This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Trojan problem, could be Vundo and others

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here is a Hijack This log from a Trojan-affected computer with Windows XP, I would love your suggestions, thank you. This trojan has slowed internet usage and given the computer pop-ups. I have run ATF cleaner, Malwarebytes, Spybot and Vundofix to no avail.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:17:54, on 16/11/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\System32\SVCHOST.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\System32\keyhook.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Apoint\Apntex.exe
C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Napster\napster.exe
c:\program files\mcafee.com\vso\mcmnhdlr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\WINDOWS\SYSTEM32\sistray.exe
C:\Program Files\ntl\broadband medic\bin\mpbtn.exe
c:\program files\internet explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\M2dQO118.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Tiscali 10.0
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {50c81acb-581c-451b-8260-47e72a5f7df8} - C:\WINDOWS\System32\namogizu.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [VirusScan] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [C:\WINDOWS\System32\kdctg.exe] C:\WINDOWS\system32\kdctg.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [mopedudupo] Rundll32.exe "C:\WINDOWS\System32\romarete.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [mopedudupo] Rundll32.exe "C:\WINDOWS\System32\romarete.dll",s (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil9e.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil9e.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O4 - Global Startup: broadband medic.lnk = C:\Program Files\ntl\broadband medic\bin\matcli.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\SYSTEM32\sistray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O15 - Trusted Zone: *.amaena.com (HKLM)
O15 - Trusted Zone: *.antimalwareguard.com (HKLM)
O15 - Trusted Zone: *.antispyexpert.com (HKLM)
O15 - Trusted Zone: *.avsystemcare.com (HKLM)
O15 - Trusted Zone: *.gomyhit.com (HKLM)
O15 - Trusted Zone: *.imageservr.com (HKLM)
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
O15 - Trusted Zone: *.onerateld.com (HKLM)
O15 - Trusted Zone: *.safetydownload.com (HKLM)
O15 - Trusted Zone: *.spyguardpro.com (HKLM)
O15 - Trusted Zone: *.storageguardsoft.com (HKLM)
O15 - Trusted Zone: *.trustedantivirus.com (HKLM)
O15 - Trusted Zone: *.virusremover2008.com (HKLM)
O15 - Trusted Zone: *.virusschlacht.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.1.2.76.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} (Quantum Streaming IE Player Class) - http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O20 - AppInit_DLLs: c:\windows\system32\gumeyesu.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

–
End of file - 9011 bytes
Hello

Please run the MGA Diagnostic Tool and post back the report it shall produce:
  • Download MGADiag to your desktop.
  • Double-click on MGADiag.exe to launch the program
  • Click "Continue"
  • Ensure that the "Windows" tab is selected (it should be by default).
  • Click the "Copy" button to copy the MGA Diagnostic Report to the Windows clipboard.
  • Paste the MGA Diagnostic Report back here in your next reply.
Thank you for helping me. Here is the validation info: Diagnostic Report (1.7.0110.1): —————————————– WGA Data–> Validation Status: Genuine Validation Code: 0 Online Validation Code: N/A Cached Validation Code: N/A Windows Product Key: *****-*****-GD6GR-K6DP3-4C8MT Windows Product Key Hash: s2kt66ZJWfV4nS1wFD5F9bxTSDw= Windows Product ID: 55277-OEM-2111907-00102 Windows Product ID Type: 2 Windows License Type: OEM SLP Windows OS version: 5.1.2600.2.00010300.1.0.hom ID: {E1BE0954-6B79-4350-963A-60128E2F8494}(1) Is Admin: Yes TestCab: 0x0 WGA Version: Registered, 1.3.272.0 Signed By: Microsoft Product Name: N/A Architecture: N/A Build lab: N/A TTS Error: N/A Validation Diagnostic: 025D1FF3-171-1 Resolution Status: N/A WgaER Data–> ThreatID(s): N/A Version: N/A WGA Notifications Data–> Cached Result: N/A, hr = 0x80070002 File Exists: No Version: N/A, hr = 0x80070002 WgaTray.exe Signed By: N/A, hr = 0x80070002 WgaLogon.dll Signed By: N/A, hr = 0x80070002 OGA Notifications Data–> Cached Result: N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 WGATray.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: N/A, hr = 0x80070002 OGA Data–> Office Status: 109 N/A OGA Version: N/A, 0x80070002 Signed By: N/A, hr = 0x80070002 Office Diagnostics: B4D0AA8B-648-80070002_025D1FF3-171-1_FA827CE6-153-8007007e_FA827CE6-180-8007007e Browser Data–> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32) Default Browser: C:\Program Files\Internet Explorer\iexplore.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Active scripting: Script ActiveX controls marked as safe for scripting: File Scan Data–> File Mismatch: C:\WINDOWS\system32\oembios.bin
File Mismatch: C:\WINDOWS\system32\oembios.dat
File Mismatch: C:\WINDOWS\system32\oembios.sig
Other data–> Office Details: {E1BE0954-6B79-4350-963A-60128E2F8494}1.7.0110.15.1.2600.2.00010300.1.0.homx32*****-*****-*****-*****-4C8MT55277-OEM-2111907-001022S-1-5-21-1903616263-3074701166-2194597432Dell Computer Corp.Inspiron 1000Dell Computer Corp.A05 (Q3B01)20041008******.******+***Dell QuantaC6C93C07018400C208090409GMT Standard Time(GMT+00:00)02Dell Computer CorporationDell INSPIRON I1000 109 Licensing Data–> N/A HWID Data–> N/A OEM Activation 1.0 Data–> BIOS string matches: yes Marker string from BIOS: 1E832:Dell Inc|15140:Dell Inc|15140:Microsoft Corporation|A7C5:Semp Toshiba Informatica Ltda|A7C5:TOSHIBA CORPORATION Marker string from OEMBIOS.DAT: Dell Quanta OEM Activation 2.0 Data–> N/A
Hello

Disable resident protections (Antivirus…); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
I 'm not sure how to disable protections. This is the log:


——————–\\ Lop S&D 4.2.4-9c XP/Vista

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 1
X86-based PC ( Uniprocessor Free : Mobile Intel® Celeron® CPU 2.20GHz )
BIOS : PhoenixBIOS 4.0 Release 6.0
USER:
BOOT : Normal boot
C:\ (Local Disk) - NTFS - Total:27 Go (Free:19 Go)
D:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 01-11-2008|16:30 )
Option : [1] ( 19/11/2008|13:04 )

——————–\\ Listing folders in APPLIC~1

[18/11/2005|16:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[14/07/2004|12:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
[14/07/2004|12:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[11/08/2008|18:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[14/07/2004|12:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com
[08/11/2005|12:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[26/10/2006|20:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Move Networks
[03/10/2007|10:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Napster
[16/11/2008|21:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Office Genuine Advantage
[27/11/2004|04:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[14/07/2004|12:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[11/11/2008|00:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[21/10/2005|23:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
[08/11/2007|09:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
[21/10/2005|22:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[18/11/2005|17:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion

[14/07/2004|12:38] C:\DOCUME~1\DEFAUL~1\APPLIC~1\AOL
[14/07/2004|11:38] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[14/07/2004|12:31] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Jasc Software Inc
[14/07/2004|12:26] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[14/07/2004|12:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Sonic
[14/07/2004|12:22] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Sun
[14/07/2004|12:35] C:\DOCUME~1\DEFAUL~1\APPLIC~1\You've Got Pictures Screensaver

[01/10/2008|15:57] C:\DOCUME~1\JOHNGO~1\APPLIC~1\Adobe
[14/07/2004|12:38] C:\DOCUME~1\JOHNGO~1\APPLIC~1\AOL
[26/11/2004|20:35] C:\DOCUME~1\JOHNGO~1\APPLIC~1\CyberLink
[14/07/2004|11:38] C:\DOCUME~1\JOHNGO~1\APPLIC~1\Identities
[14/07/2004|12:31] C:\DOCUME~1\JOHNGO~1\APPLIC~1\Jasc Software Inc
[26/11/2004|20:32] C:\DOCUME~1\JOHNGO~1\APPLIC~1\Leadertech
[30/01/2005|17:56] C:\DOCUME~1\JOHNGO~1\APPLIC~1\Macromedia
[11/11/2008|09:33] C:\DOCUME~1\JOHNGO~1\APPLIC~1\Microsoft
[30/01/2005|19:16] C:\DOCUME~1\JOHNGO~1\APPLIC~1\Motive
[03/05/2005|21:49] C:\DOCUME~1\JOHNGO~1\APPLIC~1\Mozilla
[01/11/2006|08:36] C:\DOCUME~1\JOHNGO~1\APPLIC~1\Sierra
[26/11/2004|20:33] C:\DOCUME~1\JOHNGO~1\APPLIC~1\Sonic
[14/07/2004|12:22] C:\DOCUME~1\JOHNGO~1\APPLIC~1\Sun
[14/07/2004|12:35] C:\DOCUME~1\JOHNGO~1\APPLIC~1\You've Got Pictures Screensaver

[11/11/2008|09:33] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[22/12/2007|11:59] C:\DOCUME~1\MARYGO~1\APPLIC~1\Adobe
[18/11/2005|16:54] C:\DOCUME~1\MARYGO~1\APPLIC~1\AdobeUM
[14/07/2004|12:38] C:\DOCUME~1\MARYGO~1\APPLIC~1\AOL
[18/03/2005|13:55] C:\DOCUME~1\MARYGO~1\APPLIC~1\CyberLink
[14/07/2004|11:38] C:\DOCUME~1\MARYGO~1\APPLIC~1\Identities
[15/11/2008|21:41] C:\DOCUME~1\MARYGO~1\APPLIC~1\IUpd721
[14/07/2004|12:31] C:\DOCUME~1\MARYGO~1\APPLIC~1\Jasc Software Inc
[25/12/2005|16:33] C:\DOCUME~1\MARYGO~1\APPLIC~1\Leadertech
[01/02/2005|12:20] C:\DOCUME~1\MARYGO~1\APPLIC~1\Macromedia
[11/08/2008|18:33] C:\DOCUME~1\MARYGO~1\APPLIC~1\Malwarebytes
[11/11/2008|09:33] C:\DOCUME~1\MARYGO~1\APPLIC~1\Microsoft
[01/02/2005|20:48] C:\DOCUME~1\MARYGO~1\APPLIC~1\Motive
[16/03/2005|13:06] C:\DOCUME~1\MARYGO~1\APPLIC~1\Mozilla
[24/01/2006|20:29] C:\DOCUME~1\MARYGO~1\APPLIC~1\My Games
[03/10/2007|15:21] C:\DOCUME~1\MARYGO~1\APPLIC~1\Roxio
[25/12/2005|16:34] C:\DOCUME~1\MARYGO~1\APPLIC~1\Sonic
[14/07/2004|12:22] C:\DOCUME~1\MARYGO~1\APPLIC~1\Sun
[10/09/2005|18:26] C:\DOCUME~1\MARYGO~1\APPLIC~1\Template
[08/11/2007|09:28] C:\DOCUME~1\MARYGO~1\APPLIC~1\Viewpoint
[14/07/2004|12:35] C:\DOCUME~1\MARYGO~1\APPLIC~1\You've Got Pictures Screensaver

[11/11/2008|09:33] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[19/11/2008 09:00][–a——] C:\WINDOWS\tasks\hdxmudhd.job
[16/11/2008 07:12][–a——] C:\WINDOWS\tasks\At48.job
[10/11/2008 22:00][–a——] C:\WINDOWS\tasks\At47.job
[15/11/2008 21:30][–a——] C:\WINDOWS\tasks\At46.job
[14/11/2008 20:00][–a——] C:\WINDOWS\tasks\At45.job
[14/11/2008 19:00][–a——] C:\WINDOWS\tasks\At44.job
[16/11/2008 18:00][–a——] C:\WINDOWS\tasks\At43.job
[15/11/2008 17:00][–a——] C:\WINDOWS\tasks\At42.job
[16/11/2008 16:00][–a——] C:\WINDOWS\tasks\At41.job
[16/11/2008 15:00][–a——] C:\WINDOWS\tasks\At40.job
[16/11/2008 14:00][–a——] C:\WINDOWS\tasks\At39.job
[16/11/2008 13:00][–a——] C:\WINDOWS\tasks\At38.job
[14/11/2008 12:00][–a——] C:\WINDOWS\tasks\At37.job
[16/11/2008 11:03][–a——] C:\WINDOWS\tasks\At36.job
[16/11/2008 10:00][–a——] C:\WINDOWS\tasks\At35.job
[18/11/2008 08:10][–a——] C:\WINDOWS\tasks\At33.job
[19/11/2008 13:04][–a——] C:\WINDOWS\tasks\At34.job
[04/11/2008 07:00][–a——] C:\WINDOWS\tasks\At32.job
[13/10/2008 07:53][–a——] C:\WINDOWS\tasks\At31.job
[13/10/2008 07:53][–a——] C:\WINDOWS\tasks\At30.job
[13/10/2008 07:53][–a——] C:\WINDOWS\tasks\At29.job
[13/10/2008 07:53][–a——] C:\WINDOWS\tasks\At28.job
[13/10/2008 07:53][–a——] C:\WINDOWS\tasks\At27.job
[13/10/2008 07:53][–a——] C:\WINDOWS\tasks\At26.job
[11/11/2008 00:09][–a——] C:\WINDOWS\tasks\At25.job
[15/11/2008 23:00][–a——] C:\WINDOWS\tasks\At24.job
[10/11/2008 22:00][–a——] C:\WINDOWS\tasks\At23.job
[15/11/2008 21:00][–a——] C:\WINDOWS\tasks\At22.job
[14/11/2008 20:00][–a——] C:\WINDOWS\tasks\At21.job
[14/11/2008 19:00][–a——] C:\WINDOWS\tasks\At20.job
[16/11/2008 18:00][–a——] C:\WINDOWS\tasks\At19.job
[15/11/2008 17:00][–a——] C:\WINDOWS\tasks\At18.job
[16/11/2008 16:00][–a——] C:\WINDOWS\tasks\At17.job
[16/11/2008 15:00][–a——] C:\WINDOWS\tasks\At16.job
[16/11/2008 14:00][–a——] C:\WINDOWS\tasks\At15.job
[16/11/2008 13:00][–a——] C:\WINDOWS\tasks\At14.job
[14/11/2008 12:00][–a——] C:\WINDOWS\tasks\At13.job
[16/11/2008 11:00][–a——] C:\WINDOWS\tasks\At12.job
[16/11/2008 10:00][–a——] C:\WINDOWS\tasks\At11.job
[19/11/2008 09:00][–a——] C:\WINDOWS\tasks\At10.job
[17/11/2008 08:00][–a——] C:\WINDOWS\tasks\At9.job
[04/11/2008 07:00][–a——] C:\WINDOWS\tasks\At8.job
[13/10/2008 07:42][–a——] C:\WINDOWS\tasks\At7.job
[13/10/2008 07:42][–a——] C:\WINDOWS\tasks\At6.job
[13/10/2008 07:42][–a——] C:\WINDOWS\tasks\At5.job
[13/10/2008 07:42][–a——] C:\WINDOWS\tasks\At4.job
[13/10/2008 07:42][–a——] C:\WINDOWS\tasks\At3.job
[13/10/2008 07:42][–a——] C:\WINDOWS\tasks\At2.job
[11/11/2008 00:06][–a——] C:\WINDOWS\tasks\At1.job
[19/11/2008 08:10][–ah—–] C:\WINDOWS\tasks\SA.DAT
[29/08/2002 04:00][-r-h—–] C:\WINDOWS\tasks\DESKTOP.INI

——————–\\ Listing Folders in C:\Program Files

[18/11/2005|16:50] C:\Program Files\Adobe
[14/07/2004|12:35] C:\Program Files\AOL 9.0
[14/07/2004|12:35] C:\Program Files\AOL Companion
[14/07/2004|12:03] C:\Program Files\Apoint
[20/06/2008|12:38] C:\Program Files\BetTrader PRO
[30/01/2005|23:25] C:\Program Files\BroadJump
[14/07/2004|12:30] C:\Program Files\BTOW
[03/10/2007|10:45] C:\Program Files\Common Files
[14/07/2004|11:38] C:\Program Files\ComPlus Applications
[14/07/2004|12:29] C:\Program Files\CyberLink
[14/07/2004|12:28] C:\Program Files\Dell
[14/07/2004|12:31] C:\Program Files\Dell Computer
[04/01/2006|00:59] C:\Program Files\Firaxis Games
[01/01/2006|10:09] C:\Program Files\IGN
[19/12/2007|13:33] C:\Program Files\InstallShield Installation Information
[14/07/2004|12:29] C:\Program Files\Internet
[27/11/2007|20:33] C:\Program Files\Internet Explorer
[14/07/2004|12:32] C:\Program Files\Jasc Software Inc
[14/07/2004|12:22] C:\Program Files\Java
[14/07/2004|12:35] C:\Program Files\Learn2.com
[10/11/2008|11:30] C:\Program Files\Malwarebytes' Anti-Malware
[14/07/2004|12:32] C:\Program Files\McAfee.com
[14/07/2004|11:38] C:\Program Files\Messenger
[14/07/2004|11:38] C:\Program Files\microsoft frontpage
[14/07/2004|12:29] C:\Program Files\Microsoft Works
[14/07/2004|12:27] C:\Program Files\Modem Helper
[30/01/2005|17:40] C:\Program Files\Motive
[14/07/2004|11:38] C:\Program Files\Movie Maker
[12/10/2005|12:42] C:\Program Files\Mozilla Firefox
[14/07/2004|11:38] C:\Program Files\MSN
[14/07/2004|11:38] C:\Program Files\MSN Gaming Zone
[05/11/2008|10:16] C:\Program Files\Napster
[14/07/2004|11:38] C:\Program Files\NetMeeting
[30/01/2005|17:40] C:\Program Files\ntl
[14/07/2004|11:38] C:\Program Files\Online Services
[14/07/2004|11:38] C:\Program Files\Outlook Express
[14/07/2004|12:35] C:\Program Files\QuickTime
[14/07/2004|12:34] C:\Program Files\Real
[19/12/2007|13:29] C:\Program Files\Shockwave.com
[14/07/2004|12:26] C:\Program Files\SiS VGA Utilities V3.59b
[14/07/2004|12:03] C:\Program Files\SiSLan
[14/07/2004|12:27] C:\Program Files\Sonic
[10/11/2008|22:25] C:\Program Files\Spybot - Search & Destroy
[16/11/2008|17:17] C:\Program Files\Trend Micro
[14/07/2004|11:38] C:\Program Files\Uninstall Information
[25/10/2005|12:38] C:\Program Files\ValuSoft
[14/07/2004|12:35] C:\Program Files\Viewpoint
[08/11/2005|12:33] C:\Program Files\Windows Media Player
[14/07/2004|11:38] C:\Program Files\Windows NT
[13/11/2008|18:06] C:\Program Files\WindowsUpdate
[14/07/2004|11:38] C:\Program Files\XEROX
[08/11/2005|12:43] C:\Program Files\XviD
[18/11/2005|16:49] C:\Program Files\Yahoo!
[25/10/2005|12:39] C:\Program Files\Zone Labs

——————–\\ Listing Folders in C:\Program Files\Common Files

[18/11/2005|16:52] C:\Program Files\Common Files\Adobe
[14/07/2004|12:35] C:\Program Files\Common Files\AOL
[14/07/2004|12:35] C:\Program Files\Common Files\aolshare
[14/07/2004|12:26] C:\Program Files\Common Files\InstallShield
[14/07/2004|12:21] C:\Program Files\Common Files\Java
[04/01/2006|01:02] C:\Program Files\Common Files\Microsoft Shared
[30/01/2005|17:41] C:\Program Files\Common Files\Motive
[14/07/2004|11:38] C:\Program Files\Common Files\MSSoap
[03/10/2007|10:45] C:\Program Files\Common Files\Napster Shared
[25/08/2005|22:21] C:\Program Files\Common Files\NSV
[14/07/2004|12:34] C:\Program Files\Common Files\Nullsoft
[14/07/2004|11:38] C:\Program Files\Common Files\ODBC
[14/07/2004|12:34] C:\Program Files\Common Files\Real
[14/07/2004|11:38] C:\Program Files\Common Files\Services
[14/07/2004|12:27] C:\Program Files\Common Files\Sonic
[14/07/2004|11:38] C:\Program Files\Common Files\SpeechEngines
[14/07/2004|11:38] C:\Program Files\Common Files\System

——————–\\ Process

( 45 Processes )

iexplore.exe ~ [PID:720]
iexplore.exe ~ [PID:3580]

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

No Lop folder found !

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-19 13:05:24
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections

C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At10.job
C:\WINDOWS\Tasks\At11.job
C:\WINDOWS\Tasks\At12.job
C:\WINDOWS\Tasks\At13.job
C:\WINDOWS\Tasks\At14.job
C:\WINDOWS\Tasks\At15.job
C:\WINDOWS\Tasks\At16.job
C:\WINDOWS\Tasks\At17.job
C:\WINDOWS\Tasks\At18.job
C:\WINDOWS\Tasks\At19.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At20.job
C:\WINDOWS\Tasks\At21.job
C:\WINDOWS\Tasks\At22.job
C:\WINDOWS\Tasks\At23.job
C:\WINDOWS\Tasks\At24.job
C:\WINDOWS\Tasks\At25.job
C:\WINDOWS\Tasks\At26.job
C:\WINDOWS\Tasks\At27.job
C:\WINDOWS\Tasks\At28.job
C:\WINDOWS\Tasks\At29.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At30.job
C:\WINDOWS\Tasks\At31.job
C:\WINDOWS\Tasks\At32.job
C:\WINDOWS\Tasks\At33.job
C:\WINDOWS\Tasks\At34.job
C:\WINDOWS\Tasks\At35.job
C:\WINDOWS\Tasks\At36.job
C:\WINDOWS\Tasks\At37.job
C:\WINDOWS\Tasks\At38.job
C:\WINDOWS\Tasks\At39.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At40.job
C:\WINDOWS\Tasks\At41.job
C:\WINDOWS\Tasks\At42.job
C:\WINDOWS\Tasks\At43.job
C:\WINDOWS\Tasks\At44.job
C:\WINDOWS\Tasks\At45.job
C:\WINDOWS\Tasks\At46.job
C:\WINDOWS\Tasks\At47.job
C:\WINDOWS\Tasks\At48.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
C:\WINDOWS\Tasks\At7.job
C:\WINDOWS\Tasks\At8.job
C:\WINDOWS\Tasks\At9.job



[F:9866][D:2999]-> C:\DOCUME~1\MARYGO~1\LOCALS~1\Temp
[F:20][D:0]-> C:\DOCUME~1\MARYGO~1\Cookies
[F:458][D:4]-> C:\DOCUME~1\MARYGO~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 19/11/2008|13:09 - Option : [1]

——————–\\ Scan completed at 13:09:46
Why haven't you updated to SP2 ?

Please download the OTMoveIt3 by OldTimer or from here.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\WINDOWS\tasks\At*.job
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
This is the initial results, I need to reboot my machine but I'm posting this in case I lose this info when the computer reboots. ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== C:\WINDOWS\tasks\At1.job moved successfully. C:\WINDOWS\tasks\At10.job moved successfully. C:\WINDOWS\tasks\At11.job moved successfully. C:\WINDOWS\tasks\At12.job moved successfully. C:\WINDOWS\tasks\At13.job moved successfully. C:\WINDOWS\tasks\At14.job moved successfully. C:\WINDOWS\tasks\At15.job moved successfully. C:\WINDOWS\tasks\At16.job moved successfully. C:\WINDOWS\tasks\At17.job moved successfully. C:\WINDOWS\tasks\At18.job moved successfully. C:\WINDOWS\tasks\At19.job moved successfully. C:\WINDOWS\tasks\At2.job moved successfully. C:\WINDOWS\tasks\At20.job moved successfully. C:\WINDOWS\tasks\At21.job moved successfully. C:\WINDOWS\tasks\At22.job moved successfully. C:\WINDOWS\tasks\At23.job moved successfully. C:\WINDOWS\tasks\At24.job moved successfully. C:\WINDOWS\tasks\At25.job moved successfully. C:\WINDOWS\tasks\At26.job moved successfully. C:\WINDOWS\tasks\At27.job moved successfully. C:\WINDOWS\tasks\At28.job moved successfully. C:\WINDOWS\tasks\At29.job moved successfully. C:\WINDOWS\tasks\At3.job moved successfully. C:\WINDOWS\tasks\At30.job moved successfully. C:\WINDOWS\tasks\At31.job moved successfully. C:\WINDOWS\tasks\At32.job moved successfully. C:\WINDOWS\tasks\At33.job moved successfully. C:\WINDOWS\tasks\At34.job moved successfully. C:\WINDOWS\tasks\At35.job moved successfully. C:\WINDOWS\tasks\At36.job moved successfully. C:\WINDOWS\tasks\At37.job moved successfully. C:\WINDOWS\tasks\At38.job moved successfully. C:\WINDOWS\tasks\At39.job moved successfully. C:\WINDOWS\tasks\At4.job moved successfully. C:\WINDOWS\tasks\At40.job moved successfully. C:\WINDOWS\tasks\At41.job moved successfully. C:\WINDOWS\tasks\At42.job moved successfully. C:\WINDOWS\tasks\At43.job moved successfully. C:\WINDOWS\tasks\At44.job moved successfully. C:\WINDOWS\tasks\At45.job moved successfully. C:\WINDOWS\tasks\At46.job moved successfully. C:\WINDOWS\tasks\At47.job moved successfully. C:\WINDOWS\tasks\At48.job moved successfully. C:\WINDOWS\tasks\At5.job moved successfully. C:\WINDOWS\tasks\At6.job moved successfully. C:\WINDOWS\tasks\At7.job moved successfully. C:\WINDOWS\tasks\At8.job moved successfully. C:\WINDOWS\tasks\At9.job moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\MARYGO~1\LOCALS~1\Temp\~DFC0C0.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 11192008_134250
Having rebooted the computer, it adds to the log- Files moved on Reboot… C:\DOCUME~1\MARYGO~1\LOCALS~1\Temp\~DFC0C0.tmp moved successfully. File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
No I was just curious

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
Logfile of random's system information tool 1.04 (written by random/random)

Microsoft Windows XP Home Edition Service Pack 1
System drive C: has 20 GB (71%) free of 29 GB
Total RAM: 221 MB (34% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:47:44, on 19/11/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\SVCHOST.EXE
C:\WINDOWS\notepad.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\System32\keyhook.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Apoint\Apntex.exe
C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\WINDOWS\SYSTEM32\sistray.exe
C:\Program Files\ntl\broadband medic\bin\mpbtn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Mary Gordon\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Mary Gordon.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Tiscali 10.0
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {50c81acb-581c-451b-8260-47e72a5f7df8} - C:\WINDOWS\System32\namogizu.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [VirusScan] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [C:\WINDOWS\System32\kdctg.exe] C:\WINDOWS\system32\kdctg.exe
O4 - HKLM\..\Run: [mopedudupo] Rundll32.exe "C:\WINDOWS\System32\romarete.dll",s
O4 - HKLM\..\Run: [obwcurlyidmvn] C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\System32\dtfcujmvzetrbzejn.dll"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [mopedudupo] Rundll32.exe "C:\WINDOWS\System32\romarete.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [mopedudupo] Rundll32.exe "C:\WINDOWS\System32\romarete.dll",s (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil9e.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil9e.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O4 - Global Startup: broadband medic.lnk = C:\Program Files\ntl\broadband medic\bin\matcli.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\SYSTEM32\sistray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O15 - Trusted Zone: *.amaena.com (HKLM)
O15 - Trusted Zone: *.antimalwareguard.com (HKLM)
O15 - Trusted Zone: *.antispyexpert.com (HKLM)
O15 - Trusted Zone: *.avsystemcare.com (HKLM)
O15 - Trusted Zone: *.gomyhit.com (HKLM)
O15 - Trusted Zone: *.imageservr.com (HKLM)
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
O15 - Trusted Zone: *.onerateld.com (HKLM)
O15 - Trusted Zone: *.safetydownload.com (HKLM)
O15 - Trusted Zone: *.spyguardpro.com (HKLM)
O15 - Trusted Zone: *.storageguardsoft.com (HKLM)
O15 - Trusted Zone: *.trustedantivirus.com (HKLM)
O15 - Trusted Zone: *.virusremover2008.com (HKLM)
O15 - Trusted Zone: *.virusschlacht.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.1.2.76.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} (Quantum Streaming IE Player Class) - http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O20 - AppInit_DLLs: c:\windows\system32\gumeyesu.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - (no file)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

–
End of file - 9182 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\hdxmudhd.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2005-09-23 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50c81acb-581c-451b-8260-47e72a5f7df8}]
C:\WINDOWS\System32\namogizu.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2008-09-15 1562960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}]
DriveLetterAccess - C:\WINDOWS\system32\dla\tfswshx.dll [2004-03-15 118836]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BA52B914-B692-46c4-B683-905236F6F655} - McAfee VirusScan - c:\progra~1\mcafee.com\vso\mcvsshl.dll [2003-08-18 114743]
{8E718888-423F-11D2-876E-00A0C9082467} - &Radio - C:\WINDOWS\System32\msdxm.ocx [2002-08-29 842268]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2005-08-04 343112]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AGRSMMSG"=C:\WINDOWS\AGRSMMSG.exe [2003-11-19 88363]
"Apoint"=C:\Program Files\Apoint\Apoint.exe [2004-02-02 155648]
"SunJavaUpdateSched"=C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe [2003-11-19 32881]
"SiS Windows KeyHook"=C:\WINDOWS\System32\keyhook.exe [2004-05-12 249856]
"dla"=C:\WINDOWS\system32\dla\tfswctrl.exe [2004-03-15 122933]
"UpdateManager"=C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe [2003-08-19 110592]
"PCMService"=C:\Program Files\Dell\Media Experience\PCMService.exe [2004-04-11 290816]
"DVDLauncher"=C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe [2004-04-11 53248]
"VSOCheckTask"=c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe [2003-08-08 122880]
"MCAgentExe"=c:\PROGRA~1\mcafee.com\agent\mcagent.exe [2005-09-22 303104]
"MCUpdateExe"=C:\PROGRA~1\mcafee.com\agent\mcupdate.exe [2006-01-11 212992]
"AOLDialer"=C:\Program Files\Common Files\AOL\ACS\AOLDial.exe [2004-02-25 496752]
"RealTray"=C:\Program Files\Real\RealPlayer\RealPlay.exe [2004-07-14 26112]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2004-07-14 98304]
"AOL Spyware Protection"=C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe [2004-02-16 147456]
"VirusScan"=c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe [2003-08-17 163840]
"BJCFD"=C:\Program Files\BroadJump\Client Foundation\CFD.exe [2002-09-10 368706]
"Motive SmartBridge"=C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe [2003-12-30 380928]
"NapsterShell"=C:\Program Files\Napster\napster.exe [2007-01-12 323216]
"C:\WINDOWS\System32\kdctg.exe"=C:\WINDOWS\system32\kdctg.exe []
"mopedudupo"=C:\WINDOWS\System32\romarete.dll []
"obwcurlyidmvn"=C:\WINDOWS\System32\regsvr32.exe [2002-08-29 9728]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2002-08-20 1511453]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2008-09-16 1833296]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
AOL 9.0 Tray Icon.lnk - C:\Program Files\AOL 9.0\aoltray.exe
broadband medic.lnk - C:\Program Files\ntl\broadband medic\bin\matcli.exe
Utility Tray.lnk - C:\WINDOWS\SYSTEM32\sistray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"=" c:\windows\system32\gumeyesu.dll "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"NoDispScrSavPage"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.reg - open - regedit.exe "%1" %*
.scr - open - "%1" %*

======List of files/folders created in the last 1 months======

2008-11-19 14:47:35 —-D—- C:\rsit
2008-11-19 13:42:50 —-D—- C:\_OTMoveIt
2008-11-19 13:04:34 —-A—- C:\lopR.txt
2008-11-19 13:03:18 —-D—- C:\Lop SD
2008-11-16 21:02:34 —-D—- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-11-16 17:26:28 —-A—- C:\WINDOWS\System32\M2dQO118.exe.a_a
2008-11-16 17:17:09 —-D—- C:\Program Files\Trend Micro
2008-11-16 10:23:15 —-A—- C:\WINDOWS\System32\el32.dll
2008-11-15 21:41:02 —-D—- C:\Documents and Settings\Mary Gordon\Application Data\IUpd721
2008-11-15 21:40:54 —-A—- C:\WINDOWS\System32\g86.exe
2008-11-15 21:26:14 —-A—- C:\WINDOWS\System32\tdapberp.dll
2008-11-15 21:25:40 —-A—- C:\WINDOWS\System32\33dc5de2-.txt
2008-11-15 21:19:59 —-SHD—- C:\WINDOWS\TWFyeSBHb3Jkb24
2008-11-15 21:19:34 —-A—- C:\WINDOWS\System32\kptdonsksnlnryam.exe
2008-11-15 21:19:16 —-D—- C:\WINDOWS\System32\nas
2008-11-15 21:19:16 —-D—- C:\WINDOWS\System32\ITX
2008-11-15 21:19:16 —-D—- C:\WINDOWS\System32\ex
2008-11-15 21:19:16 —-D—- C:\WINDOWS\System32\cs2
2008-11-15 21:18:59 —-D—- C:\WINDOWS\System32\sX3i19
2008-11-15 21:18:55 —-A—- C:\WINDOWS\System32\prun.exe
2008-11-14 16:35:42 —-D—- C:\VundoFix Backups
2008-11-14 16:35:42 —-A—- C:\VundoFix.txt
2008-11-14 07:57:54 —-D—- C:\WINDOWS\System32\bits
2008-11-14 07:57:40 —-HDC—- C:\WINDOWS\$NtUninstallKB842773$
2008-11-14 07:56:46 —-HDC—- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2008-11-14 07:55:53 —-D—- C:\WINDOWS\System32\PreInstall
2008-11-14 07:55:40 —-A—- C:\WINDOWS\System32\spupdsvc.exe
2008-11-14 07:55:38 —-HDC—- C:\WINDOWS\$NtUninstallKB898461$
2008-11-14 07:55:38 —-HD—- C:\WINDOWS\$hf_mig$
2008-11-14 07:54:02 —-SH—- C:\WINDOWS\System32\sarisamo.exe
2008-11-13 18:25:57 —-N—- C:\WINDOWS\System32\xpob2res.dll
2008-11-13 18:25:57 —-N—- C:\WINDOWS\System32\bitsprx3.dll
2008-11-13 18:25:57 —-N—- C:\WINDOWS\System32\bitsprx2.dll
2008-11-13 18:25:57 —-A—- C:\WINDOWS\System32\winhttp.dll
2008-11-13 18:25:57 —-A—- C:\WINDOWS\System32\qmgrprxy.dll
2008-11-13 18:11:02 —-D—- C:\WINDOWS\System32\SoftwareDistribution
2008-11-13 18:06:23 —-D—- C:\WINDOWS\SoftwareDistribution
2008-11-13 18:04:54 —-A—- C:\WINDOWS\System32\wuweb.dll
2008-11-13 18:04:54 —-A—- C:\WINDOWS\System32\wucltui.dll
2008-11-13 18:04:54 —-A—- C:\WINDOWS\System32\wuaueng1.dll
2008-11-13 18:04:53 —-A—- C:\WINDOWS\System32\wups.dll
2008-11-13 18:04:53 —-A—- C:\WINDOWS\System32\wuauclt1.exe
2008-11-13 18:04:53 —-A—- C:\WINDOWS\System32\wuapi.dll
2008-11-13 10:26:14 —-A—- C:\WINDOWS\ntbtlog.txt
2008-11-13 07:43:33 —-SH—- C:\WINDOWS\System32\bowagina.exe
2008-11-12 15:50:58 —-D—- C:\WINDOWS\System32\QI19
2008-11-12 07:35:22 —-SH—- C:\WINDOWS\System32\vezipoyo.exe
2008-11-10 21:37:14 —-SH—- C:\WINDOWS\System32\buvurosi.exe
2008-11-10 20:35:25 —-D—- C:\Program Files\Spybot - Search & Destroy
2008-11-10 20:35:25 —-D—- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-10 07:18:16 —-SH—- C:\WINDOWS\System32\ririzaki.exe
2008-11-09 20:25:36 —-A—- C:\WINDOWS\IE4 Error Log.txt
2008-10-28 16:46:50 —-A—- C:\WINDOWS\System32\korwbrkr.dll
2008-10-28 16:46:50 —-A—- C:\WINDOWS\System32\chtbrkr.dll
2008-10-28 16:46:50 —-A—- C:\WINDOWS\System32\chsbrkr.dll
2008-10-28 16:46:49 —-A—- C:\WINDOWS\System32\msir3jp.dll
2008-10-28 16:46:10 —-A—- C:\WINDOWS\System32\c_g18030.dll
2008-10-28 16:46:08 —-A—- C:\WINDOWS\System32\kbd101a.dll
2008-10-28 16:45:50 —-A—- C:\WINDOWS\System32\kbdlk41j.dll
2008-10-28 16:45:50 —-A—- C:\WINDOWS\System32\kbdlk41a.dll
2008-10-28 16:45:49 —-A—- C:\WINDOWS\System32\kbdnecNT.dll
2008-10-28 16:45:49 —-A—- C:\WINDOWS\System32\kbdnecAT.dll
2008-10-28 16:45:49 —-A—- C:\WINDOWS\System32\kbdnec95.dll
2008-10-28 16:45:49 —-A—- C:\WINDOWS\System32\f3ahvoas.dll
2008-10-28 16:45:48 —-A—- C:\WINDOWS\System32\kbdibm02.dll
2008-10-28 16:45:48 —-A—- C:\WINDOWS\System32\kbdax2.dll
2008-10-28 16:45:48 —-A—- C:\WINDOWS\System32\kbd106n.dll
2008-10-28 16:45:48 —-A—- C:\WINDOWS\System32\kbd101.dll
2008-10-28 16:45:14 —-A—- C:\WINDOWS\System32\c_is2022.dll
2008-10-28 16:45:11 —-A—- C:\WINDOWS\System32\uniime.dll
2008-10-28 16:44:54 —-A—- C:\WINDOWS\System32\imjp81k.dll
2008-10-28 16:44:46 —-A—- C:\WINDOWS\System32\kbdkor.dll
2008-10-28 16:44:45 —-A—- C:\WINDOWS\System32\kbdjpn.dll
2008-10-28 16:44:45 —-A—- C:\WINDOWS\System32\kbd106.dll
2008-10-28 16:44:45 —-A—- C:\WINDOWS\System32\kbd103.dll
2008-10-28 16:44:45 —-A—- C:\WINDOWS\System32\kbd101c.dll
2008-10-28 16:44:44 —-A—- C:\WINDOWS\System32\kbd101b.dll

======List of files/folders modified in the last 1 months======

2008-11-19 14:47:44 —-D—- C:\WINDOWS\Prefetch
2008-11-19 13:55:49 —-D—- C:\WINDOWS\Temp
2008-11-19 13:54:47 —-D—- C:\WINDOWS\Debug
2008-11-19 13:53:59 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-11-19 13:42:52 —-SD—- C:\WINDOWS\Tasks
2008-11-17 08:00:01 —-D—- C:\WINDOWS\SYSTEM32
2008-11-16 21:02:36 —-D—- C:\WINDOWS\System32\CatRoot2
2008-11-16 17:26:24 —-A—- C:\WINDOWS\System32\M2dQO118.exe
2008-11-16 17:17:09 —-RD—- C:\Program Files
2008-11-16 17:13:21 —-D—- C:\WINDOWS\System32\DRIVERS
2008-11-16 17:13:21 —-D—- C:\WINDOWS
2008-11-16 09:22:47 —-D—- C:\temp
2008-11-14 08:57:27 —-HD—- C:\WINDOWS\INF
2008-11-14 07:57:58 —-RSHD—- C:\WINDOWS\System32\DLLCACHE
2008-11-14 07:57:28 —-A—- C:\WINDOWS\imsins.BAK
2008-11-13 18:11:55 —-D—- C:\WINDOWS\Help
2008-11-13 18:06:10 —-HD—- C:\Program Files\WindowsUpdate
2008-11-13 10:50:04 —-SD—- C:\WINDOWS\Downloaded Program Files
2008-11-11 13:13:26 —-A—- C:\WINDOWS\wininit.ini
2008-11-11 09:33:51 —-SD—- C:\Documents and Settings\Mary Gordon\Application Data\Microsoft
2008-11-10 11:30:03 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-11-05 10:16:57 —-D—- C:\Program Files\Napster
2008-10-28 16:46:44 —-RSD—- C:\WINDOWS\Fonts
2008-10-26 07:47:23 —-A—- C:\WINDOWS\System32\PerfStringBackup.INI
2008-10-25 08:18:49 —-A—- C:\WINDOWS\System32\2cD84csd.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\System32\drivers\Cdr4_xp.sys [2005-09-07 44288]
R1 Cdralw2k;Cdralw2k; C:\WINDOWS\System32\drivers\Cdralw2k.sys [2005-09-07 24960]
R1 SiSkp;SiSkp; C:\WINDOWS\System32\DRIVERS\srvkp.sys [2004-06-10 12160]
R1 sscdbhk5;sscdbhk5; C:\WINDOWS\system32\drivers\sscdbhk5.sys [2004-01-14 5621]
R1 ssrtln;ssrtln; C:\WINDOWS\system32\drivers\ssrtln.sys [2004-01-14 23219]
R2 ASCTRM;ASCTRM; C:\WINDOWS\System32\drivers\ASCTRM.sys [2004-07-14 8552]
R2 drvnddm;drvnddm; C:\WINDOWS\system32\drivers\drvnddm.sys [2004-02-27 40480]
R2 tfsnboio;tfsnboio; C:\WINDOWS\system32\dla\tfsnboio.sys [2004-03-15 25685]
R2 tfsncofs;tfsncofs; C:\WINDOWS\system32\dla\tfsncofs.sys [2004-03-15 34837]
R2 tfsndrct;tfsndrct; C:\WINDOWS\system32\dla\tfsndrct.sys [2004-03-15 4117]
R2 tfsndres;tfsndres; C:\WINDOWS\system32\dla\tfsndres.sys [2004-03-15 2233]
R2 tfsnifs;tfsnifs; C:\WINDOWS\system32\dla\tfsnifs.sys [2004-03-15 85972]
R2 tfsnopio;tfsnopio; C:\WINDOWS\system32\dla\tfsnopio.sys [2004-03-15 14229]
R2 tfsnpool;tfsnpool; C:\WINDOWS\system32\dla\tfsnpool.sys [2004-03-15 6357]
R2 tfsnudf;tfsnudf; C:\WINDOWS\system32\dla\tfsnudf.sys [2004-03-15 98580]
R2 tfsnudfa;tfsnudfa; C:\WINDOWS\system32\dla\tfsnudfa.sys [2004-03-15 100597]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\System32\DRIVERS\AGRSM.sys [2003-11-19 1205292]
R3 ApfiltrService;Alps Touch Pad Filter Driver for Windows 2000/XP; C:\WINDOWS\System32\DRIVERS\Apfiltr.sys [2003-08-21 94600]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\System32\DRIVERS\CmBatt.sys [2002-08-29 13184]
R3 NaiFiltr;NaiFiltr; C:\WINDOWS\System32\DRIVERS\NaiFiltr.sys [2002-03-13 23296]
R3 odysseyIM3;Odyssey Network Services Miniport; C:\WINDOWS\System32\DRIVERS\odysseyIM3.sys [2004-02-04 62865]
R3 SiS315;SiS315; C:\WINDOWS\System32\DRIVERS\sisgrp.sys [2004-06-10 216320]
R3 SISNIC;SiS PCI Fast Ethernet Adapter Driver; C:\WINDOWS\System32\DRIVERS\sisnic.sys [2004-04-06 32256]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2004-03-29 612352]
R3 TNET1130;802.11 WLAN; C:\WINDOWS\System32\DRIVERS\tnet1130.sys [2004-03-10 385536]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2003-08-02 25216]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2003-08-02 53120]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2003-08-02 16000]
R3 wanatw;WAN Miniport (ATW); C:\WINDOWS\System32\DRIVERS\wanatw4.sys [2003-01-10 33588]
S1 P3;Intel PentiumIII Processor Driver; C:\WINDOWS\System32\DRIVERS\p3.sys [2002-11-25 37632]
S3 bvrp_pci;bvrp_pci; C:\WINDOWS\System32\drivers\bvrp_pci.sys []
S3 EL90XBC;3Com EtherLink XL 90XB/C Adapter Driver; C:\WINDOWS\System32\DRIVERS\el90xbc5.sys [2001-08-17 66591]
S3 i81x;i81x; C:\WINDOWS\System32\DRIVERS\i81xnt5.sys [2001-08-17 138240]
S3 iAimFP0;iAimFP0; C:\WINDOWS\System32\DRIVERS\wADV01nt.sys [2001-08-17 12672]
S3 iAimFP1;iAimFP1; C:\WINDOWS\System32\DRIVERS\wADV02NT.sys [2001-08-17 12288]
S3 iAimFP2;iAimFP2; C:\WINDOWS\System32\DRIVERS\wADV05NT.sys [2001-08-17 12032]
S3 iAimFP3;iAimFP3; C:\WINDOWS\System32\DRIVERS\wSiINTxx.sys [2001-08-17 12160]
S3 iAimFP4;iAimFP4; C:\WINDOWS\System32\DRIVERS\wVchNTxx.sys [2001-08-17 18688]
S3 iAimTV0;iAimTV0; C:\WINDOWS\System32\DRIVERS\wATV01nt.sys [2001-08-17 29440]
S3 iAimTV1;iAimTV1; C:\WINDOWS\System32\DRIVERS\wATV02NT.sys [2001-08-17 19456]
S3 iAimTV2;iAimTV2; C:\WINDOWS\System32\DRIVERS\wATV03nt.sys [2001-08-17 44928]
S3 iAimTV3;iAimTV3; C:\WINDOWS\System32\DRIVERS\wATV04nt.sys [2001-08-17 31104]
S3 iAimTV4;iAimTV4; C:\WINDOWS\System32\DRIVERS\wCh7xxNT.sys [2001-08-17 23680]
S3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2002-08-28 891711]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2002-08-29 21760]
S3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2003-08-02 19328]
S4 agp440;Intel AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\agp440.sys [2001-08-17 25472]
S4 agpCPQ;Compaq AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\agpCPQ.sys [2001-08-17 29056]
S4 alim1541;ALI AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\alim1541.sys [2001-08-17 27648]
S4 amdagp;AMD AGP Bus Filter Driver; C:\WINDOWS\System32\DRIVERS\amdagp.sys [2001-08-17 27648]
S4 cbidf;cbidf; C:\WINDOWS\System32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
S4 IntelIde;IntelIde; C:\WINDOWS\System32\DRIVERS\intelide.sys [2002-08-29 4736]
S4 viaagp;VIA AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\viaagp.sys [2001-08-17 27392]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AOL ACS;AOL Connectivity Service; C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe [2004-02-25 1123440]
R2 McDetect.exe;McAfee WSC Integration; c:\program files\mcafee.com\agent\mcdetect.exe [2005-10-13 126976]
R2 McTskshd.exe;McAfee Task Scheduler; c:\PROGRA~1\mcafee.com\agent\mctskshd.exe [2005-08-24 122368]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\System32\wdfmgr.exe [2004-09-22 38912]
S2 MCVSRte;McAfee.com VirusScan Online Realtime Engine; c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe [2003-08-08 106496]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2003-02-20 32768]
S3 McShield;McAfee.com McShield; c:\PROGRA~1\mcafee.com\vso\mcshield.exe [2002-03-13 225375]
S3 mcupdmgr.exe;McAfee SecurityCenter Update Manager; C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe [2005-07-01 245760]

—————–EOF—————–


info.txt logfile of random's system information tool 1.04 2008-11-19 14:47:52

======Uninstall list======

–>C:\PROGRA~1\ntl\BROADB~1\Uninstall.exe ntl
–>C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
–>C:\WINDOWS\System32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature
–>C:\WINDOWS\System32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
–>C:\WINDOWS\System32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E06E4F4E-72D6-4497-BFFD-BCB43077C2F4}\is.exe" -l0x9 -uninst
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Download Manager 2.0 (Remove Only)–>"C:\Program Files\Common Files\Adobe\ESD\uninst.exe"
Adobe Flash Player ActiveX–>C:\WINDOWS\System32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.0.5–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70500000002}
Advertisement Service–>C:\WINDOWS\System32\prun.exe Uninstall
Agere Systems AC'97 Modem–>agrsmdel
ALPS Touch Pad Driver–>C:\Program Files\Apoint\Uninstap.exe ADDREMOVE
AOL Coach Version 1.0(Build:20040201.2 uk)–>"C:\Program Files\Common Files\aolshare\Coach\AolCInUn.exe" -lang="en-uk"
AOL Connectivity Services–>C:\PROGRA~1\COMMON~1\AOL\ACS\AcsUninstall.exe /c
AOL Spyware Protection–>C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\UNWISE.EXE C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\INSTALL.LOG
AOL UK (Choose which version to remove)–>C:\Program Files\Common Files\aolshare\Aolunins_uk.exe
AOL You've Got Pictures Screensaver–>C:\Program Files\Common Files\AOL\Screensaver\uninst_ygpss.exe
BetTrader PRO–>C:\Program Files\BetTrader PRO\Uninstall.exe
broadband medic–>C:\WINDOWS\Motive\ntl\MCCUninst.exe
BroadJump Client Foundation–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\BroadJump\Client Foundation\Uninst.isu" -c"C:\Program Files\BroadJump\Client Foundation\RmvBJCFD.dll" -b"CFD" -h"CFD" -a
BT Openworld Dell Signup–>MsiExec.exe /X{2CB511DF-AD50-4087-8934-8ACE54DE4FC1}
Dell Media Experience–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\setup.exe" -uninstall
Dell Solution Center–>MsiExec.exe /X{11F1920A-56A2-4642-B6E0-3B31A12C9288}
HijackThis 2.0.2–>"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
IGN Download Manager 2.1.2–>C:\Program Files\IGN\Download Manager\uninst.exe
Jasc Paint Shop Photo Album–>MsiExec.exe /I{CC000127-5E5D-4A1C-90CB-EEAAAC1E3AC0}
Jasc Paint Shop Pro 8 Dell Edition–>MsiExec.exe /I{81A34902-9D0B-4920-A25C-4CDC5D14B328}
Java 2 Runtime Environment, SE v1.4.2_03–>MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142030}
Learn2 Player (Uninstall Only)–>C:\Program Files\Learn2.com\StRunner\stuninst.exe
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
McAfee SecurityCenter–>c:\PROGRA~1\mcafee.com\shared\mcappins.exe /v=3 /uninstall=1 /appid=msc /interact=1 /script_proactive=0 /start=c:\PROGRA~1\mcafee.com\agent\uninst\screm.ui::uninstall.htm
McAfee VirusScan–>c:\PROGRA~1\mcafee.com\shared\mcappins.exe /v=3 /uninstall=1 /interact=1 /script_proactive=1 /start=c:\PROGRA~1\mcafee.com\agent\uninst\vsoremui.dll::uninstall.htm
Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft Works 7.0–>MsiExec.exe /I{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}
Modem Helper–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F142D56-3326-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel
Mozilla Firefox (1.0.7)–>C:\WINDOWS\UninstallFirefox.exe /ua "1.0.7 (en-GB)"
Napster Burn Engine–>MsiExec.exe /I{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}
Napster–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BBBCAE4B-B416-4182-A6F2-438180894A81}\setup.exe" -l0x9 -removeonly
PowerDVD 5.1–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
QuickTime–>C:\WINDOWS\unvise32qt.exe C:\WINDOWS\System32\QuickTime\Uninstall.log
RealPlayer Basic–>C:\Program Files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0
RON Tool Netupbanner–>C:\WINDOWS\System32\kptdonsksnlnryam.exe
SiS 900 PCI Fast Ethernet Adapter Driver–>C:\Progra~1\SiSLan\Uninst.exe
SiS VGA Utilities–>Rundll32 SiSInst.dll,Uninstall VGA,R
Sonic DLA–>MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
Sonic RecordNow!–>MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
Sonic Update Manager–>MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3}
Spybot - Search & Destroy–>"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Tiscali 10.0–>MsiExec.exe /X{1EDBB5DD-3AB0-49D8-99CC-235A93865D03}
Update for Windows XP (KB898461)–>"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Viewpoint Media Player–>C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
Windows Installer 3.1 (KB893803)–>"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
Windows Media Format Runtime–>"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Player 10–>"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows XP Hotfix - KB842773–>C:\WINDOWS\$NtUninstallKB842773$\spuninst\spuninst.exe
WlanUtility–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{07DEC7A1-F8D2-4DBB-900B-A2F9302647BB}\setup.exe" -l0x9
XviD MPEG-4 Video Codec–>"C:\Program Files\XviD\unins000.exe"
Yahoo! Toolbar–>C:\PROGRA~1\Yahoo!\Common\unyt.exe

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 2 Stepping 9, GenuineIntel
"PROCESSOR_REVISION"=0209
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP

—————–EOF—————–
Hello

1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

O2 - BHO: (no name) - {50c81acb-581c-451b-8260-47e72a5f7df8} - C:\WINDOWS\System32\namogizu.dll (file missing)
O4 - HKLM\..\Run: [mopedudupo] Rundll32.exe "C:\WINDOWS\System32\romarete.dll",s
O4 - HKLM\..\Run: [obwcurlyidmvn] C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\System32\dtfcujmvzetrbzejn.dll"
O4 - HKUS\S-1-5-19\..\Run: [mopedudupo] Rundll32.exe "C:\WINDOWS\System32\romarete.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [mopedudupo] Rundll32.exe "C:\WINDOWS\System32\romarete.dll",s (User 'NETWORK SERVICE')
O15 - Trusted Zone: *.amaena.com (HKLM)
O15 - Trusted Zone: *.antimalwareguard.com (HKLM)
O15 - Trusted Zone: *.antispyexpert.com (HKLM)
O15 - Trusted Zone: *.avsystemcare.com (HKLM)
O15 - Trusted Zone: *.gomyhit.com (HKLM)
O15 - Trusted Zone: *.imageservr.com (HKLM)
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
O15 - Trusted Zone: *.onerateld.com (HKLM)
O15 - Trusted Zone: *.safetydownload.com (HKLM)
O15 - Trusted Zone: *.spyguardpro.com (HKLM)
O15 - Trusted Zone: *.storageguardsoft.com (HKLM)
O15 - Trusted Zone: *.trustedantivirus.com (HKLM)
O15 - Trusted Zone: *.virusremover2008.com (HKLM)
O15 - Trusted Zone: *.virusschlacht.com (HKLM)
O20 - AppInit_DLLs: c:\windows\system32\gumeyesu.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - (no file)


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.



Please download the OTMoveIt3 by OldTimer or from here.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :files
    C:\WINDOWS\System32\M2dQO118.exe.a_a
    C:\WINDOWS\System32\el32.dll
    C:\WINDOWS\System32\g86.exe
    C:\WINDOWS\System32\tdapberp.dll
    C:\WINDOWS\System32\33dc5de2-.txt
    C:\WINDOWS\System32\kptdonsksnlnryam.exe
    C:\WINDOWS\System32\prun.exe
    C:\WINDOWS\System32\bowagina.exe
    C:\WINDOWS\System32\vezipoyo.exe
    C:\WINDOWS\System32\buvurosi.exe
    C:\WINDOWS\System32\ririzaki.exe
    C:\WINDOWS\System32\M2dQO118.exe
    C:\WINDOWS\System32\2cD84csd.dll
    C:\WINDOWS\TWFyeSBHb3Jkb24
    C:\WINDOWS\System32\nas
    C:\WINDOWS\System32\ITX
    C:\WINDOWS\System32\ex
    C:\WINDOWS\System32\cs2
    C:\WINDOWS\System32\sX3i19
    C:\WINDOWS\System32\QI19
    
    
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



Also post a new Rsit log
The OldTimer log- ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== C:\WINDOWS\System32\M2dQO118.exe.a_a moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\el32.dll C:\WINDOWS\System32\el32.dll NOT unregistered. C:\WINDOWS\System32\el32.dll moved successfully. C:\WINDOWS\System32\g86.exe moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\tdapberp.dll C:\WINDOWS\System32\tdapberp.dll NOT unregistered. C:\WINDOWS\System32\tdapberp.dll moved successfully. C:\WINDOWS\System32\33dc5de2-.txt moved successfully. C:\WINDOWS\System32\kptdonsksnlnryam.exe moved successfully. C:\WINDOWS\System32\prun.exe moved successfully. C:\WINDOWS\System32\bowagina.exe moved successfully. C:\WINDOWS\System32\vezipoyo.exe moved successfully. C:\WINDOWS\System32\buvurosi.exe moved successfully. C:\WINDOWS\System32\ririzaki.exe moved successfully. C:\WINDOWS\System32\M2dQO118.exe moved successfully. LoadLibrary failed for C:\WINDOWS\System32\2cD84csd.dll C:\WINDOWS\System32\2cD84csd.dll NOT unregistered. C:\WINDOWS\System32\2cD84csd.dll moved successfully. C:\WINDOWS\TWFyeSBHb3Jkb24 moved successfully. C:\WINDOWS\System32\nas moved successfully. C:\WINDOWS\System32\ITX moved successfully. C:\WINDOWS\System32\ex moved successfully. C:\WINDOWS\System32\cs2 moved successfully. C:\WINDOWS\System32\sX3i19 moved successfully. C:\WINDOWS\System32\QI19 moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\MARYGO~1\LOCALS~1\Temp\WER18.tmp.dir00\appcompat.txt scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\MARYGO~1\LOCALS~1\Temp\~DF5376.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 11192008_153042 Files moved on Reboot… C:\DOCUME~1\MARYGO~1\LOCALS~1\Temp\WER18.tmp.dir00\appcompat.txt moved successfully. C:\DOCUME~1\MARYGO~1\LOCALS~1\Temp\~DF5376.tmp moved successfully. File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI