This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Searching Causes Pop-Ups

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Every time I use a search engine, be it Yahoo!, Google, or just searching for things on sites like YouTube or Imdb. My computer starts acting up and will open two or three windows of different sites. I kept the Program Manager open to see if something new starts up when I do this and it does. But it's so quick I can never get what the .exe is. This is a really frustrating problem, considering the net is nearly impossible to navigate if you can search.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:45:18 AM, on 2/5/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrls.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\psimsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/mail?.intl=us
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0F47B2EB-3ACD-4ECC-9E92-72903E833135} - C:\WINDOWS\system32\ssqrq.dll
O2 - BHO: (no name) - {4140C4CD-7657-359C-5711-5300CAC78BBA} - C:\WINDOWS\system32\afrmxxot.dll
O2 - BHO: (no name) - {42F2CE47-25D8-6E4C-8839-51C07758D1EC} - C:\WINDOWS\system32\xielkrog.dll
O2 - BHO: (no name) - {4CB8F4B4-5F66-4D9E-BC3B-184596A58824} - C:\WINDOWS\system32\jkkljgg.dll
O2 - BHO: Gordon tool - {4D8F81B2-80C9-45B1-9F03-67B2B0D2320B} - C:\WINDOWS\system32\gjavn.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: OIN Analytics - {6B221E01-F517-4959-8C41-81948E7F2F17} - C:\Program Files\OINAnalytics\OINAnalytics2.dll
O2 - BHO: bannerstyle browser optimizer - {81aa3b3b-45b7-e428-ed82-b7a6ef965b39} - C:\WINDOWS\system32\rmipphlowloxuhjx.dll
O2 - BHO: (no name) - {887EA37D-2348-412F-A011-37DDF88F66CE} - (no file)
O2 - BHO: {0d3df31b-5517-5ebb-ad54-d56a04857d98} - {89d75840-a65d-45da-bbe5-7155b13fd3d0} - C:\WINDOWS\system32\phwavs.dll
O2 - BHO: DrFlex IE Helper - {8EEB2711-9D21-4f9c-99A1-B7FC5A8CA56A} - C:\Program Files\QdrDrive\QdrDrive20.dll
O2 - BHO: (no name) - {A6FE4E63-F2A1-463B-92CF-7F6061A19B39} - (no file)
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\lwvbealv.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\lwvbealv.dll
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [LanzarL2007] "C:\DOCUME~1\AARONK~1\LOCALS~1\Temp\{B5CCD7BD-0F24-4DD4-9125-E2A475002832}\{D1DA2BA7-2592-4036-9BB2-DCCABDE8DC1A}\..\..\L2007tmp\Setup.exe" /SETUP:"/l0x0009"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Antivirus 2008\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [{a6755f01-71b0-81c6-cc33-9d19a7fd3a8b}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\rmipphlowloxuhjx.dll" DllStart
O4 - HKLM\..\Run: [0012eed0] rundll32.exe "C:\WINDOWS\system32\pprlfqly.dll",b
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: CallWave.lnk = C:\Program Files\CallWave\IAM.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: phwavs.dll
O23 - Service: DM1Service - OLYMPUS OPTICAL CO.,LTD - C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\gldwxvdl.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrls.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\pavsrv51.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\psimsvc.exe

–
End of file - 6017 bytes
hello

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
OTListIt logfile created on: 2/5/2009 12:15:42 PM - Run
OTListIt2 by OldTimer - Version 2.0.0.5 Folder = C:\Documents and Settings\Margaret Kenney\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.00 Mb Total Physical Memory | 329.18 Mb Available Physical Memory | 64.55% Memory free
1.22 Gb Paging File | 1.10 Gb Available in Paging File | 90.40% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 18.04 Gb Free Space | 24.22% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TOM-SERVO
Current User Name: Margaret Kenney
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrlS.exe (Panda Software International)
C:\Program Files\Panda Security\Panda Antivirus 2008\PsImSvc.exe (Panda Software International)
C:\WINDOWS\SYSTEM32\hkcmd.exe (Intel Corporation)
C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe (Sonic Solutions)
C:\Program Files\Dell\Media Experience\PCMService.exe (CyberLink Corp.)
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe (Dell Computer Corporation)
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe (Dell Computer Corporation)
C:\Documents and Settings\Margaret Kenney\Desktop\OTListIt22.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (6to4 [Auto | Running]) – C:\WINDOWS\SYSTEM32\6to4svc.dll (Microsoft Corporation)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (DM1Service [Auto | Stopped]) – C:\Program Files\Olympus\DeviceDetector\DM1Service.exe (OLYMPUS OPTICAL CO.,LTD)
SRV - (DomainService [Auto | Stopped]) – File not found
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (LexBceS [Auto | Stopped]) – C:\WINDOWS\SYSTEM32\LEXBCES.EXE (Lexmark International, Inc.)
SRV - (Panda Software Controller [Auto | Running]) – C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrlS.exe (Panda Software International)
SRV - (PavPrSrv [Auto | Stopped]) – C:\Program Files\Common Files\Panda Software\PavShld\PavPrSrv.exe (Panda Software)
SRV - (PAVSRV [Auto | Stopped]) – C:\Program Files\Panda Security\Panda Antivirus 2008\PAVSRV51.EXE (Panda Software International)
SRV - (PSIMSVC [Auto | Running]) – C:\Program Files\Panda Security\Panda Antivirus 2008\PsImSvc.exe (Panda Software International)

========== Driver Services (SafeList) ==========

DRV - (aeaudio [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\aeaudio.sys (Andrea Electronics Corporation)
DRV - (AliIde [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\ALIIDE.SYS (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\ASC.SYS (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\ASC3550.SYS (Advanced System Products, Inc.)
DRV - (ati2mtag [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (bcm4sbxp [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\CMDIDE.SYS (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\DAC2W2K.SYS (Mylex Corporation)
DRV - (drvmcdb [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm [Auto | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\drvnddm.sys (Sonic Solutions)
DRV - (EL90XBC [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)
DRV - (FileDisk [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\filedisk.sys (iolo technologies, LLC (based on original work by Bo Brantén))
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HSFHWBS2 [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSF_DP [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (i81x [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (iAimFP0 [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)
DRV - (iAimFP1 [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)
DRV - (iAimFP2 [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)
DRV - (iAimFP3 [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)
DRV - (iAimFP4 [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)
DRV - (iAimTV0 [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)
DRV - (iAimTV1 [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)
DRV - (iAimTV3 [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)
DRV - (iAimTV4 [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\MRAID35X.SYS (American Megatrends Inc.)
DRV - (nm [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\nmnt.sys (Microsoft Corporation)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (omci [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (PavProc [Auto | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\PavProc.sys (Panda Software International)
DRV - (pfc [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\pfc.sys (Padus, Inc.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\pxhelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\QL1080.SYS (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\QL12160.SYS (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\QL1280.SYS (QLogic Corporation)
DRV - (SCDEmu [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\scdemu.sys (PowerISO Computing, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\SECDRV.SYS ()
DRV - (ShldDrv [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\ShlDrv51.sys (Panda Software)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (smwdm [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\smwdm.sys (Analog Devices, Inc.)
DRV - (SONYPVU1 [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\SONYPVU1.SYS (Sony Corporation)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\SPARROW.SYS (Adaptec, Inc.)
DRV - (sscdbhk5 [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\ssrtln.sys (Sonic Solutions)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\SYMC810.SYS (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\SYMC8XX.SYS (LSI Logic)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\SYM_HI.SYS (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\SYM_U3.SYS (LSI Logic)
DRV - (Tcpip6 [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\tcpip6.sys (Microsoft Corporation)
DRV - (tfsnboio [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsncofs [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsndrct [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsndres.sys (Sonic Solutions)
DRV - (tfsnifs [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsnopio [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsnudf [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnudfa [Auto | Running]) – C:\WINDOWS\SYSTEM32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tunmp [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\tunmp.sys (Microsoft Corporation)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\ULTRA.SYS (Promise Technology, Inc.)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (WS2IFSL [System | Running]) – C:\WINDOWS\SYSTEM32\DRIVERS\WS2IFSL.SYS (Microsoft Corporation)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) – C:\WINDOWS\SYSTEM32\DRIVERS\ialmkchw.sys (Intel Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/mail?.intl=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O1 HOSTS File: (736 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {4140C4CD-7657-359C-5711-5300CAC78BBA} - C:\WINDOWS\SYSTEM32\afrmxxot.dll ()
O2 - BHO: (no name) - {42F2CE47-25D8-6E4C-8839-51C07758D1EC} - C:\WINDOWS\SYSTEM32\xielkrog.dll ()
O2 - BHO: (no name) - {4CB8F4B4-5F66-4D9E-BC3B-184596A58824} - C:\WINDOWS\SYSTEM32\jkkljgg.dll ()
O2 - BHO: (Gordon tool) - {4D8F81B2-80C9-45B1-9F03-67B2B0D2320B} - C:\WINDOWS\SYSTEM32\gjavn.dll ()
O2 - BHO: () - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (OIN Analytics) - {6B221E01-F517-4959-8C41-81948E7F2F17} - C:\Program Files\OINAnalytics\OINAnalytics2.dll ()
O2 - BHO: (bannerstyle browser optimizer) - {81aa3b3b-45b7-e428-ed82-b7a6ef965b39} - C:\WINDOWS\SYSTEM32\rmipphlowloxuhjx.dll ( )
O2 - BHO: (no name) - {887EA37D-2348-412F-A011-37DDF88F66CE} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {89d75840-a65d-45da-bbe5-7155b13fd3d0} - C:\WINDOWS\SYSTEM32\phwavs.dll ()
O2 - BHO: (DrFlex IE Helper) - {8EEB2711-9D21-4f9c-99A1-B7FC5A8CA56A} - C:\Program Files\QdrDrive\QdrDrive20.dll ()
O2 - BHO: (no name) - {93A6AE09-42F0-4B38-8198-7972AFE25E88} - C:\WINDOWS\SYSTEM32\ssqrq.dll ()
O2 - BHO: (no name) - {A6FE4E63-F2A1-463B-92CF-7F6061A19B39} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\SYSTEM32\lwvbealv.dll ()
O2 - BHO: (no name) - SOFTWARE - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKLM\..\Toolbar: (Security Toolbar) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\SYSTEM32\lwvbealv.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\SYSTEM32\lwvbealv.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key does not exist or could not be opened. File not found
O4 - HKLM..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe (Google Inc.)
O4 - HKLM..\Run: [{a6755f01-71b0-81c6-cc33-9d19a7fd3a8b}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\rmipphlowloxuhjx.dll" DllStart ( )
O4 - HKLM..\Run: [0012eed0] rundll32.exe "C:\WINDOWS\system32\pprlfqly.dll",b ()
O4 - HKLM..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Antivirus 2008\APVXDWIN.EXE" /s (Panda Software International)
O4 - HKLM..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe" (Dell Computer Corporation)
O4 - HKLM..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [LanzarL2007] "C:\DOCUME~1\AARONK~1\LOCALS~1\Temp\{B5CCD7BD-0F24-4DD4-9125-E2A475002832}\{D1DA2BA7-2592-4036-9BB2-DCCABDE8DC1A}\..\..\L2007tmp\Setup.exe" /SETUP:"/l0x0009" File not found
O4 - HKLM..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKCU..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl File not found
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [Sonic RecordNow!] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CallWave.lnk = C:\Program Files\CallWave\IAM.exe (CallWave, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key does not exist or could not be opened. File not found
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll (Panda Software International)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: ([]msn in My Computer)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_05)
O16 - DPF: {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_05)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (phwavs.dll) - C:\WINDOWS\SYSTEM32\phwavs.dll ()
O20 - Winlogon\Notify\avldr: DllName - avldr.dll - C:\WINDOWS\SYSTEM32\avldr.dll (Panda Software International)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\SYSTEM32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\jkkljgg: DllName - jkkljgg.dll - C:\WINDOWS\SYSTEM32\jkkljgg.dll ()
O20 - Winlogon\Notify\lwvbealv: DllName - lwvbealv.dll - C:\WINDOWS\SYSTEM32\lwvbealv.dll ()
O20 - Winlogon\Notify\mllmm: DllName - Reg Error: Value DLLName does not exist or could not be read. - File not found
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {4CB8F4B4-5F66-4D9E-BC3B-184596A58824} - C:\WINDOWS\SYSTEM32\jkkljgg.dll ()
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\ssqrq.dll) - C:\WINDOWS\SYSTEM32\ssqrq.dll ()
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1

========== Files/Folders - Created Within 30 Days ==========

[2009/02/05 12:14:34 | 00,487,424 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Margaret Kenney\Desktop\OTListIt22.exe
[2009/02/05 03:45:13 | 00,001,734 | —- | C] () – C:\Documents and Settings\Margaret Kenney\Desktop\HijackThis.lnk
[2009/02/05 03:45:13 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/02/05 03:45:04 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Margaret Kenney\Desktop\HJTInstall.exe
[2009/02/05 03:26:41 | 01,536,827 | -HS- | C] () – C:\WINDOWS\System32\ylqflrpp.ini
[2009/02/05 03:26:38 | 00,085,056 | —- | C] () – C:\WINDOWS\System32\pprlfqly.dll
[2009/02/05 03:17:03 | 00,000,000 | —D | C] – C:\Program Files\Hijackthis
[2009/02/05 03:16:47 | 00,488,144 | —- | C] (Soeperman Enterprises Ltd ) – C:\Documents and Settings\Margaret Kenney\Desktop\HJTsetup.exe
[2009/02/05 02:52:11 | 00,123,456 | —- | C] () – C:\WINDOWS\System32\phwavs.dll
[2009/02/05 02:52:10 | 00,123,456 | —- | C] () – C:\WINDOWS\System32\nsnynyvq.dll
[2009/01/30 03:57:22 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/01/30 03:57:22 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/01/30 03:04:21 | 01,483,063 | -HS- | C] () – C:\WINDOWS\System32\bjmfmpjq.ini
[2009/01/30 03:04:18 | 00,085,056 | —- | C] () – C:\WINDOWS\System32\qjpmfmjb.dll
[2009/01/30 03:04:15 | 00,122,432 | —- | C] () – C:\WINDOWS\System32\xtctyq.dll
[2009/01/30 03:04:14 | 00,122,432 | —- | C] () – C:\WINDOWS\System32\ilxpfamg.dll

========== Files - Modified Within 30 Days ==========

[2009/02/05 12:14:34 | 00,487,424 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Margaret Kenney\Desktop\OTListIt22.exe
[2009/02/05 12:09:35 | 00,460,344 | -HS- | M] () – C:\WINDOWS\System32\qrqss.ini2
[2009/02/05 12:09:34 | 00,460,344 | -HS- | M] () – C:\WINDOWS\System32\qrqss.ini
[2009/02/05 12:09:31 | 00,020,810 | -HS- | M] () – C:\WINDOWS\System32\lwvbealv.dllbox
[2009/02/05 05:00:19 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/05 04:59:57 | 00,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2009/02/05 04:59:48 | 53,484,3392 | -HS- | M] () – C:\hiberfil.sys
[2009/02/05 04:59:00 | 04,312,026 | -H– | M] () – C:\Documents and Settings\Margaret Kenney\Local Settings\Application Data\IconCache.db
[2009/02/05 04:55:49 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/02/05 03:45:13 | 00,001,734 | —- | M] () – C:\Documents and Settings\Margaret Kenney\Desktop\HijackThis.lnk
[2009/02/05 03:45:05 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Margaret Kenney\Desktop\HJTInstall.exe
[2009/02/05 03:26:52 | 01,536,827 | -HS- | M] () – C:\WINDOWS\System32\ylqflrpp.ini
[2009/02/05 03:26:39 | 00,085,056 | —- | M] () – C:\WINDOWS\System32\pprlfqly.dll
[2009/02/05 03:16:48 | 00,488,144 | —- | M] (Soeperman Enterprises Ltd ) – C:\Documents and Settings\Margaret Kenney\Desktop\HJTsetup.exe
[2009/02/05 02:52:11 | 00,123,456 | —- | M] () – C:\WINDOWS\System32\phwavs.dll
[2009/02/05 02:52:11 | 00,123,456 | —- | M] () – C:\WINDOWS\System32\nsnynyvq.dll
[2009/02/02 18:19:00 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/01/30 03:57:22 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/01/30 03:04:24 | 01,483,063 | -HS- | M] () – C:\WINDOWS\System32\bjmfmpjq.ini
[2009/01/30 03:04:18 | 00,085,056 | —- | M] () – C:\WINDOWS\System32\qjpmfmjb.dll
[2009/01/30 03:04:15 | 00,122,432 | —- | M] () – C:\WINDOWS\System32\xtctyq.dll
[2009/01/30 03:04:15 | 00,122,432 | —- | M] () – C:\WINDOWS\System32\ilxpfamg.dll
[2009/01/29 22:45:11 | 00,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL

========== LOP Check ==========

[2008/09/03 01:39:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data
[2004/05/14 20:45:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/01/30 23:50:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2008/01/10 09:24:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2008/01/18 12:03:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2005/04/20 22:20:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Dell
[2004/05/26 21:08:54 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Dpi
[2008/01/14 19:12:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2008/07/03 22:23:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GRETECH
[2005/04/19 23:52:36 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2008/04/19 10:44:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2008/09/03 01:39:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ludia
[2006/09/22 18:00:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2007/11/29 23:48:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2007/02/05 10:56:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall
[2008/05/20 19:55:13 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2004/05/10 18:22:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2004/05/26 20:37:51 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\pcsvc
[2004/05/04 10:51:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2004/05/04 10:22:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2008/08/21 02:19:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/09/03 18:41:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2004/10/26 19:40:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2008/04/26 01:46:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/06/10 13:04:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/01/02 02:32:53 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Margaret Kenney\Application Data
[2008/04/30 13:51:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Adobe
[2008/03/21 01:45:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\AdobeUM
[2004/10/20 03:31:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Aim
[2007/02/12 16:21:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Apple Computer
[2004/05/22 21:34:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Corel
[2009/01/02 02:35:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\DVD Profiler
[2006/11/02 08:30:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Google
[2008/08/13 02:42:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\GRETECH
[2005/04/19 23:53:11 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Gtek
[2008/03/27 18:56:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Help
[2004/05/04 10:22:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Identities
[2004/05/04 10:54:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Jasc Software Inc
[2008/09/03 01:39:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Ludia
[2004/10/20 03:11:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Macromedia
[2004/05/12 14:32:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\McAfee.com Personal Firewall
[2004/11/13 11:35:19 | 00,000,000 | –SD | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Microsoft
[2007/09/20 11:46:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Mozilla
[2006/09/17 22:35:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\MSN6
[2007/02/24 04:46:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\MySpace
[2004/05/10 14:05:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Real
[2008/11/12 20:23:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Sonic
[2004/05/04 10:44:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Margaret Kenney\Application Data\Sun
[2009/02/02 18:19:00 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2002/08/29 05:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\DESKTOP.INI
[2009/02/05 05:00:19 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

[2008/01/28 19:55:02 | 00,000,000 | —D | M] – C:\Program Files\Outerinfo
[2008/01/28 19:55:02 | 00,000,000 | —D | M] – C:\Program Files\Outerinfo\FF
[2008/07/12 02:41:25 | 00,000,000 | —D | M] – C:\Program Files\ѕecurity
** - C:\Program Files\?ecurity
[2008/11/04 21:39:49 | 00,000,000 | —D | M] – C:\Program Files\ѕecurity\ѕecurity
** - C:\Program Files\?ecurity\?ecurity

========== Alternate Data Streams ==========

@Alternate Data Stream - 127 bytes -> %AllUsersProfile%\Application Data\TEMP:5B85C37B
@Alternate Data Stream - 0 bytes -> %SystemRoot%\Thumbs.db:encryptable
< End of report >

—————————————————————————————————————————————————————–


OTListIt Extras logfile created on: 2/5/2009 12:15:42 PM - Run
OTListIt2 by OldTimer - Version 2.0.0.5 Folder = C:\Documents and Settings\Margaret Kenney\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.00 Mb Total Physical Memory | 329.18 Mb Available Physical Memory | 64.55% Memory free
1.22 Gb Paging File | 1.10 Gb Available in Paging File | 90.40% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 18.04 Gb Free Space | 24.22% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TOM-SERVO
Current User Name: Margaret Kenney
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
"DisableMonitoring" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger (America Online, Inc.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe:*:Enabled:LimeWire: The most advanced file sharing program on the planet. File not found
C:\Program Files\Hello\Hello.exe:*:Enabled:Hello! File not found
C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealOne Player File not found
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger File not found
C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server File not found
C:\Program Files\HangStan Trivia\HangStanTrivia.exe:*:Disabled:Hang Stan File not found
C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire File not found
C:\WINDOWS\SYSTEM32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test (Microsoft Corporation)
C:\WINDOWS\SYSTEM32\rundll32.exe:*:Enabled:Run a DLL as an App (Microsoft Corporation)
C:\Program Files\BitSpirit\BitSpirit.exe:*:Enabled:The powerful and easy-to-use BitTorrent Client File not found
C:\Program Files\WinAntiVirus Pro 2006\Updater.exe:*:Enabled:updater.exe File not found
C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger (America Online, Inc.)
C:\Program Files\Last.fm\LastFM.exe:*:Enabled:Last.fm File not found
C:\Tcl\bin\wish85.exe:*:Enabled:Wish Application File not found
C:\WINDOWS\SYSTEM32\LEXPPS.EXE:*:Enabled:LEXPPS.EXE (Lexmark International, Inc.)
C:\Program Files\CallWave\IAM.exe:*:Enabled:CallWave (CallWave, Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" = Google Gmail Notifier
"{04410044-9149-45C6-A806-F2BF9CFCE762}" = Microsoft Encarta Encyclopedia Standard 2004
"{0F756CD9-4A1E-409B-B101-601DDC4C03AA}" = Qualxserve Service Agreement
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Dell Media Experience
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{54F90B55-BEB3-4F0D-8802-228822FA5921}" = WordPerfect Office 11
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68D60342-7686-45C9-B8EB-40EF843D0460}" = Dell Networking Guide
"{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2
"{7148F0A8-6813-11D6-A77B-00B0D0142050}" = Java 2 Runtime Environment, SE v1.4.2_05
"{76E6BBAA-25E6-4BFC-9613-75A5CACE2940}" = Olympus
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-114767253}" = The Price is Right
"{89EE857B-8970-4F9F-AB58-A1C873AC72B3}" = Broadcom Management Programs
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{98DF85D9-96C0-4F57-A92E-C3539477EF5E}" = DVDSentry
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{BFD96B89-B769-4CD6-B11E-E79FFD46F067}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC000127-5E5D-4A1C-90CB-EEAAAC1E3AC0}" = Jasc Paint Shop Photo Album
"{D1DA2BA7-2592-4036-9BB2-DCCABDE8DC1A}" = Panda Antivirus 2008
"{EE7C3A14-1D20-49F6-B903-491561076F0F}" = ArcSoft Software Suite
"{FC4ED75D-916C-4A8C-BB67-3C6F6E06D62B}" = Banctec Service Agreement
"Ad-aware 6 Personal" = Ad-aware 6 Personal
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AOL Instant Messenger" = AOL Instant Messenger
"bannerstyle" = Enhancement Browser Tools Bannerstyle
"CallWave" = CallWave
"CCleaner" = CCleaner (remove only)
"CNXT_MODEM_PCI_VEN_14F1&DEV_2702" = Conexant SmartHSFi V.9x 56K DF PCI Modem
"Dell AIO Printer A920" = Dell AIO Printer A920
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"GOM Player" = GOM Player
"HijackThis" = HijackThis 2.0.2
"Hijackthis_is1" = Hijackthis 1.99.1
"iCheck" = Internet Speed Monitor
"InstallShield_{89EE857B-8970-4F9F-AB58-A1C873AC72B3}" = Broadcom Management Programs
"InterActual Player" = InterActual Player
"intexp" = TopFiveSearch.com Search Assistant
"InvelosDVDProfiler_is1" = DVD Profiler Version 3.1.1
"Mozilla Firefox (3.0.3)" = Mozilla Firefox (3.0.3)
"OINAnalytics" = OIN Analytics
"Outerinfo" = Outerinfo
"PCFriendly" = PCFriendly
"Plasma Pong_is1" = Plasma Pong v1.3b
"PodUtil_is1" = PodUtil 3.0.2
"PowerISO" = PowerISO
"Shockwave" = Shockwave
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.3
"System Mechanic Professional 6_is1" = iolo technologies' System Mechanic Professional 6
"Windows XP Service Pack" = Windows XP Service Pack 2
"WinRAR archiver" = WinRAR archiver

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/28/2008 3:13:18 PM | Computer Name = TOM-SERVO | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module ntdll.dll, version 5.1.2600.2180, fault address 0x00001010.

Error - 12/31/2008 11:55:10 PM | Computer Name = TOM-SERVO | Source = Application Hang | ID = 1002
Description = Hanging application QuickTimePlayer.exe, version 7.4.1.14, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/2/2009 3:23:34 AM | Computer Name = TOM-SERVO | Source = Application Hang | ID = 1002
Description = Hanging application dvdpro.exe, version 3.1.1.1171, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 1/2/2009 9:15:49 AM | Computer Name = TOM-SERVO | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module ntdll.dll, version 5.1.2600.2180, fault address 0x0003426d.

Error - 1/2/2009 9:15:56 AM | Computer Name = TOM-SERVO | Source = Application Error | ID = 1001
Description = Fault bucket 127913559.

Error - 1/2/2009 9:22:06 AM | Computer Name = TOM-SERVO | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.2180, faulting
module ntdll.dll, version 5.1.2600.2180, fault address 0x0003426d.

Error - 1/15/2009 10:26:33 PM | Computer Name = TOM-SERVO | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3188, faulting module
unknown, version 0.0.0.0, fault address 0x058812c8.

Error - 1/20/2009 3:16:33 AM | Computer Name = TOM-SERVO | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3188, faulting module
ssqrq.dll, version 0.0.0.0, fault address 0x000282a0.

Error - 1/30/2009 2:10:43 AM | Computer Name = TOM-SERVO | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3188, faulting module
ssqrq.dll, version 0.0.0.0, fault address 0x000282a0.

Error - 1/31/2009 4:39:57 AM | Computer Name = TOM-SERVO | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.0.3188, faulting module
ssqrq.dll, version 0.0.0.0, fault address 0x000282a0.

[ System Events ]
Error - 2/4/2009 3:19:33 AM | Computer Name = TOM-SERVO | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
vspf vspf_hk

Error - 2/5/2009 6:00:40 AM | Computer Name = TOM-SERVO | Source = Service Control Manager | ID = 7003
Description = The Panda anti-virus service service depends on the following nonexistent
service: PavDrv

Error - 2/5/2009 6:00:40 AM | Computer Name = TOM-SERVO | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the LexBce Server service
to connect.

Error - 2/5/2009 6:00:41 AM | Computer Name = TOM-SERVO | Source = Service Control Manager | ID = 7000
Description = The LexBce Server service failed to start due to the following error:
%%1053

Error - 2/5/2009 6:00:41 AM | Computer Name = TOM-SERVO | Source = Service Control Manager | ID = 7001
Description = The Print Spooler service depends on the LexBce Server service which
failed to start because of the following error: %%1053

Error - 2/5/2009 6:00:41 AM | Computer Name = TOM-SERVO | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the DM1Service service to
connect.

Error - 2/5/2009 6:00:41 AM | Computer Name = TOM-SERVO | Source = Service Control Manager | ID = 7000
Description = The DM1Service service failed to start due to the following error:
%%1053

Error - 2/5/2009 6:00:41 AM | Computer Name = TOM-SERVO | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Panda Process Protection
Service service to connect.

Error - 2/5/2009 6:00:41 AM | Computer Name = TOM-SERVO | Source = Service Control Manager | ID = 7000
Description = The Panda Process Protection Service service failed to start due to
the following error: %%1053

Error - 2/5/2009 6:00:44 AM | Computer Name = TOM-SERVO | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
vspf vspf_hk


< End of report >
hello


Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    SRV - (DomainService [Auto | Stopped]) – File not found
    O2 - BHO: (no name) - {4140C4CD-7657-359C-5711-5300CAC78BBA} - C:\WINDOWS\SYSTEM32\afrmxxot.dll ()
    O2 - BHO: (no name) - {42F2CE47-25D8-6E4C-8839-51C07758D1EC} - C:\WINDOWS\SYSTEM32\xielkrog.dll ()
    O2 - BHO: (no name) - {4CB8F4B4-5F66-4D9E-BC3B-184596A58824} - C:\WINDOWS\SYSTEM32\jkkljgg.dll ()
    O2 - BHO: (Gordon tool) - {4D8F81B2-80C9-45B1-9F03-67B2B0D2320B} - C:\WINDOWS\SYSTEM32\gjavn.dll ()
    O2 - BHO: (OIN Analytics) - {6B221E01-F517-4959-8C41-81948E7F2F17} - C:\Program Files\OINAnalytics\OINAnalytics2.dll ()
    O2 - BHO: (bannerstyle browser optimizer) - {81aa3b3b-45b7-e428-ed82-b7a6ef965b39} - C:\WINDOWS\SYSTEM32\rmipphlowloxuhjx.dll ( )
    O2 - BHO: (no name) - {887EA37D-2348-412F-A011-37DDF88F66CE} - Reg Error: Key does not exist or could not be opened. File not found
    O2 - BHO: (no name) - {89d75840-a65d-45da-bbe5-7155b13fd3d0} - C:\WINDOWS\SYSTEM32\phwavs.dll ()
    O2 - BHO: (DrFlex IE Helper) - {8EEB2711-9D21-4f9c-99A1-B7FC5A8CA56A} - C:\Program Files\QdrDrive\QdrDrive20.dll ()
    O2 - BHO: (no name) - {93A6AE09-42F0-4B38-8198-7972AFE25E88} - C:\WINDOWS\SYSTEM32\ssqrq.dll ()
    O2 - BHO: (no name) - {A6FE4E63-F2A1-463B-92CF-7F6061A19B39} - Reg Error: Key does not exist or could not be opened. File not found
    O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\SYSTEM32\lwvbealv.dll ()
    O2 - BHO: (no name) - SOFTWARE - Reg Error: Key does not exist or could not be opened. File not found
    O3 - HKLM\..\Toolbar: (Security Toolbar) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\SYSTEM32\lwvbealv.dll ()
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\SYSTEM32\lwvbealv.dll ()
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key does not exist or could not be opened. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key does not exist or could not be opened. File not found
    O4 - HKLM..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe (Google Inc.)
    O4 - HKLM..\Run: [{a6755f01-71b0-81c6-cc33-9d19a7fd3a8b}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\rmipphlowloxuhjx.dll" DllStart ( )
    O4 - HKLM..\Run: [0012eed0] rundll32.exe "C:\WINDOWS\system32\pprlfqly.dll",b ()
    O4 - HKLM..\Run: [LanzarL2007] "C:\DOCUME~1\AARONK~1\LOCALS~1\Temp\{B5CCD7BD-0F24-4DD4-9125-E2A475002832}\{D1DA2BA7-2592-4036-9BB2-DCCABDE8DC1A}\..\..\L2007tmp\Setup.exe" /SETUP:"/l0x0009" File not found
    O20 - AppInit_DLLs: (phwavs.dll) - C:\WINDOWS\SYSTEM32\phwavs.dll ()
    O20 - Winlogon\Notify\jkkljgg: DllName - jkkljgg.dll - C:\WINDOWS\SYSTEM32\jkkljgg.dll ()
    O20 - Winlogon\Notify\lwvbealv: DllName - lwvbealv.dll - C:\WINDOWS\SYSTEM32\lwvbealv.dll ()
    O20 - Winlogon\Notify\mllmm: DllName - Reg Error: Value DLLName does not exist or could not be read. - File not found
    O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - File not found
    O28 - HKLM ShellExecuteHooks: {4CB8F4B4-5F66-4D9E-BC3B-184596A58824} - C:\WINDOWS\SYSTEM32\jkkljgg.dll ()
    O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\ssqrq.dll) - C:\WINDOWS\SYSTEM32\ssqrq.dll ()
    [2009/02/05 03:26:41 | 01,536,827 | -HS- | C] () – C:\WINDOWS\System32\ylqflrpp.ini
    [2009/02/05 03:26:38 | 00,085,056 | —- | C] () – C:\WINDOWS\System32\pprlfqly.dll
    [2009/02/05 02:52:11 | 00,123,456 | —- | C] () – C:\WINDOWS\System32\phwavs.dll
    [2009/02/05 02:52:10 | 00,123,456 | —- | C] () – C:\WINDOWS\System32\nsnynyvq.dll
    [2009/01/30 03:04:21 | 01,483,063 | -HS- | C] () – C:\WINDOWS\System32\bjmfmpjq.ini
    [2009/01/30 03:04:18 | 00,085,056 | —- | C] () – C:\WINDOWS\System32\qjpmfmjb.dll
    [2009/01/30 03:04:15 | 00,122,432 | —- | C] () – C:\WINDOWS\System32\xtctyq.dll
    [2009/01/30 03:04:14 | 00,122,432 | —- | C] () – C:\WINDOWS\System32\ilxpfamg.dll
    [2009/02/05 12:09:35 | 00,460,344 | -HS- | M] () – C:\WINDOWS\System32\qrqss.ini2
    [2009/02/05 12:09:34 | 00,460,344 | -HS- | M] () – C:\WINDOWS\System32\qrqss.ini
    [2009/02/05 12:09:31 | 00,020,810 | -HS- | M] () – C:\WINDOWS\System32\lwvbealv.dllbox
    [2009/02/05 03:26:52 | 01,536,827 | -HS- | M] () – C:\WINDOWS\System32\ylqflrpp.ini
    [2009/02/05 03:26:39 | 00,085,056 | —- | M] () – C:\WINDOWS\System32\pprlfqly.dll
    [2009/02/05 02:52:11 | 00,123,456 | —- | M] () – C:\WINDOWS\System32\phwavs.dll
    [2009/02/05 02:52:11 | 00,123,456 | —- | M] () – C:\WINDOWS\System32\nsnynyvq.dll
    [2009/01/30 03:04:24 | 01,483,063 | -HS- | M] () – C:\WINDOWS\System32\bjmfmpjq.ini
    [2009/01/30 03:04:18 | 00,085,056 | —- | M] () – C:\WINDOWS\System32\qjpmfmjb.dll
    [2009/01/30 03:04:15 | 00,122,432 | —- | M] () – C:\WINDOWS\System32\xtctyq.dll
    [2009/01/30 03:04:15 | 00,122,432 | —- | M] () – C:\WINDOWS\System32\ilxpfamg.dll
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the box beside LOP Check this time )
Doesn't say where it locks up does it ?

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.
ComboFix 09-02-06.01 - Margaret Kenney 2009-02-06 14:45:33.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.174 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Panda Antivirus 2008 *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Aaron Kenney\Application Data\SpeedRunner
c:\documents and settings\Aaron Kenney\Application Data\SpeedRunner\config.cfg
c:\documents and settings\Aaron Kenney\Application Data\SpeedRunner\SpeedRunner.exe
c:\documents and settings\Aaron Kenney\Application Data\SpeedRunner\SRUninstall.exe
c:\documents and settings\Aaron Kenney\Application Data\WinAntiVirus Pro 2006
c:\documents and settings\Aaron Kenney\Application Data\WinAntiVirus Pro 2006\Logs\update.log
c:\documents and settings\Aaron Kenney\Application Data\WinAntiVirus Pro 2006\Logs\wa6Support.log
c:\documents and settings\Aaron Kenney\Application Data\WinAntiVirus Pro 2006\Logs\winav.log
c:\documents and settings\Aaron Kenney\Application Data\WinAntiVirus Pro 2006\PGE.dat
c:\documents and settings\Aaron Kenney\Application Data\YMANTE~1
c:\documents and settings\Aaron Kenney\Favorites\Online Security Guide.lnk
c:\documents and settings\Aaron Kenney\My Documents\ASKS~1
c:\documents and settings\Aaron Kenney\My Documents\ASKS~1\w?auclt.exe
c:\documents and settings\Aaron Kenney\Start Menu\Programs\Outerinfo
c:\documents and settings\Aaron Kenney\Start Menu\Programs\Outerinfo\Terms.lnk
c:\documents and settings\Aaron Kenney\Start Menu\Programs\Outerinfo\Uninstall.lnk
c:\documents and settings\Administrator\Favorites\Online Security Guide.lnk
c:\documents and settings\Margaret Kenney\Favorites\Online Security Guide.lnk
c:\documents and settings\William Kenney\Application Data\SpeedRunner
c:\documents and settings\William Kenney\Application Data\SpeedRunner\config.cfg
c:\documents and settings\William Kenney\Application Data\SpeedRunner\SpeedRunner.exe
c:\documents and settings\William Kenney\Application Data\SpeedRunner\SRUninstall.exe
C:\Documents
c:\program files\AntiSpywareMaster
c:\program files\AntiSpywareMaster\asm.exe
c:\program files\Common Files\companion wizard
c:\program files\Common Files\Yazzle1281OinAdmin.exe
c:\program files\Common Files\Yazzle1281OinUninstaller.exe
c:\program files\Dot1XCfg
c:\program files\Dot1XCfg\Dot1XCfg.exe
c:\program files\ecurit~1
c:\program files\ecurit~1\?ecurity\
c:\program files\ecurit~1\logonui.exe
c:\program files\GetModule
c:\program files\GetModule\dicik.gz
c:\program files\GetModule\GetModule23.exe
c:\program files\GetModule\kwdik.gz
c:\program files\GetPack
c:\program files\GetPack\dianeadupd.exe
c:\program files\GetPack\dictame.gz
c:\program files\GetPack\gastroupd.exe
c:\program files\GetPack\GetPack19.exe
c:\program files\GetPack\GetPack20.exe
c:\program files\GetPack\GetPack21.exe
c:\program files\GetPack\GetPack22.exe
c:\program files\GetPack\trgtame.gz
c:\program files\iCheck
c:\program files\iCheck\iCheck.exe
c:\program files\iCheck\Uninstall.exe
c:\program files\inetget2
c:\program files\ISM
c:\program files\ISM\ISMModule3.exe
c:\program files\Mjcore
c:\program files\Mjcore\Mjcore.dll
c:\program files\outerinfo
c:\program files\outerinfo\FF\chrome.manifest
c:\program files\outerinfo\FF\components\FF.dll
c:\program files\outerinfo\FF\components\OuterinfoAds.xpt
c:\program files\outerinfo\FF\install.rdf
c:\program files\outerinfo\Terms.rtf
c:\program files\QdrDrive
c:\program files\QdrDrive\QdrDrive20.dll
c:\program files\QdrDrive\qdrloader.exe
c:\program files\Sakora
c:\program files\Sakora\Sakora.exe
c:\program files\Temporary
c:\program files\Temporary\kernInst.exe
c:\program files\Temporary\wininstall.exe
c:\temp\abW9
c:\windows\17PHolmes572.exe
c:\windows\b103.exe
c:\windows\b104.exe.bin
c:\windows\b116.exe
c:\windows\b122.exe
c:\windows\b138.exe.bin
c:\windows\b147.exe
c:\windows\b148.exe
c:\windows\b149.exe.bin
c:\windows\b151.exe
c:\windows\b152.exe
c:\windows\b155.exe
c:\windows\b156.exe
c:\windows\b157.exe
c:\windows\b158.exe
c:\windows\BM0321dd4c.txt
c:\windows\BM0321dd4c.xml
c:\windows\cookies.ini
c:\windows\k.txt
c:\windows\mrofinu572.exe
c:\windows\pskt.ini
c:\windows\system32\a.exe
c:\windows\system32\accdd.ini
c:\windows\SYSTEM32\accdd.ini2
c:\windows\system32\adbblcbv.ini
c:\windows\system32\ahheciwc.ini
c:\windows\system32\akihpxnd.ini
c:\windows\system32\anfmqigh.ini
c:\windows\system32\autnfkyw.ini
c:\windows\system32\auueffdw.ini
c:\windows\system32\awvts.dll
c:\windows\system32\awvvs.dll
c:\windows\system32\awvvv.dll
c:\windows\SYSTEM32\aycdd.ini
c:\windows\SYSTEM32\aycdd.ini2
c:\windows\system32\basybjmo.ini
c:\windows\system32\bdejdvtk.ini
c:\windows\system32\bfoyntkl.ini
c:\windows\system32\bgkgettt.ini
c:\windows\system32\bhkklorm.ini
c:\windows\system32\bjmfmpjq.ini
c:\windows\system32\buvivcru.ini
c:\windows\system32\bycnjvci.ini
c:\windows\system32\ccnbidaj.ini
c:\windows\system32\cfhkj.ini
c:\windows\system32\cfhkj.ini2
c:\windows\system32\cgspvpnw.ini
c:\windows\system32\cmhrgfex.ini
c:\windows\system32\cnlhvcbd.ini
c:\windows\system32\cnourbts.ini
c:\windows\system32\comrepl.exe
c:\windows\system32\cvikmfwr.ini
c:\windows\system32\cxquuuqq.ini
c:\windows\system32\cyvgprax.ini
c:\windows\system32\ddtodsht.ini
c:\windows\system32\degvgwuj.ini
c:\windows\system32\deoplulq.ini
c:\windows\system32\djlcjpwp.ini
c:\windows\system32\dnrksbsd.ini
c:\windows\system32\drivers\fad.sys
c:\windows\system32\dstooglu.ini
c:\windows\system32\dumphive.exe
c:\windows\system32\dwdwxnvu.ini
c:\windows\system32\dwueqkhs.ini
c:\windows\system32\dyqpgbqv.ini
c:\windows\system32\eawqdqsd.ini
c:\windows\system32\ecxoowgf.ini
c:\windows\system32\edhntlam.ini
c:\windows\system32\fcolbsej.ini
c:\windows\system32\fhiefwym.ini
c:\windows\system32\fitjvlqd.ini
c:\windows\system32\fpwaoc.dll
c:\windows\system32\fqeqwteg.ini
c:\windows\system32\fryyaiax.ini
c:\windows\system32\######.exe
c:\windows\system32\fvxjhuwj.ini
c:\windows\system32\fyvoqrvo.ini
c:\windows\system32\gahmhdus.ini
c:\windows\SYSTEM32\ghhkj.ini2
c:\windows\system32\gilonjjo.ini
c:\windows\system32\gjavn.dll
c:\windows\system32\gjqulqnm.ini
c:\windows\system32\gjwmgtia.ini
c:\windows\system32\gnafiqrn.ini
c:\windows\system32\gsbjbvtj.ini
c:\windows\system32\gwoduiyy.dll
c:\windows\system32\hdgclxnp.ini
c:\windows\SYSTEM32\hhhkj.ini
c:\windows\SYSTEM32\hhhkj.ini2
c:\windows\system32\hisprwit.ini
c:\windows\system32\hjbikemn.ini
c:\windows\system32\hkavmlck.ini
c:\windows\system32\hkybksqy.ini
c:\windows\system32\hoginwho.ini
c:\windows\system32\hyqvdlay.ini
c:\windows\system32\ihlmgeva.ini
c:\windows\system32\ilxpfamg.dll
c:\windows\system32\iqkcguqi.ini
c:\windows\system32\iqmmclmw.ini
c:\windows\system32\iubgvdcf.ini
c:\windows\system32\jbkiuvvr.ini
c:\windows\system32\jbvwscig.ini
c:\windows\system32\jkhfc.dll
c:\windows\system32\jkhhe.dll
c:\windows\system32\jkhhh.dll
c:\windows\system32\jkkji.dll
c:\windows\system32\jkkljgg.dll
c:\windows\system32\jnmsdqmi.ini
c:\windows\system32\jplpbwpp.ini
c:\windows\system32\jssbfqdx.dll
c:\windows\system32\jvjdelse.ini
c:\windows\system32\jvlihfvc.ini
c:\windows\system32\kelpeckj.ini
c:\windows\system32\kgjsanxl.ini
c:\windows\SYSTEM32\kmllm.ini
c:\windows\system32\kmllm.ini2
c:\windows\system32\kmuilaaq.ini
c:\windows\system32\knmijtrd.ini
c:\windows\system32\kosscsle.ini
c:\windows\system32\krhgmhys.dll
c:\windows\system32\krhmhhca.ini
c:\windows\system32\krjfdbqc.ini
c:\windows\system32\lffftudy.ini
c:\windows\system32\lkxtnwxg.ini
c:\windows\system32\loqiotds.ini
c:\windows\system32\lsolftlu.ini
c:\windows\system32\ltirydxi.dllbox
c:\windows\system32\lumyigyp.ini
c:\windows\system32\lwvbealv.dll
c:\windows\system32\lwvbealv.dllbox
c:\windows\system32\lyryktfo.ini
c:\windows\system32\mjhkrpdw.ini
c:\windows\system32\mllmk.dll
c:\windows\SYSTEM32\mmllm.bak1
c:\windows\SYSTEM32\mmllm.bak2
c:\windows\SYSTEM32\mmllm.ini
c:\windows\SYSTEM32\mmllm.ini2
c:\windows\system32\mpxcywnq.ini
c:\windows\system32\mujejkru.ini
c:\windows\system32\muxenmph.ini
c:\windows\system32\mxhcgmlt.ini
c:\windows\system32\ndfyrwsd.ini
c:\windows\system32\nGpxx01
c:\windows\system32\nGpxx01\nGpxx011065.exe
c:\windows\system32\ngwcgkbj.ini
c:\windows\system32\nlmwrtnv.ini
c:\windows\system32\nlwaiqvd.ini
c:\windows\system32\nnnmp.ini
c:\windows\system32\nnnmp.ini2
c:\windows\SYSTEM32\npqss.ini
c:\windows\system32\npqss.ini2
c:\windows\SYSTEM32\nqtss.ini
c:\windows\SYSTEM32\nqtss.ini2
c:\windows\system32\nrgplbyk.ini
c:\windows\system32\nsnynyvq.dll
c:\windows\system32\oarrpire.ini
c:\windows\system32\odffcjxw.ini
c:\windows\SYSTEM32\onnmp.ini
c:\windows\SYSTEM32\onnmp.ini2
c:\windows\system32\onvikkmq.ini
c:\windows\system32\oooyxgrm.ini
c:\windows\system32\oqtss.ini
c:\windows\system32\oqtss.ini2
c:\windows\system32\orwobfas.ini
c:\windows\system32\pac.txt
c:\windows\system32\patundcr.ini
c:\windows\system32\pdsqlvyu.ini
c:\windows\system32\phwavs.dll
c:\windows\system32\pihwdele.ini
c:\windows\system32\pjpvvsqk.ini
c:\windows\system32\pmnno.dll
c:\windows\system32\pprlfqly.dll
c:\windows\system32\psnrahbh.ini
c:\windows\system32\pygxswqg.ini
c:\windows\system32\qajvwums.ini
c:\windows\system32\qatjtqoq.ini
c:\windows\system32\qdyilbxf.ini
c:\windows\system32\qjpmfmjb.dll
c:\windows\system32\qkbbfdef.ini
c:\windows\system32\qqstv.ini
c:\windows\SYSTEM32\qqstv.ini2
c:\windows\SYSTEM32\qrqss.ini
c:\windows\SYSTEM32\qrqss.ini2
c:\windows\system32\qvoyfvnc.ini
c:\windows\system32\qyntbejo.ini
c:\windows\system32\rakphwcy.ini
c:\windows\system32\rciyvgyw.ini
c:\windows\system32\rdhadwkr.ini
c:\windows\system32\rdmwipxn.ini
c:\windows\system32\rMa02yy
c:\windows\system32\rMa02yy\rMa02yy1099.exe
c:\windows\system32\rmipphlowloxuhjx.dll
c:\windows\system32\rnpwlkfs.ini
c:\windows\system32\rqfghqim.ini
c:\windows\system32\rqslse.dll
c:\windows\SYSTEM32\rtutv.ini
c:\windows\SYSTEM32\rtutv.ini2
c:\windows\system32\rvalqdxs.ini
c:\windows\system32\rvxsynci.ini
c:\windows\system32\rwhdqfdw.ini
c:\windows\system32\sbuglkwf.ini
c:\windows\system32\sjwokgcf.ini
c:\windows\system32\skchykiv.ini
c:\windows\system32\smteesha.ini
c:\windows\system32\srafeesr.ini
c:\windows\system32\SrchSTS.exe
c:\windows\system32\ssqpo.dll
c:\windows\system32\ssqrq.dll
c:\windows\system32\sstqo.dll
c:\windows\system32\stera.log
c:\windows\system32\ststv.ini
c:\windows\system32\ststv.ini2
c:\windows\system32\stvwa.ini
c:\windows\system32\stvwa.ini2
c:\windows\system32\svvwa.ini
c:\windows\system32\svvwa.ini2
c:\windows\system32\tgbylvjw.ini
c:\windows\system32\tkqtasmj.ini
c:\windows\system32\tmp.reg
c:\windows\system32\tpcdwkwt.ini
c:\windows\system32\trttxnva.ini
c:\windows\system32\tspiwjln.ini
c:\windows\system32\ubtmvpcy.ini
c:\windows\system32\ufudrgdn.ini
c:\windows\system32\ujufsego.ini
c:\windows\system32\uninstall.exe
c:\windows\system32\utovbibe.ini
c:\windows\system32\uwwqlhyf.ini
c:\windows\system32\uxvattha.ini
c:\windows\system32\uyruyuxo.ini
c:\windows\system32\VCCLSID.exe
c:\windows\system32\venuxsvn.ini
c:\windows\system32\vimyivcp.ini
c:\windows\system32\vowofbkg.ini
c:\windows\system32\vtsqq.dll
c:\windows\system32\vtsts.dll
c:\windows\system32\vycdd.ini
c:\windows\SYSTEM32\vycdd.ini2
c:\windows\system32\wagtej.dll
c:\windows\system32\wapisvtr32.exe
c:\windows\system32\wdssyeao.ini
c:\windows\system32\wefktubl.ini
c:\windows\system32\wefmgupu.ini
c:\windows\system32\wmkesicn.ini
c:\windows\system32\wqdfxqdb.ini
c:\windows\system32\WS2Fix.exe
c:\windows\system32\wudflrpm.ini
c:\windows\system32\wxtuhika.ini
c:\windows\system32\wypkvvwd.ini
c:\windows\system32\xbadd.ini
c:\windows\SYSTEM32\xbadd.ini2
c:\windows\system32\xdqfbssj.ini
c:\windows\system32\xgwfuxef.ini
c:\windows\system32\xoublrwl.ini
c:\windows\system32\xryoncfp.ini
c:\windows\system32\xtctyq.dll
c:\windows\SYSTEM32\xybeg.ini
c:\windows\SYSTEM32\xybeg.ini2
c:\windows\system32\ycrwmomf.ini
c:\windows\system32\ygdtfntg.ini
c:\windows\system32\ylqflrpp.ini
c:\windows\system32\yrhfduly.dll
c:\windows\system32\yuepvwnh.dll
c:\windows\system32\yyhwxyrs.ini
c:\windows\system32\yyiudowg.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_DOMAINSERVICE
——-\Legacy_FOPN
——-\Legacy_NPF
——-\Legacy_VSPF
——-\Legacy_VSPF_HK
——-\Legacy_ZESOFT
——-\Service_DomainService
——-\Service_vspf
——-\Service_vspf_hk


((((((((((((((((((((((((( Files Created from 2009-01-06 to 2009-02-06 )))))))))))))))))))))))))))))))
.

2009-02-05 23:53 . 2009-02-05 23:53 d——– C:\_OTListIt
2009-02-05 03:45 . 2009-02-05 03:45 d——– c:\program files\Trend Micro
2009-01-30 03:57 . 2009-02-06 03:13 54,156 –ah—– c:\windows\QTFont.qfn
2009-01-30 03:57 . 2009-01-30 03:57 1,409 –a—— c:\windows\QTFont.for

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-02 07:35 ——— d—–w c:\documents and settings\Margaret Kenney\Application Data\DVD Profiler
2009-01-02 07:32 ——— d—–w c:\program files\DVD Profiler
2009-01-02 07:23 ——— d—–w c:\documents and settings\Aaron Kenney\Application Data\DVD Profiler
2004-05-18 20:38 0 -c–a-w c:\documents and settings\Guest\ub.dat
2004-05-18 20:38 0 -c–a-w c:\documents and settings\Guest\ad.dat
2008-08-05 16:33 73,728 —-a-w c:\program files\mozilla firefox\components\srff.dll
.

——- Sigcheck ——-

2002-08-29 05:00 12800 0f7d9c87b0ce1fa520473119752c6f79 c:\windows\$NtServicePackUninstall$\svchost.exe
2004-08-04 02:56 14336 8f078ae4ed187aaabc0a305146de6716 c:\windows\ServicePackFiles\i386\svchost.exe
2004-08-04 02:56 14336 8f078ae4ed187aaabc0a305146de6716 c:\windows\SYSTEM32\svchost.exe
2004-08-04 02:56 14336 8f078ae4ed187aaabc0a305146de6716 c:\windows\SYSTEM32\DLLCACHE\svchost.exe

2005-03-02 13:19 577024 1800f293bccc8ede8a70e12b88d80036 c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
2003-09-25 11:49 560128 32173306185f603e75c477e117f3bb8d c:\windows\$NtServicePackUninstall$\user32.dll
2004-08-04 02:56 577024 c72661f8552ace7c5c85e16a3cf505c4 c:\windows\ServicePackFiles\i386\user32.dll
2004-06-17 12:58 560128 31fb2d788a9aa618452c02e8375b6dcd c:\windows\SoftwareDistribution\Download\0bfb0fd6d1529228f4175fc177388244\sp1qfe\user32.dll
2005-03-02 13:09 577024 de2db164bbb35db061af0997e4499054 c:\windows\SYSTEM32\user32.dll
2005-03-02 13:09 577024 de2db164bbb35db061af0997e4499054 c:\windows\SYSTEM32\DLLCACHE\user32.dll

2002-08-29 05:00 75264 8529c295df59b564d37a73b5629162b1 c:\windows\$NtServicePackUninstall$\ws2_32.dll
2004-08-04 02:56 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\ServicePackFiles\i386\ws2_32.dll
2004-08-04 02:56 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\SYSTEM32\ws2_32.dll
2004-08-04 02:56 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\SYSTEM32\DLLCACHE\ws2_32.dll

2004-09-29 13:27 656896 2c07195588d69a067c2afdaa31759295 c:\windows\$hf_mig$\KB834707\SP2QFE\wininet.dll
2005-01-27 12:08 657920 a8eac5330876548e9966a7d13025d196 c:\windows\$hf_mig$\KB867282\SP2QFE\wininet.dll
2005-05-02 15:57 658944 e1e18136f9dd3df1ad9c82193a5898a6 c:\windows\$hf_mig$\KB883939\SP2QFE\wininet.dll
2005-03-10 02:43 657920 c8663b488996e89a84c3d17c1d12b79e c:\windows\$hf_mig$\KB890923\SP2QFE\wininet.dll
2005-09-02 18:53 660480 97a6fd7cafd688cf2c78939ebaf0cd0c c:\windows\$hf_mig$\KB896688\SP2QFE\wininet.dll
2005-07-02 21:09 659456 6e533d155b259eb2363d3e04b5be309f c:\windows\$hf_mig$\KB896727\SP2QFE\wininet.dll
2005-10-20 22:38 661504 af785c4947676a7fc1673fdc5c8d0b5b c:\windows\$hf_mig$\KB905915\SP2QFE\wininet.dll
2006-03-03 22:58 663552 c0845ecbf4f9164e618ee381b79c9032 c:\windows\$hf_mig$\KB912812\SP2QFE\wininet.dll
2006-05-10 00:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\$hf_mig$\KB916281\SP2QFE\wininet.dll
2006-06-23 06:25 664576 64ce26db72810b30f7855ea51e1df836 c:\windows\$hf_mig$\KB918899\SP2QFE\wininet.dll
2004-02-06 17:05 588288 4f64d1df989e3aa2fad91a2f1167b9c7 c:\windows\$NtServicePackUninstall$\wininet.dll
2004-08-04 02:56 656384 c0823fc5469663ba63e7db88f9919d70 c:\windows\ServicePackFiles\i386\wininet.dll
2006-06-23 06:02 658944 2b4db890936430c71419037039502752 c:\windows\SYSTEM32\wininet.dll
2006-06-23 06:02 658944 2b4db890936430c71419037039502752 c:\windows\SYSTEM32\DLLCACHE\wininet.dll

2005-05-25 14:07 359936 63fdfea54eb53de2d863ee454937ce1e c:\windows\$hf_mig$\KB893066\SP2QFE\tcpip.sys
2006-01-13 12:07 360448 5562cc0a47b2aef06d3417b733f3c195 c:\windows\$hf_mig$\KB913446\SP2QFE\tcpip.sys
2006-04-20 07:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2002-08-29 05:00 332928 244a2f9816bc9b593957281ef577d976 c:\windows\$NtServicePackUninstall$\tcpip.sys
2004-08-04 01:14 359040 9f4b36614a0fc234525ba224957de55c c:\windows\ServicePackFiles\i386\tcpip.sys
2006-04-20 06:51 359808 1dbf125862891817f374f407626967f4 c:\windows\SYSTEM32\DLLCACHE\tcpip.sys
2006-04-20 06:51 359808 1dbf125862891817f374f407626967f4 c:\windows\SYSTEM32\DRIVERS\tcpip.sys

2002-08-29 05:00 516608 2246d8d8f4714a2cedb21ab9b1849abb c:\windows\$NtServicePackUninstall$\winlogon.exe
2004-08-04 02:56 502272 01c3346c241652f43aed8e2149881bfe c:\windows\ServicePackFiles\i386\winlogon.exe
2004-05-26 20:38 483328 e7f9d2e4e4a94a6f58014e5ffa16a65e c:\windows\SoftwareDistribution\Download\0bfb0fd6d1529228f4175fc177388244\sp1qfe\winlogon.exe
2004-08-04 02:56 502272 01c3346c241652f43aed8e2149881bfe c:\windows\SYSTEM32\winlogon.exe
2004-08-04 02:56 502272 01c3346c241652f43aed8e2149881bfe c:\windows\SYSTEM32\DLLCACHE\winlogon.exe

2003-10-04 02:54 168192 d999ce17681d7d074d534fc5bc662e0a c:\windows\$NtServicePackUninstall$\ndis.sys
2004-08-04 01:14 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\ServicePackFiles\i386\ndis.sys
2004-08-04 01:14 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\SYSTEM32\DLLCACHE\ndis.sys
2004-08-04 01:14 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\SYSTEM32\DRIVERS\ndis.sys

2004-08-04 01:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\ServicePackFiles\i386\ip6fw.sys
2004-08-04 01:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\SYSTEM32\DLLCACHE\ip6fw.sys
2004-08-04 01:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\SYSTEM32\DRIVERS\ip6fw.sys

2005-03-01 19:36 2056832 d8aba3eab509627e707a3b14f00fbb6b c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2003-04-24 10:57 1949440 46ae6f2d416c39ffdcfc8bcb01203ea3 c:\windows\$NtServicePackUninstall$\ntkrnlpa.exe
2005-03-01 19:34 2056832 81013f36b21c7f72cf784cc6731e0002 c:\windows\Driver Cache\I386\ntkrnlpa.exe
2004-08-04 00:58 2056832 947fb1d86d14afcffdb54bf837ec25d0 c:\windows\ServicePackFiles\i386\ntkrnlpa.exe
2004-06-17 03:03 1954688 ed0d7a5f1138ccfd3ecaf8f6ac691f13 c:\windows\SoftwareDistribution\Download\0bfb0fd6d1529228f4175fc177388244\sp1qfe\ntkrnlpa.exe
2005-03-01 19:34 2056832 81013f36b21c7f72cf784cc6731e0002 c:\windows\SYSTEM32\ntkrnlpa.exe
2005-03-01 19:34 2056832 81013f36b21c7f72cf784cc6731e0002 c:\windows\SYSTEM32\DLLCACHE\ntkrnlpa.exe

2005-03-01 20:04 2179456 28187802b7c368c0d3aef7d4c382aabb c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2003-04-24 10:57 1925760 97ec4ab4650da6fc521cf16f8a6ddcb0 c:\windows\$NtServicePackUninstall$\ntoskrnl.exe
2005-03-01 19:59 2179328 4d4cf2c14550a4b7718e94a6e581856e c:\windows\Driver Cache\I386\ntoskrnl.exe
2004-08-04 01:19 2180992 ce218bc7088681faa06633e218596ca7 c:\windows\ServicePackFiles\i386\ntoskrnl.exe
2004-06-17 12:22 2051584 f240dc474f8edb2d95514d831df069e5 c:\windows\SoftwareDistribution\Download\0bfb0fd6d1529228f4175fc177388244\sp1qfe\ntoskrnl.exe
2005-03-01 19:59 2179328 4d4cf2c14550a4b7718e94a6e581856e c:\windows\SYSTEM32\ntoskrnl.exe
2005-03-01 19:59 2179328 4d4cf2c14550a4b7718e94a6e581856e c:\windows\SYSTEM32\DLLCACHE\ntoskrnl.exe

2004-08-04 02:56 1032192 a0732187050030ae399b241436565e64 c:\windows\explorer.exe
2002-08-29 05:00 1004032 a82b28bfc2e4455fe43022a498c0ef0a c:\windows\$NtServicePackUninstall$\explorer.exe
2004-08-04 02:56 1032192 a0732187050030ae399b241436565e64 c:\windows\ServicePackFiles\i386\explorer.exe
2004-08-04 02:56 1032192 a0732187050030ae399b241436565e64 c:\windows\SYSTEM32\DLLCACHE\explorer.exe

2002-08-29 05:00 101376 e3df4a0252d287c44606ee55355e1623 c:\windows\$NtServicePackUninstall$\services.exe
2004-08-04 02:56 108032 c6ce6eec82f187615d1002bb3bb50ed4 c:\windows\ServicePackFiles\i386\services.exe
2004-08-04 02:56 108032 c6ce6eec82f187615d1002bb3bb50ed4 c:\windows\SYSTEM32\services.exe
2004-08-04 02:56 108032 c6ce6eec82f187615d1002bb3bb50ed4 c:\windows\SYSTEM32\DLLCACHE\services.exe

2002-08-29 05:00 11776 b2b6ba905d0e3f8a32a0eb3b4051807b c:\windows\$NtServicePackUninstall$\lsass.exe
2004-08-04 02:56 13312 84885f9b82f4d55c6146ebf6065d75d2 c:\windows\ServicePackFiles\i386\lsass.exe
2004-08-04 02:56 13312 84885f9b82f4d55c6146ebf6065d75d2 c:\windows\SYSTEM32\lsass.exe
2004-08-04 02:56 13312 84885f9b82f4d55c6146ebf6065d75d2 c:\windows\SYSTEM32\DLLCACHE\lsass.exe

2002-08-29 05:00 13312 414de7cf9d3f19c3ea902f1bb38ec116 c:\windows\$NtServicePackUninstall$\ctfmon.exe
2004-08-04 02:56 15360 24232996a38c0b0cf151c2140ae29fc8 c:\windows\ServicePackFiles\i386\ctfmon.exe
2004-08-04 02:56 15360 24232996a38c0b0cf151c2140ae29fc8 c:\windows\SYSTEM32\ctfmon.exe

2005-06-10 19:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2002-08-29 05:00 51200 9b4155ba58192d4073082b8fc5d42612 c:\windows\$NtServicePackUninstall$\spoolsv.exe
2004-08-04 02:56 57856 7435b108b935e42ea92ca94f59c8e717 c:\windows\ServicePackFiles\i386\spoolsv.exe
2005-06-10 18:53 57856 da81ec57acd4cdc3d4c51cf3d409af9f c:\windows\SYSTEM32\spoolsv.exe
2005-06-10 18:53 57856 da81ec57acd4cdc3d4c51cf3d409af9f c:\windows\SYSTEM32\DLLCACHE\spoolsv.exe

2004-08-04 02:56 111104 4126d27cece4471e00e425411f7306b5 c:\windows\ServicePackFiles\i386\wuauclt.exe
2005-05-26 04:16 124184 ebf1ab7e4fc05cabf2f4680d2a45f827 c:\windows\SYSTEM32\wuauclt.exe
2005-05-26 04:16 124184 ebf1ab7e4fc05cabf2f4680d2a45f827 c:\windows\SYSTEM32\DLLCACHE\wuauclt.exe

2002-08-29 05:00 22016 e931e0a2b8bf0019db902e98d03662cb c:\windows\$NtServicePackUninstall$\userinit.exe
2004-08-04 02:56 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\ServicePackFiles\i386\userinit.exe
2004-08-04 02:56 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\SYSTEM32\userinit.exe
2004-08-04 02:56 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\SYSTEM32\DLLCACHE\userinit.exe

2002-08-29 05:00 200192 fe84e045a09a4abc4deef7270448b64e c:\windows\$NtServicePackUninstall$\termsrv.dll
2004-08-04 02:56 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\ServicePackFiles\i386\termsrv.dll
2004-08-04 02:56 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\SYSTEM32\termsrv.dll
2004-08-04 02:56 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\SYSTEM32\DLLCACHE\termsrv.dll

2006-07-05 05:57 985088 0fdd84928a5dde2510761b7ec76ccec9 c:\windows\$hf_mig$\KB917422\SP2QFE\kernel32.dll
2002-08-29 05:00 930304 8f162dc91d67d87c1a481bf602a9dac8 c:\windows\$NtServicePackUninstall$\kernel32.dll
2004-08-04 02:56 983552 888190e31455fad793312f8d087146eb c:\windows\ServicePackFiles\i386\kernel32.dll
2004-06-17 12:58 930816 fca73de7b988a2f7837ffbffcfbed088 c:\windows\SoftwareDistribution\Download\0bfb0fd6d1529228f4175fc177388244\sp1qfe\kernel32.dll
2006-07-05 05:55 984064 d8db5397de07577c1cb50ba6d23b3ad4 c:\windows\SYSTEM32\kernel32.dll
2006-07-05 05:55 984064 d8db5397de07577c1cb50ba6d23b3ad4 c:\windows\SYSTEM32\DLLCACHE\kernel32.dll

2002-08-29 05:00 14848 865ad7ccb20856727d5bd994b094dc5e c:\windows\$NtServicePackUninstall$\powrprof.dll
2004-08-04 02:56 17408 1b5f6923abb450692e9fe0672c897aed c:\windows\ServicePackFiles\i386\powrprof.dll
2004-08-04 02:56 17408 1b5f6923abb450692e9fe0672c897aed c:\windows\SYSTEM32\powrprof.dll
2004-08-04 02:56 17408 1b5f6923abb450692e9fe0672c897aed c:\windows\SYSTEM32\DLLCACHE\powrprof.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4140C4CD-7657-359C-5711-5300CAC78BBA}]
2008-01-28 11:29 60928 –a—— c:\windows\system32\afrmxxot.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{42F2CE47-25D8-6E4C-8839-51C07758D1EC}]
2008-09-30 08:51 60928 –a—— c:\windows\system32\xielkrog.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="c:\program files\AIM\aim.exe" [2006-08-01 67112]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-10-19 126976]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2003-08-06 114741]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2003-08-26 204800]
"Dell AIO Printer A920"="c:\program files\Dell AIO Printer A920\dlbkbmgr.exe" [2003-06-02 270336]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"APVXDWIN"="c:\program files\Panda Security\Panda Antivirus 2008\APVXDWIN.EXE" [2007-10-04 455984]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-01-31 385024]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2008-06-16 167936]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
CallWave.lnk - c:\program files\CallWave\IAM.exe [2004-05-11 1940544]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
2007-02-15 20:02 50736 c:\windows\SYSTEM32\avldr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wagtej.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0smrgdf c:\program files\iolo\System Mechanic Professional 6\

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CallWave.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\CallWave.lnk
backup=c:\windows\pss\CallWave.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Device Detector 2.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Device Detector 2.lnk
backup=c:\windows\pss\Device Detector 2.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkbMonitor.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk
backup=c:\windows\pss\NkbMonitor.exe.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-01-31 23:13 385024 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\SYSTEM32\\dpvsetup.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"=
"c:\\Program Files\\CallWave\\IAM.exe"=

R1 ShldDrv;Panda File Shield Driver;c:\windows\SYSTEM32\DRIVERS\ShlDrv51.sys [2008-09-01 38968]
R2 PavProc;Panda Process Protection Driver;c:\windows\SYSTEM32\DRIVERS\PavProc.sys [2008-09-01 178872]
.
Contents of the 'Scheduled Tasks' folder

2009-02-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
.
- - - - ORPHANS REMOVED - - - -

BHO-{4cfc4a17-25cf-4038-8800-1d03a0879fa3} - c:\windows\system32\wagtej.dll
BHO-{81aa3b3b-45b7-e428-ed82-b7a6ef965b39} - c:\windows\system32\rmipphlowloxuhjx.dll
BHO-{887EA37D-2348-412F-A011-37DDF88F66CE} - (no file)
BHO-{93A6AE09-42F0-4B38-8198-7972AFE25E88} - c:\windows\system32\ssqrq.dll
BHO-{A6FE4E63-F2A1-463B-92CF-7F6061A19B39} - (no file)
HKCU-Run-Sonic RecordNow! - (no file)
HKLM-Run-LanzarL2007 - c:\docume~1\AARONK~1\LOCALS~1\Temp\{B5CCD7BD-0F24-4DD4-9125-E2A475002832}\{D1DA2BA7-2592-4036-9BB2-DCCABDE8DC1A}\..\..\L2007tmp\Setup.exe
Notify-mllmm - (no file)
MSConfigStartUp-DellSupport - c:\program files\Dell Support\DSAgnt.exe
MSConfigStartUp-mmtask - c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe
MSConfigStartUp-P - c:\documents and settings\Aaron Kenney\Local Settings\Temp\P.exe
MSConfigStartUp-PicasaNet - c:\program files\Hello\Hello.exe
MSConfigStartUp-TkBellExe - c:\program files\Common Files\Real\Update_OB\realsched.exe
MSConfigStartUp-ViewMgr - c:\program files\Viewpoint\Viewpoint Manager\ViewMgr_.exe
MSConfigStartUp-WinAble - c:\program files\WinAble\winable.exe
MSConfigStartUp-WinAntiVirusPro2006 - c:\program files\WinAntiVirus Pro 2006\winav.exe
MSConfigStartUp-Yahoo! Pager - c:\program files\Yahoo!\Messenger\ypager.exe
MSConfigStartUp-Ywo9RgN4e - fsuatelc.exe


.
——- Supplementary Scan ——-
.
uStart Page = https://login.yahoo.com/config/mail?.intl=us
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
LSP: c:\program files\Panda Security\Panda Antivirus 2008\pavlsp.dll
FF - ProfilePath - c:\documents and settings\Margaret Kenney\Application Data\Mozilla\Firefox\Profiles\8m37ovzq.default\
FF - prefs.js: browser.startup.homepage - hxxps://login.yahoo.com/config/login?.src=fpctx&.done=http://www.yahoo.com&rl=1
FF - component: c:\program files\Mozilla Firefox\components\srff.dll
FF - plugin: c:\documents and settings\Margaret Kenney\Application Data\Mozilla\Firefox\Profiles\8m37ovzq.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npOberonGameHost.dll
FF - plugin: c:\program files\Java\j2re1.4.2_05\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_05\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_05\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_05\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_05\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_05\bin\NPJPI142_05.dll
FF - plugin: c:\program files\Java\j2re1.4.2_05\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
.
.
——- File Associations ——-
.
JSEFile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-06 14:56:13
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(836)
c:\windows\system32\avldr.dll
.
———————— Other Running Processes ————————
.
c:\windows\SYSTEM32\LEXBCES.EXE
c:\windows\SYSTEM32\LEXPPS.EXE
c:\program files\Olympus\DeviceDetector\DM1Service.exe
c:\program files\Panda Security\Panda Antivirus 2008\PsCtrlS.exe
c:\program files\Common Files\Panda Software\PavShld\PavPrSrv.exe
c:\program files\Panda Security\Panda Antivirus 2008\PsImSvc.exe
c:\program files\Dell AIO Printer A920\dlbkbmon.exe
c:\program files\Panda Security\Panda Antivirus 2008\WebProxy.exe
.
**************************************************************************
.
Completion time: 2009-02-06 15:00:40 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-06 20:00:11

Pre-Run: 19,301,691,392 bytes free
Post-Run: 18,978,127,872 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptOut

622
hello

Please download OTMoveIt3 by OldTimer
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :files
    c:\documents and settings\Guest\ub.dat
    c:\documents and settings\Guest\ad.dat
    c:\program files\mozilla firefox\components\srff.dll
    c:\windows\system32\afrmxxot.dll
    c:\windows\system32\xielkrog.dll
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
========== FILES ========== c:\documents and settings\Guest\ub.dat moved successfully. c:\documents and settings\Guest\ad.dat moved successfully. DllUnregisterServer procedure not found in c:\program files\mozilla firefox\components\srff.dll c:\program files\mozilla firefox\components\srff.dll NOT unregistered. c:\program files\mozilla firefox\components\srff.dll moved successfully. c:\windows\system32\afrmxxot.dll unregistered successfully. c:\windows\system32\afrmxxot.dll moved successfully. c:\windows\system32\xielkrog.dll unregistered successfully. c:\windows\system32\xielkrog.dll moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\MARGAR~1\LOCALS~1\Temp\etilqs_zpJpM59AX22qQtuvtfym scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\Margaret Kenney\Local Settings\Application Data\Mozilla\Firefox\Profiles\8m37ovzq.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Margaret Kenney\Local Settings\Application Data\Mozilla\Firefox\Profiles\8m37ovzq.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Margaret Kenney\Local Settings\Application Data\Mozilla\Firefox\Profiles\8m37ovzq.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Margaret Kenney\Local Settings\Application Data\Mozilla\Firefox\Profiles\8m37ovzq.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Margaret Kenney\Local Settings\Application Data\Mozilla\Firefox\Profiles\8m37ovzq.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Margaret Kenney\Local Settings\Application Data\Mozilla\Firefox\Profiles\8m37ovzq.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02062009_152544
hello

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
good news and bad.

The malware scan cleaned a bunch of stuff. Log is posted below.

I couldn't do the Kaspersky scan because it wanted me to update java. When I went to do this, after it downloaded the setup files, I received a windows error. Is there another online scan that you would want me to do instead?

Windows has found a problem with this file
Name: jre1.6.0_11-c-1.msi
Publisher: Unknown Publisher

The file was blocked because it does not have a valid digital signature that verifies its publisher.




Here's the malware log.

Malwarebytes' Anti-Malware 1.33
Database version: 1736
Windows 5.1.2600 Service Pack 2

2/6/2009 3:51:31 PM
mbam-log-2009-02-06 (15-51-30).txt

Scan type: Quick Scan
Objects scanned: 63564
Time elapsed: 11 minute(s), 8 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 33
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 3
Files Infected: 150

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\anonym (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\drflex.band.1 (Adware.DrFlex) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\drflex.bho.1 (Adware.DrFlex) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\glx3rz.bho (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\oincs.oinanalytics (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\oincs.oinanalytics.1 (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{4438a5dc-e00b-41a0-b0e6-b63fd3b86eee} (Adware.Delphinmediaviewer) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{44cd99fd-cdc0-4c83-a856-cc088872b038} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{8b7d6dfd-0001-4136-a6a7-5d2e7462ecc7} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{4767c447-ef15-42f2-8809-68adb7fa76f1} (Adware.Delphinmediaviewer) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{f7fa36a4-3177-4b57-b9c1-e9c5b2e0d3a9} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d088cf78-4d40-4790-b6cc-e174f6d3c741} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{0041b08f-5878-4bbf-a548-dcf7b2e31a24} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{541f22e6-0935-4578-9013-10421b00f7d0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b162d757-0a88-4e53-8597-8ca8582e22d1} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{dbce5c25-f13c-482f-96ad-5ac559256db5} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a10b5bea-d333-4224-a65d-317a6c273d9d} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1121de13-82a9-463d-ac1e-a56856e1e0b3} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{39e10a35-955d-4c7b-983f-ffcf4277b12d} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{70e7f140-f4e1-43c3-9c3f-5ee6134dbc56} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f6e1f436-0f0e-4d87-a923-683fbfbb94b9} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{955e4bf1-98a4-429c-bd44-6291df2b43b8} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3288bcc0-5b78-4d88-8b35-cda81e6a5fdb} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bannerstyle (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8b4680eb-55ca-485f-b8f3-8519e86247cf} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\oinanalytics (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\OINAnalytics.DLL (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\Webtools (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\OINAnalytics (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Skra (Trojan.Agent) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\meane.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\fylslhqf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\fzyfzq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\gbktnumg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\getwqeqf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\gilokd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\iphavyyd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\jhxohoir.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\jxbxbwko.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\jxdibees.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\knfojurr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\lnmgbpdv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\dgtgarxd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\ebibvotu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\bvccdh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\bxwobtyh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\chqspipd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\cjcrvcbs.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\wdprkhjm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\rtuxbnbl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\qbbjirhh.dll (Trojan.AVKiller) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\qksylqwm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\rdjcomwg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\sqtsdxuy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\sryxwhyy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\uwdbeajw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\uwslnaqo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\vbclbbda.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\vfurorvn.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\vwqlypap.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\uovnvv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\tcllsevh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\nvrbkjgs.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\afxslcfv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\dtubwawu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\howmfick.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\rhjenabt.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\tvrlajss.dll (Trojan.AVKiller) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\uaddja.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\smfyfmfe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\smyqjjtk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\cqbdfjrk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\cqkxjv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\iqucouvc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\iqugvukq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\wjvlybgt.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\evgnpwhl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\fctrfpmt.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\fmomwrcy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\wrrwdqpf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\idnjnqej.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\sdyxrvmm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\sujhjwxq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\sxabqcik.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\pjjaclxr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\pjwxvffb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\pnxlcgdh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\xewbnxub.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\xgshajxv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\xidvfrku.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\xlpjktwy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\xqgcqhmb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\jabnrupv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\jbkgcwgn.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\jcnmahsj.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\heaxelph.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\setuupno.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\wufqvynh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\wxcpcyxb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\xaiayyrf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\mnqluqjg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\moyjsrum.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\lalppehw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\ldayvowv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\lhhdfdpk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\mywfeihf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\ehlaek.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\ehqvfcmd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\elaybuth.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\elscssok.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\esledjvj.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\bmejxsnd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\bnwrwmwp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\bpgxydse.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\xsbfcsni.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\xtbpynfa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\ydutfffl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\yurgijcd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\yxntimnc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\pygsrusp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\gtnftdgy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\guekiomg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\gwgeyhku.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\krcsorow.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\ktlaeibq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\kuooacnn.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\kvrdnyem.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\kxvyrh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\kyyncsqx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\ofhwongt.dll (Trojan.AVKiller) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\ofjjsqvp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\ofvhomxg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\ohwnigoh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\sopiht.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\spkgfajd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\hjulcbyq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\hmqmldsc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\lunycdku.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\lwpuvqij.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\lwztoh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\lxnasjgk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\mgnckwkp.dll (Trojan.AVKiller) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\miqhgfqr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\mjavapsqql.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\mkmgtnce.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\cccurl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\uduirmdj.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\ugbhwirw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\uisuwjsn.dll (Trojan.AVKiller) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\umblpkac.dll (Trojan.AVKiller) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\bdecdhwm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\wnpvpsgc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\kclmvakh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\ddcyv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Aaron Kenney\Application Data\Microsoft\Windows\cxladi.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\William Kenney\Application Data\Microsoft\Windows\buptwnpb.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Program Files\Webtools\webtools.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\OINAnalytics\OINAnalytics2.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\OINAnalytics\Uninstall.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Skra\Skra.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Aaron Kenney\Desktop\Internet Security Suite.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\sstqn.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\gebyx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\awtqp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\ssqpn.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\vtutr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\ddcca.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\cbXOEurr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\geBtQhiF.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\jkkLCvwW.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\byopexep.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\ddcya.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\pmnnn.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\hgghghg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\jkkjjig.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\bwfuyoce.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\uuyojhjs.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\fcccaaWn.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\ClickToFindandFixErrors_US.ico (Malware.Trace) -> Quarantined and deleted successfully.
do this

Please click here to download AVP Tool by Kaspersky.
  • Save it to your desktop.
  • Reboot your computer into SafeMode.

    You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
    Use your up arrow key to highlight SafeMode then hit enter
    .

  • Double click the setup file to run it.
  • Click Next to continue.
  • It will by default install it to your desktop folder.Click Next.
  • Hit ok at the prompt for scanning in Safe Mode.
  • It will then open a box There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.

  • System Memory
  • Startup Objects
  • Disk Boot Sectors.
  • My Computer.
  • Also any other drives (Removable that you may have)


  • Then click on Scan at the to right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left unneutralized then click the button that says Neutralize all
  • If it says it cannot be Neutralized then chooose The delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file name it Kas.
  • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.

Detected ——– Status Object —— —— deleted: Trojan program Trojan-Downloader.Win32.Agent.aeqn File: C:\Qoobox\Quarantine\C\Documents and Settings\Aaron Kenney\Application Data\SpeedRunner\SpeedRunner.exe.vir deleted: Trojan program Trojan-Downloader.Win32.Agent.abqa File: C:\Qoobox\Quarantine\C\Documents and Settings\Aaron Kenney\Application Data\SpeedRunner\SRUninstall.exe.vir//UPX deleted: adware not-a-virus:AdWare.Win32.PurityScan.jw File: C:\Qoobox\Quarantine\C\Documents and Settings\Aaron Kenney\My Documents\ASKS~1\w?auclt.exe.vir//PE_Patch.PECompact//PecBundle//PECompact deleted: Trojan program Trojan-Downloader.Win32.Agent.aeqn File: C:\Qoobox\Quarantine\C\Documents and Settings\William Kenney\Application Data\SpeedRunner\SpeedRunner.exe.vir deleted: Trojan program Trojan-Downloader.Win32.Agent.abqa File: C:\Qoobox\Quarantine\C\Documents and Settings\William Kenney\Application Data\SpeedRunner\SRUninstall.exe.vir//UPX deleted: new threat not-a-virus:FraudTool.Win32.AntiSpywareExpert.h File: C:\Qoobox\Quarantine\C\Program Files\AntiSpywareMaster\asm.exe.vir//ASPack deleted: Trojan program Trojan.Win32.Scapur.k File: C:\Qoobox\Quarantine\C\Program Files\Common Files\Yazzle1281OinAdmin.exe.vir//PE_Patch.PECompact//PecBundle//PECompact deleted: adware not-a-virus:AdWare.Win32.PurityScan.gp File: C:\Qoobox\Quarantine\C\Program Files\Common Files\Yazzle1281OinUninstaller.exe.vir//data0001 deleted: Trojan program Trojan-Downloader.Win32.Adload.pr File: C:\Qoobox\Quarantine\C\Program Files\Dot1XCfg\Dot1XCfg.exe.vir deleted: Trojan program Trojan-Downloader.Win32.PurityScan.fj File: C:\Qoobox\Quarantine\C\Program Files\ECURIT~1\logonui.exe.vir//PE_Patch.UPX//UPX deleted: adware not-a-virus:AdWare.Win32.Agent.fyz File: C:\Qoobox\Quarantine\C\Program Files\GetModule\GetModule23.exe.vir deleted: adware not-a-virus:AdWare.Win32.Agent.fsw File: C:\Qoobox\Quarantine\C\Program Files\GetPack\dianeadupd.exe.vir//data0002 deleted: adware not-a-virus:AdWare.Win32.Agent.fsw File: C:\Qoobox\Quarantine\C\Program Files\GetPack\gastroupd.exe.vir deleted: adware not-a-virus:AdWare.Win32.Agent.ebu File: C:\Qoobox\Quarantine\C\Program Files\GetPack\GetPack19.exe.vir//PE_Patch deleted: adware not-a-virus:AdWare.Win32.Agent.hxx File: C:\Qoobox\Quarantine\C\Program Files\GetPack\GetPack20.exe.vir deleted: adware not-a-virus:AdWare.Win32.Agent.fsw File: C:\Qoobox\Quarantine\C\Program Files\GetPack\GetPack21.exe.vir deleted: adware not-a-virus:AdWare.Win32.Agent.fva File: C:\Qoobox\Quarantine\C\Program Files\GetPack\GetPack22.exe.vir deleted: adware not-a-virus:AdWare.Win32.Agent.apq File: C:\Qoobox\Quarantine\C\Program Files\ISM\ISMModule3.exe.vir deleted: adware not-a-virus:AdWare.Win32.ZenoSearch.ce File: C:\Qoobox\Quarantine\C\Program Files\Outerinfo\FF\components\FF.dll.vir deleted: adware not-a-virus:AdWare.Win32.Agent.fph File: C:\Qoobox\Quarantine\C\Program Files\Sakora\Sakora.exe.vir deleted: Trojan program Trojan.Win32.Agent.edq File: C:\Qoobox\Quarantine\C\Program Files\Temporary\kernInst.exe.vir deleted: Trojan program Trojan.Win32.Agent.crf File: C:\Qoobox\Quarantine\C\Program Files\Temporary\wininstall.exe.vir deleted: Trojan program Trojan-Downloader.Win32.Homles.br File: C:\Qoobox\Quarantine\C\WINDOWS\17PHolmes572.exe.vir//PE_Patch.Upolyx//PE_Patch.UPX//UPX deleted: adware not-a-virus:AdWare.Win32.Rond.d File: C:\Qoobox\Quarantine\C\WINDOWS\b103.exe.vir deleted: Trojan program Trojan-Downloader.Win32.Agent.ezc File: C:\Qoobox\Quarantine\C\WINDOWS\b116.exe.vir deleted: Trojan program Trojan-Downloader.Win32.Agent.hvj File: C:\Qoobox\Quarantine\C\WINDOWS\b122.exe.vir deleted: Trojan program Trojan-Downloader.Win32.Agent.fjn File: C:\Qoobox\Quarantine\C\WINDOWS\b147.exe.vir deleted: Trojan program Trojan-Dropper.Win32.Agent.vgu File: C:\Qoobox\Quarantine\C\WINDOWS\b148.exe.vir deleted: Trojan program Trojan-Downloader.Win32.Agent.fjn File: C:\Qoobox\Quarantine\C\WINDOWS\b151.exe.vir deleted: Trojan program Trojan-Spy.Win32.Agent.due File: C:\Qoobox\Quarantine\C\WINDOWS\b152.exe.vir deleted: Trojan program Trojan-Downloader.Win32.Agent.agga File: C:\Qoobox\Quarantine\C\WINDOWS\b155.exe.vir deleted: Trojan program Trojan.Win32.Multis.cw File: C:\Qoobox\Quarantine\C\WINDOWS\b156.exe.vir deleted: Trojan program Trojan-Downloader.Win32.Agent.jih File: C:\Qoobox\Quarantine\C\WINDOWS\b157.exe.vir deleted: Trojan program Trojan-Downloader.Win32.Agent.aggc File: C:\Qoobox\Quarantine\C\WINDOWS\b158.exe.vir deleted: Trojan program Trojan-Downloader.Win32.Homles.bz File: C:\Qoobox\Quarantine\C\WINDOWS\mrofinu572.exe.vir deleted: Trojan program Trojan.Win32.Pakes.kmo File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\a.exe.vir deleted: Trojan program Trojan.Win32.Monder.gen File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\awvts.dll.vir deleted: Trojan program Trojan.Win32.Monder.gen File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\awvvs.dll.vir deleted: Trojan program Trojan.Win32.Monder.gen File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\awvvv.dll.vir deleted: Trojan program Trojan.Win32.BHO.gvp File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\gjavn.dll.vir deleted: Trojan program Trojan.Win32.Monder.gen File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\jkhfc.dll.vir deleted: Trojan program Trojan.Win32.Monder.gen File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\jkhhe.dll.vir deleted: Trojan program Trojan.Win32.Monder.gen File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\jkhhh.dll.vir deleted: Trojan program Trojan.Win32.Monder.gen File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\jkkji.dll.vir deleted: Trojan program Trojan.Win32.Monder.gen File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\mllmk.dll.vir deleted: Trojan program Trojan.Win32.Monder.gen File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\pmnno.dll.vir//PE_Patch deleted: Trojan program Trojan.Win32.Monder.avty File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\pprlfqly.dll.vir deleted: Trojan program Trojan-Clicker.Win32.Agent.bip File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\rmipphlowloxuhjx.dll.vir deleted: Trojan program Trojan.Win32.Monder.gen File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\ssqpo.dll.vir deleted: Trojan program Trojan.Win32.Monder.gen File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\sstqo.dll.vir//PE_Patch deleted: Trojan program Trojan.Win32.Monder.gen File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\vtsqq.dll.vir deleted: Trojan program Trojan.Win32.Monder.gen File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\vtsts.dll.vir deleted: adware not-a-virus:AdWare.Win32.Virtumonde.apx File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_jkkljgg_.dll.zip/jkkljgg.dll deleted: adware not-a-virus:AdWare.Win32.SecToolBar.k File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_lwvbealv_.dll.zip/lwvbealv.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\_ssqrq_.dll.zip/ssqrq.dll deleted: Trojan program Trojan-Downloader.Win32.VB.cge File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\nGpxx01\nGpxx011065.exe.vir deleted: Trojan program Trojan-Downloader.Win32.VB.bto File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\rMa02yy\rMa02yy1099.exe.vir deleted: Trojan program Trojan.Win32.Monder.wsf File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP311\A0041802.dll deleted: Trojan program Trojan-Downloader.Win32.FraudLoad.vcdu File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP321\A0042861.exe//PE_Patch.UPX//UPX deleted: Trojan program Trojan-Downloader.Win32.VB.bto File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP381\A0048251.exe deleted: new threat not-a-virus:FraudTool.Win32.AntiSpywareExpert.h File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048279.exe//ASPack deleted: Trojan program Trojan-Downloader.Win32.Adload.pr File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048280.exe deleted: Trojan program Trojan-Downloader.Win32.PurityScan.fj File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048281.exe//PE_Patch.UPX//UPX deleted: adware not-a-virus:AdWare.Win32.Agent.fyz File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048282.exe deleted: adware not-a-virus:AdWare.Win32.Agent.fsw File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048283.exe//data0002 deleted: adware not-a-virus:AdWare.Win32.Agent.fsw File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048284.exe deleted: adware not-a-virus:AdWare.Win32.Agent.ebu File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048285.exe//PE_Patch deleted: adware not-a-virus:AdWare.Win32.Agent.hxx File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048286.exe deleted: adware not-a-virus:AdWare.Win32.Agent.fsw File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048287.exe deleted: adware not-a-virus:AdWare.Win32.Agent.fva File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048288.exe deleted: adware not-a-virus:AdWare.Win32.Agent.apq File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048291.exe deleted: adware not-a-virus:AdWare.Win32.ZenoSearch.ce File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048294.dll deleted: adware not-a-virus:AdWare.Win32.Agent.fph File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048297.exe deleted: Trojan program Trojan.Win32.Agent.edq File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048298.exe deleted: Trojan program Trojan.Win32.Agent.crf File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048299.exe deleted: Trojan program Trojan.Win32.Pakes.kmo File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048302.exe deleted: Trojan program Trojan-Downloader.Win32.Agent.aeqn File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048315.exe deleted: Trojan program Trojan-Downloader.Win32.Agent.abqa File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048316.exe//UPX deleted: Trojan program Trojan-Downloader.Win32.Agent.aeqn File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048320.exe deleted: Trojan program Trojan-Downloader.Win32.Agent.abqa File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048321.exe//UPX deleted: Trojan program Trojan.Win32.Scapur.k File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048322.exe//PE_Patch.PECompact//PecBundle//PECompact deleted: adware not-a-virus:AdWare.Win32.PurityScan.gp File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048323.exe//data0001 deleted: Trojan program Trojan-Downloader.Win32.Homles.br File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048324.exe//PE_Patch.Upolyx//PE_Patch.UPX//UPX deleted: adware not-a-virus:AdWare.Win32.Rond.d File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048325.exe deleted: Trojan program Trojan-Downloader.Win32.Agent.ezc File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048326.exe deleted: Trojan program Trojan-Downloader.Win32.Agent.hvj File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048327.exe deleted: Trojan program Trojan-Downloader.Win32.Agent.fjn File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048328.exe deleted: Trojan program Trojan-Dropper.Win32.Agent.vgu File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048329.exe deleted: Trojan program Trojan-Downloader.Win32.Agent.fjn File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048330.exe deleted: Trojan program Trojan-Spy.Win32.Agent.due File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048331.exe deleted: Trojan program Trojan-Downloader.Win32.Agent.agga File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048332.exe deleted: Trojan program Trojan.Win32.Multis.cw File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048333.exe deleted: Trojan program Trojan-Downloader.Win32.Agent.jih File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048334.exe deleted: Trojan program Trojan-Downloader.Win32.Agent.aggc File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048335.exe deleted: Trojan program Trojan-Downloader.Win32.Homles.bz File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048336.exe deleted: Trojan program Trojan-Downloader.Win32.VB.cge File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048337.exe deleted: Trojan program Trojan-Downloader.Win32.VB.bto File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048338.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048347.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048348.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048349.dll deleted: Trojan program Trojan.Win32.BHO.gvp File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048390.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048411.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048412.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048413.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048414.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048436.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048463.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.avty File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048464.dll deleted: Trojan program Trojan-Clicker.Win32.Agent.bip File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048479.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048492.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048493.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.gen File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048512.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048513.dll deleted: Trojan program Trojan.Win32.Monder.af File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048643.dll deleted: Trojan program Trojan.Win32.Monder.cc File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048647.dll deleted: adware not-a-virus:AdWare.Win32.Virtumonde.din File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048653.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048686.dll deleted: Trojan program Trojan.Win32.Monder.af File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048687.dll deleted: adware not-a-virus:AdWare.Win32.Virtumonde.din File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048698.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048716.dll deleted: Trojan program Trojan.Win32.Monder.aw File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048722.dll deleted: adware not-a-virus:AdWare.Win32.SuperJuan.ae File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048731.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048737.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\aausnrqn.dll deleted: adware not-a-virus:AdWare.Win32.Virtumonde.tsw File: C:\WINDOWS\SYSTEM32\achhmhrk.dll deleted: adware not-a-virus:AdWare.Win32.Agent.bgj File: C:\WINDOWS\SYSTEM32\aeimixak.dll deleted: adware not-a-virus:AdWare.Win32.Virtumonde.quv File: C:\WINDOWS\SYSTEM32\agcxlshb.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\aliepbta.dll//PE_Patch deleted: Trojan program Trojan.Win32.Obfuscated.kp File: C:\WINDOWS\SYSTEM32\amholwkq.exe deleted: adware not-a-virus:AdWare.Win32.Virtumonde.vln File: C:\WINDOWS\SYSTEM32\amxxyjbq.dll deleted: Trojan program Trojan.Win32.Monder.bp File: C:\WINDOWS\SYSTEM32\anwswoav.dll deleted: adware not-a-virus:AdWare.Win32.Virtumonde.qrg File: C:\WINDOWS\SYSTEM32\apxvambv.dll deleted: Trojan program Trojan.Win32.Monder.bp File: C:\WINDOWS\SYSTEM32\avfjcgja.dll deleted: Trojan program Trojan.Win32.Monder.cq File: C:\WINDOWS\SYSTEM32\awaehfjv.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\bcepjuam.dll//PE_Patch deleted: Trojan program Trojan.Win32.LowZones.gb File: C:\WINDOWS\SYSTEM32\biatkrdi.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\bltejbuj.dll deleted: Trojan program Trojan.Win32.Agent.zae File: C:\WINDOWS\SYSTEM32\bmoepsvl.exe deleted: Trojan program Trojan.Win32.Monder.ap File: C:\WINDOWS\SYSTEM32\bqylbikr.dll deleted: Trojan program Trojan.Win32.Monder.io File: C:\WINDOWS\SYSTEM32\brqyllvl.dll deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\bsouiera.exe deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\bsyayhik.exe deleted: Trojan program Trojan.Win32.LowZones.gb File: C:\WINDOWS\SYSTEM32\bwsghych.exe deleted: Trojan program Trojan.Win32.Monder.p File: C:\WINDOWS\SYSTEM32\byuhthvx.dll deleted: Trojan program Trojan.Win32.Monder.ma File: C:\WINDOWS\SYSTEM32\cbjghdik.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\cjnowiqq.dll deleted: adware not-a-virus:AdWare.Win32.Virtumonde.tsf File: C:\WINDOWS\SYSTEM32\cnvfyovq.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\corfjova.dll deleted: adware not-a-virus:AdWare.Win32.SuperJuan.ao File: C:\WINDOWS\SYSTEM32\cubdxljs.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\cuochsgr.dll deleted: Trojan program Trojan.Win32.Monder.ag File: C:\WINDOWS\SYSTEM32\cwbujrah.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\dbftukmx.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\ddaba(2).dll deleted: adware not-a-virus:AdWare.Win32.Virtumonde.quv File: C:\WINDOWS\SYSTEM32\dkasvjaj.dll deleted: Trojan program Trojan.Win32.Monder.bxy File: C:\WINDOWS\SYSTEM32\dnxphika.dll deleted: adware not-a-virus:AdWare.Win32.Virtumonde.aps File: C:\WINDOWS\SYSTEM32\dqlvjtif.dll deleted: Trojan program Trojan.Win32.Monder.bq File: C:\WINDOWS\SYSTEM32\dwnxtkuo.dll deleted: adware not-a-virus:AdWare.Win32.SuperJuan.ao File: C:\WINDOWS\SYSTEM32\dwtgkygb.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\dxcpugsc.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\ebnbcysh.dll deleted: Trojan program Trojan.Win32.Agent.zae File: C:\WINDOWS\SYSTEM32\ejukouxu.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\ekocypwi.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.lh File: C:\WINDOWS\SYSTEM32\eoivgcpm.dll deleted: Trojan program Trojan.Win32.Monder.da File: C:\WINDOWS\SYSTEM32\eopcdfdc.dll deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\eqlovhwc.exe deleted: Trojan program Trojan.Win32.Monder.v File: C:\WINDOWS\SYSTEM32\fbslcayx.dll deleted: adware not-a-virus:AdWare.Win32.Virtumonde.aps File: C:\WINDOWS\SYSTEM32\fcgkowjs.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\ffnsmhbj.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.ao File: C:\WINDOWS\SYSTEM32\fhkohpea.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\fjtqrjun.dll deleted: adware not-a-virus:AdWare.Win32.Virtumonde.quv File: C:\WINDOWS\SYSTEM32\fjuwxtgo.dll deleted: Trojan program Trojan.Win32.LowZones.gb File: C:\WINDOWS\SYSTEM32\flbwqamq.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\fmrvfi.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\fuiekayx.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.r File: C:\WINDOWS\SYSTEM32\fxbliydq.dll deleted: Trojan program Trojan.Win32.Monder.v File: C:\WINDOWS\SYSTEM32\fxlwkmuw.dll deleted: Trojan program Trojan.Win32.LowZones.gb File: C:\WINDOWS\SYSTEM32\gerstdmn.exe deleted: Trojan program Trojan.Win32.Monder.bg File: C:\WINDOWS\SYSTEM32\ghsyadih.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\gixhsyjn.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\gjkgiiqv.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\gkbfowov.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\gluuvjma.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\goabgwmi.dll deleted: Trojan program Trojan.Win32.Monder.ay File: C:\WINDOWS\SYSTEM32\gpyimhln.dll deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\grkndhhw.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\grqxfgal.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\gtfalrfs.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\guutmxfr.dll//PE_Patch deleted: adware not-a-virus:AdWare.Win32.Virtumonde.quv File: C:\WINDOWS\SYSTEM32\gvfqsxnk.dll deleted: Trojan program Trojan.Win32.Monder.do File: C:\WINDOWS\SYSTEM32\gxsdsbcl.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\hahrrldi.dll//PE_Patch deleted: adware not-a-virus:AdWare.Win32.Virtumonde.quv File: C:\WINDOWS\SYSTEM32\hbjjdkkt.dll deleted: adware not-a-virus:AdWare.Win32.Virtumonde.jxa File: C:\WINDOWS\SYSTEM32\hbnwivgf.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\hditppmr.dll deleted: Trojan program Trojan.Win32.Monder.ap File: C:\WINDOWS\SYSTEM32\hdutvwcj.dll deleted: Trojan program Trojan.Win32.Agent.zae File: C:\WINDOWS\SYSTEM32\hihcaefu.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\hijcqbel.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\hkyxgyja.dll//PE_Patch deleted: adware not-a-virus:AdWare.Win32.Virtumonde.mvn File: C:\WINDOWS\SYSTEM32\hnktwdrx.dll//PE_Patch deleted: Trojan program Trojan.Win32.LowZones.gb File: C:\WINDOWS\SYSTEM32\holamovm.exe deleted: Trojan program Trojan.Win32.Monder.ay File: C:\WINDOWS\SYSTEM32\hovdumgo.dll deleted: adware not-a-virus:AdWare.Win32.Virtumonde.aps File: C:\WINDOWS\SYSTEM32\hpmnexum.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\hpxshvjm.dll deleted: adware not-a-virus:AdWare.Win32.Virtumonde.qok File: C:\WINDOWS\SYSTEM32\hrmsdxdn.dll deleted: Trojan program Trojan.Win32.Agent.zae File: C:\WINDOWS\SYSTEM32\hycooeba.exe deleted: Trojan program Trojan.Win32.LowZones.gb File: C:\WINDOWS\SYSTEM32\ibiifxpe.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\idfawppc.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\ifjirbvh.dll deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\ijdqoapk.exe deleted: Trojan program Trojan.Win32.LowZones.gb File: C:\WINDOWS\SYSTEM32\ikmxsfxn.exe deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\ilrsmasi.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\imcjqctr.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\inmgjpps.dll deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\iqludwry.exe deleted: adware not-a-virus:AdWare.Win32.Agent.bgj File: C:\WINDOWS\SYSTEM32\irvjhycj.dll deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\irvspweb.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\isocwpsn.dll deleted: adware not-a-virus:AdWare.Win32.SuperJuan.ao File: C:\WINDOWS\SYSTEM32\jaxigxew.dll deleted: Trojan program Trojan.Win32.Monder.ap File: C:\WINDOWS\SYSTEM32\jdhxrisw.dll deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\jktxtcxh.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\jlrikooh.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\jlyhwvoy.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\jmtagosf.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.cz File: C:\WINDOWS\SYSTEM32\joplvkyr.dll deleted: Trojan program Trojan.Win32.Monder.ag File: C:\WINDOWS\SYSTEM32\jtsxfpwa.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\jvsrmoeb.dll//PE_Patch deleted: adware not-a-virus:AdWare.Win32.Virtumonde.bjc File: C:\WINDOWS\SYSTEM32\jwuhjxvf.dll deleted: Trojan program Trojan.Win32.Monder.aq File: C:\WINDOWS\SYSTEM32\kadityda.dll deleted: Trojan program Trojan.Win32.Agent.zae File: C:\WINDOWS\SYSTEM32\kconymfw.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\kfobacbv.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\kftsbpso.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\kgvcuyke.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.ba File: C:\WINDOWS\SYSTEM32\kiruokkc.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\kivuarko.dll deleted: Trojan program Trojan.Win32.Agent.zae File: C:\WINDOWS\SYSTEM32\kpgtjrdr.exe deleted: Trojan program Trojan.Win32.Monder.az File: C:\WINDOWS\SYSTEM32\kqcfdhlq.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\ktdqbsli.dll deleted: Trojan program Trojan.Win32.Monder.io File: C:\WINDOWS\SYSTEM32\kxokctbi.dll deleted: Trojan program Trojan.Win32.Monder.mj File: C:\WINDOWS\SYSTEM32\kygyxhsx.dll deleted: Trojan program Trojan.Win32.Agent.zae File: C:\WINDOWS\SYSTEM32\kyvqijnk.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\lokdqtdt.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\lpojsmgx.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\lrvyoxms.dll//PE_Patch deleted: adware not-a-virus:AdWare.Win32.SecToolBar.k File: C:\WINDOWS\SYSTEM32\ltirydxi.dll deleted: adware not-a-virus:AdWare.Win32.Agent.bgj File: C:\WINDOWS\SYSTEM32\ltrqitvd.dll deleted: Trojan program Trojan.Win32.Agent.zae File: C:\WINDOWS\SYSTEM32\ltwmjpsw.exe deleted: Trojan program Trojan.Win32.Agent.zae File: C:\WINDOWS\SYSTEM32\lwukpcmu.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\mdjbbear.dll//PE_Patch deleted: adware not-a-virus:AdWare.Win32.Virtumonde.qoy File: C:\WINDOWS\SYSTEM32\mgbgligd.dll deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\miplhfuj.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\mllmm(2).dll deleted: Trojan program Trojan.Win32.Monder.au File: C:\WINDOWS\SYSTEM32\mroiwobd.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\mrolkkhb.dll deleted: Trojan program Trojan.Win32.LowZones.gb File: C:\WINDOWS\SYSTEM32\mvcwoywk.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\mwrqbvbq.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\ncelucgc.dll//PE_Patch deleted: Trojan program Trojan.Win32.LowZones.gb File: C:\WINDOWS\SYSTEM32\nchymihv.exe deleted: Trojan program Trojan.Win32.Monder.dl File: C:\WINDOWS\SYSTEM32\ndahdwag.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\nflnnagh.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\nfmldymv.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.kd File: C:\WINDOWS\SYSTEM32\nhomdyft.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\nigngatv.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.s File: C:\WINDOWS\SYSTEM32\nikvfmko.dll deleted: adware not-a-virus:AdWare.Win32.Virtumonde.jxa File: C:\WINDOWS\SYSTEM32\nlcnsunm.dll deleted: adware not-a-virus:AdWare.Win32.Virtumonde.qoy File: C:\WINDOWS\SYSTEM32\nowqifur.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\nqwdkbqk.dll//PE_Patch deleted: Trojan program Trojan.Win32.LowZones.gb File: C:\WINDOWS\SYSTEM32\nrdhsrjf.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\nrpxrwpk.dll//PE_Patch deleted: adware not-a-virus:AdWare.Win32.Virtumonde.aps File: C:\WINDOWS\SYSTEM32\nrqifang.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\nskocwqg.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\nvhnxhjg.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\nvymfjnk.dll deleted: adware not-a-virus:AdWare.Win32.Virtumonde.qrt File: C:\WINDOWS\SYSTEM32\nwkkdemy.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\nwovvbwf.dll deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\nwuohnpn.exe deleted: Trojan program Trojan.Win32.Monder.la File: C:\WINDOWS\SYSTEM32\nxpiwmdr.dll deleted: Trojan program Trojan.Win32.Monder.cy File: C:\WINDOWS\SYSTEM32\nyhkvndn.dll deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\oadebnyv.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\oathyybm.dll deleted: Trojan program Trojan.Win32.Monder.s File: C:\WINDOWS\SYSTEM32\ocdxwlwf.dll deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\oexrkfym.exe deleted: Trojan program Trojan.Win32.LowZones.gb File: C:\WINDOWS\SYSTEM32\okefriih.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\omppbnmw.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.cq File: C:\WINDOWS\SYSTEM32\oriygrji.dll deleted: adware not-a-virus:AdWare.Win32.SecToolBar.k File: C:\WINDOWS\SYSTEM32\orrcuipa.dll deleted: Trojan program Trojan.Win32.Obfuscated.kp File: C:\WINDOWS\SYSTEM32\ovkmorwr.exe deleted: Trojan program Trojan.Win32.Monder.bm File: C:\WINDOWS\SYSTEM32\oyyhuvfv.dll deleted: Trojan program Trojan.Win32.LowZones.gb File: C:\WINDOWS\SYSTEM32\pcybcxqi.exe deleted: adware not-a-virus:AdWare.Win32.Virtumonde.qok File: C:\WINDOWS\SYSTEM32\pehmhkqx.dll deleted: Trojan program Trojan.Win32.Monder.ba File: C:\WINDOWS\SYSTEM32\pevjjfjn.dll deleted: Trojan program Trojan.Win32.Monder.bw File: C:\WINDOWS\SYSTEM32\pgamfaba.dll deleted: adware not-a-virus:AdWare.Win32.Virtumonde.tsp File: C:\WINDOWS\SYSTEM32\pgasednt.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\pgivtoun.dll//PE_Patch deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\pkdvdtyi.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\pvqlqppa.dll deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\pvwbycqo.exe deleted: adware not-a-virus:AdWare.Win32.SecToolBar.k File: C:\WINDOWS\SYSTEM32\pylmlglh.dll deleted: Trojan program Trojan.Win32.Monder.dk File: C:\WINDOWS\SYSTEM32\qagiktrh.dll deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\qhwvhvtj.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\qmiqglto.dll//PE_Patch deleted: adware not-a-virus:AdWare.Win32.Virtumonde.tsg File: C:\WINDOWS\SYSTEM32\qssbpyyt.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\racfcctm.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\rbmdrgoe.dll deleted: adware not-a-virus:AdWare.Win32.Virtumonde.vpc File: C:\WINDOWS\SYSTEM32\rdlqnkll.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\rfaeyshj.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\rgejuwlu.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.di File: C:\WINDOWS\SYSTEM32\rnvetrke.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\robcysts.dll//PE_Patch deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\rtwdxxxu.exe deleted: adware not-a-virus:AdWare.Win32.Virtumonde.mvn File: C:\WINDOWS\SYSTEM32\ruhpqwan.dll//PE_Patch deleted: adware not-a-virus:AdWare.Win32.Virtumonde.quc File: C:\WINDOWS\SYSTEM32\safbowro.dll deleted: Trojan program Trojan.Win32.Monder.li File: C:\WINDOWS\SYSTEM32\sdtoiqol.dll deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\sevuumkc.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\sfampcyc.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\sgayuphp.dll//PE_Patch//PE_Patch deleted: Trojan program Trojan.Win32.Monder.do File: C:\WINDOWS\SYSTEM32\sgfikwko.dll deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\snggypol.exe deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\sojibkyo.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\tcdhrjgl.dll//PE_Patch deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\thvtltye.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\tknbjdbl.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.ik File: C:\WINDOWS\SYSTEM32\totjnkng.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\trdvktdx.dll deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\trferstu.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\ttsplwyd.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\tubhlyvh.dll deleted: Trojan program Trojan.Win32.Monder.de File: C:\WINDOWS\SYSTEM32\txifnsku.dll deleted: Trojan program Trojan.Win32.LowZones.gb File: C:\WINDOWS\SYSTEM32\ubhtvmpr.exe deleted: Trojan program Trojan.Win32.Monder.mu File: C:\WINDOWS\SYSTEM32\ucisnctm.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\uempstes.dll deleted: Trojan program Trojan.Win32.Agent.zae File: C:\WINDOWS\SYSTEM32\ufjniern.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\ugtftwdk.dll deleted: adware not-a-virus:AdWare.Win32.Virtumonde.ytl File: C:\WINDOWS\SYSTEM32\uojuybeq.dll deleted: Trojan program Trojan.Win32.Monder.gz File: C:\WINDOWS\SYSTEM32\upaqyioy.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\upugmfew.dll//PE_Patch deleted: adware not-a-virus:AdWare.Win32.Virtumonde.quv File: C:\WINDOWS\SYSTEM32\usrftpla.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\usrwxanr.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\uxiigsnt.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\vbfcwrwg.dll//PE_Patch deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\vhqgotol.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\vnlqwjnk.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\vulwlxfg.dll deleted: Trojan program Trojan.Win32.Obfuscated.kp File: C:\WINDOWS\SYSTEM32\vypchwux.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\wcnykoqe.dll//PE_Patch deleted: adware not-a-virus:AdWare.Win32.Agent.bgj File: C:\WINDOWS\SYSTEM32\wcsumdwf.dll deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\wefduopw.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\wkxeynke.dll deleted: adware not-a-virus:AdWare.Win32.Agent.bgj File: C:\WINDOWS\SYSTEM32\wnbvvtld.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\wnvvxoso.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\wqefwexe.dll deleted: adware not-a-virus:AdWare.Win32.Virtumonde.quv File: C:\WINDOWS\SYSTEM32\wrmcpemx.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\xbbomxlo.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\xefgrhmc.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\xkdtopoi.dll deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\xmirhmsc.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\xnwdcdqb.dll//PE_Patch deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\xpohemts.dll deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\xrvpopjq.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\xtuskaxy.dll deleted: Trojan program Trojan.Win32.Obfuscated.kp File: C:\WINDOWS\SYSTEM32\xximjpim.exe deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\yjerdtgc.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\ykauotek.dll deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\ykfttubj.dll deleted: Trojan program Trojan.Win32.Monder.cq File: C:\WINDOWS\SYSTEM32\ykjutlvi.dll deleted: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\WINDOWS\SYSTEM32\yqfxqocr.exe deleted: Trojan program Trojan.Win32.Agent.zae File: C:\WINDOWS\SYSTEM32\yqrlcwwf.exe deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\SYSTEM32\yvynsarp.dll//PE_Patch deleted: adware not-a-virus:AdWare.Win32.PurityScan.gv File: C:\_OTMoveIt\MovedFiles\02062009_152544\windows\system32\afrmxxot.dll//PE_Patch.PECompact//PecBundle//PECompact deleted: adware not-a-virus:AdWare.Win32.PurityScan.jv File: C:\_OTMoveIt\MovedFiles\02062009_152544\windows\system32\xielkrog.dll//PE_Patch.PECompact//PecBundle//PECompact deleted: adware not-a-virus:AdWare.Win32.Agent.fsw File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048283.exe deleted: adware not-a-virus:AdWare.Win32.PurityScan.gp File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP383\A0048323.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI