This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Horrible Trojan Infection

52 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey guys/gals, I've been in hell for the past 24 hours trying to get rid of, (what my computer calls) a trojan (given the name Win32/fakeinit).

FIRST PLEASE TELL ME IF I NEED TO DO ANYTHING ELSE OR IF IM POSTING THIS IN THE WRONG AREA.
I DONT WANT TO MAKE ANYONE MAD AT MY EXTREME LACK OF INTERNET SKILLS


Symptoms:

Task mananger disabled by the "admin"

I.E. does not load some pages and says that there is a C ++ error

In the bottom tool bar there is a red x'ed circle that has the pop up saying "Warning! Security Report Your computer is infected! It is recommended to start spyware clearner tool"

The ability to change the background settings, in the display, is grey-ed out.

I ran HijackThis and below is the logfile.

This is my first visit and Im not comp savvy at all, so my apologies in advance. If I post in the wrong place or do something wrong let me know. Thank you so much in advance.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:39:44, on 2/5/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
C:\Documents and Settings\Lane 8\Local Settings\Temp\{231F68F4-70E4-41A6-BEDA-7E7934169B54}\MXOALDR.EXE
C:\WINDOWS\system32\frmwrk32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Lane 8\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Dell Photo Printer 720\dlbcserv.exe
C:\Program Files\ppcbooster\ppcb_32.exe
C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe
C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\regsvr32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 - BHO: TBSB05288 - {6714ADBD-C6C1-42A8-BD84-9C9339059421} - C:\Program Files\IEToolbar\ECO Bar\ecobar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: (no name) - {C0D38F0E-BFF2-4229-B046-0BBDA652E70E} - C:\WINDOWS\system\gvayss.dll (file missing)
O2 - BHO: adsoftinc browser enhancer - {C5784472-D42E-72C7-08FA-C41D78C8EF85} - C:\WINDOWS\system32\oqrjoisockpwi.dll
O3 - Toolbar: Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: ECO Bar - {10000000-1000-1000-1000-100000000000} - C:\Program Files\IEToolbar\ECO Bar\ecobar.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
O4 - HKLM\..\Run: [MXOBG] C:\Documents and Settings\Lane 8\Local Settings\Temp\{231F68F4-70E4-41A6-BEDA-7E7934169B54}\MXOALDR.EXE
O4 - HKLM\..\Run: [RetroExpress] C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe /h
O4 - HKLM\..\Run: [fjysdhttvrn] C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\oqrjoisockpwi.dll"
O4 - HKLM\..\Run: [Framework Windows] frmwrk32.exe
O4 - HKLM\..\RunServices: [Microsoft Windows DLL Services Configuration] windir32.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Lane 8\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: Clean Access Agent.lnk = C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgentLauncher.exe
O4 - Startup: p2pmax.lnk = C:\Program Files\p2pmax\p2pmax.exe
O4 - Startup: ppcb_32.lnk = C:\Program Files\ppcbooster\ppcb_32.exe
O4 - Startup: runit_32.lnk = C:\Program Files\runit\runit_32.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - http://site.ebrary.com.avoserv.library.for…s/ebraryRdr.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6662.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://www.shockwave.com/content/dinerdash…h2.1.0.0.67.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O20 - Winlogon Notify: gvayss - C:\WINDOWS\system\gvayss.dll (file missing)
O20 - Winlogon Notify: mljjh - C:\WINDOWS\system32\mljjh.dll (file missing)
O20 - Winlogon Notify: raswave - C:\WINDOWS\Help\SBSI\raswave.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 16374 bytes
hello

1. Please download Brute Force Uninstaller to your desktop.
  • Right click the BFU folder on your desktop, and choose Extract All
  • Click "Next"
  • In the box to choose where to extract the files to,
  • Click "Browse"
  • Click on the + sign next to "My Computer"
  • Click on "Local Disk (C:) or whatever your primary drive is
  • Click "Make New Folder"
  • Type in BFU
  • Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".

2. RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target/Link As") in order to download MyWebSearch and FunWebProduct Remover .
Save it in the same folder you made earlier (on your desktop).


3. Then, please go to Start > My Computer and navigate to the BFU folder.
  • Start the Brute Force Uninstaller by doubleclicking BFU.exe
  • Behind the scriptline to execute field click the folder icon [external image: Posted Image] and select MyWebSearch.bfu
  • Press Execute and let it do it’s job. (You ought to see a progress bar if you did this correctly.)
  • Wait for the complete script execution box to pop up and press OK.
  • Press exit to terminate the BFU program.



Reboot then do this

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
hello, sorry it took so long for a response. This is the result of the OTListIt scan (It only opened 1 notepad window) Thank you so much:

OTListIt logfile created on: 2/9/2009 2:11:46 AM - Run 3
OTListIt2 by OldTimer - Version 2.0.0.9 Folder = C:\Documents and Settings\Lane 8\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.37 Mb Total Physical Memory | 54.77 Mb Available Physical Memory | 10.71% Memory free
1.22 Gb Paging File | 0.65 Gb Available in Paging File | 52.99% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 51.67 Gb Total Space | 16.74 Gb Free Space | 32.40% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CHRIS
Current User Name: Lane 8
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\AskBarDis\bar\bin\AskService.exe ()
PRC - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe ()
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe (Dell Inc.)
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Dantz\Retrospect Express HD\retrorun.exe (Dantz Development Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\1XConfig.exe (Intel)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
PRC - C:\Program Files\Dell\Media Experience\PCMService.exe (CyberLink Corp.)
PRC - C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (CyberLink Corp.)
PRC - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe (Musicmatch Inc.)
PRC - C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DoScan.exe (Symantec Corporation)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Maxtor\OneTouch\Utils\OneTouch.exe (Maxtor Corporation)
PRC - C:\Documents and Settings\Lane 8\Local Settings\Temp\{231F68F4-70E4-41A6-BEDA-7E7934169B54}\mxoaldr.exe (Cypress Semiconductor)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\frmwrk32.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\LEXPPS.EXE (Lexmark International, Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Documents and Settings\Lane 8\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\Dell Photo Printer 720\dlbcserv.exe ()
PRC - C:\WINDOWS\system32\regsvr32.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MpCmdRun.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Lane 8\Desktop\OTListIt22.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (AOL ACS [Auto | Running]) – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (ASKService [Auto | Running]) – C:\Program Files\AskBarDis\bar\bin\AskService.exe ()
SRV - (ASKUpgrade [Auto | Running]) – C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe ()
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
SRV - (ccEvtMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (ccProxy [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccProxy.exe (Symantec Corporation)
SRV - (ccPwdSvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccSetMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (DefWatch [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (dlbu_device [On_Demand | Stopped]) – C:\WINDOWS\system32\dlbucoms.exe (Dell)
SRV - (DSBrokerService [On_Demand | Stopped]) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (EvtEng [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (gusvc [Auto | Running]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (ISSVC [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe (Symantec Corporation)
SRV - (LexBceS [Auto | Running]) – C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (NICCONFIGSVC [Auto | Running]) – C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe (Dell Inc.)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (RegSrvc [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (RetroExpLauncher [Auto | Running]) – C:\Program Files\Dantz\Retrospect Express HD\retrorun.exe (Dantz Development Corporation)
SRV - (S24EventMonitor [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (SavRoam [On_Demand | Stopped]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (SNDSrvc [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (SPBBCSvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (Symantec AntiVirus [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (SymSecurePort [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe (Symantec Corporation)
SRV - (UMWdf [Auto | Running]) – C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (WLANKEEPER [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)

========== Driver Services (SafeList) ==========

DRV - (AegisP [Auto | Running]) – C:\WINDOWS\system32\drivers\AegisP.sys (Meetinghouse Data Communications)
DRV - (AliIde [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\AMDAGP.SYS (Advanced Micro Devices, Inc.)
DRV - (ApfiltrService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (APPDRV [System | Running]) – C:\WINDOWS\system32\drivers\APPDRV.SYS (Dell Inc)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\asc3550.sys (Advanced System Products, Inc.)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (bcm4sbxp [On_Demand | Running]) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (BVRPMPR5 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\dac2w2k.sys (Mylex Corporation)
DRV - (drvmcdb [Boot | Running]) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm [Auto | Running]) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (DSproct [On_Demand | Stopped]) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (dsunidrv [Auto | Running]) – C:\WINDOWS\system32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (E100B [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (eeCtrl [System | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HSFHWICH [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (HSF_DP [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (IWCA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\iwca.sys (Intel Corporation)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\mraid35x.sys (American Megatrends Inc.)
DRV - (MXOFX [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\MXOFX.SYS (Cypress Semiconductor)
DRV - (MXOPSWD [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\mxopswd.sys (Maxtor Corp.)
DRV - (NAVENG [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090208.016\naveng.sys (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090208.016\navex15.sys (Symantec Corporation)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (omci [System | Running]) – C:\WINDOWS\system32\drivers\omci.sys (Dell Inc)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\drivers\pxhelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql1280.sys (QLogic Corporation)
DRV - (s24trans [Auto | Running]) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (SAVRT [System | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SAVRTPEL [System | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (sdbus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\sdbus.sys (Microsoft Corporation)
DRV - (Secdrv [Auto | Running]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\SISAGP.SYS (Silicon Integrated Systems Corporation)
DRV - (SONYPVU1 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\SONYPVU1.SYS (Sony Corporation)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sparrow.sys (Adaptec, Inc.)
DRV - (SPBBCDrv [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (sscdbhk5 [System | Running]) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln [System | Running]) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (STAC97 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\STAC97.sys (SigmaTel, Inc.)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (SYMDNS [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symdns.sys (Symantec Corporation)
DRV - (SymEvent [On_Demand | Running]) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMFW [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symfw.sys (Symantec Corporation)
DRV - (SYMIDS [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symids.sys (Symantec Corporation)
DRV - (SYMIDSCO [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\SymcData\scfidsdefs\20090129.001\SymIDSCo.sys (Symantec Corporation)
DRV - (SYMNDIS [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symndis.sys (Symantec Corporation)
DRV - (SYMREDRV [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symredrv.sys (Symantec Corporation)
DRV - (SYMTDI [System | Running]) – C:\WINDOWS\system32\drivers\symtdi.sys (Symantec Corporation)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (tfsnboio [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsncofs [Auto | Running]) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsndrct [Auto | Running]) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres [Auto | Running]) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (tfsnifs [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsnopio [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsnudf [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnudfa [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ultra.sys (Promise Technology, Inc.)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaapl.sys (Apple, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (usbvideo [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbvideo.sys (Microsoft Corporation)
DRV - (w29n51 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (wanatw [On_Demand | Running]) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (WS2IFSL [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ws2ifsl.sys (Microsoft Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - URLSearchHook: {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: () - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll (MyWay.com)
O2 - BHO: (TBSB05288 Class) - {6714ADBD-C6C1-42A8-BD84-9C9339059421} - C:\Program Files\IEToolbar\ECO Bar\ecobar.dll ()
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll (Google Inc.)
O2 - BHO: (no name) - {C0D38F0E-BFF2-4229-B046-0BBDA652E70E} - C:\WINDOWS\system\gvayss.dll File not found
O2 - BHO: (adsoftinc browser enhancer) - {C5784472-D42E-72C7-08FA-C41D78C8EF85} - C:\WINDOWS\system32\oqrjoisockpwi.dll ()
O3 - HKLM\..\Toolbar: (ECO Bar) - {10000000-1000-1000-1000-100000000000} - C:\Program Files\IEToolbar\ECO Bar\ecobar.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Radio) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {10000000-1000-1000-1000-100000000000} - C:\Program Files\IEToolbar\ECO Bar\ecobar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {F0993251-2512-4710-AF6E-0A13EA199D02} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" (Symantec Corporation)
O4 - HKLM..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs (Microsoft Corporation)
O4 - HKLM..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe" (Dell Computer Corporation)
O4 - HKLM..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16 ()
O4 - HKLM..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [fjysdhttvrn] C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\oqrjoisockpwi.dll" (Microsoft Corporation)
O4 - HKLM..\Run: [Framework Windows] frmwrk32.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start (InstallShield Software Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe (Maxtor Corporation)
O4 - HKLM..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe (Musicmatch Inc.)
O4 - HKLM..\Run: [MXOBG] C:\Documents and Settings\Lane 8\Local Settings\Temp\{231F68F4-70E4-41A6-BEDA-7E7934169B54}\MXOALDR.EXE (Cypress Semiconductor)
O4 - HKLM..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RetroExpress] C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe /h (Dantz Development Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKLM..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide (Microsoft Corporation)
O4 - HKCU..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h File not found
O4 - HKCU..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup (Gteko Ltd.)
O4 - HKCU..\Run: [Google Update] "C:\Documents and Settings\Lane 8\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (Google Inc.)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKLM..\RunServices: [Microsoft Windows DLL Services Configuration] windir32.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe (America Online, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe ()
O4 - Startup: C:\Documents and Settings\Lane 8\Start Menu\Programs\Startup\Clean Access Agent.lnk = C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgentLauncher.exe (Cisco Systems, Inc.)
O4 - Startup: C:\Documents and Settings\Lane 8\Start Menu\Programs\Startup\p2pmax.lnk = C:\Program Files\p2pmax\p2pmax.exe (BB Inc)
O4 - Startup: C:\Documents and Settings\Lane 8\Start Menu\Programs\Startup\ppcb_32.lnk = C:\Program Files\ppcbooster\ppcb_32.exe ()
O4 - Startup: C:\Documents and Settings\Lane 8\Start Menu\Programs\Startup\runit_32.lnk = C:\Program Files\runit\runit_32.exe (BB Inc)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (America Online, Inc.)
O9 - Extra Button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe File not found
O9 - Extra 'Tools' menuitem : EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9 - Extra Button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YPager.exe ()
O9 - Extra 'Tools' menuitem : Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YPager.exe ()
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 71 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} http://site.ebrary.com.avoserv.library.for…s/ebraryRdr.cab (Infotl Control)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnotes.com/download/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase6662.cab (Windows Live Safety Center Base Module)
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} http://www.shockwave.com/content/dinerdash…h2.1.0.0.67.cab (CPlayFirstDinerDash2Control Object)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://go.divx.com/plugin/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/software/…tiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.popcap.com/games/popcaploader_v6.cab (PopCapLoader Object)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\gvayss: DllName - C:\WINDOWS\system\gvayss.dll - C:\WINDOWS\system\gvayss.dll File not found
O20 - Winlogon\Notify\IntelWireless: DllName - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll (Intel Corporation)
O20 - Winlogon\Notify\mljjh: DllName - C:\WINDOWS\system32\mljjh.dll - C:\WINDOWS\system32\mljjh.dll File not found
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O20 - Winlogon\Notify\raswave: DllName - C:\WINDOWS\Help\SBSI\raswave.dll - C:\WINDOWS\Help\SBSI\raswave.dll File not found
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{22a92702-5b94-11dd-985f-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{22a92702-5b94-11dd-985f-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{22a92702-5b94-11dd-985f-00038a000015}\Shell\AutoRun\command - "" = E:\ONSPCLCK.exe – File not found
O33 - MountPoints2\{58221e37-67bd-11dd-9866-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{58221e37-67bd-11dd-9866-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{58221e37-67bd-11dd-9866-00038a000015}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found

========== Files/Folders - Created Within 30 Days ==========

[4 C:\WINDOWS\System32\*.tmp files]
[2009/02/09 01:55:12 | 00,487,424 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Lane 8\Desktop\OTListIt22.exe
[2009/02/09 01:30:26 | 00,000,000 | —D | C] – C:\Documents and Settings\Lane 8\Desktop\bfu
[2009/02/05 19:39:19 | 00,001,734 | —- | C] () – C:\Documents and Settings\Lane 8\Desktop\HijackThis.lnk
[2009/02/05 19:39:16 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/02/05 19:38:41 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Lane 8\My Documents\HJTInstall.exe
[2009/02/05 19:07:22 | 00,000,000 | —D | C] – C:\Program Files\Hijackthis
[2009/02/05 19:06:18 | 00,488,144 | —- | C] (Soeperman Enterprises Ltd ) – C:\Documents and Settings\Lane 8\My Documents\HJTsetup.exe
[2009/02/05 17:06:24 | 00,000,000 | —D | C] – C:\Documents and Settings\Lane 8\Desktop\SmitfraudFix
[2009/02/05 11:12:34 | 53,628,1088 | -HS- | C] () – C:\hiberfil.sys
[2009/02/05 10:58:37 | 00,000,000 | —D | C] – C:\Documents and Settings\Lane 8\My Documents\SmitfraudFix
[2009/02/05 10:22:03 | 00,005,418 | —- | C] () – C:\WINDOWS\System32\tmp.reg
[2009/02/05 10:21:38 | 00,078,336 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\Agent.OMZ.Fix.exe
[2009/02/05 10:21:37 | 00,080,384 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\o4Patch.exe
[2009/02/05 10:21:36 | 00,087,552 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\VACFix.exe
[2009/02/05 10:21:35 | 00,025,600 | —- | C] () – C:\WINDOWS\System32\WS2Fix.exe
[2009/02/05 10:21:34 | 00,289,144 | —- | C] (S!Ri) – C:\WINDOWS\System32\VCCLSID.exe
[2009/02/05 10:21:34 | 00,288,417 | —- | C] (S!Ri) – C:\WINDOWS\System32\SrchSTS.exe
[2009/02/05 10:21:34 | 00,079,360 | —- | C] (SteelWerX) – C:\WINDOWS\System32\swxcacls.exe
[2009/02/05 10:21:34 | 00,051,200 | —- | C] () – C:\WINDOWS\System32\dumphive.exe
[2009/02/05 10:21:33 | 00,135,168 | —- | C] (SteelWerX) – C:\WINDOWS\System32\swreg.exe
[2009/02/05 10:21:33 | 00,053,248 | —- | C] (http://www.beyondlogic.org) – C:\WINDOWS\System32\Process.exe
[2009/02/05 10:21:33 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\swsc.exe
[2009/02/05 10:20:41 | 01,661,611 | —- | C] () – C:\Documents and Settings\Lane 8\My Documents\SmitfraudFix.exe
[2009/02/04 23:55:10 | 00,000,000 | —D | C] – C:\Program Files\Windows Live Safety Center
[2009/02/04 19:45:01 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\userinit.exe
[2009/02/04 19:44:23 | 00,000,001 | —- | C] () – C:\WINDOWS\System32\uniq.tll
[2009/02/04 19:43:58 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\frmwrk32.exe
[2009/01/22 09:53:25 | 00,050,375 | —- | C] () – C:\Documents and Settings\Lane 8\Desktop\l_6c9a8731e1b525d086f42ff4c16a707a.jpg
[2009/01/21 08:35:29 | 00,000,000 | —D | C] – C:\WINDOWS\ie7updates
[2009/01/21 08:33:13 | 00,000,000 | —D | C] – C:\WINDOWS\WBEM
[2009/01/21 08:33:11 | 00,000,000 | —D | C] – C:\WINDOWS\System32\en-US
[2009/01/21 08:31:14 | 00,000,000 | -H-D | C] – C:\WINDOWS\ie7
[2009/01/21 08:30:39 | 00,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
[2009/01/21 08:29:22 | 00,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
[2009/01/21 08:27:05 | 00,121,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xmllite.dll
[2009/01/21 08:20:58 | 00,000,000 | —D | C] – C:\WINDOWS\network diagnostic
[2009/01/21 08:19:14 | 00,459,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2009/01/21 08:19:13 | 00,267,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2009/01/21 08:19:13 | 00,052,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2009/01/21 08:19:12 | 00,383,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieapfltr.dll
[2009/01/21 08:19:12 | 00,063,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icardie.dll
[2009/01/21 08:19:12 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieudinit.exe
[2009/01/21 08:19:11 | 02,455,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieapfltr.dat
[2009/01/21 08:19:11 | 00,991,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll.mui
[2009/01/21 08:19:09 | 06,066,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2009/01/21 08:17:01 | 00,000,000 | —D | C] – C:\59251d4b9db2c7c0fbab
[2009/01/21 08:16:49 | 15,452,536 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Lane 8\My Documents\IE7-WindowsXP-x86-enu.exe
[2009/01/16 18:42:12 | 00,001,200 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4154990965-559821465-4190246901-1007.job
[2009/01/16 18:20:33 | 00,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/01/16 18:20:29 | 00,000,000 | —D | C] – C:\Documents and Settings\Lane 8\Application Data\skypePM
[2009/01/16 18:10:13 | 00,000,000 | R–D | C] – C:\Program Files\Skype
[2009/01/16 18:10:01 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Skype
[2009/01/15 13:17:58 | 00,035,328 | —- | C] () – C:\WINDOWS\System32\ztLib.dll

========== Files - Modified Within 30 Days ==========

[4 C:\WINDOWS\System32\*.tmp files]
[2009/02/09 02:06:24 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/02/09 01:55:33 | 00,487,424 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Lane 8\Desktop\OTListIt22.exe
[2009/02/09 01:47:40 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/09 01:45:07 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/09 01:44:52 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/09 01:44:44 | 53,628,1088 | -HS- | M] () – C:\hiberfil.sys
[2009/02/09 01:41:25 | 00,000,000 | —- | M] () – C:\WINDOWS\dsww06562.exe
[2009/02/09 01:41:21 | 00,000,000 | —- | M] () – C:\WINDOWS\acnq35580.exe
[2009/02/09 01:40:09 | 05,897,174 | -H– | M] () – C:\Documents and Settings\Lane 8\Local Settings\Application Data\IconCache.db
[2009/02/06 08:49:08 | 00,000,040 | —- | M] () – C:\WINDOWS\System32\profile.dat
[2009/02/06 08:34:44 | 00,001,200 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4154990965-559821465-4190246901-1007.job
[2009/02/05 19:39:19 | 00,001,734 | —- | M] () – C:\Documents and Settings\Lane 8\Desktop\HijackThis.lnk
[2009/02/05 19:39:11 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Lane 8\My Documents\HJTInstall.exe
[2009/02/05 19:06:33 | 00,488,144 | —- | M] (Soeperman Enterprises Ltd ) – C:\Documents and Settings\Lane 8\My Documents\HJTsetup.exe
[2009/02/05 17:18:42 | 00,382,260 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/02/05 17:18:42 | 00,053,838 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/02/05 17:18:41 | 00,441,626 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/02/05 10:59:41 | 00,005,418 | —- | M] () – C:\WINDOWS\System32\tmp.reg
[2009/02/05 10:21:10 | 01,661,611 | —- | M] () – C:\Documents and Settings\Lane 8\My Documents\SmitfraudFix.exe
[2009/02/04 19:44:23 | 00,000,001 | —- | M] () – C:\WINDOWS\System32\uniq.tll
[2009/02/04 19:43:51 | 00,024,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\frmwrk32.exe
[2009/02/01 16:30:23 | 00,000,000 | —- | M] () – C:\WINDOWS\echp00265.exe
[2009/01/27 18:39:27 | 00,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/01/27 06:32:19 | 00,048,267 | —- | M] () – C:\WINDOWS\System32\wjslqojcykb.exe
[2009/01/23 23:04:04 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/01/23 18:27:44 | 00,302,080 | —- | M] () – C:\WINDOWS\System32\oqrjoisockpwi.dll
[2009/01/22 03:02:05 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/01/21 22:31:29 | 00,050,375 | —- | M] () – C:\Documents and Settings\Lane 8\Desktop\l_6c9a8731e1b525d086f42ff4c16a707a.jpg
[2009/01/21 08:50:40 | 00,000,077 | -HS- | M] () – C:\Documents and Settings\Lane 8\My Documents\desktop.ini
[2009/01/21 08:17:00 | 15,452,536 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Lane 8\My Documents\IE7-WindowsXP-x86-enu.exe
[2009/01/16 18:20:33 | 00,000,056 | -H– | M] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/01/15 13:17:58 | 00,035,328 | —- | M] () – C:\WINDOWS\System32\ztLib.dll

========== LOP Check ==========

[2009/01/16 18:10:01 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/10/17 16:20:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2007/02/11 22:15:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/02/08 13:22:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Age of Empires 3
[2007/04/07 12:16:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ahead
[2006/09/30 23:04:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2007/11/17 10:50:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2007/11/17 10:53:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/01/01 14:50:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2007/06/21 16:27:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2005/07/13 11:04:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2008/01/13 11:04:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Dell
[2005/08/29 15:30:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Dell Photo Printer 720
[2009/02/05 00:05:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2009/02/09 01:23:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google Updater
[2005/07/13 11:13:17 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2005/07/13 11:14:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2005/07/13 11:01:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intel
[2005/07/13 11:18:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2005/08/28 12:17:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2008/09/04 17:43:40 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2006/12/12 15:23:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2005/09/01 13:47:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2005/07/13 11:17:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2009/02/09 01:29:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RetroExp
[2006/11/30 22:35:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2004/08/10 13:13:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2009/01/16 18:44:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Skype
[2005/08/17 23:55:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2005/07/26 12:04:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Support.com
[2005/08/28 11:45:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2007/04/20 15:16:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/10/11 21:09:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2007/04/20 16:17:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/01/15 12:15:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2005/10/21 21:13:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2009/02/05 10:59:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data
[2008/10/23 19:10:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Adobe
[2007/02/11 22:16:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\AdobeUM
[2007/04/07 12:26:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Ahead
[2005/10/03 22:40:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Aim
[2008/07/27 21:44:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Apple Computer
[2009/01/01 21:34:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Azureus
[2007/02/05 19:49:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\CiscoCAA
[2005/07/19 23:57:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\CyberLink
[2006/12/07 17:25:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Google
[2008/01/13 11:03:33 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Lane 8\Application Data\Gtek
[2007/10/12 16:04:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Help
[2004/08/10 13:08:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Identities
[2005/07/13 11:02:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Intel
[2005/08/29 15:28:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Jasc Software Inc
[2005/08/17 23:57:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Lavasoft
[2006/11/26 13:18:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Leadertech
[2006/10/27 16:08:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Macromedia
[2008/12/31 15:56:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\MalwareRemoval
[2005/08/17 23:47:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\McAfee.com
[2005/07/28 11:52:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\McAfee.com Personal Firewall
[2008/02/02 17:52:47 | 00,000,000 | –SD | M] – C:\Documents and Settings\Lane 8\Application Data\Microsoft
[2009/01/01 15:30:07 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Lane 8\Application Data\Move Networks
[2009/01/20 19:30:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Mozilla
[2007/08/23 11:45:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Netscape
[2006/12/12 15:23:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\PlayFirst
[2008/03/21 08:56:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Real
[2008/12/31 15:56:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\SetupMalwareRemoval
[2009/01/16 18:20:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\skypePM
[2006/11/26 13:20:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Sonic
[2005/07/13 11:00:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Sun
[2005/11/29 18:16:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Thunderbird
[2008/08/14 22:23:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\U3
[2007/02/24 03:41:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Viewpoint
[2009/01/23 23:04:04 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004/08/04 05:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/02/06 08:34:44 | 00,001,200 | —- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4154990965-559821465-4190246901-1007.job
[2009/02/09 02:06:24 | 00,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2009/02/09 01:45:07 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2005/08/28 12:12:02 | 00,000,366 | —- | M] () – C:\WINDOWS\Tasks\Symantec NetDetect.job

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 104 bytes -> %AllUsersProfile%\Application Data\TEMP:4295826C
< End of report >
hello

Download Rooter.exe to your desktop
  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here



Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    PRC - C:\WINDOWS\system32\frmwrk32.exe (Microsoft Corporation)
    IE - URLSearchHook: {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll ()
    O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
    O2 - BHO: () - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll (MyWay.com)
    O2 - BHO: (no name) - {C0D38F0E-BFF2-4229-B046-0BBDA652E70E} - C:\WINDOWS\system\gvayss.dll File not found
    O2 - BHO: (adsoftinc browser enhancer) - {C5784472-D42E-72C7-08FA-C41D78C8EF85} - C:\WINDOWS\system32\oqrjoisockpwi.dll ()
    O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {F0993251-2512-4710-AF6E-0A13EA199D02} - Reg Error: Key error. File not found
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [Framework Windows] frmwrk32.exe (Microsoft Corporation)
    O4 - HKLM..\RunServices: [Microsoft Windows DLL Services Configuration] windir32.exe File not found
    O20 - Winlogon\Notify\gvayss: DllName - C:\WINDOWS\system\gvayss.dll - C:\WINDOWS\system\gvayss.dll File not found
    O20 - Winlogon\Notify\mljjh: DllName - C:\WINDOWS\system32\mljjh.dll - C:\WINDOWS\system32\mljjh.dll File not found
    O20 - Winlogon\Notify\raswave: DllName - C:\WINDOWS\Help\SBSI\raswave.dll - C:\WINDOWS\Help\SBSI\raswave.dll File not found
    O33 - MountPoints2\{22a92702-5b94-11dd-985f-00038a000015}\Shell - "" = AutoRun
    O33 - MountPoints2\{22a92702-5b94-11dd-985f-00038a000015}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{22a92702-5b94-11dd-985f-00038a000015}\Shell\AutoRun\command - "" = E:\ONSPCLCK.exe – File not found
    O33 - MountPoints2\{58221e37-67bd-11dd-9866-00038a000015}\Shell - "" = AutoRun
    O33 - MountPoints2\{58221e37-67bd-11dd-9866-00038a000015}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{58221e37-67bd-11dd-9866-00038a000015}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
    [4 C:\WINDOWS\System32\*.tmp files]
    [2009/02/04 19:44:23 | 00,000,001 | —- | C] () – C:\WINDOWS\System32\uniq.tll
    [2009/02/04 19:43:58 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\frmwrk32.exe
    [2009/02/09 01:41:25 | 00,000,000 | —- | M] () – C:\WINDOWS\dsww06562.exe
    [2009/02/09 01:41:21 | 00,000,000 | —- | M] () – C:\WINDOWS\acnq35580.exe
    [2009/02/04 19:44:23 | 00,000,001 | —- | M] () – C:\WINDOWS\System32\uniq.tll
    [2009/02/04 19:43:51 | 00,024,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\frmwrk32.exe
    [2009/02/01 16:30:23 | 00,000,000 | —- | M] () – C:\WINDOWS\echp00265.exe
    [2009/01/27 06:32:19 | 00,048,267 | —- | M] () – C:\WINDOWS\System32\wjslqojcykb.exe
    [2009/01/23 18:27:44 | 00,302,080 | —- | M] () – C:\WINDOWS\System32\oqrjoisockpwi.dll
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )
Hello,

Here is what Rooter gave back:

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : Intel® Pentium® M processor 1.60GHz )
BIOS : Phoenix ROM BIOS PLUS Version 1.10 A07
USER : Lane 8 ( Administrator )
BOOT : Normal boot

Antivirus : Symantec AntiVirus Corporate Edition 10.0.0.359 (Activated)
Firewall : Symantec Client Firewall 8.6.0.80 (Activated)

C:\ (Local Disk) - NTFS - Total:51 Go (Free:16 Go)
D:\ (CD or DVD)

Mon 02/09/2009|13:11

———————-\\ Search..

C:\WINDOWS\system32\hjjlm.bak2
C:\WINDOWS\system32\hjjlm.ini
==> VUNDO <==


1 - "C:\Rooter$\Rooter_1.txt" - Mon 02/09/2009|13:13

———————-\\ Scan completed at 13:13
Hello, Ive tried to run the scan, close to a dozen times. And everytime it freezes at 'Checking Manual Scan'. All other programs are not on. and it runs fine until that point.
Hello,

Ran it in safe mode, still no luck. Re-downloaded it and then ran it again. Here is the output:

OTListIt logfile created on: 2/9/2009 7:52:17 PM - Run 27
OTListIt2 by OldTimer - Version 2.0.0.10 Folder = C:\Documents and Settings\Lane 8\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.37 Mb Total Physical Memory | 74.42 Mb Available Physical Memory | 14.55% Memory free
1.22 Gb Paging File | 0.73 Gb Available in Paging File | 60.02% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 51.67 Gb Total Space | 16.74 Gb Free Space | 32.39% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CHRIS
Current User Name: Lane 8
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\system32\LEXPPS.EXE (Lexmark International, Inc.)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\AskBarDis\bar\bin\AskService.exe ()
PRC - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe ()
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe (Dell Inc.)
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Intel\Wireless\Bin\1XConfig.exe (Intel)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
PRC - C:\Program Files\Dell\Media Experience\PCMService.exe (CyberLink Corp.)
PRC - C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (CyberLink Corp.)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe (Musicmatch Inc.)
PRC - C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DoScan.exe (Symantec Corporation)
PRC - C:\Program Files\Maxtor\OneTouch\Utils\OneTouch.exe (Maxtor Corporation)
PRC - C:\Documents and Settings\Lane 8\Local Settings\Temp\{231F68F4-70E4-41A6-BEDA-7E7934169B54}\mxoaldr.exe (Cypress Semiconductor)
PRC - C:\WINDOWS\system32\regsvr32.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\frmwrk32.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Documents and Settings\Lane 8\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Dell Photo Printer 720\dlbcserv.exe ()
PRC - C:\Program Files\Dantz\Retrospect Express HD\Retrospect.exe (Dantz Development Corporation)
PRC - C:\Program Files\Dantz\Retrospect Express HD\retrorun.exe (Dantz Development Corporation)
PRC - C:\Documents and Settings\Lane 8\Desktop\OTListIt22.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (AOL ACS [Auto | Running]) – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (ASKService [Auto | Running]) – C:\Program Files\AskBarDis\bar\bin\AskService.exe ()
SRV - (ASKUpgrade [Auto | Running]) – C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe ()
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
SRV - (ccEvtMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (ccProxy [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccProxy.exe (Symantec Corporation)
SRV - (ccPwdSvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccSetMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (DefWatch [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (dlbu_device [On_Demand | Stopped]) – C:\WINDOWS\system32\dlbucoms.exe (Dell)
SRV - (DSBrokerService [On_Demand | Stopped]) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (EvtEng [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (gusvc [Auto | Running]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (ISSVC [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe (Symantec Corporation)
SRV - (LexBceS [Auto | Running]) – C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (NICCONFIGSVC [Auto | Running]) – C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe (Dell Inc.)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (RegSrvc [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (RetroExpLauncher [Auto | Running]) – C:\Program Files\Dantz\Retrospect Express HD\retrorun.exe (Dantz Development Corporation)
SRV - (S24EventMonitor [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (SavRoam [On_Demand | Stopped]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (SNDSrvc [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (SPBBCSvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (Symantec AntiVirus [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (SymSecurePort [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe (Symantec Corporation)
SRV - (UMWdf [Auto | Running]) – C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (WLANKEEPER [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)

========== Driver Services (SafeList) ==========

DRV - (AegisP [Auto | Running]) – C:\WINDOWS\system32\drivers\AegisP.sys (Meetinghouse Data Communications)
DRV - (AliIde [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\AMDAGP.SYS (Advanced Micro Devices, Inc.)
DRV - (ApfiltrService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (APPDRV [System | Running]) – C:\WINDOWS\system32\drivers\APPDRV.SYS (Dell Inc)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\asc3550.sys (Advanced System Products, Inc.)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (bcm4sbxp [On_Demand | Running]) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (BVRPMPR5 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\dac2w2k.sys (Mylex Corporation)
DRV - (drvmcdb [Boot | Running]) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm [Auto | Running]) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (DSproct [On_Demand | Stopped]) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (dsunidrv [Auto | Running]) – C:\WINDOWS\system32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (E100B [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (eeCtrl [System | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HSFHWICH [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (HSF_DP [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (IWCA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\iwca.sys (Intel Corporation)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\mraid35x.sys (American Megatrends Inc.)
DRV - (MXOFX [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\MXOFX.SYS (Cypress Semiconductor)
DRV - (MXOPSWD [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\mxopswd.sys (Maxtor Corp.)
DRV - (NAVENG [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090208.016\naveng.sys (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090208.016\navex15.sys (Symantec Corporation)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (omci [System | Running]) – C:\WINDOWS\system32\drivers\omci.sys (Dell Inc)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\drivers\pxhelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql1280.sys (QLogic Corporation)
DRV - (s24trans [Auto | Running]) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (SAVRT [System | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SAVRTPEL [System | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (sdbus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\sdbus.sys (Microsoft Corporation)
DRV - (Secdrv [Auto | Running]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\SISAGP.SYS (Silicon Integrated Systems Corporation)
DRV - (SONYPVU1 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\SONYPVU1.SYS (Sony Corporation)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sparrow.sys (Adaptec, Inc.)
DRV - (SPBBCDrv [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (sscdbhk5 [System | Running]) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln [System | Running]) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (STAC97 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\STAC97.sys (SigmaTel, Inc.)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (SYMDNS [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symdns.sys (Symantec Corporation)
DRV - (SymEvent [On_Demand | Running]) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMFW [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symfw.sys (Symantec Corporation)
DRV - (SYMIDS [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symids.sys (Symantec Corporation)
DRV - (SYMIDSCO [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\SymcData\scfidsdefs\20090129.001\SymIDSCo.sys (Symantec Corporation)
DRV - (SYMNDIS [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symndis.sys (Symantec Corporation)
DRV - (SYMREDRV [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symredrv.sys (Symantec Corporation)
DRV - (SYMTDI [System | Running]) – C:\WINDOWS\system32\drivers\symtdi.sys (Symantec Corporation)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (tfsnboio [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsncofs [Auto | Running]) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsndrct [Auto | Running]) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres [Auto | Running]) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (tfsnifs [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsnopio [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsnudf [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnudfa [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ultra.sys (Promise Technology, Inc.)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaapl.sys (Apple, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (usbvideo [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbvideo.sys (Microsoft Corporation)
DRV - (w29n51 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (wanatw [On_Demand | Running]) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (WS2IFSL [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ws2ifsl.sys (Microsoft Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - URLSearchHook: {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: () - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll (MyWay.com)
O2 - BHO: (TBSB05288 Class) - {6714ADBD-C6C1-42A8-BD84-9C9339059421} - C:\Program Files\IEToolbar\ECO Bar\ecobar.dll ()
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll (Google Inc.)
O2 - BHO: (no name) - {C0D38F0E-BFF2-4229-B046-0BBDA652E70E} - C:\WINDOWS\system\gvayss.dll File not found
O2 - BHO: (adsoftinc browser enhancer) - {C5784472-D42E-72C7-08FA-C41D78C8EF85} - C:\WINDOWS\system32\oqrjoisockpwi.dll ()
O3 - HKLM\..\Toolbar: (ECO Bar) - {10000000-1000-1000-1000-100000000000} - C:\Program Files\IEToolbar\ECO Bar\ecobar.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Radio) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {10000000-1000-1000-1000-100000000000} - C:\Program Files\IEToolbar\ECO Bar\ecobar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {F0993251-2512-4710-AF6E-0A13EA199D02} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" (Symantec Corporation)
O4 - HKLM..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs (Microsoft Corporation)
O4 - HKLM..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe" (Dell Computer Corporation)
O4 - HKLM..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16 ()
O4 - HKLM..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [fjysdhttvrn] C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\oqrjoisockpwi.dll" (Microsoft Corporation)
O4 - HKLM..\Run: [Framework Windows] frmwrk32.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start (InstallShield Software Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe (Maxtor Corporation)
O4 - HKLM..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe (Musicmatch Inc.)
O4 - HKLM..\Run: [MXOBG] C:\Documents and Settings\Lane 8\Local Settings\Temp\{231F68F4-70E4-41A6-BEDA-7E7934169B54}\MXOALDR.EXE (Cypress Semiconductor)
O4 - HKLM..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RetroExpress] C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe /h (Dantz Development Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKLM..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide (Microsoft Corporation)
O4 - HKCU..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h File not found
O4 - HKCU..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup (Gteko Ltd.)
O4 - HKCU..\Run: [Google Update] "C:\Documents and Settings\Lane 8\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (Google Inc.)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKLM..\RunServices: [Microsoft Windows DLL Services Configuration] windir32.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe (America Online, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe ()
O4 - Startup: C:\Documents and Settings\Lane 8\Start Menu\Programs\Startup\Clean Access Agent.lnk = C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgentLauncher.exe (Cisco Systems, Inc.)
O4 - Startup: C:\Documents and Settings\Lane 8\Start Menu\Programs\Startup\p2pmax.lnk = C:\Program Files\p2pmax\p2pmax.exe (BB Inc)
O4 - Startup: C:\Documents and Settings\Lane 8\Start Menu\Programs\Startup\ppcb_32.lnk = C:\Program Files\ppcbooster\ppcb_32.exe ()
O4 - Startup: C:\Documents and Settings\Lane 8\Start Menu\Programs\Startup\runit_32.lnk = C:\Program Files\runit\runit_32.exe (BB Inc)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (America Online, Inc.)
O9 - Extra Button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe File not found
O9 - Extra 'Tools' menuitem : EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9 - Extra Button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YPager.exe ()
O9 - Extra 'Tools' menuitem : Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YPager.exe ()
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 71 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} http://site.ebrary.com.avoserv.library.for…s/ebraryRdr.cab (Infotl Control)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnotes.com/download/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase6662.cab (Windows Live Safety Center Base Module)
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} http://www.shockwave.com/content/dinerdash…h2.1.0.0.67.cab (CPlayFirstDinerDash2Control Object)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://go.divx.com/plugin/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} http://www.sibelius.com/download/software/…tiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.popcap.com/games/popcaploader_v6.cab (PopCapLoader Object)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\gvayss: DllName - C:\WINDOWS\system\gvayss.dll - C:\WINDOWS\system\gvayss.dll File not found
O20 - Winlogon\Notify\IntelWireless: DllName - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll (Intel Corporation)
O20 - Winlogon\Notify\mljjh: DllName - C:\WINDOWS\system32\mljjh.dll - C:\WINDOWS\system32\mljjh.dll File not found
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O20 - Winlogon\Notify\raswave: DllName - C:\WINDOWS\Help\SBSI\raswave.dll - C:\WINDOWS\Help\SBSI\raswave.dll File not found
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{22a92702-5b94-11dd-985f-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{22a92702-5b94-11dd-985f-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{22a92702-5b94-11dd-985f-00038a000015}\Shell\AutoRun\command - "" = E:\ONSPCLCK.exe – File not found
O33 - MountPoints2\{58221e37-67bd-11dd-9866-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{58221e37-67bd-11dd-9866-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{58221e37-67bd-11dd-9866-00038a000015}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found

========== Files/Folders - Created Within 30 Days ==========

[4 C:\WINDOWS\System32\*.tmp files]
[2009/02/09 19:42:30 | 53,628,1088 | -HS- | C] () – C:\hiberfil.sys
[2009/02/09 18:22:43 | 00,488,960 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Lane 8\Desktop\OTListIt22.exe
[2009/02/09 13:11:42 | 00,000,000 | —D | C] – C:\Rooter$
[2009/02/09 13:11:30 | 00,268,052 | —- | C] () – C:\Documents and Settings\Lane 8\Desktop\Rooter.exe
[2009/02/09 01:30:26 | 00,000,000 | —D | C] – C:\Documents and Settings\Lane 8\Desktop\bfu
[2009/02/05 19:39:19 | 00,001,734 | —- | C] () – C:\Documents and Settings\Lane 8\Desktop\HijackThis.lnk
[2009/02/05 19:39:16 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/02/05 19:38:41 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Lane 8\My Documents\HJTInstall.exe
[2009/02/05 19:07:22 | 00,000,000 | —D | C] – C:\Program Files\Hijackthis
[2009/02/05 19:06:18 | 00,488,144 | —- | C] (Soeperman Enterprises Ltd ) – C:\Documents and Settings\Lane 8\My Documents\HJTsetup.exe
[2009/02/05 17:06:24 | 00,000,000 | —D | C] – C:\Documents and Settings\Lane 8\Desktop\SmitfraudFix
[2009/02/05 10:58:37 | 00,000,000 | —D | C] – C:\Documents and Settings\Lane 8\My Documents\SmitfraudFix
[2009/02/05 10:22:03 | 00,005,418 | —- | C] () – C:\WINDOWS\System32\tmp.reg
[2009/02/05 10:21:38 | 00,078,336 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\Agent.OMZ.Fix.exe
[2009/02/05 10:21:37 | 00,080,384 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\o4Patch.exe
[2009/02/05 10:21:36 | 00,087,552 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\VACFix.exe
[2009/02/05 10:21:35 | 00,025,600 | —- | C] () – C:\WINDOWS\System32\WS2Fix.exe
[2009/02/05 10:21:34 | 00,289,144 | —- | C] (S!Ri) – C:\WINDOWS\System32\VCCLSID.exe
[2009/02/05 10:21:34 | 00,288,417 | —- | C] (S!Ri) – C:\WINDOWS\System32\SrchSTS.exe
[2009/02/05 10:21:34 | 00,079,360 | —- | C] (SteelWerX) – C:\WINDOWS\System32\swxcacls.exe
[2009/02/05 10:21:34 | 00,051,200 | —- | C] () – C:\WINDOWS\System32\dumphive.exe
[2009/02/05 10:21:33 | 00,135,168 | —- | C] (SteelWerX) – C:\WINDOWS\System32\swreg.exe
[2009/02/05 10:21:33 | 00,053,248 | —- | C] (http://www.beyondlogic.org) – C:\WINDOWS\System32\Process.exe
[2009/02/05 10:21:33 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\swsc.exe
[2009/02/05 10:20:41 | 01,661,611 | —- | C] () – C:\Documents and Settings\Lane 8\My Documents\SmitfraudFix.exe
[2009/02/04 23:55:10 | 00,000,000 | —D | C] – C:\Program Files\Windows Live Safety Center
[2009/02/04 19:45:01 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\userinit.exe
[2009/02/04 19:44:23 | 00,000,001 | —- | C] () – C:\WINDOWS\System32\uniq.tll
[2009/02/04 19:43:58 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\frmwrk32.exe
[2009/01/22 09:53:25 | 00,050,375 | —- | C] () – C:\Documents and Settings\Lane 8\Desktop\l_6c9a8731e1b525d086f42ff4c16a707a.jpg
[2009/01/21 08:35:29 | 00,000,000 | —D | C] – C:\WINDOWS\ie7updates
[2009/01/21 08:33:13 | 00,000,000 | —D | C] – C:\WINDOWS\WBEM
[2009/01/21 08:33:11 | 00,000,000 | —D | C] – C:\WINDOWS\System32\en-US
[2009/01/21 08:31:14 | 00,000,000 | -H-D | C] – C:\WINDOWS\ie7
[2009/01/21 08:30:39 | 00,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
[2009/01/21 08:29:22 | 00,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
[2009/01/21 08:27:05 | 00,121,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xmllite.dll
[2009/01/21 08:20:58 | 00,000,000 | —D | C] – C:\WINDOWS\network diagnostic
[2009/01/21 08:19:14 | 00,459,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2009/01/21 08:19:13 | 00,267,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2009/01/21 08:19:13 | 00,052,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2009/01/21 08:19:12 | 00,383,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieapfltr.dll
[2009/01/21 08:19:12 | 00,063,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icardie.dll
[2009/01/21 08:19:12 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieudinit.exe
[2009/01/21 08:19:11 | 02,455,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieapfltr.dat
[2009/01/21 08:19:11 | 00,991,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll.mui
[2009/01/21 08:19:09 | 06,066,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2009/01/21 08:17:01 | 00,000,000 | —D | C] – C:\59251d4b9db2c7c0fbab
[2009/01/21 08:16:49 | 15,452,536 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Lane 8\My Documents\IE7-WindowsXP-x86-enu.exe
[2009/01/16 18:42:12 | 00,001,200 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4154990965-559821465-4190246901-1007.job
[2009/01/16 18:20:33 | 00,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/01/16 18:20:29 | 00,000,000 | —D | C] – C:\Documents and Settings\Lane 8\Application Data\skypePM
[2009/01/16 18:10:13 | 00,000,000 | R–D | C] – C:\Program Files\Skype
[2009/01/16 18:10:01 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Skype
[2009/01/15 13:17:58 | 00,035,328 | —- | C] () – C:\WINDOWS\System32\ztLib.dll

========== Files - Modified Within 30 Days ==========

[4 C:\WINDOWS\System32\*.tmp files]
[2009/02/09 19:46:53 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/02/09 19:43:54 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/09 19:42:52 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/09 19:42:37 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/09 19:42:30 | 53,628,1088 | -HS- | M] () – C:\hiberfil.sys
[2009/02/09 18:41:36 | 00,000,040 | —- | M] () – C:\WINDOWS\System32\profile.dat
[2009/02/09 18:38:07 | 00,001,200 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4154990965-559821465-4190246901-1007.job
[2009/02/09 18:22:53 | 00,488,960 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Lane 8\Desktop\OTListIt22.exe
[2009/02/09 13:11:41 | 00,268,052 | —- | M] () – C:\Documents and Settings\Lane 8\Desktop\Rooter.exe
[2009/02/09 01:41:25 | 00,000,000 | —- | M] () – C:\WINDOWS\dsww06562.exe
[2009/02/09 01:41:21 | 00,000,000 | —- | M] () – C:\WINDOWS\acnq35580.exe
[2009/02/09 01:40:09 | 05,897,174 | -H– | M] () – C:\Documents and Settings\Lane 8\Local Settings\Application Data\IconCache.db
[2009/02/05 19:39:19 | 00,001,734 | —- | M] () – C:\Documents and Settings\Lane 8\Desktop\HijackThis.lnk
[2009/02/05 19:39:11 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Lane 8\My Documents\HJTInstall.exe
[2009/02/05 19:06:33 | 00,488,144 | —- | M] (Soeperman Enterprises Ltd ) – C:\Documents and Settings\Lane 8\My Documents\HJTsetup.exe
[2009/02/05 17:18:42 | 00,382,260 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/02/05 17:18:42 | 00,053,838 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/02/05 17:18:41 | 00,441,626 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/02/05 10:59:41 | 00,005,418 | —- | M] () – C:\WINDOWS\System32\tmp.reg
[2009/02/05 10:21:10 | 01,661,611 | —- | M] () – C:\Documents and Settings\Lane 8\My Documents\SmitfraudFix.exe
[2009/02/04 20:59:31 | 00,001,891 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/02/04 19:44:23 | 00,000,001 | —- | M] () – C:\WINDOWS\System32\uniq.tll
[2009/02/04 19:43:51 | 00,024,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\frmwrk32.exe
[2009/02/01 16:30:23 | 00,000,000 | —- | M] () – C:\WINDOWS\echp00265.exe
[2009/01/27 18:39:27 | 00,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/01/27 06:32:19 | 00,048,267 | —- | M] () – C:\WINDOWS\System32\wjslqojcykb.exe
[2009/01/23 23:04:04 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/01/23 18:27:44 | 00,302,080 | —- | M] () – C:\WINDOWS\System32\oqrjoisockpwi.dll
[2009/01/21 22:31:29 | 00,050,375 | —- | M] () – C:\Documents and Settings\Lane 8\Desktop\l_6c9a8731e1b525d086f42ff4c16a707a.jpg
[2009/01/21 08:50:40 | 00,000,077 | -HS- | M] () – C:\Documents and Settings\Lane 8\My Documents\desktop.ini
[2009/01/21 08:17:00 | 15,452,536 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Lane 8\My Documents\IE7-WindowsXP-x86-enu.exe
[2009/01/16 18:20:33 | 00,000,056 | -H– | M] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/01/15 13:17:58 | 00,035,328 | —- | M] () – C:\WINDOWS\System32\ztLib.dll
< End of report >
hello

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.
Hello,

Here is the result of the ComboFix. (FYI the pop up stated as one of the symptoms didnt come up this time. Also I can access both the taskmanager and change the background now -So all the symptoms are (what I can see) solved) But here is the ComboFix log:

ComboFix 09-02-10.01 - Lane 8 2009-02-10 17:44:31.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.143 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated)
FW: Symantec Client Firewall *disabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Lane 8\Start Menu\Programs\Startup\ppcb_32.lnk
c:\program files\Common Files\inetget2
c:\program files\IEToolbar
c:\program files\IEToolbar\ECO Bar\basis.xml
c:\program files\IEToolbar\ECO Bar\ecobar.dll
c:\program files\IEToolbar\ECO Bar\icons.bmp
c:\program files\IEToolbar\ECO Bar\info.txt
c:\program files\IEToolbar\ECO Bar\tbhelper.dll
c:\program files\IEToolbar\ECO Bar\uninstall.exe
c:\program files\IEToolbar\ECO Bar\version.txt
c:\program files\IEToolbar\ECO Bar\your_logo.png
c:\program files\p2pmax
c:\program files\p2pmax\p2pmax.exe
c:\program files\p2pmax\p2pmaxu.exe
c:\program files\ppcbooster
c:\program files\ppcbooster\ppcb_32.exe
c:\program files\ppcbooster\ppcbu_32.exe
c:\program files\Setup Wizard
c:\program files\Setup Wizard\asycfilt.dll
c:\program files\Setup Wizard\comcat.dll
c:\program files\Setup Wizard\Comdlg32.ocx
c:\program files\Setup Wizard\MSCOMCTL.OCX
c:\program files\Setup Wizard\MSINET.OCX
c:\program files\Setup Wizard\msvbvm60.dll
c:\program files\Setup Wizard\Mswinsck.ocx
c:\program files\Setup Wizard\oleaut32.dll
c:\program files\Setup Wizard\olepro32.dll
c:\program files\Setup Wizard\settings.ini
c:\program files\Setup Wizard\SetupWizard.exe
c:\program files\Setup Wizard\stdole2.tlb
c:\program files\Setup Wizard\uninstall.exe
c:\windows\acnq35580.exe
c:\windows\dsww06562.exe
c:\windows\echp00265.exe
c:\windows\IE4 Error Log.txt
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\akndxhqf.dll
c:\windows\system32\bacyuera.dll
c:\windows\system32\bihevsbi.dll
c:\windows\system32\cdkdxvlf.dll
c:\windows\system32\csjjcynu.dll
c:\windows\system32\dedurqjg.dll
c:\windows\system32\djmeqvyw.dll
c:\windows\system32\dumphive.exe
c:\windows\system32\eiwksigk.dll
c:\windows\system32\etfarkdq.dll
c:\windows\system32\eutnubyb.dll
c:\windows\system32\frmwrk32.exe
c:\windows\system32\gwbfmhyd.dll
c:\windows\system32\hjjlm.bak2
c:\windows\system32\hjjlm.ini
c:\windows\system32\htcuaaod.dll
c:\windows\system32\IJL15.dll
c:\windows\system32\ldwdgrfd.dll
c:\windows\system32\mbovkhjd.dll
c:\windows\system32\mcrh.tmp
c:\windows\system32\o4Patch.exe
c:\windows\system32\oqrjoisockpwi.dll
c:\windows\system32\ovuioknx.dll
c:\windows\system32\Process.exe
c:\windows\system32\rlqptsoa.dll
c:\windows\system32\rwiirufw.dll
c:\windows\system32\sacocowq.dll
c:\windows\system32\schsbbwq.dll
c:\windows\system32\sqrbpevp.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\thsqyqoa.ini
c:\windows\system32\tmp.reg
c:\windows\system32\trnobxrb.dll
c:\windows\system32\uixkpyra.dll
c:\windows\system32\uniq.tll
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\vhnutbpg.dll
c:\windows\system32\vundkmoo.dll
c:\windows\system32\WS2Fix.exe

.
((((((((((((((((((((((((( Files Created from 2009-01-10 to 2009-02-10 )))))))))))))))))))))))))))))))
.

2009-02-09 13:16 . 2009-02-09 13:16 d——– c:\documents and settings\LANE8~1ttings\Lane 8
2009-02-09 13:16 . 2009-02-09 13:16 d——– c:\documents and settings\LANE8~1ttings
2009-02-09 13:11 . 2009-02-09 13:16 d——– C:\Rooter$
2009-02-05 19:39 . 2009-02-05 19:39 d——– c:\program files\Trend Micro
2009-02-05 10:33 . 2009-02-05 17:05 d——– c:\documents and settings\Administrator
2009-02-04 23:55 . 2009-02-04 23:55 d——– c:\program files\Windows Live Safety Center
2009-02-04 19:45 . 2004-08-04 05:00 24,576 –a—— c:\windows\system32\dllcache\userinit.exe
2009-01-21 08:19 . 2008-10-16 15:38 6,066,176 ——— c:\windows\system32\dllcache\ieframe.dll
2009-01-21 08:19 . 2007-04-17 04:32 2,455,488 ——— c:\windows\system32\dllcache\ieapfltr.dat
2009-01-21 08:19 . 2007-03-08 00:10 991,232 ——— c:\windows\system32\dllcache\ieframe.dll.mui
2009-01-21 08:19 . 2008-10-16 15:38 459,264 ——— c:\windows\system32\dllcache\msfeeds.dll
2009-01-21 08:19 . 2008-10-16 15:38 383,488 ——— c:\windows\system32\dllcache\ieapfltr.dll
2009-01-21 08:19 . 2008-10-16 15:38 267,776 ——— c:\windows\system32\dllcache\iertutil.dll
2009-01-21 08:19 . 2008-10-16 15:38 63,488 ——— c:\windows\system32\dllcache\icardie.dll
2009-01-21 08:19 . 2008-10-16 15:38 52,224 ——— c:\windows\system32\dllcache\msfeedsbs.dll
2009-01-21 08:19 . 2008-10-16 08:11 13,824 ——— c:\windows\system32\dllcache\ieudinit.exe
2009-01-21 08:17 . 2009-01-21 08:17 d——– C:\59251d4b9db2c7c0fbab
2009-01-16 18:20 . 2009-01-16 18:20 d——– c:\documents and settings\Lane 8\Application Data\skypePM
2009-01-16 18:20 . 2009-01-16 18:20 56 –ah—– c:\windows\system32\ezsidmv.dat
2009-01-16 18:10 . 2009-01-16 18:44 dr——- c:\program files\Skype
2009-01-16 18:10 . 2009-01-16 18:44 d——– c:\documents and settings\All Users\Application Data\Skype
2009-01-15 13:17 . 2009-01-15 13:17 35,328 –a—— c:\windows\system32\ztLib.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-10 12:57 ——— d—–w c:\documents and settings\All Users\Application Data\RetroExp
2009-02-10 12:54 ——— d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-02-10 12:47 ——— d—–w c:\program files\runit
2009-02-05 05:05 ——— d—–w c:\program files\Google
2009-01-31 01:02 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-01-16 23:41 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-10 00:10 ——— d—–w c:\program files\Vuze
2009-01-02 02:34 ——— d—–w c:\documents and settings\Lane 8\Application Data\Azureus
2009-01-01 20:58 ——— d—–w c:\program files\Dantz
2009-01-01 20:53 ——— d—–w c:\program files\Maxtor
2009-01-01 20:51 94,208 —-a-w c:\windows\MXOALDR.EXE
2009-01-01 20:36 2,560 —-a-w c:\windows\_MSRSTRT.EXE
2009-01-01 20:36 ——— d—–w c:\program files\SimpleOCR
2009-01-01 20:34 ——— d—–w c:\program files\Common Files\Intuit
2009-01-01 20:30 ——— d–h–w c:\documents and settings\Lane 8\Application Data\Move Networks
2009-01-01 20:21 ——— d—–w c:\program files\ABBYY FineReader 5.0 Sprint
2009-01-01 20:12 ——— d—–w c:\program files\MusicNotes
2009-01-01 20:07 ——— d—–w c:\program files\Coupons
2009-01-01 19:50 ——— d—–w c:\documents and settings\All Users\Application Data\Azureus
2009-01-01 19:48 ——— d—–w c:\program files\AskSearch
2009-01-01 19:48 ——— d—–w c:\program files\AskBarDis
2009-01-01 00:46 ——— d—–w c:\program files\MalwareRemoval
2008-12-31 20:56 ——— d—–w c:\documents and settings\Lane 8\Application Data\SetupMalwareRemoval
2008-12-31 20:56 ——— d—–w c:\documents and settings\Lane 8\Application Data\MalwareRemoval
2008-12-31 19:13 905,320 —-a-w c:\windows\kjbh72462.exe
2008-12-31 19:12 69,686 —-a-w c:\windows\lwitq71375.exe
2008-12-31 19:12 2,024,484 —-a-w c:\windows\ktik82530.exe
2008-12-31 19:12 198,331 —-a-w c:\windows\hqob8081.exe
2008-12-11 11:57 333,184 —-a-w c:\windows\system32\drivers\srv.sys
2005-10-03 11:54 390,846 -csh–w c:\windows\Help\SBSI\evawsar.bak2
2005-10-04 01:07 390,736 -csh–w c:\windows\Help\SBSI\evawsar.ini2
2007-01-30 21:06 968,619 –sha-w c:\windows\system\ssyavg.bak2
2007-02-03 02:06 1,423,434 –sha-w c:\windows\system\ssyavg.ini2
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-12-09 18:40 333192 –a—— c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-12-09 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-12-09 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Google Update"="c:\documents and settings\Lane 8\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-01-16 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-09-13 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 132496]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 385024]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-12-03 344064]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"mmtask"="c:\program files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2004-09-14 53248]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-08-15 180269]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-04-08 48752]
"vptray"="c:\progra~1\SYMANT~1\SYMANT~2\VPTray.exe" [2005-04-17 85184]
"DeadAIM"="c:\program files\AIM\\DeadAIM.ocm" [2003-02-24 266313]
"Dell AIO Printer A940"="c:\program files\Dell AIO Printer A940\dlbabmgr.exe" [2003-06-25 294998]
"DLBUCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll" [2004-11-09 69632]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"MaxtorOneTouch"="c:\program files\Maxtor\OneTouch\utils\Onetouch.exe" [2004-12-22 823296]
"RetroExpress"="c:\progra~1\Dantz\RETROS~1\RetroExpress.exe" [2004-07-30 6946816]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2003-11-10 34832]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0\aoltray.exe [2005-07-13 156784]
dlbcserv.lnk - c:\program files\Dell Photo Printer 720\dlbcserv.exe [2005-08-29 315392]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 16:08 110592 c:\program files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [2009-01-01 464264]
R2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [2009-01-01 234888]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 SavRoam;SAVRoam;c:\program files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe [2005-04-17 124608]

— Other Services/Drivers In Memory —

*Deregistered* - EraserUtilDrvI7

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{22a92702-5b94-11dd-985f-00038a000015}]
\Shell\AutoRun\command - E:\ONSPCLCK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{58221e37-67bd-11dd-9866-00038a000015}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2009-01-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2009-02-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4154990965-559821465-4190246901-1007.job
- c:\documents and settings\Lane 8\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-01-16 18:30]

2009-02-10 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 17:20]

2005-08-28 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-03-31 16:32]
.
- - - - ORPHANS REMOVED - - - -

BHO-{C0D38F0E-BFF2-4229-B046-0BBDA652E70E} - c:\windows\system\gvayss.dll
BHO-{C5784472-D42E-72C7-08FA-C41D78C8EF85} - c:\windows\system32\oqrjoisockpwi.dll
HKCU-Run-ares - c:\program files\Ares\Ares.exe
HKLM-Run-MXOBG - c:\documents and settings\Lane 8\Local Settings\Temp\{231F68F4-70E4-41A6-BEDA-7E7934169B54}\MXOALDR.EXE
HKLM-RunServices-Microsoft Windows DLL Services Configuration - windir32.exe
Notify-gvayss - c:\windows\system\gvayss.dll
Notify-mljjh - c:\windows\system32\mljjh.dll
Notify-raswave - c:\windows\Help\SBSI\raswave.dll


.
——- Supplementary Scan ——-
.
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-10 17:56:25
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLBUCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
Microsoft Windows DLL Services Configuration = windir32.exe?

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(988)
c:\windows\system32\Ati2evxx.dll
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
Completion time: 2009-02-10 18:00:34
ComboFix-quarantined-files.txt 2009-02-10 22:59:14

Pre-Run: 17,838,116,864 bytes free
Post-Run: 18,681,884,672 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

280 — E O F — 2009-02-10 04:12:18
hello

Open notepad and copy/paste the text in the quotebox below into it:

http://forums.whatthetech.com/Horrible_Tro…ion_t99774.html

Collect::
c:\windows\kjbh72462.exe
c:\windows\lwitq71375.exe
c:\windows\ktik82530.exe
c:\windows\hqob8081.exe
c:\windows\Help\SBSI\evawsar.bak2
c:\windows\Help\SBSI\evawsar.ini2
c:\windows\system\ssyavg.bak2
c:\windows\system\ssyavg.ini2

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{22a92702-5b94-11dd-985f-00038a000015}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{58221e37-67bd-11dd-9866-00038a000015}]


Suspect::


Save this as CFScript.txt


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you. Post that log in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
Hello

ComboFix 09-02-10.01 - Lane 8 2009-02-11 17:42:45.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.102 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Lane 8\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated)
FW: Symantec Client Firewall *enabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Help\SBSI\evawsar.bak2
c:\windows\Help\SBSI\evawsar.ini2
c:\windows\hqob8081.exe
c:\windows\kjbh72462.exe
c:\windows\ktik82530.exe
c:\windows\lwitq71375.exe
c:\windows\system\ssyavg.bak2
c:\windows\system\ssyavg.ini2

.
((((((((((((((((((((((((( Files Created from 2009-01-11 to 2009-02-11 )))))))))))))))))))))))))))))))
.

2009-02-09 13:16 . 2009-02-09 13:16 d——– c:\documents and settings\LANE8~1ttings\Lane 8
2009-02-09 13:16 . 2009-02-09 13:16 d——– c:\documents and settings\LANE8~1ttings
2009-02-09 13:11 . 2009-02-09 13:16 d——– C:\Rooter$
2009-02-05 19:39 . 2009-02-05 19:39 d——– c:\program files\Trend Micro
2009-02-05 10:33 . 2009-02-05 17:05 d——– c:\documents and settings\Administrator
2009-02-04 23:55 . 2009-02-04 23:55 d——– c:\program files\Windows Live Safety Center
2009-02-04 19:45 . 2004-08-04 05:00 24,576 –a—— c:\windows\system32\dllcache\userinit.exe
2009-01-21 08:19 . 2008-12-20 18:15 6,066,688 ——— c:\windows\system32\dllcache\ieframe.dll
2009-01-21 08:19 . 2007-04-17 04:32 2,455,488 ——— c:\windows\system32\dllcache\ieapfltr.dat
2009-01-21 08:19 . 2007-03-08 00:10 991,232 ——— c:\windows\system32\dllcache\ieframe.dll.mui
2009-01-21 08:19 . 2008-12-20 18:15 459,264 ——— c:\windows\system32\dllcache\msfeeds.dll
2009-01-21 08:19 . 2008-12-20 18:15 383,488 ——— c:\windows\system32\dllcache\ieapfltr.dll
2009-01-21 08:19 . 2008-12-20 18:15 267,776 ——— c:\windows\system32\dllcache\iertutil.dll
2009-01-21 08:19 . 2008-12-20 18:15 63,488 ——— c:\windows\system32\dllcache\icardie.dll
2009-01-21 08:19 . 2008-12-20 18:15 52,224 ——— c:\windows\system32\dllcache\msfeedsbs.dll
2009-01-21 08:19 . 2008-12-19 04:10 13,824 ——— c:\windows\system32\dllcache\ieudinit.exe
2009-01-21 08:17 . 2009-01-21 08:17 d——– C:\59251d4b9db2c7c0fbab
2009-01-16 18:20 . 2009-01-16 18:20 d——– c:\documents and settings\Lane 8\Application Data\skypePM
2009-01-16 18:20 . 2009-01-16 18:20 56 –ah—– c:\windows\system32\ezsidmv.dat
2009-01-16 18:10 . 2009-01-16 18:44 dr——- c:\program files\Skype
2009-01-16 18:10 . 2009-01-16 18:44 d——– c:\documents and settings\All Users\Application Data\Skype
2009-01-15 13:17 . 2009-01-15 13:17 35,328 –a—— c:\windows\system32\ztLib.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-11 22:40 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-02-11 15:17 ——— d—–w c:\documents and settings\All Users\Application Data\RetroExp
2009-02-11 15:08 ——— d—–w c:\program files\runit
2009-02-11 14:54 ——— d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-02-05 05:05 ——— d—–w c:\program files\Google
2009-01-16 23:41 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-10 00:10 ——— d—–w c:\program files\Vuze
2009-01-02 02:34 ——— d—–w c:\documents and settings\Lane 8\Application Data\Azureus
2009-01-01 20:58 ——— d—–w c:\program files\Dantz
2009-01-01 20:53 ——— d—–w c:\program files\Maxtor
2009-01-01 20:51 94,208 —-a-w c:\windows\MXOALDR.EXE
2009-01-01 20:36 2,560 —-a-w c:\windows\_MSRSTRT.EXE
2009-01-01 20:36 ——— d—–w c:\program files\SimpleOCR
2009-01-01 20:34 ——— d—–w c:\program files\Common Files\Intuit
2009-01-01 20:30 ——— d–h–w c:\documents and settings\Lane 8\Application Data\Move Networks
2009-01-01 20:21 ——— d—–w c:\program files\ABBYY FineReader 5.0 Sprint
2009-01-01 20:12 ——— d—–w c:\program files\MusicNotes
2009-01-01 20:07 ——— d—–w c:\program files\Coupons
2009-01-01 19:50 ——— d—–w c:\documents and settings\All Users\Application Data\Azureus
2009-01-01 19:48 ——— d—–w c:\program files\AskSearch
2009-01-01 19:48 ——— d—–w c:\program files\AskBarDis
2009-01-01 00:46 ——— d—–w c:\program files\MalwareRemoval
2008-12-31 20:56 ——— d—–w c:\documents and settings\Lane 8\Application Data\SetupMalwareRemoval
2008-12-31 20:56 ——— d—–w c:\documents and settings\Lane 8\Application Data\MalwareRemoval
2008-12-11 11:57 333,184 —-a-w c:\windows\system32\drivers\srv.sys
.

((((((((((((((((((((((((((((( SnapShot@2009-02-10_17.57.51.78 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-16 20:38:34 124,928 -c—-w c:\windows\ie7updates\KB961260-IE7\advpack.dll
+ 2008-10-16 20:38:34 347,136 -c—-w c:\windows\ie7updates\KB961260-IE7\dxtmsft.dll
+ 2008-10-16 20:38:34 214,528 -c—-w c:\windows\ie7updates\KB961260-IE7\dxtrans.dll
+ 2008-10-16 20:38:35 133,120 -c—-w c:\windows\ie7updates\KB961260-IE7\extmgr.dll
+ 2008-10-16 20:38:35 63,488 -c—-w c:\windows\ie7updates\KB961260-IE7\icardie.dll
+ 2008-10-16 13:11:09 70,656 -c—-w c:\windows\ie7updates\KB961260-IE7\ie4uinit.exe
+ 2008-10-16 20:38:35 153,088 -c—-w c:\windows\ie7updates\KB961260-IE7\ieakeng.dll
+ 2008-10-16 20:38:35 230,400 -c—-w c:\windows\ie7updates\KB961260-IE7\ieaksie.dll
+ 2008-10-15 07:04:53 161,792 -c—-w c:\windows\ie7updates\KB961260-IE7\ieakui.dll
+ 2008-10-16 20:38:35 383,488 -c—-w c:\windows\ie7updates\KB961260-IE7\ieapfltr.dll
+ 2008-10-16 20:38:35 384,512 -c—-w c:\windows\ie7updates\KB961260-IE7\iedkcs32.dll
+ 2008-10-16 20:38:37 6,066,176 -c—-w c:\windows\ie7updates\KB961260-IE7\ieframe.dll
+ 2008-10-16 20:38:37 44,544 -c—-w c:\windows\ie7updates\KB961260-IE7\iernonce.dll
+ 2008-10-16 20:38:37 267,776 -c—-w c:\windows\ie7updates\KB961260-IE7\iertutil.dll
+ 2008-10-16 13:11:09 13,824 -c—-w c:\windows\ie7updates\KB961260-IE7\ieudinit.exe
+ 2008-10-15 07:06:26 633,632 -c—-w c:\windows\ie7updates\KB961260-IE7\iexplore.exe
+ 2008-10-16 20:38:37 27,648 -c—-w c:\windows\ie7updates\KB961260-IE7\jsproxy.dll
+ 2008-10-16 20:38:37 459,264 -c—-w c:\windows\ie7updates\KB961260-IE7\msfeeds.dll
+ 2008-10-16 20:38:37 52,224 -c—-w c:\windows\ie7updates\KB961260-IE7\msfeedsbs.dll
+ 2008-12-13 06:40:02 3,593,216 -c—-w c:\windows\ie7updates\KB961260-IE7\mshtml.dll
+ 2008-10-16 20:38:38 477,696 -c—-w c:\windows\ie7updates\KB961260-IE7\mshtmled.dll
+ 2008-10-16 20:38:38 193,024 -c—-w c:\windows\ie7updates\KB961260-IE7\msrating.dll
+ 2008-10-16 20:38:39 671,232 -c—-w c:\windows\ie7updates\KB961260-IE7\mstime.dll
+ 2008-10-16 20:38:39 102,912 -c—-w c:\windows\ie7updates\KB961260-IE7\occache.dll
+ 2008-10-16 20:38:39 44,544 -c—-w c:\windows\ie7updates\KB961260-IE7\pngfilt.dll
+ 2007-03-06 01:22:41 213,216 -c—-w c:\windows\ie7updates\KB961260-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w c:\windows\ie7updates\KB961260-IE7\spuninst\updspapi.dll
+ 2008-10-16 20:38:39 105,984 -c—-w c:\windows\ie7updates\KB961260-IE7\url.dll
+ 2008-10-16 20:38:39 1,160,192 -c—-w c:\windows\ie7updates\KB961260-IE7\urlmon.dll
+ 2008-10-16 20:38:39 233,472 -c—-w c:\windows\ie7updates\KB961260-IE7\webcheck.dll
+ 2008-10-16 20:38:40 826,368 -c—-w c:\windows\ie7updates\KB961260-IE7\wininet.dll
- 2008-10-16 20:38:34 124,928 —-a-w c:\windows\system32\advpack.dll
+ 2008-12-20 23:15:11 124,928 —-a-w c:\windows\system32\advpack.dll
- 2008-10-16 20:38:34 124,928 ——w c:\windows\system32\dllcache\advpack.dll
+ 2008-12-20 23:15:11 124,928 ——w c:\windows\system32\dllcache\advpack.dll
- 2008-10-16 20:38:34 347,136 ——w c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-12-20 23:15:12 347,136 ——w c:\windows\system32\dllcache\dxtmsft.dll
- 2008-10-16 20:38:34 214,528 ——w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-12-20 23:15:13 214,528 ——w c:\windows\system32\dllcache\dxtrans.dll
- 2008-10-16 20:38:35 133,120 ——w c:\windows\system32\dllcache\extmgr.dll
+ 2008-12-20 23:15:13 133,120 ——w c:\windows\system32\dllcache\extmgr.dll
- 2008-10-16 13:11:09 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-12-19 09:10:15 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
- 2008-10-16 20:38:35 153,088 ——w c:\windows\system32\dllcache\ieakeng.dll
+ 2008-12-20 23:15:14 153,088 ——w c:\windows\system32\dllcache\ieakeng.dll
- 2008-10-16 20:38:35 230,400 ——w c:\windows\system32\dllcache\ieaksie.dll
+ 2008-12-20 23:15:14 230,400 ——w c:\windows\system32\dllcache\ieaksie.dll
- 2008-10-15 07:04:53 161,792 ——w c:\windows\system32\dllcache\ieakui.dll
+ 2008-12-19 05:23:56 161,792 ——w c:\windows\system32\dllcache\ieakui.dll
- 2008-10-16 20:38:35 384,512 ——w c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-12-20 23:15:16 384,512 ——w c:\windows\system32\dllcache\iedkcs32.dll
- 2008-10-16 20:38:37 44,544 ——w c:\windows\system32\dllcache\iernonce.dll
+ 2008-12-20 23:15:21 44,544 ——w c:\windows\system32\dllcache\iernonce.dll
- 2008-10-15 07:06:26 633,632 ——w c:\windows\system32\dllcache\iexplore.exe
+ 2008-12-19 05:25:25 634,024 ——w c:\windows\system32\dllcache\iexplore.exe
- 2008-10-16 20:38:37 27,648 ——w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-12-20 23:15:23 27,648 ——w c:\windows\system32\dllcache\jsproxy.dll
- 2008-12-13 06:40:02 3,593,216 ——w c:\windows\system32\dllcache\mshtml.dll
+ 2009-01-17 02:35:14 3,594,752 ——w c:\windows\system32\dllcache\mshtml.dll
- 2008-10-16 20:38:38 477,696 ——w c:\windows\system32\dllcache\mshtmled.dll
+ 2008-12-20 23:15:30 477,696 ——w c:\windows\system32\dllcache\mshtmled.dll
- 2008-10-16 20:38:38 193,024 ——w c:\windows\system32\dllcache\msrating.dll
+ 2008-12-20 23:15:31 193,024 ——w c:\windows\system32\dllcache\msrating.dll
- 2008-10-16 20:38:39 671,232 ——w c:\windows\system32\dllcache\mstime.dll
+ 2008-12-20 23:15:32 671,232 ——w c:\windows\system32\dllcache\mstime.dll
- 2008-10-16 20:38:39 102,912 ——w c:\windows\system32\dllcache\occache.dll
+ 2008-12-20 23:15:38 102,912 ——w c:\windows\system32\dllcache\occache.dll
- 2008-10-16 20:38:39 44,544 ——w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-12-20 23:15:38 44,544 ——w c:\windows\system32\dllcache\pngfilt.dll
- 2008-10-16 20:38:39 105,984 ——w c:\windows\system32\dllcache\url.dll
+ 2008-12-20 23:15:39 105,984 ——w c:\windows\system32\dllcache\url.dll
- 2008-10-16 20:38:39 1,160,192 ——w c:\windows\system32\dllcache\urlmon.dll
+ 2008-12-20 23:15:40 1,160,192 ——w c:\windows\system32\dllcache\urlmon.dll
- 2008-10-16 20:38:39 233,472 ——w c:\windows\system32\dllcache\webcheck.dll
+ 2008-12-20 23:15:40 233,472 ——w c:\windows\system32\dllcache\webcheck.dll
- 2008-10-16 20:38:40 826,368 ——w c:\windows\system32\dllcache\wininet.dll
+ 2008-12-20 23:15:41 826,368 ——w c:\windows\system32\dllcache\wininet.dll
- 2008-10-16 20:38:34 347,136 ——w c:\windows\system32\dxtmsft.dll
+ 2008-12-20 23:15:12 347,136 ——w c:\windows\system32\dxtmsft.dll
- 2008-10-16 20:38:34 214,528 ——w c:\windows\system32\dxtrans.dll
+ 2008-12-20 23:15:13 214,528 ——w c:\windows\system32\dxtrans.dll
- 2008-10-16 20:38:35 133,120 ——w c:\windows\system32\extmgr.dll
+ 2008-12-20 23:15:13 133,120 ——w c:\windows\system32\extmgr.dll
- 2008-10-16 20:38:35 63,488 —-a-w c:\windows\system32\icardie.dll
+ 2008-12-20 23:15:13 63,488 —-a-w c:\windows\system32\icardie.dll
- 2008-10-16 13:11:09 70,656 ——w c:\windows\system32\ie4uinit.exe
+ 2008-12-19 09:10:15 70,656 ——w c:\windows\system32\ie4uinit.exe
- 2008-10-16 20:38:35 153,088 ——w c:\windows\system32\ieakeng.dll
+ 2008-12-20 23:15:14 153,088 ——w c:\windows\system32\ieakeng.dll
- 2008-10-16 20:38:35 230,400 ——w c:\windows\system32\ieaksie.dll
+ 2008-12-20 23:15:14 230,400 ——w c:\windows\system32\ieaksie.dll
- 2008-10-15 07:04:53 161,792 ——w c:\windows\system32\ieakui.dll
+ 2008-12-19 05:23:56 161,792 ——w c:\windows\system32\ieakui.dll
- 2008-10-16 20:38:35 383,488 —-a-w c:\windows\system32\ieapfltr.dll
+ 2008-12-20 23:15:15 383,488 —-a-w c:\windows\system32\ieapfltr.dll
- 2008-10-16 20:38:35 384,512 ——w c:\windows\system32\iedkcs32.dll
+ 2008-12-20 23:15:16 384,512 ——w c:\windows\system32\iedkcs32.dll
- 2008-10-16 20:38:37 6,066,176 —-a-w c:\windows\system32\ieframe.dll
+ 2008-12-20 23:15:21 6,066,688 —-a-w c:\windows\system32\ieframe.dll
- 2008-10-16 20:38:37 44,544 ——w c:\windows\system32\iernonce.dll
+ 2008-12-20 23:15:21 44,544 ——w c:\windows\system32\iernonce.dll
- 2008-10-16 20:38:37 267,776 —-a-w c:\windows\system32\iertutil.dll
+ 2008-12-20 23:15:22 267,776 —-a-w c:\windows\system32\iertutil.dll
- 2008-10-16 13:11:09 13,824 —-a-w c:\windows\system32\ieudinit.exe
+ 2008-12-19 09:10:15 13,824 —-a-w c:\windows\system32\ieudinit.exe
- 2008-10-16 20:38:37 27,648 ——w c:\windows\system32\jsproxy.dll
+ 2008-12-20 23:15:23 27,648 ——w c:\windows\system32\jsproxy.dll
- 2008-10-16 20:38:37 459,264 —-a-w c:\windows\system32\msfeeds.dll
+ 2008-12-20 23:15:23 459,264 —-a-w c:\windows\system32\msfeeds.dll
- 2008-10-16 20:38:37 52,224 —-a-w c:\windows\system32\msfeedsbs.dll
+ 2008-12-20 23:15:24 52,224 —-a-w c:\windows\system32\msfeedsbs.dll
- 2008-12-13 06:40:02 3,593,216 —-a-w c:\windows\system32\mshtml.dll
+ 2009-01-17 02:35:14 3,594,752 —-a-w c:\windows\system32\mshtml.dll
- 2008-10-16 20:38:38 477,696 ——w c:\windows\system32\mshtmled.dll
+ 2008-12-20 23:15:30 477,696 ——w c:\windows\system32\mshtmled.dll
- 2008-10-16 20:38:38 193,024 ——w c:\windows\system32\msrating.dll
+ 2008-12-20 23:15:31 193,024 ——w c:\windows\system32\msrating.dll
- 2008-10-16 20:38:39 671,232 ——w c:\windows\system32\mstime.dll
+ 2008-12-20 23:15:32 671,232 ——w c:\windows\system32\mstime.dll
- 2008-10-16 20:38:39 102,912 ——w c:\windows\system32\occache.dll
+ 2008-12-20 23:15:38 102,912 ——w c:\windows\system32\occache.dll
- 2009-02-05 22:18:42 53,838 —-a-w c:\windows\system32\perfc009.dat
+ 2009-02-10 23:10:08 53,838 —-a-w c:\windows\system32\perfc009.dat
- 2009-02-05 22:18:42 382,260 —-a-w c:\windows\system32\perfh009.dat
+ 2009-02-10 23:10:08 382,260 —-a-w c:\windows\system32\perfh009.dat
- 2008-10-16 20:38:39 44,544 ——w c:\windows\system32\pngfilt.dll
+ 2008-12-20 23:15:38 44,544 ——w c:\windows\system32\pngfilt.dll
- 2007-11-30 12:39:22 17,272 ——w c:\windows\system32\spmsg.dll
+ 2008-07-09 07:38:24 17,272 ——w c:\windows\system32\spmsg.dll
- 2008-10-16 20:38:39 105,984 —-a-w c:\windows\system32\url.dll
+ 2008-12-20 23:15:39 105,984 —-a-w c:\windows\system32\url.dll
- 2008-10-16 20:38:39 1,160,192 —-a-w c:\windows\system32\urlmon.dll
+ 2008-12-20 23:15:40 1,160,192 —-a-w c:\windows\system32\urlmon.dll
- 2008-10-16 20:38:39 233,472 —-a-w c:\windows\system32\webcheck.dll
+ 2008-12-20 23:15:40 233,472 —-a-w c:\windows\system32\webcheck.dll
- 2008-10-16 20:38:40 826,368 —-a-w c:\windows\system32\wininet.dll
+ 2008-12-20 23:15:41 826,368 —-a-w c:\windows\system32\wininet.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-12-09 18:40 333192 –a—— c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-12-09 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-12-09 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Google Update"="c:\documents and settings\Lane 8\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-01-16 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-09-13 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 132496]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 385024]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-12-03 344064]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"mmtask"="c:\program files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2004-09-14 53248]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-08-15 180269]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-04-08 48752]
"vptray"="c:\progra~1\SYMANT~1\SYMANT~2\VPTray.exe" [2005-04-17 85184]
"DeadAIM"="c:\program files\AIM\\DeadAIM.ocm" [2003-02-24 266313]
"Dell AIO Printer A940"="c:\program files\Dell AIO Printer A940\dlbabmgr.exe" [2003-06-25 294998]
"DLBUCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll" [2004-11-09 69632]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"MaxtorOneTouch"="c:\program files\Maxtor\OneTouch\utils\Onetouch.exe" [2004-12-22 823296]
"RetroExpress"="c:\progra~1\Dantz\RETROS~1\RetroExpress.exe" [2004-07-30 6946816]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2003-11-10 34832]

c:\documents and settings\Lane 8\Start Menu\Programs\Startup\
Clean Access Agent.lnk - c:\program files\Cisco Systems\Clean Access Agent\CCAAgentLauncher.exe [2007-12-07 28672]
p2pmax.lnk - c:\qoobox\Quarantine\C\Program Files\p2pmax\p2pmax.exe.vir [2008-12-19 28672]
runit_32.lnk - c:\program files\runit\runit_32.exe [2008-12-25 24576]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0\aoltray.exe [2005-07-13 156784]
dlbcserv.lnk - c:\program files\Dell Photo Printer 720\dlbcserv.exe [2005-08-29 315392]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 16:08 110592 c:\program files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [2009-01-01 464264]
R2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [2009-01-01 234888]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 SavRoam;SAVRoam;c:\program files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe [2005-04-17 124608]

— Other Services/Drivers In Memory —

*Deregistered* - EraserUtilDrvI7
.
Contents of the 'Scheduled Tasks' folder

2009-01-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2009-02-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4154990965-559821465-4190246901-1007.job
- c:\documents and settings\Lane 8\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-01-16 18:30]

2009-02-11 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 17:20]

2005-08-28 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-03-31 16:32]
.
.
——- Supplementary Scan ——-
.
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-11 17:49:12
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLBUCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …


c:\windows\TEMP\TMP000000D69283000094FCB7B7 524288 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(988)
c:\windows\system32\Ati2evxx.dll
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
Completion time: 2009-02-11 17:53:35
ComboFix-quarantined-files.txt 2009-02-11 22:52:20
ComboFix2.txt 2009-02-10 23:00:36

Pre-Run: 18,451,046,400 bytes free
Post-Run: 18,511,204,352 bytes free

331 — E O F — 2009-02-11 05:13:58
hello

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
hello Malwarebytes' Anti-Malware 1.34 Database version: 1764 Windows 5.1.2600 Service Pack 2 2/15/2009 8:15:00 PM mbam-log-2009-02-15 (20-15-00).txt Scan type: Quick Scan Objects scanned: 83951 Time elapsed: 15 minute(s), 50 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 29 Registry Values Infected: 2 Registry Data Items Infected: 0 Folders Infected: 7 Files Infected: 10 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll (Adware.MyWebSearch) -> Delete on reboot. Registry Keys Infected: HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{17de5e5e-bfe3-4e83-8e1f-8755795359ec} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{1f52a5fa-a705-4415-b975-88503b291728} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{3e720451-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{3e720453-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{7473d293-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{7473d295-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{7473d297-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{8cbb349a-6b7b-445b-8296-1586b859e942} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{a85ca9ae-00b0-49c3-ba80-bac3084e433e} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25e} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25f} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{e4e3e0f8-cd30-4380-8ce9-b96904bdefca} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{fe8a736f-4124-4d9c-b4b1-3b12381efabe} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{4d25f920-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{4d25f923-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{4d25f921-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4d25f921-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4d25f921-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{4d25f924-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{4d25f926-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{c9c5deaf-0a1f-4660-8279-9edfad6fefe1} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{0d26bc71-a633-4e71-ad31-eadc3a1b6a3a} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{3e720450-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{c8cecde3-1ae1-4c4a-ad82-6d5b00212144} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wjslqojcykb (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\runit (Adware.Trace) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{4d25f926-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{77fbf9b8-1d37-4ff2-9ced-192d8e3aba6f} (Adware.BHO) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Program Files\MyWaySA (Adware.MyWebSearch) -> Delete on reboot. C:\Program Files\MyWaySA\SrchAsDe (Adware.MyWebSearch) -> Delete on reboot. C:\Program Files\MyWaySA\SrchAsDe\1.bin (Adware.MyWebSearch) -> Delete on reboot. C:\Program Files\runit (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Start Menu\Programs\MalwareRemoval (Rogue.FakeMSRT) -> Quarantined and deleted successfully. C:\Documents and Settings\Lane 8\Application Data\MalwareRemoval (Rogue.FakeMSRT) -> Quarantined and deleted successfully. C:\Documents and Settings\Lane 8\Application Data\SetupMalwareRemoval (Rogue.FakeMSRT) -> Quarantined and deleted successfully. Files Infected: C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll (Adware.MyWebSearch) -> Delete on reboot. C:\WINDOWS\system32\wjslqojcykb.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\MalwareKiller.exe (Rogue.FakeMSRT) -> Quarantined and deleted successfully. C:\Program Files\runit\config.txt (Trojan.Agent) -> Quarantined and deleted successfully. C:\Program Files\runit\runitu_32.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Program Files\runit\runit_32.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\Lane 8\Application Data\MalwareRemoval\MalwareRemoval.ini (Rogue.FakeMSRT) -> Quarantined and deleted successfully. C:\Documents and Settings\Lane 8\Application Data\SetupMalwareRemoval\spl.ini (Rogue.FakeMSRT) -> Quarantined and deleted successfully. C:\Documents and Settings\Lane 8\Start Menu\Programs\Startup\p2pmax.lnk (Rogue.Link) -> Quarantined and deleted successfully. C:\Documents and Settings\Lane 8\Start Menu\Programs\Startup\runit_32.lnk (Rogue.Link) -> Quarantined and deleted successfully.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI