This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Vundo causing delays and popups

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My dad's computer has a Norton Antivirus Notification telling me there is a trojan Vundo. I cannot shut the message off, it keeps turning back on. Also the mouse and keyboard have rediculously long reaction time - forcing me to pause between each letter I type.

Here are the Malwarebites and HiJackthis logs.

Malwarebytes' Anti-Malware 1.31
Database version: 1597
Windows 5.1.2600 Service Pack 2

1/3/2009 8:22:34 AM
mbam-log-2009-01-03 (08-22-10).txt

Scan type: Quick Scan
Objects scanned: 65151
Time elapsed: 58 minute(s), 10 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 3
Registry Keys Infected: 27
Registry Values Infected: 2
Registry Data Items Infected: 2
Folders Infected: 5
Files Infected: 15

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\SYSTEM32\mlJBQIbY.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\SYSTEM32\opnomnnm.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\SYSTEM32\gxllex.dll (Trojan.Vundo) -> No action taken.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\opnomnnm (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9bd5b00f-7ace-4e6c-940e-4756a0992077} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{9bd5b00f-7ace-4e6c-940e-4756a0992077} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c539bb18-51a3-4ea9-91df-a77c0be35ecd} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{c539bb18-51a3-4ea9-91df-a77c0be35ecd} (Trojan.Vundo.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c539bb18-51a3-4ea9-91df-a77c0be35ecd} (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9bd5b00f-7ace-4e6c-940e-4756a0992077} (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> No action taken.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\icheck (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\GetModule (Adware.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\getmodule32 (Trojan.Agent) -> No action taken.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\mljbqiby -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\mljbqiby -> No action taken.

Folders Infected:
C:\Program Files\MyWaySA (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWaySA\SrchAsDe (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWaySA\SrchAsDe\1.bin (Adware.MyWebSearch) -> No action taken.
C:\Program Files\iCheck (Trojan.Agent) -> No action taken.
C:\Program Files\GetModule (Trojan.Agent) -> No action taken.

Files Infected:
C:\WINDOWS\SYSTEM32\opnomnnm.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\SYSTEM32\mlJBQIbY.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\SYSTEM32\YbIQBJlm.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\SYSTEM32\YbIQBJlm.ini2 (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\SYSTEM32\gxllex.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\SYSTEM32\cggjbmhu.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\SYSTEM32\uhmbjggc.ini (Trojan.Vundo.H) -> No action taken.
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -> No action taken.
C:\WINDOWS\SYSTEM32\klvbcc.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\SYSTEM32\oyxcftgq.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\rsvgyukm.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\SYSTEM32\wmcivtbb.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\wpv401229907513.cpx (Adware.Agent) -> No action taken.
C:\Documents and Settings\Erminio Cardi\q.exe (Trojan.Downloader) -> No action taken.
C:\Program Files\iCheck\Uninstall.exe (Trojan.Agent) -> No action taken.

************************************
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:23:22 AM, on 1/3/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Polesoft\Lockspam_Pro\Addins\oehooker.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\Polesoft\Lockspam_Pro\jre\bin\lockspam.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://refdesk.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [StartLockspam] C:\Program Files\Polesoft\Lockspam_Pro\Lockspam.exe
O4 - HKLM\..\Run: [StartOEhooker] C:\Program Files\Polesoft\Lockspam_Pro\Addins\oehooker.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [GetModule32] "C:\Program Files\GetModule\GetModule32.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://download.shockwave.com/pub/otoy/OTOYAX.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/in…l/installer.exe
O20 - AppInit_DLLs: gxllex.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

–
End of file - 6933 bytes

***********

Thanks for your help. My dad is "legally blind" and needs his computer to read and do just about everything else.
hello

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.
Thanks for the quick reply. I ran SDfix. here is the log. The keyboard is responding correctly now. However upon opening internet explorer and loading the home page I get an error message that reads: "Internet Explorer cannot open the internet site Operation Aborted." In the time it took me to write down the message, a second IE window opened and went to that page anyway (it looks like an Apple Ipod site.)

Anyway - here is the sdfix log:


SDFix: Version 1.240
Run by [removed] on Sun 01/04/2009 at 08:32 AM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\WINDOWS\system32\opnomnnm.dll - Deleted
C:\Program Files\iCheck\Uninstall.exe - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP15.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP1A.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP1B.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP21.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP2A.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP2D.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP2F.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP32.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP33.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP36.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP37.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP39.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP3A.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP3D.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP3E.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP40.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP46.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP47.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP4B.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP4E.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP51.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP55.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP58.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP62.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP66.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\tmp6D.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP79.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\tmp86.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP8D.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP91.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP94.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMP9C.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\tmpA6.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMPA7.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMPAC.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMPAF.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMPB2.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMPB5.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMPCA.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMPCE.tmp - Deleted
C:\DOCUME~1\ERMINI~1\LOCALS~1\Temp\TMPF1.tmp - Deleted



Folder C:\Program Files\iCheck - Removed


Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-04 08:43:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Polesoft\\Lockspam_Pro\\jre\\bin\\lockspam.exe"="C:\\Program Files\\Polesoft\\Lockspam_Pro\\jre\\bin\\lockspam.exe:*:Enabled:lockspam"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Disabled:AOL Instant Messenger"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Tue 24 Aug 2004 155,648 A..H. — "C:\DELL\PRIMOSDK.DLL"
Tue 24 Aug 2004 360,448 A..H. — "C:\DELL\PX.DLL"
Wed 28 Jul 2004 56,832 A..H. — "C:\DELL\PXCPYA64.EXE"
Wed 28 Jul 2004 108,544 A..H. — "C:\DELL\PXCPYI64.EXE"
Wed 18 Aug 2004 389,120 A..H. — "C:\DELL\PXDRV.DLL"
Mon 2 Aug 2004 20,576 A..H. — "C:\DELL\PXHELP20.SYS"
Mon 2 Aug 2004 54,976 A..H. — "C:\DELL\PXHELP64.SYS"
Mon 2 Aug 2004 32,272 A..H. — "C:\DELL\PXHELPER.SYS"
Mon 2 Aug 2004 26,720 A..H. — "C:\DELL\PXHLPA64.SYS"
Mon 2 Aug 2004 57,344 A..H. — "C:\DELL\PXHPINST.EXE"
Mon 2 Aug 2004 53,760 A..H. — "C:\DELL\PXINSA64.EXE"
Mon 2 Aug 2004 104,960 A..H. — "C:\DELL\PXINSI64.EXE"
Tue 24 Aug 2004 159,744 A..H. — "C:\DELL\PXMAS.DLL"
Wed 28 Jul 2004 57,344 A..H. — "C:\DELL\PXSETUP.EXE"
Tue 24 Aug 2004 339,968 A..H. — "C:\DELL\PXWAVE.DLL"
Thu 20 May 2004 28,672 A..H. — "C:\DELL\VXBLOCK.DLL"
Tue 24 Aug 2004 155,648 A..H. — "C:\DELL\MEDIAEXE\PRIMOSDK.DLL"
Tue 24 Aug 2004 360,448 A..H. — "C:\DELL\MEDIAEXE\PX.DLL"
Wed 28 Jul 2004 56,832 A..H. — "C:\DELL\MEDIAEXE\PXCPYA64.EXE"
Wed 28 Jul 2004 108,544 A..H. — "C:\DELL\MEDIAEXE\PXCPYI64.EXE"
Wed 18 Aug 2004 389,120 A..H. — "C:\DELL\MEDIAEXE\PXDRV.DLL"
Mon 2 Aug 2004 20,576 A..H. — "C:\DELL\MEDIAEXE\PXHELP20.SYS"
Mon 2 Aug 2004 54,976 A..H. — "C:\DELL\MEDIAEXE\PXHELP64.SYS"
Mon 2 Aug 2004 32,272 A..H. — "C:\DELL\MEDIAEXE\PXHELPER.SYS"
Mon 2 Aug 2004 26,720 A..H. — "C:\DELL\MEDIAEXE\PXHLPA64.SYS"
Mon 2 Aug 2004 57,344 A..H. — "C:\DELL\MEDIAEXE\PXHPINST.EXE"
Mon 2 Aug 2004 53,760 A..H. — "C:\DELL\MEDIAEXE\PXINSA64.EXE"
Mon 2 Aug 2004 104,960 A..H. — "C:\DELL\MEDIAEXE\PXINSI64.EXE"
Tue 24 Aug 2004 159,744 A..H. — "C:\DELL\MEDIAEXE\PXMAS.DLL"
Wed 28 Jul 2004 57,344 A..H. — "C:\DELL\MEDIAEXE\PXSETUP.EXE"
Tue 24 Aug 2004 339,968 A..H. — "C:\DELL\MEDIAEXE\PXWAVE.DLL"
Thu 20 May 2004 28,672 A..H. — "C:\DELL\MEDIAEXE\VXBLOCK.DLL"
Mon 26 Mar 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Mon 25 Jun 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Thu 12 Apr 2007 8 A..H. — "C:\Documents and Settings\Erminio Cardi\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Thu 12 Apr 2007 8 A..H. — "C:\Documents and Settings\Erminio Cardi\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Thu 12 Apr 2007 8 A..H. — "C:\Documents and Settings\Erminio Cardi\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Thu 12 Apr 2007 8 A..H. — "C:\Documents and Settings\Erminio Cardi\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"

Finished!


************

What's next? Again, I so appreciate the help - you people are fantastic!
I wanted to post Hijackthis and malwarebites logs as well. The browser is sort of getting redirected now. Everytime I open IE, in the middle of the homepage opening pocess, a second IE window opensand brings me to different places - a diferent window everytime. As youcan see, the Malwarebites log still shows a Vundo trojan.

alwarebytes' Anti-Malware 1.31
Database version: 1597
Windows 5.1.2600 Service Pack 2

1/4/2009 9:43:58 AM
mbam-log-2009-01-04 (09-43-54).txt

Scan type: Quick Scan
Objects scanned: 50467
Time elapsed: 4 minute(s), 16 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 3
Registry Keys Infected: 22
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 3
Files Infected: 15

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\SYSTEM32\cksljalr.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\SYSTEM32\mlJBQIbY.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\SYSTEM32\vyupby.dll (Trojan.Vundo) -> No action taken.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1066cda9-cf61-46f0-9d82-24faffcf08e3} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{1066cda9-cf61-46f0-9d82-24faffcf08e3} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d9c07c9f-0dfd-49a4-a79d-16dc000be160} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{d9c07c9f-0dfd-49a4-a79d-16dc000be160} (Trojan.Vundo.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1066cda9-cf61-46f0-9d82-24faffcf08e3} (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d9c07c9f-0dfd-49a4-a79d-16dc000be160} (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> No action taken.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\74e838fe (Trojan.Vundo.H) -> No action taken.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\mljbqiby -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\mljbqiby -> No action taken.

Folders Infected:
C:\Program Files\MyWaySA (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWaySA\SrchAsDe (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWaySA\SrchAsDe\1.bin (Adware.MyWebSearch) -> No action taken.

Files Infected:
C:\WINDOWS\SYSTEM32\vyupby.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\SYSTEM32\mlJBQIbY.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\SYSTEM32\YbIQBJlm.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\SYSTEM32\YbIQBJlm.ini2 (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\SYSTEM32\cggjbmhu.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\SYSTEM32\uhmbjggc.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\SYSTEM32\cksljalr.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\SYSTEM32\rlajlskc.ini (Trojan.Vundo.H) -> No action taken.
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -> No action taken.
C:\WINDOWS\SYSTEM32\klvbcc.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\SYSTEM32\oyxcftgq.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\SYSTEM32\tpglnjbo.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\SYSTEM32\wmcivtbb.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\SYSTEM32\gxllex.dll (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\Erminio Cardi\q.exe (Trojan.Downloader) -> No action taken.


********************
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:38:21 AM, on 1/4/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Polesoft\Lockspam_Pro\Addins\oehooker.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Polesoft\Lockspam_Pro\jre\bin\lockspam.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://refdesk.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [StartLockspam] C:\Program Files\Polesoft\Lockspam_Pro\Lockspam.exe
O4 - HKLM\..\Run: [StartOEhooker] C:\Program Files\Polesoft\Lockspam_Pro\Addins\oehooker.exe
O4 - HKLM\..\Run: [74e838fe] rundll32.exe "C:\WINDOWS\system32\cksljalr.dll",b
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://download.shockwave.com/pub/otoy/OTOYAX.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/in…l/installer.exe
O20 - AppInit_DLLs: vyupby.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

–
End of file - 6741 bytes

********
When I bring up the Add/Remove program screen from Control panel, there is a program in there called MySearch which I am unable to remove. There was also something called OTOY which I did remove, allthough perhaps I shouldn't have?

again, thanks for you help.
:unsure:
hello

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
So far so good. I ran ATF cleaner then Malwarebites, and I did have to restart to complete the removal process. Here is the log: Malwarebytes' Anti-Malware 1.31 Database version: 1597 Windows 5.1.2600 Service Pack 2 1/4/2009 10:33:31 AM mbam-log-2009-01-04 (10-33-31).txt Scan type: Quick Scan Objects scanned: 49122 Time elapsed: 3 minute(s), 10 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ********************************* What's next?
What is the "Kaspersky log" - I must have missed something? Here is the new HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:53:19 AM, on 1/4/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Polesoft\Lockspam_Pro\Addins\oehooker.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Polesoft\Lockspam_Pro\jre\bin\lockspam.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://refdesk.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [StartLockspam] C:\Program Files\Polesoft\Lockspam_Pro\Lockspam.exe
O4 - HKLM\..\Run: [StartOEhooker] C:\Program Files\Polesoft\Lockspam_Pro\Addins\oehooker.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://download.shockwave.com/pub/otoy/OTOYAX.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/in…l/installer.exe
O20 - AppInit_DLLs: vyupby.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

–
End of file - 6953 bytes
**********

I'll reread your posts - I don't know what the "Kaspersky log" is.
Here is the kaspersky scan report: ——————————————————————————- KASPERSKY ONLINE SCANNER 7 REPORT Sunday, January 4, 2009 Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Sunday, January 04, 2009 15:43:32 Records in database: 1558856 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Files scanned: 49668 Threat name: 2 Infected objects: 3 Suspicious objects: 0 Duration of the scan: 00:58:57 ************** Sorry about missing that the first time.
hello

1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O20 - AppInit_DLLs: vyupby.dll


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.



  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
ok here are the otlistllt2 logs.

OTListIt logfile created on: 1/4/2009 2:09:09 PM - Run
OTListIt2 by OldTimer - Version 1.0.2.0 Folder = C:\Documents and Settings\Erminio Cardi\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.25 Gb Total Physical Memory | 0.78 Gb Available Physical Memory | 62.61% Memory free
1.86 Gb Paging File | 1.60 Gb Available in Paging File | 86.20% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 70.82 Gb Total Space | 59.32 Gb Free Space | 83.77% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: D6JR9F61
Current User Name: Erminio Cardi
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

C:\Program Files\NavNT\defwatch.exe (Symantec Corporation)
C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe (Intel Corporation)
C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe (Sonic Solutions)
C:\WINDOWS\SYSTEM32\hkcmd.exe (Intel Corporation)
C:\WINDOWS\SYSTEM32\igfxpers.exe (Intel Corporation)
C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
C:\Program Files\NavNT\vptray.exe (Symantec Corporation)
C:\Program Files\Polesoft\Lockspam_Pro\addins\OEHooker.exe ()
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.)
C:\Program Files\Dell\Media Experience\PCMService.exe (CyberLink Corp.)
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe (Musicmatch, Inc.)
C:\Program Files\iTunes\iTunesHelper.exe (Apple Computer, Inc.)
C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
C:\Program Files\Polesoft\Lockspam_Pro\jre\bin\lockspam.exe ()
C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe (Panicware, Inc.)
C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
C:\Program Files\iPod\bin\iPodService.exe (Apple Computer, Inc.)
C:\WINDOWS\SYSTEM32\WSCNTFY.EXE (Microsoft Corporation)
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE (Microsoft Corporation)
C:\WINDOWS\SYSTEM32\igfxsrvc.exe (Intel Corporation)
C:\Documents and Settings\Erminio Cardi\Desktop\OTListIt2.exe (OldTimer Tools)
C:\WINDOWS\NOTEPAD.EXE (Microsoft Corporation)

========== (O23) Win32 Services (SafeList) ==========

(aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
(DefWatch [Auto | Running]) – C:\Program Files\NavNT\defwatch.exe (Symantec Corporation)
(DSBrokerService [On_Demand | Stopped]) – C:\Program Files\DellSupport\brkrsvc.exe ()
(IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
(iPodService [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Computer, Inc.)
(JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
(NetSvc [On_Demand | Stopped]) – C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe (Intel® Corporation)
(Norton AntiVirus Server [Disabled | Stopped]) – C:\Program Files\NavNT\rtvscan.exe (Symantec Corporation)
(WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

(AliIde [Boot | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\ALIIDE.SYS (Acer Laboratories Inc.)
(amdagp [Boot | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\AMDAGP.SYS (Advanced Micro Devices, Inc.)
(asc [Boot | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\ASC.SYS (Advanced System Products, Inc.)
(asc3550 [Boot | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\ASC3550.SYS (Advanced System Products, Inc.)
(ASCTRM [Auto | Running]) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
(CmdIde [Boot | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\CMDIDE.SYS (CMD Technology, Inc.)
(dac2w2k [Boot | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\DAC2W2K.SYS (Mylex Corporation)
(drvmcdb [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\drvmcdb.sys (Sonic Solutions)
(drvnddm [Auto | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\drvnddm.sys (Sonic Solutions)
(DSproct [On_Demand | Running]) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
(dsunidrv [Auto | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
(E100B [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\e100b325.sys (Intel Corporation)
(GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
(ialm [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\ialmnt5.sys (Intel Corporation)
(IntelC51 [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC51.sys (Intel Corporation)
(IntelC52 [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC52.sys (Intel Corporation)
(IntelC53 [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC53.sys (Intel Corporation)
(MODEMCSA [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)
(mohfilt [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\mohfilt.sys (Intel Corporation)
(mraid35x [Boot | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\MRAID35X.SYS (American Megatrends Inc.)
(NAVAP [On_Demand | Stopped]) – C:\Program Files\NavNT\navap.sys ()
(NAVAPEL [Auto | Running]) – C:\Program Files\NavNT\Navapel.sys ()
(NAVENG [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20081231.003\NAVENG.SYS (Symantec Corporation)
(NAVEX15 [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20081231.003\NAVEX15.SYS (Symantec Corporation)
(nv [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\NV4_MINI.SYS (NVIDIA Corporation)
(Ptilink [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS (Parallel Technologies, Inc.)
(PxHelp20 [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\pxhelp20.sys (Sonic Solutions)
(ql1080 [Boot | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\QL1080.SYS (QLogic Corporation)
(ql12160 [Boot | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\QL12160.SYS (QLogic Corporation)
(ql1280 [Boot | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\QL1280.SYS (QLogic Corporation)
(rtl8139 [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\RTL8139.sys (Realtek Semiconductor Corporation)
(Secdrv [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(senfilt [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\senfilt.sys (Sensaura)
(sisagp [Boot | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\SISAGP.SYS (Silicon Integrated Systems Corporation)
(smwdm [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\smwdm.sys (Analog Devices, Inc.)
(Sparrow [Boot | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\SPARROW.SYS (Adaptec, Inc.)
(sscdbhk5 [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\sscdbhk5.sys (Sonic Solutions)
(ssrtln [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\ssrtln.sys (Sonic Solutions)
(symc810 [Boot | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\SYMC810.SYS (Symbios Logic Inc.)
(symc8xx [Boot | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\SYMC8XX.SYS (LSI Logic)
(SymEvent [On_Demand | Stopped]) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
(sym_hi [Boot | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\SYM_HI.SYS (LSI Logic)
(sym_u3 [Boot | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\SYM_U3.SYS (LSI Logic)
(tfsnboio [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnboio.sys (Sonic Solutions)
(tfsncofs [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsncofs.sys (Sonic Solutions)
(tfsndrct [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsndrct.sys (Sonic Solutions)
(tfsndres [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsndres.sys (Sonic Solutions)
(tfsnifs [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnifs.sys (Sonic Solutions)
(tfsnopio [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnopio.sys (Sonic Solutions)
(tfsnpool [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnpool.sys (Sonic Solutions)
(tfsnudf [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnudf.sys (Sonic Solutions)
(tfsnudfa [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnudfa.sys (Sonic Solutions)
(ultra [Boot | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\ULTRA.SYS (Promise Technology, Inc.)
(WS2IFSL [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS (Microsoft Corporation)

========== Standard Registry (All) ==========


========== Internet Explorer ==========

HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://refdesk.com/
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O1 HOSTS File: (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\SYSTEM32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\SYSTEM32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {1028F737-81E7-452B-A860-E50CAD90A08C} - Reg Error: Key does not exist or could not be opened. File not found
O4 - HKLM..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Computer, Inc.)
O4 - HKLM..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER (RealNetworks, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [StartLockspam] C:\Program Files\Polesoft\Lockspam_Pro\Lockspam.exe ()
O4 - HKLM..\Run: [StartOEhooker] C:\Program Files\Polesoft\Lockspam_Pro\Addins\oehooker.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r (Sonic Solutions)
O4 - HKLM..\Run: [vptray] C:\Program Files\NavNT\vptray.exe (Symantec Corporation)
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup (Gteko Ltd.)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" (Panicware, Inc.)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9 (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9 - Extra Button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\shdocvw.dll (Microsoft Corporation)
O9 - Extra Button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Sites: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} http://download.shockwave.com/pub/otoy/OTOYAX.cab (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://3dlifeplayer.dl.3dvia.com/player/in…l/installer.exe (Virtools WebPlayer Class)
O18 - Protocol\Handler: - about - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - cdl - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - cdo - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - dvd - C:\WINDOWS\SYSTEM32\MSVIDCTL.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - file - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ftp - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - gopher - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - http\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - https - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - https\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - https\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ipp - No CLSID value found
O18 - Protocol\Handler: - ipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - its - C:\WINDOWS\SYSTEM32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - javascript - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - local - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mailto - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mhtml - C:\WINDOWS\SYSTEM32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mk - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp - No CLSID value found
O18 - Protocol\Handler: - msdaipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ms-its - C:\WINDOWS\SYSTEM32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ms-itss - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - res - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - sysimage - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - tv - C:\WINDOWS\SYSTEM32\MSVIDCTL.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - vbscript - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - wia - C:\WINDOWS\SYSTEM32\WIASCR.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\SYSTEM32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\SYSTEM32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\SYSTEM32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\SYSTEM32\shell32.dll (Microsoft Corporation)
O20 - See sections below for AppInitDlls and Winlogon settings
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9}C:\WINDOWS\SYSTEM32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9}C:\WINDOWS\SYSTEM32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153}C:\WINDOWS\SYSTEM32\STOBJECT.DLL (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}C:\WINDOWS\SYSTEM32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5}C:\WINDOWS\SYSTEM32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: (Browseui preloader) - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\SYSTEM32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: (Component Categories cache daemon) - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\SYSTEM32\browseui.dll (Microsoft Corporation)

========== HKLM Winlogon Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell" = Explorer.exe
>C:\WINDOWS\explorer.exe (Microsoft Corporation)

"UserInit" = C:\WINDOWS\system32\userinit.exe,
>C:\WINDOWS\SYSTEM32\USERINIT.EXE (Microsoft Corporation)

"UIHost" = logonui.exe
>C:\WINDOWS\SYSTEM32\LOGONUI.EXE (Microsoft Corporation)

"VMApplet" = rundll32 shell32,Control_RunDLL "sysdm.cpl"
>C:\WINDOWS\SYSTEM32\shell32.dll (Microsoft Corporation)
>C:\WINDOWS\SYSTEM32\SYSDM.CPL (Microsoft Corporation)


========== Winlogon Notify Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
crypt32chain: "DllName" = crypt32.dll – C:\WINDOWS\SYSTEM32\CRYPT32.DLL (Microsoft Corporation)
cryptnet: "DllName" = cryptnet.dll – C:\WINDOWS\SYSTEM32\CRYPTNET.DLL (Microsoft Corporation)
cscdll: "DllName" = cscdll.dll – C:\WINDOWS\SYSTEM32\CSCDLL.DLL (Microsoft Corporation)
igfxcui: "DllName" = igfxdev.dll – C:\WINDOWS\SYSTEM32\igfxdev.dll (Intel Corporation)
NavLogon: "DllName" = C:\WINDOWS\system32\NavLogon.dll – C:\WINDOWS\SYSTEM32\NavLogon.dll ()
ScCertProp: "DllName" = wlnotify.dll – C:\WINDOWS\SYSTEM32\WLNOTIFY.DLL (Microsoft Corporation)
Schedule: "DllName" = wlnotify.dll – C:\WINDOWS\SYSTEM32\WLNOTIFY.DLL (Microsoft Corporation)
sclgntfy: "DllName" = sclgntfy.dll – C:\WINDOWS\SYSTEM32\SCLGNTFY.DLL (Microsoft Corporation)
SensLogn: "DllName" = WlNotify.dll – C:\WINDOWS\SYSTEM32\WLNOTIFY.DLL (Microsoft Corporation)
termsrv: "DllName" = wlnotify.dll – C:\WINDOWS\SYSTEM32\WLNOTIFY.DLL (Microsoft Corporation)
wlballoon: "DllName" = wlnotify.dll – C:\WINDOWS\SYSTEM32\WLNOTIFY.DLL (Microsoft Corporation)

========== IFEO "Debugger" Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\]
Your Image File Name Here without a path:"Debugger" = C:\WINDOWS\SYSTEM32\NTSD.EXE (Microsoft Corporation)

========== HKLM *SecurityProviders* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders" = msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, digeste.dll
>C:\WINDOWS\SYSTEM32\MSAPSSPC.DLL (Microsoft Corporation)
>C:\WINDOWS\SYSTEM32\schannel.dll (Microsoft Corporation)
>C:\WINDOWS\SYSTEM32\DIGEST.DLL (Microsoft Corporation)
>C:\WINDOWS\SYSTEM32\MSNSSPC.DLL (Microsoft Corporation)
> File not found

========== LSA *Authentication Packages* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages" = msv1_0,
>C:\WINDOWS\SYSTEM32\MSV1_0.DLL (Microsoft Corporation)

========== LSA *Security Packages* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Security Packages" = kerberos,msv1_0,schannel,wdigest,
>C:\WINDOWS\SYSTEM32\kerberos.dll (Microsoft Corporation)
>C:\WINDOWS\SYSTEM32\MSV1_0.DLL (Microsoft Corporation)
>C:\WINDOWS\SYSTEM32\schannel.dll (Microsoft Corporation)
>C:\WINDOWS\SYSTEM32\wdigest.dll (Microsoft Corporation)

========== Safeboot Options ==========

"AlternateShell" = cmd.exe

========== CDRom AutoRun Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1

========== Autorun Files on Drives ==========

AUTOEXEC.BAT []
C:\AUTOEXEC.BAT () – [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[1 C:\*.tmp files]
[2009/01/04 14:06:35 | 00,420,864 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Erminio Cardi\Desktop\OTListIt2.exe
[2009/01/04 09:25:46 | 00,001,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2009/01/04 09:17:54 | 00,000,000 | —D | C] – C:\WINDOWS\pss
[2009/01/04 08:41:06 | 13,401,33376 | -HS- | C] () – C:\hiberfil.sys
[2009/01/03 12:33:18 | 00,000,000 | —D | C] – C:\WINDOWS\ERUNT
[2009/01/03 12:22:44 | 00,000,000 | —D | C] – C:\SDFix
[2009/01/03 12:22:23 | 01,529,241 | —- | C] () – C:\Documents and Settings\Erminio Cardi\Desktop\SDFix.exe
[2009/01/03 09:07:49 | 00,001,599 | —- | C] () – C:\Documents and Settings\Erminio Cardi\Desktop\Remote Assistance.lnk
[2009/01/02 21:19:53 | 00,000,000 | —D | C] – C:\VundoFix Backups
[2009/01/02 20:59:43 | 00,000,000 | —D | C] – C:\Documents and Settings\Erminio Cardi\Application Data\Malwarebytes
[2009/01/02 20:59:29 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/02 20:59:28 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/02 20:59:22 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/02 20:59:20 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/02 20:59:19 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/01/02 20:58:29 | 02,539,168 | —- | C] (Malwarebytes Corporation ) – C:\Program Files\mbam-setup.exe
[2009/01/02 20:47:04 | 00,001,734 | —- | C] () – C:\Documents and Settings\Erminio Cardi\Desktop\HijackThis.lnk
[2009/01/02 20:47:03 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/01/02 20:46:44 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Program Files\HJTInstall.exe
[2009/01/01 11:57:57 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\poasgn.dll
[2009/01/01 11:57:54 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\haodgwcd.dll
[2009/01/01 11:55:15 | 01,308,211 | -HS- | C] () – C:\WINDOWS\System32\vbnpgfjx.ini
[2008/12/30 16:17:38 | 00,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2008/12/30 11:05:36 | 01,308,211 | -HS- | C] () – C:\WINDOWS\System32\uqowtntu.ini
[2008/12/30 11:05:33 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\xdgpkg.dll
[2008/12/30 11:05:30 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\gsdgrykd.dll
[2008/12/28 20:45:03 | 01,308,204 | -HS- | C] () – C:\WINDOWS\System32\ofekcvyn.ini
[2008/12/28 20:33:53 | 00,000,326 | —- | C] () – C:\WINDOWS\tasks\aanxrlpp.job

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[8 C:\WINDOWS\System32\*.tmp files]
[2009/01/04 14:06:39 | 00,420,864 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Erminio Cardi\Desktop\OTListIt2.exe
[2009/01/04 11:00:00 | 00,000,326 | —- | M] () – C:\WINDOWS\tasks\aanxrlpp.job
[2009/01/04 10:24:42 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/01/04 10:24:31 | 00,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2009/01/04 10:24:26 | 13,401,33376 | -HS- | M] () – C:\hiberfil.sys
[2009/01/04 10:23:53 | 06,789,792 | -H– | M] () – C:\Documents and Settings\Erminio Cardi\Local Settings\Application Data\IconCache.db
[2009/01/04 09:25:48 | 00,000,507 | —- | M] () – C:\WINDOWS\WIN.INI
[2009/01/04 09:25:48 | 00,000,227 | —- | M] () – C:\WINDOWS\SYSTEM.INI
[2009/01/04 09:25:48 | 00,000,211 | RHS- | M] () – C:\BOOT.INI
[2009/01/04 08:33:40 | 00,000,686 | —- | M] () – C:\WINDOWS\System32\drivers\ETC\HOSTS
[2009/01/03 12:22:43 | 01,529,241 | —- | M] () – C:\Documents and Settings\Erminio Cardi\Desktop\SDFix.exe
[2009/01/02 20:59:29 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/02 20:47:04 | 00,001,734 | —- | M] () – C:\Documents and Settings\Erminio Cardi\Desktop\HijackThis.lnk
[2009/01/02 11:56:04 | 01,308,211 | -HS- | M] () – C:\WINDOWS\System32\vbnpgfjx.ini
[2009/01/01 11:57:57 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\poasgn.dll
[2009/01/01 11:57:57 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\haodgwcd.dll
[2009/01/01 11:54:56 | 01,308,211 | -HS- | M] () – C:\WINDOWS\System32\uqowtntu.ini
[2008/12/30 16:17:38 | 00,000,552 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2008/12/30 11:05:33 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\xdgpkg.dll
[2008/12/30 11:05:33 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\gsdgrykd.dll
[2008/12/30 11:03:34 | 01,308,204 | -HS- | M] () – C:\WINDOWS\System32\ofekcvyn.ini
[2008/12/13 01:40:02 | 03,593,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.dll
[2008/12/13 01:40:02 | 03,593,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2008/12/10 22:11:25 | 00,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2008/12/09 18:24:37 | 17,593,280 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe

========== LOP Check ==========

[2009/01/02 20:59:20 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2007/11/26 10:53:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2005/01/01 10:39:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2006/04/08 13:29:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2004/12/23 16:06:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2008/02/02 11:52:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Dell
[2009/01/02 20:21:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2004/12/23 16:14:22 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2004/12/23 16:15:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2009/01/02 20:59:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2007/01/02 20:32:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2006/12/30 18:00:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall
[2005/02/15 21:26:46 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2005/01/01 10:52:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Polesoft
[2005/02/05 15:24:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2004/12/23 15:31:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2007/01/11 17:37:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2008/02/29 12:55:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/06/12 08:50:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/01/02 20:59:43 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Erminio Cardi\Application Data
[2008/01/09 10:48:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Adobe
[2008/02/07 09:46:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\AdobeUM
[2005/03/05 15:08:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Aim
[2006/10/06 18:48:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Apple Computer
[2005/03/06 22:37:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\CyberLink
[2007/09/23 13:32:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Google
[2007/04/12 15:16:08 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Gtek
[2008/08/16 06:43:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Identities
[2004/12/23 16:14:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Jasc Software Inc
[2005/01/01 10:43:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Lavasoft
[2005/03/06 15:46:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Macromedia
[2009/01/02 20:59:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Malwarebytes
[2005/01/21 18:30:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\McAfee.com
[2005/10/30 11:55:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\McAfee.com Personal Firewall
[2005/10/13 19:03:06 | 00,000,000 | –SD | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Microsoft
[2005/02/05 14:58:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Nikon
[2005/01/01 10:52:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Polesoft
[2004/12/23 16:21:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Sonic
[2004/12/23 16:04:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Sun
[2007/03/16 13:41:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Viewpoint
[2009/01/04 11:00:00 | 00,000,326 | —- | M] () – C:\WINDOWS\Tasks\aanxrlpp.job
[2004/08/04 06:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\DESKTOP.INI
[2009/01/04 10:24:42 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

< End of report >

********************
OTListIt Extras logfile created on: 1/4/2009 2:07:54 PM - Run
OTListIt2 by OldTimer - Version 1.0.2.0 Folder = C:\Documents and Settings\Erminio Cardi\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.25 Gb Total Physical Memory | 0.79 Gb Available Physical Memory | 63.18% Memory free
1.86 Gb Paging File | 1.60 Gb Available in Paging File | 86.41% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 70.82 Gb Total Space | 59.32 Gb Free Space | 83.77% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: D6JR9F61
Current User Name: Erminio Cardi
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
File not found – C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
File not found – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
File not found – C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL
[2006/10/10 07:44:50 | 00,557,568 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
File not found – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
File not found – C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
File not found – C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL
[2005/12/21 10:45:46 | 14,135,808 | —- | M] (Apple Computer, Inc.) – C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
[2004/02/24 15:45:44 | 00,020,576 | —- | M] () – C:\Program Files\Polesoft\Lockspam_Pro\jre\bin\lockspam.exe:*:Enabled:lockspam
[2006/10/10 07:44:50 | 00,557,568 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2004/12/08 17:50:04 | 00,067,160 | —- | M] (America Online, Inc.) – C:\Program Files\AIM\aim.exe:*:Disabled:AOL Instant Messenger
[2009/01/02 17:51:47 | 00,144,792 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{04410044-9149-45C6-A806-F2BF9CFCE762}" = Microsoft Encarta Encyclopedia Standard 2004
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{17334AAF-C9E7-483B-9F45-E3FCAF07FFA7}" = Intel® PROSet for Wired Connections
"{1D643CD7-4DD6-11D7-A4E0-000874180BB3}" = Microsoft Money 2004
"{1E04F83B-2AB9-4301-9EF7-E86307F79C72}" = Google Earth
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Dell Media Experience
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{33BEE6F3-9987-4F98-A069-97A64EC8321A}" = Microsoft Works Suite Add-in for Microsoft Word
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{3D047C15-C859-45F7-81CE-F2681778069B}" = iPod for Windows 2006-01-10
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = Modem On Hold
"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement
"{501BADCD-F8F7-44CB-AC3F-6ED25C1A28B5}" = iTunes
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{78C496B9-5A6B-4692-8C2E-AFFFC34E4961}" = Jasc Paint Shop Pro Studio, Dell Editon
"{78D944D7-A97B-4004-AB0A-B5AD06839940}" = My Way Search Assistant
"{7A0EFAFB-AC4B-4B88-8C6B-6731BE88DB68}" = Modem Event Monitor
"{7A3F0566-5E05-4919-9C98-456F6B5CF831}" = Get High Speed Internet!
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{8704D51E-25B7-4F23-81E7-AA4F54790210}" = Microsoft Streets and Trips 2004
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8C64E145-54BA-11D6-91B1-00500462BE80}" = Microsoft Money 2004 System Pack
"{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}" = Musicmatch® Jukebox
"{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{929408E6-D265-4174-805F-81D1D914E2A4}" = QuickTime
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{AF06CAE4-C134-44B1-B699-14FBDB63BD37}" = Dell Picture Studio v3.0
"{B9966F27-9678-4620-9579-925E3084647E}" = Microsoft Works
"{BD12EB47-DBDF-11D3-BEEA-00A0CC272509}" = Norton AntiVirus Corporate Edition
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{DBA8B9E1-C6FF-4624-9598-73D3B41A0903}" = Microsoft Picture It! Photo Premium 9
"{E93E5EF6-D361-481E-849D-F16EF5C78EBC}" = Musicmatch for Windows Media Player
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"Ad-Aware SE Personal" = Ad-Aware SE Personal
"Adobe Atmosphere Player" = Adobe Atmosphere Player for Acrobat and Adobe Reader
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"AOL Instant Messenger" = AOL Instant Messenger
"FamilyFeudOnlineParty" = FamilyFeudOnlineParty (remove only)
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{3D047C15-C859-45F7-81CE-F2681778069B}" = iPod for Windows 2006-01-10
"InstallShield_{501BADCD-F8F7-44CB-AC3F-6ED25C1A28B5}" = iTunes
"InstallShield_{929408E6-D265-4174-805F-81D1D914E2A4}" = QuickTime
"Intel® 537EP V9x DF PCI Modem" = Intel® 537EP V9x DF PCI Modem
"LiveUpdate1.6" = LiveUpdate 1.6 (Symantec Corporation)
"Lockspam Pro_is1" = Lockspam Pro 3.0.160
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MyWaySearchAssistantDE" = My Way Search Assistant
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PictureIt_v9" = Microsoft Picture It! Photo Premium 9
"Pop-Up Stopper Free Edition" = Pop-Up Stopper Free Edition
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0" = RealPlayer Basic
"Shockwave" = Shockwave
"StreetPlugin" = Learn2 Player (Uninstall Only)
"Virtools3DLifePlayer" = Virtools 3D Life Player
"WildTangent CDA" = WildTangent Web Driver
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Works2004Setup" = Microsoft Works 2004 Setup Launcher
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/3/2009 1:27:05 PM | Computer Name = D6JR9F61 | Source = Norton AntiVirus | ID = 16711685
Description = Virus Found!Virus name: Trojan.Vundo in File: C:\WINDOWS\SYSTEM32\opnomnnm.dll
by: Realtime Protection scan. Action: Clean failed : Quarantine failed : Access
denied

Error - 1/3/2009 1:41:12 PM | Computer Name = D6JR9F61 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2002 – Error 1706. Setup cannot find the
required files. Check your connection to the network, or CD-ROM drive. For other
potential solutions to this problem, see C:\Program Files\Microsoft Office\Office10\1033\SETUP.HLP.

Error - 1/4/2009 9:18:23 AM | Computer Name = D6JR9F61 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2002 – Error 1706. Setup cannot find the
required files. Check your connection to the network, or CD-ROM drive. For other
potential solutions to this problem, see C:\Program Files\Microsoft Office\Office10\1033\SETUP.HLP.

Error - 1/4/2009 9:46:47 AM | Computer Name = D6JR9F61 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2002 – Error 1706. Setup cannot find the
required files. Check your connection to the network, or CD-ROM drive. For other
potential solutions to this problem, see C:\Program Files\Microsoft Office\Office10\1033\SETUP.HLP.

Error - 1/4/2009 9:47:39 AM | Computer Name = D6JR9F61 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2002 – Error 1706. Setup cannot find the
required files. Check your connection to the network, or CD-ROM drive. For other
potential solutions to this problem, see C:\Program Files\Microsoft Office\Office10\1033\SETUP.HLP.

Error - 1/4/2009 9:51:33 AM | Computer Name = D6JR9F61 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16762, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/4/2009 9:52:45 AM | Computer Name = D6JR9F61 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16762, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/4/2009 9:55:46 AM | Computer Name = D6JR9F61 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2002 – Error 1706. Setup cannot find the
required files. Check your connection to the network, or CD-ROM drive. For other
potential solutions to this problem, see C:\Program Files\Microsoft Office\Office10\1033\SETUP.HLP.

Error - 1/4/2009 10:36:51 AM | Computer Name = D6JR9F61 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2002 – Error 1706. Setup cannot find the
required files. Check your connection to the network, or CD-ROM drive. For other
potential solutions to this problem, see C:\Program Files\Microsoft Office\Office10\1033\SETUP.HLP.

Error - 1/4/2009 11:26:35 AM | Computer Name = D6JR9F61 | Source = MsiInstaller | ID = 11706
Description = Product: Microsoft Word 2002 – Error 1706. Setup cannot find the
required files. Check your connection to the network, or CD-ROM drive. For other
potential solutions to this problem, see C:\Program Files\Microsoft Office\Office10\1033\SETUP.HLP.

[ System Events ]
Error - 1/4/2009 9:22:49 AM | Computer Name = D6JR9F61 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error - 1/4/2009 9:22:53 AM | Computer Name = D6JR9F61 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 1/4/2009 9:23:46 AM | Computer Name = D6JR9F61 | Source = Service Control Manager | ID = 7001
Description = The DHCP Client service depends on the NetBios over Tcpip service
which failed to start because of the following error: %%31

Error - 1/4/2009 9:23:46 AM | Computer Name = D6JR9F61 | Source = Service Control Manager | ID = 7001
Description = The DNS Client service depends on the TCP/IP Protocol Driver service
which failed to start because of the following error: %%31

Error - 1/4/2009 9:23:46 AM | Computer Name = D6JR9F61 | Source = Service Control Manager | ID = 7001
Description = The TCP/IP NetBIOS Helper service depends on the AFD service which
failed to start because of the following error: %%31

Error - 1/4/2009 9:23:46 AM | Computer Name = D6JR9F61 | Source = Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver service which
failed to start because of the following error: %%31

Error - 1/4/2009 9:23:46 AM | Computer Name = D6JR9F61 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip WS2IFSL

Error - 1/4/2009 10:28:52 AM | Computer Name = D6JR9F61 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 1/4/2009 11:25:26 AM | Computer Name = D6JR9F61 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
abp480n5 adpu160m agp440 agpCPQ Aha154x aic78u2 aic78xx AliIde alim1541 amdagp amsint asc asc3350p
asc3550
cbidf
cd20xrnt
CmdIde
Cpqarray
dac2w2k
dac960nt
dpti2o
hpn
i2omp
ini910u
IntelIde
mraid35x
perc2
perc2hib
ql1080
Ql10wnt
ql12160
ql1240
ql1280
sisagp
Sparrow
symc810
symc8xx
sym_hi
sym_u3
TosIde
ultra
viaagp
ViaIde

Error - 1/4/2009 11:26:49 AM | Computer Name = D6JR9F61 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}


< End of report >
*******************

I also deleted the 3 files out of hijackthis as instructed.
hello

Please download the OTMoveIt3 by OldTimer or from here.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
    "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
    
    :files
    C:\WINDOWS\System32\poasgn.dll
    C:\WINDOWS\System32\haodgwcd.dll
    C:\WINDOWS\System32\vbnpgfjx.ini
    C:\WINDOWS\System32\uqowtntu.ini
    C:\WINDOWS\System32\xdgpkg.dll
    C:\WINDOWS\System32\gsdgrykd.dll
    C:\WINDOWS\System32\ofekcvyn.ini
    C:\WINDOWS\tasks\aanxrlpp.job
    
    
    :Commands
    [purity]
    [zipfiles]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


This will create a zip file in the folder C:\OTMoveIt3\MovedFiles\(series of numbers).zip

I need you to upload that here

We need to upload a Suspicious file to Malwarebytes Anti-Malware

  • Please go to Malwarebytes' UploadNET
  • Under File 1: browse for

    C:\OTMoveIt3\MovedFiles\(series of numbers).zip

    *Note: If you are asked to upload more files, please repeat these steps for each of the File boxes.
Once you have selected all the files you want to upload, click on the Upload Button



Then run OTL2 again and post that log
Everything moved in the Movit process.
here is the OTlistlt log:

OTListIt logfile created on: 1/4/2009 3:27:43 PM - Run 2
OTListIt2 by OldTimer - Version 1.0.2.0 Folder = C:\Documents and Settings\Erminio Cardi\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.25 Gb Total Physical Memory | 0.86 Gb Available Physical Memory | 68.58% Memory free
1.86 Gb Paging File | 1.59 Gb Available in Paging File | 85.76% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 70.82 Gb Total Space | 59.38 Gb Free Space | 83.85% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: D6JR9F61
Current User Name: Erminio Cardi
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

C:\Program Files\NavNT\defwatch.exe (Symantec Corporation)
C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
C:\WINDOWS\SYSTEM32\WSCNTFY.EXE (Microsoft Corporation)
C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe (Intel Corporation)
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe (Sonic Solutions)
C:\WINDOWS\SYSTEM32\hkcmd.exe (Intel Corporation)
C:\WINDOWS\SYSTEM32\igfxpers.exe (Intel Corporation)
C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
C:\Program Files\NavNT\vptray.exe (Symantec Corporation)
C:\Program Files\Polesoft\Lockspam_Pro\addins\OEHooker.exe ()
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.)
C:\Program Files\Dell\Media Experience\PCMService.exe (CyberLink Corp.)
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe (Musicmatch, Inc.)
C:\Program Files\iTunes\iTunesHelper.exe (Apple Computer, Inc.)
C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe (Panicware, Inc.)
C:\Program Files\iPod\bin\iPodService.exe (Apple Computer, Inc.)
C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
C:\Program Files\Polesoft\Lockspam_Pro\jre\bin\lockspam.exe ()
C:\WINDOWS\SYSTEM32\igfxsrvc.exe (Intel Corporation)
C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
C:\Documents and Settings\Erminio Cardi\Desktop\OTListIt2.exe (OldTimer Tools)
C:\WINDOWS\NOTEPAD.EXE (Microsoft Corporation)

========== (O23) Win32 Services (SafeList) ==========

(aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
(DefWatch [Auto | Running]) – C:\Program Files\NavNT\defwatch.exe (Symantec Corporation)
(DSBrokerService [On_Demand | Stopped]) – C:\Program Files\DellSupport\brkrsvc.exe ()
(IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
(iPodService [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Computer, Inc.)
(JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
(NetSvc [On_Demand | Stopped]) – C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe (Intel® Corporation)
(Norton AntiVirus Server [Disabled | Stopped]) – C:\Program Files\NavNT\rtvscan.exe (Symantec Corporation)
(WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

(AliIde [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\ALIIDE.SYS (Acer Laboratories Inc.)
(amdagp [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\AMDAGP.SYS (Advanced Micro Devices, Inc.)
(asc [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\ASC.SYS (Advanced System Products, Inc.)
(asc3550 [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\ASC3550.SYS (Advanced System Products, Inc.)
(ASCTRM [Auto | Running]) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
(CmdIde [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\CMDIDE.SYS (CMD Technology, Inc.)
(dac2w2k [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\DAC2W2K.SYS (Mylex Corporation)
(drvmcdb [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\drvmcdb.sys (Sonic Solutions)
(drvnddm [Auto | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\drvnddm.sys (Sonic Solutions)
(DSproct [On_Demand | Running]) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
(dsunidrv [Auto | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
(E100B [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\e100b325.sys (Intel Corporation)
(GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
(ialm [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\ialmnt5.sys (Intel Corporation)
(IntelC51 [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC51.sys (Intel Corporation)
(IntelC52 [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC52.sys (Intel Corporation)
(IntelC53 [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC53.sys (Intel Corporation)
(MODEMCSA [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)
(mohfilt [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\mohfilt.sys (Intel Corporation)
(mraid35x [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\MRAID35X.SYS (American Megatrends Inc.)
(NAVAP [On_Demand | Stopped]) – C:\Program Files\NavNT\navap.sys ()
(NAVAPEL [Auto | Running]) – C:\Program Files\NavNT\Navapel.sys ()
(NAVENG [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20081231.003\NAVENG.SYS (Symantec Corporation)
(NAVEX15 [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20081231.003\NAVEX15.SYS (Symantec Corporation)
(nv [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\NV4_MINI.SYS (NVIDIA Corporation)
(Ptilink [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS (Parallel Technologies, Inc.)
(PxHelp20 [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\pxhelp20.sys (Sonic Solutions)
(ql1080 [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\QL1080.SYS (QLogic Corporation)
(ql12160 [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\QL12160.SYS (QLogic Corporation)
(ql1280 [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\QL1280.SYS (QLogic Corporation)
(rtl8139 [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\RTL8139.sys (Realtek Semiconductor Corporation)
(Secdrv [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(senfilt [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\senfilt.sys (Sensaura)
(sisagp [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\SISAGP.SYS (Silicon Integrated Systems Corporation)
(smwdm [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\smwdm.sys (Analog Devices, Inc.)
(Sparrow [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\SPARROW.SYS (Adaptec, Inc.)
(sscdbhk5 [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\sscdbhk5.sys (Sonic Solutions)
(ssrtln [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\ssrtln.sys (Sonic Solutions)
(symc810 [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\SYMC810.SYS (Symbios Logic Inc.)
(symc8xx [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\SYMC8XX.SYS (LSI Logic)
(SymEvent [On_Demand | Stopped]) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
(sym_hi [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\SYM_HI.SYS (LSI Logic)
(sym_u3 [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\SYM_U3.SYS (LSI Logic)
(tfsnboio [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnboio.sys (Sonic Solutions)
(tfsncofs [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsncofs.sys (Sonic Solutions)
(tfsndrct [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsndrct.sys (Sonic Solutions)
(tfsndres [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsndres.sys (Sonic Solutions)
(tfsnifs [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnifs.sys (Sonic Solutions)
(tfsnopio [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnopio.sys (Sonic Solutions)
(tfsnpool [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnpool.sys (Sonic Solutions)
(tfsnudf [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnudf.sys (Sonic Solutions)
(tfsnudfa [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnudfa.sys (Sonic Solutions)
(ultra [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\ULTRA.SYS (Promise Technology, Inc.)
(WS2IFSL [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS (Microsoft Corporation)

========== Standard Registry (All) ==========


========== Internet Explorer ==========

HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://refdesk.com/
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O1 HOSTS File: (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\SYSTEM32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\SYSTEM32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {1028F737-81E7-452B-A860-E50CAD90A08C} - Reg Error: Key does not exist or could not be opened. File not found
O4 - HKLM..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Computer, Inc.)
O4 - HKLM..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER (RealNetworks, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [StartLockspam] C:\Program Files\Polesoft\Lockspam_Pro\Lockspam.exe ()
O4 - HKLM..\Run: [StartOEhooker] C:\Program Files\Polesoft\Lockspam_Pro\Addins\oehooker.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r (Sonic Solutions)
O4 - HKLM..\Run: [vptray] C:\Program Files\NavNT\vptray.exe (Symantec Corporation)
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup (Gteko Ltd.)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" (Panicware, Inc.)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9 (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9 - Extra Button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\shdocvw.dll (Microsoft Corporation)
O9 - Extra Button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Sites: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} http://download.shockwave.com/pub/otoy/OTOYAX.cab (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://3dlifeplayer.dl.3dvia.com/player/in…l/installer.exe (Virtools WebPlayer Class)
O18 - Protocol\Handler: - about - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - cdl - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - cdo - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - dvd - C:\WINDOWS\SYSTEM32\MSVIDCTL.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - file - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ftp - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - gopher - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - http\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - https - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - https\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - https\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ipp - No CLSID value found
O18 - Protocol\Handler: - ipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - its - C:\WINDOWS\SYSTEM32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - javascript - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - local - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mailto - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mhtml - C:\WINDOWS\SYSTEM32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mk - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp - No CLSID value found
O18 - Protocol\Handler: - msdaipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ms-its - C:\WINDOWS\SYSTEM32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ms-itss - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - res - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - sysimage - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - tv - C:\WINDOWS\SYSTEM32\MSVIDCTL.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - vbscript - C:\WINDOWS\SYSTEM32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - wia - C:\WINDOWS\SYSTEM32\WIASCR.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\SYSTEM32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\SYSTEM32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\SYSTEM32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\SYSTEM32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\SYSTEM32\shell32.dll (Microsoft Corporation)
O20 - See sections below for AppInitDlls and Winlogon settings
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9}C:\WINDOWS\SYSTEM32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9}C:\WINDOWS\SYSTEM32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153}C:\WINDOWS\SYSTEM32\STOBJECT.DLL (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}C:\WINDOWS\SYSTEM32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5}C:\WINDOWS\SYSTEM32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: (Browseui preloader) - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\SYSTEM32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: (Component Categories cache daemon) - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\SYSTEM32\browseui.dll (Microsoft Corporation)

========== HKLM Winlogon Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell" = Explorer.exe
>C:\WINDOWS\explorer.exe (Microsoft Corporation)

"UserInit" = C:\WINDOWS\system32\userinit.exe,
>C:\WINDOWS\SYSTEM32\USERINIT.EXE (Microsoft Corporation)

"UIHost" = logonui.exe
>C:\WINDOWS\SYSTEM32\LOGONUI.EXE (Microsoft Corporation)

"VMApplet" = rundll32 shell32,Control_RunDLL "sysdm.cpl"
>C:\WINDOWS\SYSTEM32\shell32.dll (Microsoft Corporation)
>C:\WINDOWS\SYSTEM32\SYSDM.CPL (Microsoft Corporation)


========== Winlogon Notify Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
crypt32chain: "DllName" = crypt32.dll – C:\WINDOWS\SYSTEM32\CRYPT32.DLL (Microsoft Corporation)
cryptnet: "DllName" = cryptnet.dll – C:\WINDOWS\SYSTEM32\CRYPTNET.DLL (Microsoft Corporation)
cscdll: "DllName" = cscdll.dll – C:\WINDOWS\SYSTEM32\CSCDLL.DLL (Microsoft Corporation)
igfxcui: "DllName" = igfxdev.dll – C:\WINDOWS\SYSTEM32\igfxdev.dll (Intel Corporation)
NavLogon: "DllName" = C:\WINDOWS\system32\NavLogon.dll – C:\WINDOWS\SYSTEM32\NavLogon.dll ()
ScCertProp: "DllName" = wlnotify.dll – C:\WINDOWS\SYSTEM32\WLNOTIFY.DLL (Microsoft Corporation)
Schedule: "DllName" = wlnotify.dll – C:\WINDOWS\SYSTEM32\WLNOTIFY.DLL (Microsoft Corporation)
sclgntfy: "DllName" = sclgntfy.dll – C:\WINDOWS\SYSTEM32\SCLGNTFY.DLL (Microsoft Corporation)
SensLogn: "DllName" = WlNotify.dll – C:\WINDOWS\SYSTEM32\WLNOTIFY.DLL (Microsoft Corporation)
termsrv: "DllName" = wlnotify.dll – C:\WINDOWS\SYSTEM32\WLNOTIFY.DLL (Microsoft Corporation)
wlballoon: "DllName" = wlnotify.dll – C:\WINDOWS\SYSTEM32\WLNOTIFY.DLL (Microsoft Corporation)

========== IFEO "Debugger" Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\]
Your Image File Name Here without a path:"Debugger" = C:\WINDOWS\SYSTEM32\NTSD.EXE (Microsoft Corporation)

========== HKLM *SecurityProviders* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders" = msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
>C:\WINDOWS\SYSTEM32\MSAPSSPC.DLL (Microsoft Corporation)
>C:\WINDOWS\SYSTEM32\schannel.dll (Microsoft Corporation)
>C:\WINDOWS\SYSTEM32\DIGEST.DLL (Microsoft Corporation)
>C:\WINDOWS\SYSTEM32\MSNSSPC.DLL (Microsoft Corporation)

========== LSA *Authentication Packages* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages" = msv1_0,
>C:\WINDOWS\SYSTEM32\MSV1_0.DLL (Microsoft Corporation)

========== LSA *Security Packages* ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Security Packages" = kerberos,msv1_0,schannel,wdigest,
>C:\WINDOWS\SYSTEM32\kerberos.dll (Microsoft Corporation)
>C:\WINDOWS\SYSTEM32\MSV1_0.DLL (Microsoft Corporation)
>C:\WINDOWS\SYSTEM32\schannel.dll (Microsoft Corporation)
>C:\WINDOWS\SYSTEM32\wdigest.dll (Microsoft Corporation)

========== Safeboot Options ==========

"AlternateShell" = cmd.exe

========== CDRom AutoRun Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1

========== Autorun Files on Drives ==========

AUTOEXEC.BAT []
C:\AUTOEXEC.BAT () – [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[1 C:\*.tmp files]
[2009/01/04 15:19:23 | 00,000,000 | —D | C] – C:\_OTMoveIt
[2009/01/04 15:18:37 | 00,348,160 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Erminio Cardi\Desktop\OTMoveIt3.exe
[2009/01/04 14:06:35 | 00,420,864 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Erminio Cardi\Desktop\OTListIt2.exe
[2009/01/04 09:25:46 | 00,001,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2009/01/04 09:17:54 | 00,000,000 | —D | C] – C:\WINDOWS\pss
[2009/01/04 08:41:06 | 13,401,33376 | -HS- | C] () – C:\hiberfil.sys
[2009/01/03 12:33:18 | 00,000,000 | —D | C] – C:\WINDOWS\ERUNT
[2009/01/03 12:22:44 | 00,000,000 | —D | C] – C:\SDFix
[2009/01/03 12:22:23 | 01,529,241 | —- | C] () – C:\Documents and Settings\Erminio Cardi\Desktop\SDFix.exe
[2009/01/03 09:07:49 | 00,001,599 | —- | C] () – C:\Documents and Settings\Erminio Cardi\Desktop\Remote Assistance.lnk
[2009/01/02 21:19:53 | 00,000,000 | —D | C] – C:\VundoFix Backups
[2009/01/02 20:59:43 | 00,000,000 | —D | C] – C:\Documents and Settings\Erminio Cardi\Application Data\Malwarebytes
[2009/01/02 20:59:29 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/02 20:59:28 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/02 20:59:22 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/02 20:59:20 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/02 20:59:19 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/01/02 20:58:29 | 02,539,168 | —- | C] (Malwarebytes Corporation ) – C:\Program Files\mbam-setup.exe
[2009/01/02 20:47:04 | 00,001,734 | —- | C] () – C:\Documents and Settings\Erminio Cardi\Desktop\HijackThis.lnk
[2009/01/02 20:47:03 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/01/02 20:46:44 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Program Files\HJTInstall.exe
[2008/12/30 16:17:38 | 00,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[8 C:\WINDOWS\System32\*.tmp files]
[2009/01/04 15:23:06 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/01/04 15:23:04 | 00,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2009/01/04 15:23:03 | 13,401,33376 | -HS- | M] () – C:\hiberfil.sys
[2009/01/04 15:22:28 | 06,788,046 | -H– | M] () – C:\Documents and Settings\Erminio Cardi\Local Settings\Application Data\IconCache.db
[2009/01/04 15:18:40 | 00,348,160 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Erminio Cardi\Desktop\OTMoveIt3.exe
[2009/01/04 14:06:39 | 00,420,864 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Erminio Cardi\Desktop\OTListIt2.exe
[2009/01/04 09:25:48 | 00,000,507 | —- | M] () – C:\WINDOWS\WIN.INI
[2009/01/04 09:25:48 | 00,000,227 | —- | M] () – C:\WINDOWS\SYSTEM.INI
[2009/01/04 09:25:48 | 00,000,211 | RHS- | M] () – C:\BOOT.INI
[2009/01/04 08:33:40 | 00,000,686 | —- | M] () – C:\WINDOWS\System32\drivers\ETC\HOSTS
[2009/01/03 12:22:43 | 01,529,241 | —- | M] () – C:\Documents and Settings\Erminio Cardi\Desktop\SDFix.exe
[2009/01/02 20:59:29 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/02 20:47:04 | 00,001,734 | —- | M] () – C:\Documents and Settings\Erminio Cardi\Desktop\HijackThis.lnk
[2008/12/30 16:17:38 | 00,000,552 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2008/12/13 01:40:02 | 03,593,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.dll
[2008/12/13 01:40:02 | 03,593,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2008/12/10 22:11:25 | 00,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2008/12/09 18:24:37 | 17,593,280 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe

========== LOP Check ==========

[2009/01/02 20:59:20 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2007/11/26 10:53:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2005/01/01 10:39:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2006/04/08 13:29:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2004/12/23 16:06:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2008/02/02 11:52:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Dell
[2009/01/02 20:21:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2004/12/23 16:14:22 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2004/12/23 16:15:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2009/01/02 20:59:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2007/01/02 20:32:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2006/12/30 18:00:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall
[2005/02/15 21:26:46 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2005/01/01 10:52:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Polesoft
[2005/02/05 15:24:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2004/12/23 15:31:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2007/01/11 17:37:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2008/02/29 12:55:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/06/12 08:50:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/01/02 20:59:43 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Erminio Cardi\Application Data
[2008/01/09 10:48:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Adobe
[2008/02/07 09:46:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\AdobeUM
[2005/03/05 15:08:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Aim
[2006/10/06 18:48:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Apple Computer
[2005/03/06 22:37:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\CyberLink
[2007/09/23 13:32:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Google
[2007/04/12 15:16:08 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Gtek
[2008/08/16 06:43:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Identities
[2004/12/23 16:14:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Jasc Software Inc
[2005/01/01 10:43:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Lavasoft
[2005/03/06 15:46:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Macromedia
[2009/01/02 20:59:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Malwarebytes
[2005/01/21 18:30:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\McAfee.com
[2005/10/30 11:55:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\McAfee.com Personal Firewall
[2005/10/13 19:03:06 | 00,000,000 | –SD | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Microsoft
[2005/02/05 14:58:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Nikon
[2005/01/01 10:52:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Polesoft
[2004/12/23 16:21:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Sonic
[2004/12/23 16:04:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Sun
[2007/03/16 13:41:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Erminio Cardi\Application Data\Viewpoint
[2004/08/04 06:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\DESKTOP.INI
[2009/01/04 15:23:06 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

< End of report >

************

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI