This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] maware/spyware/popups

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Greetings
Ma's computer has been infested with some nastys…have done several antivirus, spyware scans….continue to have popups from poker sites, "fix my pc", etc, etc. Also,,,can't turn on automatic updates OR update from microsoft, so sorry if the defs aren't up to date.

Hijack log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:00:15 PM, on 1/1/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SYSTEM32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\lxbycoms.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\system32\imapi.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Windows Live Toolbar\msn_sl.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [LXBYCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBYtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [7023ed5f] rundll32.exe "C:\WINDOWS\system32\ybeusidw.dll",b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopularScreensaversWallpaper] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\F3SCRCTR.DLL,LES
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [SVCHOST.EXE] C:\WINDOWS\system32\drivers\svchost.exe
O4 - HKCU\..\Run: [98488504487498458609712227571907] C:\Program Files\Antivirus 2009\av2009.exe
O4 - HKCU\..\Run: [ieupdate] "C:\WINDOWS\system32\explorer32.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Holiday Lights.lnk = C:\Program Files\Tiger Technologies\Holiday Lights\Holiday Lights.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O8 - Extra context menu item: &Search -
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://zone.msn.com/bingame/dim2/default/popcaploader_v6.cab
O20 - AppInit_DLLs: aonbcb.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxby_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbycoms.exe

–
End of file - 8157 bytes


thanks!!
hello

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.
Thank you for your help
Here is the sdfix report:


SDFix: Version 1.240
Run by [removed] on Thu 01/01/2009 at 01:28 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP1.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP10.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP11.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP12.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP13.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP14.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP15.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP16.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP1E.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP1F.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP2.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP20.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP21.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP22.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP23.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP24.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP25.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP26.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP27.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP28.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP29.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP2A.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP3.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP35.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP36.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP3B.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP3D.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP4.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP46.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP47.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP5.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP6.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP64.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP65.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP66.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP67.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP7.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP7D.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP7E.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP7F.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP8.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP9.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP93.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP94.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP95.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP96.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP97.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP98.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMP99.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMPA.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMPB.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMPC.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMPD.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMPE.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\TMPF.tmp - Deleted





Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-01 13:49:14
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Tue 20 Nov 2001 43,520 A..H. — "C:\Program Files\Tiger Technologies\Holiday Lights\insthelp.exe"
Sat 23 Dec 2006 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Fri 12 Nov 2004 37,376 …H. — "C:\Program Files\Common Files\Adobe\ESD\DLMCleanup.exe"

Finished!



PS: Virus alert came on that there was a trojan somewhere when sdfix was done it's final process.
hello

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
Here are the otlistit.txt and extras.txt respectively….

OTListIt logfile created on: 1/1/2009 2:11:54 PM - Run
OTListIt2 by OldTimer - Version 1.0.1.1 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

959.36 Mb Total Physical Memory | 553.79 Mb Available Physical Memory | 57.72% Memory free
2.26 Gb Paging File | 1.87 Gb Available in Paging File | 82.60% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 63.87 Gb Free Space | 85.71% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: WAYNE-253422C9C
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation)
C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
C:\Documents and Settings\Owner\Desktop\OTListIt2.exe (OldTimer Tools)

========== (O23) Win32 Services (SafeList) ==========

(Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
(aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
(aswUpdSv [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
(Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
(avast! Antivirus [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
(avast! Mail Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
(avast! Web Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
(Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
(clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
(gusvc [Auto | Running]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
(IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
(iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
(lxby_device [On_Demand | Stopped]) – C:\WINDOWS\system32\lxbycoms.exe (Lexmark International, Inc.)
(usnjsvc [On_Demand | Stopped]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
(WMPNetworkSvc [Auto | Running]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

(Aavmker4 [System | Running]) – C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
(AmdK8 [System | Running]) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
(aswFsBlk [Auto | Running]) – C:\WINDOWS\system32\drivers\aswFsBlk.sys (ALWIL Software)
(aswMon2 [Auto | Running]) – C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
(aswRdr [On_Demand | Running]) – C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
(aswSP [System | Running]) – C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
(aswTdi [System | Running]) – C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
(ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
(catchme [On_Demand | Running]) – File not found
(GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
(HdAudAddService [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
(HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
(IntcAzAudAddService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
(itchfltr [On_Demand | Running]) – C:\WINDOWS\system32\drivers\itchfltr.sys (Logitech, Inc.)
(L8042pr2 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\L8042pr2.Sys (Logitech, Inc.)
(LHidFlt2 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\LHIDFLT2.SYS (Logitech, Inc.)
(LMouFlt2 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
(pfc [On_Demand | Running]) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
(Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
(rtl8139 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
(Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(Tcpip6 [System | Running]) – C:\WINDOWS\system32\drivers\tcpip6.sys (Microsoft Corporation)
(tunmp [On_Demand | Running]) – C:\WINDOWS\system32\drivers\tunmp.sys (Microsoft Corporation)
(USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaapl.sys (Apple, Inc.)
(WS2IFSL [System | Running]) – C:\WINDOWS\system32\drivers\ws2ifsl.sys (Microsoft Corporation)

========== Standard Registry (All) ==========


========== Internet Explorer ==========

HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,AutoSearch = http://ie.search.msn.com/{SUB_RFC1766}/src…autosearch.aspx
HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key does not exist or could not be opened. File not found
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

O1 HOSTS File: (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (no name) - {9975FF86-851C-422E-A2A1-25E4C13D67F1} - C:\WINDOWS\system32\rqRKBQhG.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll (Google Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key does not exist or could not be opened. File not found
O4 - HKLM..\Run: [7023ed5f] rundll32.exe "C:\WINDOWS\system32\ybeusidw.dll",b ()
O4 - HKLM..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [LXBYCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBYtime.dll,_RunDLLEntry@16 ()
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [PopularScreensaversWallpaper] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\F3SCRCTR.DLL,LES File not found
O4 - HKCU..\Run: [PowerBar] File not found
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1 File not found
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Search -
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\NPJPI150_06.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll [2001/08/01 19:05:42 | 00,270,336 | —- | M] (Intertrust Technologies, Inc.)
O15 - HKLM\..Trusted Sites: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab (MessengerStatsClient Class)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab (ZoneIntro Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_03)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://zone.msn.com/bingame/dim2/default/popcaploader_v6.cab (Reg Error: Key does not exist or could not be opened.)
O18 - Protocol\Handler: - about - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - cdl - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - dvd - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler: - file - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ftp - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - gopher - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http\0x00000001 - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http\oledb - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler: - https - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - https\0x00000001 - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler: - https\oledb - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ipp - No CLSID value found
O18 - Protocol\Handler: - ipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler: - its - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - javascript - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - livecall - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler: - local - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mailto - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mhtml - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mk - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp - No CLSID value found
O18 - Protocol\Handler: - msdaipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp\oledb - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ms-its - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msnim - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler: - res - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - sysimage - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - tv - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler: - vbscript - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - wia - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - See sections below for AppInitDlls and Winlogon settings
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9}C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9}C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153}C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5}C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: (Browseui preloader) - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: (Component Categories cache daemon) - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)

========== HKLM Winlogon Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell" = Explorer.exe
>C:\WINDOWS\explorer.exe (Microsoft Corporation)

"UserInit" = C:\WINDOWS\system32\userinit.exe,
>C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)

"UIHost" = logonui.exe
>C:\WINDOWS\system32\logonui.exe (Microsoft Corporation)

"VMApplet" = rundll32 shell32,Control_RunDLL "sysdm.cpl"
>C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
>C:\WINDOWS\system32\sysdm.cpl (Microsoft Corporation)


========== Winlogon Notify Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
AtiExtEvent: "DllName" = Ati2evxx.dll – C:\WINDOWS\system32\ati2evxx.dll (ATI Technologies Inc.)
crypt32chain: "DllName" = crypt32.dll – C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
cryptnet: "DllName" = cryptnet.dll – C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
cscdll: "DllName" = cscdll.dll – C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
dimsntfy: "DllName" = %SystemRoot%\System32\dimsntfy.dll – C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
efcBqrrO: "DllName" = efcBqrrO.dll – File not found
ScCertProp: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Schedule: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
sclgntfy: "DllName" = sclgntfy.dll – C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
SensLogn: "DllName" = WlNotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
termsrv: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
WgaLogon: "DllName" = WgaLogon.dll – C:\WINDOWS\system32\WgaLogon.dll (Microsoft Corporation)
wlballoon: "DllName" = wlnotify.dll – C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)

========== IFEO "Debugger" Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\]
Your Image File Name Here without a path:"Debugger" = C:\WINDOWS\system32\ntsd.exe (Microsoft Corporation)

========== Shell Execute Hooks ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}" (HKLM) – C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)

========== HKLM *SecurityProviders* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders" = msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
>C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)
>C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
>C:\WINDOWS\system32\digest.dll (Microsoft Corporation)
>C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)

========== LSA *Authentication Packages* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages" = msv1_0,C:\WINDOWS\system32\rqRKBQhG,
>C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
>C:\WINDOWS\system32\rqRKBQhG.dll ()

========== LSA *Security Packages* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Security Packages" = kerberos,msv1_0,schannel,wdigest,
>C:\WINDOWS\system32\kerberos.dll (Microsoft Corporation)
>C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
>C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
>C:\WINDOWS\system32\wdigest.dll (Microsoft Corporation)

========== Safeboot Options ==========

"AlternateShell" = cmd.exe

========== CDRom AutoRun Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1

========== Autorun Files on Drives ==========

AUTOEXEC.BAT []
C:\AUTOEXEC.BAT () – [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[5 C:\WINDOWS\*.tmp files]
[2009/01/01 14:10:28 | 00,419,328 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/01/01 13:27:14 | 00,578,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\user32.dll
[2009/01/01 13:23:56 | 00,000,000 | —D | C] – C:\WINDOWS\ERUNT
[2009/01/01 13:17:52 | 00,000,000 | —D | C] – C:\SDFix
[2009/01/01 12:00:00 | 00,001,734 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/01/01 12:00:00 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2008/12/31 20:14:42 | 00,130,560 | —- | C] () – C:\WINDOWS\System32\ujcqjpsb.dll
[2008/12/31 20:12:35 | 01,763,265 | -HS- | C] () – C:\WINDOWS\System32\wdisueby.ini
[2008/12/31 20:12:34 | 00,089,600 | —- | C] () – C:\WINDOWS\System32\ybeusidw.dll
[2008/12/31 08:12:00 | 01,763,265 | -HS- | C] () – C:\WINDOWS\System32\clihwyri.ini
[2008/12/31 08:08:58 | 00,130,560 | —- | C] () – C:\WINDOWS\System32\kptxdhkr.dll
[2008/12/30 08:10:47 | 01,763,265 | -HS- | C] () – C:\WINDOWS\System32\bbeolpsu.ini
[2008/12/30 08:08:45 | 00,126,976 | —- | C] () – C:\WINDOWS\System32\kkfsgi.dll
[2008/12/30 08:08:43 | 00,126,976 | —- | C] () – C:\WINDOWS\System32\xxvxkmch.dll
[2008/12/29 08:09:19 | 01,763,258 | -HS- | C] () – C:\WINDOWS\System32\ewuciggc.ini
[2008/12/28 21:30:08 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\WMTools Downloaded Files
[2008/12/28 11:28:56 | 01,762,037 | -HS- | C] () – C:\WINDOWS\System32\bqobmnxn.ini
[2008/12/27 11:26:17 | 01,762,028 | -HS- | C] () – C:\WINDOWS\System32\xfndjerc.ini
[2008/12/26 19:10:03 | 01,752,841 | -HS- | C] () – C:\WINDOWS\System32\ifaujgot.ini
[2008/12/26 14:36:45 | 00,000,268 | -H– | C] () – C:\sqmdata17.sqm
[2008/12/26 14:36:45 | 00,000,244 | -H– | C] () – C:\sqmnoopt17.sqm
[2008/12/25 19:07:53 | 01,752,841 | -HS- | C] () – C:\WINDOWS\System32\wjhvxcnr.ini
[2008/12/25 18:59:19 | 00,003,693 | -HS- | C] () – C:\WINDOWS\System32\GhQBKRqr.ini2
[2008/12/25 18:59:19 | 00,003,693 | -HS- | C] () – C:\WINDOWS\System32\GhQBKRqr.ini
[2008/12/25 18:59:15 | 00,294,400 | —- | C] () – C:\WINDOWS\System32\rqRKBQhG.dll
[2008/12/22 22:02:47 | 00,000,268 | -H– | C] () – C:\sqmdata16.sqm
[2008/12/22 22:02:47 | 00,000,244 | -H– | C] () – C:\sqmnoopt16.sqm
[2008/12/07 22:21:01 | 00,000,268 | -H– | C] () – C:\sqmdata15.sqm
[2008/12/07 22:21:01 | 00,000,244 | -H– | C] () – C:\sqmnoopt15.sqm

========== Files - Modified Within 30 Days ==========

[2 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/01/01 14:12:53 | 00,003,693 | -HS- | M] () – C:\WINDOWS\System32\GhQBKRqr.ini
[2009/01/01 14:11:51 | 00,003,693 | -HS- | M] () – C:\WINDOWS\System32\GhQBKRqr.ini2
[2009/01/01 14:10:32 | 00,419,328 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/01/01 13:57:00 | 00,000,254 | —- | M] () – C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
[2009/01/01 13:48:40 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/01/01 13:48:18 | 00,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/01/01 13:47:30 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/01/01 13:47:22 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/01/01 13:29:00 | 00,000,686 | —- | M] () – C:\WINDOWS\System32\drivers\etc\HOSTS
[2009/01/01 13:27:15 | 00,578,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\user32.dll
[2009/01/01 12:00:00 | 00,001,734 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/01/01 11:03:02 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2008/12/31 21:29:43 | 00,002,187 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2008/12/31 20:12:39 | 01,763,265 | -HS- | M] () – C:\WINDOWS\System32\wdisueby.ini
[2008/12/31 20:12:35 | 00,089,600 | —- | M] () – C:\WINDOWS\System32\ybeusidw.dll
[2008/12/31 19:51:18 | 00,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2008/12/31 08:12:08 | 01,763,265 | -HS- | M] () – C:\WINDOWS\System32\clihwyri.ini
[2008/12/31 08:11:15 | 01,763,265 | -HS- | M] () – C:\WINDOWS\System32\bbeolpsu.ini
[2008/12/30 08:09:59 | 01,763,258 | -HS- | M] () – C:\WINDOWS\System32\ewuciggc.ini
[2008/12/30 08:08:45 | 00,126,976 | —- | M] () – C:\WINDOWS\System32\xxvxkmch.dll
[2008/12/30 08:08:45 | 00,126,976 | —- | M] () – C:\WINDOWS\System32\kkfsgi.dll
[2008/12/29 10:38:35 | 00,000,119 | —- | M] () – C:\WINDOWS\wininit.ini
[2008/12/29 08:08:08 | 01,762,037 | -HS- | M] () – C:\WINDOWS\System32\bqobmnxn.ini
[2008/12/28 11:27:10 | 01,762,028 | -HS- | M] () – C:\WINDOWS\System32\xfndjerc.ini
[2008/12/27 21:54:24 | 00,074,752 | -HS- | M] () – C:\Documents and Settings\Owner\My Documents\Thumbs.db
[2008/12/27 21:23:17 | 00,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2008/12/26 19:10:07 | 01,752,841 | -HS- | M] () – C:\WINDOWS\System32\ifaujgot.ini
[2008/12/26 19:08:22 | 01,752,841 | -HS- | M] () – C:\WINDOWS\System32\wjhvxcnr.ini
[2008/12/26 14:36:45 | 00,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2008/12/26 14:36:45 | 00,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2008/12/25 18:59:18 | 00,294,400 | —- | M] () – C:\WINDOWS\System32\rqRKBQhG.dll
[2008/12/25 18:54:29 | 00,016,904 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2008/12/22 22:02:47 | 00,000,268 | -H– | M] () – C:\sqmdata16.sqm
[2008/12/22 22:02:47 | 00,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2008/12/13 00:40:02 | 03,593,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.dll
[2008/12/13 00:40:02 | 03,593,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2008/12/09 22:21:45 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2008/12/09 17:24:37 | 17,593,280 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2008/12/07 22:21:01 | 00,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2008/12/07 22:21:01 | 00,000,244 | -H– | M] () – C:\sqmnoopt15.sqm

========== LOP Check ==========

[2008/12/29 10:41:27 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/11/01 19:03:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2006/03/28 19:56:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/01/13 17:24:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2008/01/13 17:25:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2006/02/01 09:53:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2006/02/08 14:26:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FaxCtr
[2006/09/17 11:32:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2009/01/01 09:26:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google Updater
[2006/07/21 22:11:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Individual Software
[2006/08/11 16:55:22 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2006/07/21 19:04:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2006/02/13 12:49:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2006/12/23 22:09:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/03/12 18:59:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2006/01/31 17:49:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2007/03/05 18:56:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
[2008/12/25 18:43:01 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Owner\Application Data
[2006/03/10 21:43:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\7Wonders
[2007/09/22 17:07:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Adobe
[2006/03/28 19:57:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AdobeAUM
[2007/03/23 19:25:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AdobeUM
[2008/07/12 20:27:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Apple Computer
[2006/01/31 19:32:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ATI
[2006/02/01 10:01:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\CyberLink
[2006/02/13 12:49:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\eLanguage
[2008/07/12 20:47:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FaxCtr
[2006/03/22 18:58:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Google
[2006/02/08 14:21:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Help
[2006/01/31 18:25:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Identities
[2006/02/01 09:56:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterTrust
[2006/08/11 16:55:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Lavasoft
[2006/04/14 18:18:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2006/02/08 14:26:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Macromedia
[2008/12/27 21:42:44 | 00,000,000 | –SD | M] – C:\Documents and Settings\Owner\Application Data\Microsoft
[2007/04/26 22:22:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Real
[2006/02/20 18:23:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sun
[2009/01/01 11:03:02 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2009/01/01 13:57:00 | 00,000,254 | —- | M] () – C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
[2004/08/04 06:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2006/07/26 21:14:07 | 00,000,260 | —- | M] () – C:\WINDOWS\Tasks\Disk Cleanup.job
[2009/01/01 13:47:30 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 318 bytes -> %UserProfile%\Desktop\a2z WordFinder Free Dictionary Lookup For Scrabble, Literati, Anagrams, Word Puzzles and Teaching Lessons.url:favicon
@Alternate Data Stream - 114 bytes -> %AllUsersProfile%\Application Data\TEMP:AFB00961
@Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\Thumbs.db:encryptable
< End of report >


OTListIt Extras logfile created on: 1/1/2009 2:11:54 PM - Run
OTListIt2 by OldTimer - Version 1.0.1.1 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

959.36 Mb Total Physical Memory | 553.79 Mb Available Physical Memory | 57.72% Memory free
2.26 Gb Paging File | 1.87 Gb Available in Paging File | 82.60% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 63.87 Gb Free Space | 85.71% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: WAYNE-253422C9C
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
"DisableMonitoring" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
"DisableMonitoring" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 (Microsoft Corporation)
C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire (Lime Wire, LLC)
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 (Microsoft Corporation)
C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) (Microsoft Corporation)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{036AA4D4-6D32-11D4-9875-00105ACE7734}" = Logitech iTouch Software
"{047815FB-4E38-42D5-95CB-8A131DDD8668}" = Microsoft Windows Theme Nunavut
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = Multimedia Launcher
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{3248F0A8-6813-11D6-A77B-00B0D0150030}" = J2SE Runtime Environment 5.0 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{341201D4-4F61-4ADB-987E-9CCE4D83A58D}" = Windows Live Toolbar Extension (Windows Live Toolbar)
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35E1A8C8-6646-4101-B0AA-42D1EB2AB3AE}" = Windows Live Outlook Toolbar (Windows Live Toolbar)
"{49672EC2-171B-47B4-8CE7-50D7806360D7}" = Windows Live Sign-in Assistant
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{53B2CFE9-A508-4457-B2CA-5D253536BFB7}" = OneCare Advisor (Windows Live Toolbar)
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = Logitech MouseWare 9.79.3
"{5EC7969A-5B98-46EE-8B4E-42DF76C6F15D}" = ATI Catalyst Control Center
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{66A7A386-6F35-41A7-A731-101F0C0153C8}" = Popup Blocker (Windows Live Toolbar)
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{764C0C8F-B1B1-49BF-AEDC-4E48E857A667}" = Lexmark Fax Solutions
"{7745B7A9-F323-4BB9-9811-01BF57A028DA}" = Map Button (Windows Live Toolbar)
"{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}" = Windows Live Favorites for Windows Live Toolbar
"{83F3EED2-DDE2-4434-8FBE-9D2A1E7C2BC8}" = ALL-IN-1 USB2.0 CARD READER
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8A62A068-3FD6-495A-9F66-26FE94F32EC9}" = Rhapsody Player Engine
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{976C2B2A-CE59-4AB3-83FB-BF895E28F2E6}" = Apple Mobile Device Support
"{9FCCD9B3-4FC4-4F23-8054-ABCB0FB9FC4E}" = Learn to Speak Spanish 9.5
"{AC76BA86-7AD7-1033-7B44-A70700000002}" = Adobe Reader 7.0.8
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{B97CF5C3-0487-11D8-A36E-0050BAE317E1}" = DVD Solution
"{C9618743-1A5C-461E-91C4-E013A3D70F3C}" = Adobe® Photoshop® Album Starter Edition 3.0.1
"{C9D96682-5A4D-45FA-BA3E-DDCB2B0CB868}" = Safari
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D5A145FC-D00C-4F1A-9119-EB4D9D659750}" = Windows Live Toolbar
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{DDDE0BE3-0CBE-4BF6-B75A-E3F69C947843}" = iTunes
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F3812D83-86D2-4445-A841-3E0BA4F9A11C}" = Merriam-Webster 3.0
"Ad-Aware SE Personal" = Ad-Aware SE Personal
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"AdobeESD" = Adobe Download Manager 2.0 (Remove Only)
"All ATI Software" = ATI - Software Uninstall Utility
"AQ3D" = Aquatica 3D
"Aquatica3" = Aquatica 3
"ATI Display Driver" = ATI Display Driver
"avast!" = avast! Antivirus
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"Holiday Lights" = Holiday Lights 5.4
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{764C0C8F-B1B1-49BF-AEDC-4E48E857A667}" = Lexmark Fax Solutions
"Lexmark P910 Series" = Lexmark P910 Series
"LimeWire" = LimeWire 4.10.5
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"Nero - Burning Rom!UninstallKey" = Nero OEM
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"prunnet" = Advertisement Service
"Windows Live Toolbar" = Windows Live Toolbar
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMCSetup" = Windows Media Connect
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 12/11/2008 11:52:34 AM | Computer Name = WAYNE-253422C9C | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
http://www.loblawstores.ca/ScriptResource….049125920000000
failed, 0000A413.

[ Application Events ]
Error - 12/27/2008 9:03:57 PM | Computer Name = WAYNE-253422C9C | Source = Application Error | ID = 1000
Description = Faulting application av2009.exe, version 0.0.0.0, faulting module
av2009.exe, version 0.0.0.0, fault address 0x000015ca.

Error - 12/27/2008 9:04:09 PM | Computer Name = WAYNE-253422C9C | Source = Application Error | ID = 1000
Description = Faulting application av2009.exe, version 0.0.0.0, faulting module
av2009.exe, version 0.0.0.0, fault address 0x000015ca.

Error - 12/27/2008 9:12:17 PM | Computer Name = WAYNE-253422C9C | Source = Application Error | ID = 1000
Description = Faulting application av2009.exe, version 0.0.0.0, faulting module
av2009.exe, version 0.0.0.0, fault address 0x000015ca.

Error - 12/27/2008 9:12:43 PM | Computer Name = WAYNE-253422C9C | Source = Application Error | ID = 1000
Description = Faulting application av2009.exe, version 0.0.0.0, faulting module
av2009.exe, version 0.0.0.0, fault address 0x000015ca.

Error - 12/27/2008 9:13:35 PM | Computer Name = WAYNE-253422C9C | Source = Application Error | ID = 1000
Description = Faulting application explorer32.exe, version 0.0.0.0, faulting module
explorer32.exe, version 0.0.0.0, fault address 0x00001622.

Error - 12/27/2008 9:17:09 PM | Computer Name = WAYNE-253422C9C | Source = Application Error | ID = 1000
Description = Faulting application av2009.exe, version 0.0.0.0, faulting module
av2009.exe, version 0.0.0.0, fault address 0x000015ca.

Error - 12/27/2008 9:34:18 PM | Computer Name = WAYNE-253422C9C | Source = Application Error | ID = 1000
Description = Faulting application explorer32.exe, version 0.0.0.0, faulting module
explorer32.exe, version 0.0.0.0, fault address 0x00001622.

Error - 12/27/2008 9:37:44 PM | Computer Name = WAYNE-253422C9C | Source = Application Error | ID = 1000
Description = Faulting application explorer32.exe, version 0.0.0.0, faulting module
explorer32.exe, version 0.0.0.0, fault address 0x00001622.

Error - 12/28/2008 12:03:41 AM | Computer Name = WAYNE-253422C9C | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

Error - 12/31/2008 12:39:17 AM | Computer Name = WAYNE-253422C9C | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

[ System Events ]
Error - 1/1/2009 3:23:27 PM | Computer Name = WAYNE-253422C9C | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 1/1/2009 3:23:36 PM | Computer Name = WAYNE-253422C9C | Source = Service Control Manager | ID = 7001
Description = The DHCP Client service depends on the NetBios over Tcpip service
which failed to start because of the following error: %%31

Error - 1/1/2009 3:23:36 PM | Computer Name = WAYNE-253422C9C | Source = Service Control Manager | ID = 7001
Description = The DNS Client service depends on the TCP/IP Protocol Driver service
which failed to start because of the following error: %%31

Error - 1/1/2009 3:23:36 PM | Computer Name = WAYNE-253422C9C | Source = Service Control Manager | ID = 7001
Description = The TCP/IP NetBIOS Helper service depends on the AFD service which
failed to start because of the following error: %%31

Error - 1/1/2009 3:23:36 PM | Computer Name = WAYNE-253422C9C | Source = Service Control Manager | ID = 7001
Description = The IPv6 Helper Service service depends on the Microsoft IPv6 Protocol
Driver service which failed to start because of the following error: %%31

Error - 1/1/2009 3:23:36 PM | Computer Name = WAYNE-253422C9C | Source = Service Control Manager | ID = 7001
Description = The Apple Mobile Device service depends on the TCP/IP Protocol Driver
service which failed to start because of the following error: %%31

Error - 1/1/2009 3:23:36 PM | Computer Name = WAYNE-253422C9C | Source = Service Control Manager | ID = 7001
Description = The Bonjour Service service depends on the TCP/IP Protocol Driver
service which failed to start because of the following error: %%31

Error - 1/1/2009 3:23:36 PM | Computer Name = WAYNE-253422C9C | Source = Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver service which
failed to start because of the following error: %%31

Error - 1/1/2009 3:23:36 PM | Computer Name = WAYNE-253422C9C | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Aavmker4 AFD AmdK8 aswSP aswTdi Fips IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip Tcpip6 WS2IFSL

Error - 1/1/2009 3:57:00 PM | Computer Name = WAYNE-253422C9C | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}


< End of report >
hello

Please click on Start > Control Panel > Add/Remove Programs and uninstall the following programs(if present):

prunnet

1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

O2 - BHO: (no name) - {9975FF86-851C-422E-A2A1-25E4C13D67F1} - C:\WINDOWS\system32\rqRKBQhG.dll ()
O3 - HKCU\..\Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key does not exist or could not be opened. File not found
O4 - HKLM..\Run: [7023ed5f] rundll32.exe "C:\WINDOWS\system32\ybeusidw.dll",b ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.



Please download the OTMoveIt3 by OldTimer or from here.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
    "Authentication Packages"=hex(7):6d,00,73,00,76,00,31,00,5f,00,30,00,00,00,00,\
      00
    
    :files
    C:\WINDOWS\System32\ujcqjpsb.dll
    C:\WINDOWS\System32\wdisueby.ini
    C:\WINDOWS\System32\ybeusidw.dll
    C:\WINDOWS\System32\clihwyri.ini
    C:\WINDOWS\System32\kptxdhkr.dll
    C:\WINDOWS\System32\bbeolpsu.ini
    C:\WINDOWS\System32\kkfsgi.dll
    C:\WINDOWS\System32\xxvxkmch.dll
    C:\WINDOWS\System32\ewuciggc.ini
    C:\WINDOWS\System32\bqobmnxn.ini
    C:\WINDOWS\System32\xfndjerc.ini
    C:\WINDOWS\System32\ifaujgot.ini
    C:\WINDOWS\System32\wjhvxcnr.ini
    C:\WINDOWS\System32\GhQBKRqr.ini2
    C:\WINDOWS\System32\GhQBKRqr.ini
    C:\WINDOWS\System32\rqRKBQhG.dll
    C:\WINDOWS\System32\GhQBKRqr.ini
    C:\WINDOWS\System32\GhQBKRqr.ini2
    C:\WINDOWS\System32\wdisueby.ini
    C:\WINDOWS\System32\ybeusidw.dll
    C:\WINDOWS\System32\clihwyri.ini
    C:\WINDOWS\System32\bbeolpsu.ini
    C:\WINDOWS\System32\ewuciggc.ini
    C:\WINDOWS\System32\xxvxkmch.dll
    C:\WINDOWS\System32\kkfsgi.dll
    C:\WINDOWS\System32\bqobmnxn.ini
    C:\WINDOWS\System32\xfndjerc.ini
    C:\WINDOWS\System32\ifaujgot.ini
    C:\WINDOWS\System32\wjhvxcnr.ini
    C:\WINDOWS\System32\rqRKBQhG.dll
    
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



Open OTListIt2.exe
  • Click the None button at the top
  • Under the Custom Scan box at the bottom left paste the following in

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg
    %systemroot%\Prefetch\*.* /s
    %systemroot%\system32\drivers\*.dat
    %systemroot%\Temp\bca4e2da.$$$
    %systemroot%\Temp\ed47fa.$
    %systemroot%\Temp\fa56d7ec.$$$
    %systemroot%\Temp\*.$$$
    %systemroot%\System32\antiwpa.dll
    %SYSTEMDRIVE%\*.epk
    %systemroot%\*.epk
    %systemroot%\system32\*.epk
    %systemroot%\system32\bb*.dat
    %systemroot%\system32\cookie*.dat
    %systemroot%\system32\kaxs.dat
    %systemroot%\system32\ps*.dat
    %systemroot%\system32\*32.sys
    %systemroot%\*.dr
    %SYSTEMDRIVE%\*.dr
    %systemroot%\system32\*.dr
    %systemroot%\system32\nods32.dll
    %systemroot%\*.res
    %SYSTEMDRIVE%\*.res
    %systemroot%\system32\*.res
    %systemroot%\system32\sockins32.dll
    %systemroot%\system32\Spool\*.*
    %systemroot%\system32\Spool\*.exe
    %systemroot%\system32\Spool\*.rar /s
    %systemroot%\system32\Spool\*.zip /s
    %systemroot%\system32\Spool\*.dat /s
    %ProgramFiles%\MSN Messenger\*.zip
    %ProgramFiles%\MSN Messenger\*.exe
    %ProgramFiles%\MSN Messenger\*.rar
    %PROGRAMFILES%\*crack*.
    %PROGRAMFILES%\*keygen*.
    %SYSTEMDRIVE%\*crack*.
    %SYSTEMDRIVE%\*keygen*.
    %SYSTEMDRIVE%\*.zip
    %SYSTEMDRIVE%\*.rar
    %SYSTEMDRIVE%\*.exe
    %SYSTEMDRIVE%\*.dll
    %systemroot%\*.zip
    %systemroot%\*.rar
    %systemroot%\system32\*.zip
    %systemroot%\system32\*.rar
    %PROGRAMFILES%\*.zip
    %PROGRAMFILES%\*.rar
    %PROGRAMFILES%\*.exe
    %PROGRAMFILES%\*.dll
    %DESKTOP%\*.zip
    %DESKTOP%\*.rar
    %DESKTOP%\*.exe
    %DESKTOP%\*crack*.
    %DESKTOP%\*keygen*.
    %PROGRAMFILES%\Common Files\*.*
    %PROGRAMFILES%\Common Files\*bak*.
    %systemroot%\SYSTEM32\*bak*.
    %PROGRAMFILES%\*bak*.
    %systemroot%\ime\imjp8_1\*bak*.
    %PROGRAMFILES%\QuickTime\*bak*.
    %PROGRAMFILES%\Viewpoint\Viewpoint Manager\*bak*.
    %PROGRAMFILES%\Analog Devices\Core\*bak*.
    %SYSTEMDRIVE%\hp\KBD\*bak*.
    %PROGRAMFILES%\Adobe\Photoshop Album Starter Edition\3.2\Apps\*bak*.
    %PROGRAMFILES%\BillP Studios\WinPatrol\*bak*.
    %PROGRAMFILES%\BroadJump\Client Foundation\*bak*.
    %PROGRAMFILES%\Common Files\Real\Update_OB\*bak*.
    %PROGRAMFILES%\Common Files\Sonic\Update Manager\*bak*.
    %PROGRAMFILES%\\Google\GoogleToolbarNotifier\*bak*.
    %PROGRAMFILES%\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\*bak*.
    %PROGRAMFILES%\Yahoo!\Messenger\*bak*.
    %USERNAME%\*.zip
    %USERNAME%\*.rar
    %USERNAME%\*.exe
    %USERPROFILE%\*.zip
    %USERPROFILE%\*.rar
    %USERPROFILE%\*.exe
    %ALLUSERSPROFILE%\*.zip
    %ALLUSERSPROFILE%\*.rar
    %ALLUSERSPROFILE%\*.exe
    %APPDATA%\*.zip
    %APPDATA%\*.rar
    %APPDATA%\*.exe
    %ALLUSERSSTARTMENU%\*.zip
    %ALLUSERSSTARTMENU%\*.rar
    %ALLUSERSSTARTMENU%\*.exe
    %ALLUSERSSTARTUP%\*.zip
    %ALLUSERSSTARTUP%\*.rar
    %ALLUSERSSTARTUP%\*.exe
    %ALLUSERSPROGRAMS%\*.zip
    %ALLUSERSPROGRAMS%\*.rar
    %ALLUSERSPROGRAMS%\*.exe
    %ALLUSERSAPPDATA%\*.zip
    %ALLUSERSAPPDATA%\*.rar
    %ALLUSERSAPPDATA%\*.exe
    %APPDATA%\*.zip
    %APPDATA%\*.rar
    %APPDATA%\*.exe
    %APPDATA%\*.dat
    %APPDATA%\*.dll
    %QUICKLAUNCH%\*.zip
    %QUICKLAUNCH%\*.rar
    %QUICKLAUNCH%\*.exe
    %STARTUP%\*.zip
    %STARTUP%\*.rar
    %STARTUP%\*.exe
    %STARTMENU%\*.zip
    %STARTMENU%\*.rar
    %STARTMENU%\*.exe
    %MYDOCUMENTS%\*.zip
    %MYDOCUMENTS%\*.rar
    %MYDOCUMENTS%\*.exe
    %MYDOCUMENTS%\*crack*.
    %MYDOCUMENTS%\*keygen*.
    %PROGRAMFILES%\Mozilla Firefox\plugins\*.*
    %PROGRAMFILES%\Internet Explorer\*.*
    %PROGRAMFILES%\Internet Explorer\PLUGINS\*.*
    %PROGRAMFILES%\Mozilla Firefox\*.zip /s
    %PROGRAMFILES%\Mozilla Firefox\*.rar /s
    %PROGRAMFILES%\Mozilla Firefox\*.exe /s
    %PROGRAMFILES%\Internet Explorer\*.zip /s
    %PROGRAMFILES%\Internet Explorer\*.rar /s
    %PROGRAMFILES%\Internet Explorer\*.exe /s
    %SYSTEMDRIVE%\*.dat
    %SYSTEMDRIVE%\*.sys
    %SYSTEMROOT%\*.dat
    %SYSTEMROOT%\*.sys
    %systemroot%\system32\drivers\*.exe /s
    %systemroot%\system32\drivers\*.zip /s
    %systemroot%\system32\drivers\*.rar /s
    %systemroot%\system\*.exe /s
    %systemroot%\system\*.zip /s
    %systemroot%\system\*.rar /s
    %systemroot%\AppPatch\*.exe /s
    %systemroot%\AppPatch\*.zip /s
    %systemroot%\AppPatch\*.rar /s
    %systemroot%\Cache\*.*
    %systemroot%\Downloaded Program Files\*.*
    %systemroot%\Fonts\*.exe /s
    %systemroot%\Fonts\*.zip /s
    %systemroot%\Fonts\*.rar /s
    %systemroot%\Fonts\*.dll /s
    %systemroot%\Help\*.exe /s
    %systemroot%\Help\*.zip /s
    %systemroot%\Help\*.rar /s
    %systemroot%\Tasks\*.*
    %APPDATA%\*.sys
    %APPDATA%\Google\*.*
    %systemroot%\system32\serauth1.dll
    %systemroot%\system32\serauth2.dll
    %systemroot%\system32\sysaudio.sys
    %PROGRAMFILES%\*TinyProxy*.
    HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla|extensions /rs
    %systemroot%\system32\inf\*.exe /s
    %systemroot%\system32\inf\*.zip /s
    %systemroot%\system32\inf\*.rar /s
    %systemroot%\system32\inf\*.dll /s
    %PROGRAMFILES%\Bitlord\Downloads\*.zip /s
    %PROGRAMFILES%\Bitlord\Downloads\*.rar /s
    %PROGRAMFILES%\Bitlord\Downloads\*.exe /s
    %PROGRAMFILES%\Bitlord\Downloads\*crack*.
    %PROGRAMFILES%\Bitlord\Downloads\*keygen*.
    %PROGRAMFILES%\eMule\Incoming\*.zip /s
    %PROGRAMFILES%\eMule\Incoming\*.rar /s
    %PROGRAMFILES%\eMule\Incoming\*.exe /s
    %PROGRAMFILES%\eMule\Incoming\*crack*.
    %PROGRAMFILES%\eMule\Incoming\*keygen*.
    %ProgramFiles%\Bittorent\downloads\*.zip /s
    %ProgramFiles%\Bittorent\downloads\*.exe /s
    %ProgramFiles%\Bittorent\downloads\*.rar /s
    %PROGRAMFILES%\Bittorent\Downloads\*crack*.
    %PROGRAMFILES%\Bittorent\Downloads\*keygen*.
    %ProgramFiles%\Bearshare\Shared\*.zip /s
    %ProgramFiles%\Bearshare\Shared\*.exe /s
    %ProgramFiles%\Bearshare\Shared\*.rar /s
    %ProgramFiles%\Bearshare\Shared\*crack*.
    %ProgramFiles%\Bearshare\Shared\*keygen*.
    %ProgramFiles%\Morpheus\My Shared Folder\*.zip /s
    %ProgramFiles%\Morpheus\My Shared Folder\*.exe /s
    %ProgramFiles%\Morpheus\My Shared Folder\*.rar /s
    %ProgramFiles%\Morpheus\My Shared Folder\*crack*.
    %ProgramFiles%\Morpheus\My Shared Folder\*keygen*.
    %ProgramFiles%\uTorrent\Downloads\*.zip /s
    %ProgramFiles%\uTorrent\Downloads\*.exe /s
    %ProgramFiles%\uTorrent\Downloads\*.rar /s
    %ProgramFiles%\uTorrent\Downloads\*crack*.
    %ProgramFiles%\uTorrent\Downloads\*keygen*.
    %ProgramFiles%\Kazaa Lite\My Shared Folder\*.zip /s
    %ProgramFiles%\Kazaa Lite\My Shared Folder\*.exe /s
    %ProgramFiles%\Kazaa Lite\My Shared Folder\*.rar /s
    %ProgramFiles%\Kazaa Lite\My Shared Folder\*crack*.
    %ProgramFiles%\Kazaa Lite\My Shared Folder\*keygen*.
    %ProgramFiles%\Kazaa\My Shared Folder\*.zip /s
    %ProgramFiles%\Kazaa\My Shared Folder\*.exe /s
    %ProgramFiles%\Kazaa\My Shared Folder\*.rar /s
    %ProgramFiles%\Kazaa\My Shared Folder\*crack*.
    %ProgramFiles%\Kazaa\My Shared Folder\*keygen*.
    %ProgramFiles%\Icq\Shared Files\*.zip /s
    %ProgramFiles%\Icq\Shared Files\*.exe /s
    %ProgramFiles%\Icq\Shared Files\*.rar /s
    %ProgramFiles%\Icq\Shared Files\*crack*.
    %ProgramFiles%\Icq\Shared Files\*keygen*.
    %ProgramFiles%\Direct Connect\Received Files\*.zip /s
    %ProgramFiles%\Direct Connect\Received Files\*.exe /s
    %ProgramFiles%\Direct Connect\Received Files\*.rar /s
    %ProgramFiles%\Direct Connect\Received Files\*crack*.
    %ProgramFiles%\Direct Connect\Received Files\*keygen*.
    %ALLUSERSPROFILE%\Application Data\AOL Downloads\*.zip
    %ALLUSERSPROFILE%\Application Data\AOL Downloads\*.rar
    %ALLUSERSPROFILE%\Application Data\AOL Downloads\*.exe
    %ALLUSERSPROFILE%\Application Data\AOL Downloads\*crack*.
    %ALLUSERSPROFILE%\Application Data\AOL Downloads\*keygen*.
    %APPDATA%\Opera\Opera\profile\widgets\*.*
    %PROGRAMFILES%\Opera\program\plugins\*.* /s
    %APPDATA%\Opera\Opera\profile\toolbar\*.* /s


  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open a notepad window called OTListIt.Txt. This saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the content of this file, and post it with your next reply.
Thank you
Here are the results from the otmoveit 3 and otlist2 respectively…

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\"Authentication Packages"|hex(7):6d,00,73,00,76,00,31,00,5f,00,30,00,00,00,00,00 /E : value set successfully!
========== FILES ==========
File/Folder C:\WINDOWS\System32\ujcqjpsb.dll not found.
C:\WINDOWS\System32\wdisueby.ini moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\System32\ybeusidw.dll
C:\WINDOWS\System32\ybeusidw.dll NOT unregistered.
C:\WINDOWS\System32\ybeusidw.dll moved successfully.
C:\WINDOWS\System32\clihwyri.ini moved successfully.
File/Folder C:\WINDOWS\System32\kptxdhkr.dll not found.
C:\WINDOWS\System32\bbeolpsu.ini moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\System32\kkfsgi.dll
C:\WINDOWS\System32\kkfsgi.dll NOT unregistered.
C:\WINDOWS\System32\kkfsgi.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\System32\xxvxkmch.dll
C:\WINDOWS\System32\xxvxkmch.dll NOT unregistered.
C:\WINDOWS\System32\xxvxkmch.dll moved successfully.
C:\WINDOWS\System32\ewuciggc.ini moved successfully.
C:\WINDOWS\System32\bqobmnxn.ini moved successfully.
C:\WINDOWS\System32\xfndjerc.ini moved successfully.
C:\WINDOWS\System32\ifaujgot.ini moved successfully.
C:\WINDOWS\System32\wjhvxcnr.ini moved successfully.
C:\WINDOWS\System32\GhQBKRqr.ini2 moved successfully.
C:\WINDOWS\System32\GhQBKRqr.ini moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\System32\rqRKBQhG.dll
C:\WINDOWS\System32\rqRKBQhG.dll NOT unregistered.
C:\WINDOWS\System32\rqRKBQhG.dll moved successfully.
File/Folder C:\WINDOWS\System32\GhQBKRqr.ini not found.
File/Folder C:\WINDOWS\System32\GhQBKRqr.ini2 not found.
File/Folder C:\WINDOWS\System32\wdisueby.ini not found.
File/Folder C:\WINDOWS\System32\ybeusidw.dll not found.
File/Folder C:\WINDOWS\System32\clihwyri.ini not found.
File/Folder C:\WINDOWS\System32\bbeolpsu.ini not found.
File/Folder C:\WINDOWS\System32\ewuciggc.ini not found.
File/Folder C:\WINDOWS\System32\xxvxkmch.dll not found.
File/Folder C:\WINDOWS\System32\kkfsgi.dll not found.
File/Folder C:\WINDOWS\System32\bqobmnxn.ini not found.
File/Folder C:\WINDOWS\System32\xfndjerc.ini not found.
File/Folder C:\WINDOWS\System32\ifaujgot.ini not found.
File/Folder C:\WINDOWS\System32\wjhvxcnr.ini not found.
File/Folder C:\WINDOWS\System32\rqRKBQhG.dll not found.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\Perflib_Perfdata_3c0.dat scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\Perflib_Perfdata_cc4.dat scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\~DF9F0E.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_51c.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 01012009_144619

Files moved on Reboot…
File C:\DOCUME~1\Owner\LOCALS~1\Temp\Perflib_Perfdata_3c0.dat not found!
File C:\DOCUME~1\Owner\LOCALS~1\Temp\Perflib_Perfdata_cc4.dat not found!
C:\DOCUME~1\Owner\LOCALS~1\Temp\~DF9F0E.tmp moved successfully.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
C:\WINDOWS\temp\Perflib_Perfdata_51c.dat moved successfully.

OTListIt logfile created on: 1/1/2009 2:53:32 PM - Run 2
OTListIt2 by OldTimer - Version 1.0.1.1 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

959.36 Mb Total Physical Memory | 591.74 Mb Available Physical Memory | 61.68% Memory free
2.26 Gb Paging File | 1.89 Gb Available in Paging File | 83.54% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 63.95 Gb Free Space | 85.81% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: WAYNE-253422C9C
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Custom Scans ==========


< HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services >

< HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg >

< %systemroot%\Prefetch\*.* /s >
[2009/01/01 10:36:48 | 00,076,630 | —- | M] () – C:\WINDOWS\Prefetch\ACRORD32.EXE-13285B88.pf
[2009/01/01 12:39:49 | 00,043,668 | —- | M] () – C:\WINDOWS\Prefetch\ACRORD32INFO.EXE-013EA364.pf
[2009/01/01 09:29:25 | 00,039,414 | —- | M] () – C:\WINDOWS\Prefetch\AD-AWARE.EXE-2ED3360E.pf
[2009/01/01 13:15:24 | 00,064,778 | —- | M] () – C:\WINDOWS\Prefetch\ALG.EXE-0F138680.pf
[2009/01/01 13:51:04 | 00,032,798 | —- | M] () – C:\WINDOWS\Prefetch\APDPROXY.EXE-3946206C.pf
[2009/01/01 09:47:25 | 00,077,044 | —- | M] () – C:\WINDOWS\Prefetch\ASHAVAST.EXE-12F63458.pf
[2009/01/01 10:16:15 | 00,036,508 | —- | M] () – C:\WINDOWS\Prefetch\ASHCHEST.EXE-0FED8209.pf
[2009/01/01 13:50:51 | 00,027,616 | —- | M] () – C:\WINDOWS\Prefetch\ASHDISP.EXE-0B874892.pf
[2008/12/30 22:10:57 | 00,041,560 | —- | M] () – C:\WINDOWS\Prefetch\ASHQUICK.EXE-13F2975D.pf
[2009/01/01 09:47:59 | 00,049,818 | —- | M] () – C:\WINDOWS\Prefetch\ASHSIMPL.EXE-14F851AB.pf
[2009/01/01 13:15:24 | 00,059,454 | —- | M] () – C:\WINDOWS\Prefetch\AVAST.SETUP-032170A8.pf
[2009/01/01 14:50:36 | 00,094,662 | —- | M] () – C:\WINDOWS\Prefetch\CLI.EXE-20D5A08B.pf
[2009/01/01 13:50:34 | 00,005,286 | —- | M] () – C:\WINDOWS\Prefetch\CLIPTEXT.EXE-1606842F.pf
[2009/01/01 13:50:32 | 00,011,558 | —- | M] () – C:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf
[2008/12/31 17:27:29 | 00,055,094 | —- | M] () – C:\WINDOWS\Prefetch\COMPONENTLAUNCHER.EXE-142DFC99.pf
[2009/01/01 11:42:56 | 00,040,842 | —- | M] () – C:\WINDOWS\Prefetch\CONTROL.EXE-013DBFB5.pf
[2009/01/01 13:49:40 | 00,008,840 | —- | M] () – C:\WINDOWS\Prefetch\CSWEG.EXE-02598DDA.pf
[2009/01/01 13:50:52 | 00,018,890 | —- | M] () – C:\WINDOWS\Prefetch\CTFMON.EXE-0E17969B.pf
[2008/12/31 21:07:54 | 00,049,174 | —- | M] () – C:\WINDOWS\Prefetch\DFRGNTFS.EXE-269967DF.pf
[2009/01/01 11:03:07 | 00,023,098 | —- | M] () – C:\WINDOWS\Prefetch\DLLHOST.EXE-205D880D.pf
[2008/12/31 19:49:36 | 00,023,504 | —- | M] () – C:\WINDOWS\Prefetch\DMAMANAGER.EXE-2B9B4A50.pf
[2009/01/01 13:49:40 | 00,005,442 | —- | M] () – C:\WINDOWS\Prefetch\DNIF.EXE-26A0214B.pf
[2009/01/01 14:46:47 | 00,087,048 | —- | M] () – C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf
[2009/01/01 13:50:52 | 00,022,008 | —- | M] () – C:\WINDOWS\Prefetch\GOOGLETOOLBARNOTIFIER.EXE-3629C61D.pf
[2009/01/01 09:25:41 | 00,031,542 | —- | M] () – C:\WINDOWS\Prefetch\GOOGLEUPDATER.EXE-2CAF5929.pf
[2008/12/31 12:52:23 | 00,053,148 | —- | M] () – C:\WINDOWS\Prefetch\HELPSVC.EXE-2878DDA2.pf
[2009/01/01 14:42:18 | 00,028,056 | —- | M] () – C:\WINDOWS\Prefetch\HIJACKTHIS.EXE-34A0FC79.pf
[2009/01/01 12:00:00 | 00,020,844 | —- | M] () – C:\WINDOWS\Prefetch\HJTINSTALL.EXE-3328F4D5.pf
[2009/01/01 14:32:45 | 00,022,316 | —- | M] () – C:\WINDOWS\Prefetch\HOLIDAY LIGHTS.EXE-31AE1439.pf
[2009/01/01 14:32:44 | 00,026,080 | —- | M] () – C:\WINDOWS\Prefetch\HOLIDA~1.SCR-2627FBB6.pf
[2009/01/01 14:50:53 | 00,095,880 | —- | M] () – C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf
[2009/01/01 14:50:36 | 00,018,332 | —- | M] () – C:\WINDOWS\Prefetch\IMAPI.EXE-0BF740A4.pf
[2009/01/01 14:50:36 | 00,014,294 | —- | M] () – C:\WINDOWS\Prefetch\IPODSERVICE.EXE-3192DE38.pf
[2008/12/31 19:42:59 | 00,090,490 | —- | M] () – C:\WINDOWS\Prefetch\ITUNES.EXE-1A268432.pf
[2009/01/01 13:50:51 | 00,037,176 | —- | M] () – C:\WINDOWS\Prefetch\ITUNESHELPER.EXE-15823303.pf
[2009/01/01 14:33:10 | 00,387,968 | —- | M] () – C:\WINDOWS\Prefetch\Layout.ini
[2009/01/01 14:48:01 | 00,035,418 | —- | M] () – C:\WINDOWS\Prefetch\LOGONUI.EXE-0AF22957.pf
[2009/01/01 10:34:20 | 00,022,600 | —- | M] () – C:\WINDOWS\Prefetch\LXBYCOMS.EXE-2D7848E4.pf
[2009/01/01 10:35:39 | 00,020,674 | —- | M] () – C:\WINDOWS\Prefetch\LXBYJSWX.EXE-1D216971.pf
[2009/01/01 10:35:38 | 00,030,200 | —- | M] () – C:\WINDOWS\Prefetch\LXBYPSWX.EXE-15A3A0FB.pf
[2009/01/01 12:25:57 | 00,051,004 | —- | M] () – C:\WINDOWS\Prefetch\MMC.EXE-04EF131A.pf
[2008/12/31 21:06:44 | 00,037,490 | —- | M] () – C:\WINDOWS\Prefetch\MMC.EXE-1EF9AA05.pf
[2009/01/01 12:41:01 | 00,048,096 | —- | M] () – C:\WINDOWS\Prefetch\MSIEXEC.EXE-2F8A8CAE.pf
[2009/01/01 10:36:23 | 00,083,332 | —- | M] () – C:\WINDOWS\Prefetch\MSIMN.EXE-38BA891D.pf
[2009/01/01 13:50:51 | 00,033,496 | —- | M] () – C:\WINDOWS\Prefetch\MSMSGS.EXE-2B6052DE.pf
[2009/01/01 13:57:00 | 00,015,190 | —- | M] () – C:\WINDOWS\Prefetch\MSNTBUP.EXE-0D913FB9.pf
[2009/01/01 14:51:06 | 00,030,484 | —- | M] () – C:\WINDOWS\Prefetch\MSN_SL.EXE-18A18BC5.pf
[2008/12/31 19:27:26 | 00,028,820 | —- | M] () – C:\WINDOWS\Prefetch\MSPAINT.EXE-11CBB631.pf
[2008/12/31 19:49:37 | 00,053,742 | —- | M] () – C:\WINDOWS\Prefetch\NERO.EXE-3017C357.pf
[2008/12/31 19:48:53 | 00,061,386 | —- | M] () – C:\WINDOWS\Prefetch\NEROSTARTSMART.EXE-3289D1AD.pf
[2009/01/01 14:13:10 | 00,019,414 | —- | M] () – C:\WINDOWS\Prefetch\NOTEPAD.EXE-189578DA.pf
[2009/01/01 13:50:49 | 00,036,840 | —- | M] () – C:\WINDOWS\Prefetch\NOTEPAD.EXE-336351A9.pf
[2009/01/01 14:50:36 | 01,195,402 | —- | M] () – C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf
[2009/01/01 14:52:35 | 00,019,486 | —- | M] () – C:\WINDOWS\Prefetch\OTLISTIT2.EXE-03719BDC.pf
[2009/01/01 14:45:28 | 00,016,670 | —- | M] () – C:\WINDOWS\Prefetch\OTMOVEIT3.EXE-141B94C0.pf
[2009/01/01 11:17:35 | 00,092,828 | —- | M] () – C:\WINDOWS\Prefetch\PHOTOSHOP ALBUM STARTER EDITI-2903BF6F.pf
[2008/12/31 17:27:36 | 00,019,532 | —- | M] () – C:\WINDOWS\Prefetch\PSAPROXY.EXE-21EF7AEA.pf
[2009/01/01 13:50:41 | 00,008,740 | —- | M] () – C:\WINDOWS\Prefetch\QTTASK.EXE-342507FB.pf
[2009/01/01 14:50:36 | 00,021,904 | —- | M] () – C:\WINDOWS\Prefetch\READER_SL.EXE-3614FA6E.pf
[2009/01/01 13:49:40 | 00,005,018 | —- | M] () – C:\WINDOWS\Prefetch\RTSDNIF.EXE-2DEC3B2B.pf
[2009/01/01 11:42:58 | 00,037,000 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-155CD7BB.pf
[2009/01/01 13:50:51 | 00,016,984 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-1717606A.pf
[2008/12/31 19:19:20 | 00,034,050 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-18248BED.pf
[2009/01/01 11:42:55 | 00,037,878 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-1831A4F3.pf
[2008/12/31 19:33:30 | 00,020,616 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-18EB4BB4.pf
[2008/12/31 20:14:44 | 00,021,848 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-1967CFD4.pf
[2008/12/31 21:28:09 | 00,019,398 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-268BFF96.pf
[2009/01/01 12:08:37 | 00,024,874 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-2C7B5C4A.pf
[2009/01/01 14:41:46 | 00,060,056 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-2CD85FD3.pf
[2009/01/01 13:50:52 | 00,012,428 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-3565AB70.pf
[2009/01/01 12:08:01 | 00,033,356 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-37BEE96E.pf
[2009/01/01 11:55:47 | 00,030,330 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-385E89E5.pf
[2008/12/31 20:12:46 | 00,018,632 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-389B93F9.pf
[2008/12/30 22:32:41 | 00,038,482 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-3997B289.pf
[2009/01/01 11:56:59 | 00,037,734 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-3999A043.pf
[2008/12/30 22:32:36 | 00,036,492 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-3A0E1E22.pf
[2009/01/01 11:56:57 | 00,035,624 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-3A100BDC.pf
[2009/01/01 13:50:41 | 00,012,950 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-3AD8F343.pf
[2008/12/30 22:32:30 | 00,071,784 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-3CD4A3B8.pf
[2009/01/01 11:56:54 | 00,066,364 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-3CD69172.pf
[2008/12/31 21:38:15 | 00,054,000 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-3D97474F.pf
[2009/01/01 12:45:23 | 00,019,798 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-451FC2C0.pf
[2008/12/31 08:12:10 | 00,018,620 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-45B5B19D.pf
[2008/12/31 19:45:13 | 00,020,604 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-4689E1D8.pf
[2008/12/31 08:09:01 | 00,022,182 | —- | M] () – C:\WINDOWS\Prefetch\RUNDLL32.EXE-4B10E6EF.pf
[2008/12/31 21:29:47 | 00,066,458 | —- | M] () – C:\WINDOWS\Prefetch\SAFARI.EXE-238FF382.pf
[2009/01/01 13:17:52 | 00,009,010 | —- | M] () – C:\WINDOWS\Prefetch\SDFIX.EXE-18817835.pf
[2009/01/01 11:45:51 | 00,028,160 | —- | M] () – C:\WINDOWS\Prefetch\SETUP_WM.EXE-3135CBD6.pf
[2009/01/01 11:03:11 | 00,060,468 | —- | M] () – C:\WINDOWS\Prefetch\SOFTWAREUPDATE.EXE-1415D1B8.pf
[2008/12/31 19:08:25 | 00,020,000 | —- | M] () – C:\WINDOWS\Prefetch\SPIDER.EXE-2D998CA6.pf
[2009/01/01 14:46:41 | 00,018,240 | —- | M] () – C:\WINDOWS\Prefetch\VERCLSID.EXE-3667BD89.pf
[2008/12/31 20:12:46 | 00,072,392 | —- | M] () – C:\WINDOWS\Prefetch\WGATRAY.EXE-0ED38BED.pf
[2008/12/31 17:27:37 | 00,028,720 | —- | M] () – C:\WINDOWS\Prefetch\WIAACMGR.EXE-212ED878.pf
[2009/01/01 14:51:03 | 00,037,178 | —- | M] () – C:\WINDOWS\Prefetch\WLLOGINPROXY.EXE-1781D844.pf
[2009/01/01 14:50:36 | 00,136,434 | —- | M] () – C:\WINDOWS\Prefetch\WMIAPSRV.EXE-1E2270A5.pf
[2009/01/01 14:42:22 | 00,032,192 | —- | M] () – C:\WINDOWS\Prefetch\WMIPRVSE.EXE-28F301A9.pf
[2009/01/01 11:45:18 | 00,084,944 | —- | M] () – C:\WINDOWS\Prefetch\WMPLAYER.EXE-18DDEF9C.pf
[2008/12/31 21:30:28 | 00,077,126 | —- | M] () – C:\WINDOWS\Prefetch\WMPLAYER.EXE-18DDEF9D.pf
[2009/01/01 10:35:25 | 00,032,788 | —- | M] () – C:\WINDOWS\Prefetch\WORDPAD.EXE-24533991.pf
[2009/01/01 12:46:44 | 00,014,118 | —- | M] () – C:\WINDOWS\Prefetch\WSCNTFY.EXE-1B24F5EB.pf
[2008/12/31 19:28:32 | 00,028,974 | —- | M] () – C:\WINDOWS\Prefetch\WSCRIPT.EXE-32960AB9.pf
[2009/01/01 12:08:02 | 00,025,922 | —- | M] () – C:\WINDOWS\Prefetch\WUAUCLT.EXE-399A8E72.pf
[2009/01/01 12:24:37 | 00,026,726 | —- | M] () – C:\WINDOWS\Prefetch\WUPDMGR.EXE-2F30BEAB.pf

< %systemroot%\system32\drivers\*.dat >
[2006/07/01 14:19:24 | 00,000,000 | —- | M] () – C:\WINDOWS\system32\drivers\wnmsav.dat

< %systemroot%\Temp\bca4e2da.$$$ >

< %systemroot%\Temp\ed47fa.$ >

< %systemroot%\Temp\fa56d7ec.$$$ >

< %systemroot%\Temp\*.$$$ >

< %systemroot%\System32\antiwpa.dll >

< %SYSTEMDRIVE%\*.epk >

< %systemroot%\*.epk >

< %systemroot%\system32\*.epk >

< %systemroot%\system32\bb*.dat >

< %systemroot%\system32\cookie*.dat >

< %systemroot%\system32\kaxs.dat >

< %systemroot%\system32\ps*.dat >

< %systemroot%\system32\*32.sys >

< %systemroot%\*.dr >

< %SYSTEMDRIVE%\*.dr >

< %systemroot%\system32\*.dr >

< %systemroot%\system32\nods32.dll >

< %systemroot%\*.res >

< %SYSTEMDRIVE%\*.res >

< %systemroot%\system32\*.res >

< %systemroot%\system32\sockins32.dll >

< %systemroot%\system32\Spool\*.* >

< %systemroot%\system32\Spool\*.exe >

< %systemroot%\system32\Spool\*.rar /s >

< %systemroot%\system32\Spool\*.zip /s >

< %systemroot%\system32\Spool\*.dat /s >

< %ProgramFiles%\MSN Messenger\*.zip >

< %ProgramFiles%\MSN Messenger\*.exe >
[2007/01/04 16:10:02 | 00,297,752 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\livecall.exe
[2007/01/19 12:54:56 | 05,674,352 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\msnmsgr.exe
[2006/11/07 17:01:20 | 00,442,192 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\msvs.exe
[2007/01/19 12:54:14 | 00,097,136 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\usnsvc.exe

< %ProgramFiles%\MSN Messenger\*.rar >

< %PROGRAMFILES%\*crack*. >
[2009/01/01 12:42:30 | 00,000,000 | —D | M] – C:\Program Files

< %PROGRAMFILES%\*keygen*. >
[2009/01/01 12:42:30 | 00,000,000 | —D | M] – C:\Program Files

< %SYSTEMDRIVE%\*crack*. >
[2009/01/01 14:50:37 | 00,000,000 | —D | M] – C:

< %SYSTEMDRIVE%\*keygen*. >
[2009/01/01 14:50:37 | 00,000,000 | —D | M] – C:

< %SYSTEMDRIVE%\*.zip >

< %SYSTEMDRIVE%\*.rar >

< %SYSTEMDRIVE%\*.exe >
[2005/10/31 09:56:00 | 00,700,416 | —- | M] (LimeWire) – C:\StubInstaller.exe

< %SYSTEMDRIVE%\*.dll >

< %systemroot%\*.zip >

< %systemroot%\*.rar >

< %systemroot%\system32\*.zip >

< %systemroot%\system32\*.rar >

< %PROGRAMFILES%\*.zip >

< %PROGRAMFILES%\*.rar >

< %PROGRAMFILES%\*.exe >
[2004/10/01 17:00:16 | 00,040,960 | —- | M] () – C:\Program Files\Uninstall_CDS.exe

< %PROGRAMFILES%\*.dll >

Invalid Environment Variable: DESKTOP

Invalid Environment Variable: DESKTOP

Invalid Environment Variable: DESKTOP

Invalid Environment Variable: DESKTOP

Invalid Environment Variable: DESKTOP

< %PROGRAMFILES%\Common Files\*.* >

< %PROGRAMFILES%\Common Files\*bak*. >
[2008/01/13 17:24:04 | 00,000,000 | —D | M] – C:\Program Files\Common Files

< %systemroot%\SYSTEM32\*bak*. >
[2 C:\WINDOWS\SYSTEM32\*.tmp files]
[2009/01/01 14:46:20 | 00,000,000 | —D | M] – C:\WINDOWS\SYSTEM32

< %PROGRAMFILES%\*bak*. >
[2009/01/01 12:42:30 | 00,000,000 | —D | M] – C:\Program Files

< %systemroot%\ime\imjp8_1\*bak*. >
[2006/01/31 18:20:10 | 00,000,000 | —D | M] – C:\WINDOWS\ime\imjp8_1

< %PROGRAMFILES%\QuickTime\*bak*. >
[2008/11/01 19:02:05 | 00,000,000 | —D | M] – C:\Program Files\QuickTime

< %PROGRAMFILES%\Viewpoint\Viewpoint Manager\*bak*. >

< %PROGRAMFILES%\Analog Devices\Core\*bak*. >

< %SYSTEMDRIVE%\hp\KBD\*bak*. >

< %PROGRAMFILES%\Adobe\Photoshop Album Starter Edition\3.2\Apps\*bak*. >

< %PROGRAMFILES%\BillP Studios\WinPatrol\*bak*. >

< %PROGRAMFILES%\BroadJump\Client Foundation\*bak*. >

< %PROGRAMFILES%\Common Files\Real\Update_OB\*bak*. >

< %PROGRAMFILES%\Common Files\Sonic\Update Manager\*bak*. >

< %PROGRAMFILES%\\Google\GoogleToolbarNotifier\*bak*. >
[2008/10/29 09:56:01 | 00,000,000 | —D | M] – C:\Program Files\\Google\GoogleToolbarNotifier

< %PROGRAMFILES%\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\*bak*. >

< %PROGRAMFILES%\Yahoo!\Messenger\*bak*. >

< %USERNAME%\*.zip >

< %USERNAME%\*.rar >

< %USERNAME%\*.exe >

< %USERPROFILE%\*.zip >

< %USERPROFILE%\*.rar >

< %USERPROFILE%\*.exe >

< %ALLUSERSPROFILE%\*.zip >

< %ALLUSERSPROFILE%\*.rar >

< %ALLUSERSPROFILE%\*.exe >

< %APPDATA%\*.zip >

< %APPDATA%\*.rar >

< %APPDATA%\*.exe >

Invalid Environment Variable: ALLUSERSSTARTMENU

Invalid Environment Variable: ALLUSERSSTARTMENU

Invalid Environment Variable: ALLUSERSSTARTMENU

Invalid Environment Variable: ALLUSERSSTARTUP

Invalid Environment Variable: ALLUSERSSTARTUP

Invalid Environment Variable: ALLUSERSSTARTUP

Invalid Environment Variable: ALLUSERSPROGRAMS

Invalid Environment Variable: ALLUSERSPROGRAMS

Invalid Environment Variable: ALLUSERSPROGRAMS

Invalid Environment Variable: ALLUSERSAPPDATA

Invalid Environment Variable: ALLUSERSAPPDATA

Invalid Environment Variable: ALLUSERSAPPDATA

< %APPDATA%\*.zip >

< %APPDATA%\*.rar >

< %APPDATA%\*.exe >

< %APPDATA%\*.dat >

< %APPDATA%\*.dll >

Invalid Environment Variable: QUICKLAUNCH

Invalid Environment Variable: QUICKLAUNCH

Invalid Environment Variable: QUICKLAUNCH

Invalid Environment Variable: STARTUP

Invalid Environment Variable: STARTUP

Invalid Environment Variable: STARTUP

Invalid Environment Variable: STARTMENU

Invalid Environment Variable: STARTMENU

Invalid Environment Variable: STARTMENU

Invalid Environment Variable: MYDOCUMENTS

Invalid Environment Variable: MYDOCUMENTS

Invalid Environment Variable: MYDOCUMENTS

Invalid Environment Variable: MYDOCUMENTS

Invalid Environment Variable: MYDOCUMENTS

< %PROGRAMFILES%\Mozilla Firefox\plugins\*.* >

< %PROGRAMFILES%\Internet Explorer\*.* >
[2006/11/07 21:03:36 | 00,033,792 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\custsat.dll
[2006/10/17 11:44:36 | 00,060,416 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\hmmapi.dll
[2006/10/17 12:04:50 | 00,069,120 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iedw.exe
[2006/11/07 21:03:36 | 00,287,744 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\ieproxy.dll
[2008/10/15 01:06:26 | 00,633,632 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iexplore.exe

< %PROGRAMFILES%\Internet Explorer\PLUGINS\*.* >
[2001/08/01 19:05:42 | 00,270,336 | —- | M] (Intertrust Technologies, Inc.) – C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll
[2008/11/01 19:02:05 | 00,004,208 | —- | M] () – C:\Program Files\Internet Explorer\PLUGINS\QuickTimePlugin.class

< %PROGRAMFILES%\Mozilla Firefox\*.zip /s >

< %PROGRAMFILES%\Mozilla Firefox\*.rar /s >

< %PROGRAMFILES%\Mozilla Firefox\*.exe /s >

< %PROGRAMFILES%\Internet Explorer\*.zip /s >

< %PROGRAMFILES%\Internet Explorer\*.rar /s >

< %PROGRAMFILES%\Internet Explorer\*.exe /s >
[2006/10/17 12:04:50 | 00,069,120 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iedw.exe
[2008/10/15 01:06:26 | 00,633,632 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iexplore.exe
[2008/04/13 18:12:22 | 00,214,528 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe
[2008/04/13 18:12:22 | 00,086,016 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\Connection Wizard\icwconn2.exe
[2008/04/13 18:12:22 | 00,024,576 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\Connection Wizard\icwrmind.exe
[2004/08/04 06:00:00 | 00,073,728 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\Connection Wizard\icwtutor.exe
[2008/04/13 18:12:22 | 00,020,480 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\Connection Wizard\inetwiz.exe
[2004/08/04 06:00:00 | 00,016,384 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\Connection Wizard\isignup.exe

< %SYSTEMDRIVE%\*.dat >

< %SYSTEMDRIVE%\*.sys >
[2006/01/31 18:20:04 | 00,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/01/31 18:20:04 | 00,000,000 | RHS- | M] () – C:\IO.SYS
[2006/01/31 18:20:04 | 00,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2009/01/01 14:48:55 | 15,099,49440 | -HS- | M] () – C:\pagefile.sys

< %SYSTEMROOT%\*.dat >
[2009/01/01 14:49:00 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2006/12/23 22:09:33 | 00,000,031 | —- | M] () – C:\WINDOWS\popcinfo.dat
[5 C:\WINDOWS\*.tmp files]

< %SYSTEMROOT%\*.sys >

< %systemroot%\system32\drivers\*.exe /s >

< %systemroot%\system32\drivers\*.zip /s >

< %systemroot%\system32\drivers\*.rar /s >

< %systemroot%\system\*.exe /s >

< %systemroot%\system\*.zip /s >

< %systemroot%\system\*.rar /s >

< %systemroot%\AppPatch\*.exe /s >

< %systemroot%\AppPatch\*.zip /s >

< %systemroot%\AppPatch\*.rar /s >

< %systemroot%\Cache\*.* >

< %systemroot%\Downloaded Program Files\*.* >
[2006/01/31 18:19:15 | 00,000,065 | -H– | M] () – C:\WINDOWS\Downloaded Program Files\desktop.ini
[2006/01/25 12:43:16 | 00,000,367 | —- | M] () – C:\WINDOWS\Downloaded Program Files\LegitCheckControl.inf
[2003/05/29 15:00:20 | 00,160,864 | —- | M] () – C:\WINDOWS\Downloaded Program Files\messengerstatsclient.dll
[2007/02/22 23:41:12 | 00,304,544 | —- | M] () – C:\WINDOWS\Downloaded Program Files\MessengerStatsPAClient.dll
[2004/08/18 14:47:58 | 00,000,241 | —- | M] () – C:\WINDOWS\Downloaded Program Files\popcaploader.inf
[2005/01/31 22:26:46 | 00,117,800 | —- | M] () – C:\WINDOWS\Downloaded Program Files\ZIntro.ocx

< %systemroot%\Fonts\*.exe /s >

< %systemroot%\Fonts\*.zip /s >

< %systemroot%\Fonts\*.rar /s >

< %systemroot%\Fonts\*.dll /s >

< %systemroot%\Help\*.exe /s >
[2004/08/04 06:00:00 | 03,374,640 | —- | M] (Macromedia, Inc.) – C:\WINDOWS\Help\Tours\mmTour\tour.exe

< %systemroot%\Help\*.zip /s >

< %systemroot%\Help\*.rar /s >

< %systemroot%\Tasks\*.* >
[2009/01/01 11:03:02 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2009/01/01 13:57:00 | 00,000,254 | —- | M] () – C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
[2004/08/04 06:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2006/07/26 21:14:07 | 00,000,260 | —- | M] () – C:\WINDOWS\Tasks\Disk Cleanup.job
[2009/01/01 14:49:03 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

< %APPDATA%\*.sys >

< %APPDATA%\Google\*.* >

< %systemroot%\system32\serauth1.dll >

< %systemroot%\system32\serauth2.dll >

< %systemroot%\system32\sysaudio.sys >

< %PROGRAMFILES%\*TinyProxy*. >
[2009/01/01 12:42:30 | 00,000,000 | —D | M] – C:\Program Files

< HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla|extensions /rs >

< %systemroot%\system32\inf\*.exe /s >

< %systemroot%\system32\inf\*.zip /s >

< %systemroot%\system32\inf\*.rar /s >

< %systemroot%\system32\inf\*.dll /s >

< %PROGRAMFILES%\Bitlord\Downloads\*.zip /s >

< %PROGRAMFILES%\Bitlord\Downloads\*.rar /s >

< %PROGRAMFILES%\Bitlord\Downloads\*.exe /s >

< %PROGRAMFILES%\Bitlord\Downloads\*crack*. >

< %PROGRAMFILES%\Bitlord\Downloads\*keygen*. >

< %PROGRAMFILES%\eMule\Incoming\*.zip /s >

< %PROGRAMFILES%\eMule\Incoming\*.rar /s >

< %PROGRAMFILES%\eMule\Incoming\*.exe /s >

< %PROGRAMFILES%\eMule\Incoming\*crack*. >

< %PROGRAMFILES%\eMule\Incoming\*keygen*. >

< %ProgramFiles%\Bittorent\downloads\*.zip /s >

< %ProgramFiles%\Bittorent\downloads\*.exe /s >

< %ProgramFiles%\Bittorent\downloads\*.rar /s >

< %PROGRAMFILES%\Bittorent\Downloads\*crack*. >

< %PROGRAMFILES%\Bittorent\Downloads\*keygen*. >

< %ProgramFiles%\Bearshare\Shared\*.zip /s >

< %ProgramFiles%\Bearshare\Shared\*.exe /s >

< %ProgramFiles%\Bearshare\Shared\*.rar /s >

< %ProgramFiles%\Bearshare\Shared\*crack*. >

< %ProgramFiles%\Bearshare\Shared\*keygen*. >

< %ProgramFiles%\Morpheus\My Shared Folder\*.zip /s >

< %ProgramFiles%\Morpheus\My Shared Folder\*.exe /s >

< %ProgramFiles%\Morpheus\My Shared Folder\*.rar /s >

< %ProgramFiles%\Morpheus\My Shared Folder\*crack*. >

< %ProgramFiles%\Morpheus\My Shared Folder\*keygen*. >

< %ProgramFiles%\uTorrent\Downloads\*.zip /s >

< %ProgramFiles%\uTorrent\Downloads\*.exe /s >

< %ProgramFiles%\uTorrent\Downloads\*.rar /s >

< %ProgramFiles%\uTorrent\Downloads\*crack*. >

< %ProgramFiles%\uTorrent\Downloads\*keygen*. >

< %ProgramFiles%\Kazaa Lite\My Shared Folder\*.zip /s >

< %ProgramFiles%\Kazaa Lite\My Shared Folder\*.exe /s >

< %ProgramFiles%\Kazaa Lite\My Shared Folder\*.rar /s >

< %ProgramFiles%\Kazaa Lite\My Shared Folder\*crack*. >

< %ProgramFiles%\Kazaa Lite\My Shared Folder\*keygen*. >

< %ProgramFiles%\Kazaa\My Shared Folder\*.zip /s >

< %ProgramFiles%\Kazaa\My Shared Folder\*.exe /s >

< %ProgramFiles%\Kazaa\My Shared Folder\*.rar /s >

< %ProgramFiles%\Kazaa\My Shared Folder\*crack*. >

< %ProgramFiles%\Kazaa\My Shared Folder\*keygen*. >

< %ProgramFiles%\Icq\Shared Files\*.zip /s >

< %ProgramFiles%\Icq\Shared Files\*.exe /s >

< %ProgramFiles%\Icq\Shared Files\*.rar /s >

< %ProgramFiles%\Icq\Shared Files\*crack*. >

< %ProgramFiles%\Icq\Shared Files\*keygen*. >

< %ProgramFiles%\Direct Connect\Received Files\*.zip /s >

< %ProgramFiles%\Direct Connect\Received Files\*.exe /s >

< %ProgramFiles%\Direct Connect\Received Files\*.rar /s >

< %ProgramFiles%\Direct Connect\Received Files\*crack*. >

< %ProgramFiles%\Direct Connect\Received Files\*keygen*. >

< %ALLUSERSPROFILE%\Application Data\AOL Downloads\*.zip >

< %ALLUSERSPROFILE%\Application Data\AOL Downloads\*.rar >

< %ALLUSERSPROFILE%\Application Data\AOL Downloads\*.exe >

< %ALLUSERSPROFILE%\Application Data\AOL Downloads\*crack*. >

< %ALLUSERSPROFILE%\Application Data\AOL Downloads\*keygen*. >

< %APPDATA%\Opera\Opera\profile\widgets\*.* >

< %PROGRAMFILES%\Opera\program\plugins\*.* /s >

< %APPDATA%\Opera\Opera\profile\toolbar\*.* /s >
< End of report >
hello

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
Sorry…that took forever!! Here are the MBAM and Kaspersky results: Malwarebytes' Anti-Malware 1.31 Database version: 1590 Windows 5.1.2600 Service Pack 3 1/1/2009 3:09:27 PM mbam-log-2009-01-01 (15-09-27).txt Scan type: Quick Scan Objects scanned: 49735 Time elapsed: 2 minute(s), 1 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 36 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\mywebsearch.htmlpanel (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywebsearch.htmlpanel.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{17de5e5e-bfe3-4e83-8e1f-8755795359ec} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{1f52a5fa-a705-4415-b975-88503b291728} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{2763e333-b168-41a0-a112-d35f96f410c0} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{3e720451-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{3e720453-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25e} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25f} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{2eff3cf7-99c1-4c29-bc2b-68e057e22340} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{84da4fdf-a1cf-4195-8688-3e961f505983} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{d9fffb27-d62a-4d64-8cec-1ff006528805} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{0d26bc71-a633-4e71-ad31-eadc3a1b6a3a} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{3e720450-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{621feacd-8857-43a6-ae26-451d670d5370} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{c8cecde3-1ae1-4c4a-ad82-6d5b00212144} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{037c7b8a-151a-49e6-baed-cc05fcb50328} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-0000-0000-0000-100005000004} (Rogue.Installer) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\prunnet (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\xpreapp (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully. ——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Thursday, January 1, 2009 Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Thursday, January 01, 2009 19:42:53 Records in database: 1544185 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ D:\ Scan statistics: Files scanned: 45197 Threat name: 3 Infected objects: 4 Suspicious objects: 0 Duration of the scan: 00:33:28 File name / Threat name / Threats count C:\_OTMoveIt\MovedFiles\01012009_144619\WINDOWS\System32\kkfsgi.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.fpf 1 C:\_OTMoveIt\MovedFiles\01012009_144619\WINDOWS\System32\rqRKBQhG.dll Infected: Trojan.Win32.Monder.aftl 1 C:\_OTMoveIt\MovedFiles\01012009_144619\WINDOWS\System32\xxvxkmch.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.fpf 1 C:\_OTMoveIt\MovedFiles\01012009_144619\WINDOWS\System32\ybeusidw.dll Infected: Trojan.Win32.Monder.agia 1 The selected area was scanned.
Thank you…here is the log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:11:33 PM, on 1/2/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SYSTEM32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9975FF86-851C-422E-A2A1-25E4C13D67F1} - C:\WINDOWS\system32\rqRKBQhG.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [LXBYCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBYtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopularScreensaversWallpaper] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\F3SCRCTR.DLL,LES
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O8 - Extra context menu item: &Search -
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O20 - Winlogon Notify: efcBqrrO - efcBqrrO.dll (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxby_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbycoms.exe

–
End of file - 8292 bytes
hello

1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

O2 - BHO: (no name) - {9975FF86-851C-422E-A2A1-25E4C13D67F1} - C:\WINDOWS\system32\rqRKBQhG.dll (file missing)
O20 - Winlogon Notify: efcBqrrO - efcBqrrO.dll (file missing)


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.


REboot and post a new HJT log
Thank you….here is the hjt log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:51:31 PM, on 1/2/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\SYSTEM32\Ati2evxx.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [LXBYCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBYtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopularScreensaversWallpaper] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\F3SCRCTR.DLL,LES
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O8 - Extra context menu item: &Search -
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxby_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbycoms.exe

–
End of file - 8028 bytes
Your logs are clean

  • Make sure you have an Internet Connection.
  • Download OTCleanIt to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTCleanUp to reach the Internet, please allow the application to do so.
  • Click Yes to beging the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.



Your using an old version of Adobe Acrobat Reader, this can leave your pc open to vulnerabilities, you can update it here :
http://www.adobe.com/products/acrobat/readstep2.html



Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.



Now we need to create a new System Restore point.

Click Start Menu > Run > type (or copy and paste)

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it and click Create, when the confirmation screen shows the restore point has been created click Close.

Next goto Start Menu > Run > type

cleanmgr

Click OK, Disk Cleanup will open and start calculating the amount of space that can be freed, Once thats finished it will open the Disk Cleanup options screen, click the More Options tab then click Clean up on the system restore area and choose Yes at the confirmation window which will remove all the restore points except the one we just created.

To close Disk Cleanup and remove the Temporary Internet Files detected in the initial scan click OK then choose Yes on the confirmation window.



Below I have included a number of recommendations for how to protect your computer against malware infections.

* Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.

* To reduce re-infection for malware in the future, I strongly recommend installing these free programs:

SpywareBlaster protects against bad ActiveX

* SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender) or there will be a conflict.

Make Internet Explorer more secure
  • Click Start > Run
  • Type Inetcpl.cpl & click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected & Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.


*ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

*NoScript - Addon for Firefox that stops all scripts from running on websites. Stops malicious software from invading via flash, java, javascript, and many other entry points.

*Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

* MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

* Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
Here

* Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place'
Here

*ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

* Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.

Thank you for your patience, and performing all of the procedures requested.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI