This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] hijacked!

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

web browser ie 7 redirected to undesirable sites each time!
Using trend micro hijack this! Here is my logfile….thank you!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:32:02 AM, on 10/17/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\RosettaStoneLtdServices\RosettaStoneLtdController.exe
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\RosettaStoneLtdServices\RosettaStoneLtdServer.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Microsoft Student\Microsoft Student with Encarta Premium 2008 DVD\EDICT.EXE
C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\V7PYKPXD\HiJackThis[1].exe
C:\Program Files\HiJackThis.exe
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\OPC\{C86EA115-FACD-4AA8-BFA2-398C677D0936}\SSAUTORN.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [L08AXLRD_10001578] "C:\Program Files\Microsoft Student\Microsoft Student with Encarta Premium 2008 DVD\EDICT.EXE" -m
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Encarta Search Bar - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (file missing)
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200705…ex/qtplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1165223957875
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://66.91.147.106:8010/activex/AMC.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O20 - AppInit_DLLs: karna.dat
O21 - SSODL: cmdsmartutil - {53699353-0C4C-57EE-A7D0-099BF33A1E62} - C:\Program Files\kvldqtb\cmdsmartutil.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: GameConsoleService - Unknown owner - C:\Program Files\WildTangent\Apps\My HP Game Console\GameConsoleService.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RosettaStoneLtdController - Rosetta Stone Ltd. - C:\Program Files\RosettaStoneLtdServices\RosettaStoneLtdController.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

–
End of file - 9421 bytes
Hello

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.


Download OTScanIt2.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt2 on your desktop.
  • Open the OTScanIt2 folder and double-click on OTScanIt.exe to start the program.
  • Under File Age at the top, change it from 30 days to 90 days
  • Under Additional Scans check the boxes beside Reg - App Paths, Reg - Desktop Components, Reg - Disabled MS Config Items, Reg - File Associations, File - Lop Check, File - Purity Scan, and Evnt - EventViewer Logs ( Last 10 Errors).
  • Under Rootkit Search change it to Yes
  • Now click the Run Scan button on the toolbar.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and post the information back here in an attachment. I will review it when it comes in. The last line is < End of Report >, so make sure that is the last line in the attached report.


Make sure you attach the report in your reply. If it is too big to upload, then zip the text file and upload it that way
Thank you, I have run SDFix.exe and here is the resultant Report.txt


SDFix: Version 1.236
Run by [removed] on Fri 10/17/2008 at 07:11 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\WINDOWS\system32\wini104552502.exe - Deleted
C:\WINDOWS\brastk.exe - Deleted
C:\WINDOWS\system32\brastk.exe - Deleted





Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-17 19:23:15
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{85AA346C-31AB-D13D-8346-962EAFD7A047}]
"bbjehkpkbibedmnngpigodenadhhoeehdpge"=hex:6a,61,67,6e,6e,6d,6a,67,6b,69,65,6e,61,62,6e,61,68,6d,6a,62,00,..
"abdgnheicjiamkkokbhllamcfdgogalllb"=hex:6a,61,67,6e,70,6d,70,62,61,62,63,65,65,6c,6b,6c,67,6a,66,61,00,..
"iajehkpkbibedmnngp"=hex:61,61,00,01
"hadgnheicjiamkko"=hex:61,61,00,01
"iafhhpdgnpjehieoai"=hex:61,61,00,01
"bbjehkpkbibedmnngpigodenadhhpehjbgop"=hex:6a,61,67,6e,6e,6d,6a,67,6b,69,65,6e,61,62,6e,61,68,6d,6a,62,00,..
"abdgnheicjiamkkokbhllamcfddodcnhkp"=hex:6a,61,66,6e,6a,6d,6a,63,69,69,6e,6a,6c,67,64,62,64,6d,61,6d,00,..
"abfhholfphokmdaddclnnbhjilifbepbmk"=hex:61,61,00,00
"maehmnbddhdngaffgkocapokja"=hex:61,61,00,00

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\DISC\\DISCover.exe"="C:\\Program Files\\DISC\\DISCover.exe:*:Enabled:DISCover Drop & Play System"
"C:\\Program Files\\DISC\\DiscStreamHub.exe"="C:\\Program Files\\DISC\\DiscStreamHub.exe:*:Enabled:DISCover Stream Hub"
"C:\\Program Files\\DISC\\myFTP.exe"="C:\\Program Files\\DISC\\myFTP.exe:*:Enabled:DISCover FTP"
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP"
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"="C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe:*:Enabled:Earthlink"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\RosettaStoneLtdServices\\RosettaStoneLtdController.exe"="C:\\Program Files\\RosettaStoneLtdServices\\RosettaStoneLtdController.exe:*:Enabled:RosettaStoneLtdController"
"C:\\Program Files\\RosettaStoneLtdServices\\RosettaStoneLtdServer.exe"="C:\\Program Files\\RosettaStoneLtdServices\\RosettaStoneLtdServer.exe:*:Enabled:RosettaStoneLtdServer"
"C:\\Program Files\\RosettaStoneLtdServices\\RosettaStoneLtdServices.exe"="C:\\Program Files\\RosettaStoneLtdServices\\RosettaStoneLtdServices.exe:*:Enabled:RosettaStoneLtdServices"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\RosettaStoneLtdServices\\RosettaStoneLtdController.exe"="C:\\Program Files\\RosettaStoneLtdServices\\RosettaStoneLtdController.exe:*:Enabled:RosettaStoneLtdController"
"C:\\Program Files\\RosettaStoneLtdServices\\RosettaStoneLtdServer.exe"="C:\\Program Files\\RosettaStoneLtdServices\\RosettaStoneLtdServer.exe:*:Enabled:RosettaStoneLtdServer"
"C:\\Program Files\\RosettaStoneLtdServices\\RosettaStoneLtdServices.exe"="C:\\Program Files\\RosettaStoneLtdServices\\RosettaStoneLtdServices.exe:*:Enabled:RosettaStoneLtdServices"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Sun 3 Dec 2006 211 A.SHR — "C:\BOOT.BAK"
Mon 22 Jan 2007 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 30 Jun 2008 12,506 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0061.tmp"
Sun 20 Jul 2008 11,786 …H. — "C:\Documents and Settings\HP_Administrator\My Documents\~WRL0546.tmp"
Sun 30 Mar 2008 56 A.SH. — "C:\Documents and Settings\All Users\Documents\Recorded TV\MSDVRMM_2564650841_2424832_19974.tmp"
Sat 21 Jul 2007 63,668 A.SH. — "C:\Documents and Settings\All Users\Documents\Recorded TV\MSDVRMM_2564650841_1245184_151984.tmp"
Sun 30 Mar 2008 56 A.SH. — "C:\Documents and Settings\All Users\Documents\Recorded TV\MSDVRMM_2564650841_23724032_36878.tmp"
Wed 25 Jul 2007 14,192 A.SH. — "C:\Documents and Settings\All Users\Documents\Recorded TV\MSDVRMM_2564650841_2949120_88152.tmp"
Sun 6 May 2007 3,590 A.SH. — "C:\Documents and Settings\All Users\Documents\Recorded TV\MSDVRMM_2564650841_1507328_76812.tmp"
Mon 1 Oct 2007 31,862 A.SH. — "C:\Documents and Settings\All Users\Documents\Recorded TV\MSDVRMM_2564650841_1984167936_30796.tmp"
Sat 21 Jul 2007 56 A.SH. — "C:\Documents and Settings\All Users\Documents\Recorded TV\MSDVRMM_2564650841_3538944_151203.tmp"
Fri 25 Jul 2008 10,658 A.SH. — "C:\Documents and Settings\All Users\Documents\Recorded TV\MSDVRMM_2564650841_327680_56514.tmp"
Sun 30 Mar 2008 3,590 A.SH. — "C:\Documents and Settings\All Users\Documents\Recorded TV\MSDVRMM_2564650841_1114112_30503.tmp"
Sat 12 Apr 2008 56 A.SH. — "C:\Documents and Settings\All Users\Documents\Recorded TV\MSDVRMM_2564650841_327680_9726.tmp"
Sat 13 Jan 2007 31,862 A.SH. — "C:\Documents and Settings\All Users\Documents\Recorded TV\MSDVRMM_2564650841_1048576_98816.tmp"
Sun 4 Feb 2007 130,814 A.SH. — "C:\Documents and Settings\All Users\Documents\Recorded TV\MSDVRMM_2564650841_1310720_157105.tmp"
Mon 2 Apr 2007 14,192 A.SH. — "C:\Documents and Settings\All Users\Documents\Recorded TV\MSDVRMM_2564650841_786432_154958.tmp"
Sun 4 Feb 2007 14,192 A.SH. — "C:\Documents and Settings\All Users\Documents\Recorded TV\MSDVRMM_2564650841_196608_159538.tmp"
Mon 28 Apr 2008 63,668 A.SH. — "C:\Documents and Settings\All Users\Documents\Recorded TV\MSDVRMM_2564650841_1985413120_40176.tmp"
Wed 18 Jun 2008 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Fri 2 Feb 2007 20,480 …H. — "C:\Documents and Settings\HP_Administrator\Desktop\Erica's School\~WRL2128.tmp"
Fri 18 Jan 2008 400 A..H. — "C:\Program Files\Common Files\Symantec Shared\COH\COH32LU.reg"
Fri 18 Jan 2008 403 A..H. — "C:\Program Files\Common Files\Symantec Shared\COH\COHDLU.reg"
Sun 18 Sep 2005 788,568 A..H. — "C:\Program Files\Online Services\Canada\KOL\client.exe"
Wed 17 Aug 2005 13,459,528 A..H. — "C:\Program Files\Online Services\NetscapeOnline\Netscape Tech\nsb-install-8-0.exe"
Wed 17 Aug 2005 233,472 A..H. — "C:\Program Files\Online Services\NetscapeOnline\Netscape Tech\webutil8.exe"
Wed 17 Aug 2005 389,120 A..H. — "C:\Program Files\Online Services\NetscapeOnline\Netscape Tech\WinsockFix.exe"
Sun 12 Oct 2008 266,048 …HR — "C:\WINDOWS\system32\drivers\etc\Hosts.bak"
Tue 23 Oct 2007 3,350,528 A..H. — "C:\Documents and Settings\HP_Administrator\Application Data\U3\temp\Launchpad Removal.exe"
Mon 22 Jan 2007 11,115 A.SH. — "C:\Documents and Settings\HP_Administrator\My Documents\My Music\License Backup\drmv2key.bak"
Wed 14 Dec 2005 200,704 A..H. — "C:\Program Files\Online Services\Aol\United States\AOL90\ACST4.DLL"
Tue 22 Nov 2005 81,920 A..H. — "C:\Program Files\Online Services\Aol\United States\AOL90\AOLFIREWALLMGR.DLL"
Tue 22 Nov 2005 73,728 A..H. — "C:\Program Files\Online Services\Aol\United States\AOL90\AOLINSTALLERFW.DLL"
Wed 14 Dec 2005 88,064 A..H. — "C:\Program Files\Online Services\Aol\United States\AOL90\INSTPH.DLL"
Wed 14 Dec 2005 200,704 A..H. — "C:\Program Files\Online Services\Aol\United States\AOL90E\ACST4.DLL"
Tue 22 Nov 2005 81,920 A..H. — "C:\Program Files\Online Services\Aol\United States\AOL90E\AOLFIREWALLMGR.DLL"
Tue 22 Nov 2005 73,728 A..H. — "C:\Program Files\Online Services\Aol\United States\AOL90E\AOLINSTALLERFW.DLL"
Wed 14 Dec 2005 88,064 A..H. — "C:\Program Files\Online Services\Aol\United States\AOL90E\INSTPH.DLL"
Fri 17 Oct 2008 5,946 A.SH. — "C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\TempSBE\SBE4.tmp"
Sun 18 Sep 2005 77,824 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\acs\AcsInstN.dll"
Sun 18 Sep 2005 6,961,146 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\acs\acsnet.zip"
Sun 18 Sep 2005 3,058,888 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\acs\acssetup.exe"
Sun 18 Sep 2005 307,289 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\asp\aspcheck.dll"
Sun 18 Sep 2005 7,083,361 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\asp\aspsetup.exe"
Wed 21 Sep 2005 1,960,296 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\autoit\autoit-v3.zip"
Sun 18 Sep 2005 550,488 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\deskbar\deskbr.exe"
Sun 18 Sep 2005 553,984 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\flash\FlashAX.exe"
Sun 18 Sep 2005 2,242,759 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\fw\nisale.exe"
Sun 18 Sep 2005 24,064 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\fw\NISChk.dll"
Sun 18 Sep 2005 57,344 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\ocp\ocpchk.dll"
Sun 18 Sep 2005 748,728 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\ocp\ocpinst.exe"
Sun 18 Sep 2005 7,515,304 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\qt\qt.exe"
Sun 18 Sep 2005 86,016 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\qt\QTInsInf.dll"
Sun 18 Sep 2005 45,056 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\rp\RealChk.dll"
Sun 18 Sep 2005 5,111,296 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\rp\RealPl8.EXE"
Sun 18 Sep 2005 4,378,673 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\rp\real_upd.exe"
Sun 18 Sep 2005 360,448 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\rp\rp9codec.exe"
Sun 18 Sep 2005 40,960 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\sysinfo\SiNdInst.dll"
Sun 18 Sep 2005 473,736 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\sysinfo\SinfInst.exe"
Sun 18 Sep 2005 12,288 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\tb\tbinst.dll"
Sun 18 Sep 2005 516,032 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\tb\tbsetup.exe"
Sun 18 Sep 2005 597,080 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\toolbar\toolbr.exe"
Sun 18 Sep 2005 590,688 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\tpspd\TSsetup.exe"
Sun 18 Sep 2005 57,344 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\tpspd\tsverchk.dll"
Sun 18 Sep 2005 49,152 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\vwpt\AOLVPChk.dll"
Sun 18 Sep 2005 61,440 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\vwpt\VPPrePop.exe"
Sun 18 Sep 2005 3,858,056 A..H. — "C:\Program Files\Online Services\Canada\KOL\comps\vwpt\Vwpt.exe"

Finished!
Hello

Start OTScanIt2. Copy/Paste the information in the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

[Kill Explorer]
[Unregister Dlls]
[Processes - Safe List]
YN -> aawservice.exe -> %ProgramFiles%\Lavasoft\Ad-Aware\aawservice.exe
YN -> teatimer.exe -> %ProgramFiles%\Spybot - Search & Destroy\TeaTimer.exe
YN -> ad-watch.exe -> %ProgramFiles%\Lavasoft\Ad-Aware\Ad-Watch.exe
[Win32 Services - Safe List]
YY -> (GameConsoleService) GameConsoleService [Win32_Own | On_Demand | Stopped] ->
[Registry - Safe List]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\
YN -> {E2D4D26B-0180-43a4-B05F-462D6D54C789}:C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm [HKLM] -> %SystemRoot%\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm [Button: Internet Connection Help]
YN -> {E2D4D26B-0180-43a4-B05F-462D6D54C789}:C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm [HKLM] -> %SystemRoot%\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm [Menu: Internet Connection Help]
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\
YN -> CmdMapping\\"{2D663D1A-8670-49D9-A1A5-4C56B4E14E84}" [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
YN -> CmdMapping\\"{E2D4D26B-0180-43a4-B05F-462D6D54C789}" [HKLM] -> [Internet Connection Help]
< SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
YY -> "{53699353-0C4C-57EE-A7D0-099BF33A1E62}" [HKLM] -> %ProgramFiles%\kvldqtb\cmdsmartutil.dll [cmdsmartutil]
[Files/Folders - Created Within All Days]
NY -> 170 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> 4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> SDFix -> %SystemDrive%\SDFix
NY -> SDFix.exe -> %UserProfile%\Desktop\SDFix.exe
[Empty Temp Folders]
[Start Explorer]
[Reboot]


The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here

I will review the information when it comes back in.




Also post a new HJT log
heres the next log…thank you [Processes - Safe List] Unable to kill process aawservice.exe . Process teatimer.exe killed successfully. Unable to kill process ad-watch.exe . [Win32 Services - Safe List] Service GameConsoleService stopped successfully. Service GameConsoleService deleted successfully. File not found. [Registry - Safe List] Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{E2D4D26B-0180-43a4-B05F-462D6D54C789}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2D4D26B-0180-43a4-B05F-462D6D54C789}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{E2D4D26B-0180-43a4-B05F-462D6D54C789}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2D4D26B-0180-43a4-B05F-462D6D54C789}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{2D663D1A-8670-49D9-A1A5-4C56B4E14E84} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D663D1A-8670-49D9-A1A5-4C56B4E14E84}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{E2D4D26B-0180-43a4-B05F-462D6D54C789} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2D4D26B-0180-43a4-B05F-462D6D54C789}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\cmdsmartutil deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\"{53699353-0C4C-57EE-A7D0-099BF33A1E62}"\ not found. C:\Program Files\kvldqtb\cmdsmartutil.dll moved successfully. [Files/Folders - Created Within All Days] C:\WINDOWS\msdownld.tmp folder deleted successfully. C:\SDFix\backups folder moved successfully. C:\SDFix\apps\Replace\xp folder moved successfully. C:\SDFix\apps\Replace\w2k folder moved successfully. C:\SDFix\apps\Replace folder moved successfully. C:\SDFix\apps folder moved successfully. C:\SDFix folder moved successfully. C:\Documents and Settings\HP_Administrator\Desktop\SDFix.exe moved successfully. [Empty Temp Folders] File delete failed. C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\PX1SYBFN\;a1_0=0;a1_7=0;a2=0;a3=0;a4=0;a5=0;a6=0;a7=0;a9=0;a11=0;a13=0;a15=0;a18=0;s pon=aol_autos;sens=0;m=0;mage=0;area=groups;gcat=;gid=82484;2omk=;sz=300x250;tile =2;ord=412316737[1] scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\8UP8WVGL\;a1_0=0;a1_7=0;a2=0;a3=0;a4=0;a5=0;a6=0;a7=0;a9=0;a11=0;a13=0;a15=0;a18=0;s pon=aol_autos;sens=0;m=0;mage=0;area=groups;gcat=;gid=82484;2omk=;sz=160x600;tile =3;ord=412316737[1] scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\8UP8WVGL\VtYkdodVBXMWxkR0UyTXkxbE1Ba3dMakF4TlFreE56VXpNUWt4Q1RnMk1qUmZOakVKQ1RJSlZXN XBkR1ZrSUZOMFlYUmxjd2xWVXclM0QlM0Qmb2JqVGltU3RyPTAuMDQ3NzkyMDArMTIyMzkzNTc0Mg==;f _79627077649[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\12V6XWG7\0;a1_0=0;a1_7=0;a2=0;a3=0;a4=0;a5=0;a6=0;a7=0;a9=0;a11=0;a13=0;a15=0;a18=0;sp on=aol_autos;sens=0;m=0;mage=0;area=groups;gcat=;gid=82484;2omk=;sz=728x90;tile=1 ;ord=412316737[1] scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\JET92F9.tmp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_704.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. RecycleBin -> emptied. Explorer started successfully < End of fix log > OTScanIt2 by OldTimer - Version 1.0.0.16b fix logfile created on 10182008_144418 Files moved on Reboot… File C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\PX1SYBFN\;a1_0=0;a1_7=0;a2=0;a3=0;a4=0;a5=0;a6=0;a7=0;a9=0;a11=0;a13=0;a15=0;a18=0;s pon=aol_autos;sens=0;m=0;mage=0;area=groups;gcat=;gid=82484;2omk=;sz=300x250;tile =2;ord=412316737[1] not found! File C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\8UP8WVGL\;a1_0=0;a1_7=0;a2=0;a3=0;a4=0;a5=0;a6=0;a7=0;a9=0;a11=0;a13=0;a15=0;a18=0;s pon=aol_autos;sens=0;m=0;mage=0;area=groups;gcat=;gid=82484;2omk=;sz=160x600;tile =3;ord=412316737[1] not found! File C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\8UP8WVGL\VtYkdodVBXMWxkR0UyTXkxbE1Ba3dMakF4TlFreE56VXpNUWt4Q1RnMk1qUmZOakVKQ1RJSlZXN XBkR1ZrSUZOMFlYUmxjd2xWVXclM0QlM0Qmb2JqVGltU3RyPTAuMDQ3NzkyMDArMTIyMzkzNTc0Mg==;f _79627077649[1].gif not found! File C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\12V6XWG7\0;a1_0=0;a1_7=0;a2=0;a3=0;a4=0;a5=0;a6=0;a7=0;a9=0;a11=0;a13=0;a15=0;a18=0;sp on=aol_autos;sens=0;m=0;mage=0;area=groups;gcat=;gid=82484;2omk=;sz=728x90;tile=1 ;ord=412316737[1] not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be moved on reboot. File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be moved on reboot. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat moved successfully. File C:\WINDOWS\temp\JET92F9.tmp not found! File move failed. C:\WINDOWS\temp\Perflib_Perfdata_704.dat scheduled to be moved on reboot.
Hello

]Disable resident protections (Antivirus…); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)



Also post a new HJT log
back to you…should all this be done in safe mode or normal ?

——————–\\ Lop S&D 4.2.4-5 XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : AMD Athlon™ 64 X2 Dual Core Processor 3800+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : HP_Administrator ( Administrator )
BOOT : Normal boot
Antivirus : Norton 360 2007 (Activated)
Firewall : Norton 360 2007 (Activated)
C:\ (Local Disk) - NTFS - Total : 177 Go Free : 87 Go
D:\ (Local Disk) - FAT32 - Total : 8 Go Free : 0 Go
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)

"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [1] ( Sun 10/19/2008| 6:37 )

——————–\\ Listing folders in APPLIC~1

[10/12/2008|06:49] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Adobe
[11/14/2005|03:04] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Identities
[09/27/2006|02:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Intuit
[10/12/2008|06:49] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Macromedia
[10/12/2008|07:56] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Microsoft
[09/27/2006|02:41] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Real
[10/12/2008|06:51] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Symantec

[10/12/2008|01:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[05/22/2008|05:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[08/16/2007|10:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple
[05/02/2007|05:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[09/27/2006|02:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ CyberLink
[06/03/2007|02:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Digital Interactive Systems Corporation
[12/05/2006|05:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Google
[10/18/2008|09:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Google Updater
[09/27/2006|03:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Hewlett-Packard
[12/08/2006|07:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ HP
[09/27/2006|02:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ InstallShield
[09/27/2006|02:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Intuit
[10/11/2008|07:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Lavasoft
[01/29/2008|06:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[10/14/2008|10:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft Help
[12/08/2006|10:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ nView_Profiles
[05/04/2007|10:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Office Genuine Advantage
[02/25/2007|06:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Otto
[10/12/2008|02:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ PCPitstop
[05/02/2007|05:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ QuickTime
[08/14/2008|03:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ RosettaStoneLtdServices
[12/04/2006|04:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Sandlot Games
[09/27/2006|02:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SBSI
[09/27/2006|02:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Sonic
[10/13/2008|06:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Spybot - Search & Destroy
[10/12/2008|05:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Symantec
[01/18/2007|01:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TEMP
[03/24/2008|02:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ WildTangent
[12/03/2006|11:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[10/17/2008|09:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ WinZip
[10/12/2008|01:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ wrgzevat

[11/14/2005|03:04] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Identities
[09/27/2006|02:54] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Intuit
[07/29/2008|08:55] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Macromedia
[09/27/2006|03:23] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft
[09/27/2006|02:41] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Real

[11/14/2005|03:04] C:\DOCUME~1\Guest\APPLIC~1\ Identities
[09/27/2006|02:54] C:\DOCUME~1\Guest\APPLIC~1\ Intuit
[10/12/2008|07:56] C:\DOCUME~1\Guest\APPLIC~1\ Microsoft
[09/27/2006|02:41] C:\DOCUME~1\Guest\APPLIC~1\ Real

[04/11/2007|11:18] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Adobe
[05/22/2008|05:24] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ AdobeUM
[07/23/2008|07:39] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Alternative Software Ltd
[03/31/2008|08:12] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Apple Computer
[12/06/2006|08:08] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ funkitron
[05/12/2008|11:32] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Google
[12/28/2006|05:17] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Help
[12/08/2006|07:40] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ HP
[12/08/2006|09:55] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ HPQ
[12/12/2006|04:33] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Identities
[01/01/2008|09:51] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Image Zone Express
[09/27/2006|02:54] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Intuit
[01/29/2008|06:38] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Lavasoft
[01/11/2007|10:15] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Leadertech
[12/04/2006|04:11] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Macromedia
[08/28/2008|03:49] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Microsoft
[12/03/2006|11:00] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Netscape
[03/04/2008|09:46] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Nikon
[08/25/2007|09:22] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ OfficeUpdate12
[02/25/2007|06:42] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Otto
[12/04/2006|04:11] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ PlayFirst
[10/04/2007|12:37] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Printer Info Cache
[04/22/2008|05:47] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Real
[01/11/2007|10:15] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Sonic
[12/03/2006|10:30] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Sun
[10/12/2008|12:53] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Symantec
[05/03/2008|03:54] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Template
[09/22/2008|03:13] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ U3
[02/26/2008|07:02] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Watchtower
[12/04/2006|09:04] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ WildTangent
[10/03/2007|10:21] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ WinBatch

[10/12/2008|07:56] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft
[12/25/2007|04:37] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Symantec

[10/12/2008|07:56] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft

——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[09/05/2007 10:20 PM][–ah—–] C:\WINDOWS\tasks\Microsoft_Hardware_Launch_IPoint_exe.job
[08/16/2008 05:44 AM][–a——] C:\WINDOWS\tasks\Disk Cleanup.job
[10/19/2008 06:17 AM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[08/10/2004 01:00 AM][-rah—–] C:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in C:\Program Files

[09/27/2006|02:54] C:\Program Files\ Adobe
[09/04/2008|07:11] C:\Program Files\ Akamai
[07/23/2008|07:27] C:\Program Files\ Alternative Software Ltd
[04/16/2008|06:21] C:\Program Files\ Apple Software Update
[03/04/2008|09:37] C:\Program Files\ ArcSoft
[06/21/2008|11:26] C:\Program Files\ Axis Communications
[04/10/2008|05:03] C:\Program Files\ CCleaner
[10/12/2008|08:23] C:\Program Files\ Common Files
[11/11/2005|12:56] C:\Program Files\ ComPlus Applications
[04/15/2007|05:57] C:\Program Files\ Cosmi
[01/16/2007|03:58] C:\Program Files\ DIFX
[11/07/2007|02:04] C:\Program Files\ DISC
[09/27/2006|02:54] C:\Program Files\ DivX
[09/27/2006|02:12] C:\Program Files\ EnglishOtto
[09/27/2006|02:12] C:\Program Files\ GemMaster
[07/29/2008|08:56] C:\Program Files\ Google
[09/27/2006|03:05] C:\Program Files\ Hewlett-Packard
[04/11/2008|05:13] C:\Program Files\ HP
[09/27/2006|02:42] C:\Program Files\ HP DigitalMedia Archive
[03/24/2008|02:50] C:\Program Files\ HP Games
[03/24/2008|01:42] C:\Program Files\ InstallShield Installation Information
[02/17/2007|08:18] C:\Program Files\ InterActual
[10/14/2008|10:29] C:\Program Files\ Internet Explorer
[04/07/2008|01:26] C:\Program Files\ iPod
[04/07/2008|01:26] C:\Program Files\ iTunes
[02/26/2008|06:42] C:\Program Files\ Java
[10/18/2008|02:44] C:\Program Files\ kvldqtb
[10/12/2008|08:24] C:\Program Files\ Lavasoft
[08/28/2007|03:39] C:\Program Files\ Learning Essentials
[09/05/2008|07:37] C:\Program Files\ Messenger
[08/25/2007|10:01] C:\Program Files\ Microsoft CAPICOM 2.1.0.2
[11/14/2005|03:06] C:\Program Files\ microsoft frontpage
[01/18/2007|03:18] C:\Program Files\ Microsoft Games
[09/05/2007|06:07] C:\Program Files\ Microsoft IntelliPoint
[09/27/2006|02:50] C:\Program Files\ Microsoft Money 2006
[09/07/2007|06:48] C:\Program Files\ Microsoft My Personal Tutor
[08/25/2007|06:49] C:\Program Files\ Microsoft Office
[10/08/2008|06:13] C:\Program Files\ Microsoft Silverlight
[08/28/2007|03:51] C:\Program Files\ Microsoft Student
[08/25/2007|08:27] C:\Program Files\ Microsoft Visual Studio
[08/25/2007|08:28] C:\Program Files\ Microsoft Works
[08/25/2007|06:49] C:\Program Files\ Microsoft.NET
[09/05/2008|07:28] C:\Program Files\ Movie Maker
[08/30/2008|02:08] C:\Program Files\ MSECache
[11/14/2005|03:07] C:\Program Files\ MSN
[09/27/2006|02:50] C:\Program Files\ MSN Encarta Standard
[11/14/2005|03:07] C:\Program Files\ MSN Gaming Zone
[12/03/2006|11:39] C:\Program Files\ MSXML 4.0
[08/29/2007|09:22] C:\Program Files\ MSXML 6.0
[09/27/2006|02:41] C:\Program Files\ music_now
[09/27/2006|02:53] C:\Program Files\ muvee Technologies
[03/17/2008|12:20] C:\Program Files\ Netflix
[09/05/2008|07:24] C:\Program Files\ NetMeeting
[09/27/2006|02:41] C:\Program Files\ Netscape
[03/04/2008|09:39] C:\Program Files\ Nikon
[05/26/2008|04:18] C:\Program Files\ Nobeltec
[10/12/2008|01:52] C:\Program Files\ Norton 360
[09/27/2006|03:07] C:\Program Files\ Online Services
[09/05/2008|07:42] C:\Program Files\ Outlook Express
[10/12/2008|08:02] C:\Program Files\ Panda Security
[12/05/2006|12:51] C:\Program Files\ PC-Doctor 5 for Windows
[09/27/2006|03:03] C:\Program Files\ PC-Doctor for DOS
[03/24/2008|02:04] C:\Program Files\ PCPitstop
[01/16/2007|02:00] C:\Program Files\ Pure Networks
[09/27/2006|02:54] C:\Program Files\ Quicken
[04/07/2008|01:23] C:\Program Files\ QuickTime
[10/17/2008|08:42] C:\Program Files\ QuickZip4
[09/27/2006|02:40] C:\Program Files\ Real
[10/18/2008|08:48] C:\Program Files\ Registry Mechanic
[10/02/2008|11:00] C:\Program Files\ RosettaStoneLtdServices
[03/24/2008|02:51] C:\Program Files\ Sonic
[10/11/2008|07:30] C:\Program Files\ SpeedFan
[10/12/2008|08:35] C:\Program Files\ Spybot - Search & Destroy
[01/18/2007|01:30] C:\Program Files\ Spyware Doctor
[10/12/2008|02:02] C:\Program Files\ Symantec
[01/18/2007|07:00] C:\Program Files\ Symantec Technical Support
[02/26/2007|04:09] C:\Program Files\ The Weather Channel FW
[04/27/2007|02:28] C:\Program Files\ THQ
[11/11/2005|12:56] C:\Program Files\ Uninstall Information
[09/27/2006|02:58] C:\Program Files\ Updates from HP
[02/26/2008|06:41] C:\Program Files\ Watchtower
[09/27/2006|02:43] C:\Program Files\ WildTangent
[10/13/2008|06:41] C:\Program Files\ Windows Media Components
[04/21/2007|11:14] C:\Program Files\ Windows Media Connect 2
[04/21/2007|11:14] C:\Program Files\ Windows Media Player
[09/05/2008|07:24] C:\Program Files\ Windows NT
[11/14/2005|03:08] C:\Program Files\ Windows Plus
[10/12/2008|12:50] C:\Program Files\ Windows Sidebar
[11/11/2005|12:56] C:\Program Files\ WindowsUpdate
[10/17/2008|08:58] C:\Program Files\ WinRAR
[10/17/2008|09:26] C:\Program Files\ WinZip
[11/14/2005|03:08] C:\Program Files\ xerox
[04/10/2008|05:03] C:\Program Files\ Yahoo!

——————–\\ Listing Folders in C:\Program Files\Common Files

[05/22/2008|05:26] C:\Program Files\Common Files\ Adobe
[12/16/2006|05:39] C:\Program Files\Common Files\ AOL
[08/16/2007|10:51] C:\Program Files\Common Files\ Apple
[03/05/2007|08:30] C:\Program Files\Common Files\ Cosmi
[08/25/2007|08:27] C:\Program Files\Common Files\ DESIGNER
[12/08/2006|07:30] C:\Program Files\Common Files\ Hewlett-Packard
[09/27/2006|02:36] C:\Program Files\Common Files\ HP
[09/27/2006|03:04] C:\Program Files\Common Files\ InstallShield
[09/27/2006|02:54] C:\Program Files\Common Files\ Intuit
[09/27/2006|02:17] C:\Program Files\Common Files\ Java
[01/09/2007|08:43] C:\Program Files\Common Files\ LightScribe
[09/27/2006|02:48] C:\Program Files\Common Files\ LS Getting Started
[03/19/2008|09:22] C:\Program Files\Common Files\ Microsoft Shared
[11/14/2005|03:06] C:\Program Files\Common Files\ MSSoap
[09/27/2006|02:53] C:\Program Files\Common Files\ muvee Technologies
[03/04/2008|09:39] C:\Program Files\Common Files\ Nikon
[11/14/2005|03:06] C:\Program Files\Common Files\ ODBC
[09/27/2006|02:54] C:\Program Files\Common Files\ Palo Alto Software
[02/26/2007|04:08] C:\Program Files\Common Files\ Pure Networks Shared
[09/27/2006|02:40] C:\Program Files\Common Files\ Real
[12/04/2006|04:04] C:\Program Files\Common Files\ Sandlot Shared
[11/14/2005|03:06] C:\Program Files\Common Files\ Services
[03/24/2008|02:50] C:\Program Files\Common Files\ Sonic Shared
[11/14/2005|03:06] C:\Program Files\Common Files\ SpeechEngines
[10/19/2008|06:17] C:\Program Files\Common Files\ Symantec Shared
[09/05/2008|07:42] C:\Program Files\Common Files\ System
[10/12/2008|08:23] C:\Program Files\Common Files\ Wise Installation Wizard
[09/27/2006|02:40] C:\Program Files\Common Files\ xing shared

——————–\\ Process

( 45 Processes )

IEXPLORE.EXE ~ [PID:3160]

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

No Lop folder found !

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-19 06:38:08
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections

——————–\\ Cracks & Keygens ..

C:\DOCUME~1\HP_ADM~1\My Documents\My Videos\Creativity Fun Packs\Sound Effects\sports\Baseball Bat Hit, Crack.wma


[F:8][D:3]-> C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp
[F:156][D:0]-> C:\DOCUME~1\HP_ADM~1\Cookies
[F:2255][D:16]-> C:\DOCUME~1\HP_ADM~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Sun 10/19/2008| 6:39 - Option : [1]

——————–\\ Scan completed at 6:39:16
2nd try…nav now deactivated

——————–\\ Lop S&D 4.2.4-5 XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : AMD Athlon™ 64 X2 Dual Core Processor 3800+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : HP_Administrator ( Administrator )
BOOT : Normal boot
Antivirus : Norton 360 2007 (Activated)
Firewall : Norton 360 2007 (Activated)
C:\ (Local Disk) - NTFS - Total : 177 Go Free : 87 Go
D:\ (Local Disk) - FAT32 - Total : 8 Go Free : 0 Go
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)

"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [1] ( Sun 10/19/2008| 6:37 )

——————–\\ Listing folders in APPLIC~1

[10/12/2008|06:49] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Adobe
[11/14/2005|03:04] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Identities
[09/27/2006|02:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Intuit
[10/12/2008|06:49] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Macromedia
[10/12/2008|07:56] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Microsoft
[09/27/2006|02:41] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Real
[10/12/2008|06:51] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Symantec

[10/12/2008|01:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[05/22/2008|05:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[08/16/2007|10:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple
[05/02/2007|05:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[09/27/2006|02:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ CyberLink
[06/03/2007|02:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Digital Interactive Systems Corporation
[12/05/2006|05:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Google
[10/18/2008|09:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Google Updater
[09/27/2006|03:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Hewlett-Packard
[12/08/2006|07:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ HP
[09/27/2006|02:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ InstallShield
[09/27/2006|02:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Intuit
[10/11/2008|07:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Lavasoft
[01/29/2008|06:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[10/14/2008|10:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft Help
[12/08/2006|10:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ nView_Profiles
[05/04/2007|10:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Office Genuine Advantage
[02/25/2007|06:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Otto
[10/12/2008|02:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ PCPitstop
[05/02/2007|05:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ QuickTime
[08/14/2008|03:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ RosettaStoneLtdServices
[12/04/2006|04:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Sandlot Games
[09/27/2006|02:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SBSI
[09/27/2006|02:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Sonic
[10/13/2008|06:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Spybot - Search & Destroy
[10/12/2008|05:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Symantec
[01/18/2007|01:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TEMP
[03/24/2008|02:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ WildTangent
[12/03/2006|11:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[10/17/2008|09:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ WinZip
[10/12/2008|01:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ wrgzevat

[11/14/2005|03:04] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Identities
[09/27/2006|02:54] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Intuit
[07/29/2008|08:55] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Macromedia
[09/27/2006|03:23] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft
[09/27/2006|02:41] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Real

[11/14/2005|03:04] C:\DOCUME~1\Guest\APPLIC~1\ Identities
[09/27/2006|02:54] C:\DOCUME~1\Guest\APPLIC~1\ Intuit
[10/12/2008|07:56] C:\DOCUME~1\Guest\APPLIC~1\ Microsoft
[09/27/2006|02:41] C:\DOCUME~1\Guest\APPLIC~1\ Real

[04/11/2007|11:18] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Adobe
[05/22/2008|05:24] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ AdobeUM
[07/23/2008|07:39] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Alternative Software Ltd
[03/31/2008|08:12] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Apple Computer
[12/06/2006|08:08] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ funkitron
[05/12/2008|11:32] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Google
[12/28/2006|05:17] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Help
[12/08/2006|07:40] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ HP
[12/08/2006|09:55] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ HPQ
[12/12/2006|04:33] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Identities
[01/01/2008|09:51] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Image Zone Express
[09/27/2006|02:54] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Intuit
[01/29/2008|06:38] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Lavasoft
[01/11/2007|10:15] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Leadertech
[12/04/2006|04:11] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Macromedia
[08/28/2008|03:49] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Microsoft
[12/03/2006|11:00] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Netscape
[03/04/2008|09:46] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Nikon
[08/25/2007|09:22] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ OfficeUpdate12
[02/25/2007|06:42] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Otto
[12/04/2006|04:11] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ PlayFirst
[10/04/2007|12:37] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Printer Info Cache
[04/22/2008|05:47] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Real
[01/11/2007|10:15] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Sonic
[12/03/2006|10:30] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Sun
[10/12/2008|12:53] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Symantec
[05/03/2008|03:54] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Template
[09/22/2008|03:13] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ U3
[02/26/2008|07:02] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ Watchtower
[12/04/2006|09:04] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ WildTangent
[10/03/2007|10:21] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ WinBatch

[10/12/2008|07:56] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft
[12/25/2007|04:37] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Symantec

[10/12/2008|07:56] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft

——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[09/05/2007 10:20 PM][–ah—–] C:\WINDOWS\tasks\Microsoft_Hardware_Launch_IPoint_exe.job
[08/16/2008 05:44 AM][–a——] C:\WINDOWS\tasks\Disk Cleanup.job
[10/19/2008 06:17 AM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[08/10/2004 01:00 AM][-rah—–] C:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in C:\Program Files

[09/27/2006|02:54] C:\Program Files\ Adobe
[09/04/2008|07:11] C:\Program Files\ Akamai
[07/23/2008|07:27] C:\Program Files\ Alternative Software Ltd
[04/16/2008|06:21] C:\Program Files\ Apple Software Update
[03/04/2008|09:37] C:\Program Files\ ArcSoft
[06/21/2008|11:26] C:\Program Files\ Axis Communications
[04/10/2008|05:03] C:\Program Files\ CCleaner
[10/12/2008|08:23] C:\Program Files\ Common Files
[11/11/2005|12:56] C:\Program Files\ ComPlus Applications
[04/15/2007|05:57] C:\Program Files\ Cosmi
[01/16/2007|03:58] C:\Program Files\ DIFX
[11/07/2007|02:04] C:\Program Files\ DISC
[09/27/2006|02:54] C:\Program Files\ DivX
[09/27/2006|02:12] C:\Program Files\ EnglishOtto
[09/27/2006|02:12] C:\Program Files\ GemMaster
[07/29/2008|08:56] C:\Program Files\ Google
[09/27/2006|03:05] C:\Program Files\ Hewlett-Packard
[04/11/2008|05:13] C:\Program Files\ HP
[09/27/2006|02:42] C:\Program Files\ HP DigitalMedia Archive
[03/24/2008|02:50] C:\Program Files\ HP Games
[03/24/2008|01:42] C:\Program Files\ InstallShield Installation Information
[02/17/2007|08:18] C:\Program Files\ InterActual
[10/14/2008|10:29] C:\Program Files\ Internet Explorer
[04/07/2008|01:26] C:\Program Files\ iPod
[04/07/2008|01:26] C:\Program Files\ iTunes
[02/26/2008|06:42] C:\Program Files\ Java
[10/18/2008|02:44] C:\Program Files\ kvldqtb
[10/12/2008|08:24] C:\Program Files\ Lavasoft
[08/28/2007|03:39] C:\Program Files\ Learning Essentials
[09/05/2008|07:37] C:\Program Files\ Messenger
[08/25/2007|10:01] C:\Program Files\ Microsoft CAPICOM 2.1.0.2
[11/14/2005|03:06] C:\Program Files\ microsoft frontpage
[01/18/2007|03:18] C:\Program Files\ Microsoft Games
[09/05/2007|06:07] C:\Program Files\ Microsoft IntelliPoint
[09/27/2006|02:50] C:\Program Files\ Microsoft Money 2006
[09/07/2007|06:48] C:\Program Files\ Microsoft My Personal Tutor
[08/25/2007|06:49] C:\Program Files\ Microsoft Office
[10/08/2008|06:13] C:\Program Files\ Microsoft Silverlight
[08/28/2007|03:51] C:\Program Files\ Microsoft Student
[08/25/2007|08:27] C:\Program Files\ Microsoft Visual Studio
[08/25/2007|08:28] C:\Program Files\ Microsoft Works
[08/25/2007|06:49] C:\Program Files\ Microsoft.NET
[09/05/2008|07:28] C:\Program Files\ Movie Maker
[08/30/2008|02:08] C:\Program Files\ MSECache
[11/14/2005|03:07] C:\Program Files\ MSN
[09/27/2006|02:50] C:\Program Files\ MSN Encarta Standard
[11/14/2005|03:07] C:\Program Files\ MSN Gaming Zone
[12/03/2006|11:39] C:\Program Files\ MSXML 4.0
[08/29/2007|09:22] C:\Program Files\ MSXML 6.0
[09/27/2006|02:41] C:\Program Files\ music_now
[09/27/2006|02:53] C:\Program Files\ muvee Technologies
[03/17/2008|12:20] C:\Program Files\ Netflix
[09/05/2008|07:24] C:\Program Files\ NetMeeting
[09/27/2006|02:41] C:\Program Files\ Netscape
[03/04/2008|09:39] C:\Program Files\ Nikon
[05/26/2008|04:18] C:\Program Files\ Nobeltec
[10/12/2008|01:52] C:\Program Files\ Norton 360
[09/27/2006|03:07] C:\Program Files\ Online Services
[09/05/2008|07:42] C:\Program Files\ Outlook Express
[10/12/2008|08:02] C:\Program Files\ Panda Security
[12/05/2006|12:51] C:\Program Files\ PC-Doctor 5 for Windows
[09/27/2006|03:03] C:\Program Files\ PC-Doctor for DOS
[03/24/2008|02:04] C:\Program Files\ PCPitstop
[01/16/2007|02:00] C:\Program Files\ Pure Networks
[09/27/2006|02:54] C:\Program Files\ Quicken
[04/07/2008|01:23] C:\Program Files\ QuickTime
[10/17/2008|08:42] C:\Program Files\ QuickZip4
[09/27/2006|02:40] C:\Program Files\ Real
[10/18/2008|08:48] C:\Program Files\ Registry Mechanic
[10/02/2008|11:00] C:\Program Files\ RosettaStoneLtdServices
[03/24/2008|02:51] C:\Program Files\ Sonic
[10/11/2008|07:30] C:\Program Files\ SpeedFan
[10/12/2008|08:35] C:\Program Files\ Spybot - Search & Destroy
[01/18/2007|01:30] C:\Program Files\ Spyware Doctor
[10/12/2008|02:02] C:\Program Files\ Symantec
[01/18/2007|07:00] C:\Program Files\ Symantec Technical Support
[02/26/2007|04:09] C:\Program Files\ The Weather Channel FW
[04/27/2007|02:28] C:\Program Files\ THQ
[11/11/2005|12:56] C:\Program Files\ Uninstall Information
[09/27/2006|02:58] C:\Program Files\ Updates from HP
[02/26/2008|06:41] C:\Program Files\ Watchtower
[09/27/2006|02:43] C:\Program Files\ WildTangent
[10/13/2008|06:41] C:\Program Files\ Windows Media Components
[04/21/2007|11:14] C:\Program Files\ Windows Media Connect 2
[04/21/2007|11:14] C:\Program Files\ Windows Media Player
[09/05/2008|07:24] C:\Program Files\ Windows NT
[11/14/2005|03:08] C:\Program Files\ Windows Plus
[10/12/2008|12:50] C:\Program Files\ Windows Sidebar
[11/11/2005|12:56] C:\Program Files\ WindowsUpdate
[10/17/2008|08:58] C:\Program Files\ WinRAR
[10/17/2008|09:26] C:\Program Files\ WinZip
[11/14/2005|03:08] C:\Program Files\ xerox
[04/10/2008|05:03] C:\Program Files\ Yahoo!

——————–\\ Listing Folders in C:\Program Files\Common Files

[05/22/2008|05:26] C:\Program Files\Common Files\ Adobe
[12/16/2006|05:39] C:\Program Files\Common Files\ AOL
[08/16/2007|10:51] C:\Program Files\Common Files\ Apple
[03/05/2007|08:30] C:\Program Files\Common Files\ Cosmi
[08/25/2007|08:27] C:\Program Files\Common Files\ DESIGNER
[12/08/2006|07:30] C:\Program Files\Common Files\ Hewlett-Packard
[09/27/2006|02:36] C:\Program Files\Common Files\ HP
[09/27/2006|03:04] C:\Program Files\Common Files\ InstallShield
[09/27/2006|02:54] C:\Program Files\Common Files\ Intuit
[09/27/2006|02:17] C:\Program Files\Common Files\ Java
[01/09/2007|08:43] C:\Program Files\Common Files\ LightScribe
[09/27/2006|02:48] C:\Program Files\Common Files\ LS Getting Started
[03/19/2008|09:22] C:\Program Files\Common Files\ Microsoft Shared
[11/14/2005|03:06] C:\Program Files\Common Files\ MSSoap
[09/27/2006|02:53] C:\Program Files\Common Files\ muvee Technologies
[03/04/2008|09:39] C:\Program Files\Common Files\ Nikon
[11/14/2005|03:06] C:\Program Files\Common Files\ ODBC
[09/27/2006|02:54] C:\Program Files\Common Files\ Palo Alto Software
[02/26/2007|04:08] C:\Program Files\Common Files\ Pure Networks Shared
[09/27/2006|02:40] C:\Program Files\Common Files\ Real
[12/04/2006|04:04] C:\Program Files\Common Files\ Sandlot Shared
[11/14/2005|03:06] C:\Program Files\Common Files\ Services
[03/24/2008|02:50] C:\Program Files\Common Files\ Sonic Shared
[11/14/2005|03:06] C:\Program Files\Common Files\ SpeechEngines
[10/19/2008|06:17] C:\Program Files\Common Files\ Symantec Shared
[09/05/2008|07:42] C:\Program Files\Common Files\ System
[10/12/2008|08:23] C:\Program Files\Common Files\ Wise Installation Wizard
[09/27/2006|02:40] C:\Program Files\Common Files\ xing shared

——————–\\ Process

( 45 Processes )

IEXPLORE.EXE ~ [PID:3160]

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

No Lop folder found !

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-19 06:38:08
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections

——————–\\ Cracks & Keygens ..

C:\DOCUME~1\HP_ADM~1\My Documents\My Videos\Creativity Fun Packs\Sound Effects\sports\Baseball Bat Hit, Crack.wma


[F:8][D:3]-> C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp
[F:156][D:0]-> C:\DOCUME~1\HP_ADM~1\Cookies
[F:2255][D:16]-> C:\DOCUME~1\HP_ADM~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Sun 10/19/2008| 6:39 - Option : [1]

——————–\\ Scan completed at 6:39:16
Hello

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\wrgzevat
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI