnk
backup=C:\WINDOWS\pss\D-Link REG Utility.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^M-Audio MobilePre Control Panel Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\M-Audio MobilePre Control Panel Launcher.lnk
backup=C:\WINDOWS\pss\M-Audio MobilePre Control Panel Launcher.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Oxhorn^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Oxhorn\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
"C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
C:\Program Files\Apoint\Apoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
"C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDET]
C:\Program Files\Creative\USB SBAudigy2 NX\DVDAudio\CTDVDDet.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
C:\Program Files\Creative\USB SBAudigy2 NX\Surround Mixer\CTSysVol.exe /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
"C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
"C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1147441616\ee\AOLSoftware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SbUsb AudCtrl]
RunDll32 sbusbdll.dll,RCMonitor

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
C:\WINDOWS\UpdReg.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WD Button Manager]
WDBtnMgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*


**************************************************************************

catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-09 07:52:30
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-06-09 7:55:02 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-06-09 07:55

— E O F —

Here is the Uninstall Manager list from HijackThis!:

Ad-Aware SE Personal
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Download Manager 2.2 (Remove Only)
Adobe Flash Player 9 ActiveX
Adobe Help Center 2.0
Adobe Premiere Pro
Adobe Premiere Pro 2.0
Adobe Reader 7.0.9
Adobe Stock Photos 1.0
AIM 6.0
ALPS Touch Pad Driver
ATI Display Driver
AVG Anti-Spyware 7.5
BitTorrent 5.0.0
Broadcom Advanced Control Suite
Camera Driver
CardRd81
CCScore
Celtx (0.9.9.1)
Combined Community Codec Pack 2006-07-28 (Remove Only)
COMODO Firewall Pro
Conexant D480 MDC V.9x Modem
Consumer Complete Care Services Agreement
CR2
CuteFTP 8 Home
Dark Age of Camelot - Shrouded Isles
Dark Age of Camelot - Trials of Atlantis
Dell Driver Reset Tool
Dell Home Systems Services Agreement
Dell Photo Printer 720
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
D-Link AirPlus G Wireless Adapter
ESSBrwr
ESSCDBK
ESScore
ESSgui
ESShelp
ESSini
ESSPCD
ESSPDock
ESSSONIC
ESSTOOLS
essvatgt
essvcpt
ExtractNow
File Renamer - Basic
Fraps (remove only)
Free iPod Video Converter 1.26
GD Winamp Control
Google Desktop
Google Desktop Plugin - eBay Watcher
Google Desktop Plugin - IPS Website Counter
Google Desktop Plugin - JobSearch
Google Earth
Google Video Player
Google Video Uploader
GTK+ 2.6.8-1 runtime environment
HaxFix 4.10
Helix Xiph Plugins 0.5
HijackThis / CWShredder Installer 1.0
HijackThis 1.99.1
HLPPDOCK
Homestead SiteBuilder LPX
Hotfix for Microsoft .NET Framework 2.0 (KB922981)
Hotfix for Microsoft .NET Framework 2.0 (KB923319)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 4
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 9
Java 2 Runtime Environment, SE v1.4.2_03
Java™ SE Runtime Environment 6 Update 1
kgcbase
K-Lite Codec Pack 2.70 Full
Kodak EasyShare software
KSU
Macromedia Extension Manager
Macromedia Flash 8
Macromedia Flash 8 Video Encoder
Macromedia Flash Player 8
Macromedia Flash Player 8 Plugin
Macromedia Shockwave Player
MediaJoin
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2003 Web Components
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional 2007
Microsoft Office Professional 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Small Business Connectivity Components
Microsoft Office Word MUI (English) 2007
Microsoft SQL Server Native Client
Microsoft SQL Server Setup Support Files (English)
Microsoft SQL Server VSS Writer
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Word 2002
MobilePre 1.0.0.12
Mozilla Firefox (2.0.0.4)
MPTagger v1.60
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 6.0 Parser (KB927977)
MyEdit™ 1.0
Notifier
OfotoXMI
OTtBP
OTtBPSDK
Panda ActiveScan
Pdf995
PowerDVD 5.3
QuickSet
QuickTime
RealPlayer
Revver Upload Tool (remove only)
Security Update for Excel 2007 (KB934670)
Security Update for Microsoft .NET Framework 2.0 (KB917283)
Security Update for Microsoft .NET Framework 2.0 (KB922770)
Security Update for Office 2007 (KB934062)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926247)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
SFR
SHASTA
SKIN0001
SKINXSDK
Skype 3.0
Skype add-on for IE
Skype Plugin Manager
Sonic DLA
Sonic RecordNow!
Sonic Update Manager
Spybot - Search & Destroy 1.4
SpywareGuard v2.2
staticcr
The GIMP 2.2.8
Total Commander (Remove or Repair)
Update for Office 2007 (KB932080)
Update for Office 2007 (KB933688)
Update for Office 2007 (KB934393)
Update for Outlook 2007 Junk Email Filter (KB934655)
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Word 2007 (KB934173)
USB Sound Blaster Audigy 2 NX
VPRINTOL
WavePad Uninstall
WD Diagnostics
WD Firewire HID Driver
Winamp (remove only)
Windows Defender Signatures
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 11
Windows Media Player 11
Windows XP Creativity Fun Packs - Windows Movie Maker 2
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB886716
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
WinRAR archiver
WIRELESS
Xfire (remove only)
XnView 1.74

Here is the MWAV report:

Object "grokster Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "gain.gator Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "gain.gator Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "gain.gator Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "wareout Adware" found in File System! Action Taken: No Action Taken.
Object "trojan-downloader.bat.ftp.ab Trojan-Downloader" found in File System! Action Taken: No Action Taken.
Object "trojan-downloader.bat.ftp.ab Trojan-Downloader" found in File System! Action Taken: No Action Taken.
Object "trojan-downloader.bat.ftp.ab Trojan-Downloader" found in File System! Action Taken: No Action Taken.
Object "trojan-downloader.bat.ftp.ab Trojan-Downloader" found in File System! Action Taken: No Action Taken.
Object "smitfraud Browser Hijacker" found in File System! Action Taken: No Action Taken.
Object "elite toolbar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "elite toolbar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "elite toolbar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "elite toolbar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "elite toolbar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "elite toolbar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "savenow Adware" found in File System! Action Taken: No Action Taken.
Object "savenow Adware" found in File System! Action Taken: No Action Taken.
Entry "HKCR\ComPlusMetaData.MsCorHost" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken.
Entry "HKCR\ComPlusMetaData.MsCorHost.2" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken.
Entry "HKCR\COMSNAP.COMAdminCatalog.2" refers to invalid object "{DFC1A733-0B12-34C4-37CA-6CF9039F9FD9}". Action Taken: No Action Taken.
Entry "HKCR\DirectAnimation.PathControl" refers to invalid object "{D7A7D7C3-D47F-11D0-89D3-00A0C90833E6}". Action Taken: No Action Taken.
Entry "HKCR\DirectAnimation.Sequence" refers to invalid object "{4F241DB1-EE9F-11D0-9824-006097C99E51}". Action Taken: No Action Taken.
Entry "HKCR\DirectAnimation.SequencerControl" refers to invalid object "{B0A6BAE2-AAF0-11D0-A152-00A0C908DB96}". Action Taken: No Action Taken.
Entry "HKCR\DirectAnimation.SpriteControl" refers to invalid object "{FD179533-D86E-11D0-89D6-00A0C90833E6}". Action Taken: No Action Taken.
Entry "HKCR\DirectAnimation.StructuredGraphicsControl" refers to invalid object "{369303C2-D7AC-11D0-89D5-00A0C90833E6}". Action Taken: No Action Taken.
Entry "HKCR\GoogleDesktop.ContentItemHelper" refers to invalid object "{E622966D-28A0-43C2-A5B8-0CAF622A6711}". Action Taken: No Action Taken.
Entry "HKCR\GoogleDesktop.ContentItemHelper.1" refers to invalid object "{E622966D-28A0-43C2-A5B8-0CAF622A6711}". Action Taken: No Action Taken.
Entry "HKCR\GoogleDesktop.DetailsViewHelper" refers to invalid object "{FACE4234-6A8F-48AB-898A-237F6529C70E}". Action Taken: No Action Taken.
Entry "HKCR\GoogleDesktop.DetailsViewHelper.1" refers to invalid object "{FACE4234-6A8F-48AB-898A-237F6529C70E}". Action Taken: No Action Taken.
Entry "HKCR\GoogleTalk.TalkFriend" refers to invalid object "{A8F086C3-2497-4229-82FE-586F2D326F95}". Action Taken: No Action Taken.
Entry "HKCR\GoogleTalk.TalkFriend.1" refers to invalid object "{A8F086C3-2497-4229-82FE-586F2D326F95}". Action Taken: No Action Taken.
Entry "HKCR\SPhoneParser.FoundSkypeNumber" refers to invalid object "{E40A96CC-4A5B-47F4-9957-87CDED1DFF45}". Action Taken: No Action Taken.
Entry "HKCR\SPhoneParser.FoundSkypeNumber.1" refers to invalid object "{E40A96CC-4A5B-47F4-9957-87CDED1DFF45}". Action Taken: No Action Taken.
Entry "HKCR\SymWriter.pdb" refers to invalid object "{520DC67A-752E-11D3-8D56-00C04F680B2B}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\asinst.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\FacebookPhotoUploader.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\FilePlanetDownloadCtrl.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\mnviewer.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\NPSibelius.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\WebCleaner.dll". Action Taken: No Action Taken.
Entry "HKCU\Software\Netscape\Netscape Navigator\User Trusted External Applications" refers to invalid object "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmjblaunch.exe". Action Taken: No Action Taken.
Entry "HKCU\Software\Netscape\Netscape Navigator\User Trusted External Applications" refers to invalid object "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmfwlaunch.exe". Action Taken: No Action Taken.
Entry "HKCU\Software\Netscape\Netscape Navigator\User Trusted External Applications" refers to invalid object "C:\Program Files\Kodak\Kodak Software Updater\7288971\6.3.2.62-7288971L\Program\PrvCnt.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\system32\drivers\FAD.sys". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\DellSupport.EXE". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\stlport_vc746.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Real\GToolbar\BarControl.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\FilePlanetDownloadCtrl.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\FacebookPhotoUploader.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Documents and Settings\Oxhorn\My Documents\Creativity_Pack_ReadMe.htm". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\mnviewer.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\NPSibelius.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\WebCleaner.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.Windows.Forms.tlb". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.EnterpriseServices.tlb". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Microsoft.JScript.tlb". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Microsoft.Vsa.tlb". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.Drawing.tlb". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscoree.tlb". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\mscorlib.tlb". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\System.tlb". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\Microsoft.Vsa.Vb.CodeDOMProcessor.tlb". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "c:\Program Files\Common Files\System\Ole Db\Resources\1028\MSOLAP80.RLL". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "c:\Program Files\Common Files\System\Ole Db\Resources\1031\MSOLAP80.RLL". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "c:\Program Files\Common Files\System\Ole Db\Resources\1034\MSOLAP80.RLL". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "c:\Program Files\Common Files\System\Ole Db\Resources\1036\MSOLAP80.RLL". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "c:\Program Files\Common Files\System\Ole Db\Resources\1040\MSOLAP80.RLL". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "c:\Program Files\Common Files\System\Ole Db\Resources\1041\MSOLAP80.RLL". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "c:\Program Files\Common Files\System\Ole Db\Resources\1042\MSOLAP80.RLL". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "c:\Program Files\Common Files\System\Ole Db\Resources\1043\MSOLAP80.RLL". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "c:\Program Files\Common Files\System\Ole Db\Resources\1046\MSOLAP80.RLL". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "c:\Program Files\Common Files\System\Ole Db\Resources\1053\MSOLAP80.RLL". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "c:\Program Files\Common Files\System\Ole Db\Resources\2052\MSOLAP80.RLL". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\asinst.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\iPod\bin\iPodService.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\iPod\bin\iPodService.Resources\iPodService.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\iPod\bin\iPodService.Resources\da.lproj\iPodServiceLocalized.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\iPod\bin\iPodService.Resources\de.lproj\iPodServiceLocalized.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\iPod\bin\iPodService.Resources\en.lproj\iPodServiceLocalized.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\iPod\bin\iPodService.Resources\es.lproj\iPodServiceLocalized.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\iPod\bin\iPodService.Resources\fi.lproj\iPodServiceLocalized.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\iPod\bin\iPodService.Resources\fr.lproj\iPodServiceLocalized.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\iPod\bin\iPodService.Resources\it.lproj\iPodServiceLocalized.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\iPod\bin\iPodService.Resources\ja.lproj\iPodServiceLocalized.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\iPod\bin\iPodService.Resources\ko.lproj\iPodServiceLocalized.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\iPod\bin\iPodService.Resources\nb.lproj\iPodServiceLocalized.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\iPod\bin\iPodService.Resources\nl.lproj\iPodServiceLocalized.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\iPod\bin\iPodService.Resources\ru.lproj\iPodServiceLocalized.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\iPod\bin\iPodService.Resources\sv.lproj\iPodServiceLocalized.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\iPod\bin\iPodService.Resources\zh_CN.lproj\iPodServiceLocalized.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\iPod\bin\iPodService.Resources\zh_TW.lproj\iPodServiceLocalized.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Oxhorn\My Documents\My PSP8 Files\Scripts-Restricted\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Oxhorn\My Documents\My Videos\Creativity Fun Packs\Sound Effects\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Oxhorn\My Documents\My Videos\Creativity Fun Packs\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Oxhorn\My Documents\My Videos\Creativity Fun Packs\Sound Effects\sports\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Oxhorn\My Documents\My Videos\Creativity Fun Packs\Sound Effects\party_sound_effects\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Oxhorn\My Documents\My Videos\Creativity Fun Packs\Sound Effects\graduation_sound_effects\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Oxhorn\My Documents\My Videos\Creativity Fun Packs\Sound Effects\fun_random_sounds\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Oxhorn\My Documents\My Videos\Creativity Fun Packs\Sound Effects\animal_sound_effects\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Oxhorn\My Documents\My Videos\Creativity Fun Packs\Music Tracks and Music Transitions\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Oxhorn\My Documents\My Videos\Creativity Fun Packs\Video Titles and End Credits\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Oxhorn\My Documents\My Videos\Creativity Fun Packs\Static Titles\". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".1&th=10b45682f2ed2785". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".17_with_SMTP_id_17cs447139wxo". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".3ds". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".bak". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".celtx". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".chr". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".csv". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".dds". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".de/tex-archive/fonts/allrunes/type1/". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".DS_Store". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".eq". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".FSC". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".gcs". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".GME". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".lwo". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".m2". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".mdf". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".MDI". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".MPQ". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".ms3d". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".mtl". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".nif". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".nopatch". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".part". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".php". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".prepatch". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".reply&friendID=29246508&messageID=31910239&friendName=Joanna%21&Mytoken=6841EC63-1167-1098-0368986EBA647E0733544624". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".reply&friendId=94464472&type=inbox&messageID=190523830&fed=True&MyToken=c1085d5a-b684-4e3b-b326-aec2eda9cc6e". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".tmp". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".toc". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".wps". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".wtf". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "AOL Uninstaller". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "InstallShield_{3868A8EE-5051-4DB0-8DF6-4F4B8A98D083}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "InstallShield_{3CB41017-F5CA-4C56-934C-ED02156251E6}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "InstallShield_{501BADCD-F8F7-44CB-AC3F-6ED25C1A28B5}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "InstallShield_{929408E6-D265-4174-805F-81D1D914E2A4}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "InstallShield_{C21D5524-A970-42FA-AC8A-59B8C7CDCA31}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Internet Explorer Security Plugin 2006". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Internet Security Add-On". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Microsoft SQL Server 2005". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Mozilla Firefox (2.0.0.1)". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Mozilla Firefox (2.0.0.3)". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Public Messenger ver 2.03". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "QuickTime". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "StyleXP". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{032B93E8-D9A1-48D2-AA51-D057ABBA9E52}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{0456ebd7-5f67-4ab6-852e-63781e3f389c}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{04AD9B45-8D30-480A-B586-86AAF6675EE7}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{106E7A1C-22DA-42D7-8E74-37772A9C89FB}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{2959B9F6-2D49-4E0D-96F4-D684106FE48D}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{2B257128-0B59-4A88-AFDF-BE12E5F5B9A0}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{2B257128-0B59-4A88-AFDF-BE12E5F5B9A1}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{32971938-65B1-4B38-B483-9A32560B7CF2}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{345321B9-E6DC-4606-9C44-CEC373E64CCF}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{353D20CC-719B-4A60-AD33-D03F88C10330}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{438852BE-D270-4B2E-8E8C-DF813E3313EF}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{46614A49-222A-48EF-87A9-BFD603E608E1}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{5FA793A6-0071-42C1-9355-8F69A428C44F}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{66D08203-FB46-4D27-A609-FFE9A77FAA1F}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{6A6A5A40-FB6D-402C-8516-CC61E6DFE524}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{6EC77255-2E6B-49C0-B730-9C38410E0A85}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{7B802DE5-84E5-4503-965B-2ABFFC78506A}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{7C0A567A-8336-48D1-AD10-2CC56E4720B0}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{8110D4AF-439E-4F17-8C9C-E54B3F4006F7}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{8C711818-076E-475C-B95B-DF11CD9D8DBE}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{9C5A5A6D-4B86-4315-8ED0-BACB86686F0A}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{AA0370C1-BEB2-4C8E-ADFD-B7AFE85F0FBE}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{AC76BA86-0000-0000-0000-6028747ADE01}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{AC76BA86-7AD7-1033-7B44-A00000000001}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{AC76BA86-7AD7-1033-7B44-A70000000000}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{AEB9948B-4FF2-47C9-990E-47014492A0FE}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{B2D7CE29-614A-4ACC-8BFE-009EB3A244C9}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{B6F867E8-F092-4C5E-7D72-AC7057DBEF45}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{B945219C-C51C-4BD0-BAD5-A3FED95B555F}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{C4535494-0732-4123-BD27-8A000D3B36F2}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{DA256408-A2E7-41A5-8AD6-62ACB86A0FD7}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{E425ED22-87D8-48C0-9DEC-0519D49B78E1}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{EE9B31BB-1958-48CB-A298-57E3BE72FF2B}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{F891AAF3-DE9F-4445-85CF-6E41261A7F5A}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{FF0311AB-34A0-4B0B-A8D3-B51E72B34F2C}". Action Taken: No Action Taken.
File C:\Deckard\System Scanner\backup\DOCUME~1\Oxhorn\LOCALS~1\Temp\nsupdate.exe infected by "Exe.Corrupted" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\6.0\1\3af28841-6b2be326/BlackBox.class infected by "Trojan-Downloader.Java.OpenConnection.aa" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\6.0\15\a91cf4f-66680546/Installer.class infected by "Trojan-Downloader.Java.OpenStream.z" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\6.0\17\1e3a0ed1-491804d3/GetAccess.class infected by "Trojan-Downloader.Java.OpenConnection.v" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\6.0\2\7a3a8d42-78b9bbd3/a.class infected by "Trojan.Java.ClassLoader.u" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\6.0\34\3309722-2c048e4b infected by "Trojan-Downloader.Java.Agent.d" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\6.0\45\7bff92d-5247295e/BlackBox.class infected by "Trojan-Downloader.Java.OpenStream.d" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\6.0\46\1ddcc3ee-4bf3832d/BlackBox.class infected by "Trojan-Downloader.Java.OpenConnection.v" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\6.0\54\15af68b6-3d91b9b5/Counter.class infected by "Trojan.Java.ClassLoader.d" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\6.0\61\1d55cbd-2bd7d33a/Installer.class infected by "Trojan-Downloader.Java.OpenStream.z" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\java.class-5ca47f8f-1d7a6aff.class infected by "Trojan-Downloader.Java.Agent.d" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-228d5c98-3ea5bc04.zip/a.class infected by "Trojan.Java.ClassLoader.u" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-52be229c-3cb840ba.zip/BlackBox.class infected by "Trojan-Downloader.Java.OpenConnection.v" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-25c13e55-1e606a17.zip/GetAccess.class infected by "Trojan-Downloader.Java.OpenConnection.v" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-5cd730cf-31f1729b.zip/BlackBox.class infected by "Trojan-Downloader.Java.OpenConnection.aa" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0601a.jar-686cd5c0-752bff2c.zip/Installer.class infected by "Trojan-Downloader.Java.OpenStream.z" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0601a.jar-6e427444-2d095395.zip/Installer.class infected by "Trojan-Downloader.Java.OpenStream.z" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loader.jar-273595c6-46c0d3b4.zip/Counter.class infected by "Trojan.Java.ClassLoader.d" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\loaded.exe infected by "Exe.Corrupted" Virus! Action Taken: No Action Taken.
File C:\Program Files\World of Warcraft\WoW-1.8.3.4807-to-1.8.4.4878-enUS-patch.exe infected by "Exe.Corrupted" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\Resources\Themes\14410.exe//WISE0018.BIN tagged as "not-a-virus:AdWare.Win32.EZula.z". Action Taken: No Action Taken.
File C:\Deckard\System Scanner\backup\DOCUME~1\Oxhorn\LOCALS~1\Temp\nsupdate.exe infected by "Exe.Corrupted" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\6.0\1\3af28841-6b2be326/BlackBox.class infected by "Trojan-Downloader.Java.OpenConnection.aa" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\6.0\15\a91cf4f-66680546/Installer.class infected by "Trojan-Downloader.Java.OpenStream.z" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\6.0\17\1e3a0ed1-491804d3/GetAccess.class infected by "Trojan-Downloader.Java.OpenConnection.v" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\6.0\2\7a3a8d42-78b9bbd3/a.class infected by "Trojan.Java.ClassLoader.u" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\6.0\34\3309722-2c048e4b infected by "Trojan-Downloader.Java.Agent.d" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\6.0\45\7bff92d-5247295e/BlackBox.class infected by "Trojan-Downloader.Java.OpenStream.d" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\6.0\46\1ddcc3ee-4bf3832d/BlackBox.class infected by "Trojan-Downloader.Java.OpenConnection.v" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\6.0\54\15af68b6-3d91b9b5/Counter.class infected by "Trojan.Java.ClassLoader.d" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\6.0\61\1d55cbd-2bd7d33a/Installer.class infected by "Trojan-Downloader.Java.OpenStream.z" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\java.class-5ca47f8f-1d7a6aff.class infected by "Trojan-Downloader.Java.Agent.d" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-228d5c98-3ea5bc04.zip/a.class infected by "Trojan.Java.ClassLoader.u" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-52be229c-3cb840ba.zip/BlackBox.class infected by "Trojan-Downloader.Java.OpenConnection.v" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-25c13e55-1e606a17.zip/GetAccess.class infected by "Trojan-Downloader.Java.OpenConnection.v" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-5cd730cf-31f1729b.zip/BlackBox.class infected by "Trojan-Downloader.Java.OpenConnection.aa" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0601a.jar-686cd5c0-752bff2c.zip/Installer.class infected by "Trojan-Downloader.Java.OpenStream.z" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0601a.jar-6e427444-2d095395.zip/Installer.class infected by "Trojan-Downloader.Java.OpenStream.z" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loader.jar-273595c6-46c0d3b4.zip/Counter.class infected by "Trojan.Java.ClassLoader.d" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Oxhorn\loaded.exe infected by "Exe.Corrupted" Virus! Action Taken: No Action Taken.
File C:\Program Files\World of Warcraft\WoW-1.8.3.4807-to-1.8.4.4878-enUS-patch.exe infected by "Exe.Corrupted" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\Resources\Themes\14410.exe//WISE0018.BIN tagged as "not-a-virus:AdWare.Win32.EZula.z". Action Taken: No Action Taken.

And lastly, the new HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 9:56:15 PM, on 6/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.brandonmdennis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01CA75F1-054B-4A63-9221-C6926369EC52} (HS_live Control) - http://install.homestead.com/~site/Install…ive/HS_live.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {5AA5A569-F96F-4628-A528-8B3698F558BB} (HS_live Control) - http://install.homestead.com/~site/Install…ive/HS_live.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1128709406296
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup161.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MobilePre Installer (MobilePreInstallerService) - M-Audio - C:\Program Files\M-Audio MobilePre\Install\MPInst.exe

Thank you so much for taking the time to help me out! I really appreciate it!
Hi oxhorn,

Let's clear that Java cache folder which has infected files.

http://support.f-secure.com/enu/home/virus…javacache.shtml
How to Clean a Java Cache Folder
You have infected files in your Java cache. So you need to delete all the files within cache folder (do not delete the
Cache folder!)

C:\Documents and Settings\Oxhorn\Application Data\Sun\Java\Deployment\cache<=all files within the cache folder.

=========================
Please set your system to show all files; please see here if you're unsure how to do this.

Reboot into Safe Mode: please see here if you are not sure how to do this.

Using Windows Explorer, locate the following files/folders, and delete them:
C:\Deckard\System Scanner\backup\<=file
C:\Documents and Settings\Oxhorn\loaded.exe<=file
C:\Program Files\World of Warcraft\WoW-1.8.3.4807-to-1.8.4.4878-enUS-patch.exe<=file
C:\WINDOWS\Resources\Themes\14410.exe<=file

Exit Explorer, and reboot as normal afterwards.

==========
Please perform an online scan with Internet Explorer at
http://www.kaspersky.com/service?chapter=161739400

* Turn off the real time scanner of any existing antivirus program while performing the online scan
Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure to:
    • Scan using the following Anti-Virus database:
      Extended
    • Scan Options:
      Scan Archives
      Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
**Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.


Please post (reply) with the Kaspersky log and a fresh hijackthis log. How is your computer running now?
I deleted the files you told me to (I deleted the whole “backup” folder within the Deckard folder, because there was no “backup” file).

I tried using the Kaspersky but it doesn’t work. I ran it twice and each time it stops at 1%, the 63rd file, freezing while trying to scan the file c:\\dell\mediaexe\ondrvmed.bin. I left it to scan for an hour and it was stuck nearly the whole time on that one file.

Here is my latest hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 5:29:26 PM, on 6/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.brandonmdennis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01CA75F1-054B-4A63-9221-C6926369EC52} (HS_live Control) - http://install.homestead.com/~site/Install…ive/HS_live.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {5AA5A569-F96F-4628-A528-8B3698F558BB} (HS_live Control) - http://install.homestead.com/~site/Install…ive/HS_live.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1128709406296
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup161.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MobilePre Installer (MobilePreInstallerService) - M-Audio - C:\Program Files\M-Audio MobilePre\Install\MPInst.exe

My system is acting a little better, but it is not perfect. I still cannot get through video files without the video hitching up. If I try to multitask, I drain my CPU. Things are noticeably better, but still not back to normal.
I started the Kaspersky scanner again and left it running all night while I slept, just in case it didn't work last time because I was too impatient. When I woke up, I saw the blue screen of death. It said that windows had encountered a problem and had shut down to prevent harm to my computer. Then it said: DRIVER_IRQL_NOT_LESS_OR_EQUAL. I tried starting IE this morning to post here, but I kept getting error messages and IE wouldn't load. It said that IE had encountered an error and had to close. Tried to start IE three times. So I am posting this using FireFox. Hopefully it isn't a permanent error. Yesterday I tried to use my computer like normal and ran into the same issues. I tried to use Adobe Premiere Pro, and for the first twenty minutes, everything was fine. Then it really started to slow down, and got so bad that I couldn't switch section tabs without waiting three minutes for the new section to load. Then I opened up my Homestead Site Builder software to update my webpage. I tried to type text into a text field and it literally took three minutes for the text I had typed to appear. Then I tried to watch some movies on YouTube and though the sound played well, I only saw one frame of video every five seconds or so. So my problems still persist, and I would really hate to reformat, because I have a number of programs which I use every day that I would be unable to reinstall. Thanks again for all of your help. I do appreciate it!
Have you done any of the recommendations from PCPitstop?
The "unusually low memory performance" is troubling. I am guessing that the 1024 MB RAM installed is the max?.

Unusually low performance (Drive C, F)
Drive F:\ has only 8 percent of its space available.

Are there any applications that you do not use anymore that you could uninstall?

Yes, I found that others cannot run the Panda or Kaspersky scan with the c:\\dell\mediaexe\ondrvmed.bin. One suggestion was to back-up/copy the ondrvmed.bin file, then delete it from your system, run the Panda and Kaspersky scans. Then restore or copy the file back to your system.

These programs do not need to run at start-up and so we will use hijackthis to delete the entries. Programs are still there but just will not load at start-up.

Disable SpywareGuard:
You have SpywareGuard installed. While this is a great program, we need to temporarily disable (not uninstall) the program because it might stop our fix.
  • Right click the running icon ofSpywareGuard, it will open the program.
  • Then go to Menu, file, exit.
  • Then confirm the program is closed.
After all of the fixes are complete it is very important that you enable SpywareGuard again.

Run hijackthis. Click Do a System Scan Only. Put a Check in the box on the left side on these:
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

Close ALL windows and browsers except HijackThis and click Fix checked and exit.

Get Updated Drivers (Touchstone Driver Agent)
http://www.pcpitstop.com/driverscan.asp
Please click the link and follow the instructions to run the scan.
Let me know if any bad drivers were found.
Please post(reply) with a fresh HijackThis log and let me know if you have any bad drivers.
Thanks again. Yes, some bad drivers were found, here is the list:

Driver Agent Scan Results
Print
Good Drivers (76%)
Bad Drivers (24%)

Driver Agent has determined that your computer is missing significant driver updates.

Display adapters
ATI MOBILITY RADEON 9800

IDE ATA/ATAPI controllers
Intel® 82801EB Ultra ATA Storage Controllers

Modems
Conexant D480 MDC V.9x Modem
Network adapters
Broadcom 570x Gigabit Integrated Controller

System Devices
Intel® 82865G\PE\P Processor to AGP Controller - 2571
Intel® 82865G\PE\P Processor to I/O Controller - 2570
Intel® 82801EB LPC Interface Controller - 24D0
Intel® 82801DB PCI Bridge - 244E
Texas Instruments OHCI Compliant IEEE 1394 Host Controller

F is an external hard drive. I can always unplug it or delete some files I have stored there. It is just for storage. I did uninstall a number of programs when I first started getting these troubles, so I am confident that all unneccesary programs are gone. Would you like me to backup and delete the dell file and then run a new Kaspersky scan?

I checked and removed the files you told me to. Here is the new HijackThis log. Thanks again!:

Logfile of HijackThis v1.99.1
Scan saved at 4:08:22 PM, on 6/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.brandonmdennis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01CA75F1-054B-4A63-9221-C6926369EC52} (HS_live Control) - http://install.homestead.com/~site/Install…ive/HS_live.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {5AA5A569-F96F-4628-A528-8B3698F558BB} (HS_live Control) - http://install.homestead.com/~site/Install…ive/HS_live.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1128709406296
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup161.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MobilePre Installer (MobilePreInstallerService) - M-Audio - C:\Program Files\M-Audio MobilePre\Install\MPInst.exe

Would you like me to backup and delete the dell file and then run a new Kaspersky scan?


I would feel better seeing the results of another scan run since MWAV did find some infected files.

Since you have a Dell from the PCPitstop results, try going to the Dell site and update those bad drivers. Bad drivers may be causing some of your problems and fixing those may clear up some problems.
http://search.dell.com/results.aspx?c=us&a…se&~ck=anav

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI