This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Errant Pop ups

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:02, on 12/31/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Trend Micro\Internet Security 14\pccguide.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Common Files\Lacerte Shared\Update Scheduler\UpdSched.EXE
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {06663B56-0D73-4f9f-BCC5-4AA941470AFD} - C:\Program Files\PandoBar\SrchAstt\1.bin\P4SRCHAS.DLL
O2 - BHO: {56dae859-5d88-a1b8-93a4-7d50224b5cf2} - {2fc5b422-05d7-4a39-8b1a-88d5958ead65} - C:\WINDOWS\system32\zeppsm.dll
O2 - BHO: (no name) - {305632EE-CB12-4208-90EE-6D0E495FF918} - C:\WINDOWS\system32\ssqPfdCU.dll
O2 - BHO: (no name) - {33FDCDE2-246A-47AE-9661-E98E9D11DB61} - C:\WINDOWS\system32\ssqPfdCU.dll
O2 - BHO: CInterceptor Object - {38D3FE60-3D53-4F37-BB0E-C7A97A26A156} - C:\Program Files\Pando Networks\Pando\PandoIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\hgGxXRjK.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7F30C9D3-ECAF-4A18-984F-120B26A5D0EA} - C:\WINDOWS\system32\ssqPfdCU.dll
O2 - BHO: (no name) - {B24DCD7D-E5B9-4209-82D1-301447B04C7B} - C:\WINDOWS\system32\ssqPfdCU.dll
O2 - BHO: (no name) - {BDB2DF01-6622-46B8-A440-7B584E0A6437} - C:\WINDOWS\system32\ssqPfdCU.dll
O2 - BHO: (no name) - {C22EED21-9A33-477D-9F06-44219D3A370B} - C:\WINDOWS\system32\ssqPfdCU.dll
O2 - BHO: (no name) - {d7cc31ea-0429-47c2-b6a4-9c9200013810} - C:\WINDOWS\system32\vibomate.dll
O3 - Toolbar: Pando Toolbar - {E3EA4FD9-CADE-4ae5-84F7-086EEE888BE4} - C:\Program Files\PandoBar\bar\1.bin\PANDOBAR.DLL
O3 - Toolbar: atfxqogp - {23649E36-60C6-4433-880A-9DF59FC27342} - C:\WINDOWS\atfxqogp.dll (file missing)
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Trend Micro\Internet Security 14\pccguide.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [nabobuvoha] Rundll32.exe "C:\WINDOWS\system32\fibunewu.dll",s
O4 - HKLM\..\Run: [CPM0fb8f4ea] Rundll32.exe "c:\windows\system32\fovutila.dll",a
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Pando] "C:\Program Files\Pando Networks\Pando\Pando.exe" /Minimized
O4 - HKCU\..\Run: [OE_OEM] "C:\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [Updates Scheduler] C:\Program Files\Common Files\Lacerte Shared\Update Scheduler\UpdSched.EXE
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKUS\S-1-5-20\..\Run: [nabobuvoha] Rundll32.exe "C:\WINDOWS\system32\fibunewu.dll",s (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-734704646-2542578703-1319970288-1008\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'logan')
O4 - HKUS\S-1-5-21-734704646-2542578703-1319970288-1008\..\Run: [prunnet] "C:\WINDOWS\system32\prunnet.exe" (User 'logan')
O4 - HKUS\S-1-5-21-734704646-2542578703-1319970288-1008\..\Run: [nabobuvoha] Rundll32.exe "C:\WINDOWS\system32\fibunewu.dll",s (User 'logan')
O4 - HKUS\S-1-5-21-734704646-2542578703-1319970288-1008\..\Run: [0c8bc776] rundll32.exe "C:\WINDOWS\system32\latalelu.dll",b (User 'logan')
O4 - HKUS\S-1-5-21-734704646-2542578703-1319970288-1008\..\Run: [CPM0fb8f4ea] Rundll32.exe "C:\WINDOWS\system32\fovutila.dll",a (User 'logan')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Service Manager.norun
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://download.windowsupdate.com
O15 - Trusted Zone: *.antimalwareguard.com (HKLM)
O15 - Trusted Zone: *.gomyhit.com (HKLM)
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://symantec.atgnow.com/sdccommon/download/tgctlsi.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1228795483884
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1228795455962
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.2.1.cab
O20 - AppInit_DLLs: zeppsm.dll C:\WINDOWS\system32\roziwowu.dll c:\windows\system32\fovutila.dll
O20 - Winlogon Notify: hgGxXRjK - C:\WINDOWS\SYSTEM32\hgGxXRjK.dll
O20 - Winlogon Notify: qommlkh - qommlkh.dll (file missing)
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\fovutila.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\fovutila.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (file missing)
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton Ghost - Unknown owner - C:\Program Files\Norton Ghost\Agent\VProSvc.exe (file missing)
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (file missing)
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\TRENDM~1\INTERN~1\tmproxy.exe

–
End of file - 14519 bytes
hello

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.
Thank you for the help. Here is the ComboFix Log.


ComboFix 08-12-31.01 - Kevin 2009-01-01 9:33:50.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.482 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: PC-cillin Internet Security - Virus Protection *On-access scanning disabled* (Updated)
FW: PC-cillin Internet Security - Firewall *disabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\BM0fb8f4ea.txt
c:\windows\IE4 Error Log.txt
c:\windows\system32\~.exe
c:\windows\system32\fedakawu.dll
c:\windows\system32\fovutila.dll
c:\windows\system32\gakasaja.dll
c:\windows\system32\gnwhvsty.dll
c:\windows\system32\hfrlhlnu.ini
c:\windows\system32\hgGxXRjK.dll
c:\windows\system32\humirabi.dll
c:\windows\system32\ibarimuh.ini
c:\windows\system32\jefubega.dll
c:\windows\system32\kneagxkr.dll
c:\windows\system32\latalelu.dll
c:\windows\system32\lfbjauwt.ini
c:\windows\system32\orspatap.ini
c:\windows\system32\oxbfdifk.dll
c:\windows\system32\patapsro.dll
c:\windows\system32\pobivamo.dll
c:\windows\system32\Process.exe
c:\windows\system32\rkxgaenk.ini
c:\windows\system32\sqkfewcy.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\ssqPfdCU.dll
c:\windows\system32\tmp.reg
c:\windows\system32\tuvVLdax.dll
c:\windows\system32\UCdfPqss.ini
c:\windows\system32\UCdfPqss.ini2
c:\windows\system32\ujxtuqvj.dll
c:\windows\system32\ulelatal.ini
c:\windows\system32\uwakadef.ini
c:\windows\system32\ycwefkqs.ini
c:\windows\system32\yjswfmmf.ini
c:\windows\system32\yxnuvoej.ini
c:\windows\system32\zeppsm.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_OREANS32
——-\Service_oreans32


((((((((((((((((((((((((( Files Created from 2008-12-01 to 2009-01-01 )))))))))))))))))))))))))))))))
.

2008-12-28 00:29 . 2008-12-28 00:29 d——– c:\program files\iTunes
2008-12-28 00:29 . 2008-12-28 00:29 d——– c:\program files\iPod
2008-12-28 00:29 . 2008-12-28 00:29 d——– c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-03 21:47 . 2008-12-08 22:28 d——– c:\program files\MSECache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-31 05:46 ——— d—–w c:\program files\Coupons
2008-12-28 06:29 ——— d—–w c:\program files\Common Files\Apple
2008-12-28 06:26 ——— d—–w c:\program files\QuickTime
2008-11-30 16:35 ——— d—–w c:\program files\HP
2008-11-02 03:24 ——— d—–w c:\program files\Common Files\Lacerte Shared
1601-01-01 00:12 61,159 –sha-w c:\windows\system32\fibunewu.dll
2008-09-27 05:40 1,786 –sha-w c:\windows\system32\KGyGaAvL.sys
1601-01-01 00:12 61,159 –sha-w c:\windows\system32\roziwowu.dll
1601-01-01 00:12 61,159 –sha-w c:\windows\system32\vibomate.dll
.

——- Sigcheck ——-

2004-08-04 03:00 14336 8f078ae4ed187aaabc0a305146de6716 c:\windows\system32\svchost.exe

2005-03-02 12:19 577024 1800f293bccc8ede8a70e12b88d80036 c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 09:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
2004-08-04 03:00 577024 c72661f8552ace7c5c85e16a3cf505c4 c:\windows\$NtUninstallKB890859$\user32.dll
2005-03-02 12:09 577024 de2db164bbb35db061af0997e4499054 c:\windows\$NtUninstallKB925902$\user32.dll
2007-03-08 09:36 577536 b409909f6e2e8a7067076ed748abf1e7 c:\windows\system32\user32.dll
2007-03-08 09:36 577536 b409909f6e2e8a7067076ed748abf1e7 c:\windows\system32\dllcache\user32.dll

2004-08-04 03:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\system32\ws2_32.dll

2004-08-04 03:00 502272 01c3346c241652f43aed8e2149881bfe c:\windows\system32\winlogon.exe

2004-08-04 03:00 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\system32\drivers\ndis.sys

2004-08-04 03:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\system32\drivers\ip6fw.sys

2005-03-01 18:36 2056832 d8aba3eab509627e707a3b14f00fbb6b c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2005-06-22 18:05 2015744 65f4b29a0793adb5d924fb3f47f1bca4 c:\windows\$NtUninstallKB931784$\ntkrnlpa.exe
2007-02-28 03:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba c:\windows\Driver Cache\i386\ntkrnlpa.exe
2007-02-28 03:15 2017280 2dfb215e291e3d9b1cf9a6739b3bf16c c:\windows\system32\ntkrnlpa.exe
2007-02-28 03:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba c:\windows\system32\dllcache\ntkrnlpa.exe

2005-03-01 19:04 2179456 28187802b7c368c0d3aef7d4c382aabb c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2005-06-22 18:30 2136064 5611f453c6d20ab0552956f39bcddb88 c:\windows\$NtUninstallKB931784$\ntoskrnl.exe
2007-02-28 03:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 c:\windows\Driver Cache\i386\ntoskrnl.exe
2007-02-28 03:53 2137600 e6679c3023b17d8b78946bc5df53fa20 c:\windows\system32\ntoskrnl.exe
2007-02-28 03:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 c:\windows\system32\dllcache\ntoskrnl.exe

2007-06-13 04:23 1033216 97bd6515465659ff8f3b7be375b2ea87 c:\windows\explorer.exe
2007-06-13 05:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-04 03:00 1032192 a0732187050030ae399b241436565e64 c:\windows\$NtUninstallKB938828$\explorer.exe
2007-06-13 04:23 1033216 97bd6515465659ff8f3b7be375b2ea87 c:\windows\system32\dllcache\explorer.exe

2004-08-04 03:00 108032 c6ce6eec82f187615d1002bb3bb50ed4 c:\windows\system32\services.exe

2004-08-04 03:00 13312 84885f9b82f4d55c6146ebf6065d75d2 c:\windows\system32\lsass.exe

2004-08-04 03:00 15360 24232996a38c0b0cf151c2140ae29fc8 c:\windows\system32\ctfmon.exe

2005-06-10 18:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2005-06-10 17:53 57856 da81ec57acd4cdc3d4c51cf3d409af9f c:\windows\system32\spoolsv.exe

2004-08-04 03:00 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\system32\userinit.exe

2004-08-04 03:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\system32\termsrv.dll
.
((((((((((((((((((((((((((((( snapshot_2008-06-02_15.35.28.50 )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-08-04 09:00:00 30,080 -c—-w c:\windows\$NtUninstallKB909394$\rndismp.sys
+ 2005-10-12 23:12:26 213,216 -c—-w c:\windows\$NtUninstallKB909394$\spuninst\spuninst.exe
+ 2005-10-12 23:12:33 371,424 -c—-w c:\windows\$NtUninstallKB909394$\spuninst\updspapi.dll
+ 2004-08-04 09:00:00 12,672 -c—-w c:\windows\$NtUninstallKB909394$\usb8023.sys
+ 2008-08-09 01:41:33 53,248 —-a-w c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2008-08-09 01:41:33 12,800 —-a-w c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2008-08-09 01:41:33 473,600 —-a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2008-08-09 01:41:29 2,676,224 —-a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-08-09 01:41:29 2,846,720 —-a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-08-09 01:41:30 563,712 —-a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-08-09 01:41:30 567,296 —-a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-08-09 01:41:31 576,000 —-a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-08-09 01:41:31 577,024 —-a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-08-09 01:41:32 577,536 —-a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-08-09 01:41:32 577,536 —-a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-08-09 01:41:33 578,560 —-a-w c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-08-09 01:41:34 145,920 —-a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2008-08-09 01:41:34 159,232 —-a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2008-08-09 01:41:34 364,544 —-a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2008-08-09 01:41:34 178,176 —-a-w c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2008-08-09 01:41:33 223,232 —-a-w c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2007-06-01 19:25:26 317,016 —-a-w c:\windows\Downloaded Program Files\mnviewer.dll
+ 2005-10-21 01:47:04 30,592 ——w c:\windows\Driver Cache\i386\rndismpx.sys
+ 2005-10-21 01:47:05 12,800 ——w c:\windows\Driver Cache\i386\usb8023x.sys
- 2005-10-21 01:02:28 163,328 —-a-w c:\windows\erdnt\Hiv-backup\ERDNT.EXE
+ 2005-10-21 02:02:28 163,328 —-a-w c:\windows\erdnt\Hiv-backup\ERDNT.EXE
- 2005-10-21 01:02:28 163,328 —-a-w c:\windows\erdnt\subs\ERDNT.EXE
+ 2005-10-21 02:02:28 163,328 —-a-w c:\windows\erdnt\subs\ERDNT.EXE
+ 2007-11-15 15:24:00 1,013,552 —-a-r c:\windows\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_bcont.exe
+ 2007-11-15 15:24:00 1,013,552 —-a-r c:\windows\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_bcont_nm.exe
+ 2007-11-15 15:24:00 1,017,240 —-a-r c:\windows\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_dsc.exe
+ 2007-11-15 15:23:56 1,069,056 —-a-r c:\windows\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_libeay32.dll
+ 2007-09-06 19:16:24 421,888 —-a-r c:\windows\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_pcdr2d3dvideodx9.dll
+ 2007-11-15 15:23:56 202,544 —-a-r c:\windows\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtcmd.exe
+ 2007-11-15 15:23:56 378,408 —-a-r c:\windows\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtevent.dll
+ 2007-11-15 15:23:56 398,624 —-a-r c:\windows\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtfod.dll
+ 2007-11-15 15:23:56 116,264 —-a-r c:\windows\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprthook.dll
+ 2007-11-15 15:23:56 73,728 —-a-r c:\windows\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtmessage.dll
+ 2007-11-15 15:23:56 873,760 —-a-r c:\windows\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtsched.dll
+ 2007-11-15 15:23:56 202,544 —-a-r c:\windows\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtsvc.exe
+ 2007-11-15 15:23:56 337,448 —-a-r c:\windows\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprttrigger.dll
+ 2007-11-15 15:23:56 374,048 —-a-r c:\windows\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtui.dll
+ 2007-11-15 15:23:56 341,280 —-a-r c:\windows\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtupdate.dll
+ 2007-11-15 15:23:56 200,704 —-a-r c:\windows\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_ssleay32.dll
+ 2007-11-15 15:23:56 20,480 —-a-r c:\windows\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_SupportSoft.Agent.Sprocket.dll
+ 2007-11-15 15:23:56 24,576 —-a-r c:\windows\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_SupportSoft.Agent.Sprocket.SupportMessage.dll
+ 2008-06-23 17:58:26 27,136 —-a-r c:\windows\Installer\{02DFF6B1-1654-411C-8D7B-FD6052EF016F}\AppleSoftwareUpdateIco.exe
+ 2008-12-28 06:29:59 102,400 —-a-r c:\windows\Installer\{318AB667-3230-41B5-A617-CB3BF748D371}\iTunesIco.exe
+ 2008-10-17 23:02:05 86,016 —-a-r c:\windows\Installer\{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}\PrntWzrdIco.exe
+ 2008-12-09 04:28:52 38,240 —-a-r c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2008-12-04 03:47:28 49,936 —-a-r c:\windows\Installer\{95120000-00AF-0409-0000-0000000FF1CE}\ppvwicon.exe
+ 2008-08-21 13:03:21 22,486 —-a-r c:\windows\Installer\{99052DB7-9592-4522-A558-5417BBAD48EE}\ARPPRODUCTICON.exe
+ 2008-08-21 13:03:22 22,486 —-a-r c:\windows\Installer\{99052DB7-9592-4522-A558-5417BBAD48EE}\WCESMgrIcon.exe
+ 2008-12-16 14:25:56 25,214 —-a-r c:\windows\Installer\{AB480DA0-7EE9-465D-9C12-4CDE65BF18FB}\ARPPRODUCTICON.exe
+ 2008-12-16 14:25:56 65,536 —-a-r c:\windows\Installer\{AB480DA0-7EE9-465D-9C12-4CDE65BF18FB}\NewShortcut3_C0B0FA55D4E943749871BBFBF2AEF0D1.exe
+ 2008-12-16 14:25:56 65,536 —-a-r c:\windows\Installer\{AB480DA0-7EE9-465D-9C12-4CDE65BF18FB}\NewShortcut4_C0B0FA55D4E943749871BBFBF2AEF0D1.exe
+ 2008-12-16 14:25:56 65,536 —-a-r c:\windows\Installer\{AB480DA0-7EE9-465D-9C12-4CDE65BF18FB}\pando.exe_ED0ECD11C6AB405E9A06D25E96BD6FD7.exe
+ 2008-12-16 14:25:56 65,536 —-a-r c:\windows\Installer\{AB480DA0-7EE9-465D-9C12-4CDE65BF18FB}\pando.exe1_ED0ECD11C6AB405E9A06D25E96BD6FD7.exe
- 2008-02-14 05:27:39 25,214 —-a-r c:\windows\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\ARPPRODUCTICON.exe
+ 2008-06-17 01:06:39 25,214 —-a-r c:\windows\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\ARPPRODUCTICON.exe
- 2008-02-14 05:27:40 65,536 —-a-r c:\windows\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\NewShortcut3_C0B0FA55D4E943749871BBFBF2AEF0D1.exe
+ 2008-06-17 01:06:40 65,536 —-a-r c:\windows\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\NewShortcut3_C0B0FA55D4E943749871BBFBF2AEF0D1.exe
- 2008-02-14 05:27:40 65,536 —-a-r c:\windows\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\NewShortcut4_C0B0FA55D4E943749871BBFBF2AEF0D1.exe
+ 2008-06-17 01:06:40 65,536 —-a-r c:\windows\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\NewShortcut4_C0B0FA55D4E943749871BBFBF2AEF0D1.exe
- 2008-02-14 05:27:40 65,536 —-a-r c:\windows\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\pando.exe_ED0ECD11C6AB405E9A06D25E96BD6FD7.exe
+ 2008-06-17 01:06:40 65,536 —-a-r c:\windows\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\pando.exe_ED0ECD11C6AB405E9A06D25E96BD6FD7.exe
- 2008-02-14 05:27:40 65,536 —-a-r c:\windows\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\pando.exe1_ED0ECD11C6AB405E9A06D25E96BD6FD7.exe
+ 2008-06-17 01:06:40 65,536 —-a-r c:\windows\Installer\{C0B0FA55-D4E9-4374-9871-BBFBF2AEF0D1}\pando.exe1_ED0ECD11C6AB405E9A06D25E96BD6FD7.exe
+ 2008-11-30 16:36:02 689,456 —-a-r c:\windows\Installer\{FE57DE70-95DE-4B64-9266-84DA811053DB}\HPSUShortcut_BB85ED9CAFC943BDB8DC258C3C7DF72E.exe
+ 2005-03-18 21:23:10 53,248 —-a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2005-03-18 21:23:10 12,800 —-a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Diagnostics.dll
+ 2005-03-18 21:23:14 473,600 —-a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3D.dll
+ 2004-09-29 17:38:58 2,676,224 —-a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-03-18 21:23:10 145,920 —-a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectDraw.dll
+ 2005-03-18 21:23:10 159,232 —-a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectInput.dll
+ 2005-03-18 21:23:14 364,544 —-a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectPlay.dll
+ 2005-03-18 21:23:12 178,176 —-a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectSound.dll
+ 2005-03-18 21:23:14 223,232 —-a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.dll
+ 2004-12-01 20:53:06 2,846,720 —-a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2903.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-02-06 00:32:54 563,712 —-a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2904.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-03-18 22:23:14 567,296 —-a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2905.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-05-26 20:15:56 576,000 —-a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2906.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-07-22 22:21:34 577,024 —-a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2907.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-09-28 19:11:52 577,536 —-a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2908.0\Microsoft.DirectX.Direct3DX.dll
+ 2005-12-05 22:20:50 577,536 —-a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2909.0\Microsoft.DirectX.Direct3DX.dll
+ 2006-02-03 12:40:48 578,560 —-a-w c:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2910.0\Microsoft.DirectX.Direct3DX.dll
- 2000-08-31 13:00:00 28,160 —-a-w c:\windows\nircmd.exe
+ 2000-08-31 14:00:00 28,672 —-a-w c:\windows\nircmd.exe
- 2000-08-31 13:00:00 161,792 —-a-w c:\windows\swreg.exe
+ 2000-08-31 14:00:00 161,792 —-a-w c:\windows\swreg.exe
+ 2004-04-07 16:45:06 225,280 —-a-w c:\windows\system32\AOLDial.dll
- 2007-07-31 00:19:20 92,504 —-a-w c:\windows\system32\cdm.dll
+ 2008-10-16 20:09:44 92,696 —-a-w c:\windows\system32\cdm.dll
+ 2006-11-13 18:38:40 22,824 —-a-w c:\windows\system32\ceutil.dll
- 2006-06-01 21:25:07 16,384 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-12-30 18:01:07 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-12-30 18:00:37 16,384 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat
- 2006-06-01 21:25:07 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-30 18:00:34 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-30 18:01:07 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008123020081231\index.dat
+ 2008-12-30 18:00:45 78,924 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat
- 2006-06-01 21:25:07 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-30 18:01:07 81,920 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2005-02-06 00:45:26 2,222,800 —-a-w c:\windows\system32\d3dx9_24.dll
+ 2005-03-18 22:19:58 2,337,488 —-a-w c:\windows\system32\d3dx9_25.dll
+ 2005-05-26 20:34:52 2,297,552 —-a-w c:\windows\system32\d3dx9_26.dll
+ 2005-07-23 00:59:04 2,319,568 —-a-w c:\windows\system32\d3dx9_27.dll
+ 2005-12-05 23:09:18 2,323,664 —-a-w c:\windows\system32\d3dx9_28.dll
+ 2006-02-03 13:43:16 2,332,368 —-a-w c:\windows\system32\d3dx9_29.dll
- 2007-07-31 00:19:20 92,504 —-a-w c:\windows\system32\dllcache\cdm.dll
+ 2008-10-16 20:09:44 92,696 —-a-w c:\windows\system32\dllcache\cdm.dll
- 2007-07-31 00:19:36 549,720 —-a-w c:\windows\system32\dllcache\wuapi.dll
+ 2008-10-16 20:12:20 561,688 —-a-w c:\windows\system32\dllcache\wuapi.dll
- 2007-07-31 00:19:16 53,080 —-a-w c:\windows\system32\dllcache\wuauclt.exe
+ 2008-10-16 20:09:44 51,224 —-a-w c:\windows\system32\dllcache\wuauclt.exe
- 2007-07-31 00:19:42 1,712,984 —-a-w c:\windows\system32\dllcache\wuaueng.dll
+ 2008-10-16 20:13:40 1,809,944 —-a-w c:\windows\system32\dllcache\wuaueng.dll
- 2007-07-31 00:19:32 325,976 —-a-w c:\windows\system32\dllcache\wucltui.dll
+ 2008-10-16 20:12:22 323,608 —-a-w c:\windows\system32\dllcache\wucltui.dll
- 2007-07-31 00:18:40 33,624 —-a-w c:\windows\system32\dllcache\wups.dll
+ 2008-10-16 20:08:58 34,328 —-a-w c:\windows\system32\dllcache\wups.dll
- 2007-07-31 00:19:28 203,096 —-a-w c:\windows\system32\dllcache\wuweb.dll
+ 2008-10-16 20:12:24 202,776 —-a-w c:\windows\system32\dllcache\wuweb.dll
+ 2008-08-29 15:18:58 87,336 —-a-w c:\windows\system32\dns-sd.exe
+ 2008-08-29 14:53:50 61,440 —-a-w c:\windows\system32\dnssd.dll
- 2004-08-04 03:59:56 36,352 —-a-w c:\windows\system32\drivers\disk.sys
+ 2004-08-04 04:59:56 36,352 —-a-w c:\windows\system32\drivers\disk.sys
- 2006-09-19 21:44:04 15,664 —-a-w c:\windows\system32\drivers\GEARAspiWDM.sys
+ 2008-04-17 18:12:54 15,464 —-a-w c:\windows\system32\drivers\GEARAspiWDM.sys
+ 2008-06-10 18:17:18 521,472 —-a-w c:\windows\system32\drivers\L6PODX3LV.sys
- 2004-08-04 09:00:00 30,080 —-a-w c:\windows\system32\drivers\rndismp.sys
+ 2005-10-21 01:47:04 30,592 —-a-w c:\windows\system32\drivers\rndismp.sys
+ 2005-10-21 01:47:04 30,592 ——w c:\windows\system32\drivers\rndismpx.sys
- 2008-05-02 21:21:52 36,368 —-a-w c:\windows\system32\drivers\tmpreflt.sys
+ 2008-08-16 08:00:46 36,368 —-a-w c:\windows\system32\drivers\tmpreflt.sys
- 2008-05-02 21:22:00 205,328 —-a-w c:\windows\system32\drivers\tmxpflt.sys
+ 2008-08-16 08:00:52 205,328 —-a-w c:\windows\system32\drivers\tmxpflt.sys
- 2004-08-04 09:00:00 12,672 —-a-w c:\windows\system32\drivers\usb8023.sys
+ 2005-10-21 01:47:05 12,800 —-a-w c:\windows\system32\drivers\usb8023.sys
+ 2005-10-21 01:47:05 12,800 ——w c:\windows\system32\drivers\usb8023x.sys
- 2004-08-04 04:08:48 26,496 —-a-w c:\windows\system32\drivers\USBSTOR.SYS
+ 2004-08-04 05:08:48 26,496 —-a-w c:\windows\system32\drivers\USBSTOR.SYS
- 2008-05-02 21:17:18 1,169,240 —-a-w c:\windows\system32\drivers\vsapint.sys
+ 2008-08-16 07:53:50 1,195,448 —-a-w c:\windows\system32\drivers\vsapint.sys
+ 2003-01-10 21:13:04 33,588 —-a-w c:\windows\system32\drivers\wanatw4.sys
+ 2008-04-17 18:12:54 107,368 -c–a-w c:\windows\system32\DRVSTORE\GEARAspiWD_D213663B6381F01E45A131159A9DEFE018321CB3\x86\GEARAspi.dll
+ 2008-04-17 18:12:54 15,464 -c–a-w c:\windows\system32\DRVSTORE\GEARAspiWD_D213663B6381F01E45A131159A9DEFE018321CB3\x86\GEARAspiWDM.sys
+ 2008-06-10 18:17:16 167,936 -c–a-w c:\windows\system32\DRVSTORE\l6podx3_160D5A9C6E411476858D990A5F43A5B52AF645A5\l6podx3.dll
+ 2008-06-10 18:17:16 521,472 -c–a-w c:\windows\system32\DRVSTORE\l6podx3_160D5A9C6E411476858D990A5F43A5B52AF645A5\L6PODX3.sys
+ 2008-06-10 18:17:16 220,672 -c–a-w c:\windows\system32\DRVSTORE\l6podx3_160D5A9C6E411476858D990A5F43A5B52AF645A5\l6podx3_x64.dll
+ 2008-06-10 18:17:18 816,640 -c–a-w c:\windows\system32\DRVSTORE\l6podx3_160D5A9C6E411476858D990A5F43A5B52AF645A5\L6PODX364.sys
+ 2008-06-10 18:17:16 167,936 -c–a-w c:\windows\system32\DRVSTORE\l6podx3_160D5A9C6E411476858D990A5F43A5B52AF645A5\l6podx3lv.dll
+ 2008-06-10 18:17:18 521,472 -c–a-w c:\windows\system32\DRVSTORE\l6podx3_160D5A9C6E411476858D990A5F43A5B52AF645A5\L6PODX3LV.sys
+ 2008-06-10 18:17:16 220,672 -c–a-w c:\windows\system32\DRVSTORE\l6podx3_160D5A9C6E411476858D990A5F43A5B52AF645A5\l6podx3lv_x64.dll
+ 2008-06-10 18:17:18 816,640 -c–a-w c:\windows\system32\DRVSTORE\l6podx3_160D5A9C6E411476858D990A5F43A5B52AF645A5\L6PODX3LV64.sys
+ 2008-06-10 18:17:16 167,936 -c–a-w c:\windows\system32\DRVSTORE\l6podx3_160D5A9C6E411476858D990A5F43A5B52AF645A5\l6podx3pro.dll
+ 2008-06-10 18:17:16 521,472 -c–a-w c:\windows\system32\DRVSTORE\l6podx3_160D5A9C6E411476858D990A5F43A5B52AF645A5\L6PODX3PRO.sys
+ 2008-06-10 18:17:16 220,672 -c–a-w c:\windows\system32\DRVSTORE\l6podx3_160D5A9C6E411476858D990A5F43A5B52AF645A5\l6podx3pro_x64.dll
+ 2008-06-10 18:17:16 816,640 -c–a-w c:\windows\system32\DRVSTORE\l6podx3_160D5A9C6E411476858D990A5F43A5B52AF645A5\L6PODX3Pro64.sys
+ 2008-10-01 18:01:28 32,000 -c–a-w c:\windows\system32\DRVSTORE\usbaapl_246F92BBD6449C86FC3F3F28C40D59AC1F69C558\usbaapl.sys
- 2008-04-10 08:07:11 214,472 —-a-w c:\windows\system32\FNTCACHE.DAT
+ 2008-12-09 04:10:45 233,576 —-a-w c:\windows\system32\FNTCACHE.DAT
- 2006-10-04 00:47:52 109,360 —-a-w c:\windows\system32\GEARAspi.dll
+ 2008-04-17 18:12:54 107,368 —-a-w c:\windows\system32\GEARAspi.dll
+ 2008-06-10 18:17:16 167,936 —-a-w c:\windows\system32\l6podx3lv.dll
+ 2008-10-05 03:16:26 235,936 —-a-r c:\windows\system32\Macromed\Flash\FlashUtil10a.exe
- 2008-05-15 12:00:15 74,137 —-a-w c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2008-11-13 05:01:08 88,590 —-a-w c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2007-02-28 00:36:12 24,576 —-a-w c:\windows\system32\msxml3a.dll
- 2007-07-31 00:19:04 207,736 —-a-w c:\windows\system32\muweb.dll
+ 2008-10-16 20:07:48 208,744 —-a-w c:\windows\system32\muweb.dll
- 2008-03-24 04:35:31 102,358 —-a-w c:\windows\system32\perfc009.dat
+ 2008-11-05 19:46:21 102,358 —-a-w c:\windows\system32\perfc009.dat
- 2008-03-24 04:35:31 531,210 —-a-w c:\windows\system32\perfh009.dat
+ 2008-11-05 19:46:21 531,210 —-a-w c:\windows\system32\perfh009.dat
+ 2006-11-13 18:39:28 138,024 —-a-w c:\windows\system32\rapi.dll
+ 2008-10-16 20:12:20 561,688 —-a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wuapi.dll\7.2.6001.788\wuapi.dll
+ 2008-10-16 20:08:58 34,328 —-a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.788\wups.dll
+ 2008-10-16 20:09:44 43,544 —-a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.788\wups2.dll
+ 2003-04-16 06:10:00 110,592 —-a-w c:\windows\system32\tsccvid.dll
+ 2004-01-07 16:21:24 237,936 —-a-w c:\windows\system32\unicows.dll
- 2007-07-31 00:19:36 549,720 —-a-w c:\windows\system32\wuapi.dll
+ 2008-10-16 20:12:20 561,688 —-a-w c:\windows\system32\wuapi.dll
- 2007-07-31 00:19:16 53,080 —-a-w c:\windows\system32\wuauclt.exe
+ 2008-10-16 20:09:44 51,224 —-a-w c:\windows\system32\wuauclt.exe
- 2007-07-31 00:19:42 1,712,984 —-a-w c:\windows\system32\wuaueng.dll
+ 2008-10-16 20:13:40 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
- 2007-07-31 00:19:32 325,976 —-a-w c:\windows\system32\wucltui.dll
+ 2008-10-16 20:12:22 323,608 —-a-w c:\windows\system32\wucltui.dll
- 2007-07-31 00:18:40 33,624 —-a-w c:\windows\system32\wups.dll
+ 2008-10-16 20:08:58 34,328 —-a-w c:\windows\system32\wups.dll
- 2007-07-31 00:19:12 43,352 —-a-w c:\windows\system32\wups2.dll
+ 2008-10-16 20:09:44 43,544 —-a-w c:\windows\system32\wups2.dll
- 2007-07-31 00:19:28 203,096 —-a-w c:\windows\system32\wuweb.dll
+ 2008-10-16 20:12:24 202,776 —-a-w c:\windows\system32\wuweb.dll
+ 2006-02-03 13:41:26 14,032 —-a-w c:\windows\system32\x3daudio1_0.dll
+ 2006-02-03 13:42:06 230,096 —-a-w c:\windows\system32\xactengine2_0.dll
+ 2005-12-05 23:07:30 61,136 —-a-w c:\windows\system32\xinput9_1_0.dll
- 2003-03-16 03:15:04 90,112 —-a-w c:\windows\unvise32.exe
+ 2004-03-29 21:23:44 90,112 —-a-w c:\windows\unvise32.exe
+ 2006-12-02 03:56:00 96,256 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.dll
+ 2005-09-23 06:16:02 1,093,632 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80.dll
+ 2005-09-23 06:16:06 1,079,808 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80u.dll
+ 2005-09-23 06:16:08 69,632 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80.dll
+ 2005-09-23 06:16:10 57,344 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80u.dll
+ 2006-12-02 05:25:52 1,101,824 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80.dll
+ 2006-12-02 05:25:56 1,093,120 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80u.dll
+ 2006-12-02 05:25:58 69,632 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80.dll
+ 2006-12-02 05:26:00 57,856 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80u.dll
+ 2006-10-26 19:40:36 40,960 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHS.dll
+ 2006-10-26 19:40:36 45,056 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80CHT.dll
+ 2006-10-26 19:40:36 65,536 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80DEU.dll
+ 2006-10-26 19:40:36 57,344 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ENU.dll
+ 2006-10-26 19:40:36 61,440 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ESP.dll
+ 2006-10-26 19:40:36 61,440 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80FRA.dll
+ 2006-10-26 19:40:36 61,440 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80ITA.dll
+ 2006-10-26 19:40:36 49,152 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80JPN.dll
+ 2006-10-26 19:40:36 49,152 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0\mfc80KOR.dll
+ 2006-12-02 05:08:00 40,960 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll
+ 2006-12-02 05:08:00 45,056 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll
+ 2006-12-02 05:08:00 65,536 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll
+ 2006-12-02 05:08:00 57,344 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll
+ 2006-12-02 05:08:00 61,440 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll
+ 2006-12-02 05:08:00 61,440 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll
+ 2006-12-02 05:08:00 61,440 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll
+ 2006-12-02 05:08:00 49,152 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll
+ 2006-12-02 05:08:00 49,152 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll
+ 2006-12-02 05:46:44 65,536 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a\vcomp.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{06663B56-0D73-4f9f-BCC5-4AA941470AFD}"= "c:\program files\PandoBar\SrchAstt\1.bin\P4SRCHAS.DLL" [2007-10-06 61440]

[HKEY_CLASSES_ROOT\clsid\{06663b56-0d73-4f9f-bcc5-4aa941470afd}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{E3EA4FD9-CADE-4ae5-84F7-086EEE888BE4}"= "c:\program files\PandoBar\bar\1.bin\PANDOBAR.DLL" [2007-10-06 266240]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{E3EA4FD9-CADE-4AE5-84F7-086EEE888BE4}"= "c:\program files\PandoBar\bar\1.bin\PANDOBAR.DLL" [2007-10-06 266240]

[HKEY_CLASSES_ROOT\clsid\{e3ea4fd9-cade-4ae5-84f7-086eee888be4}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"Pando"="c:\program files\Pando Networks\Pando\Pando.exe" [2008-11-20 3647304]
"OE_OEM"="c:\trend micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe" [2006-08-04 321040]
"Updates Scheduler"="c:\program files\Common Files\Lacerte Shared\Update Scheduler\UpdSched.EXE" [2008-03-14 65536]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-11-01 94208]
"CTDVDDET"="c:\program files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-17 45056]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" [2005-10-14 122880]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 49152]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 241664]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"pccguide.exe"="c:\trend micro\Internet Security 14\pccguide.exe" [2006-11-21 1807960]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-01-15 185896]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2004-04-07 496752]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"CTHelper"="CTHELPER.EXE" [2006-12-12 c:\windows\system32\CtHelper.exe]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-12-12 c:\windows\system32\Ctxfihlp.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 237568]
Service Manager.norun [2007-02-20 1908]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i263_32.drv
"msacm.g723"= g723.acm
"vidc.I263"= I263_32.drv
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Pando Networks\\Pando\\pando.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\userinit.exe"=
"c:\\Program Files\\Common Files\\InstallShield\\UpdateService\\ISUSPM.exe"=
"c:\\WINDOWS\\system32\\Ctxfihlp.exe"=
"c:\\Program Files\\Dell\\Media Experience\\DMXLauncher.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R2 tmpreflt;tmpreflt;c:\windows\system32\DRIVERS\tmpreflt.sys [2007-09-16 36368]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\DRIVERS\TM_CFW.sys [2007-09-16 280392]
S1 HPZius122;HPZius122;c:\windows\system32\drivers\HPZius122.sys []
S2 Tmntsrv;Trend Micro Real-time Service;c:\trendm~1\INTERN~1\Tmntsrv.exe [2007-09-16 345696]
S2 TmPfw;Trend Micro Personal Firewall;c:\trendm~1\INTERN~1\TmPfw.exe [2007-09-16 923216]
S2 tmproxy;Trend Micro Proxy Service;c:\trendm~1\INTERN~1\tmproxy.exe [2007-09-16 566872]
S3 L6PODX3LV;POD X3 Live Service;c:\windows\system32\Drivers\L6PODX3LV.sys [2008-06-16 521472]
S3 MSSQL$LACERTEDB;MSSQL$LACERTEDB;c:\program files\Microsoft SQL Server\MSSQL$LACERTEDB\Binn\sqlservr.exe -sLACERTEDB []
S3 SQLAgent$LACERTEDB;SQLAgent$LACERTEDB;c:\program files\Microsoft SQL Server\MSSQL$LACERTEDB\Binn\sqlagent.EXE -i LACERTEDB []
S4 cmmonsvc32;cmmonsvc32;"c:\windows\cmmonsvc32.exe" []
.
Contents of the 'Scheduled Tasks' folder

2008-12-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:57]

2009-01-01 c:\windows\Tasks\uwmhkbzp.job
- c:\windows\system32\rundll32.exe [2004-08-04 03:00]
.
- - - - ORPHANS REMOVED - - - -

BHO-{1A48C8F4-5EB5-46B3-94B4-DE2D953F3CB0} - c:\windows\system32\ssqPfdCU.dll
BHO-{2fc5b422-05d7-4a39-8b1a-88d5958ead65} - c:\windows\system32\zeppsm.dll
BHO-{C804C817-2844-47E5-940E-916DEEFF0EE2} - c:\windows\system32\ssqPfdCU.dll
HKLM-Run-DXDllRegExe - dxdllreg.exe
Notify-qommlkh - qommlkh.dll


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://yahoo.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
Trusted Zone: *.update.microsoft.com
Trusted Zone: download.windowsupdate.com
Trusted Zone: *.antimalwareguard.com
Trusted Zone: *.gomyhit.com
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-01 09:37:47
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTSVCCDA.EXE
c:\windows\system32\gearsec.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\system32\CTxfispi.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\hpzipm12.exe
c:\windows\system32\wscntfy.exe
c:\program files\HP\hpcoretech\comp\hpdarc.exe
.
**************************************************************************
.
Completion time: 2009-01-01 9:41:20 - machine was rebooted [Kevin]
ComboFix-quarantined-files.txt 2009-01-01 15:41:18
ComboFix2.txt 2008-06-02 20:35:47
ComboFix3.txt 2008-04-02 02:40:57
ComboFix4.txt 2007-08-31 04:31:20

Pre-Run: 89,423,503,360 bytes free
Post-Run: 90,305,515,520 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

490 — E O F — 2008-05-29 08:01:32
hello

Please download the OTMoveIt3 by OldTimer or from here.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    cmmonsvc32
    HPZius122
    :Reg
    
    :files
    c:\program files\Coupons
    c:\windows\system32\fibunewu.dll
    c:\windows\system32\roziwowu.dll
    c:\windows\system32\vibomate.dll
    c:\windows\Tasks\uwmhkbzp.job
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
Thanks for the help. Things seem to be runnig better already? Is there more wrong than I realized? ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== Service cmmonsvc32 stopped successfully. Service cmmonsvc32 deleted successfully. Service HPZius122 stopped successfully. Service HPZius122 deleted successfully. ========== REGISTRY ========== ========== FILES ========== c:\program files\Coupons moved successfully. DllUnregisterServer procedure not found in c:\windows\system32\fibunewu.dll c:\windows\system32\fibunewu.dll NOT unregistered. c:\windows\system32\fibunewu.dll moved successfully. DllUnregisterServer procedure not found in c:\windows\system32\roziwowu.dll c:\windows\system32\roziwowu.dll NOT unregistered. c:\windows\system32\roziwowu.dll moved successfully. DllUnregisterServer procedure not found in c:\windows\system32\vibomate.dll c:\windows\system32\vibomate.dll NOT unregistered. c:\windows\system32\vibomate.dll moved successfully. c:\windows\Tasks\uwmhkbzp.job moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\Kevin\LOCALS~1\Temp\Perflib_Perfdata_7e8.dat scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Kevin\LOCALS~1\Temp\Perflib_Perfdata_dd8.dat scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Kevin\LOCALS~1\Temp\WCESLog.log scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Kevin\LOCALS~1\Temp\~DF2A10.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 01012009_231943 Files moved on Reboot… File C:\DOCUME~1\Kevin\LOCALS~1\Temp\Perflib_Perfdata_7e8.dat not found! File C:\DOCUME~1\Kevin\LOCALS~1\Temp\Perflib_Perfdata_dd8.dat not found! C:\DOCUME~1\Kevin\LOCALS~1\Temp\WCESLog.log moved successfully. File C:\DOCUME~1\Kevin\LOCALS~1\Temp\~DF2A10.tmp not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
Was plenty wrong at the start :)

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
These scans took a long time. I feel a little discouraged by the volumn of errors. Would I do myself any good running these scans in safe mode? If so how would I disable my pccillin? Here is teh report from the Kasperky scan. Thank you again for any help you can offer. ——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Saturday, January 3, 2009 Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Friday, January 02, 2009 22:55:44 Records in database: 1550312 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ I:\ J:\ L:\ Scan statistics: Files scanned: 147871 Threat name: 31 Infected objects: 94 Suspicious objects: 4 Duration of the scan: 05:16:16 File name / Threat name / Threats count C:\442.tmp Infected: not-a-virus:Downloader.Win32.Agent.q 1 C:\442.tmp Infected: not-a-virus:AdWare.Win32.AdBand.d 1 C:\Documents and Settings\Kevin\.housecall\Quarantine\UNI2C5.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 C:\Documents and Settings\Kevin\.housecall\Quarantine\UNI2CC.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 C:\Documents and Settings\Kevin\.housecall\Quarantine\UNI2D2.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 C:\Documents and Settings\Kevin\.housecall\Quarantine\UNI2D8.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 C:\Documents and Settings\Kevin\.housecall\Quarantine\UNI2EB.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 C:\Documents and Settings\Kevin\.housecall\Quarantine\UNI2F1.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 C:\Documents and Settings\Kevin\.housecall\Quarantine\UNI2F7.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 C:\Documents and Settings\Kevin\.housecall\Quarantine\UNI2FD.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 C:\Documents and Settings\Kevin\.housecall\Quarantine\UNI303.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 C:\Documents and Settings\Kevin\.housecall\Quarantine\UNI309.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 C:\Documents and Settings\Kevin\.housecall6.6\Quarantine\UNI2C5.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 C:\Documents and Settings\Kevin\.housecall6.6\Quarantine\UNI2CC.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 C:\Documents and Settings\Kevin\.housecall6.6\Quarantine\UNI2D2.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 C:\Documents and Settings\Kevin\.housecall6.6\Quarantine\UNI2D8.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 C:\Documents and Settings\Kevin\.housecall6.6\Quarantine\UNI2EB.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 C:\Documents and Settings\Kevin\.housecall6.6\Quarantine\UNI2F1.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 C:\Documents and Settings\Kevin\.housecall6.6\Quarantine\UNI2F7.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 C:\Documents and Settings\Kevin\.housecall6.6\Quarantine\UNI2FD.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 C:\Documents and Settings\Kevin\.housecall6.6\Quarantine\UNI303.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 C:\Documents and Settings\Kevin\.housecall6.6\Quarantine\UNI309.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 C:\Documents and Settings\Kevin\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Suspicious: Trojan-Spy.HTML.Fraud.gen 1 C:\Documents and Settings\logan\Application Data\Sun\Java\Deployment\cache\6.0\23\6c5f45d7-3a5aaddd Infected: Exploit.Java.ByteVerify 1 C:\Documents and Settings\logan\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-4bb5293d-7c21ccb0.zip Infected: Trojan.Java.ClassLoader.as 3 C:\Documents and Settings\mikee\Application Data\Sun\Java\Deployment\cache\6.0\17\299e4e91-39d1d060 Infected: Exploit.Java.ByteVerify 1 C:\Documents and Settings\mikee\Desktop\Shared\dildo lesbians.mpg Infected: Trojan-Downloader.WMA.GetCodec.c 1 C:\HijackThis\backups\backup-20080331-190807-101.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.lie 1 C:\qoobox\Quarantine\C\Program Files\ISM\BndDrive.dll.vir Infected: not-a-virus:AdWare.Win32.AdBand.d 1 C:\qoobox\Quarantine\C\Program Files\ISM\BndDrive2.dll.vir Infected: not-a-virus:AdWare.Win32.AdBand.ad 1 C:\qoobox\Quarantine\C\Program Files\ISM\ISMModule3.exe.vir Infected: not-a-virus:AdWare.Win32.Agent.apq 1 C:\qoobox\Quarantine\C\Program Files\ISM\syncupd.exe.vir Infected: not-a-virus:AdWare.Win32.Agent.apq 1 C:\qoobox\Quarantine\C\Program Files\ISM\syncupd.exe.vir Infected: not-a-virus:AdWare.Win32.AdBand.ad 1 C:\qoobox\Quarantine\C\WINDOWS\Resources\RunOnceKernel.dll.vir Infected: Trojan.Win32.Agent.quk 1 C:\qoobox\Quarantine\C\WINDOWS\system32\818646\818646.dll.vir Infected: not-a-virus:AdWare.Win32.E404.bp 1 C:\qoobox\Quarantine\C\WINDOWS\system32\fedakawu.dll.vir Infected: Trojan.Win32.Monder.agor 1 C:\qoobox\Quarantine\C\WINDOWS\system32\fovutila.dll.vir Infected: Trojan-Spy.Win32.Agent.hgr 1 C:\qoobox\Quarantine\C\WINDOWS\system32\gakasaja.dll.vir Infected: Trojan.Win32.Monder.gen 1 C:\qoobox\Quarantine\C\WINDOWS\system32\gnwhvsty.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.fou 1 C:\qoobox\Quarantine\C\WINDOWS\system32\latalelu.dll.vir Infected: Trojan.Win32.Monder.gen 1 C:\qoobox\Quarantine\C\WINDOWS\system32\oxbfdifk.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.fou 1 C:\qoobox\Quarantine\C\WINDOWS\system32\patapsro.dll.vir Infected: Trojan.Win32.Monder.agia 1 C:\qoobox\Quarantine\C\WINDOWS\system32\pobivamo.dll.vir Infected: Trojan-Spy.Win32.Agent.hgr 1 C:\qoobox\Quarantine\C\WINDOWS\system32\ssqPfdCU.dll.vir Infected: Trojan.Win32.Monder.aggz 1 C:\qoobox\Quarantine\C\WINDOWS\system32\ujxtuqvj.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.fpv 1 C:\qoobox\Quarantine\C\WINDOWS\system32\zeppsm.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.fou 1 C:\qoobox\Quarantine\C\WINDOWS\system32\~.exe.vir Infected: Trojan.Win32.Monder.gen 1 C:\qoobox\Quarantine\C\winlogon.exe.vir Infected: Trojan-Downloader.Win32.VB.dqq 1 C:\Trend Micro\Internet Security 14\Quarantine\112.tmp Suspicious: PECompact 1 C:\Trend Micro\Internet Security 14\Quarantine\1ED.tmp Infected: Trojan.Win32.Monder.agbj 1 C:\Trend Micro\Internet Security 14\Quarantine\1EE.tmp Infected: Trojan.Win32.Monder.agbj 1 C:\Trend Micro\Internet Security 14\Quarantine\1EF.tmp Infected: Trojan.Win32.Monder.afvu 1 C:\Trend Micro\Internet Security 14\Quarantine\2.tmp Suspicious: PECompact 1 C:\Trend Micro\Internet Security 14\Quarantine\20F.tmp Infected: Trojan.Win32.Monderb.acew 1 C:\Trend Micro\Internet Security 14\Quarantine\210.tmp Infected: Trojan.Win32.Monder.agbj 1 C:\Trend Micro\Internet Security 14\Quarantine\211.tmp Infected: Trojan.Win32.Monder.agbj 1 C:\Trend Micro\Internet Security 14\Quarantine\212.tmp Infected: Trojan.Win32.Monder.afvu 1 C:\Trend Micro\Internet Security 14\Quarantine\2F87.tmp Infected: Trojan.Win32.Agent.axoc 1 C:\Trend Micro\Internet Security 14\Quarantine\2F89.tmp Infected: not-a-virus:FraudTool.Win32.VirusRemover.k 1 C:\Trend Micro\Internet Security 14\Quarantine\306C.tmp Infected: Trojan.Win32.Agent.axoc 1 C:\Trend Micro\Internet Security 14\Quarantine\306F.tmp Infected: not-a-virus:FraudTool.Win32.VirusRemover.k 1 C:\Trend Micro\Internet Security 14\Quarantine\30C2.tmp Infected: not-a-virus:FraudTool.Win32.VirusRemover.k 1 C:\Trend Micro\Internet Security 14\Quarantine\537A.tmp Infected: Trojan-Downloader.Java.OpenStream.ac 1 C:\Trend Micro\Internet Security 14\Quarantine\5F3D.tmp Infected: Trojan-Downloader.Java.OpenStream.ac 1 C:\Trend Micro\Internet Security 14\Quarantine\F9.tmp Infected: Trojan.Win32.Monderb.acew 1 C:\WINDOWS\system32\behalave.dll.tmp Infected: Trojan.Win32.Agent.bbvq 1 C:\WINDOWS\system32\dirusimo.dll.tmp Infected: Trojan.Win32.Agent.bbvq 1 C:\WINDOWS\system32\IDME\dimnet201.exe Infected: Trojan.Win32.Multis.bv 1 C:\WINDOWS\system32\yabodesu.dll.tmp Infected: Trojan.Win32.Agent.bbvq 1 D:\Kevin\.housecall\Quarantine\UNI2C5.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 D:\Kevin\.housecall\Quarantine\UNI2CC.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 D:\Kevin\.housecall\Quarantine\UNI2D2.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 D:\Kevin\.housecall\Quarantine\UNI2D8.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 D:\Kevin\.housecall\Quarantine\UNI2EB.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 D:\Kevin\.housecall\Quarantine\UNI2F1.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 D:\Kevin\.housecall\Quarantine\UNI2F7.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 D:\Kevin\.housecall\Quarantine\UNI2FD.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 D:\Kevin\.housecall\Quarantine\UNI303.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 D:\Kevin\.housecall\Quarantine\UNI309.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 D:\Kevin\.housecall6.6\Quarantine\UNI2C5.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 D:\Kevin\.housecall6.6\Quarantine\UNI2CC.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 D:\Kevin\.housecall6.6\Quarantine\UNI2D2.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 D:\Kevin\.housecall6.6\Quarantine\UNI2D8.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 D:\Kevin\.housecall6.6\Quarantine\UNI2EB.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 D:\Kevin\.housecall6.6\Quarantine\UNI2F1.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 D:\Kevin\.housecall6.6\Quarantine\UNI2F7.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 D:\Kevin\.housecall6.6\Quarantine\UNI2FD.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 D:\Kevin\.housecall6.6\Quarantine\UNI303.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 D:\Kevin\.housecall6.6\Quarantine\UNI309.tmp.exe.bac_a02112 Infected: Trojan.Win32.Agent.qg 1 D:\Kevin\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Suspicious: Trojan-Spy.HTML.Fraud.gen 1 D:\Kevin\Local Settings\Temp\D206.tmp Infected: not-a-virus:AdWare.Win32.Agent.vv 1 D:\Kevin\Local Settings\Temp\D206.tmp Infected: not-a-virus:AdWare.Win32.AdBand.e 1 D:\logan\Application Data\Sun\Java\Deployment\cache\6.0\23\6c5f45d7-3a5aaddd Infected: Exploit.Java.ByteVerify 1 D:\logan\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-4bb5293d-7c21ccb0.zip Infected: Trojan.Java.ClassLoader.as 3 The selected area was scanned.
Don't be

Can you post the MBAM log ?


Please download the OTMoveIt3 by OldTimer or from here.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\442.tmp 
    C:\442.tmp 
    C:\Documents and Settings\mikee\Desktop\Shared\dildo lesbians.mpg 
    C:\WINDOWS\system32\behalave.dll.tmp
    C:\WINDOWS\system32\dirusimo.dll.tmp 
    C:\WINDOWS\system32\IDME
    C:\WINDOWS\system32\yabodesu.dll.tmp 
    D:\Kevin\Local Settings\Temp\D206.tmp 
    D:\Kevin\Local Settings\Temp\D206.tmp 
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



Also post a new HJT log
Sorry runnig to and from Little rock for sick inlaws. Battle 2 teenagers for computer time.
I could ot locate MBAM Log.

Here is the lates OTMovit3 log. HJT Log follows.


========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\442.tmp moved successfully.
File/Folder C:\442.tmp not found.
File/Folder C:\Documents and Settings\mikee\Desktop\Shared\dildo lesbians.mpg not found.
C:\WINDOWS\system32\behalave.dll.tmp moved successfully.
C:\WINDOWS\system32\dirusimo.dll.tmp moved successfully.
C:\WINDOWS\system32\IDME moved successfully.
C:\WINDOWS\system32\yabodesu.dll.tmp moved successfully.
D:\Kevin\Local Settings\Temp\D206.tmp moved successfully.
File/Folder D:\Kevin\Local Settings\Temp\D206.tmp not found.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Kevin\LOCALS~1\Temp\Perflib_Perfdata_30c.dat scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Kevin\LOCALS~1\Temp\Perflib_Perfdata_df4.dat scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Kevin\LOCALS~1\Temp\WCESLog.log scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Kevin\LOCALS~1\Temp\~DF2979.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 01052009_231510

Files moved on Reboot…
File C:\DOCUME~1\Kevin\LOCALS~1\Temp\Perflib_Perfdata_30c.dat not found!
File C:\DOCUME~1\Kevin\LOCALS~1\Temp\Perflib_Perfdata_df4.dat not found!
C:\DOCUME~1\Kevin\LOCALS~1\Temp\WCESLog.log moved successfully.
File C:\DOCUME~1\Kevin\LOCALS~1\Temp\~DF2979.tmp not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.


HJT Log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:25, on 1/5/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\TRENDM~1\INTERN~1\TmPfw.exe
C:\TRENDM~1\INTERN~1\tmproxy.exe
C:\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Common Files\Lacerte Shared\Update Scheduler\UpdSched.EXE
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\PROGRA~1\MICROS~4\OFFICE11\OUTLOOK.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Pando Networks\Pando\pando.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {06663B56-0D73-4f9f-BCC5-4AA941470AFD} - C:\Program Files\PandoBar\SrchAstt\1.bin\P4SRCHAS.DLL
O2 - BHO: (no name) - {06663B51-0D73-4f9f-BCC5-4AA941470AFD} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: CInterceptor Object - {38D3FE60-3D53-4F37-BB0E-C7A97A26A156} - C:\Program Files\Pando Networks\Pando\PandoIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: Pando Toolbar - {E3EA4FD9-CADE-4ae5-84F7-086EEE888BE4} - C:\Program Files\PandoBar\bar\1.bin\PANDOBAR.DLL
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Trend Micro\Internet Security 14\pccguide.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Pando] "C:\Program Files\Pando Networks\Pando\Pando.exe" /Minimized
O4 - HKCU\..\Run: [OE_OEM] "C:\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [Updates Scheduler] C:\Program Files\Common Files\Lacerte Shared\Update Scheduler\UpdSched.EXE
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Service Manager.norun
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://download.windowsupdate.com
O15 - Trusted Zone: *.antimalwareguard.com (HKLM)
O15 - Trusted Zone: *.gomyhit.com (HKLM)
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://symantec.atgnow.com/sdccommon/download/tgctlsi.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1228795483884
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1228795455962
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.2.1.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\roziwowu.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (file missing)
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton Ghost - Unknown owner - C:\Program Files\Norton Ghost\Agent\VProSvc.exe (file missing)
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (file missing)
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\TRENDM~1\INTERN~1\tmproxy.exe

–
End of file - 12547 bytes
hello

1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

O15 - Trusted Zone: *.antimalwareguard.com (HKLM)
O15 - Trusted Zone: *.gomyhit.com (HKLM)
O20 - AppInit_DLLs: C:\WINDOWS\system32\roziwowu.dll


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.



Reboot and post a new HJT log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI