Jump to content

vundo.h - virus keeps coming back


Recommended Posts

I previously posted this in the wrong forum and got directed here. Thanks again for any help.

Mbam says I have it but it keeps coming back.

Vundo.h Deletes all my restore points on reboot (please keep in mind that I won't have one.)

I can't turn off the system restore before I scan for virus.

Can't make changes to system configuration.

Basically overrides my user settings and who knows what else.

Delete tool on mbam didn't work either.

Xp user here, grandma and the grand kids thank you in advance!

Here are the goods, I'll wait before I do anything else.

Malwarebytes' Anti-Malware 1.42

Database version: 3456

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

12/30/09 1:29:34 PM

mbam-log-2009-12-30 (13-29-34).txt

Scan type: Quick Scan

Objects scanned: 160172

Time elapsed: 15 minute(s), 54 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 1

Registry Keys Infected: 6

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 2

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

C:\WINDOWS\SYSTEM32\cyzndanw.dll (Trojan.Vundo.H) -> Delete on reboot.

Registry Keys Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e7db3b5d-add7-4245-aa45-40258e688f5d} (Trojan.Vundo.H) -> Delete on reboot.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\boiqrkkf (Trojan.Vundo.H) -> Delete on reboot.

HKEY_CLASSES_ROOT\CLSID\{e7db3b5d-add7-4245-aa45-40258e688f5d} (Trojan.Vundo.H) -> Delete on reboot.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01a6a49d-0b17-48a8-9bfd-1eade94ff08c} (Trojan.Vundo.H) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{01a6a49d-0b17-48a8-9bfd-1eade94ff08c} (Trojan.Vundo.H) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{01a6a49d-0b17-48a8-9bfd-1eade94ff08c} (Trojan.Vundo.H) -> Quarantined and deleted successfully.

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

c:\WINDOWS\SYSTEM32\kttqdac.dll (Trojan.Vundo.H) -> Delete on reboot.

C:\WINDOWS\SYSTEM32\cyzndanw.dll (Trojan.Vundo.H) -> Delete on reboot.

DDS (Ver_09-12-01.01) - NTFSx86

Run by MELWYN BARKER at 14:35:19.78 on 12/30/09

Internet Explorer: 8.0.6001.18702

Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.52 [GMT -6:00]

AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}

FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch

C:\WINDOWS\system32\svchost -k rpcss

C:\WINDOWS\System32\svchost.exe -k netsvcs

C:\WINDOWS\system32\svchost.exe -k NetworkService

C:\WINDOWS\system32\svchost.exe -k LocalService

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Analog Devices\Core\smax4pnp.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe

C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe

C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe

C:\Program Files\Real\RealPlayer\RealPlay.exe

C:\WINDOWS\system32\dla\tfswctrl.exe

C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\QuickTime\qttask.exe

C:\WINDOWS\system32\svchost.exe -k LocalService

C:\WINDOWS\system32\igfxpers.exe

C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe

C:\Program Files\McAfee.com\Agent\mcagent.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\WINDOWS\system32\svchost.exe -k hpdevmgmt

C:\WINDOWS\system32\svchost.exe -k HPService

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\McAfee\SiteAdvisor\McSACore.exe

C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe

c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe

c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe

C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe

C:\Program Files\McAfee\MPF\MPFSrv.exe

C:\WINDOWS\System32\svchost.exe -k HPZ12

C:\WINDOWS\System32\svchost.exe -k HPZ12

C:\Program Files\Dell Support Center\bin\sprtsvc.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\WINDOWS\system32\wdfmgr.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\System32\alg.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\MSN\Toolbar\3.0.0988.2\msntask.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\Documents and Settings\MELWYN BARKER\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/

uDefault_Page_URL = hxxp://www.dell4me.com/myway

uSearch Bar = hxxp://bfc.myway.com/search/de_srchlft.html

uInternet Connection Wizard,ShellNext = iexplore

uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll

BHO: {01a6a49d-0b17-48a8-9bfd-1eade94ff08c} - c:\windows\system32\cyzndanw.dll

BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll

BHO: Java

Attach.zip

Link to post
Share on other sites

GOOD NEWS! I got my system restore points to work!

(assuming that's why nobody has helped me yet)

I think I can credit the online register scan on the Microsoft site. Anyway, I also ran a couple other programs, clumsily, but here's where I'm at now:

Mbam still shows vundo.h but can't remove it,

I also ran Superantispy and found Gen-Nullo and vundo that can't be removed.

Here's the reports, if anyone can help me, you'd be my hero:

Malwarebytes' Anti-Malware 1.43

Database version: 3485

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

01/02/10 10:29:20 PM

mbam-log-2010-01-02 (22-29-20).txt

Scan type: Quick Scan

Objects scanned: 141672

Time elapsed: 8 minute(s), 37 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 3

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 1

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e7db3b5d-add7-4245-aa45-40258e688f5d} (Trojan.Vundo.H) -> Delete on reboot.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\boiqrkkf (Trojan.Vundo.H) -> Delete on reboot.

HKEY_CLASSES_ROOT\CLSID\{e7db3b5d-add7-4245-aa45-40258e688f5d} (Trojan.Vundo.H) -> Delete on reboot.

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

c:\WINDOWS\SYSTEM32\kttqdac.dll (Trojan.Vundo.H) -> Delete on reboot.

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 10:45:02 PM, on 01/02/10

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

c:\Program Files\Microsoft Security Essentials\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Dell Support Center\bin\sprtsvc.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\wscntfy.exe

C:\Program Files\Analog Devices\Core\smax4pnp.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe

C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\igfxpers.exe

C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\Microsoft Security Essentials\msseces.exe

C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\MSN\Toolbar\3.0.0988.2\msntask.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll

O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: (no name) - {E7DB3B5D-ADD7-4245-AA45-40258E688F5D} - c:\windows\system32\kttqdac.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll

O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll

O4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [intelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe

O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"

O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"

O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u

O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide

O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL

O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O15 - Trusted Zone: http://*.mcafee.com

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab

O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers...vex-2.2.4.1.cab

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1193665563107

O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

O20 - Winlogon Notify: boiqrkkf - C:\WINDOWS\SYSTEM32\kttqdac.dll

O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

--

End of file - 8773 bytes

Link to post
Share on other sites

Hello 123Carolyn,

Sorry that no one replied to you earlier. This system is still full of malwares.

Please do not use System Restore as it will not clear your issues.

Please do the following, post back with reports, and await my next reply.

You will want to print out or copy these instructions to Notepad for offline reference!

eusa_hand.gif

If you are a casual viewer, do NOT try this on your system!

If you are not 123Carolyn and have a similar problem, do NOT post here; start your own topic

Do not run or start any other programs while these utilities and tools are in use!

icon_arrow.gif Do NOT run any other tools on your own or do any fixes other than what is listed here.

If you have questions, please ask before you do something on your own.

But it is important that you get going on these following steps.

=

Close any of your open programs while you run these tools.

Step 1

Start HijackThis. Look for these lines and place a checkmark against each of the following, if still present

O2 - BHO: (no name) - {E7DB3B5D-ADD7-4245-AA45-40258E688F5D} - c:\windows\system32\kttqdac.dll

O20 - Winlogon Notify: boiqrkkf - C:\WINDOWS\SYSTEM32\kttqdac.dll

Click on Fix Checked when finished and exit HijackThis.

Make sure your Internet Explorer (& or any other window) is closed when you click Fix Checked!

O20 - Winlogon Notify: boiqrkkf - C:\WINDOWS\SYSTEM32\kttqdac.dll

Step 2

1. Go >> Here << and download ERUNT

(ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.)

2. Install ERUNT by following the prompts

(use the default install settings but say no to the portion that asks you to add ERUNT to the start-up folder, if you like you can enable this option later)

3. Start ERUNT

(either by double clicking on the desktop icon or choosing to start the program at the end of the setup)

4. Choose a location for the backup

(the default location is C:\WINDOWS\ERDNT which is acceptable).

5. Make sure that at least the first two check boxes are ticked

6. Press OK

7. Press YES to create the folder.

Step 3

Set Windows to show all files and all folders.

On your Desktop, double click My Computer, from the menu options, select tools, then Folder Options, and then select VIEW Tab and look at all of settings listed.

"CHECK" (turn on) Display the contents of system folders.

Under column, Hidden files and folders----choose ( *select* ) Show hidden files and folders.

Next, un-check Hide extensions for known file types.

Next un-check Hide protected operating system files.

NEXT:

Please do the following.

Download The Avenger by Swandog46 from here.

  • Unzip/extract it to a folder on your desktop.
  • Double click on avenger.exe to run The Avenger.
  • Click OK.
  • Make sure that the box next to Scan for rootkits has a tick in it and that the box next to Automatically disable any rootkits found does not have a tick in it.
  • Copy all of the text in the below textbox to the clibpboard by highlighting it and then pressing Ctrl+C.
    Files to delete:
    c:\windows\evejigokimaki.dll
    c:\windows\erozabul.dll
    c:\windows\ugaconisixejigu.dll
    c:\windows\exegoyineba.dll
    c:\windows\azaxubigaxel.dll
    c:\windows\uzulasih.dll
    c:\windows\erucebepag.dll
    c:\windows\efeqobac.dll
    c:\windows\itekusad.dll
    c:\windows\ububabud.dll
    c:\windows\ogunesumi.dll
    c:\windows\uwihosozi.dll
    c:\windows\omuretub.dll
    c:\windows\ejatuyihitamaga.dll
    c:\windows\afadebibereriyon.dll
    c:\windows\oyepamotetacoyuc.dll
    c:\windows\iwumezocijezoweq.dll
    c:\windows\esocamotig.dll
    c:\windows\enihicekiqa.dll
    c:\windows\amejiqal.dll
    c:\windows\upatoced.dll
    c:\windows\ujevehadajakuc.dll
    c:\windows\esiqaquzuwocuc.dll
    c:\windows\emesicuz.dll
    c:\windows\unabiqobacagayus.dll
    c:\windows\ovavuyubo.dll
    c:\windows\ayeqojoqokaqo.dll
    c:\windows\ikizeqeqal.dll
    c:\windows\anajoyiqopacaju.dll
    c:\windows\otiresoxiwuv.dll
    c:\windows\aditeboyobubo.dll
    c:\windows\alagozux.dll
    c:\windows\uqovagifobaw.dll
    c:\windows\ovocomexe.dll
    c:\windows\emagobaba.dll
    c:\windows\ewujugaborovom.dll
    c:\windows\uhawimuwesebebe.dll
    c:\windows\abocagay.dll
    c:\windows\egeqinoqoyej.dll
    c:\windows\ugakoboxagijo.dll
    c:\windows\opubugojudoyat.dll
    c:\windows\ijunawozavuyubo.dll
    c:\windows\idehibew.dll
    c:\windows\efazoger.dll
    c:\windows\afumuwesebebe.dll
    c:\windows\ivaqegay.dll
    c:\windows\utahasaj.dll
    c:\windows\oyelowunikazubi.dll
    c:\windows\igacunojagiqetet.dll
    c:\windows\edujehokonipuc.dll
    c:\windows\ulimimesumiwu.dll
    c:\windows\uzagumam.dll
    c:\windows\eruxayotikapaw.dll
    c:\windows\obulemun.dll
    c:\windows\alikeyojiyed.dll
    c:\windows\icunenorixatabiv.dll
    c:\windows\ogakamika.dll
    c:\windows\uwisogol.dll
    c:\windows\ecojemilape.dll
    c:\windows\ejapotaf.dll
    c:\windows\iborigegopep.dll
    c:\windows\egaxavowiyelukig.dll
    c:\windows\eramoxobuzogaz.dll
    c:\windows\ifanizok.dll
    c:\windows\oqarumecahalevet.dll
    c:\windows\ohexowexuluqizev.dll
    c:\windows\utamevixipabu.dll
    c:\windows\iripufaxaw.dll
    c:\windows\idurizazowemulu.dll
    c:\windows\ezerihes.dll
    c:\windows\elozimim.dll
    c:\windows\eyixiyetuk.dll
    c:\windows\uyilomin.dll
    c:\windows\opufatah.dll
    c:\windows\esoqeyuhasaj.dll
    c:\windows\avabezaxe.dll
    c:\windows\ohefohavo.dll
    c:\windows\ojozapowijevo.dll
    c:\windows\edokijir.dll
    c:\windows\azedihosozidohu.dll
    c:\windows\ijoganisapamotet.dll
    c:\windows\ekosucejalafoqip.dll
    c:\windows\inahodop.dll
    c:\windows\afofunanerulat.dll
    c:\windows\itaderir.dll
    c:\windows\opirubur.dll
    c:\windows\azerevafidelujol.dll
    c:\windows\aviwomewomewo.dll
    c:\windows\ewisijeg.dll
    c:\windows\ebodibotaxar.dll
    c:\windows\umosoxebuxe.dll
    c:\windows\ugalasihikilu.dll
    c:\windows\ijacebep.dll
    c:\windows\urubuworu.dll
    c:\windows\eyadiziresoxiw.dll
    c:\windows\ufuxexexivu.dll
    c:\windows\icetoxic.dll
    c:\windows\ekicupodovuje.dll


  • In the avenger window, click the Paste Script from Clipboard icon, pastets4.png button.
  • icon_exclaim.gifMake sure that what appears in Avenger matches exactly what you were asked to Copy/Paste from the Code box above.
  • Click the Execute button.
  • You will be asked Are you sure you want to execute the current script?.
  • Click Yes.
  • You will now be asked First step completed --- The Avenger has been successfully set up to run on next boot. Reboot now?.
  • Click Yes.
  • Your PC will now be rebooted.
  • Note: If the above script contains Drivers to delete: or Drivers to disable:, then The Avenger will require two reboots to complete its operation.
  • If that is the case, it will force a BSOD on the first reboot. This is normal & expected behaviour.
  • After your PC has completed the necessary reboots, a log should automatically open. Please copy/paste the contents of c:\avenger.txt into your next reply.

Step 4

Download OTL by OldTimer to your desktop: http://oldtimer.geekstogo.com/OTL.exe

  • Close all open windows on the Task Bar. Click the icon (for Vista, right click the icon and Run as Administrator) to start the program.
  • In the lower right corner of the Top Panel, checkmark "LOP Check" and checkmark "Purity Check".
  • Now click Run Scan at Top left and let the program run uninterrupted. It will take about 4 minutes.
  • It will produce two logs for you, one will pop up called OTL.txt, the other will be saved on your desktop and called Extras.txt.
  • Exit Notepad. Remember where you've saved these 2 files as we will need both of them shortly!
  • Exit OTL by clicking the X at top right.

Download Security Check by screen317 and save it to your Desktop: here or here

  • Run Security Check
  • Follow the onscreen instructions inside of the command window.
  • A Notepad document should open automatically called checkup.txt; close Notepad. We will need this log, too, so remember where you've saved it!

eusa_hand.gifIf one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.

Then copy/paste the following into your post (in order):

  • the contents of C:\Avenger.txt
  • the contents of OTL.txt
  • the contents of Extras.txt
  • the contents of checkup.txt

Be sure to do a Preview prior to pressing Submit because all reports may not fit into 1 single reply. You may have to do more than 1 reply.

Do not use the attachment feature to place any of your reports. Always put them in-line inside the body of reply.

Edited by Maurice Naggar
Added section for Avenger procedure
Link to post
Share on other sites

I haven't and won't do anything till I here from you.

Thanks so much!

Logfile of The Avenger Version 2.0, © by Swandog46

http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.

Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.

No rootkits found!

Error: file "c:\windows\evejigokimaki.dll" not found!

Deletion of file "c:\windows\evejigokimaki.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\erozabul.dll" not found!

Deletion of file "c:\windows\erozabul.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ugaconisixejigu.dll" not found!

Deletion of file "c:\windows\ugaconisixejigu.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\exegoyineba.dll" not found!

Deletion of file "c:\windows\exegoyineba.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\azaxubigaxel.dll" not found!

Deletion of file "c:\windows\azaxubigaxel.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\uzulasih.dll" not found!

Deletion of file "c:\windows\uzulasih.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\erucebepag.dll" not found!

Deletion of file "c:\windows\erucebepag.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\efeqobac.dll" not found!

Deletion of file "c:\windows\efeqobac.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\itekusad.dll" not found!

Deletion of file "c:\windows\itekusad.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ububabud.dll" not found!

Deletion of file "c:\windows\ububabud.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ogunesumi.dll" not found!

Deletion of file "c:\windows\ogunesumi.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\uwihosozi.dll" not found!

Deletion of file "c:\windows\uwihosozi.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\omuretub.dll" not found!

Deletion of file "c:\windows\omuretub.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ejatuyihitamaga.dll" not found!

Deletion of file "c:\windows\ejatuyihitamaga.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\afadebibereriyon.dll" not found!

Deletion of file "c:\windows\afadebibereriyon.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\oyepamotetacoyuc.dll" not found!

Deletion of file "c:\windows\oyepamotetacoyuc.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\iwumezocijezoweq.dll" not found!

Deletion of file "c:\windows\iwumezocijezoweq.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\esocamotig.dll" not found!

Deletion of file "c:\windows\esocamotig.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\enihicekiqa.dll" not found!

Deletion of file "c:\windows\enihicekiqa.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\amejiqal.dll" not found!

Deletion of file "c:\windows\amejiqal.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\upatoced.dll" not found!

Deletion of file "c:\windows\upatoced.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ujevehadajakuc.dll" not found!

Deletion of file "c:\windows\ujevehadajakuc.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\esiqaquzuwocuc.dll" not found!

Deletion of file "c:\windows\esiqaquzuwocuc.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\emesicuz.dll" not found!

Deletion of file "c:\windows\emesicuz.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\unabiqobacagayus.dll" not found!

Deletion of file "c:\windows\unabiqobacagayus.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ovavuyubo.dll" not found!

Deletion of file "c:\windows\ovavuyubo.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ayeqojoqokaqo.dll" not found!

Deletion of file "c:\windows\ayeqojoqokaqo.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ikizeqeqal.dll" not found!

Deletion of file "c:\windows\ikizeqeqal.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\anajoyiqopacaju.dll" not found!

Deletion of file "c:\windows\anajoyiqopacaju.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\otiresoxiwuv.dll" not found!

Deletion of file "c:\windows\otiresoxiwuv.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\aditeboyobubo.dll" not found!

Deletion of file "c:\windows\aditeboyobubo.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\alagozux.dll" not found!

Deletion of file "c:\windows\alagozux.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\uqovagifobaw.dll" not found!

Deletion of file "c:\windows\uqovagifobaw.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ovocomexe.dll" not found!

Deletion of file "c:\windows\ovocomexe.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\emagobaba.dll" not found!

Deletion of file "c:\windows\emagobaba.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ewujugaborovom.dll" not found!

Deletion of file "c:\windows\ewujugaborovom.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\uhawimuwesebebe.dll" not found!

Deletion of file "c:\windows\uhawimuwesebebe.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\abocagay.dll" not found!

Deletion of file "c:\windows\abocagay.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\egeqinoqoyej.dll" not found!

Deletion of file "c:\windows\egeqinoqoyej.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ugakoboxagijo.dll" not found!

Deletion of file "c:\windows\ugakoboxagijo.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\opubugojudoyat.dll" not found!

Deletion of file "c:\windows\opubugojudoyat.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ijunawozavuyubo.dll" not found!

Deletion of file "c:\windows\ijunawozavuyubo.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\idehibew.dll" not found!

Deletion of file "c:\windows\idehibew.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\efazoger.dll" not found!

Deletion of file "c:\windows\efazoger.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\afumuwesebebe.dll" not found!

Deletion of file "c:\windows\afumuwesebebe.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ivaqegay.dll" not found!

Deletion of file "c:\windows\ivaqegay.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\utahasaj.dll" not found!

Deletion of file "c:\windows\utahasaj.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\oyelowunikazubi.dll" not found!

Deletion of file "c:\windows\oyelowunikazubi.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\igacunojagiqetet.dll" not found!

Deletion of file "c:\windows\igacunojagiqetet.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\edujehokonipuc.dll" not found!

Deletion of file "c:\windows\edujehokonipuc.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ulimimesumiwu.dll" not found!

Deletion of file "c:\windows\ulimimesumiwu.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\uzagumam.dll" not found!

Deletion of file "c:\windows\uzagumam.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\eruxayotikapaw.dll" not found!

Deletion of file "c:\windows\eruxayotikapaw.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\obulemun.dll" not found!

Deletion of file "c:\windows\obulemun.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\alikeyojiyed.dll" not found!

Deletion of file "c:\windows\alikeyojiyed.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\icunenorixatabiv.dll" not found!

Deletion of file "c:\windows\icunenorixatabiv.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ogakamika.dll" not found!

Deletion of file "c:\windows\ogakamika.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\uwisogol.dll" not found!

Deletion of file "c:\windows\uwisogol.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ecojemilape.dll" not found!

Deletion of file "c:\windows\ecojemilape.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ejapotaf.dll" not found!

Deletion of file "c:\windows\ejapotaf.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\iborigegopep.dll" not found!

Deletion of file "c:\windows\iborigegopep.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\egaxavowiyelukig.dll" not found!

Deletion of file "c:\windows\egaxavowiyelukig.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\eramoxobuzogaz.dll" not found!

Deletion of file "c:\windows\eramoxobuzogaz.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ifanizok.dll" not found!

Deletion of file "c:\windows\ifanizok.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\oqarumecahalevet.dll" not found!

Deletion of file "c:\windows\oqarumecahalevet.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ohexowexuluqizev.dll" not found!

Deletion of file "c:\windows\ohexowexuluqizev.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\utamevixipabu.dll" not found!

Deletion of file "c:\windows\utamevixipabu.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\iripufaxaw.dll" not found!

Deletion of file "c:\windows\iripufaxaw.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\idurizazowemulu.dll" not found!

Deletion of file "c:\windows\idurizazowemulu.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ezerihes.dll" not found!

Deletion of file "c:\windows\ezerihes.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\elozimim.dll" not found!

Deletion of file "c:\windows\elozimim.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\eyixiyetuk.dll" not found!

Deletion of file "c:\windows\eyixiyetuk.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\uyilomin.dll" not found!

Deletion of file "c:\windows\uyilomin.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\opufatah.dll" not found!

Deletion of file "c:\windows\opufatah.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\esoqeyuhasaj.dll" not found!

Deletion of file "c:\windows\esoqeyuhasaj.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\avabezaxe.dll" not found!

Deletion of file "c:\windows\avabezaxe.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ohefohavo.dll" not found!

Deletion of file "c:\windows\ohefohavo.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ojozapowijevo.dll" not found!

Deletion of file "c:\windows\ojozapowijevo.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\edokijir.dll" not found!

Deletion of file "c:\windows\edokijir.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\azedihosozidohu.dll" not found!

Deletion of file "c:\windows\azedihosozidohu.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ijoganisapamotet.dll" not found!

Deletion of file "c:\windows\ijoganisapamotet.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ekosucejalafoqip.dll" not found!

Deletion of file "c:\windows\ekosucejalafoqip.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\inahodop.dll" not found!

Deletion of file "c:\windows\inahodop.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\afofunanerulat.dll" not found!

Deletion of file "c:\windows\afofunanerulat.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\itaderir.dll" not found!

Deletion of file "c:\windows\itaderir.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\opirubur.dll" not found!

Deletion of file "c:\windows\opirubur.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\azerevafidelujol.dll" not found!

Deletion of file "c:\windows\azerevafidelujol.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\aviwomewomewo.dll" not found!

Deletion of file "c:\windows\aviwomewomewo.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ewisijeg.dll" not found!

Deletion of file "c:\windows\ewisijeg.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ebodibotaxar.dll" not found!

Deletion of file "c:\windows\ebodibotaxar.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\umosoxebuxe.dll" not found!

Deletion of file "c:\windows\umosoxebuxe.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ugalasihikilu.dll" not found!

Deletion of file "c:\windows\ugalasihikilu.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ijacebep.dll" not found!

Deletion of file "c:\windows\ijacebep.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\urubuworu.dll" not found!

Deletion of file "c:\windows\urubuworu.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\eyadiziresoxiw.dll" not found!

Deletion of file "c:\windows\eyadiziresoxiw.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ufuxexexivu.dll" not found!

Deletion of file "c:\windows\ufuxexexivu.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\icetoxic.dll" not found!

Deletion of file "c:\windows\icetoxic.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "c:\windows\ekicupodovuje.dll" not found!

Deletion of file "c:\windows\ekicupodovuje.dll" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Completed script processing.

*******************

Finished! Terminate.

OTL Extras logfile created on: 1/3/2010 10:39:40 PM - Run 1

OTL by OldTimer - Version 3.1.21.0 Folder = C:\Documents and Settings\WILLIAM BARKER\Desktop

Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.00 Mb Total Physical Memory | 219.00 Mb Available Physical Memory | 43.00% Memory free

1.00 Gb Paging File | 1.00 Gb Available in Paging File | 74.00% Paging File free

Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 144.82 Gb Total Space | 123.64 Gb Free Space | 85.38% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: WILLBARKERIII

Current User Name: WILLIAM BARKER

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: Current user

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Standard

========== Extra Registry (SafeList) ==========

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]

.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

exefile [open] -- "%1" %*

htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)

htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)

htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)

htmlfile [print] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)

http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)

https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)

CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"UpdatesDisableNotify" = 0

"AntiVirusOverride" = 0

"FirewallOverride" = 0

"AntiVirusDisableNotify" = 0

"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004

"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005

"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001

"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 0

"DoNotAllowExceptions" = 0

"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004

"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005

"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001

"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{05410044-64A6-4248-A026-9745C1E9E159}" = Microsoft Encarta Encyclopedia Standard 2005

"{092eeeee-9fdd-4895-a568-0818c96beb6c}" = AiO_Scan

"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager

"{0A55CDBB-0566-4AA2-A15B-24C7F27C6FF4}" = BPD_Scan

"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE

"{10C69612-017B-45F5-B986-7D113D5A2EA3}" = MSN Toolbar

"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA

"{14374619-0900-4056-BA06-C87C900AF9E6}" = QuickBooks Simple Start Special Edition

"{17334AAF-C9E7-483B-9F45-E3FCAF07FFA7}" = Intel® PROSet for Wired Connections

"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan

"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg

"{1CAD83B0-87A3-4206-BF70-644546808731}" = Overland

"{1EB321CB-3D1D-4cf2-ACB5-9F20874B8E69}" = HP Officejet Pro All-In-One Series

"{21D50B58-73F5-11D6-B2FB-0002A5E32BEF}" = Treasure Planet Training Academy Etherium Rescue

"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java 6 Update 17

"{2E132061-C78A-48D4-A899-1D13B9D189FA}" = Memories Disc Creator 2.0

"{324CEC09-007A-48eb-90E0-9D42D4D5EB0A}" = NetDeviceManager

"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10

"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page

"{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}" = HPSystemDiagnostics

"{3F262ADC-5AD2-48E5-A586-44315E04A9E2}" = Microsoft Picture It! Library 10

"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = Modem On Hold

"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works

"{4192EAC0-6B36-4723-B216-D0E86E7757AC}" = Jasc Paint Shop Photo Album 5

"{42756145-9997-4D28-809B-8756BFD00106}" = Microsoft Picture It! Premium 10

"{48B3FB4D-CE22-488C-8E9F-24EBB77EAC0F}" = Microsoft Security Essentials

"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc

"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement

"{4E5E22C2-1386-47AE-8EDE-32DDCDCD6653}" = QuickTime

"{4FB600F5-C478-4DF7-A2BC-57D3807BAC91}" = BPDSoftware_Ini

"{4FB6F304-A91D-4919-98E5-D96E074EA9E5}" = SkinsHP1

"{5104B07C-6A3D-4E7E-8BBB-960B52554BDD}" = BPD_HPSU

"{54e854d5-d5d4-452d-9c75-b39f5625b5fb}" = Readme

"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool

"{5ADF6293-D60F-4425-AFA7-CEB820DB872B}" = QuickProjects

"{642a22b1-7ab8-44b5-84b9-e58eecf8ece2}" = 2400_2500Help

"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder

"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant

"{67E4EE98-59F4-4210-89A6-A20AF5BEC689}" = Microsoft Streets and Trips 2005

"{6B64C9D6-EEBA-4712-8477-69D6C55ADD6F}" = L7700

"{6E179C77-7335-458D-9537-4F4EAC0181ED}" = Photo Click

"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer

"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder

"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03

"{728278A1-0BB7-45E4-AC5E-91D7C0FD1EDE}" = EarthLink setup files

"{745A92AF-53B4-41A7-91C3-9B026B1D5897}" = InstantShare

"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore

"{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}" = overland

"{78C496B9-5A6B-4692-8C2E-AFFFC34E4961}" = Jasc Paint Shop Pro Studio, Dell Editon

"{78D944D7-A97B-4004-AB0A-B5AD06839940}" = My Way Search Assistant

"{78F4DFCE-1336-4027-BCB2-1A00C24A8653}" = iTunes

"{7A0EFAFB-AC4B-4B88-8C6B-6731BE88DB68}" = Modem Event Monitor

"{7A3F0566-5E05-4919-9C98-456F6B5CF831}" = Get High Speed Internet!

"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax

"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport

"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper

"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder

"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder

"{8868D822-2CBA-46B2-A286-B400B6185769}" = 7500_7600_7700_Help

"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver

"{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}" = Musicmatch

Link to post
Share on other sites

OTL logfile created on: 1/3/2010 10:39:40 PM - Run 1

OTL by OldTimer - Version 3.1.21.0 Folder = C:\Documents and Settings\WILLIAM BARKER\Desktop

Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

510.00 Mb Total Physical Memory | 219.00 Mb Available Physical Memory | 43.00% Memory free

1.00 Gb Paging File | 1.00 Gb Available in Paging File | 74.00% Paging File free

Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 144.82 Gb Total Space | 123.64 Gb Free Space | 85.38% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: WILLBARKERIII

Current User Name: WILLIAM BARKER

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: Current user

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/01/03 22:35:17 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\WILLIAM BARKER\Desktop\OTL.exe

PRC - [2010/01/03 10:36:38 | 00,198,160 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe

PRC - [2009/10/11 04:17:36 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe

PRC - [2009/10/11 04:17:35 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe

PRC - [2009/09/13 18:52:50 | 01,048,392 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Essentials\msseces.exe

PRC - [2009/07/02 17:36:52 | 00,017,904 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe

PRC - [2008/08/13 17:32:40 | 00,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe

PRC - [2008/04/13 18:12:41 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\wscntfy.exe

PRC - [2008/04/13 18:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

PRC - [2007/03/15 10:09:36 | 00,460,784 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\DSAgnt.exe

PRC - [2007/01/02 21:40:10 | 00,210,520 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

PRC - [2006/12/10 21:51:08 | 00,271,960 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe

PRC - [2005/09/21 14:29:56 | 00,323,584 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\iPod\bin\iPodService.exe

PRC - [2005/09/20 09:36:20 | 00,114,688 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\igfxpers.exe

PRC - [2005/09/20 09:32:24 | 00,077,824 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\hkcmd.exe

PRC - [2005/09/16 08:43:06 | 00,274,432 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe

PRC - [2004/10/14 13:42:54 | 01,404,928 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\Core\smax4pnp.exe

PRC - [2004/05/12 15:18:56 | 00,241,664 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

PRC - [2004/05/12 15:18:54 | 00,135,168 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe

PRC - [2003/09/03 19:12:44 | 00,221,184 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe

========== Modules (SafeList) ==========

MOD - [2010/01/03 22:35:17 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\WILLIAM BARKER\Desktop\OTL.exe

========== Win32 Services (SafeList) ==========

SRV - [2009/10/11 04:17:35 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) [Auto | Running] -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService)

SRV - [2009/07/02 17:36:52 | 00,017,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Essentials\MsMpEng.exe -- (MsMpSvc)

SRV - [2008/08/13 17:32:40 | 00,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)

SRV - [2007/05/16 22:13:08 | 00,602,112 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL -- (HPSLPSVC)

SRV - [2007/03/07 14:47:46 | 00,076,848 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService)

SRV - [2007/01/02 22:46:54 | 00,225,280 | ---- | M] (Hewlett-Packard Co.) [On_Demand | Running] -- C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll -- (hpqcxs08)

SRV - [2006/12/10 23:29:24 | 00,131,072 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll -- (hpqddsvc)

SRV - [2006/11/08 16:35:38 | 00,053,248 | ---- | M] (Hewlett-Packard) [Auto | Running] -- C:\WINDOWS\SYSTEM32\HPZipm12.dll -- (Pml Driver HPZ12)

SRV - [2006/11/08 16:35:36 | 00,043,520 | ---- | M] (Hewlett-Packard) [Auto | Running] -- C:\WINDOWS\SYSTEM32\HPZinw12.dll -- (Net Driver HPZ12)

SRV - [2005/09/21 14:29:56 | 00,323,584 | ---- | M] (Apple Computer, Inc.) [On_Demand | Running] -- C:\Program Files\iPod\bin\iPodService.exe -- (iPodService)

SRV - [2005/04/04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT)

SRV - [2003/12/17 12:59:48 | 00,143,360 | ---- | M] (Intel® Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe -- (NetSvc)

========== Driver Services (SafeList) ==========

DRV - [2009/08/05 14:58:40 | 00,093,872 | ---- | M] (Sunbelt Software) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\SBREDrv.sys -- (SBRE)

DRV - [2009/06/18 18:48:04 | 00,142,832 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\MpFilter.sys -- (MpFilter)

DRV - [2008/04/13 12:36:39 | 00,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)

DRV - [2008/04/13 12:36:39 | 00,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)

DRV - [2007/11/13 04:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys -- (Secdrv)

DRV - [2007/02/25 11:10:48 | 00,005,376 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys -- (dsunidrv)

DRV - [2006/12/03 08:32:53 | 00,021,568 | R--- | M] (HP) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\HPZius12.sys -- (HPZius12)

DRV - [2006/12/03 08:32:39 | 00,016,496 | R--- | M] (HP) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\HPZipr12.sys -- (HPZipr12)

DRV - [2006/12/03 08:32:36 | 00,049,920 | R--- | M] (HP) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\HPZid412.sys -- (HPZid412)

DRV - [2006/10/05 15:07:28 | 00,004,736 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Running] -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct)

DRV - [2005/09/20 10:00:54 | 01,302,332 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\ialmnt5.sys -- (ialm)

DRV - [2005/02/02 01:21:04 | 00,014,408 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys -- (GEARAspiWDM)

DRV - [2005/01/27 14:31:06 | 00,260,352 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\smwdm.sys -- (smwdm)

DRV - [2004/12/06 00:05:00 | 00,100,603 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\tfsnudfa.sys -- (tfsnudfa)

DRV - [2004/12/06 00:05:00 | 00,098,714 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\tfsnudf.sys -- (tfsnudf)

DRV - [2004/12/06 00:05:00 | 00,086,586 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\tfsnifs.sys -- (tfsnifs)

DRV - [2004/12/06 00:05:00 | 00,034,843 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\tfsncofs.sys -- (tfsncofs)

DRV - [2004/12/06 00:05:00 | 00,025,883 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\tfsnboio.sys -- (tfsnboio)

DRV - [2004/12/06 00:05:00 | 00,015,227 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\tfsnopio.sys -- (tfsnopio)

DRV - [2004/12/06 00:05:00 | 00,006,363 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\tfsnpool.sys -- (tfsnpool)

DRV - [2004/12/06 00:05:00 | 00,004,123 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\tfsndrct.sys -- (tfsndrct)

DRV - [2004/12/06 00:05:00 | 00,002,239 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\dla\tfsndres.sys -- (tfsndres)

DRV - [2004/12/01 02:22:00 | 00,087,488 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\drvmcdb.sys -- (drvmcdb)

DRV - [2004/11/23 01:56:00 | 00,040,480 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\drvnddm.sys -- (drvnddm)

DRV - [2004/10/07 19:16:04 | 00,035,840 | ---- | M] (Oak Technology Inc.) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\AFS2K.SYS -- (AFS2K)

DRV - [2004/09/17 08:02:54 | 00,732,928 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\senfilt.sys -- (senfilt)

DRV - [2004/08/04 04:00:00 | 00,023,424 | ---- | M] (Acer Laboratories Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\ufvfvnth.sys -- (ufvfvnth)

DRV - [2004/08/04 04:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS -- (Ptilink)

DRV - [2004/08/03 21:29:56 | 01,897,408 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\NV4_MINI.SYS -- (nv)

DRV - [2004/08/02 01:03:00 | 00,020,576 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20)

DRV - [2004/07/14 10:29:04 | 00,005,627 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\sscdbhk5.sys -- (sscdbhk5)

DRV - [2004/07/14 10:28:50 | 00,023,545 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\ssrtln.sys -- (ssrtln)

DRV - [2004/06/15 21:52:40 | 00,061,157 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC53.sys -- (IntelC53)

DRV - [2004/03/05 21:15:34 | 00,647,929 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC52.sys -- (IntelC52)

DRV - [2004/03/05 21:14:42 | 01,233,525 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC51.sys -- (IntelC51)

DRV - [2004/03/05 21:13:38 | 00,037,048 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\mohfilt.sys -- (mohfilt)

DRV - [2004/02/10 14:49:14 | 00,154,112 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\e100b325.sys -- (E100B) Intel®

DRV - [2003/01/10 15:13:04 | 00,033,588 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\wanatw4.sys -- (wanatw) WAN Miniport (ATW)

DRV - [2001/08/17 13:07:44 | 00,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)

DRV - [2001/08/17 13:07:42 | 00,030,688 | ---- | M] (LSI Logic) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)

DRV - [2001/08/17 13:07:40 | 00,028,384 | ---- | M] (LSI Logic) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)

DRV - [2001/08/17 13:07:36 | 00,032,640 | ---- | M] (LSI Logic) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)

DRV - [2001/08/17 13:07:34 | 00,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)

DRV - [2001/08/17 12:57:38 | 00,016,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys -- (MODEMCSA)

DRV - [2001/08/17 12:52:22 | 00,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)

DRV - [2001/08/17 12:52:20 | 00,045,312 | ---- | M] (QLogic Corporation) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)

DRV - [2001/08/17 12:52:20 | 00,040,320 | ---- | M] (QLogic Corporation) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)

DRV - [2001/08/17 12:52:18 | 00,049,024 | ---- | M] (QLogic Corporation) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)

DRV - [2001/08/17 12:52:16 | 00,179,584 | ---- | M] (Mylex Corporation) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)

DRV - [2001/08/17 12:52:12 | 00,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)

DRV - [2001/08/17 12:52:00 | 00,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)

DRV - [2001/08/17 12:51:58 | 00,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)

DRV - [2001/08/17 12:51:56 | 00,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)

DRV - [2001/08/17 12:51:54 | 00,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Boot | Stopped] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = F1 F7 21 03 6B B9 DF 40 BD D9 71 64 D7 16 6B F2 [binary data]

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0

FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0

FF - prefs.js..extensions.enabledItems: {68E13F06-2FFD-4A63-B0E1-A8E368F70450}:1.0

FF - prefs.js..extensions.enabledItems: {7BC4495C-5FF3-41D7-9E52-14217E13F85D}:1.0

FF - HKLM\software\mozilla\Firefox\extensions\\{68E13F06-2FFD-4A63-B0E1-A8E368F70450}: C:\Documents and Settings\WILLIAM BARKER\Local Settings\Application Data\{68E13F06-2FFD-4A63-B0E1-A8E368F70450} [2009/04/13 09:20:03 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Firefox\extensions\\{7BC4495C-5FF3-41D7-9E52-14217E13F85D}: C:\Documents and Settings\MELWYN BARKER\Local Settings\Application Data\{7BC4495C-5FF3-41D7-9E52-14217E13F85D} [2009/04/15 04:50:13 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/03 12:26:10 | 00,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/03 19:47:06 | 00,000,000 | ---D | M]

[2010/01/03 12:26:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\WILLIAM BARKER\Application Data\Mozilla\Extensions

[2010/01/03 21:10:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\WILLIAM BARKER\Application Data\Mozilla\Firefox\Profiles\c9wcwybu.default\extensions

[2010/01/03 16:09:43 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

Hosts file not found

O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - No CLSID value found.

O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)

O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)

O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)

O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)

O2 - BHO: (no name) - {E7DB3B5D-ADD7-4245-AA45-40258E688F5D} - C:\WINDOWS\SYSTEM32\kttqdac.dll ()

O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)

O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)

O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)

O3 - HKLM\..\Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - No CLSID value found.

O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.

O4 - HKLM..\Run: [HP Component Manager] C:\Program Files\HP\hpcoretech\hpcmpmgr.exe (Hewlett-Packard Company)

O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\SYSTEM32\hkcmd.exe (Intel Corporation)

O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\SYSTEM32\igfxpers.exe (Intel Corporation)

O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\SYSTEM32\igfxtray.exe (Intel Corporation)

O4 - HKLM..\Run: [intelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe (Intel Corporation)

O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Computer, Inc.)

O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)

O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)

O4 - HKLM..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)

O4 - HKLM..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)

O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)

O4 - HKLM..\Run: [userFaultCheck] File not found

O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 1

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145

O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)

O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.

O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)

O15 - HKCU\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)

O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www1.snapfish.com/SnapfishActivia.cab (Snapfish Activia)

O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers...vex-2.2.4.1.cab (DLM Control)

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu...b?1193665563107 (MUWebControl Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_17)

O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...r/ultrashim.cab (Reg Error: Key error.)

O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl...indows-i586.cab (Reg Error: Key error.)

O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_17)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_17)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab (Shockwave Flash Object)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12

O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\boiqrkkf: DllName - kttqdac.dll - C:\WINDOWS\System32\kttqdac.dll ()

O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2004/08/10 12:04:08 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - comfile [open] -- "%1" %*

O35 - exefile [open] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/01/03 22:35:16 | 00,513,536 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\WILLIAM BARKER\Desktop\OTL.exe

[2010/01/03 22:31:13 | 00,000,000 | ---D | C] -- C:\Avenger

[2010/01/03 22:06:17 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT

[2010/01/03 22:02:26 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT

[2010/01/03 21:39:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\WILLIAM BARKER\Desktop\pro help

[2010/01/03 15:05:20 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft

[2010/01/03 13:57:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\WILLIAM BARKER\Application Data\SUPERAntiSpyware.com

[2010/01/03 12:36:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\WILLIAM BARKER\Application Data\Malwarebytes

[2010/01/03 12:30:26 | 00,000,000 | -HSD | C] -- C:\Documents and Settings\WILLIAM BARKER\IECompatCache

[2010/01/03 12:30:06 | 00,000,000 | -HSD | C] -- C:\Documents and Settings\WILLIAM BARKER\PrivacIE

[2010/01/03 12:30:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\WILLIAM BARKER\Application Data\Yahoo!

[2010/01/03 12:26:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\WILLIAM BARKER\Local Settings\Application Data\Mozilla

[2010/01/03 12:06:45 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\WILLIAM BARKER\Recent

[2010/01/03 12:01:04 | 00,000,000 | ---D | C] -- C:\Documents and Settings\WILLIAM BARKER\Application Data\Real

[2010/01/03 11:59:29 | 00,000,000 | -HSD | C] -- C:\Documents and Settings\WILLIAM BARKER\IETldCache

[2010/01/03 11:49:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion

[2010/01/03 11:49:12 | 00,000,000 | ---D | C] -- C:\Program Files\Yahoo!

[2010/01/03 10:47:21 | 00,016,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg.dll

[2010/01/03 10:46:23 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Media Connect 2

[2010/01/03 10:44:07 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\UMDF

[2010/01/03 10:37:21 | 00,185,920 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\rmoc3260.dll

[2010/01/03 10:37:08 | 00,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5016.dll

[2010/01/03 10:37:08 | 00,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5032.dll

[2010/01/03 10:37:06 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared

[2010/01/03 10:36:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Real

[2010/01/03 10:20:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NOS

[2010/01/03 09:12:01 | 00,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe

[2010/01/03 09:12:01 | 00,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe

[2010/01/03 09:12:01 | 00,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe

[2010/01/02 22:44:17 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro

[2010/01/02 19:15:17 | 00,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware

[2010/01/02 13:31:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth

[2010/01/02 10:26:07 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Essentials

[2010/01/01 18:06:52 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft

[2010/01/01 17:58:32 | 00,093,872 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys

[2010/01/01 17:58:32 | 00,027,944 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\sbbd.exe

[2010/01/01 17:26:46 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys

[2010/01/01 17:26:45 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2010/01/01 17:26:45 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware

[2010/01/01 16:56:58 | 00,195,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe

[2009/12/31 17:21:00 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com

[2009/12/31 10:41:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\WILLIAM BARKER\Desktop\New Folder

[2009/12/30 11:26:00 | 00,000,000 | ---D | C] -- C:\WINDOWS\ie8updates

[2009/12/30 11:23:13 | 00,471,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aclayers.dll

[2009/12/30 07:36:18 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8

[2009/12/29 21:51:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft

[2009/12/29 21:50:30 | 00,000,000 | ---D | C] -- C:\WINDOWS\Prefetch

[2009/12/29 21:33:41 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\scripting

[2009/12/29 21:33:40 | 00,000,000 | ---D | C] -- C:\WINDOWS\l2schemas

[2009/12/29 21:33:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\en

[2009/12/29 21:33:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\bits

[2009/12/29 21:24:07 | 00,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$

[2009/12/29 21:24:02 | 00,000,000 | ---D | C] -- C:\WINDOWS\EHome

[2009/12/29 21:11:40 | 00,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox

[2009/12/29 20:54:03 | 00,000,000 | ---D | C] -- C:\WINDOWS\pss

[2009/12/29 18:37:15 | 00,024,576 | ---- | C] (Atribune.org) -- C:\WINDOWS\System32\VundoFixSVC.exe

[2009/12/29 12:41:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes

[2009/11/26 16:16:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\SACore

[2009/11/23 00:22:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft

[2009/11/21 18:55:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia

[2009/11/21 18:55:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Adobe

[2009/04/10 21:04:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Mozilla

[2008/05/26 02:42:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\SupportSoft

[2008/05/25 20:14:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Adobe

[2008/05/10 08:33:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\HP

[2007/08/31 18:03:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Macromedia

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/01/03 22:35:17 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\WILLIAM BARKER\Desktop\OTL.exe

[2010/01/03 22:32:12 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL

[2010/01/03 22:31:41 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT

[2010/01/03 22:31:33 | 00,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT

[2010/01/03 22:31:32 | 53,482,7008 | -HS- | M] () -- C:\hiberfil.sys

[2010/01/03 22:30:34 | 04,194,304 | -H-- | M] () -- C:\Documents and Settings\WILLIAM BARKER\NTUSER.DAT

[2010/01/03 22:30:34 | 00,000,278 | -HS- | M] () -- C:\Documents and Settings\WILLIAM BARKER\NTUSER.INI

[2010/01/03 22:02:27 | 00,000,611 | ---- | M] () -- C:\Documents and Settings\WILLIAM BARKER\Desktop\NTREGOPT.lnk

[2010/01/03 22:02:27 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\WILLIAM BARKER\Desktop\ERUNT.lnk

[2010/01/03 21:42:07 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\WILLIAM BARKER\Desktop\HijackThis.lnk

[2010/01/03 20:46:36 | 00,000,007 | ---- | M] () -- C:\WINDOWS\System32\Class11

[2010/01/03 20:46:36 | 00,000,005 | ---- | M] () -- C:\WINDOWS\System32\Band4

[2010/01/03 19:27:43 | 00,071,920 | ---- | M] () -- C:\Documents and Settings\WILLIAM BARKER\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

[2010/01/03 19:26:42 | 00,266,208 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[2010/01/03 18:25:20 | 00,000,671 | ---- | M] () -- C:\WINDOWS\WIN.INI

[2010/01/03 18:25:20 | 00,000,227 | ---- | M] () -- C:\WINDOWS\SYSTEM.INI

[2010/01/03 18:25:20 | 00,000,211 | -HS- | M] () -- C:\BOOT.INI

[2010/01/03 18:18:20 | 00,000,434 | ---- | M] () -- C:\WINDOWS\tasks\At1.job

[2010/01/03 15:46:11 | 00,000,708 | ---- | M] () -- C:\Documents and Settings\WILLIAM BARKER\Desktop\run me if computer needs help-Carolyn Malwarebytes' Anti-Malware.lnk

[2010/01/03 15:05:23 | 00,000,782 | ---- | M] () -- C:\Documents and Settings\WILLIAM BARKER\Desktop\Windows Media Player.lnk

[2010/01/03 13:52:50 | 00,001,072 | ---- | M] () -- C:\Documents and Settings\WILLIAM BARKER\Application Data\wklnhst.dat

[2010/01/03 13:11:46 | 00,000,434 | ---- | M] () -- C:\WINDOWS\tasks\At2.job

[2010/01/03 13:05:04 | 00,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK

[2010/01/03 10:46:50 | 00,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb

[2010/01/03 10:46:50 | 00,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb

[2010/01/03 10:44:11 | 00,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf

[2010/01/03 10:37:33 | 00,000,715 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\RealPlayer SP.lnk

[2010/01/03 10:37:21 | 00,185,920 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\rmoc3260.dll

[2010/01/03 10:37:08 | 00,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5016.dll

[2010/01/03 10:37:08 | 00,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5032.dll

[2010/01/03 10:36:41 | 00,499,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcp71.dll

[2010/01/03 10:36:41 | 00,348,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msvcr71.dll

[2010/01/03 10:36:40 | 00,278,528 | ---- | M] (Real Networks, Inc) -- C:\WINDOWS\System32\pncrt.dll

[2010/01/02 10:26:08 | 00,000,820 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\turn me on for security-Carolyn Microsoft Security Essentials.lnk

[2010/01/01 10:03:17 | 00,002,415 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Dell Support Center.lnk

[2009/12/31 16:36:47 | 07,451,168 | ---- | M] () -- C:\Documents and Settings\WILLIAM BARKER\Desktop\SUPERAntiSpyware.exe

[2009/12/30 14:55:24 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys

[2009/12/30 14:54:58 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys

[2009/12/30 14:40:41 | 00,293,376 | ---- | M] () -- C:\Documents and Settings\WILLIAM BARKER\Desktop\fd6s9x8r.exe

[2009/12/29 21:55:19 | 00,442,466 | ---- | M] () -- C:\WINDOWS\System32\PERFH009.DAT

[2009/12/29 21:55:19 | 00,071,732 | ---- | M] () -- C:\WINDOWS\System32\PERFC009.DAT

[2009/12/29 21:55:18 | 00,524,198 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI

[2009/12/29 21:52:11 | 00,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx

[2009/12/29 21:29:04 | 00,250,048 | RHS- | M] () -- C:\NTLDR

[2009/12/29 21:11:47 | 00,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk

[2009/12/29 18:37:15 | 00,024,576 | ---- | M] (Atribune.org) -- C:\WINDOWS\System32\VundoFixSVC.exe

[2009/12/19 16:17:35 | 00,001,755 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache

[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/01/03 22:02:27 | 00,000,611 | ---- | C] () -- C:\Documents and Settings\WILLIAM BARKER\Desktop\NTREGOPT.lnk

[2010/01/03 22:02:27 | 00,000,592 | ---- | C] () -- C:\Documents and Settings\WILLIAM BARKER\Desktop\ERUNT.lnk

[2010/01/03 21:42:07 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\WILLIAM BARKER\Desktop\HijackThis.lnk

[2010/01/03 20:46:36 | 00,000,007 | ---- | C] () -- C:\WINDOWS\System32\Class11

[2010/01/03 15:46:11 | 00,000,708 | ---- | C] () -- C:\Documents and Settings\WILLIAM BARKER\Desktop\run me if computer needs help-Carolyn Malwarebytes' Anti-Malware.lnk

[2010/01/03 13:04:24 | 00,001,355 | ---- | C] () -- C:\WINDOWS\imsins.BAK

[2010/01/03 10:44:11 | 00,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf

[2010/01/03 10:37:33 | 00,000,715 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\RealPlayer SP.lnk

[2010/01/02 20:08:06 | 53,482,7008 | -HS- | C] () -- C:\hiberfil.sys

[2010/01/02 19:11:48 | 07,451,168 | ---- | C] () -- C:\Documents and Settings\WILLIAM BARKER\Desktop\SUPERAntiSpyware.exe

[2010/01/02 10:26:08 | 00,000,820 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\turn me on for security-Carolyn Microsoft Security Essentials.lnk

[2009/12/30 14:40:38 | 00,293,376 | ---- | C] () -- C:\Documents and Settings\WILLIAM BARKER\Desktop\fd6s9x8r.exe

[2009/12/29 21:11:47 | 00,001,602 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk

[2009/12/19 16:17:35 | 00,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache

[2009/11/21 14:58:36 | 00,003,920 | ---- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\E7DB3B5D-ADD7-4245-AA45-40258E688F5D.txt

[2009/09/13 11:52:24 | 00,003,790 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\5A3BDC81-6666-46B5-8DF8-C69AFC2135E1.txt

[2009/04/20 02:03:57 | 00,000,276 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI

[2009/04/10 14:32:26 | 00,004,330 | ---- | C] () -- C:\Documents and Settings\WILLIAM BARKER\Local Settings\Application Data\5A3BDC81-6666-46B5-8DF8-C69AFC2135E1.txt

[2009/04/10 14:24:03 | 00,003,912 | ---- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\5A3BDC81-6666-46B5-8DF8-C69AFC2135E1.txt

[2008/03/21 19:56:54 | 00,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini

[2007/09/15 17:19:43 | 00,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll

[2006/11/05 10:10:06 | 00,000,657 | ---- | C] () -- C:\WINDOWS\hegames.ini

[2006/04/15 19:02:43 | 00,001,563 | ---- | C] () -- C:\WINDOWS\disney.ini

[2005/08/29 12:57:18 | 00,006,144 | ---- | C] () -- C:\Documents and Settings\WILLIAM BARKER\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2005/08/16 15:46:21 | 00,000,085 | ---- | C] () -- C:\WINDOWS\upst.ini

[2005/08/16 15:46:21 | 00,000,028 | ---- | C] () -- C:\WINDOWS\atid.ini

[2005/05/29 20:59:39 | 00,000,137 | ---- | C] () -- C:\Documents and Settings\WILLIAM BARKER\Local Settings\Application Data\fusioncache.dat

[2005/04/28 17:46:20 | 00,002,933 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log

[2005/04/28 16:25:24 | 00,001,072 | ---- | C] () -- C:\Documents and Settings\WILLIAM BARKER\Application Data\wklnhst.dat

[2005/04/23 05:25:21 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini

[2005/04/23 05:23:03 | 00,000,138 | ---- | C] () -- C:\WINDOWS\wininit.ini

[2005/04/23 05:15:46 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI

[2005/04/23 04:42:42 | 00,000,370 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI

[2005/01/28 07:08:34 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini

[2004/08/10 12:13:12 | 00,000,780 | ---- | C] () -- C:\WINDOWS\ORUN32.INI

[2004/08/04 04:00:00 | 00,147,968 | ---- | C] () -- C:\WINDOWS\System32\cyzndanw.dll

[2004/08/04 04:00:00 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\kttqdac.dll

[2004/08/04 04:00:00 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\bfadlkb.dll

[2004/08/04 04:00:00 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\FXSPERF.INI

[2003/08/11 02:07:40 | 00,565,248 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll

[1979/12/31 23:00:00 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll

========== LOP Check ==========

[2009/04/12 12:20:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Age of Empires 3

[2007/01/28 20:10:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ATX

[2008/08/10 15:23:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Firefly Studios

[2008/02/21 01:56:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft

[2008/11/27 18:59:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\WILLIAM BARKER\Application Data\alot

[2009/04/10 17:30:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\WILLIAM BARKER\Application Data\rcukszcq

[2005/06/19 15:53:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\WILLIAM BARKER\Application Data\xLeadertech

[2010/01/03 18:18:20 | 00,000,434 | ---- | M] () -- C:\WINDOWS\Tasks\At1.job

[2010/01/03 13:11:46 | 00,000,434 | ---- | M] () -- C:\WINDOWS\Tasks\At2.job

========== Purity Check ==========

< End of report >

Results of screen317's Security Check version 0.99.1

Windows XP Service Pack 3

``````````````````````````````

Antivirus/Firewall Check:

Windows Firewall Disabled!

``````````````````````````````

Anti-malware/Other Utilities Check:

HijackThis 2.0.2

Java 6 Update 17

Java 2 Runtime Environment, SE v1.4.2_03

Adobe Flash Player 10

``````````````````````````````

Process Check:

objlist.exe by Laurent

Windows Defender MSMpEng.exe

``````````````````````````````

DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

`````````End of Log```````````

Looks like that ktt.dll thing is pretty stubborn!

Link to post
Share on other sites

Sorry for delay in getting back to you.

This system needs to have the firewall on. Relay this procedure to the pc owner.

To turn on the Internet Connection Firewall in Windows XP

1. Click Start, and click Control Panel.

2. Click Network and Internet Connections. If you do not see Network and Internet Connections,

click Switch to Category View.

3. Click Change Windows Firewall Settings.

4. Select On.

5. Click OK.

6. Exit Control Panel.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.