This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Suspicious Registry Keys error messages on startup

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have recently got rid of vundo virus and now I am getting 4 error messages on start up. Each time I run Malwarebytes it picks up the same 4 keys and says it has successfully deleted them only for them to reappear the next time I start the PC up. I have looked for these files and cannot find them in the stated locations but I can find them if i run [regedit] and search through the registry keys.


These are the 4 files that Malwarebytes picks up each time and the ones that appear in the error messages on start up.

O4 - HKLM\..\Run: [Nduvugav] rundll32.exe "C:\WINDOWS\urifemey.dll",e
O4 - HKLM\..\Run: [Nfutuxekuv] rundll32.exe "C:\WINDOWS\Hqixapa.dll",e
O4 - HKLM\..\Run: [powukokela] Rundll32.exe "C:\WINDOWS\system32\viyutoni.dll",s
O4 - HKLM\..\Run: [58ea0404] rundll32.exe "C:\WINDOWS\system32\ibcaojvd.dll",b


I have posted my most recent log below. Just want advice on if it is safe to delete these 4 files.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:04:55, on 04/02/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Wireless-G PCI Adapter with RangeBooster\WLService.exe
C:\Program Files\Wireless-G PCI Adapter with RangeBooster\WMP54GR.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {49d5f1fd-bf20-40de-b9cb-3d934109414d} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {E845C02B-A6E2-4922-A1FE-A647A25942F6} - C:\WINDOWS\system32\tuvVLfFw.dll (file missing)
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [Nduvugav] rundll32.exe "C:\WINDOWS\urifemey.dll",e
O4 - HKLM\..\Run: [Nfutuxekuv] rundll32.exe "C:\WINDOWS\Hqixapa.dll",e
O4 - HKLM\..\Run: [powukokela] Rundll32.exe "C:\WINDOWS\system32\viyutoni.dll",s
O4 - HKLM\..\Run: [58ea0404] rundll32.exe "C:\WINDOWS\system32\ibcaojvd.dll",b
O4 - HKLM\..\RunOnce: [NSSInstallation] C:\WINDOWS\system32\Adobe\Shockwave 11\nssstub.exe /RunOnce
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: WIKI.DLL avgrsstx.dll wecegx.dll c:\windows\system32\ c:\windows\system32\tegawula.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: xxyYoNfd - xxyYoNfd.dll (file missing)
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WMP54GRSVC - GEMTEKS - C:\Program Files\Wireless-G PCI Adapter with RangeBooster\WLService.exe

–
End of file - 9263 bytes
hello

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
HI

I ran the program and once the scan had completed it only opened up 1 notepad window (OTListIt.Txt ).







OTListIt logfile created on: 05/02/2009 00:03:57 - Run 3
OTListIt2 by OldTimer - Version 2.0.0.5 Folder = C:\Documents and Settings\satnam\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18372)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1023.48 Mb Total Physical Memory | 454.01 Mb Available Physical Memory | 44.36% Memory free
2.40 Gb Paging File | 1.90 Gb Available in Paging File | 78.94% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 152.66 Gb Total Space | 117.16 Gb Free Space | 76.74% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: P-22BBV8YGR7VMK
Current User Name: satnam
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe (NVIDIA Corporation)
C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation)
C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
C:\Program Files\BroadJump\Client Foundation\CFD.exe ()
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA)
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA)
C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
C:\Program Files\Wireless-G PCI Adapter with RangeBooster\WLService.exe (GEMTEKS)
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe ()
C:\Program Files\Wireless-G PCI Adapter with RangeBooster\WMP54GR.exe (Linksys)
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
C:\WINDOWS\system32\wbem\unsecapp.exe (Microsoft Corporation)
C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation)
C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
C:\Documents and Settings\satnam\Desktop\OTListIt22.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ForceWare Intelligent Application Manager (IAM) [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe ()
SRV - (ForcewareWebInterface [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (hpqcxs08 [On_Demand | Running]) – C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (hpqddsvc [Auto | Running]) – C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (KService [Auto | Running]) – C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (nSvcIp [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA)
SRV - (nSvcLog [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (usnjsvc [On_Demand | Running]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WMP54GRSVC [Auto | Running]) – File not found
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (WudfSvc [Auto | Running]) – C:\WINDOWS\system32\WudfSvc.dll (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (asuskbnt [System | Running]) – C:\WINDOWS\system32\drivers\atkkbnt.sys (ASUSTeK COMPUTER INC.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (k750bus [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\k750bus.sys (MCCI)
DRV - (k750obex [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\k750obex.sys (MCCI)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\drivers\Lbd.sys (Lavasoft AB)
DRV - (ms_mpu401 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (MTsensor [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (nvata [Boot | Running]) – C:\WINDOWS\system32\drivers\nvata.sys (NVIDIA Corporation)
DRV - (NVENETFD [On_Demand | Running]) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVTCP [System | Running]) – C:\WINDOWS\system32\drivers\NVTCP.SYS (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (RT61 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\rt61.sys (Ralink Technology Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (StarOpen [System | Running]) – C:\WINDOWS\system32\drivers\StarOpen.sys ()
DRV - (V0080Dev [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\V0080Dev.sys (Creative Technology Ltd.)
DRV - (WS2IFSL [System | Running]) – C:\WINDOWS\system32\drivers\ws2ifsl.sys (Microsoft Corporation)

========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
IE - URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O1 HOSTS File: (292138 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10060 more lines…
O2 - BHO: (no name) - {49d5f1fd-bf20-40de-b9cb-3d934109414d} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O2 - BHO: (no name) - {E845C02B-A6E2-4922-A1FE-A647A25942F6} - C:\WINDOWS\system32\tuvVLfFw.dll File not found
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O4 - HKLM..\Run: [58ea0404] rundll32.exe "C:\WINDOWS\system32\ibcaojvd.dll",b File not found
O4 - HKLM..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe ()
O4 - HKLM..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [Nduvugav] rundll32.exe "C:\WINDOWS\urifemey.dll",e File not found
O4 - HKLM..\Run: [Nfutuxekuv] rundll32.exe "C:\WINDOWS\Hqixapa.dll",e File not found
O4 - HKLM..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install (NVIDIA Corporation)
O4 - HKLM..\Run: [powukokela] Rundll32.exe "C:\WINDOWS\system32\viyutoni.dll",s File not found
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKCU..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe" File not found
O4 - HKCU..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [Tcpip] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [NTDS] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [Network Location Awareness (NLA) Namespace] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: 89 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key does not exist or could not be opened.)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (WIKI.DLL) - File not found
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (wecegx.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\) - c:\WINDOWS\system32 [2009/01/31 12:38:23 00,000,000 | —D | M]
O20 - AppInit_DLLs: (c:\windows\system32\tegawula.dll) - c:\windows\system32\tegawula.dll File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\system32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\system32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\system32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\xxyYoNfd: DllName - xxyYoNfd.dll - File not found
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\Your Image File Name Here without a path: Debugger - C:\WINDOWS\system32\ntsd.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( schannel.dll) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( digest.dll) - C:\WINDOWS\system32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( msnsspc.dll) - C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\tuvVLfFw) - File not found
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\system32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\system32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[3 C:\WINDOWS\*.tmp files]
[2009/02/04 22:53:04 | 00,487,424 | —- | C] (OldTimer Tools) – C:\Documents and Settings\satnam\Desktop\OTListIt22.exe
[2009/02/04 22:05:24 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2009/02/01 19:13:29 | 00,000,000 | —D | C] – C:\Program Files\HijackThis
[2009/01/31 12:34:49 | 00,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2009/01/31 12:32:38 | 00,079,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/01/28 21:08:20 | 00,000,000 | —D | C] – C:\Documents and Settings\satnam\Local Settings\Application Data\TVU Networks
[2009/01/28 21:08:20 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TVU Networks
[2009/01/25 20:54:18 | 00,001,736 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Windows Live Messenger.lnk
[2009/01/25 20:54:16 | 00,000,000 | —D | C] – C:\Program Files\MSN Messenger
[2009/01/23 17:22:26 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/01/23 17:22:26 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/01/22 22:51:09 | 20,853,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/01/22 22:34:45 | 00,000,000 | —D | C] – C:\1b2a9624b4e5549ce91d3dd8
[2009/01/20 23:01:32 | 00,015,688 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2009/01/20 18:31:49 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/01/20 18:31:36 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/01/20 18:29:59 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/01/20 18:29:58 | 00,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/01/15 02:22:00 | 00,049,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll.mui
[2009/01/15 02:21:44 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe.mui
[2009/01/15 02:19:22 | 00,004,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe.mui
[2009/01/15 02:19:02 | 00,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll.mui
[2009/01/11 11:52:00 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2009/01/11 11:51:50 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Office Outlook Connector
[2009/01/11 11:50:58 | 03,426,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_32.dll
[2009/01/11 11:50:49 | 00,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2009/01/11 11:48:40 | 00,000,000 | —D | C] – C:\Program Files\Microsoft
[2009/01/11 11:48:29 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\microsoft
[2009/01/11 11:48:18 | 00,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2009/01/11 11:36:34 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2009/01/07 20:24:44 | 00,000,000 | —D | C] – C:\Documents and Settings\satnam\Application Data\Malwarebytes
[2009/01/07 20:24:41 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/07 20:24:41 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/07 20:24:39 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/07 20:24:38 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/01/07 20:24:38 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/07 20:23:35 | 00,251,392 | —- | C] () – C:\Documents and Settings\satnam\Desktop\hijackthis_sfx.exe
[2009/01/07 20:02:50 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qmgrprxy.dll
[2009/01/07 20:02:50 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bitsprx2.dll
[2009/01/07 20:02:50 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bitsprx4.dll
[2009/01/07 20:02:50 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bitsprx3.dll
[2009/01/07 20:02:50 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx4.dll
[2009/01/07 20:02:49 | 00,409,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qmgr.dll
[2009/01/06 21:17:57 | 00,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk

========== Files - Modified Within 30 Days ==========

[8 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/02/04 23:32:52 | 32,784,322 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/02/04 23:32:52 | 00,086,834 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/02/04 23:00:00 | 00,000,312 | —- | M] () – C:\WINDOWS\tasks\qxefzrnl.job
[2009/02/04 22:53:14 | 00,487,424 | —- | M] (OldTimer Tools) – C:\Documents and Settings\satnam\Desktop\OTListIt22.exe
[2009/02/04 22:51:31 | 00,002,137 | —- | M] () – C:\Documents and Settings\satnam\Desktop\iTunes.lnk
[2009/02/04 22:40:31 | 00,000,581 | —- | M] () – C:\Documents and Settings\satnam\My Documents\My Sharing Folders.lnk
[2009/02/04 22:38:05 | 00,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/04 22:37:41 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/02/04 22:37:32 | 00,026,682 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/02/04 22:37:24 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/04 22:37:19 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/04 22:35:38 | 04,840,154 | -H– | M] () – C:\Documents and Settings\satnam\Local Settings\Application Data\IconCache.db
[2009/02/04 16:41:29 | 00,292,138 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/02/01 21:27:41 | 00,002,497 | —- | M] () – C:\Documents and Settings\satnam\Desktop\Microsoft Office Word 2003.lnk
[2009/01/31 13:50:27 | 00,015,688 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2009/01/31 12:37:47 | 00,000,077 | -HS- | M] () – C:\Documents and Settings\satnam\My Documents\desktop.ini
[2009/01/31 12:35:37 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/01/29 20:16:18 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090204-164129.backup
[2009/01/29 20:16:09 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090129-201618.backup
[2009/01/28 18:52:34 | 00,325,128 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/01/28 18:52:34 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/01/28 18:52:34 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/01/28 18:52:29 | 00,107,272 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/01/27 18:31:06 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/01/25 20:54:18 | 00,001,736 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Windows Live Messenger.lnk
[2009/01/23 17:22:26 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/01/21 18:45:57 | 00,291,722 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090129-201609.backup
[2009/01/20 18:29:58 | 00,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/01/18 21:30:13 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/01/15 02:22:22 | 01,228,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieframe.dll.mui
[2009/01/15 02:22:22 | 01,228,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll.mui
[2009/01/15 02:22:00 | 00,049,152 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll.mui
[2009/01/15 02:21:44 | 00,002,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe.mui
[2009/01/15 02:19:22 | 00,010,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\advpack.dll.mui
[2009/01/15 02:19:22 | 00,004,096 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe.mui
[2009/01/15 02:19:02 | 00,081,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll.mui
[2009/01/15 02:17:22 | 00,636,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iexplore.exe
[2009/01/15 02:17:22 | 00,392,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll
[2009/01/15 02:17:22 | 00,392,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedkcs32.dll
[2009/01/15 02:13:18 | 05,888,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.dll
[2009/01/15 02:13:18 | 05,888,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2009/01/15 02:12:12 | 10,963,968 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieframe.dll
[2009/01/15 02:12:12 | 10,963,968 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2009/01/15 02:07:16 | 00,385,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\html.iec
[2009/01/15 02:06:48 | 01,182,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\urlmon.dll
[2009/01/15 02:06:48 | 01,182,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\urlmon.dll
[2009/01/15 02:06:44 | 01,467,392 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\inetcpl.cpl
[2009/01/15 02:06:44 | 01,467,392 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetcpl.cpl
[2009/01/15 02:06:22 | 00,208,384 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\WinFXDocObj.exe
[2009/01/15 02:06:08 | 00,236,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\webcheck.dll
[2009/01/15 02:06:08 | 00,236,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\webcheck.dll
[2009/01/15 02:06:00 | 00,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\url.dll
[2009/01/15 02:06:00 | 00,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\url.dll
[2009/01/15 02:05:42 | 00,911,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wininet.dll
[2009/01/15 02:05:42 | 00,911,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wininet.dll
[2009/01/15 02:05:34 | 00,193,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll
[2009/01/15 02:05:34 | 00,193,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msrating.dll
[2009/01/15 02:05:34 | 00,109,056 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\occache.dll
[2009/01/15 02:05:34 | 00,109,056 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\occache.dll
[2009/01/15 02:05:34 | 00,043,008 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\licmgr10.dll
[2009/01/15 02:05:34 | 00,043,008 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\licmgr10.dll
[2009/01/15 02:04:56 | 00,755,200 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\VGX.dll
[2009/01/15 02:04:28 | 00,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\corpol.dll
[2009/01/15 02:04:28 | 00,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\corpol.dll
[2009/01/15 02:04:16 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\jsproxy.dll
[2009/01/15 02:04:16 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsproxy.dll
[2009/01/15 02:03:58 | 00,724,992 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\jscript.dll
[2009/01/15 02:03:58 | 00,724,992 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jscript.dll
[2009/01/15 02:03:50 | 00,228,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieaksie.dll
[2009/01/15 02:03:50 | 00,228,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieaksie.dll
[2009/01/15 02:03:42 | 00,125,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieakeng.dll
[2009/01/15 02:03:42 | 00,125,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieakeng.dll
[2009/01/15 02:03:36 | 00,420,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\vbscript.dll
[2009/01/15 02:03:36 | 00,420,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\vbscript.dll
[2009/01/15 02:03:32 | 00,072,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admparse.dll
[2009/01/15 02:03:32 | 00,072,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\admparse.dll
[2009/01/15 02:03:28 | 00,172,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe
[2009/01/15 02:03:28 | 00,172,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ie4uinit.exe
[2009/01/15 02:03:20 | 00,163,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieakui.dll
[2009/01/15 02:03:20 | 00,163,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieakui.dll
[2009/01/15 02:03:18 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iesetup.dll
[2009/01/15 02:03:18 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iesetup.dll
[2009/01/15 02:03:18 | 00,036,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieudinit.exe
[2009/01/15 02:03:14 | 00,094,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\inseng.dll
[2009/01/15 02:03:14 | 00,094,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inseng.dll
[2009/01/15 02:03:14 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iernonce.dll
[2009/01/15 02:03:14 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iernonce.dll
[2009/01/15 02:03:12 | 00,128,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advpack.dll
[2009/01/15 02:03:12 | 00,128,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\advpack.dll
[2009/01/15 02:02:50 | 01,975,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iertutil.dll
[2009/01/15 02:02:50 | 01,975,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2009/01/15 02:02:40 | 00,593,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeeds.dll
[2009/01/15 02:02:40 | 00,593,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2009/01/15 02:02:20 | 00,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mstime.dll
[2009/01/15 02:02:20 | 00,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstime.dll
[2009/01/15 02:01:52 | 00,183,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iepeers.dll
[2009/01/15 02:01:52 | 00,183,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iepeers.dll
[2009/01/15 02:01:42 | 00,013,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeedssync.exe
[2009/01/15 02:01:40 | 00,059,904 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\icardie.dll
[2009/01/15 02:01:40 | 00,059,904 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icardie.dll
[2009/01/15 02:01:40 | 00,054,272 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeedsbs.dll
[2009/01/15 02:01:40 | 00,054,272 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2009/01/15 02:01:26 | 00,034,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\imgutil.dll
[2009/01/15 02:01:26 | 00,034,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imgutil.dll
[2009/01/15 02:01:22 | 00,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dxtmsft.dll
[2009/01/15 02:01:22 | 00,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dxtmsft.dll
[2009/01/15 02:01:18 | 00,046,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\pngfilt.dll
[2009/01/15 02:01:18 | 00,046,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pngfilt.dll
[2009/01/15 02:01:16 | 00,216,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dxtrans.dll
[2009/01/15 02:01:16 | 00,216,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dxtrans.dll
[2009/01/15 02:01:06 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtmled.dll
[2009/01/15 02:01:06 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmled.dll
[2009/01/15 02:00:46 | 00,048,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtmler.dll
[2009/01/15 02:00:46 | 00,048,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmler.dll
[2009/01/15 02:00:40 | 01,639,936 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.tlb
[2009/01/15 02:00:40 | 01,639,936 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.tlb
[2009/01/15 02:00:38 | 00,045,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe
[2009/01/15 02:00:38 | 00,045,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshta.exe
[2009/01/15 02:00:36 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tdc.ocx
[2009/01/15 02:00:36 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdc.ocx
[2009/01/15 01:53:40 | 00,068,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hmmapi.dll
[2009/01/15 01:50:50 | 00,164,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieui.dll
[2009/01/15 01:50:38 | 00,156,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msls31.dll
[2009/01/15 01:50:38 | 00,156,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msls31.dll
[2009/01/15 01:39:06 | 00,057,667 | —- | M] () – C:\WINDOWS\System32\ieuinit.inf
[2009/01/15 01:35:10 | 00,445,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieapfltr.dll
[2009/01/15 01:35:10 | 00,445,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieapfltr.dll
[2009/01/14 17:00:24 | 00,291,222 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090121-184557.backup
[2009/01/14 16:11:32 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/14 16:11:28 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/12 19:48:59 | 00,205,712 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/12 17:47:54 | 00,045,624 | —- | M] () – C:\Documents and Settings\satnam\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/01/11 12:08:07 | 00,456,008 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/01/11 12:08:07 | 00,391,606 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/01/11 12:08:07 | 00,057,896 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/01/11 05:00:34 | 00,079,360 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/01/09 17:35:30 | 20,853,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/01/07 21:44:37 | 00,006,456 | -H– | M] () – C:\WINDOWS\System32\fabovaye
[2009/01/07 20:24:41 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/07 20:23:36 | 00,251,392 | —- | M] () – C:\Documents and Settings\satnam\Desktop\hijackthis_sfx.exe
[2009/01/07 13:58:10 | 00,290,772 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.msn
[2009/01/07 13:58:10 | 00,290,772 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090114-170024.backup
[2009/01/06 22:20:30 | 00,290,793 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090107-135810.backup
[2009/01/06 22:16:29 | 00,000,153 | —- | M] () – C:\WINDOWS\wininit.ini
[2009/01/06 21:17:57 | 00,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk

========== LOP Check ==========

[2009/01/28 21:08:20 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/01/20 18:29:59 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2007/05/15 21:09:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/05/12 18:39:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/01/28 18:47:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2008/12/20 17:43:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DFX
[2007/07/16 16:46:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2007/11/15 21:25:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2007/11/15 21:26:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2007/11/15 21:26:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
[2009/02/05 00:03:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2008/07/17 17:15:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/01/07 20:24:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/22 22:59:38 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/05/07 14:02:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2009/01/05 21:44:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/01/28 21:08:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TVU Networks
[2007/11/15 21:30:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WEBREG
[2007/06/23 16:11:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/02/26 19:34:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WLInstaller
[2009/01/22 22:59:38 | 00,000,000 | RH-D | M] – C:\Documents and Settings\satnam\Application Data
[2008/12/21 19:48:27 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Adobe
[2007/05/15 21:09:14 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\AdobeAUM
[2007/05/19 21:19:44 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\AdobeUM
[2007/07/02 13:09:56 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Apple Computer
[2009/01/04 23:55:08 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\AVGTOOLBAR
[2008/04/01 19:00:03 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\BitTorrent
[2007/10/27 10:21:25 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Creative
[2008/08/02 19:08:56 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\DivX
[2008/07/15 21:03:33 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\DNA
[2008/02/10 20:53:46 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Google
[2007/06/23 21:07:03 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Help
[2007/11/15 21:38:22 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\HP
[2007/05/07 13:35:08 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Identities
[2007/05/12 17:11:07 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Lavasoft
[2007/05/13 15:40:27 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Leadertech
[2008/04/19 15:39:53 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\LimeWire
[2007/05/07 15:55:11 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Macromedia
[2009/01/07 20:24:44 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Malwarebytes
[2009/01/07 20:05:29 | 00,000,000 | –SD | M] – C:\Documents and Settings\satnam\Application Data\Microsoft
[2009/01/06 21:19:12 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Mozilla
[2007/05/07 14:53:19 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\MSN6
[2007/06/23 16:22:13 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\NetMedia Providers
[2007/06/23 16:22:12 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Publish Providers
[2007/05/09 16:58:15 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Real
[2009/01/06 21:47:28 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Samsung
[2007/10/19 16:53:04 | 00,000,000 | RH-D | M] – C:\Documents and Settings\satnam\Application Data\SecuROM
[2007/06/23 16:22:07 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Sonic Foundry
[2007/10/19 16:53:15 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Sports Interactive
[2007/05/29 20:52:16 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Sun
[2009/01/27 18:31:06 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2002/08/29 14:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/02/04 23:00:00 | 00,000,312 | —- | M] () – C:\WINDOWS\Tasks\qxefzrnl.job
[2009/02/04 22:37:24 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

< End of report >
hello

Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :Processes
    explorer.exe
    AAWService.exe
    TeaTimer.exe
    
    :OTLI
    O2 - BHO: (no name) - {49d5f1fd-bf20-40de-b9cb-3d934109414d} - Reg Error: Key does not exist or could not be opened. File not found
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key does not exist or could not be opened. File not found
    O2 - BHO: (no name) - {E845C02B-A6E2-4922-A1FE-A647A25942F6} - C:\WINDOWS\system32\tuvVLfFw.dll File not found
    O4 - HKLM..\Run: [58ea0404] rundll32.exe "C:\WINDOWS\system32\ibcaojvd.dll",b File not found
    O4 - HKLM..\Run: [Nduvugav] rundll32.exe "C:\WINDOWS\urifemey.dll",e File not found
    O4 - HKLM..\Run: [Nfutuxekuv] rundll32.exe "C:\WINDOWS\Hqixapa.dll",e File not found
    O4 - HKLM..\Run: [powukokela] Rundll32.exe "C:\WINDOWS\system32\viyutoni.dll",s File not found
    O20 - AppInit_DLLs: (WIKI.DLL) - File not found
    O20 - AppInit_DLLs: (wecegx.dll) - File not found
    O20 - AppInit_DLLs: (c:\windows\system32\tegawula.dll) - c:\windows\system32\tegawula.dll File not found
    O20 - Winlogon\Notify\xxyYoNfd: DllName - xxyYoNfd.dll - File not found
    O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\tuvVLfFw) - File not found
    [3 C:\WINDOWS\*.tmp files]
    [8 C:\WINDOWS\System32\*.tmp files]
    [3 C:\WINDOWS\*.tmp files]
    [2009/02/04 23:00:00 | 00,000,312 | —- | M] () – C:\WINDOWS\Tasks\qxefzrnl.job
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )
try it in safe mode, if it fails just do this

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
I ran it in safe mode and it still crashed at the same point. I also downloaded the program again and it only gave me one notepad window.
This is the OTListIT.Txt file produced after running the program agian.
OTListIt logfile created on: 05/02/2009 18:52:54 - Run 19
OTListIt2 by OldTimer - Version 2.0.0.5 Folder = C:\Documents and Settings\satnam\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18372)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1023.48 Mb Total Physical Memory | 461.71 Mb Available Physical Memory | 45.11% Memory free
2.40 Gb Paging File | 1.94 Gb Available in Paging File | 80.77% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 152.66 Gb Total Space | 117.14 Gb Free Space | 76.73% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: P-22BBV8YGR7VMK
Current User Name: satnam
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe (NVIDIA Corporation)
C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation)
C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
C:\Program Files\Creative\Shared Files\CamTray.exe (Creative Technology Ltd)
C:\Program Files\BroadJump\Client Foundation\CFD.exe ()
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA)
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA)
C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
C:\Program Files\Wireless-G PCI Adapter with RangeBooster\WLService.exe (GEMTEKS)
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe ()
C:\Program Files\Wireless-G PCI Adapter with RangeBooster\WMP54GR.exe (Linksys)
C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
C:\WINDOWS\system32\wbem\unsecapp.exe (Microsoft Corporation)
C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.)
C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
C:\Documents and Settings\satnam\Desktop\OTListIt22(2).exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ForceWare Intelligent Application Manager (IAM) [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe ()
SRV - (ForcewareWebInterface [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (hpqcxs08 [On_Demand | Running]) – C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (hpqddsvc [Auto | Running]) – C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (KService [Auto | Running]) – C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (nSvcIp [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA)
SRV - (nSvcLog [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (usnjsvc [On_Demand | Running]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WMP54GRSVC [Auto | Running]) – File not found
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (WudfSvc [Auto | Running]) – C:\WINDOWS\system32\WudfSvc.dll (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (asuskbnt [System | Running]) – C:\WINDOWS\system32\drivers\atkkbnt.sys (ASUSTeK COMPUTER INC.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (k750bus [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\k750bus.sys (MCCI)
DRV - (k750obex [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\k750obex.sys (MCCI)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\drivers\Lbd.sys (Lavasoft AB)
DRV - (ms_mpu401 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (MTsensor [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (nvata [Boot | Running]) – C:\WINDOWS\system32\drivers\nvata.sys (NVIDIA Corporation)
DRV - (NVENETFD [On_Demand | Running]) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVTCP [System | Running]) – C:\WINDOWS\system32\drivers\NVTCP.SYS (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (RT61 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\rt61.sys (Ralink Technology Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (StarOpen [System | Running]) – C:\WINDOWS\system32\drivers\StarOpen.sys ()
DRV - (V0080Dev [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\V0080Dev.sys (Creative Technology Ltd.)
DRV - (WS2IFSL [System | Running]) – C:\WINDOWS\system32\drivers\ws2ifsl.sys (Microsoft Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
IE - URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O1 HOSTS File: (292138 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10060 more lines…
O2 - BHO: (no name) - {49d5f1fd-bf20-40de-b9cb-3d934109414d} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O2 - BHO: (no name) - {E845C02B-A6E2-4922-A1FE-A647A25942F6} - C:\WINDOWS\system32\tuvVLfFw.dll File not found
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O4 - HKLM..\Run: [58ea0404] rundll32.exe "C:\WINDOWS\system32\ibcaojvd.dll",b File not found
O4 - HKLM..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe ()
O4 - HKLM..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [Nduvugav] rundll32.exe "C:\WINDOWS\urifemey.dll",e File not found
O4 - HKLM..\Run: [Nfutuxekuv] rundll32.exe "C:\WINDOWS\Hqixapa.dll",e File not found
O4 - HKLM..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install (NVIDIA Corporation)
O4 - HKLM..\Run: [powukokela] Rundll32.exe "C:\WINDOWS\system32\viyutoni.dll",s File not found
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKCU..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe" File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: 89 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key does not exist or could not be opened.)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (WIKI.DLL) - File not found
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (wecegx.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\) - c:\WINDOWS\system32 [2009/01/31 12:38:23 00,000,000 | —D | M]
O20 - AppInit_DLLs: (c:\windows\system32\tegawula.dll) - c:\windows\system32\tegawula.dll File not found
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\xxyYoNfd: DllName - xxyYoNfd.dll - File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\tuvVLfFw) - File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[3 C:\WINDOWS\*.tmp files]
[2009/02/05 18:51:01 | 00,487,424 | —- | C] (OldTimer Tools) – C:\Documents and Settings\satnam\Desktop\OTListIt22(2).exe
[2009/02/05 10:13:05 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/02/01 19:13:29 | 00,000,000 | —D | C] – C:\Program Files\HijackThis
[2009/01/31 12:34:49 | 00,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2009/01/31 12:32:38 | 00,079,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/01/28 21:08:20 | 00,000,000 | —D | C] – C:\Documents and Settings\satnam\Local Settings\Application Data\TVU Networks
[2009/01/28 21:08:20 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TVU Networks
[2009/01/25 20:54:18 | 00,001,736 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Windows Live Messenger.lnk
[2009/01/25 20:54:16 | 00,000,000 | —D | C] – C:\Program Files\MSN Messenger
[2009/01/23 17:22:26 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/01/23 17:22:26 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/01/22 22:51:09 | 20,853,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/01/22 22:34:45 | 00,000,000 | —D | C] – C:\1b2a9624b4e5549ce91d3dd8
[2009/01/20 23:01:32 | 00,015,688 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2009/01/20 18:31:49 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/01/20 18:31:36 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/01/20 18:29:59 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/01/20 18:29:58 | 00,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/01/15 02:22:00 | 00,049,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll.mui
[2009/01/15 02:21:44 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe.mui
[2009/01/15 02:19:22 | 00,004,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe.mui
[2009/01/15 02:19:02 | 00,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll.mui
[2009/01/11 11:52:00 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2009/01/11 11:51:50 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Office Outlook Connector
[2009/01/11 11:50:58 | 03,426,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_32.dll
[2009/01/11 11:50:49 | 00,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2009/01/11 11:48:40 | 00,000,000 | —D | C] – C:\Program Files\Microsoft
[2009/01/11 11:48:29 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\microsoft
[2009/01/11 11:48:18 | 00,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2009/01/11 11:36:34 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2009/01/07 20:24:44 | 00,000,000 | —D | C] – C:\Documents and Settings\satnam\Application Data\Malwarebytes
[2009/01/07 20:24:41 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/07 20:24:41 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/07 20:24:39 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/07 20:24:38 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/01/07 20:24:38 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/07 20:23:35 | 00,251,392 | —- | C] () – C:\Documents and Settings\satnam\Desktop\hijackthis_sfx.exe
[2009/01/07 20:02:50 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qmgrprxy.dll
[2009/01/07 20:02:50 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bitsprx2.dll
[2009/01/07 20:02:50 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bitsprx4.dll
[2009/01/07 20:02:50 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bitsprx3.dll
[2009/01/07 20:02:50 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx4.dll
[2009/01/07 20:02:49 | 00,409,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qmgr.dll
[2009/01/06 21:17:57 | 00,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk

========== Files - Modified Within 30 Days ==========

[8 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/02/05 18:51:15 | 00,487,424 | —- | M] (OldTimer Tools) – C:\Documents and Settings\satnam\Desktop\OTListIt22(2).exe
[2009/02/05 18:40:07 | 00,000,581 | —- | M] () – C:\Documents and Settings\satnam\My Documents\My Sharing Folders.lnk
[2009/02/05 18:39:09 | 00,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/05 18:38:39 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/02/05 18:38:27 | 00,026,682 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/02/05 18:38:14 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/05 18:38:08 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/05 18:37:25 | 03,712,656 | -H– | M] () – C:\Documents and Settings\satnam\Local Settings\Application Data\IconCache.db
[2009/02/05 18:15:06 | 00,002,497 | —- | M] () – C:\Documents and Settings\satnam\Desktop\Microsoft Office Word 2003.lnk
[2009/02/05 18:00:11 | 00,000,312 | —- | M] () – C:\WINDOWS\tasks\qxefzrnl.job
[2009/02/04 23:32:52 | 32,784,322 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/02/04 23:32:52 | 00,086,834 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/02/04 22:51:31 | 00,002,137 | —- | M] () – C:\Documents and Settings\satnam\Desktop\iTunes.lnk
[2009/02/04 16:41:29 | 00,292,138 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/01/31 13:50:27 | 00,015,688 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2009/01/31 12:37:47 | 00,000,077 | -HS- | M] () – C:\Documents and Settings\satnam\My Documents\desktop.ini
[2009/01/31 12:35:37 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/01/29 20:16:18 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090204-164129.backup
[2009/01/29 20:16:09 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090129-201618.backup
[2009/01/28 18:52:34 | 00,325,128 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/01/28 18:52:34 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/01/28 18:52:34 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/01/28 18:52:29 | 00,107,272 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/01/27 18:31:06 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/01/25 20:54:18 | 00,001,736 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Windows Live Messenger.lnk
[2009/01/23 17:22:26 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/01/21 18:45:57 | 00,291,722 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090129-201609.backup
[2009/01/20 18:29:58 | 00,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/01/18 21:30:13 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/01/15 02:22:22 | 01,228,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieframe.dll.mui
[2009/01/15 02:22:22 | 01,228,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll.mui
[2009/01/15 02:22:00 | 00,049,152 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll.mui
[2009/01/15 02:21:44 | 00,002,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe.mui
[2009/01/15 02:19:22 | 00,010,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\advpack.dll.mui
[2009/01/15 02:19:22 | 00,004,096 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe.mui
[2009/01/15 02:19:02 | 00,081,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll.mui
[2009/01/15 02:17:22 | 00,636,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iexplore.exe
[2009/01/15 02:17:22 | 00,392,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll
[2009/01/15 02:17:22 | 00,392,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedkcs32.dll
[2009/01/15 02:13:18 | 05,888,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.dll
[2009/01/15 02:13:18 | 05,888,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2009/01/15 02:12:12 | 10,963,968 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieframe.dll
[2009/01/15 02:12:12 | 10,963,968 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2009/01/15 02:07:16 | 00,385,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\html.iec
[2009/01/15 02:06:48 | 01,182,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\urlmon.dll
[2009/01/15 02:06:48 | 01,182,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\urlmon.dll
[2009/01/15 02:06:44 | 01,467,392 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\inetcpl.cpl
[2009/01/15 02:06:44 | 01,467,392 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetcpl.cpl
[2009/01/15 02:06:22 | 00,208,384 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\WinFXDocObj.exe
[2009/01/15 02:06:08 | 00,236,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\webcheck.dll
[2009/01/15 02:06:08 | 00,236,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\webcheck.dll
[2009/01/15 02:06:00 | 00,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\url.dll
[2009/01/15 02:06:00 | 00,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\url.dll
[2009/01/15 02:05:42 | 00,911,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wininet.dll
[2009/01/15 02:05:42 | 00,911,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wininet.dll
[2009/01/15 02:05:34 | 00,193,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll
[2009/01/15 02:05:34 | 00,193,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msrating.dll
[2009/01/15 02:05:34 | 00,109,056 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\occache.dll
[2009/01/15 02:05:34 | 00,109,056 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\occache.dll
[2009/01/15 02:05:34 | 00,043,008 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\licmgr10.dll
[2009/01/15 02:05:34 | 00,043,008 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\licmgr10.dll
[2009/01/15 02:04:56 | 00,755,200 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\VGX.dll
[2009/01/15 02:04:28 | 00,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\corpol.dll
[2009/01/15 02:04:28 | 00,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\corpol.dll
[2009/01/15 02:04:16 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\jsproxy.dll
[2009/01/15 02:04:16 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsproxy.dll
[2009/01/15 02:03:58 | 00,724,992 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\jscript.dll
[2009/01/15 02:03:58 | 00,724,992 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jscript.dll
[2009/01/15 02:03:50 | 00,228,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieaksie.dll
[2009/01/15 02:03:50 | 00,228,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieaksie.dll
[2009/01/15 02:03:42 | 00,125,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieakeng.dll
[2009/01/15 02:03:42 | 00,125,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieakeng.dll
[2009/01/15 02:03:36 | 00,420,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\vbscript.dll
[2009/01/15 02:03:36 | 00,420,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\vbscript.dll
[2009/01/15 02:03:32 | 00,072,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admparse.dll
[2009/01/15 02:03:32 | 00,072,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\admparse.dll
[2009/01/15 02:03:28 | 00,172,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe
[2009/01/15 02:03:28 | 00,172,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ie4uinit.exe
[2009/01/15 02:03:20 | 00,163,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieakui.dll
[2009/01/15 02:03:20 | 00,163,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieakui.dll
[2009/01/15 02:03:18 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iesetup.dll
[2009/01/15 02:03:18 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iesetup.dll
[2009/01/15 02:03:18 | 00,036,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieudinit.exe
[2009/01/15 02:03:14 | 00,094,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\inseng.dll
[2009/01/15 02:03:14 | 00,094,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inseng.dll
[2009/01/15 02:03:14 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iernonce.dll
[2009/01/15 02:03:14 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iernonce.dll
[2009/01/15 02:03:12 | 00,128,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advpack.dll
[2009/01/15 02:03:12 | 00,128,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\advpack.dll
[2009/01/15 02:02:50 | 01,975,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iertutil.dll
[2009/01/15 02:02:50 | 01,975,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2009/01/15 02:02:40 | 00,593,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeeds.dll
[2009/01/15 02:02:40 | 00,593,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2009/01/15 02:02:20 | 00,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mstime.dll
[2009/01/15 02:02:20 | 00,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstime.dll
[2009/01/15 02:01:52 | 00,183,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iepeers.dll
[2009/01/15 02:01:52 | 00,183,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iepeers.dll
[2009/01/15 02:01:42 | 00,013,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeedssync.exe
[2009/01/15 02:01:40 | 00,059,904 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\icardie.dll
[2009/01/15 02:01:40 | 00,059,904 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icardie.dll
[2009/01/15 02:01:40 | 00,054,272 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeedsbs.dll
[2009/01/15 02:01:40 | 00,054,272 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2009/01/15 02:01:26 | 00,034,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\imgutil.dll
[2009/01/15 02:01:26 | 00,034,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imgutil.dll
[2009/01/15 02:01:22 | 00,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dxtmsft.dll
[2009/01/15 02:01:22 | 00,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dxtmsft.dll
[2009/01/15 02:01:18 | 00,046,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\pngfilt.dll
[2009/01/15 02:01:18 | 00,046,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pngfilt.dll
[2009/01/15 02:01:16 | 00,216,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dxtrans.dll
[2009/01/15 02:01:16 | 00,216,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dxtrans.dll
[2009/01/15 02:01:06 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtmled.dll
[2009/01/15 02:01:06 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmled.dll
[2009/01/15 02:00:46 | 00,048,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtmler.dll
[2009/01/15 02:00:46 | 00,048,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmler.dll
[2009/01/15 02:00:40 | 01,639,936 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.tlb
[2009/01/15 02:00:40 | 01,639,936 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.tlb
[2009/01/15 02:00:38 | 00,045,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe
[2009/01/15 02:00:38 | 00,045,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshta.exe
[2009/01/15 02:00:36 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tdc.ocx
[2009/01/15 02:00:36 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdc.ocx
[2009/01/15 01:53:40 | 00,068,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hmmapi.dll
[2009/01/15 01:50:50 | 00,164,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieui.dll
[2009/01/15 01:50:38 | 00,156,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msls31.dll
[2009/01/15 01:50:38 | 00,156,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msls31.dll
[2009/01/15 01:39:06 | 00,057,667 | —- | M] () – C:\WINDOWS\System32\ieuinit.inf
[2009/01/15 01:35:10 | 00,445,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieapfltr.dll
[2009/01/15 01:35:10 | 00,445,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieapfltr.dll
[2009/01/14 17:00:24 | 00,291,222 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090121-184557.backup
[2009/01/14 16:11:32 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/14 16:11:28 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/12 19:48:59 | 00,205,712 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/12 17:47:54 | 00,045,624 | —- | M] () – C:\Documents and Settings\satnam\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/01/11 12:08:07 | 00,456,008 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/01/11 12:08:07 | 00,391,606 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/01/11 12:08:07 | 00,057,896 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/01/11 05:00:34 | 00,079,360 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/01/09 17:35:30 | 20,853,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/01/07 21:44:37 | 00,006,456 | -H– | M] () – C:\WINDOWS\System32\fabovaye
[2009/01/07 20:24:41 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/07 20:23:36 | 00,251,392 | —- | M] () – C:\Documents and Settings\satnam\Desktop\hijackthis_sfx.exe
[2009/01/07 13:58:10 | 00,290,772 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.msn
[2009/01/07 13:58:10 | 00,290,772 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090114-170024.backup
[2009/01/06 22:20:30 | 00,290,793 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090107-135810.backup
[2009/01/06 22:16:29 | 00,000,153 | —- | M] () – C:\WINDOWS\wininit.ini
[2009/01/06 21:17:57 | 00,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk

========== LOP Check ==========

[2009/01/28 21:08:20 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/01/20 18:29:59 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2007/05/15 21:09:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/05/12 18:39:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/01/28 18:47:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2008/12/20 17:43:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DFX
[2007/07/16 16:46:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2007/11/15 21:25:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2007/11/15 21:26:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2007/11/15 21:26:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
[2009/02/05 18:53:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2008/07/17 17:15:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/01/07 20:24:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/22 22:59:38 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/05/07 14:02:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2009/01/05 21:44:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/01/28 21:08:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TVU Networks
[2007/11/15 21:30:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WEBREG
[2007/06/23 16:11:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/02/26 19:34:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WLInstaller
[2009/02/05 18:46:34 | 00,000,000 | RH-D | M] – C:\Documents and Settings\satnam\Application Data
[2008/12/21 19:48:27 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Adobe
[2007/05/15 21:09:14 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\AdobeAUM
[2007/05/19 21:19:44 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\AdobeUM
[2007/07/02 13:09:56 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Apple Computer
[2009/02/05 18:46:54 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\AVGTOOLBAR
[2008/04/01 19:00:03 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\BitTorrent
[2007/10/27 10:21:25 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Creative
[2008/08/02 19:08:56 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\DivX
[2008/07/15 21:03:33 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\DNA
[2008/02/10 20:53:46 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Google
[2007/06/23 21:07:03 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Help
[2007/11/15 21:38:22 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\HP
[2007/05/07 13:35:08 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Identities
[2007/05/12 17:11:07 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Lavasoft
[2007/05/13 15:40:27 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Leadertech
[2007/05/07 15:55:11 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Macromedia
[2009/01/07 20:24:44 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Malwarebytes
[2009/01/07 20:05:29 | 00,000,000 | –SD | M] – C:\Documents and Settings\satnam\Application Data\Microsoft
[2009/01/06 21:19:12 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Mozilla
[2007/05/07 14:53:19 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\MSN6
[2007/06/23 16:22:13 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\NetMedia Providers
[2007/06/23 16:22:12 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Publish Providers
[2007/05/09 16:58:15 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Real
[2009/01/06 21:47:28 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Samsung
[2007/10/19 16:53:04 | 00,000,000 | RH-D | M] – C:\Documents and Settings\satnam\Application Data\SecuROM
[2007/06/23 16:22:07 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Sonic Foundry
[2007/10/19 16:53:15 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Sports Interactive
[2007/05/29 20:52:16 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Sun
[2009/01/27 18:31:06 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2002/08/29 14:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/02/05 18:00:11 | 00,000,312 | —- | M] () – C:\WINDOWS\Tasks\qxefzrnl.job
[2009/02/05 18:38:14 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

< End of report >
hello


Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    O2 - BHO: (no name) - {49d5f1fd-bf20-40de-b9cb-3d934109414d} - Reg Error: Key does not exist or could not be opened. File not found
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key does not exist or could not be opened. File not found
    O2 - BHO: (no name) - {E845C02B-A6E2-4922-A1FE-A647A25942F6} - C:\WINDOWS\system32\tuvVLfFw.dll File not found
    O4 - HKLM..\Run: [58ea0404] rundll32.exe "C:\WINDOWS\system32\ibcaojvd.dll",b File not found
    O4 - HKLM..\Run: [Nduvugav] rundll32.exe "C:\WINDOWS\urifemey.dll",e File not found
    O4 - HKLM..\Run: [Nfutuxekuv] rundll32.exe "C:\WINDOWS\Hqixapa.dll",e File not found
    O4 - HKLM..\Run: [powukokela] Rundll32.exe "C:\WINDOWS\system32\viyutoni.dll",s File not found
    O20 - AppInit_DLLs: (WIKI.DLL) - File not found
    O20 - AppInit_DLLs: (wecegx.dll) - File not found
    O20 - AppInit_DLLs: (c:\windows\system32\tegawula.dll) - c:\windows\system32\tegawula.dll File not found
    O20 - Winlogon\Notify\xxyYoNfd: DllName - xxyYoNfd.dll - File not found
    O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\tuvVLfFw) - File not found
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )
HI this is the log after running the run fix. ========== OTLISTIT ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{49d5f1fd-bf20-40de-b9cb-3d934109414d}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E845C02B-A6E2-4922-A1FE-A647A25942F6}\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\58ea0404 deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Nduvugav deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Nfutuxekuv deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\powukokela deleted successfully. Registry value \SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:WIKI.DLL deleted successfully. Registry value \SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:wecegx.dll deleted successfully. Registry value \SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\tegawula.dll deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\\xxyYoNfd not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages:C:\WINDOWS\system32\tuvVLfFw deleted successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_158.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_1a4.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTListIt2 by OldTimer - Version 2.0.0.5 log created on 02052009_210519 Files moved on Reboot… File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File C:\WINDOWS\temp\Perflib_Perfdata_158.dat not found! File C:\WINDOWS\temp\Perflib_Perfdata_1a4.dat not found! Registry entries deleted on Reboot…
OTListIt logfile created on: 05/02/2009 22:02:49 - Run 23
OTListIt2 by OldTimer - Version 2.0.0.5 Folder = C:\Documents and Settings\satnam\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18372)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1023.48 Mb Total Physical Memory | 452.79 Mb Available Physical Memory | 44.24% Memory free
2.40 Gb Paging File | 1.95 Gb Available in Paging File | 81.25% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 152.66 Gb Total Space | 117.19 Gb Free Space | 76.77% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: P-22BBV8YGR7VMK
Current User Name: satnam
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA)
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA)
C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
C:\Program Files\Wireless-G PCI Adapter with RangeBooster\WLService.exe (GEMTEKS)
C:\Program Files\Wireless-G PCI Adapter with RangeBooster\WMP54GR.exe (Linksys)
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe ()
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
C:\WINDOWS\system32\wbem\unsecapp.exe (Microsoft Corporation)
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe (NVIDIA Corporation)
C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation)
C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
C:\Program Files\Creative\Shared Files\CamTray.exe (Creative Technology Ltd)
C:\Program Files\BroadJump\Client Foundation\CFD.exe ()
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.)
C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation)
C:\Documents and Settings\satnam\Desktop\OTListIt22(2).exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ForceWare Intelligent Application Manager (IAM) [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe ()
SRV - (ForcewareWebInterface [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (hpqcxs08 [On_Demand | Running]) – C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (hpqddsvc [Auto | Running]) – C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (KService [Auto | Running]) – C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (nSvcIp [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA)
SRV - (nSvcLog [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WMP54GRSVC [Auto | Running]) – File not found
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (WudfSvc [Auto | Running]) – C:\WINDOWS\system32\WudfSvc.dll (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (asuskbnt [System | Running]) – C:\WINDOWS\system32\drivers\atkkbnt.sys (ASUSTeK COMPUTER INC.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (k750bus [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\k750bus.sys (MCCI)
DRV - (k750obex [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\k750obex.sys (MCCI)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\drivers\Lbd.sys (Lavasoft AB)
DRV - (ms_mpu401 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (MTsensor [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (nvata [Boot | Running]) – C:\WINDOWS\system32\drivers\nvata.sys (NVIDIA Corporation)
DRV - (NVENETFD [On_Demand | Running]) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVTCP [System | Running]) – C:\WINDOWS\system32\drivers\NVTCP.SYS (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (RT61 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\rt61.sys (Ralink Technology Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (StarOpen [System | Running]) – C:\WINDOWS\system32\drivers\StarOpen.sys ()
DRV - (V0080Dev [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\V0080Dev.sys (Creative Technology Ltd.)
DRV - (WS2IFSL [System | Running]) – C:\WINDOWS\system32\drivers\ws2ifsl.sys (Microsoft Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
IE - URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O1 HOSTS File: (292138 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10060 more lines…
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O4 - HKLM..\Run: [58ea0404] rundll32.exe "C:\WINDOWS\system32\ibcaojvd.dll",b File not found
O4 - HKLM..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe ()
O4 - HKLM..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [Nduvugav] rundll32.exe "C:\WINDOWS\urifemey.dll",e File not found
O4 - HKLM..\Run: [Nfutuxekuv] rundll32.exe "C:\WINDOWS\Hqixapa.dll",e File not found
O4 - HKLM..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install (NVIDIA Corporation)
O4 - HKLM..\Run: [powukokela] Rundll32.exe "C:\WINDOWS\system32\viyutoni.dll",s File not found
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKCU..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe" File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: 89 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key does not exist or could not be opened.)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: () - File not found
O20 - AppInit_DLLs: (c:\windows\system32\) - c:\WINDOWS\system32 [2009/01/31 12:38:23 00,000,000 | —D | M]
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\xxyYoNfd: DllName - xxyYoNfd.dll - File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[3 C:\WINDOWS\*.tmp files]
[2009/02/05 18:51:01 | 00,487,424 | —- | C] (OldTimer Tools) – C:\Documents and Settings\satnam\Desktop\OTListIt22(2).exe
[2009/02/05 10:13:05 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/02/01 19:13:29 | 00,000,000 | —D | C] – C:\Program Files\HijackThis
[2009/01/31 12:34:49 | 00,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2009/01/31 12:32:38 | 00,079,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/01/28 21:08:20 | 00,000,000 | —D | C] – C:\Documents and Settings\satnam\Local Settings\Application Data\TVU Networks
[2009/01/28 21:08:20 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TVU Networks
[2009/01/25 20:54:18 | 00,001,736 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Windows Live Messenger.lnk
[2009/01/25 20:54:16 | 00,000,000 | —D | C] – C:\Program Files\MSN Messenger
[2009/01/23 17:22:26 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/01/23 17:22:26 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/01/22 22:51:09 | 20,853,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/01/22 22:34:45 | 00,000,000 | —D | C] – C:\1b2a9624b4e5549ce91d3dd8
[2009/01/20 23:01:32 | 00,015,688 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2009/01/20 18:31:49 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/01/20 18:31:36 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/01/20 18:29:59 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/01/20 18:29:58 | 00,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/01/15 02:22:00 | 00,049,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll.mui
[2009/01/15 02:21:44 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe.mui
[2009/01/15 02:19:22 | 00,004,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe.mui
[2009/01/15 02:19:02 | 00,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll.mui
[2009/01/11 11:52:00 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2009/01/11 11:51:50 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Office Outlook Connector
[2009/01/11 11:50:58 | 03,426,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_32.dll
[2009/01/11 11:50:49 | 00,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2009/01/11 11:48:40 | 00,000,000 | —D | C] – C:\Program Files\Microsoft
[2009/01/11 11:48:29 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\microsoft
[2009/01/11 11:48:18 | 00,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2009/01/11 11:36:34 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2009/01/07 20:24:44 | 00,000,000 | —D | C] – C:\Documents and Settings\satnam\Application Data\Malwarebytes
[2009/01/07 20:24:41 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/07 20:24:41 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/07 20:24:39 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/07 20:24:38 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/01/07 20:24:38 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/07 20:23:35 | 00,251,392 | —- | C] () – C:\Documents and Settings\satnam\Desktop\hijackthis_sfx.exe
[2009/01/07 20:02:50 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qmgrprxy.dll
[2009/01/07 20:02:50 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bitsprx2.dll
[2009/01/07 20:02:50 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bitsprx4.dll
[2009/01/07 20:02:50 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bitsprx3.dll
[2009/01/07 20:02:50 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx4.dll
[2009/01/07 20:02:49 | 00,409,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qmgr.dll

========== Files - Modified Within 30 Days ==========

[8 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/02/05 22:00:00 | 00,000,312 | —- | M] () – C:\WINDOWS\tasks\qxefzrnl.job
[2009/02/05 21:07:53 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/02/05 21:07:50 | 00,026,682 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/02/05 21:07:21 | 00,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/05 21:06:49 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/05 21:06:44 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/05 21:05:42 | 04,313,464 | -H– | M] () – C:\Documents and Settings\satnam\Local Settings\Application Data\IconCache.db
[2009/02/05 20:41:51 | 00,002,137 | —- | M] () – C:\Documents and Settings\satnam\Desktop\iTunes.lnk
[2009/02/05 20:25:11 | 00,000,581 | —- | M] () – C:\Documents and Settings\satnam\My Documents\My Sharing Folders.lnk
[2009/02/05 18:51:15 | 00,487,424 | —- | M] (OldTimer Tools) – C:\Documents and Settings\satnam\Desktop\OTListIt22(2).exe
[2009/02/05 18:15:06 | 00,002,497 | —- | M] () – C:\Documents and Settings\satnam\Desktop\Microsoft Office Word 2003.lnk
[2009/02/04 23:32:52 | 32,784,322 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/02/04 23:32:52 | 00,086,834 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/02/04 16:41:29 | 00,292,138 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/01/31 13:50:27 | 00,015,688 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2009/01/31 12:37:47 | 00,000,077 | -HS- | M] () – C:\Documents and Settings\satnam\My Documents\desktop.ini
[2009/01/31 12:35:37 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/01/29 20:16:18 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090204-164129.backup
[2009/01/29 20:16:09 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090129-201618.backup
[2009/01/28 18:52:34 | 00,325,128 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/01/28 18:52:34 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/01/28 18:52:34 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/01/28 18:52:29 | 00,107,272 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/01/27 18:31:06 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/01/25 20:54:18 | 00,001,736 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Windows Live Messenger.lnk
[2009/01/23 17:22:26 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/01/21 18:45:57 | 00,291,722 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090129-201609.backup
[2009/01/20 18:29:58 | 00,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/01/18 21:30:13 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/01/15 02:22:22 | 01,228,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieframe.dll.mui
[2009/01/15 02:22:22 | 01,228,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll.mui
[2009/01/15 02:22:00 | 00,049,152 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll.mui
[2009/01/15 02:21:44 | 00,002,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe.mui
[2009/01/15 02:19:22 | 00,010,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\advpack.dll.mui
[2009/01/15 02:19:22 | 00,004,096 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe.mui
[2009/01/15 02:19:02 | 00,081,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll.mui
[2009/01/15 02:17:22 | 00,636,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iexplore.exe
[2009/01/15 02:17:22 | 00,392,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll
[2009/01/15 02:17:22 | 00,392,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedkcs32.dll
[2009/01/15 02:13:18 | 05,888,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.dll
[2009/01/15 02:13:18 | 05,888,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2009/01/15 02:12:12 | 10,963,968 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieframe.dll
[2009/01/15 02:12:12 | 10,963,968 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2009/01/15 02:07:16 | 00,385,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\html.iec
[2009/01/15 02:06:48 | 01,182,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\urlmon.dll
[2009/01/15 02:06:48 | 01,182,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\urlmon.dll
[2009/01/15 02:06:44 | 01,467,392 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\inetcpl.cpl
[2009/01/15 02:06:44 | 01,467,392 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetcpl.cpl
[2009/01/15 02:06:22 | 00,208,384 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\WinFXDocObj.exe
[2009/01/15 02:06:08 | 00,236,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\webcheck.dll
[2009/01/15 02:06:08 | 00,236,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\webcheck.dll
[2009/01/15 02:06:00 | 00,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\url.dll
[2009/01/15 02:06:00 | 00,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\url.dll
[2009/01/15 02:05:42 | 00,911,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wininet.dll
[2009/01/15 02:05:42 | 00,911,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wininet.dll
[2009/01/15 02:05:34 | 00,193,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll
[2009/01/15 02:05:34 | 00,193,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msrating.dll
[2009/01/15 02:05:34 | 00,109,056 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\occache.dll
[2009/01/15 02:05:34 | 00,109,056 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\occache.dll
[2009/01/15 02:05:34 | 00,043,008 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\licmgr10.dll
[2009/01/15 02:05:34 | 00,043,008 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\licmgr10.dll
[2009/01/15 02:04:56 | 00,755,200 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\VGX.dll
[2009/01/15 02:04:28 | 00,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\corpol.dll
[2009/01/15 02:04:28 | 00,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\corpol.dll
[2009/01/15 02:04:16 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\jsproxy.dll
[2009/01/15 02:04:16 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsproxy.dll
[2009/01/15 02:03:58 | 00,724,992 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\jscript.dll
[2009/01/15 02:03:58 | 00,724,992 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jscript.dll
[2009/01/15 02:03:50 | 00,228,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieaksie.dll
[2009/01/15 02:03:50 | 00,228,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieaksie.dll
[2009/01/15 02:03:42 | 00,125,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieakeng.dll
[2009/01/15 02:03:42 | 00,125,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieakeng.dll
[2009/01/15 02:03:36 | 00,420,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\vbscript.dll
[2009/01/15 02:03:36 | 00,420,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\vbscript.dll
[2009/01/15 02:03:32 | 00,072,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admparse.dll
[2009/01/15 02:03:32 | 00,072,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\admparse.dll
[2009/01/15 02:03:28 | 00,172,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe
[2009/01/15 02:03:28 | 00,172,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ie4uinit.exe
[2009/01/15 02:03:20 | 00,163,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieakui.dll
[2009/01/15 02:03:20 | 00,163,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieakui.dll
[2009/01/15 02:03:18 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iesetup.dll
[2009/01/15 02:03:18 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iesetup.dll
[2009/01/15 02:03:18 | 00,036,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieudinit.exe
[2009/01/15 02:03:14 | 00,094,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\inseng.dll
[2009/01/15 02:03:14 | 00,094,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inseng.dll
[2009/01/15 02:03:14 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iernonce.dll
[2009/01/15 02:03:14 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iernonce.dll
[2009/01/15 02:03:12 | 00,128,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advpack.dll
[2009/01/15 02:03:12 | 00,128,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\advpack.dll
[2009/01/15 02:02:50 | 01,975,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iertutil.dll
[2009/01/15 02:02:50 | 01,975,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2009/01/15 02:02:40 | 00,593,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeeds.dll
[2009/01/15 02:02:40 | 00,593,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2009/01/15 02:02:20 | 00,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mstime.dll
[2009/01/15 02:02:20 | 00,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstime.dll
[2009/01/15 02:01:52 | 00,183,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iepeers.dll
[2009/01/15 02:01:52 | 00,183,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iepeers.dll
[2009/01/15 02:01:42 | 00,013,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeedssync.exe
[2009/01/15 02:01:40 | 00,059,904 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\icardie.dll
[2009/01/15 02:01:40 | 00,059,904 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icardie.dll
[2009/01/15 02:01:40 | 00,054,272 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeedsbs.dll
[2009/01/15 02:01:40 | 00,054,272 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2009/01/15 02:01:26 | 00,034,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\imgutil.dll
[2009/01/15 02:01:26 | 00,034,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imgutil.dll
[2009/01/15 02:01:22 | 00,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dxtmsft.dll
[2009/01/15 02:01:22 | 00,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dxtmsft.dll
[2009/01/15 02:01:18 | 00,046,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\pngfilt.dll
[2009/01/15 02:01:18 | 00,046,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pngfilt.dll
[2009/01/15 02:01:16 | 00,216,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dxtrans.dll
[2009/01/15 02:01:16 | 00,216,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dxtrans.dll
[2009/01/15 02:01:06 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtmled.dll
[2009/01/15 02:01:06 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmled.dll
[2009/01/15 02:00:46 | 00,048,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtmler.dll
[2009/01/15 02:00:46 | 00,048,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmler.dll
[2009/01/15 02:00:40 | 01,639,936 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.tlb
[2009/01/15 02:00:40 | 01,639,936 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.tlb
[2009/01/15 02:00:38 | 00,045,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe
[2009/01/15 02:00:38 | 00,045,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshta.exe
[2009/01/15 02:00:36 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tdc.ocx
[2009/01/15 02:00:36 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdc.ocx
[2009/01/15 01:53:40 | 00,068,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hmmapi.dll
[2009/01/15 01:50:50 | 00,164,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieui.dll
[2009/01/15 01:50:38 | 00,156,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msls31.dll
[2009/01/15 01:50:38 | 00,156,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msls31.dll
[2009/01/15 01:39:06 | 00,057,667 | —- | M] () – C:\WINDOWS\System32\ieuinit.inf
[2009/01/15 01:35:10 | 00,445,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieapfltr.dll
[2009/01/15 01:35:10 | 00,445,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieapfltr.dll
[2009/01/14 17:00:24 | 00,291,222 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090121-184557.backup
[2009/01/14 16:11:32 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/14 16:11:28 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/12 19:48:59 | 00,205,712 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/12 17:47:54 | 00,045,624 | —- | M] () – C:\Documents and Settings\satnam\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/01/11 12:08:07 | 00,456,008 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/01/11 12:08:07 | 00,391,606 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/01/11 12:08:07 | 00,057,896 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/01/11 05:00:34 | 00,079,360 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/01/09 17:35:30 | 20,853,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/01/07 21:44:37 | 00,006,456 | -H– | M] () – C:\WINDOWS\System32\fabovaye
[2009/01/07 20:24:41 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/07 20:23:36 | 00,251,392 | —- | M] () – C:\Documents and Settings\satnam\Desktop\hijackthis_sfx.exe
[2009/01/07 13:58:10 | 00,290,772 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.msn
[2009/01/07 13:58:10 | 00,290,772 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090114-170024.backup
[2009/01/06 22:20:30 | 00,290,793 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090107-135810.backup
[2009/01/06 22:16:29 | 00,000,153 | —- | M] () – C:\WINDOWS\wininit.ini

========== LOP Check ==========

[2009/01/28 21:08:20 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/01/20 18:29:59 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2007/05/15 21:09:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/05/12 18:39:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/01/28 18:47:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2008/12/20 17:43:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DFX
[2007/07/16 16:46:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2007/11/15 21:25:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2007/11/15 21:26:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2007/11/15 21:26:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
[2009/02/05 22:02:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2008/07/17 17:15:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/01/07 20:24:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/22 22:59:38 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/05/07 14:02:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2009/01/05 21:44:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/01/28 21:08:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TVU Networks
[2007/11/15 21:30:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WEBREG
[2007/06/23 16:11:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/02/26 19:34:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WLInstaller
[2009/02/05 18:46:34 | 00,000,000 | RH-D | M] – C:\Documents and Settings\satnam\Application Data
[2008/12/21 19:48:27 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Adobe
[2007/05/15 21:09:14 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\AdobeAUM
[2007/05/19 21:19:44 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\AdobeUM
[2007/07/02 13:09:56 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Apple Computer
[2009/02/05 18:46:54 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\AVGTOOLBAR
[2008/04/01 19:00:03 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\BitTorrent
[2007/10/27 10:21:25 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Creative
[2008/08/02 19:08:56 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\DivX
[2008/07/15 21:03:33 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\DNA
[2008/02/10 20:53:46 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Google
[2007/06/23 21:07:03 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Help
[2007/11/15 21:38:22 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\HP
[2007/05/07 13:35:08 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Identities
[2007/05/12 17:11:07 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Lavasoft
[2007/05/13 15:40:27 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Leadertech
[2007/05/07 15:55:11 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Macromedia
[2009/01/07 20:24:44 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Malwarebytes
[2009/01/07 20:05:29 | 00,000,000 | –SD | M] – C:\Documents and Settings\satnam\Application Data\Microsoft
[2009/01/06 21:19:12 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Mozilla
[2007/05/07 14:53:19 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\MSN6
[2007/06/23 16:22:13 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\NetMedia Providers
[2007/06/23 16:22:12 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Publish Providers
[2007/05/09 16:58:15 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Real
[2009/01/06 21:47:28 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Samsung
[2007/10/19 16:53:04 | 00,000,000 | RH-D | M] – C:\Documents and Settings\satnam\Application Data\SecuROM
[2007/06/23 16:22:07 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Sonic Foundry
[2007/10/19 16:53:15 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Sports Interactive
[2007/05/29 20:52:16 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Sun
[2009/01/27 18:31:06 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2002/08/29 14:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/02/05 22:00:00 | 00,000,312 | —- | M] () – C:\WINDOWS\Tasks\qxefzrnl.job
[2009/02/05 21:06:49 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

< End of report >
hello



Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :Processes
    explorer.exe
    
    :OTLI
    O4 - HKLM..\Run: [58ea0404] rundll32.exe "C:\WINDOWS\system32\ibcaojvd.dll",b File not found
    O4 - HKLM..\Run: [Nduvugav] rundll32.exe "C:\WINDOWS\urifemey.dll",e File not found
    O4 - HKLM..\Run: [Nfutuxekuv] rundll32.exe "C:\WINDOWS\Hqixapa.dll",e File not found
    O4 - HKLM..\Run: [powukokela] Rundll32.exe "C:\WINDOWS\system32\viyutoni.dll",s File not found
    O20 - Winlogon\Notify\xxyYoNfd: DllName - xxyYoNfd.dll - File not found
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )




Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
HI
OTlistit crashed at the same point as before(stooping process.exe).

I ran atf cleaner and it worked.

Kaspersky detected no malware.

Malwarebytes Log: This is the same result i get each time i run malwarebytes but these keys still appear on start up.

Malwarebytes' Anti-Malware 1.33
Database version: 1733
Windows 5.1.2600 Service Pack 2

06/02/2009 10:50:39
mbam-log-2009-02-06 (10-50-39).txt

Scan type: Full Scan (A:\|C:\|D:\|E:\|)
Objects scanned: 97213
Time elapsed: 34 minute(s), 17 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\powukokela (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\58ea0404 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\nduvugav (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\nfutuxekuv (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI