This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Getting pop ups from url.adtrgt.com with Firefox (HJT

29 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I never said it was gone, but any work that we did has been messed up when you restored it

Delete OTList2.exe then do this

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
OTListIt.txt :

OTListIt logfile created on: 2/9/2009 3:10:43 PM - Run
OTListIt2 by OldTimer - Version 2.0.0.10 Folder = C:\EXE & ZIP\HijackThis
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

478.48 Mb Total Physical Memory | 107.17 Mb Available Physical Memory | 22.40% Memory free
1.10 Gb Paging File | 0.87 Gb Available in Paging File | 79.52% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 152.66 Gb Total Space | 115.23 Gb Free Space | 75.48% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 76.33 Gb Total Space | 53.86 Gb Free Space | 70.57% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: N-F6908F5DF7D04
Current User Name: Kate
Logged in as Administrator.

Current Boot Mode: SafeMode with Networking
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox 3 Beta 3\firefox.exe (Mozilla Corporation)
PRC - C:\EXE & ZIP\HijackThis\OTListIt22.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Stopped]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Auto | Stopped]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (Ati HotKey Poller [Auto | Stopped]) – C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) – C:\WINDOWS\system32\ati2sgag.exe ()
SRV - (avast! Antivirus [Auto | Stopped]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Stopped]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Stopped]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (Bonjour Service [Auto | Stopped]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Stopped]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (WudfSvc [On_Demand | Stopped]) – C:\WINDOWS\system32\WudfSvc.dll (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (Aavmker4 [System | Stopped]) – C:\WINDOWS\system32\drivers\aavmker4.sys (ALWIL Software)
DRV - (ALCXWDM [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (aswFsBlk [Auto | Stopped]) – C:\WINDOWS\system32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (aswMon2 [Auto | Stopped]) – C:\WINDOWS\system32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Stopped]) – C:\WINDOWS\system32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) – C:\WINDOWS\system32\drivers\aswTdi.sys (ALWIL Software)
DRV - (ati2mtag [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (L6TPortGX [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\L6TPortGX.sys (Line 6)
DRV - (motmodem [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\motmodem.sys (Motorola)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (rtl8139 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (Secdrv [Auto | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SilverLink [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\SilvrLnk.sys (Texas Instruments Incorporated)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaapl.sys (Apple, Inc.)
DRV - (Wdf01000 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wdf01000.sys (Microsoft Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

O1 HOSTS File: (293398 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 10102 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {3541147A-29C4-40E8-BAAE-30D71529C686} - Reg Error: Key error. File not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {AC071477-43ED-4A48-A96C-698D4FEBD1C0} - C:\WINDOWS\system32\pmnoNHBQ.dll File not found
O2 - BHO: (no name) - {E3C16394-5010-4B4C-BCC2-CE63B6A92F24} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe File not found
O4 - HKLM..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" (ATI Technologies, Inc.)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" (Hewlett-Packard Company)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe (HP)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 (Microsoft Corporation)
O4 - HKLM..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe (America Online, Inc.)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC (Microsoft Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - Startup: C:\Documents and Settings\Kate\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra Button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: line6.net ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: 55 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/5/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab (Quantum Streaming IE Player Class)
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (wbsys.dll) - C:\WINDOWS\system32\wbsys.dll (Stardock.Net, Inc)
O20 - AppInit_DLLs: (yijzch.dll) - C:\WINDOWS\system32\yijzch.dll ()
O20 - AppInit_DLLs: (gmmaxq.dll) - C:\WINDOWS\system32\gmmaxq.dll ()
O20 - AppInit_DLLs: (rsrjon.dll sdbgyy.dll lqunfg.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\pmnkHyVn: DllName - pmnkHyVn.dll - File not found
O20 - Winlogon\Notify\WBSrv: DllName - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll - C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll (Stardock)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O29 - HKLM SecurityProviders - ( digeste.dll) - File not found
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\pmnoNHBQ) - File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{5790b52e-e98f-11dc-a99f-00142a8ea364}\Shell\AutoRun\command - "" = F:\system\viewer\FlipVideoforPC.exe – File not found
O33 - MountPoints2\{5790b52e-e98f-11dc-a99f-00142a8ea364}\Shell\Flip Video for PC\command - "" = F:\system\viewer\FlipVideoforPC.exe – File not found

========== Files/Folders - Created Within 30 Days ==========

[4 C:\WINDOWS\*.tmp files]
[2009/02/04 20:18:51 | 00,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2009/02/04 20:14:46 | 00,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2009/02/04 18:02:52 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/02/04 17:57:12 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/02/04 15:27:20 | 00,001,734 | —- | C] () – C:\Documents and Settings\Kate\Desktop\HijackThis.lnk
[2009/02/04 15:27:20 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/02/04 15:25:53 | 00,000,000 | —D | C] – C:\WINDOWS\Backup
[2009/02/04 15:25:20 | 00,000,767 | —- | C] () – C:\Documents and Settings\Kate\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/02/04 15:25:05 | 00,000,592 | —- | C] () – C:\Documents and Settings\Kate\Desktop\ERUNT.lnk
[2009/02/04 15:25:04 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/02/03 23:39:31 | 00,000,120 | -HS- | C] () – C:\WINDOWS\System32\djnldfnu.ini
[2009/02/03 23:39:30 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\unfdlnjd.dll
[2009/02/03 23:36:32 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\lqunfg.dll
[2009/02/03 23:36:31 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\hjjalfxi.dll
[2009/02/03 23:06:38 | 00,000,120 | -HS- | C] () – C:\WINDOWS\System32\lfepeomv.ini
[2009/02/03 23:03:37 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\sdbgyy.dll
[2009/02/03 23:03:35 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\jxgqeqdh.dll
[2009/02/02 23:14:02 | 00,001,709 | —- | C] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/02/02 23:14:01 | 00,023,152 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/02/02 23:13:59 | 00,050,864 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/02/02 23:13:56 | 00,026,944 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/02/02 23:13:48 | 00,097,480 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\AvastSS.scr
[2009/02/02 23:13:37 | 00,111,184 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2009/02/02 23:13:37 | 00,020,560 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/02/02 23:13:35 | 00,094,032 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/02/02 23:13:35 | 00,093,296 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2009/02/02 23:13:16 | 01,236,208 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\aswBoot.exe
[2009/02/02 23:13:16 | 01,060,864 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MFC71.dll
[2009/02/02 23:13:16 | 00,380,928 | —- | C] () – C:\WINDOWS\System32\actskin4.ocx
[2009/02/02 23:13:14 | 00,000,000 | —D | C] – C:\Program Files\Alwil Software
[2009/02/02 23:03:12 | 00,000,120 | -HS- | C] () – C:\WINDOWS\System32\cyxlcxjg.ini
[2009/02/02 23:03:09 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\gjxclxyc.dll
[2009/02/02 23:00:53 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\yeagxa.dll
[2009/02/02 23:00:52 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\omkpkfjq.dll
[2009/02/02 15:43:42 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\rsrjon.dll
[2009/02/02 15:43:40 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\xhbkrflg.dll
[2009/02/02 15:41:05 | 00,000,120 | -HS- | C] () – C:\WINDOWS\System32\uyymbjdo.ini
[2009/02/02 15:40:59 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\odjbmyyu.dll
[2009/01/30 10:26:21 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\duictg.dll
[2009/01/30 10:26:19 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\swdtmcsb.dll
[2009/01/30 08:04:38 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\eepcfmpr.dll
[2009/01/30 08:01:42 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\gmmaxq.dll
[2009/01/30 08:01:40 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\egunlrtl.dll
[2009/01/28 21:24:04 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\anljcqem.dll
[2009/01/28 21:22:10 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\tminnq.dll
[2009/01/28 21:22:07 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\heojtrfw.dll
[2009/01/27 21:40:44 | 00,228,520 | —- | C] () – C:\Documents and Settings\Kate\My Documents\WoWScrnShot_012709_213936.jpg
[2009/01/27 21:09:07 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\khgqcspi.dll
[2009/01/27 21:07:34 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\yijzch.dll
[2009/01/27 21:07:32 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\ovelebdv.dll
[2009/01/25 21:36:49 | 00,002,509 | —- | C] () – C:\Documents and Settings\Kate\Desktop\MS Word.lnk
[2009/01/24 21:03:49 | 00,000,000 | —D | C] – C:\Documents and Settings\Kate\Application Data\cogad
[2009/01/24 21:02:02 | 00,198,730 | —- | C] () – C:\WINDOWS\System32\wpv761232809034.cpx
[2009/01/20 00:38:22 | 00,000,000 | —D | C] – C:\Documents and Settings\Kate\Local Settings\Application Data\WMTools Downloaded Files

========== Files - Modified Within 30 Days ==========

[2 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009/02/09 14:45:50 | 00,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/09 14:44:59 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/09 06:51:40 | 04,254,480 | -H– | M] () – C:\Documents and Settings\Kate\Local Settings\Application Data\IconCache.db
[2009/02/08 22:46:41 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/07 09:25:50 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/02/04 20:18:51 | 00,000,552 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2009/02/04 15:27:20 | 00,001,734 | —- | M] () – C:\Documents and Settings\Kate\Desktop\HijackThis.lnk
[2009/02/04 15:25:20 | 00,000,767 | —- | M] () – C:\Documents and Settings\Kate\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/02/04 15:25:05 | 00,000,592 | —- | M] () – C:\Documents and Settings\Kate\Desktop\ERUNT.lnk
[2009/02/04 14:32:41 | 00,293,398 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/02/04 14:32:29 | 00,293,398 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090204-143241.backup
[2009/02/04 12:09:18 | 00,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/02/03 23:39:35 | 00,000,120 | -HS- | M] () – C:\WINDOWS\System32\djnldfnu.ini
[2009/02/03 23:39:30 | 00,072,704 | —- | M] () – C:\WINDOWS\System32\unfdlnjd.dll
[2009/02/03 23:36:31 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\lqunfg.dll
[2009/02/03 23:36:31 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\hjjalfxi.dll
[2009/02/03 23:06:38 | 00,000,120 | -HS- | M] () – C:\WINDOWS\System32\lfepeomv.ini
[2009/02/03 23:03:36 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\sdbgyy.dll
[2009/02/03 23:03:36 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\jxgqeqdh.dll
[2009/02/03 20:20:00 | 00,248,320 | -HS- | M] () – C:\Documents and Settings\Kate\My Documents\Thumbs.db
[2009/02/02 23:14:02 | 00,001,709 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/02/02 23:03:12 | 00,000,120 | -HS- | M] () – C:\WINDOWS\System32\cyxlcxjg.ini
[2009/02/02 23:03:10 | 00,072,704 | —- | M] () – C:\WINDOWS\System32\gjxclxyc.dll
[2009/02/02 23:00:53 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\yeagxa.dll
[2009/02/02 23:00:53 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\omkpkfjq.dll
[2009/02/02 15:43:40 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\xhbkrflg.dll
[2009/02/02 15:43:40 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\rsrjon.dll
[2009/02/02 15:41:05 | 00,000,120 | -HS- | M] () – C:\WINDOWS\System32\uyymbjdo.ini
[2009/02/02 15:40:59 | 00,072,704 | —- | M] () – C:\WINDOWS\System32\odjbmyyu.dll
[2009/01/30 14:58:16 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/01/30 11:45:12 | 00,000,093 | —- | M] () – C:\WINDOWS\wininit.ini
[2009/01/30 10:46:38 | 00,293,256 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090204-143228.backup
[2009/01/30 10:46:16 | 00,293,256 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090130-104638.backup
[2009/01/30 10:45:37 | 00,293,256 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090130-104616.backup
[2009/01/30 10:26:20 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\swdtmcsb.dll
[2009/01/30 10:26:20 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\duictg.dll
[2009/01/30 08:04:39 | 00,072,704 | —- | M] () – C:\WINDOWS\System32\eepcfmpr.dll
[2009/01/30 08:01:41 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\gmmaxq.dll
[2009/01/30 08:01:41 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\egunlrtl.dll
[2009/01/28 21:24:05 | 00,072,704 | —- | M] () – C:\WINDOWS\System32\anljcqem.dll
[2009/01/28 21:22:08 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\tminnq.dll
[2009/01/28 21:22:08 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\heojtrfw.dll
[2009/01/27 21:39:37 | 00,228,520 | —- | M] () – C:\Documents and Settings\Kate\My Documents\WoWScrnShot_012709_213936.jpg
[2009/01/27 21:09:08 | 00,072,704 | —- | M] () – C:\WINDOWS\System32\khgqcspi.dll
[2009/01/27 21:07:33 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\yijzch.dll
[2009/01/27 21:07:33 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\ovelebdv.dll
[2009/01/25 21:36:49 | 00,002,509 | —- | M] () – C:\Documents and Settings\Kate\Desktop\MS Word.lnk
[2009/01/24 21:02:03 | 00,198,730 | —- | M] () – C:\WINDOWS\System32\wpv761232809034.cpx
[2009/01/20 15:00:34 | 00,091,648 | —- | M] () – C:\Documents and Settings\Kate\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/14 22:26:17 | 00,231,184 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT

========== LOP Check ==========

[2009/02/02 22:57:40 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/12/25 12:34:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/08/07 00:36:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2007/05/23 22:14:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/12/20 20:25:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2008/02/16 21:46:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL Downloads
[2006/12/09 16:23:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL OCP
[2007/06/30 23:31:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2006/10/01 23:44:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/02/02 22:57:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2007/08/24 23:55:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2008/05/11 23:53:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2007/12/25 12:34:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Line 6
[2008/02/11 23:29:40 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2006/12/07 22:41:49 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Move Networks
[2009/02/02 15:40:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/02/04 12:46:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/11/08 06:26:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/06/28 18:51:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/02/02 22:33:21 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Kate\Application Data
[2007/12/20 20:27:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\acccore
[2008/11/20 21:01:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Adobe
[2008/05/06 19:14:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\AdobeUM
[2007/12/20 20:10:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Aim
[2008/12/25 19:27:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Apple Computer
[2007/04/02 20:57:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\ArcSoft
[2009/02/02 23:40:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\cogad
[2008/03/20 19:59:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\FastStone
[2009/01/20 04:06:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\FrostWire
[2006/07/12 11:04:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Google
[2007/04/02 17:54:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\gtk-2.0
[2006/06/20 15:45:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Help
[2006/05/10 20:42:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Identities
[2007/12/25 12:34:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Line 6
[2006/10/16 22:35:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Macromedia
[2009/02/02 22:55:22 | 00,000,000 | –SD | M] – C:\Documents and Settings\Kate\Application Data\Microsoft
[2008/02/16 21:42:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Mozilla
[2007/10/27 14:15:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Nvu
[2008/11/08 06:24:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Real
[2006/07/01 10:21:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Sun
[2008/02/11 23:32:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Template
[2008/11/08 06:26:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Viewpoint
[2009/01/30 14:58:16 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2008/11/19 18:00:00 | 00,000,286 | —- | M] () – C:\WINDOWS\Tasks\AVG Free Edition Test Center.job
[2004/08/04 07:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/02/08 22:46:41 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Kate\My Documents\Thumbs.db:encryptable
< End of report >


Extras.txt :

OTListIt Extras logfile created on: 2/9/2009 3:10:43 PM - Run
OTListIt2 by OldTimer - Version 2.0.0.10 Folder = C:\EXE & ZIP\HijackThis
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

478.48 Mb Total Physical Memory | 107.17 Mb Available Physical Memory | 22.40% Memory free
1.10 Gb Paging File | 0.87 Gb Available in Paging File | 79.52% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 152.66 Gb Total Space | 115.23 Gb Free Space | 75.48% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 76.33 Gb Total Space | 53.86 Gb Free Space | 70.57% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: N-F6908F5DF7D04
Current User Name: Kate
Logged in as Administrator.

Current Boot Mode: SafeMode with Networking
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = chm.file] – C:\WINDOWS\hh.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\WINDOWS\system32\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] – C:\WINDOWS\system32\mshta.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox 3 Beta 3\firefox.exe (Mozilla Corporation)
.inf [@ = inffile] – C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
.ini [@ = inifile] – C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
.js [@ = JSFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.jse [@ = JSEFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.reg [@ = regfile] – C:\WINDOWS\regedit.exe (Microsoft Corporation)
.txt [@ = txtfile] – C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
.vbe [@ = VBEFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger (America Online, Inc.)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox (Mozilla Corporation)
C:\StubInstaller.exe:*:Enabled:LimeWire swarmed installer File not found
C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire File not found
C:\Program Files\Java\jre1.5.0_08\bin\javaw.exe:*:Enabled:Java™ 2 Platform Standard Edition binary File not found
C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader (AOL LLC)
C:\Program Files\Common Files\AOL\1159050899\ee\aolsoftware.exe:*:Enabled:AOL Services File not found
C:\Program Files\Common Files\AOL\1159050899\ee\aim6.exe:*:Enabled:AIM File not found
C:\Program Files\Java\jre1.5.0_09\bin\javaw.exe:*:Enabled:Java™ 2 Platform Standard Edition binary File not found
C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger (America Online, Inc.)
C:\Program Files\Java\jre1.5.0_10\bin\javaw.exe:*:Enabled:Java™ 2 Platform Standard Edition binary File not found
C:\Program Files\Common Files\AOL\1166939575\ee\aolsoftware.exe:*:Enabled:AOL Services (America Online, Inc.)
C:\Program Files\Common Files\AOL\1166939575\ee\aim6.exe:*:Enabled:AIM (America Online, Inc.)
C:\Program Files\Java\jre1.5.0_11\bin\javaw.exe:*:Enabled:Java™ 2 Platform Standard Edition binary File not found
C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:LimeWire File not found
E:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire File not found
E:\Program Files\FrostWire\FrostWire.exe:*:Enabled:LimeWire (FrostWire Group)
C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM (AOL LLC)
C:\Program Files\Mozilla Firefox 3 Beta 3\firefox.exe:*:Enabled:Firefox (Mozilla Corporation)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console (Microsoft Corporation)
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java™ 6 Update 10
"{318AB667-3230-41B5-A617-CB3BF748D371}" = iTunes
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3D047C15-C859-45F7-81CE-F2681778069B}" = iPod for Windows 2006-01-10
"{43602F34-1AA3-44FB-AEB2-D08C2C73743F}" = Paint.NET v3.36
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9A00D1BA-D03A-44E5-AF28-86A1F377DF61}" = The Sims Makin' Magic
"{A8B94669-8654-4126-BD28-D0D2412CDED6}" = TI Connect 1.6
"{AC76BA86-7AD7-1033-7B44-A70900000002}" = Adobe Reader 7.0.9
"{B1591C79-1C35-4E09-AA15-F7D6923AFB96}" = HP Deskjet 3840
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"3ivx MPEG-4 5.0.1 Decoder" = 3ivx MPEG-4 5.0.1 Decoder (remove only)
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AdobeESD" = Adobe Download Manager 2.2 (Remove Only)
"AIM_6" = AIM 6
"All ATI Software" = ATI - Software Uninstall Utility
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"ATI Display Driver" = ATI Display Driver
"avast!" = avast! Antivirus
"ERUNT_is1" = ERUNT 1.1j
"FrostWire" = FrostWire 4.17.2
"HijackThis" = HijackThis 1.99.1
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{3D047C15-C859-45F7-81CE-F2681778069B}" = iPod for Windows 2006-01-10
"Mozilla Firefox (3.0.6)" = Mozilla Firefox (3.0.6)
"Network Play System (Patching)" = Network Play System (Patching)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SpywareBlaster_is1" = SpywareBlaster 4.0
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"WindowBlinds" = WindowBlinds
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 (Beta2)
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/27/2009 10:45:42 PM | Computer Name = N-F6908F5DF7D04 | Source = Application Hang | ID = 1002
Description = Hanging application TeaTimer.exe, version 1.5.2.16, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 1/27/2009 10:45:48 PM | Computer Name = N-F6908F5DF7D04 | Source = Application Hang | ID = 1002
Description = Hanging application TeaTimer.exe, version 1.5.2.16, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/3/2009 3:55:17 PM | Computer Name = N-F6908F5DF7D04 | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.0.3306, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/4/2009 6:59:31 PM | Computer Name = N-F6908F5DF7D04 | Source = Application Hang | ID = 1002
Description = Hanging application OTListIt22.exe, version 2.0.0.5, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/4/2009 8:31:50 PM | Computer Name = N-F6908F5DF7D04 | Source = Application Hang | ID = 1002
Description = Hanging application OTListIt22.exe, version 2.0.0.5, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/4/2009 8:42:53 PM | Computer Name = N-F6908F5DF7D04 | Source = Application Hang | ID = 1002
Description = Hanging application OTListIt22.exe, version 2.0.0.5, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/5/2009 8:12:55 PM | Computer Name = N-F6908F5DF7D04 | Source = Application Hang | ID = 1002
Description = Hanging application aim6.exe, version 1.4.9.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/5/2009 8:12:57 PM | Computer Name = N-F6908F5DF7D04 | Source = Application Hang | ID = 1002
Description = Hanging application aim6.exe, version 1.4.9.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/7/2009 10:24:20 AM | Computer Name = N-F6908F5DF7D04 | Source = Application Hang | ID = 1002
Description = Hanging application OTListIt22.exe, version 2.0.0.5, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/7/2009 10:31:44 AM | Computer Name = N-F6908F5DF7D04 | Source = Application Hang | ID = 1002
Description = Hanging application OTListIt22.exe, version 2.0.0.5, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 2/8/2009 11:48:49 PM | Computer Name = N-F6908F5DF7D04 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 2/8/2009 11:50:00 PM | Computer Name = N-F6908F5DF7D04 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Aavmker4 aswSP Fips Processor

Error - 2/9/2009 7:47:45 AM | Computer Name = N-F6908F5DF7D04 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 2/9/2009 7:48:44 AM | Computer Name = N-F6908F5DF7D04 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Aavmker4 aswSP Fips Processor

Error - 2/9/2009 7:51:45 AM | Computer Name = N-F6908F5DF7D04 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 2/9/2009 3:46:07 PM | Computer Name = N-F6908F5DF7D04 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 2/9/2009 3:46:44 PM | Computer Name = N-F6908F5DF7D04 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Aavmker4 aswSP Fips Processor

Error - 2/9/2009 3:51:06 PM | Computer Name = N-F6908F5DF7D04 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 2/9/2009 3:51:24 PM | Computer Name = N-F6908F5DF7D04 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 2/9/2009 4:09:51 PM | Computer Name = N-F6908F5DF7D04 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}


< End of report >
hello

While TeaTimer is an excellent tool for the prevention of spyware, it can sometimes prevent HijackThis from fixing certain things.
Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your HijackThis log is clean.
  • Open Spybot Search & Destroy.
  • In the Mode menu click "Advanced mode" if not already selected.
  • Choose "Yes" at the Warning prompt.
  • Expand the "Tools" menu.
  • Click "Resident".
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • In the File menu click "Exit" to exit Spybot Search & Destroy.


Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    IE - URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll File not found
    O2 - BHO: (no name) - {3541147A-29C4-40E8-BAAE-30D71529C686} - Reg Error: Key error. File not found
    O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - Reg Error: Key error. File not found
    O2 - BHO: (no name) - {AC071477-43ED-4A48-A96C-698D4FEBD1C0} - C:\WINDOWS\system32\pmnoNHBQ.dll File not found
    O2 - BHO: (no name) - {E3C16394-5010-4B4C-BCC2-CE63B6A92F24} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - Reg Error: Key error. File not found
    O20 - AppInit_DLLs: (yijzch.dll) - C:\WINDOWS\system32\yijzch.dll ()
    O20 - AppInit_DLLs: (gmmaxq.dll) - C:\WINDOWS\system32\gmmaxq.dll ()
    O20 - AppInit_DLLs: (rsrjon.dll sdbgyy.dll lqunfg.dll) - File not found
    O20 - Winlogon\Notify\pmnkHyVn: DllName - pmnkHyVn.dll - File not found
    O29 - HKLM SecurityProviders - ( digeste.dll) - File not found
    O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\pmnoNHBQ) - File not found
    O33 - MountPoints2\{5790b52e-e98f-11dc-a99f-00142a8ea364}\Shell\AutoRun\command - "" = F:\system\viewer\FlipVideoforPC.exe – File not found
    O33 - MountPoints2\{5790b52e-e98f-11dc-a99f-00142a8ea364}\Shell\Flip Video for PC\command - "" = F:\system\viewer\FlipVideoforPC.exe – File not found
    [2009/02/03 23:39:31 | 00,000,120 | -HS- | C] () – C:\WINDOWS\System32\djnldfnu.ini
    [2009/02/03 23:39:30 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\unfdlnjd.dll
    [2009/02/03 23:36:32 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\lqunfg.dll
    [2009/02/03 23:36:31 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\hjjalfxi.dll
    [2009/02/03 23:06:38 | 00,000,120 | -HS- | C] () – C:\WINDOWS\System32\lfepeomv.ini
    [2009/02/03 23:03:37 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\sdbgyy.dll
    [2009/02/03 23:03:35 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\jxgqeqdh.dll
    [2009/02/02 23:03:12 | 00,000,120 | -HS- | C] () – C:\WINDOWS\System32\cyxlcxjg.ini
    [2009/02/02 23:03:09 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\gjxclxyc.dll
    [2009/02/02 23:00:53 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\yeagxa.dll
    [2009/02/02 23:00:52 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\omkpkfjq.dll
    [2009/02/02 15:43:42 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\rsrjon.dll
    [2009/02/02 15:43:40 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\xhbkrflg.dll
    [2009/02/02 15:41:05 | 00,000,120 | -HS- | C] () – C:\WINDOWS\System32\uyymbjdo.ini
    [2009/02/02 15:40:59 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\odjbmyyu.dll
    [2009/01/30 10:26:21 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\duictg.dll
    [2009/01/30 10:26:19 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\swdtmcsb.dll
    [2009/01/30 08:04:38 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\eepcfmpr.dll
    [2009/01/30 08:01:42 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\gmmaxq.dll
    [2009/01/30 08:01:40 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\egunlrtl.dll
    [2009/01/28 21:24:04 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\anljcqem.dll
    [2009/01/28 21:22:10 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\tminnq.dll
    [2009/01/28 21:22:07 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\heojtrfw.dll
    [2009/01/27 21:09:07 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\khgqcspi.dll
    [2009/01/27 21:07:34 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\yijzch.dll
    [2009/01/27 21:07:32 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\ovelebdv.dll
    [2009/01/24 21:03:49 | 00,000,000 | —D | C] – C:\Documents and Settings\Kate\Application Data\cogad
    [2009/01/24 21:02:02 | 00,198,730 | —- | C] () – C:\WINDOWS\System32\wpv761232809034.cpx
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )
I did this and the OTList window just went blank, nothing was there except for the title bar and caption buttons. Was running solo for an hour.
ok lets do this then

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.
ComboFix 09-02-08.02 - Kate 2009-02-09 17:01:01.1 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.478.274 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Kate\Local Settings\Temporary Internet Files\fbk.sts
c:\windows\system32\anljcqem.dll
c:\windows\system32\cyxlcxjg.ini
c:\windows\system32\djnldfnu.ini
c:\windows\system32\duictg.dll
c:\windows\system32\eepcfmpr.dll
c:\windows\system32\egunlrtl.dll
c:\windows\system32\gjxclxyc.dll
c:\windows\system32\gmmaxq.dll
c:\windows\system32\heojtrfw.dll
c:\windows\system32\hjjalfxi.dll
c:\windows\system32\jxgqeqdh.dll
c:\windows\system32\khgqcspi.dll
c:\windows\system32\lfepeomv.ini
c:\windows\system32\lqunfg.dll
c:\windows\system32\odjbmyyu.dll
c:\windows\system32\omkpkfjq.dll
c:\windows\system32\ovelebdv.dll
c:\windows\system32\rsrjon.dll
c:\windows\system32\sdbgyy.dll
c:\windows\system32\swdtmcsb.dll
c:\windows\system32\tminnq.dll
c:\windows\system32\unfdlnjd.dll
c:\windows\system32\uyymbjdo.ini
c:\windows\system32\wpv761232809034.cpx
c:\windows\system32\xhbkrflg.dll
c:\windows\system32\yeagxa.dll
c:\windows\system32\yijzch.dll
c:\windows\wiaserviv.log

.
((((((((((((((((((((((((( Files Created from 2009-01-09 to 2009-02-09 )))))))))))))))))))))))))))))))
.

2009-02-04 20:18 . 2009-02-04 20:18 552 –a—— c:\windows\system32\d3d8caps.dat
2009-02-04 17:57 . 2009-02-04 17:57 d——– C:\_OTListIt
2009-02-04 15:27 . 2009-02-04 15:27 d——– c:\program files\Trend Micro
2009-02-04 15:25 . 2009-02-04 15:26 d——– c:\windows\Backup
2009-02-04 15:25 . 2009-02-04 15:25 d——– c:\program files\ERUNT
2009-02-02 23:13 . 2009-02-02 23:13 d——– c:\program files\Alwil Software
2009-02-02 23:13 . 2003-03-18 16:20 1,060,864 –a—— c:\windows\system32\MFC71.dll
2009-01-24 21:03 . 2009-02-02 23:40 d——– c:\documents and settings\Kate\Application Data\cogad

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-09 21:50 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-09 21:50 ——— d—–w c:\program files\Mozilla Firefox 3 Beta 3
2009-02-04 17:50 ——— d—–w c:\program files\SpywareBlaster
2009-02-03 03:57 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-02-03 02:57 ——— d—–w c:\program files\Spybot - Search & Destroy
2009-02-02 20:40 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-20 09:06 ——— d—–w c:\documents and settings\Kate\Application Data\FrostWire
2008-12-26 00:27 ——— d—–w c:\documents and settings\Kate\Application Data\Apple Computer
2008-12-25 17:34 ——— d—–w c:\program files\iTunes
2008-12-25 17:34 ——— d—–w c:\program files\iPod
2008-12-25 17:34 ——— d—–w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-25 17:26 ——— d—–w c:\program files\Bonjour
2008-12-25 17:22 ——— d—–w c:\program files\Common Files\Apple
2008-12-11 10:57 333,952 —-a-w c:\windows\system32\drivers\srv.sys
2008-09-23 01:50 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008092220080923\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"IPHSend"="c:\program files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 124520]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SoundMan"="SOUNDMAN.EXE" [2005-07-22 c:\windows\SOUNDMAN.EXE]

c:\documents and settings\Kate\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2005-11-28 14:52 176128 c:\progra~1\Stardock\OBJECT~1\WINDOW~1\WbSrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.3IV2"= 3ivxVfWCodec_dec.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Common Files\\AOL\\1166939575\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1166939575\\ee\\aim6.exe"=
"e:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Mozilla Firefox 3 Beta 3\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

S3 L6TPortGX;Service - Line 6 TonePort GX;c:\windows\system32\drivers\L6TPortGX.sys [2007-12-25 609280]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5790b52e-e98f-11dc-a99f-00142a8ea364}]
\Shell\AutoRun\command - f:\system\viewer\FlipVideoforPC.exe
\Shell\Flip Video for PC\command - f:\system\viewer\FlipVideoforPC.exe
.
Contents of the 'Scheduled Tasks' folder

2009-01-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2008-11-19 c:\windows\Tasks\AVG Free Edition Test Center.job
- c:\progra~1\Grisoft\AVGFRE~1\avgw.exe []
.
- - - - ORPHANS REMOVED - - - -

BHO-{3541147A-29C4-40E8-BAAE-30D71529C686} - (no file)
BHO-{AC071477-43ED-4A48-A96C-698D4FEBD1C0} - c:\windows\system32\pmnoNHBQ.dll
BHO-{E3C16394-5010-4B4C-BCC2-CE63B6A92F24} - (no file)
HKLM-Run-AppleSyncNotifier - c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
Notify-pmnkHyVn - pmnkHyVn.dll


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: line6.net
FF - ProfilePath - c:\documents and settings\Kate\Application Data\Mozilla\Firefox\Profiles\3ttzf1gk.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 3\plugins\np32dsw.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 3\plugins\npdeploytk.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 3\plugins\npnul32.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 3\plugins\npqtplugin.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 3\plugins\npqtplugin2.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 3\plugins\npqtplugin3.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 3\plugins\npqtplugin4.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 3\plugins\npqtplugin5.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 3\plugins\npqtplugin6.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 3\plugins\npqtplugin7.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-09 17:04:02
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(548)
c:\windows\system32\Ati2evxx.dll
c:\progra~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-02-09 17:07:41 - machine was rebooted [Kate]
ComboFix-quarantined-files.txt 2009-02-09 22:07:24

Pre-Run: 124,549,386,240 bytes free
Post-Run: 124,604,321,792 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

185 — E O F — 2009-01-15 01:38:19

Please let me know when I get enable SpywareBlaster, Spybot S&D, and avast! again.
hello

Please download OTMoveIt3 by OldTimer
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5790b52e-e98f-11dc-a99f-00142a8ea364}]
    :Files
    c:\documents and settings\Kate\Application Data\cogad
    
    
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
Here's what I have so far. I'm currently running the Kaspersky Scan, waiting on that to finish. OTMover.txt ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5790b52e-e98f-11dc-a99f-00142a8ea364}\\ deleted successfully. ========== FILES ========== c:\documents and settings\Kate\Application Data\cogad moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\Kate\LOCALS~1\Temp\etilqs_I8hgdCqfVfY1ZAah8GkZ scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_5ac.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\Kate\Local Settings\Application Data\Mozilla\Firefox\Profiles\3ttzf1gk.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Kate\Local Settings\Application Data\Mozilla\Firefox\Profiles\3ttzf1gk.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Kate\Local Settings\Application Data\Mozilla\Firefox\Profiles\3ttzf1gk.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Kate\Local Settings\Application Data\Mozilla\Firefox\Profiles\3ttzf1gk.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Kate\Local Settings\Application Data\Mozilla\Firefox\Profiles\3ttzf1gk.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Kate\Local Settings\Application Data\Mozilla\Firefox\Profiles\3ttzf1gk.default\urlclassifier3.sqlite-journal scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Kate\Local Settings\Application Data\Mozilla\Firefox\Profiles\3ttzf1gk.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02092009_181357 Files moved on Reboot… File C:\DOCUME~1\Kate\LOCALS~1\Temp\etilqs_I8hgdCqfVfY1ZAah8GkZ not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File C:\WINDOWS\temp\Perflib_Perfdata_5ac.dat not found! C:\Documents and Settings\Kate\Local Settings\Application Data\Mozilla\Firefox\Profiles\3ttzf1gk.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\Kate\Local Settings\Application Data\Mozilla\Firefox\Profiles\3ttzf1gk.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\Kate\Local Settings\Application Data\Mozilla\Firefox\Profiles\3ttzf1gk.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\Kate\Local Settings\Application Data\Mozilla\Firefox\Profiles\3ttzf1gk.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\Kate\Local Settings\Application Data\Mozilla\Firefox\Profiles\3ttzf1gk.default\urlclassifier3.sqlite moved successfully. File C:\Documents and Settings\Kate\Local Settings\Application Data\Mozilla\Firefox\Profiles\3ttzf1gk.default\urlclassifier3.sqlite-journal not found! C:\Documents and Settings\Kate\Local Settings\Application Data\Mozilla\Firefox\Profiles\3ttzf1gk.default\XUL.mfl moved successfully. Malwarebytes.txt : Malwarebytes' Anti-Malware 1.33 Database version: 1742 Windows 5.1.2600 Service Pack 3 2/9/2009 8:48:04 PM mbam-log-2009-02-09 (20-48-04).txt Scan type: Quick Scan Objects scanned: 56149 Time elapsed: 3 minute(s), 20 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 4 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Okay, the Kaspersky Scanner didn't work out for me. It stopped after almost two hours at 61% and didn't progress from there. I attempted to get a scan report, but when I did, it was blank.

Anyway, here's my HJT Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:19:33 PM, on 2/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox 3 Beta 3\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.line6.net
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} (Quantum Streaming IE Player Class) - http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

–
End of file - 6015 bytes
do this then

Please click here to download AVP Tool by Kaspersky.
  • Save it to your desktop.
  • Reboot your computer into SafeMode.

    You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
    Use your up arrow key to highlight SafeMode then hit enter
    .

  • Double click the setup file to run it.
  • Click Next to continue.
  • It will by default install it to your desktop folder.Click Next.
  • Hit ok at the prompt for scanning in Safe Mode.
  • It will then open a box There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.

  • System Memory
  • Startup Objects
  • Disk Boot Sectors.
  • My Computer.
  • Also any other drives (Removable that you may have)


  • Then click on Scan at the to right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left unneutralized then click the button that says Neutralize all
  • If it says it cannot be Neutralized then chooose The delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file name it Kas.
  • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.

Kaspersky log:

Scan
—-
Scanned: 791788
Detected: 34
Untreated: 0
Start time: 2/11/2009 8:28:35 PM
Duration: 03:59:27
Finish time: 2/12/2009 12:28:02 AM


Detected
——–
Status Object
—— ——
disinfected: Trojan program Trojan-Downloader.WMA.GetCodec.r File: C:\Documents and Settings\Kate\My Documents\Incomplete\T-3545427-steve austin tribute piano.mp3
deleted: Trojan program Trojan.Win32.Monder.auaa File: C:\Qoobox\Quarantine\C\WINDOWS\system32\anljcqem.dll.vir
deleted: Trojan program Trojan.Win32.Monder.avat File: C:\Qoobox\Quarantine\C\WINDOWS\system32\duictg.dll.vir
deleted: Trojan program Trojan.Win32.Monder.avhg File: C:\Qoobox\Quarantine\C\WINDOWS\system32\eepcfmpr.dll.vir
deleted: Trojan program Trojan.Win32.Monder.avat File: C:\Qoobox\Quarantine\C\WINDOWS\system32\egunlrtl.dll.vir
deleted: Trojan program Trojan.Win32.Monder.avhf File: C:\Qoobox\Quarantine\C\WINDOWS\system32\gjxclxyc.dll.vir
deleted: Trojan program Trojan.Win32.Monder.avat File: C:\Qoobox\Quarantine\C\WINDOWS\system32\gmmaxq.dll.vir
deleted: Trojan program Trojan.Win32.Monder.avbb File: C:\Qoobox\Quarantine\C\WINDOWS\system32\heojtrfw.dll.vir
deleted: Trojan program Trojan.Win32.Monder.avhf File: C:\Qoobox\Quarantine\C\WINDOWS\system32\odjbmyyu.dll.vir
deleted: adware not-a-virus:AdWare.Win32.SuperJuan.hrf File: C:\Qoobox\Quarantine\C\WINDOWS\system32\omkpkfjq.dll.vir
deleted: Trojan program Trojan.Win32.Monder.avau File: C:\Qoobox\Quarantine\C\WINDOWS\system32\ovelebdv.dll.vir
deleted: adware not-a-virus:AdWare.Win32.SuperJuan.hrf File: C:\Qoobox\Quarantine\C\WINDOWS\system32\rsrjon.dll.vir
deleted: Trojan program Trojan.Win32.Monder.avat File: C:\Qoobox\Quarantine\C\WINDOWS\system32\swdtmcsb.dll.vir
deleted: Trojan program Trojan.Win32.Monder.avbb File: C:\Qoobox\Quarantine\C\WINDOWS\system32\tminnq.dll.vir
deleted: Trojan program Trojan.Win32.Monder.avqn File: C:\Qoobox\Quarantine\C\WINDOWS\system32\unfdlnjd.dll.vir
deleted: adware not-a-virus:AdWare.Win32.Agent.kku File: C:\Qoobox\Quarantine\C\WINDOWS\system32\wpv761232809034.cpx.vir//data0002
deleted: adware not-a-virus:AdWare.Win32.SuperJuan.hrf File: C:\Qoobox\Quarantine\C\WINDOWS\system32\xhbkrflg.dll.vir
deleted: adware not-a-virus:AdWare.Win32.SuperJuan.hrf File: C:\Qoobox\Quarantine\C\WINDOWS\system32\yeagxa.dll.vir
deleted: Trojan program Trojan.Win32.Monder.avau File: C:\Qoobox\Quarantine\C\WINDOWS\system32\yijzch.dll.vir
deleted: Trojan program Trojan-Downloader.WMA.GetCodec.c File: C:\RECYCLER\S-1-5-21-1715567821-1547161642-725345543-1003\Dc4.mp3
deleted: adware not-a-virus:AdWare.Win32.VirtualBouncer.j File: C:\TRANSFER\Documents and Settings\Kate\Local Settings\Temp\wrapperouter.exe//WiseSFXDropper//WISE0001.BIN
deleted: Trojan program Trojan-Clicker.HTML.IFrame.bk File: C:\TRANSFER\Documents and Settings\Kate\Local Settings\Temp\Temporary Internet Files\Content.IE5\45YR45QJ\1[1].htm
deleted: Trojan program Trojan-Clicker.HTML.IFrame.bk File: C:\TRANSFER\Documents and Settings\Kate\Local Settings\Temp\Temporary Internet Files\Content.IE5\EI3L1VP7\1[1].htm
deleted: Trojan program Trojan-Clicker.HTML.IFrame.bk File: C:\TRANSFER\Documents and Settings\Kate\Local Settings\Temp\Temporary Internet Files\Content.IE5\O1M3WDU7\1[1].htm
deleted: Trojan program Trojan-Clicker.HTML.IFrame.bk File: C:\TRANSFER\Documents and Settings\Kate\Local Settings\Temporary Internet Files\Content.IE5\3JHFJD8S\1[1].htm
deleted: adware not-a-virus:AdWare.Win32.VirtualBouncer.j File: E:\Documents and Settings\Kate\Local Settings\Temp\wrapperouter.exe//WiseSFXDropper//WISE0001.BIN
deleted: Trojan program Trojan-Clicker.HTML.IFrame.bk File: E:\Documents and Settings\Kate\Local Settings\Temp\Temporary Internet Files\Content.IE5\45YR45QJ\1[1].htm
deleted: Trojan program Trojan-Clicker.HTML.IFrame.bk File: E:\Documents and Settings\Kate\Local Settings\Temp\Temporary Internet Files\Content.IE5\EI3L1VP7\1[1].htm
deleted: Trojan program Trojan-Clicker.HTML.IFrame.bk File: E:\Documents and Settings\Kate\Local Settings\Temp\Temporary Internet Files\Content.IE5\O1M3WDU7\1[1].htm
deleted: Trojan program Trojan-Clicker.HTML.IFrame.bk File: E:\Documents and Settings\Kate\Local Settings\Temporary Internet Files\Content.IE5\3JHFJD8S\1[1].htm
deleted: adware not-a-virus:AdWare.Win32.VirtualBouncer.j File: E:\WINDOWS\temp\wrapperouter.exe//WiseSFXDropper//WISE0001.BIN
deleted: Trojan program Trojan-Clicker.HTML.IFrame.bk File: E:\WINDOWS\temp\Temporary Internet Files\Content.IE5\0HUNSL2B\1[2].htm
deleted: adware not-a-virus:AdWare.Win32.VirtualBouncer.j File: E:\Documents and Settings\Kate\Local Settings\Temp\wrapperouter.exe//WiseSFXDropper
deleted: adware not-a-virus:AdWare.Win32.VirtualBouncer.j File: E:\WINDOWS\temp\wrapperouter.exe//WiseSFXDropper

Also, a new HJT log after the Kaspersky scan:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:40:34 AM, on 2/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox 3 Beta 3\firefox.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: is-011FR.lnk = C:\Documents and Settings\Kate\Desktop\Virus Removal Tool\is-011FR\startup.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.line6.net
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} (Quantum Streaming IE Player Class) - http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

–
End of file - 5374 bytes

Also, can I enable Spybot S&D, SpywareBlaster and avast! now?
New HJT Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:54:17 AM, on 2/13/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Mozilla Firefox 3 Beta 3\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3541147A-29C4-40E8-BAAE-30D71529C686} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O2 - BHO: (no name) - {AC071477-43ED-4A48-A96C-698D4FEBD1C0} - (no file)
O2 - BHO: (no name) - {E3C16394-5010-4B4C-BCC2-CE63B6A92F24} - (no file)
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.line6.net
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} (Quantum Streaming IE Player Class) - http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab
O20 - Winlogon Notify: pmnkHyVn - C:\WINDOWS\
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

–
End of file - 6633 bytes
hello

While TeaTimer is an excellent tool for the prevention of spyware, it can sometimes prevent HijackThis from fixing certain things.
Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your HijackThis log is clean.
  • Open Spybot Search & Destroy.
  • In the Mode menu click "Advanced mode" if not already selected.
  • Choose "Yes" at the Warning prompt.
  • Expand the "Tools" menu.
  • Click "Resident".
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • In the File menu click "Exit" to exit Spybot Search & Destroy.


Fix these with HJT

O2 - BHO: (no name) - {3541147A-29C4-40E8-BAAE-30D71529C686} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O2 - BHO: (no name) - {AC071477-43ED-4A48-A96C-698D4FEBD1C0} - (no file)
O2 - BHO: (no name) - {E3C16394-5010-4B4C-BCC2-CE63B6A92F24} - (no file)
O20 - Winlogon Notify: pmnkHyVn - C:\WINDOWS\


Reboot and post a new HJT Log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI