This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] help svchost.exe error and pop ups

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hi i need help please take a look at this . ive been getting a svchost.exe error at startup and whenever im online i get loadss of popups if you guys could help i would really appreciate it thanks again john


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:15:06 PM, on 12/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CyberLink\PCM4Everio\EverioService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\program files\steam\steam.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Webshots\WebshotsTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Java\jre1.5.0_11\bin\jucheck.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Norton 360\ScanStub.exe
C:\program files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll
O3 - Toolbar: (no name) - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - (no file)
O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [svchost.exe] C:\WINDOWS\svchost.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [EverioService] "C:\Program Files\CyberLink\PCM4Everio\EverioService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [a8ede14f] rundll32.exe "C:\WINDOWS\system32\nltjacou.dll",b
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Default user')
O4 - S-1-5-18 Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe (User 'Default user')
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?0c17c1a863504578bfd493bb74b1e475
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?0c17c1a863504578bfd493bb74b1e475
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6662.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownlo…Plugin11USA.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/flash…ent/swflash.cab
O20 - AppInit_DLLs: xkwtwu.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 10552 bytes
hello

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.


Please download MsnCleaner.zip and Save it to your Desktop.
  • Unzip it to the Desktop.
  • Now reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit Enter.
  • Double-click MsnCleaner.exe to run it.
  • Click the Analyze button.
  • A report will be created once after you finish scan.
  • If it finds an infection, click the Deleted button.
  • Now, please reboot back to normal mode.
  • Please post the contents of C:\MsnCleaner.txt in a reply to this post along with a new HJT log.
heres the report.txt from the sdfix


SDFix: Version 1.240
Run by [removed] on Mon 12/29/2008 at 06:18 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\WINDOWS\svchost.exe - Deleted





Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-29 18:31:08
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\DNA\\btdna.exe"="C:\\Program Files\\DNA\\btdna.exe:*:Enabled:DNA"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\Program Files\\Microsoft Games\\Age of Mythology\\aomx.exe"="C:\\Program Files\\Microsoft Games\\Age of Mythology\\aomx.exe:*:Enabled:Age of Mythology - The Titans Expansion"
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"="C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe:*:Enabled:MySpaceIM"
"C:\\Program Files\\CyberLink\\PowerDirector Express\\PDX.exe"="C:\\Program Files\\CyberLink\\PowerDirector Express\\PDX.exe:*:Enabled:CyberLink PowerDirector Express"
"C:\\Program Files\\CyberLink\\PCM4Everio\\PCM4Everio.exe"="C:\\Program Files\\CyberLink\\PCM4Everio\\PCM4Everio.exe:*:Enabled:CyberLink PowerCinema NE for Everio"
"C:\\Program Files\\CyberLink\\PCM4Everio\\EverioService.exe"="C:\\Program Files\\CyberLink\\PCM4Everio\\EverioService.exe:*:Enabled:CyberLink PowerCinema NE for Everio Resident Program"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Sat 10 Nov 2007 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Tue 2 Sep 2008 20,480 …H. — "C:\Documents and Settings\Juan\My Documents\~WRL0878.tmp"
Tue 2 Sep 2008 19,968 …H. — "C:\Documents and Settings\Juan\My Documents\~WRL0984.tmp"
Tue 2 Sep 2008 19,456 …H. — "C:\Documents and Settings\Juan\My Documents\~WRL1350.tmp"
Tue 4 Nov 2008 19,456 …H. — "C:\Documents and Settings\Juan\My Documents\~WRL1859.tmp"
Tue 2 Sep 2008 20,992 …H. — "C:\Documents and Settings\Juan\My Documents\~WRL2703.tmp"
Tue 2 Sep 2008 19,968 …H. — "C:\Documents and Settings\Juan\My Documents\~WRL3168.tmp"
Tue 2 Sep 2008 20,480 …H. — "C:\Documents and Settings\Juan\My Documents\~WRL3182.tmp"
Tue 4 Sep 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Fri 18 Jan 2008 400 A..H. — "C:\Program Files\Common Files\Symantec Shared\COH\COH32LU.reg"
Fri 18 Jan 2008 403 A..H. — "C:\Program Files\Common Files\Symantec Shared\COH\COHDLU.reg"
Tue 2 Sep 2008 20,480 …H. — "C:\Documents and Settings\Juan\Application Data\Microsoft\Word\~WRL0124.tmp"
Tue 2 Sep 2008 19,456 …H. — "C:\Documents and Settings\Juan\Application Data\Microsoft\Word\~WRL2210.tmp"

Finished!
hello

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
sorry for the wait but heres the msncleaner.txt



- Logfile MSNCleaner 1.7.1 by www.forospyware.com
- Created Logfile: 12/29/2008 on 7:37:59 PM
- Operative System: Windows XP
- Boot mode: Safe mode
_________________________________________

Detected files: 1
Deleted file: 0
Undeleted Files: 0

C:\Documents and Settings\Juan\Local Settings\Temp\catchme.sys

there was 2 diffrent text files so i put both on

- Logfile MSNCleaner 1.7.1 by www.forospyware.com
- Created Logfile: 12/29/2008 on 7:38:37 PM
- Operative System: Windows XP
- Boot mode: Safe mode
_________________________________________

Detected files: 1
Deleted file: 1
Undeleted Files: 0

C:\Documents and Settings\Juan\Local Settings\Temp\catchme.sys <— Deleted

Host file Restored



heres the hijackthis file

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:48:22 PM, on 12/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CyberLink\PCM4Everio\EverioService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\program files\steam\steam.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Webshots\WebshotsTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\program files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre1.5.0_11\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll
O3 - Toolbar: (no name) - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - (no file)
O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [EverioService] "C:\Program Files\CyberLink\PCM4Everio\EverioService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [a8ede14f] rundll32.exe "C:\WINDOWS\system32\nltjacou.dll",b
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Default user')
O4 - S-1-5-18 Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe (User 'Default user')
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?0c17c1a863504578bfd493bb74b1e475
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?0c17c1a863504578bfd493bb74b1e475
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6662.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownlo…Plugin11USA.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/flash…ent/swflash.cab
O20 - AppInit_DLLs: xkwtwu.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 10128 bytes
heres the otlist.txt i did not get the extras.txt


OTListIt logfile created on: 12/29/2008 7:52:55 PM - Run 2
OTListIt2 by OldTimer - Version 1.0.1.1 Folder = C:\Documents and Settings\Juan\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1023.17 Mb Total Physical Memory | 618.99 Mb Available Physical Memory | 60.50% Memory free
2.40 Gb Paging File | 2.00 Gb Available in Paging File | 83.16% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 253.18 Gb Free Space | 84.94% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 583.05 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOME-01D49B7F63
Current User Name: Juan
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE (Symantec Corporation)
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe (InterVideo Inc.)
C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
C:\WINDOWS\system32\PnkBstrA.exe ()
C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
C:\WINDOWS\system32\searchindexer.exe (Microsoft Corporation)
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe (Sun Microsystems, Inc.)
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE (Symantec Corporation)
C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation)
C:\Program Files\CyberLink\PCM4Everio\EverioService.exe (CyberLink Corp.)
C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation)
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
C:\Program Files\Steam\steam.exe (Valve Corporation)
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE (Microsoft Corporation)
C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
C:\Program Files\Webshots\WebshotsTray.exe (The Webshots Corporation)
C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
C:\Program Files\Java\jre1.5.0_11\bin\jucheck.exe (Sun Microsystems, Inc.)
C:\Documents and Settings\Juan\Desktop\OTListIt2.exe (OldTimer Tools)

========== (O23) Win32 Services (SafeList) ==========

(Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
(aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
(Automatic LiveUpdate Scheduler [Auto | Running]) – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
(Capture Device Service [Auto | Running]) – C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe (InterVideo Inc.)
(ccEvtMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE (Symantec Corporation)
(ccSetMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE (Symantec Corporation)
(clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
(CLTNetCnService [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE (Symantec Corporation)
(comHost [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe (Symantec Corporation)
(FontCache3.0.0.0 [On_Demand | Stopped]) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
(gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
(idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
(iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
(LiveUpdate [On_Demand | Stopped]) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
(LiveUpdate Notice [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE (Symantec Corporation)
(NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
(NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
(PnkBstrA [Auto | Running]) – C:\WINDOWS\system32\PnkBstrA.exe ()
(RichVideo [Auto | Running]) – C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
(Symantec Core LC [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
(usnjsvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
(Viewpoint Manager Service [Auto | Running]) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
(WLSetupSvc [On_Demand | Stopped]) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
(WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
(WSearch [Auto | Running]) – C:\WINDOWS\system32\searchindexer.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

(AtcL001 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\l151x86.sys (Atheros Communications, Inc.)
(COH_Mon [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\COH_Mon.sys (Symantec Corporation)
(CO_Mon [Auto | Running]) – C:\WINDOWS\system32\drivers\CO_Mon.sys (Symantec Corporation)
(eeCtrl [System | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
(EraserUtilRebootDrv [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
(es1371 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\es1371mp.sys (Creative Technology Ltd.)
(gameenum [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
(GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
(HCF_MSFT [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HCF_MSFT.sys (Conexant)
(HdAudAddService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
(HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
(kbdhid [System | Stopped]) – C:\WINDOWS\system32\drivers\kbdhid.sys (Microsoft Corporation)
(NAVENG [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20081229.003\NAVENG.SYS (Symantec Corporation)
(NAVEX15 [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20081229.003\NAVEX15.SYS (Symantec Corporation)
(nm [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
(nv [On_Demand | Running]) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
(Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
(PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\drivers\PxHelp20.sys (Sonic Solutions)
(Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(SPBBCDrv [System | Running]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
(SRTSP [On_Demand | Running]) – C:\WINDOWS\system32\drivers\srtsp.sys (Symantec Corporation)
(SRTSPL [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\srtspl.sys (Symantec Corporation)
(SRTSPX [System | Running]) – C:\WINDOWS\system32\drivers\srtspx.sys (Symantec Corporation)
(SYMDNS [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symdns.sys (Symantec Corporation)
(SymEvent [On_Demand | Running]) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
(SYMFW [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symfw.sys (Symantec Corporation)
(SYMIDS [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symids.sys (Symantec Corporation)
(SYMIDSCO [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\SymcData\ipsdefs\20081220.001\SymIDSco.sys (Symantec Corporation)
(SymIM [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\SymIM.sys (Symantec Corporation)
(SymIMMP [On_Demand | Running]) – C:\WINDOWS\system32\drivers\SymIM.sys (Symantec Corporation)
(SYMNDIS [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symndis.sys (Symantec Corporation)
(SYMREDRV [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symredrv.sys (Symantec Corporation)
(SYMTDI [System | Running]) – C:\WINDOWS\system32\drivers\symtdi.sys (Symantec Corporation)
(USB100TX [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\USB100TX.sys (Linksys)
(USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaapl.sys (Apple, Inc.)
(w300bus [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\w300bus.sys (MCCI)
(w300mgmt [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\w300mgmt.sys (MCCI)
(w300obex [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\w300obex.sys (MCCI)
(XIRLINK [On_Demand | Running]) – C:\WINDOWS\system32\drivers\C-itNT.sys (Xirlink, Inc)

========== Standard Registry (All) ==========


========== Internet Explorer ==========

HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - Reg Error: Key does not exist or could not be opened. File not found

HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - Reg Error: Key does not exist or could not be opened. File not found
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O1 HOSTS File: (687 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Companion BHO) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Common Files\Symantec Shared\IDS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {74FD5B84-0896-40CF-9537-D5DB4A4EC4FD} - C:\WINDOWS\system32\xxyxUkiI.dll ()
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {773704dd-e216-46b2-9a38-ff9cb9cc636a} - C:\WINDOWS\system32\xkwtwu.dll ()
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (no name) - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll (Google Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (no name) - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKLM\..\Toolbar: (Yahoo! Companion) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (Viewpoint Toolbar) - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll (Viewpoint Corporation)
O3 - HKCU\..\Toolbar: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [a8ede14f] rundll32.exe "C:\WINDOWS\system32\nltjacou.dll",b ()
O4 - HKLM..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" (Symantec Corporation)
O4 - HKLM..\Run: [EverioService] "C:\Program Files\CyberLink\PCM4Everio\EverioService.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install ()
O4 - HKLM..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe" (Symantec Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Steam] "c:\program files\steam\steam.exe" -silent (Valve Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Juan\Start Menu\Programs\Startup\Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe (The Webshots Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?0c17c1a863504578bfd493bb74b1e475
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?0c17c1a863504578bfd493bb74b1e475
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\NPJPI150_11.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Sites: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/pub/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase6662.cab (Windows Live Safety Center Base Module)
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} http://gamedownload.ijjimax.com/gamedownlo…Plugin11USA.cab (ijjiPlugin2 Class)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} https://webdl.symantec.com/activex/symdlmgr.cab (Symantec Download Manager)
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab (HpProductDetection Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler: - about - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - cdl - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - dvd - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler: - file - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ftp - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - gopher - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - http\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - https - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - https\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - https\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ipp - No CLSID value found
O18 - Protocol\Handler: - ipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - its - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - javascript - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - livecall - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler: - local - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mailto - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mhtml - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mk - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp - No CLSID value found
O18 - Protocol\Handler: - msdaipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ms-its - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msnim - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler: - res - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - sysimage - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - tv - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler: - vbscript - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - wia - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - See sections below for AppInitDlls and Winlogon settings
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9}C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9}C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153}C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5}C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: (Browseui preloader) - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: (Component Categories cache daemon) - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

========== AppInit_DLLs ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_Dlls" = xkwtwu.dll
>C:\WINDOWS\system32\xkwtwu.dll ()

========== HKLM Winlogon Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell" = Explorer.exe
>C:\WINDOWS\explorer.exe (Microsoft Corporation)

"UserInit" = C:\WINDOWS\system32\userinit.exe,
>C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

"UIHost" = logonui.exe
>C:\WINDOWS\system32\logonui.exe (Microsoft Corporation)

"VMApplet" = rundll32 shell32,Control_RunDLL "sysdm.cpl"
>C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
>C:\WINDOWS\system32\sysdm.cpl (Microsoft Corporation)


========== Winlogon Notify Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
crypt32chain: "DllName" = crypt32.dll – C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
cryptnet: "DllName" = cryptnet.dll – C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
cscdll: "DllName" = cscdll.dll – C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
rqRJDvww: "DllName" = rqRJDvww.dll – File not found
ScCertProp: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Schedule: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
sclgntfy: "DllName" = sclgntfy.dll – C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
SensLogn: "DllName" = WlNotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
termsrv: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
WgaLogon: "DllName" = WgaLogon.dll – C:\WINDOWS\system32\WgaLogon.dll (Microsoft Corporation)
wlballoon: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)

========== IFEO "Debugger" Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\]
Your Image File Name Here without a path:"Debugger" = C:\WINDOWS\system32\ntsd.exe (Microsoft Corporation)

========== Shell Execute Hooks ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}" (HKLM) – C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}" (HKLM) – C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

========== HKLM *SecurityProviders* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders" = msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
>C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)
>C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
>C:\WINDOWS\system32\digest.dll (Microsoft Corporation)
>C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)

========== LSA *Authentication Packages* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages" = msv1_0,C:\WINDOWS\system32\xxyxUkiI,
>C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
>C:\WINDOWS\system32\xxyxUkiI.dll ()

========== LSA *Security Packages* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Security Packages" = kerberos,msv1_0,schannel,wdigest,
>C:\WINDOWS\system32\kerberos.dll (Microsoft Corporation)
>C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
>C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
>C:\WINDOWS\system32\wdigest.dll (Microsoft Corporation)

========== Safeboot Options ==========

"AlternateShell" = cmd.exe

========== CDRom AutoRun Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1

========== Autorun Files on Drives ==========

AUTOEXEC.BAT []
C:\AUTOEXEC.BAT () – [ NTFS ]

autorun.inf [[autorun] | open=_aomg.exe | icon=_aomg.exe | ]
E:\autorun.inf () – [ CDFS ]

========== MountPoints2 ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0f646cec-23f7-11dc-99b0-806d6172696f}\Shell]
"" = AutoRun

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0f646cec-23f7-11dc-99b0-806d6172696f}\Shell\AutoRun]
"" = Auto&Play


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0f646cec-23f7-11dc-99b0-806d6172696f}\Shell\AutoRun\command]
"" = E:\_aomg.exe – [2004/07/16 16:07:36 | 00,045,056 | R— | M] ()


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{efbcfaea-5c2d-11dd-b6ca-0018f3744e56}\Shell\AutoRun\command]
"" = F:\wd_windows_tools\setup.exe – File not found

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\Shell]
"" = AutoRun

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\Shell\AutoRun]
"" = Auto&Play


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\Shell\AutoRun\command]
"" = E:\_aomg.exe – [2004/07/16 16:07:36 | 00,045,056 | R— | M] ()

========== Files/Folders - Created Within 30 Days ==========

[6 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[7 C:\Documents and Settings\Juan\My Documents\*.tmp files]
File not found – C:\WINDOWS\System32\xsusingf.dll
File not found – C:\WINDOWS\System32\uvqteada.dll
File not found – C:\WINDOWS\System32\tmcbnbrd.dll
File not found – C:\WINDOWS\System32\oegrjj.dll
File not found – C:\WINDOWS\System32\novclnsr.dll
File not found – C:\WINDOWS\System32\fvprjaqv.dll
[2008/12/29 19:50:44 | 00,419,328 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Juan\Desktop\OTListIt2.exe
[2008/12/29 19:36:51 | 00,000,000 | —D | C] – C:\MSNCleaner
[2008/12/29 19:19:28 | 00,184,320 | —- | C] (InfoSpyware - ForoSpyware) – C:\Documents and Settings\Juan\Desktop\MSNCleaner.exe
[2008/12/29 18:08:55 | 00,000,000 | —D | C] – C:\WINDOWS\ERUNT
[2008/12/29 17:57:21 | 00,000,000 | —D | C] – C:\SDFix
[2008/12/29 17:57:11 | 01,529,241 | —- | C] () – C:\Documents and Settings\Juan\Desktop\SDFix.exe
[2008/12/29 15:26:40 | 00,000,000 | —D | C] – C:\Documents and Settings\Juan\My Documents\windows help thing
[2008/12/29 15:14:47 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2008/12/29 15:13:36 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2008/12/29 15:12:59 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2008/12/29 14:19:26 | 00,000,000 | —D | C] – C:\Documents and Settings\Juan\Local Settings\Application Data\Cranium_Consulting_and_Cu
[2008/12/29 14:18:30 | 00,000,672 | —- | C] () – C:\Documents and Settings\Juan\Desktop\iPhoneBrowser.lnk
[2008/12/29 14:17:26 | 00,000,000 | —D | C] – C:\Program Files\iPhoneBrowser
[2008/12/29 14:11:21 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\xkwtwu.dll
[2008/12/29 14:11:20 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\feolotau.dll
[2008/12/29 14:05:21 | 01,308,204 | -HS- | C] () – C:\WINDOWS\System32\uocajtln.ini
[2008/12/29 14:05:20 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\nltjacou.dll
[2008/12/28 22:07:35 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\ziaxsi.dll
[2008/12/28 22:07:34 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\bkuvaaog.dll
[2008/12/28 22:05:09 | 01,306,974 | -HS- | C] () – C:\WINDOWS\System32\mdseagro.ini
[2008/12/26 20:19:48 | 01,745,930 | -HS- | C] () – C:\WINDOWS\System32\drbnbcmt.ini
[2008/12/25 21:44:20 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\cxracc.dll
[2008/12/25 21:44:19 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\yiapmsnd.dll
[2008/12/25 21:42:09 | 00,001,393 | —- | C] () – C:\WINDOWS\imsins.BAK
[2008/12/25 21:39:54 | 01,661,209 | -HS- | C] () – C:\WINDOWS\System32\cnspfmhb.ini
[2008/12/25 03:04:42 | 00,002,137 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2008/12/25 03:04:19 | 00,000,000 | —D | C] – C:\Program Files\iPod
[2008/12/25 03:04:17 | 00,000,000 | —D | C] – C:\Program Files\iTunes
[2008/12/25 03:02:36 | 00,001,604 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2008/12/25 03:02:15 | 00,000,000 | —D | C] – C:\Program Files\QuickTime
[2008/12/25 02:45:46 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusb.dll
[2008/12/25 02:45:45 | 00,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusd.dll
[2008/12/25 02:45:44 | 00,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\usbscan.sys
[2008/12/25 02:45:44 | 00,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2008/12/24 16:57:09 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\iczvat.dll
[2008/12/24 16:57:08 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\lcfweklw.dll
[2008/12/24 16:54:11 | 01,661,209 | -HS- | C] () – C:\WINDOWS\System32\lmatrudu.ini
[2008/12/24 11:48:30 | 00,000,000 | —D | C] – C:\Documents and Settings\Juan\Local Settings\Application Data\Symantec
[2008/12/23 21:20:11 | 01,661,209 | -HS- | C] () – C:\WINDOWS\System32\tecxmgkb.ini
[2008/12/23 21:20:11 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\bkgmxcet.dll
[2008/12/22 21:23:09 | 00,000,000 | —D | C] – C:\Documents and Settings\Juan\My Documents\MakeDiscVideo
[2008/12/22 21:23:04 | 00,000,000 | —D | C] – C:\Documents and Settings\Juan\Application Data\CyberLink
[2008/12/22 21:19:25 | 01,661,209 | -HS- | C] () – C:\WINDOWS\System32\awdfwaob.ini
[2008/12/22 21:12:59 | 00,000,000 | —D | C] – C:\Documents and Settings\Juan\Local Settings\Application Data\PCM4Everio
[2008/12/22 21:12:58 | 00,001,716 | —- | C] () – C:\Documents and Settings\All Users\Desktop\PowerCinema NE for Everio.lnk
[2008/12/22 21:12:41 | 00,198,144 | —- | C] () – C:\WINDOWS\System32\_psisdecd.dll
[2008/12/22 21:12:03 | 00,044,544 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msxml4a.dll
[2008/12/22 21:08:03 | 00,000,000 | —D | C] – C:\MyWorks
[2008/12/22 21:07:47 | 00,001,712 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Digital Photo Navigator 1.5.lnk
[2008/12/22 21:07:46 | 00,000,000 | —D | C] – C:\Program Files\Digital Photo Navigator 1.5
[2008/12/22 20:33:51 | 01,661,209 | -HS- | C] () – C:\WINDOWS\System32\ruyuigkp.ini
[2008/12/22 20:02:45 | 00,000,000 | —D | C] – C:\Documents and Settings\Juan\My Documents\VirtualDJ
[2008/12/21 14:21:00 | 00,000,000 | —D | C] – C:\Program Files\MSXML 6.0
[2008/12/21 14:11:02 | 00,000,000 | —D | C] – C:\Program Files\Windows Live Safety Center
[2008/12/20 16:37:14 | 00,203,540 | —- | C] () – C:\WINDOWS\System32\nvapps.nvb
[2008/12/20 16:37:12 | 00,000,000 | —D | C] – C:\WINDOWS\NV34683196.TMP
[2008/12/20 16:13:44 | 00,905,216 | —- | C] () – C:\WINDOWS\System32\GearDrvs.msi
[2008/12/20 16:03:41 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/12/20 15:43:47 | 00,001,632 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Norton 360.lnk
[2008/12/20 15:38:48 | 00,000,000 | —D | C] – C:\Program Files\Windows Sidebar
[2008/12/20 15:37:17 | 00,000,000 | —D | C] – C:\Program Files\Norton 360
[2008/12/20 15:33:59 | 00,123,952 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2008/12/20 15:33:59 | 00,060,800 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2008/12/20 15:33:59 | 00,010,671 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2008/12/20 15:33:59 | 00,000,805 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2008/12/20 15:33:15 | 00,000,000 | —D | C] – C:\Program Files\Symantec
[2008/12/20 15:18:53 | 00,197,259 | —- | C] () – C:\WINDOWS\System32\nvapps.xml
[2008/12/20 15:18:33 | 00,000,000 | —D | C] – C:\WINDOWS\nview
[2008/12/20 14:41:37 | 00,000,000 | —D | C] – C:\Program Files\AGEIA Technologies
[2008/12/20 14:41:28 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\xwjnompc.dll
[2008/12/20 14:41:22 | 00,000,000 | —D | C] – C:\WINDOWS\A7E07C2B2220441587E3784D5814BC93.TMP
[2008/12/20 14:41:11 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2008/12/19 16:54:34 | 01,661,209 | -HS- | C] () – C:\WINDOWS\System32\sqysdpod.ini
[2008/12/18 16:42:30 | 01,665,243 | -HS- | C] () – C:\WINDOWS\System32\adaetqvu.ini
[2008/12/17 15:33:39 | 01,664,935 | -HS- | C] () – C:\WINDOWS\System32\uumfgden.ini
[2008/12/16 18:21:05 | 00,000,000 | —D | C] – C:\Documents and Settings\Juan\Application Data\Windows Search
[2008/12/16 15:17:33 | 01,664,935 | -HS- | C] () – C:\WINDOWS\System32\rmavlrvc.ini
[2008/12/15 15:15:57 | 01,647,996 | -HS- | C] () – C:\WINDOWS\System32\gikqftaj.ini
[2008/12/14 21:11:26 | 00,023,040 | —- | C] () – C:\Documents and Settings\Juan\My Documents\History Project.doc
[2008/12/14 21:08:17 | 01,647,120 | -HS- | C] () – C:\WINDOWS\System32\dfqtutpk.ini
[2008/12/13 21:03:11 | 01,647,120 | -HS- | C] () – C:\WINDOWS\System32\vsdseufw.ini
[2008/12/13 17:14:21 | 01,647,395 | -HS- | C] () – C:\WINDOWS\System32\ypqnjpff.ini
[2008/12/13 16:44:30 | 00,000,889 | —- | C] () – C:\Documents and Settings\Juan\Desktop\Shortcut to left4dead.lnk
[2008/12/12 17:10:19 | 01,647,395 | -HS- | C] () – C:\WINDOWS\System32\vejuqlnf.ini
[2008/12/11 17:47:48 | 00,002,560 | —- | C] () – C:\WINDOWS\_MSRSTRT.EXE
[2008/12/11 16:51:18 | 00,000,000 | —D | C] – C:\Program Files\A360
[2008/12/11 14:15:34 | 01,621,754 | -HS- | C] () – C:\WINDOWS\System32\oidinfrc.ini
[2008/12/11 14:12:26 | 00,693,974 | -HS- | C] () – C:\WINDOWS\System32\IikUxyxx.ini2
[2008/12/11 14:12:26 | 00,693,974 | -HS- | C] () – C:\WINDOWS\System32\IikUxyxx.ini
[2008/12/11 14:12:23 | 00,302,592 | —- | C] () – C:\WINDOWS\System32\xxyxUkiI.dll
[2008/12/10 20:59:08 | 00,000,000 | —D | C] – C:\Program Files\MSBuild
[2008/12/10 20:53:55 | 00,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2008/12/10 20:53:06 | 00,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2008/12/10 20:51:50 | 00,014,048 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg2.dll
[2008/12/10 20:51:19 | 00,000,000 | —D | C] – C:\7620ba1c1af0cbbc75d490f3a2465f
[2008/12/10 20:49:50 | 00,000,000 | —D | C] – C:\Documents and Settings\Juan\Application Data\Windows Desktop Search
[2008/12/10 20:49:27 | 00,001,787 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2008/12/10 20:49:16 | 00,000,000 | —D | C] – C:\WINDOWS\System32\GroupPolicy
[2008/12/10 20:49:16 | 00,000,000 | —D | C] – C:\Program Files\Windows Desktop Search
[2008/12/01 17:53:30 | 00,000,000 | —D | C] – C:\Program Files\SystemRequirementsLab
[2008/12/01 17:53:29 | 00,000,000 | —D | C] – C:\Documents and Settings\Juan\Application Data\SystemRequirementsLab

========== Files - Modified Within 30 Days ==========

[6 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[7 C:\Documents and Settings\Juan\My Documents\*.tmp files]
[2008/12/29 19:55:29 | 00,693,974 | -HS- | M] () – C:\WINDOWS\System32\IikUxyxx.ini
[2008/12/29 19:53:03 | 00,693,974 | -HS- | M] () – C:\WINDOWS\System32\IikUxyxx.ini2
[2008/12/29 19:50:44 | 00,419,328 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Juan\Desktop\OTListIt2.exe
[2008/12/29 19:45:00 | 00,000,256 | —- | M] () – C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2008/12/29 19:41:45 | 00,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2008/12/29 19:41:32 | 00,197,259 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2008/12/29 19:40:47 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2008/12/29 19:40:33 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2008/12/29 19:38:37 | 00,000,687 | —- | M] () – C:\WINDOWS\System32\drivers\etc\HOSTS
[2008/12/29 18:25:48 | 00,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2008/12/29 18:19:19 | 00,000,686 | —- | M] () – C:\WINDOWS\System32\drivers\etc\BackupHosts.bak
[2008/12/29 17:57:14 | 01,529,241 | —- | M] () – C:\Documents and Settings\Juan\Desktop\SDFix.exe
[2008/12/29 14:18:30 | 00,000,672 | —- | M] () – C:\Documents and Settings\Juan\Desktop\iPhoneBrowser.lnk
[2008/12/29 14:11:21 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\xkwtwu.dll
[2008/12/29 14:11:21 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\feolotau.dll
[2008/12/29 14:05:25 | 01,308,204 | -HS- | M] () – C:\WINDOWS\System32\uocajtln.ini
[2008/12/29 14:05:21 | 00,072,704 | —- | M] () – C:\WINDOWS\System32\nltjacou.dll
[2008/12/28 22:45:30 | 00,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2008/12/28 22:07:35 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\ziaxsi.dll
[2008/12/28 22:07:35 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\bkuvaaog.dll
[2008/12/28 22:05:19 | 01,306,974 | -HS- | M] () – C:\WINDOWS\System32\mdseagro.ini
[2008/12/26 20:20:08 | 01,745,930 | -HS- | M] () – C:\WINDOWS\System32\drbnbcmt.ini
[2008/12/25 21:44:19 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\yiapmsnd.dll
[2008/12/25 21:44:19 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\cxracc.dll
[2008/12/25 21:40:09 | 01,661,209 | -HS- | M] () – C:\WINDOWS\System32\cnspfmhb.ini
[2008/12/25 03:02:36 | 00,001,604 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2008/12/25 03:01:08 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2008/12/25 02:46:05 | 01,661,209 | -HS- | M] () – C:\WINDOWS\System32\lmatrudu.ini
[2008/12/24 16:57:08 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\lcfweklw.dll
[2008/12/24 16:57:08 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\iczvat.dll
[2008/12/24 11:38:11 | 00,123,952 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2008/12/24 11:38:11 | 00,060,800 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2008/12/24 11:38:11 | 00,010,671 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2008/12/24 11:38:11 | 00,000,805 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2008/12/23 21:20:24 | 01,661,209 | -HS- | M] () – C:\WINDOWS\System32\tecxmgkb.ini
[2008/12/23 21:20:11 | 00,072,704 | —- | M] () – C:\WINDOWS\System32\bkgmxcet.dll
[2008/12/23 21:19:47 | 01,661,209 | -HS- | M] () – C:\WINDOWS\System32\awdfwaob.ini
[2008/12/22 23:23:59 | 00,065,024 | —- | M] () – C:\Documents and Settings\Juan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/22 21:23:11 | 00,038,208 | —- | M] () – C:\Documents and Settings\Juan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2008/12/22 21:17:16 | 00,158,752 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/12/22 21:12:58 | 00,001,716 | —- | M] () – C:\Documents and Settings\All Users\Desktop\PowerCinema NE for Everio.lnk
[2008/12/22 21:07:47 | 00,001,712 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Digital Photo Navigator 1.5.lnk
[2008/12/22 20:48:48 | 00,000,567 | —- | M] () – C:\Documents and Settings\Juan\My Documents\My Sharing Folders.lnk
[2008/12/22 20:34:02 | 01,661,209 | -HS- | M] () – C:\WINDOWS\System32\ruyuigkp.ini
[2008/12/20 15:43:47 | 00,001,632 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Norton 360.lnk
[2008/12/20 14:41:29 | 00,072,704 | —- | M] () – C:\WINDOWS\System32\xwjnompc.dll
[2008/12/19 16:54:44 | 01,661,209 | -HS- | M] () – C:\WINDOWS\System32\sqysdpod.ini
[2008/12/18 16:44:07 | 01,665,243 | -HS- | M] () – C:\WINDOWS\System32\adaetqvu.ini
[2008/12/18 16:41:42 | 01,664,935 | -HS- | M] () – C:\WINDOWS\System32\uumfgden.ini
[2008/12/17 15:29:20 | 01,664,935 | -HS- | M] () – C:\WINDOWS\System32\rmavlrvc.ini
[2008/12/16 21:09:04 | 00,002,193 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Steam.lnk
[2008/12/16 15:16:58 | 01,647,996 | -HS- | M] () – C:\WINDOWS\System32\gikqftaj.ini
[2008/12/14 21:19:04 | 00,023,040 | —- | M] () – C:\Documents and Settings\Juan\My Documents\History Project.doc
[2008/12/14 21:08:25 | 01,647,120 | -HS- | M] () – C:\WINDOWS\System32\dfqtutpk.ini
[2008/12/14 21:03:42 | 01,647,120 | -HS- | M] () – C:\WINDOWS\System32\vsdseufw.ini
[2008/12/13 17:14:34 | 01,647,395 | -HS- | M] () – C:\WINDOWS\System32\ypqnjpff.ini
[2008/12/13 17:10:38 | 01,647,395 | -HS- | M] () – C:\WINDOWS\System32\vejuqlnf.ini
[2008/12/13 16:44:30 | 00,000,889 | —- | M] () – C:\Documents and Settings\Juan\Desktop\Shortcut to left4dead.lnk
[2008/12/13 01:40:02 | 03,593,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.dll
[2008/12/13 01:40:02 | 03,593,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2008/12/11 17:56:19 | 00,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2008/12/11 17:56:19 | 00,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2008/12/11 17:47:53 | 00,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2008/12/11 17:47:53 | 00,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2008/12/11 17:47:48 | 00,002,560 | —- | M] () – C:\WINDOWS\_MSRSTRT.EXE
[2008/12/11 17:27:45 | 00,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2008/12/11 17:27:45 | 00,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2008/12/11 16:54:24 | 00,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2008/12/11 16:54:23 | 00,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2008/12/11 14:15:38 | 01,621,754 | -HS- | M] () – C:\WINDOWS\System32\oidinfrc.ini
[2008/12/11 14:12:24 | 00,302,592 | —- | M] () – C:\WINDOWS\System32\xxyxUkiI.dll
[2008/12/10 21:33:09 | 00,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2008/12/10 21:33:09 | 00,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2008/12/10 21:09:57 | 00,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2008/12/10 21:09:57 | 00,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2008/12/10 20:59:51 | 00,542,580 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2008/12/10 20:59:51 | 00,457,404 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2008/12/10 20:59:51 | 00,077,178 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2008/12/10 20:49:27 | 00,001,787 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2008/12/10 17:00:17 | 00,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2008/12/10 17:00:17 | 00,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2008/12/09 18:51:31 | 00,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2008/12/09 18:51:31 | 00,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2008/12/09 18:24:37 | 17,593,280 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2008/12/09 15:50:54 | 00,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2008/12/09 15:50:54 | 00,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2008/12/08 21:37:56 | 00,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2008/12/08 21:37:56 | 00,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2008/12/08 21:12:37 | 00,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2008/12/08 21:12:37 | 00,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2008/12/07 22:34:17 | 00,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2008/12/07 22:34:17 | 00,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2008/12/07 01:15:49 | 00,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2008/12/07 01:15:49 | 00,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2008/12/02 17:09:33 | 00,000,680 | —- | M] () – C:\Documents and Settings\Juan\Start Menu\Programs\Startup\Webshots.lnk
[2008/12/02 17:09:32 | 00,000,091 | —- | M] () – C:\WINDOWS\webshots.ini
[2008/12/01 12:55:54 | 00,184,320 | —- | M] (InfoSpyware - ForoSpyware) – C:\Documents and Settings\Juan\Desktop\MSNCleaner.exe

========== LOP Check ==========

[2008/12/20 16:03:41 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/12/20 16:03:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/11/20 17:34:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2007/06/26 15:31:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/02/22 09:34:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2008/11/20 17:33:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL Downloads
[2007/09/06 18:15:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL OCP
[2007/08/09 20:32:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2007/08/09 20:33:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/07/22 10:22:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avg8
[2007/09/19 18:05:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2008/12/22 21:12:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2007/08/09 14:23:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2008/10/14 08:04:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IJJIGame
[2008/12/10 20:49:29 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/07/17 22:43:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2007/10/29 14:28:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NVIDIA
[2008/12/24 11:37:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2007/09/14 18:29:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/09/12 18:50:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TVU Networks
[2008/08/12 11:40:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2008/11/20 17:34:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/06/26 19:55:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2007/08/09 14:50:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
[2008/04/02 14:46:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WLInstaller
[2008/12/22 21:23:04 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Juan\Application Data
[2007/09/06 18:15:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\acccore
[2008/03/08 11:46:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\Adobe
[2007/09/06 18:18:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\Aim
[2008/12/22 22:28:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\Any Video Converter
[2008/12/25 13:58:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\Apple Computer
[2007/09/19 18:11:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\Azureus
[2008/12/22 21:23:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\CyberLink
[2007/12/23 13:44:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\Dev-Cpp
[2008/08/31 18:58:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\DNA
[2007/08/09 14:24:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\Google
[2007/10/21 16:46:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\gunz-mrb
[2007/11/18 16:15:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\Help
[2007/06/26 14:31:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\Identities
[2008/11/21 21:24:33 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Juan\Application Data\ijjigame
[2008/10/09 17:44:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\Juce VST Host
[2008/12/16 18:57:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\LimeWire
[2007/06/26 18:58:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\Macromedia
[2008/10/09 19:49:41 | 00,000,000 | –SD | M] – C:\Documents and Settings\Juan\Application Data\Microsoft
[2007/06/26 15:53:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\Microsoft Web Folders
[2008/08/27 19:29:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\Mozilla
[2008/06/10 20:23:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\MySpace
[2008/07/17 22:42:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\NCH Swift Sound
[2008/03/28 14:39:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\Real
[2007/08/24 21:09:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\Sun
[2008/12/20 16:44:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\Symantec
[2008/12/01 17:53:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\SystemRequirementsLab
[2007/08/11 13:12:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\teamspeak2
[2008/09/12 18:50:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\TVU Networks
[2008/08/12 11:34:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\Ulead Systems
[2007/09/09 20:52:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\Ventrilo
[2007/09/06 18:25:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\Viewpoint
[2008/12/10 20:49:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\Windows Desktop Search
[2008/12/16 18:21:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\Windows Search
[2007/08/12 13:36:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Juan\Application Data\WinRAR
[2008/12/25 03:01:08 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2008/12/29 19:45:00 | 00,000,256 | —- | M] () – C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
[2004/08/04 07:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2008/12/29 19:40:47 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> %SystemRoot%\Thumbs.db:encryptable
< End of report >
hello

1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {74FD5B84-0896-40CF-9537-D5DB4A4EC4FD} - C:\WINDOWS\system32\xxyxUkiI.dll ()
O2 - BHO: (no name) - {773704dd-e216-46b2-9a38-ff9cb9cc636a} - C:\WINDOWS\system32\xkwtwu.dll ()
O2 - BHO: (no name) - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKLM\..\Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - Reg Error: Key does not exist or could not be opened. File not found
O4 - HKLM..\Run: [a8ede14f] rundll32.exe "C:\WINDOWS\system32\nltjacou.dll",b ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.




Please download the OTMoveIt3 by OldTimer or from here.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    [HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa]
    "Authentication Packages"=hex(7):6d,00,73,00,76,00,31,00,5f,00,30,00,00,00,00,\
    00
    [-HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0f646cec-23f7-11dc-99b0-806d6172696f}\Shell\AutoRun\command]
    [-HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{efbcfaea-5c2d-11dd-b6ca-0018f3744e56}\Shell\AutoRun\command]
    [-HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\Shell\AutoRun\command]
    
    :files
    C:\WINDOWS\System32\xkwtwu.dll
    C:\WINDOWS\System32\feolotau.dll
    C:\WINDOWS\System32\uocajtln.ini
    C:\WINDOWS\System32\nltjacou.dll
    C:\WINDOWS\System32\ziaxsi.dll
    C:\WINDOWS\System32\bkuvaaog.dll
    C:\WINDOWS\System32\mdseagro.ini
    C:\WINDOWS\System32\drbnbcmt.ini
    C:\WINDOWS\System32\cxracc.dll
    C:\WINDOWS\System32\yiapmsnd.dll
    C:\WINDOWS\System32\cnspfmhb.ini
    C:\WINDOWS\System32\iczvat.dll
    C:\WINDOWS\System32\lcfweklw.dll
    C:\WINDOWS\System32\lmatrudu.ini
    C:\WINDOWS\System32\tecxmgkb.ini
    C:\WINDOWS\System32\bkgmxcet.dll
    C:\WINDOWS\System32\awdfwaob.ini
    C:\WINDOWS\System32\ruyuigkp.ini
    C:\WINDOWS\System32\sqysdpod.ini
    C:\WINDOWS\System32\adaetqvu.ini
    C:\WINDOWS\System32\uumfgden.ini
    C:\WINDOWS\System32\rmavlrvc.ini
    C:\WINDOWS\System32\gikqftaj.ini
    C:\WINDOWS\System32\dfqtutpk.ini
    C:\WINDOWS\System32\vsdseufw.ini
    C:\WINDOWS\System32\ypqnjpff.ini
    C:\WINDOWS\System32\vejuqlnf.ini
    C:\WINDOWS\System32\oidinfrc.ini
    C:\WINDOWS\System32\IikUxyxx.ini2
    C:\WINDOWS\System32\IikUxyxx.ini
    C:\WINDOWS\System32\xxyxUkiI.dll
    C:\WINDOWS\System32\IikUxyxx.ini
    C:\WINDOWS\System32\IikUxyxx.ini2
    C:\WINDOWS\System32\xkwtwu.dll
    C:\WINDOWS\System32\feolotau.dll
    C:\WINDOWS\System32\uocajtln.ini
    C:\WINDOWS\System32\nltjacou.dll
    C:\WINDOWS\System32\ziaxsi.dll
    C:\WINDOWS\System32\bkuvaaog.dll
    C:\WINDOWS\System32\mdseagro.ini
    C:\WINDOWS\System32\drbnbcmt.ini
    C:\WINDOWS\System32\yiapmsnd.dll
    C:\WINDOWS\System32\cxracc.dll
    C:\WINDOWS\System32\cnspfmhb.ini
    C:\WINDOWS\System32\lmatrudu.ini
    C:\WINDOWS\System32\lcfweklw.dll
    C:\WINDOWS\System32\iczvat.dll
    C:\WINDOWS\System32\tecxmgkb.ini
    C:\WINDOWS\System32\bkgmxcet.dll
    C:\WINDOWS\System32\awdfwaob.ini
    C:\WINDOWS\System32\ruyuigkp.ini
    C:\WINDOWS\System32\xwjnompc.dll
    C:\WINDOWS\System32\sqysdpod.ini
    C:\WINDOWS\System32\adaetqvu.ini
    C:\WINDOWS\System32\uumfgden.ini
    C:\WINDOWS\System32\rmavlrvc.ini
    C:\WINDOWS\System32\gikqftaj.ini
    C:\WINDOWS\System32\dfqtutpk.ini
    C:\WINDOWS\System32\vsdseufw.ini
    C:\WINDOWS\System32\ypqnjpff.ini
    C:\WINDOWS\System32\vejuqlnf.ini
    C:\WINDOWS\System32\oidinfrc.ini
    C:\WINDOWS\System32\xxyxUkiI.dll
    C:\WINDOWS\System32\xsusingf.dll
    C:\WINDOWS\System32\uvqteada.dll
    C:\WINDOWS\System32\tmcbnbrd.dll
    C:\WINDOWS\System32\oegrjj.dll
    C:\WINDOWS\System32\novclnsr.dll
    C:\WINDOWS\System32\fvprjaqv.dll
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




Open OTListIt2.exe
  • Click the None button at the top
  • Under the Custom Scan box at the bottom left paste the following in

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg
    %systemroot%\Prefetch\*.* /s
    %systemroot%\system32\drivers\*.dat
    %systemroot%\Temp\bca4e2da.$$$
    %systemroot%\Temp\ed47fa.$
    %systemroot%\Temp\fa56d7ec.$$$
    %systemroot%\Temp\*.$$$
    %systemroot%\System32\antiwpa.dll
    %SYSTEMDRIVE%\*.epk
    %systemroot%\*.epk
    %systemroot%\system32\*.epk
    %systemroot%\system32\bb*.dat
    %systemroot%\system32\cookie*.dat
    %systemroot%\system32\kaxs.dat
    %systemroot%\system32\ps*.dat
    %systemroot%\system32\*32.sys
    %systemroot%\*.dr
    %SYSTEMDRIVE%\*.dr
    %systemroot%\system32\*.dr
    %systemroot%\system32\nods32.dll
    %systemroot%\*.res
    %SYSTEMDRIVE%\*.res
    %systemroot%\system32\*.res
    %systemroot%\system32\sockins32.dll
    %systemroot%\system32\Spool\*.*
    %systemroot%\system32\Spool\*.exe
    %systemroot%\system32\Spool\*.rar /s
    %systemroot%\system32\Spool\*.zip /s
    %systemroot%\system32\Spool\*.dat /s
    %ProgramFiles%\MSN Messenger\*.zip
    %ProgramFiles%\MSN Messenger\*.exe
    %ProgramFiles%\MSN Messenger\*.rar
    %PROGRAMFILES%\*crack*.
    %PROGRAMFILES%\*keygen*.
    %SYSTEMDRIVE%\*crack*.
    %SYSTEMDRIVE%\*keygen*.
    %SYSTEMDRIVE%\*.zip
    %SYSTEMDRIVE%\*.rar
    %SYSTEMDRIVE%\*.exe
    %SYSTEMDRIVE%\*.dll
    %systemroot%\*.zip
    %systemroot%\*.rar
    %systemroot%\system32\*.zip
    %systemroot%\system32\*.rar
    %PROGRAMFILES%\*.zip
    %PROGRAMFILES%\*.rar
    %PROGRAMFILES%\*.exe
    %PROGRAMFILES%\*.dll
    %DESKTOP%\*.zip
    %DESKTOP%\*.rar
    %DESKTOP%\*.exe
    %DESKTOP%\*crack*.
    %DESKTOP%\*keygen*.
    %PROGRAMFILES%\Common Files\*.*
    %PROGRAMFILES%\Common Files\*bak*.
    %systemroot%\SYSTEM32\*bak*.
    %PROGRAMFILES%\*bak*.
    %systemroot%\ime\imjp8_1\*bak*.
    %PROGRAMFILES%\QuickTime\*bak*.
    %PROGRAMFILES%\Viewpoint\Viewpoint Manager\*bak*.
    %PROGRAMFILES%\Analog Devices\Core\*bak*.
    %SYSTEMDRIVE%\hp\KBD\*bak*.
    %PROGRAMFILES%\Adobe\Photoshop Album Starter Edition\3.2\Apps\*bak*.
    %PROGRAMFILES%\BillP Studios\WinPatrol\*bak*.
    %PROGRAMFILES%\BroadJump\Client Foundation\*bak*.
    %PROGRAMFILES%\Common Files\Real\Update_OB\*bak*.
    %PROGRAMFILES%\Common Files\Sonic\Update Manager\*bak*.
    %PROGRAMFILES%\\Google\GoogleToolbarNotifier\*bak*.
    %PROGRAMFILES%\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\*bak*.
    %PROGRAMFILES%\Yahoo!\Messenger\*bak*.
    %USERNAME%\*.zip
    %USERNAME%\*.rar
    %USERNAME%\*.exe
    %USERPROFILE%\*.zip
    %USERPROFILE%\*.rar
    %USERPROFILE%\*.exe
    %ALLUSERSPROFILE%\*.zip
    %ALLUSERSPROFILE%\*.rar
    %ALLUSERSPROFILE%\*.exe
    %APPDATA%\*.zip
    %APPDATA%\*.rar
    %APPDATA%\*.exe
    %ALLUSERSSTARTMENU%\*.zip
    %ALLUSERSSTARTMENU%\*.rar
    %ALLUSERSSTARTMENU%\*.exe
    %ALLUSERSSTARTUP%\*.zip
    %ALLUSERSSTARTUP%\*.rar
    %ALLUSERSSTARTUP%\*.exe
    %ALLUSERSPROGRAMS%\*.zip
    %ALLUSERSPROGRAMS%\*.rar
    %ALLUSERSPROGRAMS%\*.exe
    %ALLUSERSAPPDATA%\*.zip
    %ALLUSERSAPPDATA%\*.rar
    %ALLUSERSAPPDATA%\*.exe
    %APPDATA%\*.zip
    %APPDATA%\*.rar
    %APPDATA%\*.exe
    %APPDATA%\*.dat
    %APPDATA%\*.dll
    %QUICKLAUNCH%\*.zip
    %QUICKLAUNCH%\*.rar
    %QUICKLAUNCH%\*.exe
    %STARTUP%\*.zip
    %STARTUP%\*.rar
    %STARTUP%\*.exe
    %STARTMENU%\*.zip
    %STARTMENU%\*.rar
    %STARTMENU%\*.exe
    %MYDOCUMENTS%\*.zip
    %MYDOCUMENTS%\*.rar
    %MYDOCUMENTS%\*.exe
    %MYDOCUMENTS%\*crack*.
    %MYDOCUMENTS%\*keygen*.
    %PROGRAMFILES%\Mozilla Firefox\plugins\*.*
    %PROGRAMFILES%\Internet Explorer\*.*
    %PROGRAMFILES%\Internet Explorer\PLUGINS\*.*
    %PROGRAMFILES%\Mozilla Firefox\*.zip /s
    %PROGRAMFILES%\Mozilla Firefox\*.rar /s
    %PROGRAMFILES%\Mozilla Firefox\*.exe /s
    %PROGRAMFILES%\Internet Explorer\*.zip /s
    %PROGRAMFILES%\Internet Explorer\*.rar /s
    %PROGRAMFILES%\Internet Explorer\*.exe /s
    %SYSTEMDRIVE%\*.dat
    %SYSTEMDRIVE%\*.sys
    %SYSTEMROOT%\*.dat
    %SYSTEMROOT%\*.sys
    %systemroot%\system32\drivers\*.exe /s
    %systemroot%\system32\drivers\*.zip /s
    %systemroot%\system32\drivers\*.rar /s
    %systemroot%\system\*.exe /s
    %systemroot%\system\*.zip /s
    %systemroot%\system\*.rar /s
    %systemroot%\AppPatch\*.exe /s
    %systemroot%\AppPatch\*.zip /s
    %systemroot%\AppPatch\*.rar /s
    %systemroot%\Cache\*.*
    %systemroot%\Downloaded Program Files\*.*
    %systemroot%\Fonts\*.exe /s
    %systemroot%\Fonts\*.zip /s
    %systemroot%\Fonts\*.rar /s
    %systemroot%\Fonts\*.dll /s
    %systemroot%\Help\*.exe /s
    %systemroot%\Help\*.zip /s
    %systemroot%\Help\*.rar /s
    %systemroot%\Tasks\*.*
    %APPDATA%\*.sys
    %APPDATA%\Google\*.*
    %systemroot%\system32\serauth1.dll
    %systemroot%\system32\serauth2.dll
    %systemroot%\system32\sysaudio.sys
    %PROGRAMFILES%\*TinyProxy*.
    HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla|extensions /rs
    %systemroot%\system32\inf\*.exe /s
    %systemroot%\system32\inf\*.zip /s
    %systemroot%\system32\inf\*.rar /s
    %systemroot%\system32\inf\*.dll /s
    %PROGRAMFILES%\Bitlord\Downloads\*.zip /s
    %PROGRAMFILES%\Bitlord\Downloads\*.rar /s
    %PROGRAMFILES%\Bitlord\Downloads\*.exe /s
    %PROGRAMFILES%\Bitlord\Downloads\*crack*.
    %PROGRAMFILES%\Bitlord\Downloads\*keygen*.
    %PROGRAMFILES%\eMule\Incoming\*.zip /s
    %PROGRAMFILES%\eMule\Incoming\*.rar /s
    %PROGRAMFILES%\eMule\Incoming\*.exe /s
    %PROGRAMFILES%\eMule\Incoming\*crack*.
    %PROGRAMFILES%\eMule\Incoming\*keygen*.
    %ProgramFiles%\Bittorent\downloads\*.zip /s
    %ProgramFiles%\Bittorent\downloads\*.exe /s
    %ProgramFiles%\Bittorent\downloads\*.rar /s
    %PROGRAMFILES%\Bittorent\Downloads\*crack*.
    %PROGRAMFILES%\Bittorent\Downloads\*keygen*.
    %ProgramFiles%\Bearshare\Shared\*.zip /s
    %ProgramFiles%\Bearshare\Shared\*.exe /s
    %ProgramFiles%\Bearshare\Shared\*.rar /s
    %ProgramFiles%\Bearshare\Shared\*crack*.
    %ProgramFiles%\Bearshare\Shared\*keygen*.
    %ProgramFiles%\Morpheus\My Shared Folder\*.zip /s
    %ProgramFiles%\Morpheus\My Shared Folder\*.exe /s
    %ProgramFiles%\Morpheus\My Shared Folder\*.rar /s
    %ProgramFiles%\Morpheus\My Shared Folder\*crack*.
    %ProgramFiles%\Morpheus\My Shared Folder\*keygen*.
    %ProgramFiles%\uTorrent\Downloads\*.zip /s
    %ProgramFiles%\uTorrent\Downloads\*.exe /s
    %ProgramFiles%\uTorrent\Downloads\*.rar /s
    %ProgramFiles%\uTorrent\Downloads\*crack*.
    %ProgramFiles%\uTorrent\Downloads\*keygen*.
    %ProgramFiles%\Kazaa Lite\My Shared Folder\*.zip /s
    %ProgramFiles%\Kazaa Lite\My Shared Folder\*.exe /s
    %ProgramFiles%\Kazaa Lite\My Shared Folder\*.rar /s
    %ProgramFiles%\Kazaa Lite\My Shared Folder\*crack*.
    %ProgramFiles%\Kazaa Lite\My Shared Folder\*keygen*.
    %ProgramFiles%\Kazaa\My Shared Folder\*.zip /s
    %ProgramFiles%\Kazaa\My Shared Folder\*.exe /s
    %ProgramFiles%\Kazaa\My Shared Folder\*.rar /s
    %ProgramFiles%\Kazaa\My Shared Folder\*crack*.
    %ProgramFiles%\Kazaa\My Shared Folder\*keygen*.
    %ProgramFiles%\Icq\Shared Files\*.zip /s
    %ProgramFiles%\Icq\Shared Files\*.exe /s
    %ProgramFiles%\Icq\Shared Files\*.rar /s
    %ProgramFiles%\Icq\Shared Files\*crack*.
    %ProgramFiles%\Icq\Shared Files\*keygen*.
    %ProgramFiles%\Direct Connect\Received Files\*.zip /s
    %ProgramFiles%\Direct Connect\Received Files\*.exe /s
    %ProgramFiles%\Direct Connect\Received Files\*.rar /s
    %ProgramFiles%\Direct Connect\Received Files\*crack*.
    %ProgramFiles%\Direct Connect\Received Files\*keygen*.
    %ALLUSERSPROFILE%\Application Data\AOL Downloads\*.zip
    %ALLUSERSPROFILE%\Application Data\AOL Downloads\*.rar
    %ALLUSERSPROFILE%\Application Data\AOL Downloads\*.exe
    %ALLUSERSPROFILE%\Application Data\AOL Downloads\*crack*.
    %ALLUSERSPROFILE%\Application Data\AOL Downloads\*keygen*.
    %APPDATA%\Opera\Opera\profile\widgets\*.*
    %PROGRAMFILES%\Opera\program\plugins\*.* /s
    %APPDATA%\Opera\Opera\profile\toolbar\*.* /s


  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open a notepad window called OTListIt.Txt. This saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the content of this file, and post it with your next reply.
heres the otmoveit log ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\\"Authentication Packages"|hex(7):6d,00,73,00,76,00,31,00,5f,00,30,00,00,00,00,00 /E : value set successfully! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0f646cec-23f7-11dc-99b0-806d6172696f}\Shell\AutoRun\command\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{efbcfaea-5c2d-11dd-b6ca-0018f3744e56}\Shell\AutoRun\command\\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\Shell\AutoRun\command\\ deleted successfully. ========== FILES ========== DllUnregisterServer procedure not found in C:\WINDOWS\System32\xkwtwu.dll C:\WINDOWS\System32\xkwtwu.dll NOT unregistered. C:\WINDOWS\System32\xkwtwu.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\feolotau.dll C:\WINDOWS\System32\feolotau.dll NOT unregistered. C:\WINDOWS\System32\feolotau.dll moved successfully. C:\WINDOWS\System32\uocajtln.ini moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\nltjacou.dll C:\WINDOWS\System32\nltjacou.dll NOT unregistered. C:\WINDOWS\System32\nltjacou.dll moved successfully. LoadLibrary failed for C:\WINDOWS\System32\ziaxsi.dll C:\WINDOWS\System32\ziaxsi.dll NOT unregistered. File move failed. C:\WINDOWS\System32\ziaxsi.dll scheduled to be moved on reboot. LoadLibrary failed for C:\WINDOWS\System32\bkuvaaog.dll C:\WINDOWS\System32\bkuvaaog.dll NOT unregistered. File move failed. C:\WINDOWS\System32\bkuvaaog.dll scheduled to be moved on reboot. C:\WINDOWS\System32\mdseagro.ini moved successfully. C:\WINDOWS\System32\drbnbcmt.ini moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\cxracc.dll C:\WINDOWS\System32\cxracc.dll NOT unregistered. C:\WINDOWS\System32\cxracc.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\yiapmsnd.dll C:\WINDOWS\System32\yiapmsnd.dll NOT unregistered. C:\WINDOWS\System32\yiapmsnd.dll moved successfully. C:\WINDOWS\System32\cnspfmhb.ini moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\iczvat.dll C:\WINDOWS\System32\iczvat.dll NOT unregistered. C:\WINDOWS\System32\iczvat.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\lcfweklw.dll C:\WINDOWS\System32\lcfweklw.dll NOT unregistered. C:\WINDOWS\System32\lcfweklw.dll moved successfully. C:\WINDOWS\System32\lmatrudu.ini moved successfully. C:\WINDOWS\System32\tecxmgkb.ini moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\bkgmxcet.dll C:\WINDOWS\System32\bkgmxcet.dll NOT unregistered. C:\WINDOWS\System32\bkgmxcet.dll moved successfully. C:\WINDOWS\System32\awdfwaob.ini moved successfully. C:\WINDOWS\System32\ruyuigkp.ini moved successfully. C:\WINDOWS\System32\sqysdpod.ini moved successfully. C:\WINDOWS\System32\adaetqvu.ini moved successfully. C:\WINDOWS\System32\uumfgden.ini moved successfully. C:\WINDOWS\System32\rmavlrvc.ini moved successfully. C:\WINDOWS\System32\gikqftaj.ini moved successfully. C:\WINDOWS\System32\dfqtutpk.ini moved successfully. C:\WINDOWS\System32\vsdseufw.ini moved successfully. C:\WINDOWS\System32\ypqnjpff.ini moved successfully. C:\WINDOWS\System32\vejuqlnf.ini moved successfully. C:\WINDOWS\System32\oidinfrc.ini moved successfully. C:\WINDOWS\System32\IikUxyxx.ini2 moved successfully. C:\WINDOWS\System32\IikUxyxx.ini moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\xxyxUkiI.dll C:\WINDOWS\System32\xxyxUkiI.dll NOT unregistered. C:\WINDOWS\System32\xxyxUkiI.dll moved successfully. File/Folder C:\WINDOWS\System32\IikUxyxx.ini not found. File/Folder C:\WINDOWS\System32\IikUxyxx.ini2 not found. File/Folder C:\WINDOWS\System32\xkwtwu.dll not found. File/Folder C:\WINDOWS\System32\feolotau.dll not found. File/Folder C:\WINDOWS\System32\uocajtln.ini not found. File/Folder C:\WINDOWS\System32\nltjacou.dll not found. File/Folder C:\WINDOWS\System32\ziaxsi.dll not found. File/Folder C:\WINDOWS\System32\bkuvaaog.dll not found. File/Folder C:\WINDOWS\System32\mdseagro.ini not found. File/Folder C:\WINDOWS\System32\drbnbcmt.ini not found. File/Folder C:\WINDOWS\System32\yiapmsnd.dll not found. File/Folder C:\WINDOWS\System32\cxracc.dll not found. File/Folder C:\WINDOWS\System32\cnspfmhb.ini not found. File/Folder C:\WINDOWS\System32\lmatrudu.ini not found. File/Folder C:\WINDOWS\System32\lcfweklw.dll not found. File/Folder C:\WINDOWS\System32\iczvat.dll not found. File/Folder C:\WINDOWS\System32\tecxmgkb.ini not found. File/Folder C:\WINDOWS\System32\bkgmxcet.dll not found. File/Folder C:\WINDOWS\System32\awdfwaob.ini not found. File/Folder C:\WINDOWS\System32\ruyuigkp.ini not found. LoadLibrary failed for C:\WINDOWS\System32\xwjnompc.dll C:\WINDOWS\System32\xwjnompc.dll NOT unregistered. C:\WINDOWS\System32\xwjnompc.dll moved successfully. File/Folder C:\WINDOWS\System32\sqysdpod.ini not found. File/Folder C:\WINDOWS\System32\adaetqvu.ini not found. File/Folder C:\WINDOWS\System32\uumfgden.ini not found. File/Folder C:\WINDOWS\System32\rmavlrvc.ini not found. File/Folder C:\WINDOWS\System32\gikqftaj.ini not found. File/Folder C:\WINDOWS\System32\dfqtutpk.ini not found. File/Folder C:\WINDOWS\System32\vsdseufw.ini not found. File/Folder C:\WINDOWS\System32\ypqnjpff.ini not found. File/Folder C:\WINDOWS\System32\vejuqlnf.ini not found. File/Folder C:\WINDOWS\System32\oidinfrc.ini not found. File/Folder C:\WINDOWS\System32\xxyxUkiI.dll not found. File/Folder C:\WINDOWS\System32\xsusingf.dll not found. File/Folder C:\WINDOWS\System32\uvqteada.dll not found. File/Folder C:\WINDOWS\System32\tmcbnbrd.dll not found. File/Folder C:\WINDOWS\System32\oegrjj.dll not found. File/Folder C:\WINDOWS\System32\novclnsr.dll not found. File/Folder C:\WINDOWS\System32\fvprjaqv.dll not found. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\Juan\LOCALS~1\Temp\etilqs_yPfx1htpSsoKcDgebRS8 scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\JETB006.tmp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_6f4.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\Juan\Local Settings\Application Data\Mozilla\Firefox\Profiles\deabvizf.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Juan\Local Settings\Application Data\Mozilla\Firefox\Profiles\deabvizf.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Juan\Local Settings\Application Data\Mozilla\Firefox\Profiles\deabvizf.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Juan\Local Settings\Application Data\Mozilla\Firefox\Profiles\deabvizf.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Juan\Local Settings\Application Data\Mozilla\Firefox\Profiles\deabvizf.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Juan\Local Settings\Application Data\Mozilla\Firefox\Profiles\deabvizf.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12292008_203347 Files moved on Reboot… File C:\WINDOWS\System32\ziaxsi.dll not found! File C:\WINDOWS\System32\bkuvaaog.dll not found! File C:\DOCUME~1\Juan\LOCALS~1\Temp\etilqs_yPfx1htpSsoKcDgebRS8 not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File C:\WINDOWS\temp\JETB006.tmp not found! File C:\WINDOWS\temp\Perflib_Perfdata_6f4.dat not found! C:\Documents and Settings\Juan\Local Settings\Application Data\Mozilla\Firefox\Profiles\deabvizf.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\Juan\Local Settings\Application Data\Mozilla\Firefox\Profiles\deabvizf.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\Juan\Local Settings\Application Data\Mozilla\Firefox\Profiles\deabvizf.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\Juan\Local Settings\Application Data\Mozilla\Firefox\Profiles\deabvizf.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\Juan\Local Settings\Application Data\Mozilla\Firefox\Profiles\deabvizf.default\urlclassifier3.sqlite moved successfully. C:\Documents and Settings\Juan\Local Settings\Application Data\Mozilla\Firefox\Profiles\deabvizf.default\XUL.mfl moved successfully.
heres the otlist


OTListIt logfile created on: 12/29/2008 8:44:52 PM - Run 3
OTListIt2 by OldTimer - Version 1.0.1.1 Folder = C:\Documents and Settings\Juan\My Documents\windows help thing
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1023.17 Mb Total Physical Memory | 541.92 Mb Available Physical Memory | 52.96% Memory free
2.40 Gb Paging File | 1.97 Gb Available in Paging File | 82.09% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 253.22 Gb Free Space | 84.95% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 583.05 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOME-01D49B7F63
Current User Name: Juan
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Custom Scans ==========


< HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services >

< HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg >

< %systemroot%\Prefetch\*.* /s >
[2008/12/29 20:16:27 | 00,069,494 | —- | M] () – C:\WINDOWS\Prefetch\ADOBECOLLABSYNC.EXE-26E90E96.pf
[2008/12/29 20:16:27 | 00,023,388 | —- | M] () – C:\WINDOWS\Prefetch\ALG.EXE-0F138680.pf
[2008/12/29 20:30:04 | 00,050,894 | —- | M] () – C:\WINDOWS\Prefetch\AUPDATE.EXE-2253CB60.pf
[2008/12/29 20:38:33 | 00,011,276 | —- | M] () – C:\WINDOWS\Prefetch\CCAPP.EXE-1207B2A5.pf
[2008/12/29 20:38:33 | 00,042,068 | —- | M] () – C:\WINDOWS\Prefetch\CCSVCHST.EXE-1821FA3A.pf
[2008/12/29 18:33:03 | 00,012,572 | —- | M] () – C:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf
[2008/12/29 20:11:51 | 00,024,968 | —- | M] () – C:\WINDOWS\Prefetch\CONTROL.EXE-013DBFB5.pf
[2008/12/29 18:56:30 | 00,009,132 | —- | M] () – C:\WINDOWS\Prefetch\CTFMON.EXE-0E17969B.pf
[2008/12/29 17:27:13 | 00,043,424 | —- | M] () – C:\WINDOWS\Prefetch\DRWTSN32.EXE-2B4B52AC.pf
[2008/12/29 19:06:06 | 00,014,612 | —- | M] () – C:\WINDOWS\Prefetch\DUMPREP.EXE-1B46F901.pf
[2008/12/29 20:16:47 | 00,079,052 | —- | M] () – C:\WINDOWS\Prefetch\DWWIN.EXE-30875ADC.pf
[2008/12/29 20:38:33 | 00,025,208 | —- | M] () – C:\WINDOWS\Prefetch\EVERIOSERVICE.EXE-11844926.pf
[2008/12/29 20:34:41 | 00,089,526 | —- | M] () – C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf
[2008/12/29 20:39:04 | 00,120,882 | —- | M] () – C:\WINDOWS\Prefetch\FIREFOX.EXE-28641590.pf
[2008/12/29 17:43:35 | 00,089,794 | —- | M] () – C:\WINDOWS\Prefetch\GAMEOVERLAYUI.EXE-1A46F21E.pf
[2008/12/29 18:56:28 | 00,018,884 | —- | M] () – C:\WINDOWS\Prefetch\GOOGLETOOLBARNOTIFIER.EXE-3629C61D.pf
[2008/12/29 20:38:33 | 00,015,168 | —- | M] () – C:\WINDOWS\Prefetch\HDASHCUT.EXE-1B000CA9.pf
[2008/12/29 20:30:53 | 00,059,266 | —- | M] () – C:\WINDOWS\Prefetch\HIJACKTHIS.EXE-34A0FC79.pf
[2008/12/29 20:17:44 | 00,075,656 | —- | M] () – C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf
[2008/12/29 20:38:33 | 00,063,012 | —- | M] () – C:\WINDOWS\Prefetch\IMAPI.EXE-0BF740A4.pf
[2008/12/29 20:38:34 | 00,018,920 | —- | M] () – C:\WINDOWS\Prefetch\IPODSERVICE.EXE-3192DE38.pf
[2008/12/29 20:43:14 | 00,078,318 | —- | M] () – C:\WINDOWS\Prefetch\JUCHECK.EXE-18E816EF.pf
[2008/12/29 20:38:33 | 00,011,008 | —- | M] () – C:\WINDOWS\Prefetch\JUSCHED.EXE-2A2A434F.pf
[2008/12/29 18:42:17 | 00,574,468 | —- | M] () – C:\WINDOWS\Prefetch\Layout.ini
[2008/12/29 17:43:20 | 00,073,528 | —- | M] () – C:\WINDOWS\Prefetch\LEFT4DEAD.EXE-05762C39.pf
[2008/12/29 20:35:33 | 00,097,738 | —- | M] () – C:\WINDOWS\Prefetch\LOGONUI.EXE-0AF22957.pf
[2008/12/29 20:30:07 | 00,074,492 | —- | M] () – C:\WINDOWS\Prefetch\LUCALLBACKPROXY.EXE-19ED7806.pf
[2008/12/29 20:30:12 | 00,067,714 | —- | M] () – C:\WINDOWS\Prefetch\LUCOMSERVER_3_4.EXE-2CA41E19.pf
[2008/12/29 20:12:14 | 00,018,788 | —- | M] () – C:\WINDOWS\Prefetch\MAINSTUB.EXE-0B829DCE.pf
[2008/12/29 20:12:53 | 00,020,818 | —- | M] () – C:\WINDOWS\Prefetch\MDM.EXE-07915C2C.pf
[2008/12/29 20:12:44 | 00,076,958 | —- | M] () – C:\WINDOWS\Prefetch\MMC.EXE-04EF131A.pf
[2008/12/29 17:23:00 | 00,086,334 | —- | M] () – C:\WINDOWS\Prefetch\MOVIEMK.EXE-08CCF9FE.pf
[2008/12/29 19:45:01 | 00,026,668 | —- | M] () – C:\WINDOWS\Prefetch\MSNTBUP.EXE-0D913FB9.pf
[2008/12/29 20:38:33 | 00,007,792 | —- | M] () – C:\WINDOWS\Prefetch\NEROCHECK.EXE-092C6DFA.pf
[2008/12/29 20:38:33 | 00,020,988 | —- | M] () – C:\WINDOWS\Prefetch\NOTEPAD.EXE-189578DA.pf
[2008/12/29 20:42:44 | 00,020,612 | —- | M] () – C:\WINDOWS\Prefetch\NOTEPAD.EXE-336351A9.pf
[2008/12/29 20:38:33 | 01,462,358 | —- | M] () – C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf
[2008/12/29 18:56:19 | 00,032,180 | —- | M] () – C:\WINDOWS\Prefetch\NWIZ.EXE-2D0F9FBC.pf
[2008/12/29 20:38:34 | 00,063,860 | —- | M] () – C:\WINDOWS\Prefetch\OLFSNT40.EXE-10D30C8A.pf
[2008/12/29 20:38:33 | 00,061,638 | —- | M] () – C:\WINDOWS\Prefetch\OSA9.EXE-27CD7DB8.pf
[2008/12/29 20:38:33 | 00,011,920 | —- | M] () – C:\WINDOWS\Prefetch\OSCHECK.EXE-0479CA67.pf
[2008/12/29 19:52:00 | 00,020,802 | —- | M] () – C:\WINDOWS\Prefetch\OTLISTIT2.EXE-18038DB9.pf
[2008/12/29 20:43:57 | 00,016,092 | —- | M] () – C:\WINDOWS\Prefetch\OTLISTIT2.EXE-31D52F0F.pf
[2008/12/29 20:38:33 | 00,032,868 | —- | M] () – C:\WINDOWS\Prefetch\OTMOVEIT3.EXE-075994D5.pf
[2008/12/29 20:38:33 | 00,014,200 | —- | M] () – C:\WINDOWS\Prefetch\PDVDSERV.EXE-0448293E.pf
[2008/12/29 20:35:21 | 00,073,350 | —- | M] () – C:\WINDOWS\Prefetch\PIFCRAWL.EXE-32801D5D.pf
[2008/12/29 20:38:33 | 00,008,366 | —- | M] () – C:\WINDOWS\Prefetch\QTTASK.EXE-342507FB.pf
[2008/12/29 20:16:27 | 00,153,916 | —- | M] () – C:\WINDOWS\Prefetch\READER_SL.EXE-1A438403.pf
[2008/12/29 20:38:33 | 00,018,184 | —- | M] () – C:\WINDOWS\Prefetch\REALSCHED.EXE-3282FD31.pf
[2008/12/29 20:38:33 | 00,029,216 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-1340EF7F.pf
[2008/12/29 20:26:47 | 00,022,064 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-13C92FA8.pf
[2008/12/29 20:10:51 | 00,048,512 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-1619A94E.pf
[2008/12/29 20:11:43 | 00,045,154 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-1831A4F3.pf
[2008/12/29 17:50:20 | 00,040,446 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-2E5AF1D7.pf
[2008/12/29 20:10:51 | 00,040,616 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-35A483DA.pf
[2008/12/29 18:56:22 | 00,030,372 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-415F88EC.pf
[2008/12/29 20:42:50 | 00,020,304 | —- | M] () – C:\WINDOWS\Prefetch\SEARCHFILTERHOST.EXE-148579FB.pf
[2008/12/29 20:10:51 | 00,005,044 | —- | M] () – C:\WINDOWS\Prefetch\SEARCHINDEXER.EXE-1AD3307F.pf
[2008/12/29 20:42:50 | 00,027,796 | —- | M] () – C:\WINDOWS\Prefetch\SEARCHPROTOCOLHOST.EXE-34E0253A.pf
[2008/12/29 14:22:25 | 00,111,678 | —- | M] () – C:\WINDOWS\Prefetch\SSAUTORN.EXE-0B474C29.pf
[2008/12/29 20:38:33 | 00,029,488 | —- | M] () – C:\WINDOWS\Prefetch\STEAM.EXE-15609EA3.pf
[2008/12/29 20:16:28 | 00,015,712 | —- | M] () – C:\WINDOWS\Prefetch\SVCHOST.EXE-3530F672.pf
[2008/12/29 20:30:13 | 00,014,746 | —- | M] () – C:\WINDOWS\Prefetch\SYMLCSV1.EXE-0EE21BE3.pf
[2008/12/28 17:30:59 | 00,032,216 | —- | M] () – C:\WINDOWS\Prefetch\SYMLCSV1.EXE-1C46CA2A.pf
[2008/12/29 20:30:22 | 00,047,874 | —- | M] () – C:\WINDOWS\Prefetch\SYMLCSVC.EXE-0360BE30.pf
[2008/12/29 20:20:05 | 00,057,392 | —- | M] () – C:\WINDOWS\Prefetch\UPDATE.EXE-14D90895.pf
[2008/12/29 20:38:33 | 00,021,678 | —- | M] () – C:\WINDOWS\Prefetch\VERCLSID.EXE-3667BD89.pf
[2008/12/29 20:38:33 | 00,087,056 | —- | M] () – C:\WINDOWS\Prefetch\VIEWMGR.EXE-1E800BBC.pf
[2008/12/29 20:38:34 | 00,020,060 | —- | M] () – C:\WINDOWS\Prefetch\WEBSHOTSTRAY.EXE-13293109.pf
[2008/12/28 17:30:16 | 00,085,732 | —- | M] () – C:\WINDOWS\Prefetch\WGATRAY.EXE-0ED38BED.pf
[2008/12/29 20:38:34 | 00,050,006 | —- | M] () – C:\WINDOWS\Prefetch\WINDOWSSEARCH.EXE-20C0F767.pf
[2008/12/29 19:19:27 | 00,049,486 | —- | M] () – C:\WINDOWS\Prefetch\WINRAR.EXE-39C6DAD9.pf
[2008/12/29 20:18:08 | 00,081,662 | —- | M] () – C:\WINDOWS\Prefetch\WLLOGINPROXY.EXE-1781D844.pf
[2008/12/29 20:30:55 | 00,034,482 | —- | M] () – C:\WINDOWS\Prefetch\WMIPRVSE.EXE-28F301A9.pf
[2008/12/29 19:07:06 | 00,058,924 | —- | M] () – C:\WINDOWS\Prefetch\WMPLAYER.EXE-18DDEFA2.pf
[2008/12/29 20:10:53 | 00,016,364 | —- | M] () – C:\WINDOWS\Prefetch\WSCNTFY.EXE-1B24F5EB.pf
[2008/12/29 20:16:38 | 00,077,126 | —- | M] () – C:\WINDOWS\Prefetch\WUAUCLT.EXE-399A8E72.pf

< %systemroot%\system32\drivers\*.dat >

< %systemroot%\Temp\bca4e2da.$$$ >

< %systemroot%\Temp\ed47fa.$ >

< %systemroot%\Temp\fa56d7ec.$$$ >

< %systemroot%\Temp\*.$$$ >

< %systemroot%\System32\antiwpa.dll >

< %SYSTEMDRIVE%\*.epk >

< %systemroot%\*.epk >

< %systemroot%\system32\*.epk >

< %systemroot%\system32\bb*.dat >

< %systemroot%\system32\cookie*.dat >

< %systemroot%\system32\kaxs.dat >

< %systemroot%\system32\ps*.dat >

< %systemroot%\system32\*32.sys >

< %systemroot%\*.dr >

< %SYSTEMDRIVE%\*.dr >

< %systemroot%\system32\*.dr >

< %systemroot%\system32\nods32.dll >

< %systemroot%\*.res >

< %SYSTEMDRIVE%\*.res >

< %systemroot%\system32\*.res >

< %systemroot%\system32\sockins32.dll >

< %systemroot%\system32\Spool\*.* >

< %systemroot%\system32\Spool\*.exe >

< %systemroot%\system32\Spool\*.rar /s >

< %systemroot%\system32\Spool\*.zip /s >

< %systemroot%\system32\Spool\*.dat /s >

< %ProgramFiles%\MSN Messenger\*.zip >

< %ProgramFiles%\MSN Messenger\*.exe >

< %ProgramFiles%\MSN Messenger\*.rar >

< %PROGRAMFILES%\*crack*. >
[2008/12/29 15:14:47 | 00,000,000 | R–D | M] – C:\Program Files

< %PROGRAMFILES%\*keygen*. >
[2008/12/29 15:14:47 | 00,000,000 | R–D | M] – C:\Program Files

< %SYSTEMDRIVE%\*crack*. >
[2008/12/29 20:43:42 | 00,000,000 | —D | M] – C:

< %SYSTEMDRIVE%\*keygen*. >
[2008/12/29 20:43:42 | 00,000,000 | —D | M] – C:

< %SYSTEMDRIVE%\*.zip >

< %SYSTEMDRIVE%\*.rar >
[2007/06/26 15:29:58 | 04,368,106 | —- | M] () – C:\lan.rar

< %SYSTEMDRIVE%\*.exe >

< %SYSTEMDRIVE%\*.dll >

< %systemroot%\*.zip >

< %systemroot%\*.rar >

< %systemroot%\system32\*.zip >

< %systemroot%\system32\*.rar >

< %PROGRAMFILES%\*.zip >

< %PROGRAMFILES%\*.rar >

< %PROGRAMFILES%\*.exe >
[2004/07/09 03:08:36 | 00,472,576 | —- | M] (Microsoft Corporation) – C:\Program Files\dxsetup.exe

< %PROGRAMFILES%\*.dll >
[2004/07/09 02:03:10 | 00,062,976 | —- | M] (Microsoft Corporation) – C:\Program Files\DSETUP.dll
[2004/07/09 03:08:34 | 02,242,560 | —- | M] (Microsoft Corporation) – C:\Program Files\dsetup32.dll

Invalid Environment Variable: DESKTOP

Invalid Environment Variable: DESKTOP

Invalid Environment Variable: DESKTOP

Invalid Environment Variable: DESKTOP

Invalid Environment Variable: DESKTOP

< %PROGRAMFILES%\Common Files\*.* >
[2007/06/26 15:56:15 | 00,099,840 | —- | M] (Symantec Corp.) – C:\Program Files\Common Files\IRAABOUT.DLL
[2007/06/26 15:56:15 | 00,048,640 | —- | M] (Symantec Corp., Peter Norton Computing Group) – C:\Program Files\Common Files\IRALPTTR.DLL
[2007/06/26 15:56:15 | 00,070,144 | —- | M] (Symantec Corp., Peter Norton Computing Group) – C:\Program Files\Common Files\IRAMDMTR.DLL
[2007/06/26 15:56:15 | 00,186,368 | —- | M] (Symantec Corp., Peter Norton Computing Group) – C:\Program Files\Common Files\IRAREG.DLL
[2007/06/26 15:56:15 | 00,017,920 | —- | M] (Symantec Corp.) – C:\Program Files\Common Files\IRASRIAL.DLL
[2007/06/26 15:56:16 | 00,031,744 | —- | M] (Symantec Corp., Peter Norton Computing Group) – C:\Program Files\Common Files\IRAWEBTR.DLL

< %PROGRAMFILES%\Common Files\*bak*. >
[2008/12/20 15:40:03 | 00,000,000 | —D | M] – C:\Program Files\Common Files

< %systemroot%\SYSTEM32\*bak*. >
[6 C:\WINDOWS\SYSTEM32\*.tmp files]
[2008/12/29 20:33:55 | 00,000,000 | —D | M] – C:\WINDOWS\SYSTEM32
[2008/12/29 20:26:04 | 00,000,000 | —D | M] – C:\WINDOWS\SYSTEM32\CatRoot_bak

< %PROGRAMFILES%\*bak*. >
[2008/12/29 15:14:47 | 00,000,000 | R–D | M] – C:\Program Files

< %systemroot%\ime\imjp8_1\*bak*. >
[2007/06/26 14:26:51 | 00,000,000 | —D | M] – C:\WINDOWS\ime\imjp8_1

< %PROGRAMFILES%\QuickTime\*bak*. >
[2008/12/25 03:02:44 | 00,000,000 | —D | M] – C:\Program Files\QuickTime

< %PROGRAMFILES%\Viewpoint\Viewpoint Manager\*bak*. >
[2007/11/30 16:56:01 | 00,000,000 | —D | M] – C:\Program Files\Viewpoint\Viewpoint Manager

< %PROGRAMFILES%\Analog Devices\Core\*bak*. >

< %SYSTEMDRIVE%\hp\KBD\*bak*. >

< %PROGRAMFILES%\Adobe\Photoshop Album Starter Edition\3.2\Apps\*bak*. >

< %PROGRAMFILES%\BillP Studios\WinPatrol\*bak*. >

< %PROGRAMFILES%\BroadJump\Client Foundation\*bak*. >

< %PROGRAMFILES%\Common Files\Real\Update_OB\*bak*. >
[2008/09/27 14:02:31 | 00,000,000 | —D | M] – C:\Program Files\Common Files\Real\Update_OB

< %PROGRAMFILES%\Common Files\Sonic\Update Manager\*bak*. >

< %PROGRAMFILES%\\Google\GoogleToolbarNotifier\*bak*. >
[2008/10/09 17:36:27 | 00,000,000 | —D | M] – C:\Program Files\\Google\GoogleToolbarNotifier

< %PROGRAMFILES%\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\*bak*. >

< %PROGRAMFILES%\Yahoo!\Messenger\*bak*. >

< %USERNAME%\*.zip >

< %USERNAME%\*.rar >

< %USERNAME%\*.exe >

< %USERPROFILE%\*.zip >

< %USERPROFILE%\*.rar >

< %USERPROFILE%\*.exe >

< %ALLUSERSPROFILE%\*.zip >

< %ALLUSERSPROFILE%\*.rar >

< %ALLUSERSPROFILE%\*.exe >

< %APPDATA%\*.zip >

< %APPDATA%\*.rar >

< %APPDATA%\*.exe >

Invalid Environment Variable: ALLUSERSSTARTMENU

Invalid Environment Variable: ALLUSERSSTARTMENU

Invalid Environment Variable: ALLUSERSSTARTMENU

Invalid Environment Variable: ALLUSERSSTARTUP

Invalid Environment Variable: ALLUSERSSTARTUP

Invalid Environment Variable: ALLUSERSSTARTUP

Invalid Environment Variable: ALLUSERSPROGRAMS

Invalid Environment Variable: ALLUSERSPROGRAMS

Invalid Environment Variable: ALLUSERSPROGRAMS

Invalid Environment Variable: ALLUSERSAPPDATA

Invalid Environment Variable: ALLUSERSAPPDATA

Invalid Environment Variable: ALLUSERSAPPDATA

< %APPDATA%\*.zip >

< %APPDATA%\*.rar >

< %APPDATA%\*.exe >

< %APPDATA%\*.dat >

< %APPDATA%\*.dll >

Invalid Environment Variable: QUICKLAUNCH

Invalid Environment Variable: QUICKLAUNCH

Invalid Environment Variable: QUICKLAUNCH

Invalid Environment Variable: STARTUP

Invalid Environment Variable: STARTUP

Invalid Environment Variable: STARTUP

Invalid Environment Variable: STARTMENU

Invalid Environment Variable: STARTMENU

Invalid Environment Variable: STARTMENU

Invalid Environment Variable: MYDOCUMENTS

Invalid Environment Variable: MYDOCUMENTS

Invalid Environment Variable: MYDOCUMENTS

Invalid Environment Variable: MYDOCUMENTS

Invalid Environment Variable: MYDOCUMENTS

< %PROGRAMFILES%\Mozilla Firefox\plugins\*.* >
[2008/09/10 02:39:42 | 00,075,184 | —- | M] (NHN USA Inc. ) – C:\Program Files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
[2005/12/05 21:31:00 | 00,114,688 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
[2008/12/18 22:22:48 | 00,065,528 | —- | M] (mozilla.org) – C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[2007/04/16 12:07:12 | 00,180,293 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
[2006/10/09 13:26:35 | 00,000,266 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.xpt
[2008/12/25 03:02:44 | 00,004,208 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\QuickTimePlugin.class

< %PROGRAMFILES%\Internet Explorer\*.* >
[2007/08/13 17:54:10 | 00,033,792 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\custsat.dll
[2007/08/13 17:18:02 | 00,060,416 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\hmmapi.dll
[2007/08/13 17:44:02 | 00,069,120 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iedw.exe
[2007/08/13 17:54:10 | 00,287,744 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\ieproxy.dll
[2008/10/15 02:06:26 | 00,633,632 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iexplore.exe

< %PROGRAMFILES%\Internet Explorer\PLUGINS\*.* >
[2008/12/25 03:02:44 | 00,004,208 | —- | M] () – C:\Program Files\Internet Explorer\PLUGINS\QuickTimePlugin.class

< %PROGRAMFILES%\Mozilla Firefox\*.zip /s >

< %PROGRAMFILES%\Mozilla Firefox\*.rar /s >

< %PROGRAMFILES%\Mozilla Firefox\*.exe /s >
[2008/12/18 22:22:46 | 00,185,848 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\crashreporter.exe
[2008/12/18 22:22:46 | 00,307,704 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
[2008/12/18 22:22:49 | 00,242,168 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\updater.exe
[2008/12/18 22:22:49 | 00,509,536 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\uninstall\helper.exe

< %PROGRAMFILES%\Internet Explorer\*.zip /s >

< %PROGRAMFILES%\Internet Explorer\*.rar /s >

< %PROGRAMFILES%\Internet Explorer\*.exe /s >
[2007/08/13 17:44:02 | 00,069,120 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iedw.exe
[2008/10/15 02:06:26 | 00,633,632 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iexplore.exe
[2004/08/04 07:00:00 | 00,214,528 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe
[2004/08/04 07:00:00 | 00,086,016 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\Connection Wizard\icwconn2.exe
[2004/08/04 07:00:00 | 00,024,576 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\Connection Wizard\icwrmind.exe
[2004/08/04 07:00:00 | 00,073,728 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\Connection Wizard\icwtutor.exe
[2004/08/04 07:00:00 | 00,020,480 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\Connection Wizard\inetwiz.exe
[2004/08/04 07:00:00 | 00,016,384 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\Connection Wizard\isignup.exe

< %SYSTEMDRIVE%\*.dat >

< %SYSTEMDRIVE%\*.sys >
[2007/06/26 14:26:33 | 00,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/06/26 14:26:33 | 00,000,000 | RHS- | M] () – C:\IO.SYS
[2007/06/26 14:26:33 | 00,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/12/29 20:36:54 | 16,106,12736 | -HS- | M] () – C:\pagefile.sys

< %SYSTEMROOT%\*.dat >
[2008/12/29 20:36:59 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2008/06/27 14:58:40 | 00,037,035 | —- | M] () – C:\WINDOWS\DIIUnin.dat
[2005/09/14 13:30:44 | 00,036,864 | —- | M] () – C:\WINDOWS\key.dat
[2008/07/07 09:48:42 | 00,002,130 | —- | M] () – C:\WINDOWS\mozver.dat
[2007/09/06 18:13:54 | 00,000,335 | —- | M] () – C:\WINDOWS\nsreg.dat
[5 C:\WINDOWS\*.tmp files]

< %SYSTEMROOT%\*.sys >

< %systemroot%\system32\drivers\*.exe /s >

< %systemroot%\system32\drivers\*.zip /s >

< %systemroot%\system32\drivers\*.rar /s >

< %systemroot%\system\*.exe /s >

< %systemroot%\system\*.zip /s >

< %systemroot%\system\*.rar /s >

< %systemroot%\AppPatch\*.exe /s >

< %systemroot%\AppPatch\*.zip /s >

< %systemroot%\AppPatch\*.rar /s >

< %systemroot%\Cache\*.* >

< %systemroot%\Downloaded Program Files\*.* >
[2007/01/23 20:41:42 | 00,841,304 | —- | M] () – C:\WINDOWS\Downloaded Program Files\ampAx3.0.84.2.dll
[2007/06/26 14:25:31 | 00,000,065 | -H– | M] () – C:\WINDOWS\Downloaded Program Files\desktop.ini
[2007/03/23 11:17:32 | 00,001,292 | —- | M] () – C:\WINDOWS\Downloaded Program Files\erma.inf
[2008/10/04 20:16:46 | 01,887,080 | —- | M] () – C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
[2008/01/14 15:37:14 | 00,045,056 | —- | M] () – C:\WINDOWS\Downloaded Program Files\ijjiNotify2.exe
[2007/06/21 17:59:50 | 00,058,776 | —- | M] () – C:\WINDOWS\Downloaded Program Files\ijjiPlugin2.dll
[2007/06/11 09:51:52 | 00,000,770 | —- | M] () – C:\WINDOWS\Downloaded Program Files\ijjiPlugin2.inf
[2008/01/14 15:37:20 | 00,073,728 | —- | M] () – C:\WINDOWS\Downloaded Program Files\ijjiPreNotify2.exe
[2008/01/14 15:40:14 | 00,081,920 | —- | M] () – C:\WINDOWS\Downloaded Program Files\ijjiPreStarter2.exe
[2007/09/10 10:55:54 | 00,114,688 | —- | M] () – C:\WINDOWS\Downloaded Program Files\ijjiSetup1010.dll
[2008/04/15 20:03:16 | 00,925,696 | —- | M] () – C:\WINDOWS\Downloaded Program Files\ijjistarter2.exe
[2008/11/20 17:34:20 | 00,011,416 | —- | M] () – C:\WINDOWS\Downloaded Program Files\install.log
[2008/02/01 03:21:04 | 00,000,350 | —- | M] () – C:\WINDOWS\Downloaded Program Files\MySpaceUploader.inf
[2008/02/01 03:17:04 | 02,637,440 | —- | M] () – C:\WINDOWS\Downloaded Program Files\MySpaceUploader.ocx
[2008/10/14 08:12:11 | 00,787,904 | —- | M] () – C:\WINDOWS\Downloaded Program Files\PurpleBean.exe
[2007/02/14 15:30:50 | 00,000,144 | —- | M] () – C:\WINDOWS\Downloaded Program Files\setup.inf
[2008/10/04 20:08:34 | 00,000,247 | —- | M] () – C:\WINDOWS\Downloaded Program Files\swflash.inf
[2006/12/06 09:11:48 | 00,224,768 | —- | M] () – C:\WINDOWS\Downloaded Program Files\symdlmgr.dll
[2006/12/06 09:10:20 | 00,000,350 | —- | M] () – C:\WINDOWS\Downloaded Program Files\symdlmgr.inf
[2008/11/20 17:34:20 | 00,038,428 | —- | M] () – C:\WINDOWS\Downloaded Program Files\unagiuninst.exe
[2008/10/28 16:25:00 | 00,453,512 | —- | M] () – C:\WINDOWS\Downloaded Program Files\wlscBase.dll
[2008/10/28 16:26:30 | 00,000,320 | —- | M] () – C:\WINDOWS\Downloaded Program Files\wlscBase.inf
[2003/06/30 22:41:04 | 00,001,689 | —- | M] () – C:\WINDOWS\Downloaded Program Files\WMV9VCM.inf

< %systemroot%\Fonts\*.exe /s >

< %systemroot%\Fonts\*.zip /s >

< %systemroot%\Fonts\*.rar /s >

< %systemroot%\Fonts\*.dll /s >

< %systemroot%\Help\*.exe /s >
[2004/08/04 07:00:00 | 03,374,640 | —- | M] (Macromedia, Inc.) – C:\WINDOWS\Help\Tours\mmTour\tour.exe

< %systemroot%\Help\*.zip /s >

< %systemroot%\Help\*.rar /s >

< %systemroot%\Tasks\*.* >
[2008/12/25 03:01:08 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2008/12/29 19:45:00 | 00,000,256 | —- | M] () – C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
[2004/08/04 07:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2008/12/29 20:37:05 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

< %APPDATA%\*.sys >

< %APPDATA%\Google\*.* >

< %systemroot%\system32\serauth1.dll >

< %systemroot%\system32\serauth2.dll >

< %systemroot%\system32\sysaudio.sys >

< %PROGRAMFILES%\*TinyProxy*. >
[2008/12/29 15:14:47 | 00,000,000 | R–D | M] – C:\Program Files

< HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla|extensions /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758} -> %ProgramFiles%\Real\RealPlayer\browserrecord [C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD] -> [2008/09/27 14:02:58 00,000,000 | —D | M]
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.5\extensions\\Components -> %ProgramFiles%\Mozilla Firefox\components [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2008/12/25 03:02:45 00,000,000 | —D | M]
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.5\extensions\\Plugins -> %ProgramFiles%\Mozilla Firefox\plugins [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2008/12/25 03:02:45 00,000,000 | —D | M]

< %systemroot%\system32\inf\*.exe /s >

< %systemroot%\system32\inf\*.zip /s >

< %systemroot%\system32\inf\*.rar /s >

< %systemroot%\system32\inf\*.dll /s >

< %PROGRAMFILES%\Bitlord\Downloads\*.zip /s >

< %PROGRAMFILES%\Bitlord\Downloads\*.rar /s >

< %PROGRAMFILES%\Bitlord\Downloads\*.exe /s >

< %PROGRAMFILES%\Bitlord\Downloads\*crack*. >

< %PROGRAMFILES%\Bitlord\Downloads\*keygen*. >

< %PROGRAMFILES%\eMule\Incoming\*.zip /s >

< %PROGRAMFILES%\eMule\Incoming\*.rar /s >

< %PROGRAMFILES%\eMule\Incoming\*.exe /s >

< %PROGRAMFILES%\eMule\Incoming\*crack*. >

< %PROGRAMFILES%\eMule\Incoming\*keygen*. >

< %ProgramFiles%\Bittorent\downloads\*.zip /s >

< %ProgramFiles%\Bittorent\downloads\*.exe /s >

< %ProgramFiles%\Bittorent\downloads\*.rar /s >

< %PROGRAMFILES%\Bittorent\Downloads\*crack*. >

< %PROGRAMFILES%\Bittorent\Downloads\*keygen*. >

< %ProgramFiles%\Bearshare\Shared\*.zip /s >

< %ProgramFiles%\Bearshare\Shared\*.exe /s >

< %ProgramFiles%\Bearshare\Shared\*.rar /s >

< %ProgramFiles%\Bearshare\Shared\*crack*. >

< %ProgramFiles%\Bearshare\Shared\*keygen*. >

< %ProgramFiles%\Morpheus\My Shared Folder\*.zip /s >

< %ProgramFiles%\Morpheus\My Shared Folder\*.exe /s >

< %ProgramFiles%\Morpheus\My Shared Folder\*.rar /s >

< %ProgramFiles%\Morpheus\My Shared Folder\*crack*. >

< %ProgramFiles%\Morpheus\My Shared Folder\*keygen*. >

< %ProgramFiles%\uTorrent\Downloads\*.zip /s >

< %ProgramFiles%\uTorrent\Downloads\*.exe /s >

< %ProgramFiles%\uTorrent\Downloads\*.rar /s >

< %ProgramFiles%\uTorrent\Downloads\*crack*. >

< %ProgramFiles%\uTorrent\Downloads\*keygen*. >

< %ProgramFiles%\Kazaa Lite\My Shared Folder\*.zip /s >

< %ProgramFiles%\Kazaa Lite\My Shared Folder\*.exe /s >

< %ProgramFiles%\Kazaa Lite\My Shared Folder\*.rar /s >

< %ProgramFiles%\Kazaa Lite\My Shared Folder\*crack*. >

< %ProgramFiles%\Kazaa Lite\My Shared Folder\*keygen*. >

< %ProgramFiles%\Kazaa\My Shared Folder\*.zip /s >

< %ProgramFiles%\Kazaa\My Shared Folder\*.exe /s >

< %ProgramFiles%\Kazaa\My Shared Folder\*.rar /s >

< %ProgramFiles%\Kazaa\My Shared Folder\*crack*. >

< %ProgramFiles%\Kazaa\My Shared Folder\*keygen*. >

< %ProgramFiles%\Icq\Shared Files\*.zip /s >

< %ProgramFiles%\Icq\Shared Files\*.exe /s >

< %ProgramFiles%\Icq\Shared Files\*.rar /s >

< %ProgramFiles%\Icq\Shared Files\*crack*. >

< %ProgramFiles%\Icq\Shared Files\*keygen*. >

< %ProgramFiles%\Direct Connect\Received Files\*.zip /s >

< %ProgramFiles%\Direct Connect\Received Files\*.exe /s >

< %ProgramFiles%\Direct Connect\Received Files\*.rar /s >

< %ProgramFiles%\Direct Connect\Received Files\*crack*. >

< %ProgramFiles%\Direct Connect\Received Files\*keygen*. >

< %ALLUSERSPROFILE%\Application Data\AOL Downloads\*.zip >

< %ALLUSERSPROFILE%\Application Data\AOL Downloads\*.rar >

< %ALLUSERSPROFILE%\Application Data\AOL Downloads\*.exe >

< %ALLUSERSPROFILE%\Application Data\AOL Downloads\*crack*. >
[2008/11/20 17:33:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL Downloads

< %ALLUSERSPROFILE%\Application Data\AOL Downloads\*keygen*. >
[2008/11/20 17:33:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL Downloads

< %APPDATA%\Opera\Opera\profile\widgets\*.* >

< %PROGRAMFILES%\Opera\program\plugins\*.* /s >

< %APPDATA%\Opera\Opera\profile\toolbar\*.* /s >
< End of report >
Do you recognise this file

C:\lan.rar


Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
Do this as well

Please download Gmer:

http://www.gmer.net/gmer.zip

Now let's perform a Gmer rootkit scan:

  • Double-click Gmer.exe to run the program.
  • When the program opens, click the >>> Tab
  • On the right-side, check all the items to be scanned, but leave "Show All" unchecked
  • Select all drives that are connected to your system to be scanned
  • Click the Scan button
  • When the scan is finished, click Copy to save the scan log to the Windows clipboard
  • Open Notepad or a similar text editor
  • Paste the clipboard contents into a text file by clicking Edit | Paste or Ctl V
  • Save the gmer scan log and post it in your next reply.
  • Close Gmer
  • Open a command prompt (Start | run |type cmd and hit Enter)
  • Type or paste the following to unload the Gmer driver:
    • net stop gmer
  • Hit Enter
  • Exit the command prompt.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI